Cyber threat bulletin: Iranian cyber threat to Canada from Israel-Iran conflict – Canadian Centre for Cyber Security

Cyber threat bulletin: Iranian cyber threat to Canada from Israel-Iran conflict – Canadian Centre for Cyber Security Summary On 13 June 2025 Israel launched strikes against Iran and on 22 June the U.S. carried out precision airstrikes on Iranian nuclear facilities. U.S. agencies warned of potential retaliatory cyber activity by Iranian-affiliated actors targeting U.S. critical […]

Read More →

Canadian Common Criteria program requirements and procedures for testing laboratories – Canadian Centre for Cyber Security

Canadian Common Criteria program requirements and procedures for testing laboratories – Canadian Centre for Cyber Security Summary This Cyber Centre publication (effective 8 May 2025) supersedes the March 2023 version and sets out the requirements and procedures for commercial organisations to become and operate as approved Common Criteria testing laboratories within the Canadian Common Criteria […]

Read More →

Advisory on North Korean information technology (IT) workers

Advisory on North Korean information technology (IT) workers Summary The Royal Canadian Mounted Police, together with Public Safety Canada, Global Affairs Canada, FINTRAC and the Canadian Centre for Cyber Security, have issued an advisory warning Canadians and Canadian businesses about the risks of hiring IT workers deployed by the North Korean government (DPRK). These state-affiliated […]

Read More →

Joint cyber security advisory on Scattered Spider – Canadian Centre for Cyber Security

Joint cyber security advisory on Scattered Spider – Canadian Centre for Cyber Security Summary The Canadian Centre for Cyber Security, together with partners including the US FBI, CISA, the UK NCSC, the RCMP, the Australian Federal Police and ASD’s ACSC, has published a joint advisory on the Scattered Spider cyber‑criminal group. The advisory details recent […]

Read More →

Joint guidance on managing cryptographic keys and secrets – Canadian Centre for Cyber Security

Joint guidance on managing cryptographic keys and secrets – Canadian Centre for Cyber Security Summary The Canadian Centre for Cyber Security, together with the Australian Signals Directorate’s ACSC and international partners (Australia DISR, JPCERT/CC, Japan NCO, New Zealand NCSC, and the UK NCSC), has released joint guidance on managing cryptographic keys and secrets. The guidance […]

Read More →

Introduction to cloud computing (ITSAP.50.110) – Canadian Centre for Cyber Security

Introduction to cloud computing (ITSAP.50.110) – Canadian Centre for Cyber Security Summary This guidance from the Canadian Centre for Cyber Security gives an accessible introduction to cloud computing and why organisations are moving services to cloud service providers (CSPs). It defines cloud computing as the on-demand delivery of IT resources over the internet, explains how […]

Read More →

Security considerations for critical infrastructure (ITSAP.10.100) – Canadian Centre for Cyber Security

Security considerations for critical infrastructure (ITSAP.10.100) – Canadian Centre for Cyber Security Summary Published July 2025 as part of the Cyber Centre’s Awareness series, this guidance outlines key risks to Canada’s critical infrastructure (CI) and practical security measures CI operators should adopt. It describes CI sectors, explains how cyber attacks can cause service disruption, and […]

Read More →

Security considerations when developing and managing your website (ITSAP.60.005) – Canadian Centre for Cyber Security

Security considerations when developing and managing your website (ITSAP.60.005) – Canadian Centre for Cyber Security Summary The Canadian Centre for Cyber Security’s ITSAP.60.005 (July 2025) summarises common threats to websites and provides practical security and privacy measures to develop and manage web services securely. It covers injection attacks (SQL injection, XSS), cross-site request forgery (CSRF), […]

Read More →

Quick guide to email configuration (ITSAP.60.003) – Canadian Centre for Cyber Security

Quick guide to email configuration (ITSAP.60.003) – Canadian Centre for Cyber Security Summary This guidance from the Canadian Centre for Cyber Security outlines the core email configuration controls you should have in place to reduce spoofing, phishing and interception risks. It explains Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), Transport Layer Security (TLS) and […]

Read More →