Cybersecurity Threats

The CIS® and MS-ISAC® cybersecurity professionals analyze risks and alert members to current online security threats.

Timely updates when you need to take action

Subscribe to Advisories
Low
Guarded
Elevated
High
Severe

Explanation of the Current Alert Level of GUARDED

The alert level is the overall current threat level.

On March 26, the Cyber Threat Alert Level was evaluated and is remaining at Blue (Guarded) due to vulnerabilities in AMI, Veeam, and Google products. On March 20, the MS-ISAC released two advisories. The first advisory was for a vulnerability in AMI MegaRAC software that could allow for remote code execution. The second advisory was for a vulnerability in Veeam Backup and Replication that could allow for arbitrary code execution. On March 21, the MS-ISAC released an advisory for a vulnerability in Google Chrome that could allow for arbitrary code execution. On March 26, the MS-ISAC released an advisory for a vulnerability in Google Chrome that could allow for arbitrary code execution. Organizations and users are advised to update and apply all appropriate vendor security patches to vulnerable systems and to continue to update their antivirus signatures daily. Another line of defense includes user awareness training regarding the threats posed by attachments and hypertext links contained in emails especially from un-trusted sources.

Read more about our approach

Latest Advisory

A Vulnerability in CrushFTP Could Allow for Unauthorized Access
28 Mar 2025
A vulnerability has been discovered in CrushFTP, which could allow for unauthorized access. CrushFTP is a proprietary multi-protocol, multi-platf...
Read the details

 

Our MS-ISAC Advisories

Advisories Released (Last 12 Months)

MS-ISAC Advisories - Advisories Released
Monthly Advisories for September 2024

In Q3 2024, the Top 10 Malware observed via the MS-ISAC’s monitoring services changed moderately from the previous quarter. The downloader, SocGholish, continued to lead as the top malware, making up 42% of the list. Following SocGholish were the downloaders LandUpdate808 and ClearFake. This quarter marked the first time the MS-ISAC observed either of these downloaders in its quarterly Top 10 Malware list.

Top Malware Q3 2024
  1. SocGholish
  2. LandUpdate808
  3. ClearFake
  4. ZPHP
  5. Agent Tesla
  6. CoinMiner
  7. Arechclient2
  8. Mirai
  9. NanoCore
  10. Lumma Stealer
Take Control of Your Organization's Security
Security Operations Center

The information on this page is maintained by our Security Operations Center, which is part of MS-ISAC.

MS-ISAC: Multi-State Information Sharing & Analysis Center

Join MS-ISAC


Interested in a particular platform?

See our CIS Benchmarks for secure Platforms