Skip to content
COOEY
ADVISORIES
123 advisories

CISA cyber & ICS and DC3 (DoD Cyber Crime Center / DCISE) threat products relevant to the DIB — each read by dex into a categorized card: the gist, why it matters, who's affected, and what to do.

Threat report CISA 2026-07-13

Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting ↗

Russian FSB cyber actors are exploiting poorly configured networking devices across critical sectors.

This advisory details ongoing Russian state-sponsored activity targeting misconfigured routers and vulnerable networking devices in critical infrastructure. It provides TTPs to help defenders understand and counter the threat.

▸ DO  Review and harden all networking devices for misconfigurations and apply available patches.

#state-sponsored#exploited-in-wild#mitigations#dib-sector
Threat report DC3 · DCISE

DIB Cyber Threats CY2025 Q4: October - December ↗

Quarterly threat landscape roundup for DIB covering Oct-Dec 2025.

This advisory summarizes the top cyber threats observed in Q4 2025, including nation-state campaigns, ransomware, and supply-chain risks. DIB organizations should review the linked PDF to align their security posture with current threat intelligence.

▸ DO  Download and review the full PDF report to update threat detection rules and security controls.

#threat-report#dib-sector#cyber-threats#q4-2025
Threat report DC3 · DCISE

DIB Cyber Threats CY2025 Q2: April - June ↗

Quarterly roundup of DIB cyber threats from April-June 2025.

This advisory summarizes the threat landscape for the second quarter of 2025, covering state-sponsored campaigns, malware, and supply-chain risks relevant to the defense industrial base. DIB readers should review the linked PDF for actionable intelligence on emerging threats and mitigation strategies.

▸ DO  Download and review the full PDF report to update threat detection rules and security controls.

#state-sponsored#mitigations#dib-sector#cyber-threats
Threat report DC3 · DCISE

DIB Cyber Threats CY2024 Q4: October - December ↗

Quarterly DIB Cyber Threats CY2024 Q4 report covers October-December threat landscape.

This is a periodic threat-landscape roundup for the fourth quarter of 2024, summarizing key cyber threats impacting the defense industrial base.

▸ DO  Download and review the full PDF report to assess current threat trends.

#threat-report#dib-sector#cyber-threats
Threat report DC3 · DCISE

DIB Cyber Threats CY2024 Q3: July - September ↗

Quarterly roundup of DIB cyber threats from July–September 2024.

This advisory summarizes the threat landscape for the third quarter of 2024, covering nation-state campaigns, malware, and supply-chain risks relevant to the defense industrial base. It serves as a reference for ongoing monitoring and control validation.

▸ DO  Review the linked PDF to update your threat intelligence and control validation schedule.

#threat-report#dib-sector#cyber-threats#quarterly-roundup
Threat report DC3 · DCISE

DIB Cyber Threats CY2022 Q3: July - September ↗

Quarterly DIB Cyber Threats report covering July-September 2022 threat landscape.

This is a periodic threat report summarizing cyber threats observed in the DIB sector during Q3 2022. DIB organizations should review the report to understand emerging threats and adjust their security posture accordingly.

▸ DO  Download and review the full PDF report to identify relevant threats and update security controls.

#threat-report#dib-sector#cyber-threats
Threat report DC3 · DCISE

DIB Cyber Threats CY2022 Q2: April - June ↗

Quarterly DIB Cyber Threats report covering April-June 2022 threat landscape.

This is a periodic threat report summarizing cyber threats observed in the DIB sector during Q2 2022. DIB organizations should review the report to understand emerging threats and adjust their security posture accordingly.

▸ DO  Download and review the full PDF report to identify relevant threats and update security controls.

#threat-report#dib-sector#quarterly#cyber-threats
Threat report DC3 · DCISE

DIB Cyber Threats CY2022 Q1: January - March ↗

Quarterly DIB Cyber Threats report covering January-March 2022 threat landscape.

This is a periodic threat report summarizing cyber threats observed in the first quarter of 2022. DIB organizations should review the full PDF to understand emerging threats and adjust their security posture accordingly.

▸ DO  Download and review the full PDF report to identify relevant threats.

#threat-report#dib-sector#cyber-threats
Threat report DC3 · DCISE

DIB Cyber Threats CY2021 Q4: October - December ↗

Quarterly roundup of DIB cyber threats from Oct-Dec 2021.

This advisory summarizes the threat landscape for the defense industrial base during Q4 2021, covering nation-state campaigns, malware, and supply-chain risks. DIB readers should review the linked PDF for specific indicators and mitigation guidance relevant to their systems.

▸ DO  Download and review the full PDF report to update threat-hunting rules and patch management schedules.

#state-sponsored#mitigations#dib-sector#threat-report
Threat report DC3 · DCISE

DIB Cyber Threats CY2021 Q3: July - September ↗

Quarterly DIB Cyber Threats report covering July-September 2021 threat landscape.

This is a periodic threat report summarizing cyber threats observed in the DIB sector during Q3 2021. DIB organizations should review the report to understand emerging threats and adjust their security posture accordingly.

▸ DO  Download and review the full PDF report to identify relevant threats and update security controls.

#threat-report#dib-sector#cyber-threats
Threat report DC3 · DCISE

DIB Cyber Threats CY2021 Q2: April - June ↗

Quarterly DIB Cyber Threats report covering April-June 2021 threat landscape.

This is a periodic threat report summarizing cyber threats observed in the DIB sector during Q2 2021. DIB organizations should review the report to understand emerging threats and adjust their security posture accordingly.

▸ DO  Download and review the full PDF report to identify relevant threats and update security controls.

#threat-report#dib-sector#quarterly#cyber-threats
Threat report DC3 · DCISE

DIB Cyber Threats CY2021 Q1: January - March ↗

Quarterly DIB Cyber Threats report covering January-March 2021 threat landscape.

This is a periodic threat report summarizing cyber threats observed in the first quarter of 2021. DIB organizations should review the linked PDF to understand the threat landscape and adjust their security posture accordingly.

▸ DO  Download and review the full PDF report to identify relevant threats and update security controls.

#threat-report#dib-sector#quarterly#cyber-threats
Threat report DC3 · DCISE

DIB Cyber Threats CY2025 Q3: July - September ↗

Quarterly DIB cyber threat landscape roundup covering July–September 2025.

This advisory summarizes the threat environment for the third quarter of 2025, including state-sponsored and opportunistic campaigns targeting defense-industrial-base systems. DIB readers should review the linked PDF to identify emerging threats and update their security posture accordingly.

▸ DO  Download and review the full PDF report to assess current threats and update security controls.

#threat-report#dib-sector#cyber-threats#quarterly-review
Threat report DC3 · DCISE

DIB Cyber Threats CY2025 Q1: January - March ↗

Quarterly DIB cyber threat landscape roundup for Jan-Mar 2025

This advisory summarizes key threats observed in Q1 2025 and provides context for DIB organizations to assess risk. It is a periodic report covering the threat environment rather than a specific incident or vulnerability.

▸ DO  Review the linked PDF to identify emerging threats and update security controls accordingly

#threat-report#dib-sector#cyber-threats
Threat report DC3 · DCISE

DIB Cyber Threats CY2024 Q2: April - June ↗

Quarterly roundup of DIB cyber threats from April-June 2024.

This advisory summarizes the threat landscape for defense-industrial-base organizations during Q2 2024. It covers key trends and activities relevant to DIB security posture.

▸ DO  Download and review the full PDF report to update your threat intelligence and risk assessments.

#threat-report#dib-sector#cyber-threats
Threat report DC3 · DCISE

DIB Cyber Threats CY2024 Q1: January - March ↗

Quarterly DIB cyber threat landscape roundup covering January-March 2024.

This advisory summarizes key threats observed in the first quarter of 2024, including nation-state campaigns, malware, and supply-chain risks relevant to the defense industrial base. It serves as a reference for ongoing threat intelligence and risk assessment.

▸ DO  Review the linked PDF for sector-specific threat trends and update security controls accordingly.

#state-sponsored#threat-report#dib-sector#cyber-threats
Threat report DC3 · DCISE

DIB Cyber Threats CY2023 Q4: October - December ↗

Quarterly roundup of DIB cyber threats from Oct-Dec 2023.

This advisory summarizes the threat landscape for the fourth quarter of 2023, covering nation-state campaigns, malware, and supply-chain risks relevant to the defense industrial base. It serves as a reference for ongoing threat intelligence and risk assessment.

▸ DO  Review the linked PDF for specific threat indicators and update security controls accordingly.

#threat-report#dib-sector#cyber-threats
Threat report DC3 · DCISE

DIB Cyber Threats CY2023 Q3: July - September ↗

Quarterly DIB cyber threat landscape roundup covering July–September 2023.

This advisory summarizes the threat environment for the third quarter of 2023, including active campaigns, indicators of compromise, and emerging risks relevant to the defense industrial base. It serves as a reference for ongoing threat monitoring and control validation.

▸ DO  Review the linked PDF for sector-specific threats and update detection rules accordingly.

#threat-report#dib-sector#cyber-threats#quarterly-review
Threat report DC3 · DCISE

DIB Cyber Threats CY2023 Q2: April - June ↗

Quarterly DIB cyber threat landscape roundup covering April-June 2023.

This advisory summarizes key threats observed in the second quarter of 2023, including nation-state campaigns, malware, and supply-chain risks targeting the defense industrial base. DIB organizations should review the full PDF for specific threat actor tactics and mitigation guidance.

▸ DO  Download and review the full PDF report to update threat intelligence feeds and review relevant controls.

#state-sponsored#mitigations#dib-sector#quarterly-roundup
Threat report DC3 · DCISE

DIB Cyber Threats CY2023 Q1: January - March ↗

Quarterly DIB cyber threat landscape roundup covering January-March 2023.

This advisory summarizes the top cyber threats observed in the first quarter of 2023, including state-sponsored campaigns and supply chain risks relevant to the defense industrial base. DIB organizations should review the full PDF for specific threat actor tactics and mitigation guidance.

▸ DO  Download and review the full PDF report to update threat intelligence feeds and security controls.

#state-sponsored#threat-report#dib-sector#cyber-threats
Vulnerability CISA 2026-07-10

CISA Adds Two Known Exploited Vulnerabilities to Catalog ↗

CISA added two new CVEs to the KEV Catalog requiring urgent patching on exposed assets.

CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa) allow unrestricted file uploads with dangerous types, enabling remote code execution. BOD 26-04 mandates prioritizing remediation of these KEV vulnerabilities on publicly exposed assets.

AFFECTEDiCagendaBalbooa

▸ DO  Prioritize patching iCagenda and Balbooa on exposed assets per BOD 26-04.

#patch-available#exploited-in-wild#vulnerability#federal-enterprise
Vulnerability CISA ICS 2026-07-09

Schneider Electric PowerChute Serial Shutdown ↗

Schneider Electric PowerChute Serial Shutdown <=1.4 has critical path traversal and injection flaws enabling file overwrite and credential reset.

Successful exploitation could allow attackers to overwrite critical files, forge logs, gain unauthorized access, or trigger DoS. This affects Schneider Electric PowerChute Serial Shutdown <=1.4 and impacts sectors including Communications, Critical Manufacturing, Energy, Healthcare, IT, and Transportation.

AFFECTEDSchneider Electric PowerChute Serial ShutdownPowerChute Serial Shutdown <=1.4

▸ DO  Patch Schneider Electric PowerChute Serial Shutdown to version >1.4 immediately.

#patch-available#vulnerability#critical-infrastructure#file-overwrite#credential-theft
Vulnerability CISA ICS 2026-07-09

Schneider Electric Easergy MiCOM Px40 Series ↗

Schneider Electric Easergy MiCOM Px40 Series protection relays are vulnerable to unauthorized SNMP exposure of device identification.

Schneider Electric has identified a vulnerability in its Easergy MiCOM Px40 Series products that allows unauthorized exposure of basic device identification through the SNMP protocol. Failure to apply mitigations may risk unauthorized exposure of basic device identification through the SNMP protocol.

AFFECTEDSchneider ElectricEasergy MiCOM Px40 SeriesEasergy MiCOM P14xEasergy MiCOM P24xEasergy MiCOM P341Easergy MiCOM P342

▸ DO  Apply the Schneider Electric mitigations for the affected Easergy MiCOM Px40 Series versions immediately.

#vulnerability#snmp#iot#ot#patch-available#dib-sector
Vulnerability RCE CISA ICS 2026-07-09

OpenPLC v3 ↗

Authenticated attackers can write arbitrary files and execute code via OpenPLC v3's unvalidated file upload workflow.

OpenPLC v3 contains a critical vulnerability (CVE-2026-14480) allowing authenticated users to write arbitrary files and escalate to code execution via the legacy web UI. This affects critical infrastructure sectors including manufacturing, energy, and water utilities worldwide.

AFFECTEDOpenPLC v3

▸ DO  Patch OpenPLC v3 immediately and review file upload controls in legacy web UI.

#rce#patch-available#exploited-in-wild#critical-infrastructure#code-execution
Vulnerability RCE CISA ICS 2026-07-07

Siemens SINEC OS ↗

Siemens SINEC OS before V4.0 contains multiple critical vulnerabilities affecting RuggedCom RST2428P devices.

This advisory highlights multiple vulnerabilities in Siemens SINEC OS prior to version 4.0, including buffer overflows and authentication bypasses. DIB organizations should update affected RuggedCom RST2428P devices to the latest version immediately.

AFFECTEDSiemens SINEC OSRuggedCom RST2428P

▸ DO  Update Siemens SINEC OS to version 4.0 or later on affected RuggedCom RST2428P devices.

#rce#vulnerability#patch-available#ics-ot#dib-sector
Vulnerability RCE CISA ICS 2026-07-07

Siemens Mendix Studio Pro ↗

Siemens Mendix Studio Pro versions prior to 11.12 have a file parsing vulnerability enabling arbitrary code execution during build pipelines.

This advisory details a critical vulnerability in Siemens Mendix Studio Pro where specially crafted malicious projects can trigger arbitrary code execution in the context of the user. Siemens has released patches for several affected versions and recommends immediate updates, while also advising countermeasures for products where fixes are not yet available.

AFFECTEDSiemens Mendix Studio Pro 10.11Siemens Mendix Studio Pro 10.12Siemens Mendix Studio Pro 10.13Siemens Mendix Studio Pro 10.14Siemens Mendix Studio Pro 10.15Siemens Mendix Studio Pro 10.16

▸ DO  Update Siemens Mendix Studio Pro to the latest patched version or implement compensating controls.

#rce#patch-available#exploited-in-wild#dib-sector#siemens#file-parsing
Vulnerability RCE CISA ICS 2026-07-07

Labcenter Proteus 9 ↗

Labcenter Proteus 9.1_SP4_Build_42914 has critical out-of-bounds write and buffer overflow flaws enabling arbitrary code execution.

Exploitation could disclose information or allow arbitrary code execution on affected Labcenter Proteus 9 installations. DIB organizations must patch immediately to prevent remote code execution.

AFFECTEDLabcenter Proteus 9.1_SP4_Build_42914

▸ DO  Upgrade to Labcenter Proteus 9.2 SPO immediately.

#rce#patch-available#exploited-in-wild#vulnerability
Vulnerability CISA ICS 2026-07-07

Hydro-Québec Le Circuit Electrique charging station backend ↗

Hydro-Québec charging station backend vulnerabilities allow unauthenticated websocket access and privilege escalation.

Exploitation of these flaws in Hydro-Québec Le Circuit Electrique charging station backend could lead to privilege escalation or denial-of-service attacks. Hydro-Québec has updated most stations to disable OCPP and implemented authentication for remaining systems.

AFFECTEDHydro-Québec Le Circuit Electrique charging station backend

▸ DO  Review and patch Hydro-Québec Le Circuit Electrique charging station backend systems to disable OCPP or implement authentication.

#vulnerability#patch-available#ics-ot#critical-infrastructure
◀ PREV PAGE 03 / 04 NEXT ▶