✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
CISA Highlights Four Actively Exploited Vulnerabilities in February 2026
In February 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. These vulnerabilities include CVE-2019-19006 and CVE-2025-64328 in Sangoma FreePBX, CVE-2021-39935 in GitLab Community and Enterprise Editions, and CVE-2025-40551 in SolarWinds Web Help Desk. The vulnerabilities range from improper authentication and OS command injection to server-side request forgery and deserialization of untrusted data, posing significant risks to affected systems. The inclusion of these vulnerabilities in the KEV Catalog underscores the persistent threat posed by unpatched software. Organizations are urged to prioritize remediation efforts to mitigate potential exploitation, as these vulnerabilities are actively targeted by malicious actors.
5 months ago
Kill Chain
Critical Vulnerability in Mitsubishi Electric's FREQSHIP-mini: CVE-2025-10314
In February 2026, Mitsubishi Electric disclosed a critical vulnerability (CVE-2025-10314) in its FREQSHIP-mini for Windows software, versions 8.0.0 to 8.0.2. The flaw arises from incorrect default permissions during installation, allowing local attackers to replace service executables or DLLs with malicious files. Exploiting this vulnerability enables arbitrary code execution with SYSTEM privileges, potentially leading to unauthorized access, data manipulation, or denial-of-service conditions. This vulnerability is particularly concerning for critical infrastructure sectors, including manufacturing and energy, where FREQSHIP-mini is commonly deployed. Organizations are urged to update to version 8.1.0 or later and implement recommended mitigation measures to prevent exploitation. ([jvn.jp](https://jvn.jp/en/jp/JVN64883963/?utm_source=openai))
5 months ago
Kill Chain
Unauthenticated API Leads to OAuth Token Exposure in 2025
In April 2025, a critical security vulnerability was discovered during a bug bounty program hosted by YesWeHack. An unauthenticated API endpoint exposed OAuth client credentials, allowing unauthorized access to sensitive personal and business data. This misconfiguration enabled attackers to impersonate trusted applications and retrieve confidential information without any authentication barriers. The flaw was promptly reported and addressed, mitigating potential exploitation. ([cyberpress.org](https://cyberpress.org/oauth-misconfiguration-enables-researchers-to-access-sensitive-data/?utm_source=openai)) This incident underscores the importance of securing API endpoints and properly managing OAuth credentials. As organizations increasingly rely on APIs for business operations, ensuring robust authentication and authorization mechanisms is crucial to prevent unauthorized data access and potential breaches.
5 months ago
Kill Chain
XWorm Malware Resurgence in 2025: Advanced Threats Unveiled
In mid-2025, cybersecurity researchers identified a resurgence of the XWorm Remote Access Trojan (RAT), notably with the release of version 6.0. This variant introduced advanced plugins, enhanced persistence mechanisms, and a ransomware module, significantly increasing its threat level. Attackers distributed XWorm V6 through sophisticated phishing campaigns, utilizing malicious JavaScript droppers that executed PowerShell scripts to deliver injector DLLs. The malware's modular design allowed for extensive data theft, system control, and file encryption, posing substantial risks to organizations across various sectors. The re-emergence of XWorm underscores the evolving nature of cyber threats, highlighting the necessity for organizations to adopt proactive and adaptive cybersecurity measures. The malware's advanced evasion techniques and modular capabilities reflect a broader trend of increasingly sophisticated attack vectors, emphasizing the importance of continuous monitoring, employee training, and robust security protocols to mitigate such threats.
5 months ago
Kill Chain
Critical Zero-Day Vulnerabilities in Ivanti EPMM Exploited: Immediate Action Required
In January 2026, Ivanti disclosed two critical zero-day vulnerabilities, CVE-2026-1281 and CVE-2026-1340, in its Endpoint Manager Mobile (EPMM) software. Both vulnerabilities, with a CVSS score of 9.8, allow unauthenticated remote code execution. Prior to disclosure, a limited number of customers were exploited, enabling attackers to execute arbitrary commands, access sensitive data, and potentially establish persistence through web shells. Ivanti released interim patches and plans a permanent fix in version 12.8.0.0. Organizations are urged to apply patches promptly and review logs for signs of compromise. ([cyberscoop.com](https://cyberscoop.com/ivanti-endpoint-manager-mobile-zero-day-vulnerabilities-exploit/?utm_source=openai)) This incident underscores the persistent targeting of network edge devices by threat actors, highlighting the critical need for timely patch management and vigilant monitoring of security advisories to mitigate risks associated with zero-day vulnerabilities.
5 months ago
Kill Chain
SolarWinds 2026 Unauthenticated RCE Vulnerability: Immediate Action Required
In January 2026, a critical vulnerability (CVE-2025-40551) was discovered in SolarWinds Web Help Desk, allowing unauthenticated remote code execution due to untrusted data deserialization. This flaw enables attackers to execute arbitrary commands on affected systems without authentication, posing significant risks to organizations using this software. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-flags-critical-solarwinds-rce-flaw-as-actively-exploited/?utm_source=openai)) The exploitation of this vulnerability underscores the persistent threat posed by unpatched software vulnerabilities, emphasizing the need for organizations to maintain rigorous patch management practices to safeguard against such attacks.
5 months ago
Kill Chain
Notepad++ Supply Chain Attack: Lessons Learned from the 2025 Breach
Between June and December 2025, the Notepad++ text editor's update infrastructure was compromised by the Chinese state-sponsored hacking group Lotus Blossom. The attackers exploited vulnerabilities at the hosting provider level, redirecting update requests from targeted users to malicious servers. This allowed them to deliver a custom backdoor named Chrysalis, enabling unauthorized access to users' systems. The breach was addressed in December 2025 with the release of Notepad++ version 8.8.9, which enhanced update verification processes. ([thehackernews.com](https://thehackernews.com/2026/02/notepad-hosting-breach-attributed-to.html?utm_source=openai)) This incident underscores the growing threat of supply chain attacks, where trusted software updates are manipulated to distribute malware. Organizations must prioritize securing their software supply chains and implement robust verification mechanisms to prevent similar breaches.
5 months ago
Kill Chain
Citrix NetScaler Reconnaissance Campaign Highlights Evolving Attacker Tactics
Between January 28 and February 2, 2026, a coordinated reconnaissance campaign targeted Citrix NetScaler infrastructure, utilizing over 63,000 distinct IP addresses to conduct more than 111,000 scanning sessions. Approximately 64% of this traffic originated from residential proxies, allowing attackers to masquerade as legitimate users and evade traditional security measures. The primary focus was on identifying exposed Citrix login panels and enumerating product versions, indicating a systematic effort to map vulnerable systems for potential exploitation. This incident underscores a growing trend where attackers leverage residential proxies to conduct large-scale reconnaissance, complicating detection efforts. The specific targeting of Citrix NetScaler devices suggests a heightened interest in exploiting known vulnerabilities within these systems, emphasizing the need for organizations to implement robust monitoring and timely patching strategies to mitigate such threats.
5 months ago
Kill Chain
APT28's Operation Neusploit: Exploiting Microsoft Office Vulnerability CVE-2026-21509
In January 2026, the Russian state-sponsored threat actor APT28 launched 'Operation Neusploit,' targeting users in Ukraine, Slovakia, and Romania. The group exploited CVE-2026-21509, a zero-day vulnerability in Microsoft Office, by distributing malicious RTF documents via phishing emails. These documents, when opened, executed a multi-stage infection chain deploying backdoors like MiniDoor and PixyNetLoader, enabling email theft and persistent access to compromised systems. Microsoft released an emergency patch on January 26, 2026, but exploitation continued until at least January 29. This incident underscores the rapid weaponization of newly disclosed vulnerabilities by sophisticated threat actors, emphasizing the need for immediate patching and heightened vigilance against phishing campaigns.
5 months ago
Kill Chain
Notepad++ 2025 Supply Chain Attack: A Wake-Up Call for Software Security
Between June and December 2025, state-sponsored attackers compromised the update infrastructure of Notepad++, a widely used text editor, by infiltrating its hosting provider. This allowed them to intercept and redirect update requests, delivering malicious executables to selectively targeted users. The attackers employed multiple infection chains, frequently altering their command-and-control infrastructure and payloads, which included reconnaissance tools and backdoors. The campaign primarily targeted organizations in East and Southeast Asia, including government and financial institutions, as well as IT service providers. The compromise was discovered in early 2026, leading to a public disclosure on February 2, 2026. In response, Notepad++ migrated to a new hosting provider and enhanced its update verification mechanisms to prevent similar attacks in the future. This incident underscores the growing sophistication of supply chain attacks, where adversaries exploit trusted software distribution channels to infiltrate targeted systems. Organizations are urged to scrutinize their software supply chains and implement robust verification processes to mitigate such risks.
5 months ago
Kill Chain
AI-Driven AWS Breach: Lessons from the 2025 Incident
In November 2025, a sophisticated AI-assisted attack compromised an AWS environment within eight minutes. The attacker exploited publicly accessible S3 buckets containing valid credentials, enabling rapid escalation to administrative privileges. This breach underscores the critical need for stringent access controls and continuous monitoring in cloud infrastructures. The incident highlights a growing trend of AI-driven cyberattacks that leverage automation for swift and efficient exploitation. Organizations must adapt their security strategies to address these evolving threats, emphasizing proactive defense mechanisms and regular security audits.
5 months ago
Kill Chain
macOS Infostealer Campaigns of 2025: Understanding the Threat Landscape
In 2025, a series of sophisticated infostealer campaigns targeted macOS users, exploiting social engineering tactics and trusted platforms to distribute malware. Attackers utilized deceptive websites, fake software installers, and malicious advertisements to deliver infostealers like Atomic macOS Stealer (AMOS), DigitStealer, and MacSync. These malware variants harvested sensitive data, including browser credentials, cryptocurrency wallets, and developer secrets, leading to significant security breaches and financial losses. The increasing prevalence of cross-platform infostealers underscores a critical shift in cyber threats, emphasizing the need for enhanced security measures across all operating systems. Organizations must remain vigilant against evolving tactics, such as the abuse of legitimate platforms and the use of fileless execution methods, to effectively mitigate these risks.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports