✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
APT37's Ruby Jumper Campaign: A New Threat to Air-Gapped Networks
In December 2025, the North Korean state-sponsored group APT37, also known as ScarCruft, launched the 'Ruby Jumper' campaign targeting air-gapped networks. The attack began with victims opening malicious Windows shortcut (LNK) files, which executed PowerShell scripts to deploy a series of malware tools: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, and FOOTWINE. These tools facilitated initial infection, established command-and-control via Zoho WorkDrive, and enabled lateral movement through removable media, ultimately compromising isolated systems. The campaign underscores the evolving tactics of APT37 in breaching highly secure environments. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/apt37-hackers-use-new-malware-to-breach-air-gapped-networks/?utm_source=openai)) This incident highlights a significant advancement in cyber-espionage techniques, demonstrating the capability to infiltrate air-gapped systems. Organizations with critical infrastructure should reassess their security protocols to mitigate such sophisticated threats.
5 months ago
Kill Chain
ScarCruft's 'Ruby Jumper' Campaign: A New Era in Air-Gapped Network Breaches
In December 2025, the North Korean state-sponsored group ScarCruft (APT37) launched the 'Ruby Jumper' campaign, deploying sophisticated malware to infiltrate air-gapped networks. The attack began with malicious LNK files that, when executed, initiated a multi-stage infection chain. This chain utilized Zoho WorkDrive for command-and-control communications and leveraged removable media to bridge air-gapped systems, enabling data exfiltration and command execution. The campaign introduced new malware tools, including RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, and FOOTWINE, each designed to facilitate various stages of the attack, from initial compromise to surveillance and data theft. ([thehackernews.com](https://thehackernews.com/2026/02/scarcruft-uses-zoho-workdrive-and-usb.html?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors in targeting isolated networks, highlighting the need for enhanced security measures to protect sensitive environments. The use of legitimate cloud services for C2 communications and the exploitation of removable media to breach air-gapped systems represent significant advancements in cyber-espionage techniques, posing increased risks to critical infrastructure and sensitive data repositories. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/apt37-hackers-use-new-malware-to-breach-air-gapped-networks/?utm_source=openai))
5 months ago
Kill Chain
Cisco SD-WAN Zero-Day Exploited Since 2023
In February 2026, Cisco disclosed a critical zero-day vulnerability (CVE-2026-20127) in its Catalyst SD-WAN Controller and Manager, which had been actively exploited since at least 2023. The flaw allowed unauthenticated remote attackers to bypass authentication mechanisms, granting them high-privileged access to manipulate network configurations via the NETCONF protocol. This exploitation enabled the addition of rogue peers and potential disruption of network operations. ([thehackernews.com](https://thehackernews.com/2026/02/cisco-sd-wan-zero-day-cve-2026-20127.html?utm_source=openai)) The incident underscores the persistent targeting of network infrastructure by sophisticated threat actors, emphasizing the need for organizations to prioritize timely patching and robust security measures to protect critical systems. ([thehackernews.com](https://thehackernews.com/2026/02/cisco-sd-wan-zero-day-cve-2026-20127.html?utm_source=openai))
5 months ago
Kill Chain
Critical Vulnerability in Pelco Sarix Pro 3 Series IP Cameras: Immediate Action Required
In February 2026, a critical authentication bypass vulnerability (CVE-2026-1241) was identified in Pelco, Inc.'s Sarix Pro 3 Series IP Cameras, affecting firmware versions up to 02.52. This flaw allows unauthorized access to the cameras' web management interface, enabling attackers to view live video streams and potentially manipulate device settings without proper authentication. The vulnerability poses significant privacy risks and operational challenges for organizations utilizing these surveillance systems. The incident underscores the growing threat landscape targeting IoT devices, particularly in critical infrastructure sectors such as commercial facilities, defense, energy, healthcare, and transportation. As cyber adversaries increasingly exploit vulnerabilities in connected devices, it is imperative for organizations to prioritize regular firmware updates, implement robust access controls, and conduct comprehensive security assessments to mitigate potential risks.
5 months ago
Kill Chain
FedEx Phishing Scam Unleashes XWorm Malware
In February 2026, a sophisticated phishing campaign impersonated FedEx to distribute the XWorm malware. Victims received emails claiming undelivered packages, prompting them to open malicious attachments. These attachments executed scripts that installed XWorm, a Remote Access Trojan (RAT) capable of stealing sensitive information, hijacking accounts, and executing commands remotely. The malware utilized advanced techniques like process injection and encrypted communication to evade detection. This incident underscores the evolving nature of phishing attacks, which now employ multi-stage payloads and sophisticated evasion tactics. Organizations must enhance their email security measures and educate employees on recognizing such deceptive schemes to mitigate the risk of similar threats.
5 months ago
Kill Chain
GCP Cloud SQL Vulnerability 2023: A Wake-Up Call for Cloud Security
In April 2023, a critical security vulnerability was discovered in Google Cloud Platform's (GCP) Cloud SQL service, potentially allowing unauthorized access to sensitive data. The flaw enabled attackers to escalate privileges from a basic user to a sysadmin role, granting access to internal GCP data, customer information, secrets, sensitive files, and passwords. By exploiting this misconfiguration, attackers could gain full control over the database server, posing significant risks to data integrity and confidentiality. Google addressed the issue promptly upon disclosure, mitigating the potential impact on affected systems. This incident underscores the persistent challenges associated with cloud service misconfigurations and the importance of continuous monitoring and timely remediation. As cloud adoption accelerates, organizations must prioritize robust security practices to prevent similar vulnerabilities from being exploited in the future.
5 months ago
Kill Chain
Iran's 2026 Internet Blackout: A New Era of Digital Repression
In January 2026, the Iranian government imposed a comprehensive internet blackout amid escalating nationwide protests. This shutdown disrupted all forms of digital communication, including mobile networks, landlines, and even satellite services like Starlink. The blackout aimed to suppress the coordination of protests and conceal human rights violations. Concurrently, Iran implemented a two-tiered internet system, granting unrestricted access to government officials and loyalists via 'white SIM cards,' while the general populace faced severe restrictions. This strategy effectively isolated citizens, preventing both internal coordination and external information dissemination. The incident underscores a growing trend among authoritarian regimes to leverage internet control as a tool for social suppression. The international community has condemned these actions, emphasizing the need for global efforts to uphold internet freedom and human rights.
5 months ago
Kill Chain
Google API Keys Expose Gemini AI Data in 2026
In February 2026, security researchers discovered that previously non-sensitive Google API keys embedded in client-side code could be exploited to access Google's Gemini AI services, leading to potential unauthorized data access and financial implications. This vulnerability arose when developers enabled the Gemini API in existing projects, inadvertently granting these exposed keys access to sensitive endpoints without any alerts or notifications. The issue affected numerous organizations, including major financial institutions and even Google's own infrastructure, with over 2,800 live API keys found publicly exposed. In response, Google implemented measures to detect and block leaked API keys attempting to access the Gemini API and advised developers to audit and rotate any exposed keys immediately. This incident underscores the critical importance of secure API key management and the need for developers to regularly review and update their security practices to prevent unauthorized access and potential data breaches.
5 months ago
Kill Chain
Trend Micro Apex One 2026 Critical RCE Vulnerabilities
In February 2026, Trend Micro identified and patched two critical vulnerabilities (CVE-2025-71210 and CVE-2025-71211) in its Apex One endpoint security platform. These flaws, both with a CVSS score of 9.8, allowed unauthenticated remote attackers to execute arbitrary code via path traversal weaknesses in the management console. Exploitation required access to the console, posing significant risks to organizations with externally exposed management interfaces. Trend Micro released Critical Patch Build 14136 to address these issues and advised customers to update promptly. This incident underscores the persistent threat posed by vulnerabilities in security management consoles, emphasizing the need for organizations to implement stringent access controls and maintain up-to-date systems to mitigate potential exploitation.
5 months ago
Kill Chain
Harvest Now, Decrypt Later: The Quantum Computing Threat
The 'Harvest Now, Decrypt Later' (HNDL) strategy involves adversaries collecting encrypted data today with the intention of decrypting it in the future when quantum computers become capable of breaking current cryptographic algorithms. This approach poses a significant threat to sensitive information with long-term confidentiality requirements, such as financial records, healthcare data, and intellectual property. Organizations must proactively transition to post-quantum cryptographic (PQC) algorithms to safeguard their data against future quantum-enabled decryption attacks. ([prnewswire.com](https://www.prnewswire.com/news-releases/harvest-now-decrypt-later-attacks-pose-a-security-concern-as-organizations-consider-implications-of-quantum-computing-301628445.html?utm_source=openai)) The urgency to address HNDL threats is underscored by the rapid advancements in quantum computing. Experts predict that cryptographically relevant quantum computers could emerge within the next decade, rendering existing encryption methods obsolete. ([docs.paloaltonetworks.com](https://docs.paloaltonetworks.com/network-security/quantum-security/administration/quantum-security-concepts/the-quantum-computing-threat?utm_source=openai))
5 months ago
Kill Chain
UAT-10027's Dohdoor Backdoor: A New Threat to U.S. Education and Healthcare
In December 2025, the threat actor group UAT-10027 initiated a sophisticated cyber campaign targeting the U.S. education and healthcare sectors. The attackers employed a novel backdoor named Dohdoor, which utilizes DNS-over-HTTPS (DoH) for covert command-and-control communications, effectively evading traditional network monitoring tools. The initial infection vector is suspected to involve phishing emails that execute PowerShell scripts, leading to the download and execution of malicious DLLs via DLL side-loading techniques. These DLLs facilitate the deployment of additional payloads, such as Cobalt Strike Beacons, directly into the memory of compromised systems. The campaign's use of legitimate Windows processes and encrypted communications poses significant challenges for detection and mitigation. ([thehackernews.com](https://thehackernews.com/2026/02/uat-10027-targets-us-education-and.html?utm_source=openai)) This incident underscores a growing trend of advanced persistent threats (APTs) leveraging encrypted communication channels like DoH to conceal malicious activities. The targeting of critical sectors such as education and healthcare highlights the urgent need for enhanced cybersecurity measures and vigilance against sophisticated attack vectors. ([thehackernews.com](https://thehackernews.com/2026/02/uat-10027-targets-us-education-and.html?utm_source=openai))
5 months ago
Kill Chain
FBI Seizes RAMP Cybercrime Forum, Disrupting Ransomware Operations
In January 2026, the FBI, in coordination with the U.S. Attorney’s Office for the Southern District of Florida and the Department of Justice’s Computer Crime and Intellectual Property Section, seized the RAMP cybercrime forum. Established in July 2021, RAMP was a Russian-language platform that openly permitted ransomware-as-a-service (RaaS) operations, serving as a hub for ransomware groups like LockBit, ALPHV/BlackCat, and RansomHub. The forum facilitated the promotion of RaaS activities, recruitment of affiliates, and trading of initial network access. The seizure disrupted a significant coordination point for ransomware operators, potentially leading to a short-term decline in ransomware attacks. However, the long-term impact remains uncertain as cybercriminals may migrate to alternative platforms or establish new forums. Law enforcement's access to RAMP's user data could lead to further investigations and arrests, underscoring the ongoing efforts to combat cybercrime.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports