Validated Containment Architectures are here. →Explore

Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2382 threat reports
Page 114 of 199

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Government Administration Threat Reports

Showing 13571368 / 2382 reports
Critical Zero-Day Vulnerabilities in Ivanti EPMM Exploited
Impact· CRITICAL

Critical Zero-Day Vulnerabilities in Ivanti EPMM Exploited

In January 2026, Ivanti disclosed two critical zero-day vulnerabilities in its Endpoint Manager Mobile (EPMM) software, identified as CVE-2026-1281 and CVE-2026-1340, each with a CVSS score of 9.8. These code injection flaws allow unauthenticated remote attackers to execute arbitrary code on affected systems, potentially leading to unauthorized access to sensitive data and system configurations. Ivanti confirmed active exploitation of these vulnerabilities in a limited number of customer environments at the time of disclosure. ([crn.com](https://www.crn.com/news/security/2026/ivanti-critical-mobile-management-vulnerabilities-seeing-exploitation?utm_source=openai)) The exploitation of these vulnerabilities underscores the persistent threat posed by zero-day attacks targeting enterprise management systems. Organizations are urged to apply the available patches promptly to mitigate the risk of unauthorized access and potential data breaches. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ivanti-warns-of-two-epmm-flaws-exploited-in-zero-day-attacks/?utm_source=openai))

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Sandworm's DynoWiper Targets Poland's Energy Sector in 2025 Cyberattack
Impact· LOW

Sandworm's DynoWiper Targets Poland's Energy Sector in 2025 Cyberattack

In late December 2025, Poland's energy infrastructure was targeted by a cyberattack involving a data-wiping malware named DynoWiper. The attack aimed to disrupt operations at two combined heat and power plants and several renewable energy facilities. ESET researchers attributed the attack to the Russian state-sponsored group Sandworm, noting similarities to previous incidents involving the group. Fortunately, the malware was intercepted before causing any substantial damage, and no operational disruptions were reported. ([welivesecurity.com](https://www.welivesecurity.com/en/eset-research/eset-research-sandworm-cyberattack-poland-power-grid-late-2025/?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors to critical infrastructure. The timing, coinciding with the tenth anniversary of Sandworm's first known assault on Ukraine’s power grid in 2015, highlights the group's continued focus on energy sector targets and disruptive operations. ([welivesecurity.com](https://www.welivesecurity.com/en/eset-research/eset-research-sandworm-cyberattack-poland-power-grid-late-2025/?utm_source=openai))

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Equifax 2017 Data Breach: Lessons in Cybersecurity
Impact· CRITICAL

Equifax 2017 Data Breach: Lessons in Cybersecurity

Between May and July 2017, Equifax, a major credit reporting agency, experienced a significant data breach due to unpatched vulnerabilities in their Apache Struts framework. Attackers exploited these weaknesses to access sensitive personal information, including names, Social Security numbers, birth dates, addresses, and, in some cases, driver's license numbers of approximately 147.9 million Americans. The breach also affected millions of individuals in the UK and Canada. Equifax discovered the intrusion on July 29, 2017, but did not publicly disclose it until September 7, 2017. The incident led to widespread criticism, legal actions, and regulatory scrutiny, culminating in a settlement of up to $700 million to address the fallout and implement corrective measures. ([en.wikipedia.org](https://en.wikipedia.org/wiki/2017_Equifax_data_breach?utm_source=openai)) This breach underscores the critical importance of timely software updates and robust cybersecurity practices. The exploitation of known vulnerabilities highlights the necessity for organizations to maintain vigilant patch management and comprehensive security protocols to protect sensitive consumer data.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft Announces Deprecation of NTLM Authentication Protocol
Impact· MEDIUM

Microsoft Announces Deprecation of NTLM Authentication Protocol

In June 2024, Microsoft announced the deprecation of the NTLM authentication protocol, ceasing its active development and urging organizations to transition to more secure alternatives like Kerberos. This decision was driven by NTLM's inherent security vulnerabilities, including susceptibility to relay attacks and lack of support for modern cryptographic methods. The deprecation process began in early 2025, with phased reductions in support throughout the year, aiming for complete removal by the end of 2027. Organizations relying on NTLM are advised to assess their authentication mechanisms and plan migrations to more secure protocols to mitigate potential security risks. ([threatdown.com](https://www.threatdown.com/blog/microsoft-calls-time-on-ntlm-so-should-you/?utm_source=openai)) The deprecation of NTLM underscores a broader industry shift towards enhancing authentication security. As cyber threats evolve, legacy protocols like NTLM become prime targets due to their known weaknesses. This move aligns with Microsoft's Secure Future Initiative, emphasizing the importance of adopting robust authentication methods to safeguard against emerging threats. ([microsoft.com](https://www.microsoft.com/en-us/msrc/blog/2024/12/mitigating-ntlm-relay-attacks-by-default?utm_source=openai))

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Ivanti EPMM Zero-Day Vulnerabilities Exploited in 2026
Impact· CRITICAL

Critical Ivanti EPMM Zero-Day Vulnerabilities Exploited in 2026

In January 2026, Ivanti disclosed two critical zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340) in its Endpoint Manager Mobile (EPMM) platform, both with a CVSS score of 9.8. These code injection flaws allow unauthenticated remote code execution, enabling attackers to gain full control over affected systems. Exploitation in the wild has been confirmed, with a limited number of customers compromised prior to disclosure. The vulnerabilities affect EPMM versions up to 12.7.0.0, and Ivanti has released RPM patches to address them. Organizations are urged to apply these patches immediately and monitor for signs of compromise. ([ivanti.com](https://www.ivanti.com/blog/january-2026-epmm-security-update?utm_source=openai)) The inclusion of CVE-2026-1281 in CISA's Known Exploited Vulnerabilities catalog underscores the severity and active exploitation of these flaws. This incident highlights the ongoing threat posed by zero-day vulnerabilities in widely used enterprise solutions, emphasizing the need for proactive vulnerability management and rapid response strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Unauthenticated RCE Vulnerability in SmarterMail (CVE-2026-24423) Discovered
Impact· CRITICAL

Critical Unauthenticated RCE Vulnerability in SmarterMail (CVE-2026-24423) Discovered

In January 2026, a critical unauthenticated remote code execution (RCE) vulnerability, identified as CVE-2026-24423, was discovered in SmarterTools SmarterMail versions prior to build 9511. This flaw resided in the ConnectToHub API method, allowing attackers to direct the SmarterMail server to a malicious HTTP server that delivers harmful OS commands, which the vulnerable application would then execute. The vulnerability was independently identified by multiple researchers, including those from VulnCheck and CODE WHITE GmbH. SmarterTools addressed this issue by releasing build 9511 on January 15, 2026, which patches the vulnerability. Organizations using affected versions are strongly advised to update to the latest build to mitigate potential exploitation risks. ([vulncheck.com](https://www.vulncheck.com/blog/smartermail-connecttohub-rce-cve-2026-24423?utm_source=openai)) The discovery of CVE-2026-24423 underscores the persistent threat posed by unauthenticated RCE vulnerabilities in widely used software. Such vulnerabilities can lead to complete system compromise, data exfiltration, and service disruption. The incident highlights the critical importance of timely software updates and vigilant monitoring of security advisories to protect organizational infrastructure from emerging threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
UAT-8099's Exploitation of IIS Servers in Asia Using BadIIS Malware
Impact· HIGH

UAT-8099's Exploitation of IIS Servers in Asia Using BadIIS Malware

Between late 2025 and early 2026, the China-linked threat actor UAT-8099 launched a campaign targeting vulnerable Internet Information Services (IIS) servers across Asia, with a particular focus on Thailand and Vietnam. The attackers exploited security vulnerabilities to gain initial access, deploying web shells and leveraging tools like GotoHTTP for remote control. They installed customized variants of the BadIIS malware to manipulate search engine optimization (SEO) rankings, redirecting users to malicious sites and exfiltrating sensitive data. This operation underscores the evolving tactics of cybercriminals in exploiting web server vulnerabilities for financial gain and data theft. Organizations are urged to strengthen their server defenses and monitor for signs of such sophisticated intrusions. ([thehackernews.com](https://thehackernews.com/2026/01/china-linked-uat-8099-targets-iis.html?utm_source=openai))

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Chinese APTs Target ASEAN Entities with Advanced Malware
Impact· HIGH

Chinese APTs Target ASEAN Entities with Advanced Malware

In early 2024, Chinese state-sponsored Advanced Persistent Threat (APT) groups, notably Stately Taurus (also known as Mustang Panda), launched sophisticated cyber-espionage campaigns targeting entities across ASEAN countries, including Myanmar, the Philippines, Japan, and Singapore. These operations coincided with the ASEAN-Australia Special Summit in March 2024, suggesting a strategic intent to gather intelligence during significant diplomatic events. The attackers employed advanced malware packages, such as PUBLOAD downloader, delivered through phishing emails containing malicious ZIP archives and screensaver executables. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/chinese-apts-target-asean-entities/?utm_source=openai)) This incident underscores the escalating cyber threats posed by state-sponsored actors in the Asia-Pacific region. The use of sophisticated malware and targeted phishing campaigns highlights the need for heightened cybersecurity measures, especially during high-profile events that may attract espionage activities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Salt Typhoon's 2024 Breach of U.S. Telecom Networks: A Wake-Up Call for Cybersecurity
Impact· LOW

Salt Typhoon's 2024 Breach of U.S. Telecom Networks: A Wake-Up Call for Cybersecurity

In 2024, the Chinese state-sponsored hacking group known as Salt Typhoon orchestrated a sophisticated cyber espionage campaign targeting major U.S. telecommunications companies, including AT&T, Verizon, and T-Mobile. By exploiting vulnerabilities in network devices and systems, the group gained unauthorized access to sensitive data such as call logs, text messages, and, in some instances, audio recordings. Notably, they infiltrated systems used for lawful wiretapping, posing significant national security concerns. The attackers employed advanced techniques, including 'living off the land' tactics, utilizing legitimate administrative tools to evade detection and maintain persistent access. This incident underscores the escalating threat posed by state-sponsored cyber actors to critical infrastructure. The breach highlights the necessity for robust cybersecurity measures and continuous monitoring to detect and mitigate such sophisticated intrusions. Organizations must prioritize the security of their network devices and systems to prevent similar attacks in the future.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Oracle WebLogic Server Proxy Plugin Vulnerability (CVE-2026-21962): What You Need to Know
Impact· CRITICAL

Oracle WebLogic Server Proxy Plugin Vulnerability (CVE-2026-21962): What You Need to Know

In January 2026, Oracle disclosed a critical vulnerability (CVE-2026-21962) affecting Oracle HTTP Server and WebLogic Server Proxy Plug-ins for both Apache HTTP Server and Microsoft IIS. This flaw allows unauthenticated remote attackers to bypass security controls, potentially gaining unauthorized access to backend WebLogic systems. Given that these proxy plugins often reside in DMZ environments, the exposure is significant. The vulnerability has a CVSS 3.1 Base Score of 10.0, indicating its high severity due to low attack complexity and the potential for substantial compromise. ([netspi.com](https://www.netspi.com/blog/executive-blog/vulnerability-management/oracle-weblogic-server-proxy-plugin-cve-2026-21962-overview-takeaways/?utm_source=openai)) The current relevance of this incident is underscored by the ease of exploitation and the critical nature of the affected systems. Organizations utilizing the impacted versions are urged to apply Oracle's Critical Patch Update immediately to mitigate the risk of unauthorized data access and potential system compromise. ([netspi.com](https://www.netspi.com/blog/executive-blog/vulnerability-management/oracle-weblogic-server-proxy-plugin-cve-2026-21962-overview-takeaways/?utm_source=openai))

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
TA584's Escalation: Deploying Tsundere Bot and XWorm in Ransomware Campaigns
Impact· HIGH

TA584's Escalation: Deploying Tsundere Bot and XWorm in Ransomware Campaigns

In late 2025, the threat actor TA584 significantly escalated its operations, tripling campaign volumes and expanding targets beyond North America and the UK to include Germany, other European countries, and Australia. Utilizing sophisticated phishing emails, TA584 employed the Tsundere Bot malware alongside the XWorm remote access trojan to gain unauthorized network access. These campaigns often began with emails from compromised accounts, leading victims through CAPTCHA and ClickFix pages that prompted the execution of PowerShell commands, resulting in the deployment of malware directly into system memory. Tsundere Bot, a malware-as-a-service platform, functions as both a backdoor and loader, requiring Node.js for operation and retrieving command-and-control addresses from the Ethereum blockchain using the EtherHiding technique. The malware is capable of system profiling, executing arbitrary JavaScript code, and turning infected machines into SOCKS proxies. Given TA584's history and the capabilities of the deployed malware, these infections pose a significant risk of leading to ransomware attacks. The rapid evolution and expansion of TA584's tactics underscore the increasing sophistication of initial access brokers and the persistent threat they pose to organizations worldwide.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
How the 2024 Microsoft Office Zero-Day Shaped Urgent Security Responses
Impact· HIGH

How the 2024 Microsoft Office Zero-Day Shaped Urgent Security Responses

In June 2024, Microsoft was compelled to release an emergency patch for a critical zero-day vulnerability affecting Microsoft Office products. The issue allowed attackers to exploit crafted Office documents, enabling remote code execution if a victim opened a malicious file. Attackers leveraged social engineering—including phishing—to trick users into opening infected attachments, bypassing standard email and endpoint defenses. Rapid weaponization of the exploit by criminal groups and likely state-backed actors resulted in significant risk for businesses using vulnerable Office deployments, with potential for data theft, malware infection, and lateral movement across networks. This attack highlights a pervasive trend of adversaries capitalizing on zero-day vulnerabilities in widely used productivity platforms. As seen in recent high-profile breaches, rapid exploitation before patches can be applied increases organizational risk and regulatory scrutiny, necessitating faster detection, patching, and user education across industries.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports