Validated Containment Architectures are here. →Explore

Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2382 threat reports
Page 119 of 199

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Government Administration Threat Reports

Showing 14171428 / 2382 reports
Jordan Government’s Use of Cellebrite Forensics Tools Targets Activists in 2024
Impact· high

Jordan Government’s Use of Cellebrite Forensics Tools Targets Activists in 2024

Between late 2023 and mid-2024, Jordanian authorities used Cellebrite’s digital forensic technology to access and extract data from the mobile phones of local activists and human rights defenders. According to an investigation by Citizen Lab and OCCRP, authorities seized activists’ devices—three iPhones and one Android—and subjected them to Cellebrite’s phone-cracking tools, often in connection with political protests. Court records and forensic analysis confirmed the use of Cellebrite products to nonconsensually access information, shaking victims’ trust and prompting self-censorship. This incident underscores the growing risks of commercial digital forensics tools being repurposed for surveillance beyond criminal cases. Amnesty International and other watchdogs report a broader trend of such technologies being leveraged against civil society, signaling a need for stronger governance, vendor accountability, and compliance oversight globally.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Fortinet 2026 Breach: Authentication Bypass Leads to Firewall Configuration Theft
Impact· medium

Fortinet 2026 Breach: Authentication Bypass Leads to Firewall Configuration Theft

In January 2026, Fortinet FortiGate devices became the target of a coordinated cyberattack exploiting an authentication bypass vulnerability (CVE-2025-59718) associated with the FortiCloud SSO feature. Attackers accessed vulnerable firewalls, created rogue administrative accounts, and swiftly exfiltrated firewall configuration data using automated tools, demonstrating significant threat actor sophistication. Reports indicated the campaign began on January 15, 2026, and quickly escalated as even patched devices were compromised—suggesting a patch bypass or incomplete remediation. Affected organizations faced exposure of sensitive security configurations and heightened risk of follow-on breaches or lateral movement within their networks. This incident spotlights the urgent challenges posed by cloud-exposed assets and incomplete vulnerability remediation. It emphasizes the criticality of rapid patch cycles, zero trust principles, and robust monitoring amid a trend of identity and configuration–focused attacks targeting enterprise infrastructure platforms.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Zendesk Ticket Systems Hijacked: 2026 Relay Spam Disrupts Global Brands
Impact· medium

Zendesk Ticket Systems Hijacked: 2026 Relay Spam Disrupts Global Brands

In January 2026, a massive global spam campaign exploited unsecured Zendesk support systems, enabling attackers to send hundreds of unsolicited emails to targets worldwide. By abusing the open ticket submission feature—allowing ticket creation from any email address without verification—attackers automated fake support requests to generate an overwhelming volume of confirmation emails. Major organizations including Discord, Tinder, Riot Games, Dropbox, and government agencies were impacted, with recipients receiving alarming and confusing messages that appeared to originate from legitimate support channels. No malicious payloads were identified, but the incident caused significant alarm, confusion, and business interruption for affected parties. The heightened ability for attackers to manipulate trusted service communications underscores a growing threat of platform abuse, where legitimate systems are turned against users to bypass security controls and sow disruption. With organizations increasingly reliant on third-party SaaS for customer engagement, this incident illustrates how gaps in self-service security can have wide-reaching and highly visible effects.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Okta SSO Targeted: 2024 Vishing Surge Exposes Credential Gaps
Impact· medium

Okta SSO Targeted: 2024 Vishing Surge Exposes Credential Gaps

In early 2024, Okta Single Sign-On (SSO) user accounts became the target of sophisticated phishing campaigns leveraging custom voice-based social engineering (vishing) kits. Threat actors contacted employees via phone calls, impersonating IT staff and using convincing pretexts to direct users to phishing sites tailored to mimic Okta’s authentication workflow. By capturing the credentials and multi-factor authentication (MFA) tokens, attackers accessed sensitive enterprise environments, leading to data exfiltration, disruption of operations, and potential exposure of downstream customers relying on Okta SSO for access control. This incident highlights a broader escalation in the use of vishing tactics to bypass strong authentication, underscoring the ongoing shift toward highly targeted, voice-enabled phishing attacks. Enterprises must adapt security and training programs to confront increasingly sophisticated social engineering methods targeting identity infrastructures.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Why Even Security Pros Get Phished: The Human & AI-Powered Phishing Crisis of 2026
Impact· medium

Why Even Security Pros Get Phished: The Human & AI-Powered Phishing Crisis of 2026

In January 2026, multiple incidents highlighted how even vigilant individuals and cybersecurity professionals are susceptible to highly convincing phishing attacks. Attackers leveraged advanced social engineering techniques and sophisticated phishing-as-a-service (PhaaS) platforms, often enhanced by AI-driven content generators such as PhishGPT, to deliver targeted messages via email, SMS, and collaboration tools. These lures bypassed traditional defenses, exploiting moments of distraction or emotional vulnerability to harvest sensitive information including credentials and payment data. The operational impact ranged from financial loss and credential compromise to downstream business risk due to unauthorized access or fraud. The incident typifies the evolution of phishing as an industrialized, scalable ecosystem that increasingly relies on automation, AI-tailored content, and a broadening array of tactics. As these methods proliferate and become accessible to attackers with limited technical skills, organizations face heightened regulatory, operational, and reputational risks, making effective prevention and user awareness more vital than ever.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Patched Fortinet Firewalls Breached in 2026: Authentication Bypass Exposes Enterprise Networks
Impact· low

Patched Fortinet Firewalls Breached in 2026: Authentication Bypass Exposes Enterprise Networks

In January 2026, patched FortiGate firewalls running FortiOS versions 7.4.9 and 7.4.10 were actively breached due to exploitation of a lingering authentication bypass flaw (CVE-2025-59718) in the FortiCloud SSO login feature. Despite an earlier patch, attackers utilized crafted SAML messages to create rogue admin accounts on exposed devices, as observed in customer logs and confirmed by Fortinet developers. More than 11,000 Internet-facing Fortinet devices remained vulnerable as attackers leveraged the flaw to gain privileged access and potentially compromise network defenses, triggering urgent remediation efforts. This incident underscores persisting risks from incomplete remediation, especially on security appliances pivotal to organizational defenses. Growing attacker expertise in exploiting authentication logic flaws and a surge in identity-based attacks highlight the necessity for ongoing vigilance, layered compensating controls, and rapid vulnerability response strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Cisco Zero-Day Exploited: Critical Remote Code Execution in Unified Communications (2026)
Impact· low

Cisco Zero-Day Exploited: Critical Remote Code Execution in Unified Communications (2026)

In January 2026, Cisco disclosed and patched CVE-2026-20045, a critical zero-day vulnerability affecting Unified Communications Manager, Unity Connection, and Webex Calling Dedicated Instance platforms. The flaw, arising from improper validation of user-supplied input via HTTP requests, allowed unauthenticated attackers to execute arbitrary code and escalate privileges to root on impacted servers. Cisco’s Product Security Incident Response Team (PSIRT) confirmed in-the-wild exploitation prior to patch release and issued urgent guidance for customers to update, as no workarounds exist. The U.S. CISA swiftly added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating timely remediation for federal agencies. This incident highlights a broader trend of sophisticated zero-day attacks targeting enterprise communications infrastructure. As attackers increasingly focus on supply chain and collaboration platforms, organizations must maintain rapid patching practices and improve segmentation and detection mechanisms against privilege escalation and remote code execution threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CVE-2026-20045: Active Code Injection Exploit Strikes Cisco Unified Communications
Impact· low

CVE-2026-20045: Active Code Injection Exploit Strikes Cisco Unified Communications

In January 2026, CISA added CVE-2026-20045 to its Known Exploited Vulnerabilities Catalog following reports of active exploitation targeting Cisco Unified Communications products. Attackers exploited a code injection vulnerability that allowed remote, unauthenticated threat actors to execute arbitrary code on affected devices, potentially compromising sensitive communications and opening access for further malicious activity within targeted federal civilian executive branch (FCEB) networks. This rapid addition of CVE-2026-20045 prompted urgent federal action to remediate impacted systems and reduce the risk of lateral movement and data exfiltration. The incident highlights a persistent threat vector facing organizations reliant on unified communications infrastructure. With attackers increasingly exploiting unpatched vulnerabilities and leveraging code injection to bypass security controls, the importance of timely patch management and network segmentation continues to grow amid tightening regulatory standards and intensifying audit scrutiny.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Visual Studio Code: The Hidden Supply-Chain Threat Targeting Developers (2024)
Impact· low

Visual Studio Code: The Hidden Supply-Chain Threat Targeting Developers (2024)

In January 2024, a novel supply-chain attack vector targeting Visual Studio Code (VSCode) environments was exposed. Threat actors leveraged VSCode's task automation feature by embedding malicious scripts within project-level '.vscode/tasks.json' files. When an unsuspecting developer opened a compromised repository or project directory, these hidden tasks executed automatically, enabling code execution—potentially leading to malware installation, data exfiltration, or further lateral movement within the developer’s environment. The attack mimics macro-style threats seen in Office documents, utilizing obfuscated scripts and exploiting legitimate productivity features to bypass traditional security controls. This breach highlights the growing exploitation of developer tools as initial intrusion points, particularly given the increased reliance on open-source ecosystems and extensions. Supply-chain attacks via development environments are on the rise, pressuring organizations to improve oversight of internal code, dependencies, and automated scripts. Vigilance around workspace configuration files, especially auto-executing tasks, is now critical for enterprise security posture.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
How an Azure Private Endpoint DNS Misconfiguration Triggered Massive DoS Risks in 2026
Impact· high

How an Azure Private Endpoint DNS Misconfiguration Triggered Massive DoS Risks in 2026

In January 2026, security researchers highlighted a critical cloud misconfiguration affecting Microsoft Azure’s Private Endpoint architecture that could trigger denial-of-service (DoS) conditions. Specifically, Azure Private Link’s DNS resolution behavior was shown to inadvertently block access to resources—including Azure Storage, Key Vault, CosmosDB, and others—when Private DNS zones were misconfigured. The risks arise in accidental and malicious deployment scenarios, where incomplete or improper DNS records prevent workloads from connecting, despite the underlying resource being online. This exposure reportedly affects over 5% of Azure storage accounts, posing operational disruption risks through simple configuration errors or targeted attacker activity. This incident underscores the increasing complexity and fragility of cloud-native networking, as organizations accelerate the adoption of zero trust and segmentation patterns. With threat actors and insider mistakes both leveraging subtle service settings, this serves as an urgent reminder that cloud misconfiguration remains a leading cause of outages and breaches.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Exposing the Hidden Threat: Orphan Accounts and the Identity Dark Matter (2026)
Impact· medium

Exposing the Hidden Threat: Orphan Accounts and the Identity Dark Matter (2026)

In January 2026, the cybersecurity community highlighted mounting risks associated with orphaned accounts—dormant but still-active identities left behind after employee turnover, organizational change, or fragmented onboarding processes. Attackers have repeatedly leveraged these unattended, often highly privileged accounts as entry points, as seen in notable breaches such as Colonial Pipeline (2021) and a 2025 ransomware attack on a manufacturing firm. These accounts evade detection and deprovisioning, undermining traditional Identity and Access Management (IAM) controls and enabling credential-based attacks that can lead to regulatory violations, operational inefficiencies, and delayed incident response. Such orphaned identities are a growing concern amid expanding use of non-human and AI-driven service accounts, especially following M&A activity. Their proliferation reflects a macro trend in attacker tactics: exploiting visibility and lifecycle gaps in identity governance—putting critical compliance frameworks and business continuity at risk.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Google Gemini Exploited: Calendar Invites Become AI Attack Vector in 2024
Impact· medium

Google Gemini Exploited: Calendar Invites Become AI Attack Vector in 2024

In early 2024, researchers identified a critical indirect prompt injection vulnerability affecting Google Gemini, Google's flagship AI suite. Attackers exploited calendar invites as a covert vector to manipulate Gemini's AI context, successfully bypassing native privacy filters and accessing sensitive user data. The attack leveraged the insertion of malicious prompts within innocuous-looking calendar items, which Gemini processed automatically, leading to unauthorized access and data exposure. Google responded by issuing incremental updates, but the incident highlighted inherent risks in automated AI integrations with productivity platforms reliant on user-generated content. This incident underscores the growing prevalence of AI/ML abuse through indirect attack vectors such as prompt injection. With threat actors increasingly targeting large language models in enterprise environments, security programs must rapidly adapt to cover AI-specific exposures, ensure robust segmentation, and incorporate real-time anomaly detection to defend against evolving risks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports