cybersecurity advisory Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/cybersecurity-advisory/ Breaking news about the market for products, systems and services for the U.S. intelligence community Tue, 28 Apr 2026 11:30:36 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg cybersecurity advisory Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/cybersecurity-advisory/ 32 32 59882712 NSA releases joint guidance on defending against China-nexus covert networks https://intelligencecommunitynews.com/nsa-releases-joint-guidance-on-defending-against-china-nexus-covert-networks/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-releases-joint-guidance-on-defending-against-china-nexus-covert-networks Tue, 28 Apr 2026 11:30:36 +0000 https://intelligencecommunitynews.com/?p=44424 On April 23, the National Security Agency (NSA) joined the United Kingdom’s National Cyber Security Centre, the Australian Signals Directorate’s...

The post NSA releases joint guidance on defending against China-nexus covert networks appeared first on Intelligence Community News.

]]>
On April 23, the National Security Agency (NSA) joined the United Kingdom’s National Cyber Security Centre, the Australian Signals Directorate’s Australian Cyber Security Centre, and others in releasing the joint Cybersecurity Advisory, “Defending against China-nexus covert networks of compromised devices.”

The CSA details how multiple China-nexus threat actors are now using external covert networks to facilitate malicious cyber activity strategically, at scale. These dynamic covert networks include botnets that leverage many compromised devices to connect across the internet in a low-cost, low-risk, deniable way, disguising the origin and attribution of malicious activity. These botnets frequently include compromised small office/home office network infrastructure (routers, firewalls, network attached storage, etc.) and internet of things devices (web cameras, video recorders, smart devices, etc.).

While many new covert infrastructure networks are regularly developed and deployed for use by multiple China-nexus threat actors, existing networks are also updated because of defensive or legal action, software updates, or new exploits being used to target different technologies, according to the CSA. This renders a detailed list of all known networks (how they are constructed and communicated) and previous defense paradigms ineffective. Legitimate users also browse the internet using the networks and devices involved, making attribution of the malicious activity challenging. However, since most networks of compromised infrastructure use the same basic set up, understanding the generalized structure can help aid in defensive efforts.

This CSA explains the widespread shift in tactics, techniques, and procedures by malicious cyber actors away from using individually procured infrastructure to multiple externally managed large covert networks used by many actors simultaneously. It describes the typical makeup of a covert network and how it is used, and includes protective advice for organizations targeted by cyber activity using a covert network as an access vector. Additionally, the guidance outlines tailored steps organizations of all sizes can take to mitigate the risk of attacks.

Anyone who is a target of China-nexus threat actors may be impacted by the use of covert networks, and anyone using a vulnerable device could have their device co-opted into one of these China-nexus covert networks. Cybersecurity analysts and network defenders — including those protecting national security, Department of War, and Defense Industrial Base systems — are advised to use the protective advice and mitigations listed in this CSA to thwart malicious activities.

Read the full report.

Source: NSA

If you enjoyed this article, please consider becoming a paid subscriber. Your support helps keep our site ad-free.

The post NSA releases joint guidance on defending against China-nexus covert networks appeared first on Intelligence Community News.

]]>
44424
CISA warns of programmable logic controller exploitation https://intelligencecommunitynews.com/cisa-warns-of-programmable-logic-controller-exploitation/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-warns-of-programmable-logic-controller-exploitation Sun, 12 Apr 2026 17:37:55 +0000 https://intelligencecommunitynews.com/?p=44304 On April 7, the Cybersecurity and Infrastructure Security Agency (CISA) issued a cybersecurity advisory entitled, “Iranian-Affiliated Cyber Actors Exploit Programmable...

The post CISA warns of programmable logic controller exploitation appeared first on Intelligence Community News.

]]>
On April 7, the Cybersecurity and Infrastructure Security Agency (CISA) issued a cybersecurity advisory entitled, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure.”

Iran-affiliated advanced persistent threat (APT) actors are conducting exploitation activity targeting internet-facing operational technology (OT) devices, including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. This activity has led to PLC disruptions across several U.S. critical infrastructure sectors through malicious interactions with the project file and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss.

U.S. organizations should urgently review the tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) in this advisory for indications of current or historical activity on their networks, and apply the recommendations listed in the Mitigations section of the advisory to reduce the risk of compromise.

Source: CISA

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post CISA warns of programmable logic controller exploitation appeared first on Intelligence Community News.

]]>
44304
NSA warns of Russian State-sponsored cyber campaign https://intelligencecommunitynews.com/nsa-warns-of-russian-state-sponsored-cyber-campaign/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-warns-of-russian-state-sponsored-cyber-campaign Thu, 22 May 2025 13:13:04 +0000 https://intelligencecommunitynews.com/?p=41774 On May 21, the National Security Agency (NSA) announced that it is joining several United States and foreign entities to release...

The post NSA warns of Russian State-sponsored cyber campaign appeared first on Intelligence Community News.

]]>
On May 21, the National Security Agency (NSA) announced that it is joining several United States and foreign entities to release the Cybersecurity Advisory (CSA), “Russian GRU Targeting Western Logistics Entities and Technology Companies,” to call attention to a Russia state-sponsored cyber campaign targeting Western government organizations and commercial logistics entities, transportation services, and technology companies, including those involved in providing assistance to Ukraine.

The Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (Unit 26165) has been conducting this cyber-espionage campaign—using both previously disclosed and novel tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs)—since at least February 2022. This cyber actor is commonly known in the cybersecurity community as APT28, Fancy Bear, Forest Blizzard, or BlueDelta.

In addition to targeting entities involved in supplying aid to Ukraine, Unit 26165 actors can be linked to the targeting of Internet-connected cameras in Ukraine and bordering countries, likely to monitor the movement of shipments into Ukraine.

The CSA provides guidance for at-risk organizations to posture their defenses against potential targeting by Unit 26165 through recommendations for increased monitoring and threat hunting for known TTPs and IOCs.

The report outlines several of the TTPs Unit 26165 actors use to gain access to targeted entities, including password spraying, spearphishing, and modification of Microsoft Exchange mailbox permissions. Additionally, the advisory highlights the specific risk to a range of small office/home office (SOHO) devices, as Unit 26165 actors abuse vulnerabilities associated with a range of brands and models to conduct covert cyber operations and proxy malicious activity.

The authoring agencies expect this cyber-espionage campaign to continue. To defend against and mitigate these threats, at-risk entities should anticipate targeting by Unit 26165 actors, become familiar with the known TTPs and IOCs associated with Unit 26165, and implement the mitigations listed in the CSA.

Read the full report here.

Source: NSA

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

 

The post NSA warns of Russian State-sponsored cyber campaign appeared first on Intelligence Community News.

]]>
41774
NSA issues advisory on 2022’s top exploited vulnerabilities https://intelligencecommunitynews.com/nsa-issues-advisory-on-2022s-top-exploited-vulnerabilities/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-issues-advisory-on-2022s-top-exploited-vulnerabilities Fri, 04 Aug 2023 13:16:41 +0000 https://intelligencecommunitynews.com/?p=36263 In 2022, malicious cyber actors continued exploiting known software vulnerabilities to target unpatched systems and applications, including some vulnerabilities that...

The post NSA issues advisory on 2022’s top exploited vulnerabilities appeared first on Intelligence Community News.

]]>
In 2022, malicious cyber actors continued exploiting known software vulnerabilities to target unpatched systems and applications, including some vulnerabilities that have been known for more than five years, according to a newly released joint Cybersecurity Advisory (CSA) from U.S. and foreign partner intelligence agencies.

The “2022 Top Routinely Exploited Vulnerabilities” CSA provides details on the top Common Vulnerabilities and Exposures (CVEs) routinely exploited by malicious cyber actors who continue targeting unpatched systems and applications – all known vulnerabilities from 2017 to 2022 that have not been mitigated. The authoring agencies recommend immediate patching of these CVEs to reduce the risk of compromise.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released the CSA in partnership with the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), the Communication Security Establishment’s Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NZ NCSC), and the United Kingdom’s National Cyber Security Centre (NCSC-UK).

“Organizations continue using unpatched software and systems, leaving easily discovered openings for cyber actors to target,” said Neal Ziring, the Technical Director for NSA’s Cybersecurity Directorate. “Older vulnerabilities can provide low-cost and high impact means for these actors to access sensitive data.”

In 2022, over 25,000 new security vulnerabilities were published by the Common Vulnerabilities and Exposures (CVE) Program.  From those, only five are within the top 12 software vulnerabilities exploited by malicious cyber actor during 2022, according to the CSA.

Several vulnerabilities listed in the advisory were also reported in the “2021 Top Routinely Exploited Vulnerabilities” CSA and continued to be exploited by cyber actors in 2022. PRC state-sponsored cyber actors, for example, have been using some of the vulnerabilities listed in the CSA to actively target U.S. and allied networks, as indicated in the “Top CVEs Actively Exploited By People’s Republic of China State-Sponsored Cyber Actors”.

To improve cybersecurity posture, the co-authoring agencies recommend organizations implement the mitigations listed in the advisory primarily by prioritizing scanning for and patching of vulnerable software.

Read the full report here.

Source: NSA

Like IC News? Then please consider subscribing. You’ll get full access to our searchable library of 10,000+ articles, plus new articles each weekday.

The post NSA issues advisory on 2022’s top exploited vulnerabilities appeared first on Intelligence Community News.

]]>
36263
NSA, CISA, FBI issue alert on custom exfiltration tools being used against DIB https://intelligencecommunitynews.com/nsa-cisa-fbi-issue-alert-on-custom-exfiltration-tools-being-used-against-dib/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-cisa-fbi-issue-alert-on-custom-exfiltration-tools-being-used-against-dib Thu, 06 Oct 2022 12:35:02 +0000 https://intelligencecommunitynews.com/?p=33616 On October 4, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the FBI released a Cybersecurity...

The post NSA, CISA, FBI issue alert on custom exfiltration tools being used against DIB appeared first on Intelligence Community News.

]]>
On October 4, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the FBI released a Cybersecurity Advisory that details the tactics, techniques and procedures (TTPs) that likely multiple advanced persistent threat (APT) groups recently used to steal sensitive information from a Defense Industrial Base organization. The advisory, “Impacket, Custom Exfiltration Tools Used to Steal Sensitive Information from Defense Industrial Base Organization,” provides indicators of compromise and TTPs used by the groups and shares guidance to detect and prevent related activity.

During a hunt on the organization’s network, CISA and a third-party incident response organization discovered the following malicious activity:

  • Once on the network, APT actors leveraged Impacket in their attack, a toolkit for programmatically constructing and manipulating network protocols
  • The actors used a custom exfiltration tool called CovalentStealer to steal the victim’s data
  • The actors exploited a Microsoft Exchange vulnerability on the organization’s server to gain access remotely and compromised legitimate company accounts to access the accounts of other employees

They recommend that Defense Industrial Base sector and other critical infrastructure organizations implement the mitigations in the advisory to ensure they are managing and reducing  threats to their networks.

Read the full report here.

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

 

The post NSA, CISA, FBI issue alert on custom exfiltration tools being used against DIB appeared first on Intelligence Community News.

]]>
33616
NSA and partners issue top CVE advisory https://intelligencecommunitynews.com/nsa-and-partners-issue-top-cve-advisory/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-and-partners-issue-top-cve-advisory Fri, 29 Apr 2022 12:08:46 +0000 https://intelligencecommunitynews.com/?p=32246 After more than 20,000 common vulnerabilities and exposures (CVEs) were disclosed in 2021, U.S and allied cybersecurity authorities are helping...

The post NSA and partners issue top CVE advisory appeared first on Intelligence Community News.

]]>
After more than 20,000 common vulnerabilities and exposures (CVEs) were disclosed in 2021, U.S and allied cybersecurity authorities are helping organizations prioritize and mitigate the most exploited vulnerabilities. On April 27, the Cybersecurity and Infrastructure Security Agency (CISA), along with the National Security Agency (NSA), Federal Bureau of Investigation (FBI), Australian Cyber Security Centre (ACSC), Canadian Centre for Cyber Security (CCCS), New Zealand National Cyber Security Centre (NZ NCSC), and the United Kingdom’s National Cyber Security Centre (NCSC-UK) issued a joint Cybersecurity Advisory on the top 15 common vulnerabilities and exposures (CVEs) routinely exploited by malicious cyber actors in 2021, as well as other CVEs frequently exploited.

In 2021, malicious cyber actors aggressively targeted newly disclosed critical software vulnerabilities against broad target sets, including public and private sector organizations worldwide. While the top 15 vulnerabilities have previously been made public, this Advisory is meant to help organizations prioritize their mitigation strategies:

  • Vulnerability and configuration management, including update software, operating systems, applications, and firmware in a timely manner; implement a centralized patch management system; and replace end-of-life software.
  • Identity and access management, including enforce multifactor authentication (MFA) for all users, without exception; if MFA is unavailable, require employees engaging in remote work to use strong passwords; and regularly review, validate, or remove privileged accounts.
  • Positive controls and architecture, including properly configure and secure internet-facing network devices, disable unused or unnecessary network ports and protocols, encrypt network traffic, and disable unused network services and devices.

“We know that malicious cyber actors go back to what works, which means they target these same critical software vulnerabilities and will continue to do so until companies and organizations address them,” said CISA Director Jen Easterly. “CISA and our partners are releasing this advisory to highlight the risk that the most commonly exploited vulnerabilities pose to both public and private sector networks. We urge all organizations to assess their vulnerability management practices and take action to mitigate risk to the known exploited vulnerabilities.”

“The FBI, together with our federal and international partners, is providing this information to better arm our private sector partners and the public to defend their systems from adversarial cyber threats,” said FBI’s Cyber Division Assistant Director Bryan Vorndran. “Though the FBI will continue to pursue and disrupt this type of malicious cyber activity, we need your help. We strongly encourage private sector organizations and the public to implement these steps to mitigate threats from known vulnerabilities, and if you believe you are a victim of a cyber incident, contact your local FBI field office.”

“This report should be a reminder to organizations that bad actors don’t need to develop sophisticated tools when they can just exploit publicly known vulnerabilities,” said NSA Cybersecurity Director Rob Joyce. “Get a handle on mitigations or patches as these CVEs are actively exploited.”

“Malicious cyber actors continue to exploit known and dated software vulnerabilities to attack private and public networks globally,” said Abigail Bradshaw, head of the Australian Cyber Security Centre. “The ACSC is committed to providing cyber security advice and sharing threat information with our partners, to ensure a safer online environment for everyone. Organizations can implement the effective mitigations highlighted in this advisory to protect themselves.”

“Cyber security best practices, including patch management, are essential tools for organizations to better protect themselves against malicious threat actors,” said Sami Khoury, head of the Canadian Centre for Cyber Security. “We encourage all organizations to take action and follow the appropriate mitigations in this report against known and routinely exploited vulnerabilities, and make themselves more secure.”

“We are seeing an increase in the speed and scale of malicious actors taking advantage of newly disclosed vulnerabilities,” said Lisa Fong, director of the New Zealand Government Communications Security Bureau’s National Cyber Security Centre (NCSC). “The NCSC works with international partners to provide timely access to critical cyber threat information. This joint advisory underscores the importance of addressing vulnerabilities as they are disclosed and better equips New Zealand organisations to secure their information and systems.”

“The NCSC and our allies are committed to raising awareness of global cyber vulnerabilities and presenting actionable solutions to mitigate them,” said Lindy Cameron, CEO of NCSC. “This advisory places the power in the hands of network defenders to fix the most common cyber weaknesses within the public and private sector ecosystem. Working with our international partners, we will continue to raise awareness of the threats posed by those which seek to harm us.”

Globally, malicious cyber actors targeted internet-facing systems, such as email servers and virtual private network (VPN) servers, with exploits of newly disclosed vulnerabilities. To a lesser extent in 2021, these actors continued to exploit publicly known or dated software vulnerabilities some of which were also identified as routinely exploited in 2020 or earlier.

All organizations are encouraged to review and implement the recommended mitigations in this detailed joint CSA.

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NSA and partners issue top CVE advisory appeared first on Intelligence Community News.

]]>
32246
NSA advises on operational tech security https://intelligencecommunitynews.com/nsa-advises-on-operational-tech-security/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-advises-on-operational-tech-security Mon, 03 May 2021 11:42:13 +0000 https://intelligencecommunitynews.com/?p=29296 On April 29, the National Security Agency (NSA) released the Cybersecurity Advisory, “Stop Malicious Cyber Activity Against Connected Operational Technology”...

The post NSA advises on operational tech security appeared first on Intelligence Community News.

]]>
On April 29, the National Security Agency (NSA) released the Cybersecurity Advisory, “Stop Malicious Cyber Activity Against Connected Operational Technology” for National Security System (NSS), Department of Defense (DoD), and Defense Industrial Base (DIB) operational technology (OT) owners and operators. The CSA details how to evaluate risks to systems and improve the security of connections between OT and enterprise networks. Information technology (IT) exploitation can serve as a pivot point for OT exploitation, so carefully evaluating the risk of connectivity between IT and OT systems is necessary to ensure unique cybersecurity requirements are met.

Each IT-OT connection increases the potential attack surface. To prevent dangerous results from OT exploitation, OT operators and IT system administrators should ensure only the most imperative IT-OT connections are allowed, and that these are hardened to the greatest extent possible. An example of this type of threat includes recent adversarial exploitation of IT management software and its supply chain in the SolarWinds compromise with publicly documented impacts to OT, including U.S. critical infrastructure.

This guidance provides a pragmatic evaluation methodology to assess how to best improve OT and control system cybersecurity for mission success, to include understanding necessary resources for secure systems:

  • First, NSA encourages NSS, DoD, and DIB system owners, operators, and administrators to evaluate the value against risk and costs for enterprise IT to OT connectivity. While the safest OT system is one that is not connected to an IT network, mission critical connectivity may be required at times. Review the connections and disconnect those that are not truly needed to reduce the risk to OT systems and functions.
  • Next, NSA recommends taking steps to improve cybersecurity for OT networks when IT-OT connectivity is mission critical, as appropriate to their unique needs. For IT-OT connections deemed necessary, steps should be taken to mitigate risks of IT-OT exploitation pathways. These mitigations include fully managing all IT-OT connections, limiting access, actively monitoring and logging all access attempts, and cryptographically protecting remote access vectors.

Operational technology includes hardware and software that drives the operations of a given infrastructure environment, from an engine control unit in a modern vehicle to nationwide train transportation networks.

Every IT-OT connection creates an additional vector for potential OT exploitation that could impact and compromise mission and/or production. Performing a comprehensive risk analysis for all IT-OT interconnections and only allowing mission critical interconnections when they are properly protected will create an improved cybersecurity posture. By employing an appropriate risk analysis strategy, leadership and system owners and operators can make informed decisions to better manage OT networks while reducing the threats from and impact of exploitation and destructive cyber effects.

Source: NSA

The post NSA advises on operational tech security appeared first on Intelligence Community News.

]]>
29296