NSA Cybersecurity Advisories & Guidance


NSA leverages its elite technical capability to develop advisories and mitigations on evolving cybersecurity threats.

Browse or search our repository of advisories, info sheets, tech reports, and operational risk notices listed below. Some resources have access requirements.

For a subset of cybersecurity products focused on telework and general network security for end users, view our Telework and Mobile Security Guidance page.

To read our complete series on protecting DoW microelectronics from adversary influence, view our DoW Microelectronics Guidance page.

ImageTitlePublication Date
 Joint CSA: #StopRansonware: Gunra RansomwareJoint CSA: #StopRansonware: Gunra Ransomware8/10/2026
 Joint CSA: China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed SystemsJoint CSA: China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems8/26/2026
 Joint CSA: Defending Against China-Nexus Covert Networks of Compromised DevicesJoint CSA: Defending Against China-Nexus Covert Networks of Compromised Devices4/23/2026
 Joint CSA: Improve Router Hygiene To Protect Against Russian State-Sponsored TargetsJoint CSA: Improve Router Hygiene To Protect Against Russian State-Sponsored Targets7/13/2026
 Joint CSA: Iranian-Affiliated Cyber Actors  Exploit Programmable Logic Controllers Across US Critical InfrastructureJoint CSA: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure7/22/2026
 Joint CSA: NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity MisconfigurationsJoint CSA: NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations10/5/2023
 Joint CSA: Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration SuiteJoint CSA: Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite7/23/2026
 Joint CSI: Careful Adoption of Agentic AI ServicesJoint CSI: Careful Adoption of Agentic AI Services4/30/2026
 Joint CSI: Establishing a Coordinated  Vulnerability Disclosure Program  to Work With Security ResearchersJoint CSI: Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers7/15/2026
 Joint CSI: Microsoft Exchange Server Security Best PracticesJoint CSI: Microsoft Exchange Server Security Best Practices10/30/2025
 Joint Guidance: A Shared Vision of Software Bill Of Materials For CybersecurityJoint Guidance: A Shared Vision of Software Bill Of Materials For Cybersecurity9/3/2025
 Network Device Integrity (NDI) MethodologyNetwork Device Integrity (NDI) Methodology2/23/2016
 Network Device Integrity (NDI) on Cisco IOS DevicesNetwork Device Integrity (NDI) on Cisco IOS Devices2/23/2016
 NSA 2023 Cybersecurity Year in ReviewNSA 2023 Cybersecurity Year in Review12/19/2023
 NSA Cybersecurity Year in Review 2022NSA Cybersecurity Year in Review 202212/15/2022
Page 17 of 19

Additional Documents

Some guidance is protected and requires use of a DoW Common Access Card (CAC) to access. Visit https://cyber.mil/nsa/cybersecurity-advisories-and-technical-guidance/ to access the following and other protected documents:

  • Avoid Dangers of Wildcard TLS Certificates and the ALPACA Technique (FOUO version)
  • Protecting VSAT Communications
  • Quantum Security of Symmetric Cryptography and Hash Functions: A Review
  • Securing AWS S3
  • Security Considerations for Office 365 Government Customers