Cybersecurity Advisories & Technical Guidance

NSA Leverages its elite technical capability to develop advisories and mitigations on evolving cybersecurity threats.

Browse or search our repository of advisories, info sheets, tech reports, and operational risk notices listed below. Some resources have access requirements.

For a subset of cybersecurity products focused on telework and general network security for end users, view our Telework and Mobile Security Guidance page here.

ImageTitlePublication Date
 DDD-190716-546-059.PDFAdvisory: Updated Guidance For Vulnerabilities Affecting Modern Processors (January 2019)1/25/2019
 DDD-190716-604-058.PDFAdvisory: Vulnerabilities Affecting Modern Processors (January 2018)1/4/2018
 COMPROMISED_PERSONAL_NETWORK_INDICATORS_AND_MITIGATIONS_20200914_FINAL.PDFCompromised Personal Network Indicators and Mitigations9/17/2020
 CSA_CHINESE_STATE-SPONSORED_CYBER_TTPS.PDFCSA: Chinese State Sponsored Cyber TTPs7/19/2021
 CSA: Conti Ransomware9/22/2021
 CSA_GRU_GLOBAL_BRUTE_FORCE_CAMPAIGN_UOO158036-21.PDFCSA: Russian GRU Global Brute Force Campaign7/1/2021
 CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDFCSA: Russian SVR Targets U.S. and Allied Networks4/15/2021
 CSA_STOP-MCA-AGAINST-OT_UOO13672321.PDFCSA: Stop Malicious Cyber Activity Against Connected Operational Technology4/29/2021
 CSI_DEPLOYING SECURE VVOIP SYSTEMS.PDFCSI: Deploying Secure Unified Communications/Voice and Video over IP Systems (Abridged) (June 2021)6/17/2021
 CSI_KEEPING_SAFE_ON_SOCIAL_MEDIA_20210806.PDFCSI: Keeping Safe on Social Media (August 2021 Update)8/6/2021
Page 3 of 10

Additional Documents

The following resources require use of a Federal/DoD Public Key Infrastructure (PKI), Personal Identity Verification (PIV) or Common Access Card (CAC) client certificate. Read more information about these access requirements.