Validated Containment Architectures are here. →Explore

Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2382 threat reports
Page 120 of 199

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Government Administration Threat Reports

Showing 14291440 / 2382 reports
Punycode Phishing: How IDN Abuse Enabled Stealth Attacks in 2026
Impact· low

Punycode Phishing: How IDN Abuse Enabled Stealth Attacks in 2026

In January 2026, security researchers identified a surge in phishing attacks leveraging Internationalized Domain Names (IDNs) encoded with Punycode, enabling attackers to create visually deceptive domains that closely resemble legitimate ones. By substituting standard ASCII characters with similar-looking Unicode characters, threat actors bypassed traditional detection, tricking users into visiting fraudulent sites and unknowingly exposing credentials or sensitive information. The attack was uncovered through DNS log analysis, revealing repeated internal access attempts to encoded domains such as xn--yutube-wqf.com, demonstrating the sophistication and stealth of this social engineering tactic. This incident highlights the growing prevalence of advanced phishing campaigns using homoglyph attacks and encoded domains, underscoring the need for updated detection routines and user awareness. Organizations face increased operational risk as threat actors exploit gaps caused by internationalization and encoding, making timely monitoring and DNS log analysis crucial.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Supreme Court and Agency Data Breached via Stolen Credentials: The 2023 Instagram Leak
Impact· high

Supreme Court and Agency Data Breached via Stolen Credentials: The 2023 Instagram Leak

In late 2023, a Tennessee man illicitly accessed the U.S. Supreme Court’s restricted electronic filing system, as well as accounts at AmeriCorps and the Department of Veterans Affairs, through the repeated use of stolen credentials. Over multiple months, Nicholas Moore gained unauthorized entry to sensitive government systems at least 25 times, collecting and exfiltrating personal, legal, and health data. He then publicized this sensitive information via his Instagram handle, @ihackedthegovernment, exposing government, AmeriCorps, and veteran data, including personal identifiers and privileged health information. This case underscores a rise in breaches involving compromised credentials, lateral movement, and public boasting on social media. With persistent attacker focus on governmental targets and data exfiltration, it exemplifies the ongoing risks of inadequate east-west and data-in-transit security, as well as the compliance pressure on federal agencies to shore up access controls and insider threat monitoring.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
UK Under Siege: NoName057(16) DDoS Attacks Target Critical Infrastructure in 2026
Impact· high

UK Under Siege: NoName057(16) DDoS Attacks Target Critical Infrastructure in 2026

In January 2026, the UK's National Cyber Security Centre (NCSC) issued a warning about ongoing DDoS attacks targeting critical infrastructure and local government organizations across the United Kingdom. These attacks are attributed to the pro-Russian hacktivist group NoName057(16), known for leveraging their crowdsourced DDoSia platform to coordinate massive denial-of-service campaigns. Despite an international law enforcement operation in mid-2025 that resulted in arrests and the takedown of supporting servers, the core operators evaded capture and resumed disruptive activities. The attacks, while technically unsophisticated, resulted in interruptions of public-facing services, forced organizations to invest in defensive measures, and threatened operational resilience. This incident underscores a broader trend of ideologically motivated hacktivism targeting Western critical infrastructure, amplified by evolving techniques and persistent threat actors. As geopolitical tensions rise and hacktivists increasingly collaborate via decentralized platforms, DDoS threats have become a significant operational risk for organizations across the public and private sectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
CrashFix Chrome Extension Attack Delivers ModeloRAT in ClickFix-Style Campaign
Impact· low

CrashFix Chrome Extension Attack Delivers ModeloRAT in ClickFix-Style Campaign

In January 2026, security researchers uncovered the 'KongTuke' campaign, which weaponized a malicious Chrome extension named CrashFix, disguised as an ad blocker. Attackers exploited a faux browser crash workflow—imitating ClickFix lures—to trick victims into running malicious commands, delivering the new ModeloRAT remote access trojan (RAT). The campaign allowed threat actors to silently gain persistent, covert access, facilitating lateral movement and potential data exfiltration within corporate environments. The incident highlights the evolving sophistication of browser-based attack chains and underscores browser extension risk as a modern threat vector for organizations reliant on SaaS and web apps. This breach is emblematic of a surge in malicious browser extensions delivering advanced malware. It showcases a growing trend toward supply chain compromise and the abuse of user trust in widely used browser platforms, calling for improved extension vetting and proactive security controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Fortinet 2026: How RedLine Clipjack and Copilot Shaped a New Breed of Multi-Vector Attacks
Impact· low

Fortinet 2026: How RedLine Clipjack and Copilot Shaped a New Breed of Multi-Vector Attacks

In early 2026, multiple organizations suffered a multi-vector cyberattack campaign leveraging Fortinet device vulnerabilities, RedLine stealer variants with clipjack capabilities, and weaponized Copilot-integrated phishing. Threat actors gained initial access through unpatched Fortinet appliances, moved laterally via east-west traffic, and deployed RedLine malware to intercept credentials and exfiltrate sensitive data. The attackers further abused cloud AI tools to automate reconnaissance and launch targeted campaigns, leading to significant data compromise and operational disruption across cloud and hybrid environments. This incident underscores an accelerating trend: attackers are combining zero-day exploits, infostealers, and AI-driven automation to bypass traditional defenses. As threat actors become more agile and creative with emerging tools, organizations face growing pressure to secure east-west flows and implement real-time anomaly detection to mitigate multi-stage breaches.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Fortinet FortiSIEM CVE-2025-64155: Critical Vulnerability Exploited in the Wild
Impact· low

Fortinet FortiSIEM CVE-2025-64155: Critical Vulnerability Exploited in the Wild

In June 2025, Fortinet disclosed CVE-2025-64155, a critical command injection vulnerability affecting FortiSIEM, its security information and event management solution. Attackers began exploiting the flaw almost immediately after disclosure, leveraging it to execute unauthorized system commands and gain persistent access across multiple targeted networks. Malicious activity was detected from a diverse array of IP addresses, suggesting widespread probing and potential compromise. The rapid weaponization of the vulnerability placed organizations relying on FortiSIEM at risk of data exfiltration, lateral movement, and potential service disruption, underscoring the importance of timely patch management and layered defenses. This incident is emblematic of a growing trend where attackers aggressively target newly disclosed vulnerabilities in widely used security platforms. The event highlights the urgent need for rapid vulnerability response processes and reevaluation of vendor risk in security-critical infrastructure, as threat actors continue to automate exploitation of critical flaws in security tooling itself.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Inside the 2024 Payroll Social Engineering Breach: Lessons from the Payroll Pirates
Impact· low

Inside the 2024 Payroll Social Engineering Breach: Lessons from the Payroll Pirates

In early 2024, a major payroll provider experienced a sophisticated social engineering breach orchestrated by attackers dubbed the 'Payroll Pirates.' The threat actors engineered convincing phishing campaigns targeting payroll staff, tricking them into divulging critical credentials. Once initial access was secured, the attackers leveraged lateral movement techniques to escalate privileges and manipulate internal payroll processes, ultimately leading to fraudulent fund transfers and sensitive data exposure. Rapid detection efforts limited further impact, but the breach resulted in financial losses, operational disruption, and increased scrutiny over internal controls. This incident underscores the resurgence of highly targeted social engineering attacks, specifically in the payroll and finance sectors. As attackers blend human manipulation with advanced technical tactics, organizations must prioritize zero trust architectures, staff awareness, and continuous threat monitoring to defend against this evolving risk landscape.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Google Pixel 9's 2025 Zero-Click Exploit Chain: Lessons in Mobile Supply Chain Security
Impact· medium

Google Pixel 9's 2025 Zero-Click Exploit Chain: Lessons in Mobile Supply Chain Security

In 2025, security researchers demonstrated a critical 0-click exploit chain targeting Google Pixel 9 and other Android devices, leveraging vulnerabilities in the Dolby UDC audio codec and the BigWave driver. Attackers could remotely execute code without user interaction by exploiting flaws in audio file processing and privilege escalation within device drivers. Despite early reporting and clear exploitability, it took vendors up to 139 days to release patches, leaving millions of Android users at risk. Gaps in patch management, inconsistent security controls, and delayed vulnerability classification contributed to prolonged exposure and a significant operational risk. This incident underscores the urgency of promptly addressing zero-click vulnerabilities and supply chain security issues in mobile ecosystems. As attackers increasingly exploit overlooked decoders, device drivers, and rapidly introduced AI features, coordinated patching and proactive privilege reduction remain essential to counter evolving mobile threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fortinet FortiSIEM Zero-Day: Exploitation Surge Exposes SIEM Risks in 2024
Impact· low

Fortinet FortiSIEM Zero-Day: Exploitation Surge Exposes SIEM Risks in 2024

In June 2024, attackers began actively exploiting a critical vulnerability (CVE-2024-XXXX) in Fortinet FortiSIEM, a widely deployed security event management solution. The flaw, which allows remote code execution via specially crafted API requests, was leveraged soon after public proof-of-concept exploit code emerged. Threat actors targeted unpatched FortiSIEM instances to gain privileged access, deploy malware, and establish persistence within enterprise environments, impacting security visibility and putting sensitive data at risk. Public advisories highlighted patch urgency, as exploitation was observed globally in both private and government sectors. This incident underscores sharp escalation in exploitation of high-impact vulnerabilities immediately following public disclosure and POC release. The attack illustrates the need for rapid patching, robust segmentation, and comprehensive monitoring, as threat actors increasingly automate targeting of critical management infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Sitecore 2025: China-Linked APT UAT-8837’s Zero-Day Attack Reveals Modern Espionage Tactics
Impact· medium

Sitecore 2025: China-Linked APT UAT-8837’s Zero-Day Attack Reveals Modern Espionage Tactics

In early September 2025, an advanced persistent threat group known as UAT-8837, believed to be linked to China, exploited a zero-day vulnerability (CVE-2025-53690) in Sitecore products to gain initial access to critical infrastructure targets in North America. The attackers obtained credentials and leveraged living-off-the-land tools, open-source utilities, and custom backdoors—including 'WeepSteel'—to conduct deep reconnaissance, move laterally, and collect sensitive data such as credentials and Active Directory configurations. Post-exploitation activity also included disabling security controls and exfiltrating internal DLLs, which could be leveraged for future supply chain attacks. This incident spotlights a surge in targeted espionage exploiting both zero-day and known software vulnerabilities, with an emphasis on credential compromise and lateral movement. Growing overlap in TTPs among China-nexus actors and continued attack innovation reinforce the importance of modernizing defenses against sophisticated identity- and supply-chain-driven attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
China-Linked APT Exploits Cisco Secure Email Gateway Zero-Day (2025)
Impact· medium

China-Linked APT Exploits Cisco Secure Email Gateway Zero-Day (2025)

In late 2025, Cisco disclosed a critical zero-day vulnerability (CVE-2025-20393, CVSS 10.0) within AsyncOS Software powering its Secure Email Gateway and Secure Email and Web Manager appliances. Exploited by China-linked advanced persistent threat group UAT-9686, the flaw—residing in insufficient HTTP request validation by the Spam Quarantine feature—allowed attackers to remotely execute commands as root, install tunneling and persistence tools, and drop a Python backdoor ("AquaShell"). The threat actor’s campaign saw exploitation in the wild ahead of Cisco’s January 2026 patch release, impacting organizations exposing affected appliances to the internet with the vulnerable feature enabled. This incident highlights the increasing sophistication and operational tempo of state-backed APTs exploiting zero-day vulnerabilities in enterprise infrastructure. The case underscores the urgency for rigorous patch management, network segmentation, and rapid detection as attackers target critical security appliances that serve as organizational communication lifelines.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
LOTUSLITE Backdoor: How Mustang Panda Targeted U.S. Policy Organizations in 2026
Impact· low

LOTUSLITE Backdoor: How Mustang Panda Targeted U.S. Policy Organizations in 2026

In January 2026, researchers revealed a spear phishing campaign targeting US government and policy organizations utilizing geopolitical lures themed around US intervention in Venezuela. Attackers distributed a malicious ZIP archive containing a DLL file using side-loading techniques to deploy the LOTUSLITE backdoor. The campaign, attributed to the Chinese state-linked Mustang Panda group, leveraged reliable execution flows such as DLL sideloading, beaconed over WinHTTP APIs, enabled remote command execution, and exfiltrated data. While the exact scope of any successful compromise remains unclear, the operation demonstrates a focused cyber espionage effort using proven tactics for initial access and persistence. This campaign highlights the ongoing trend where threat actors employ familiar, effective tradecraft combined with timely or provocative lures. It underscores the continued risk posed to policy organizations from geopolitical-themed spear phishing as attackers adapt their delivery but rely on consistent, operationally sound techniques.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports