Validated Containment Architectures are here. →Explore

Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2383 threat reports
Page 123 of 199

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Government Administration Threat Reports

Showing 14651476 / 2383 reports
Microsoft Patch Tuesday January 2026: Actively Exploited Zero-Day and Critical Vulnerabilities
Impact· low

Microsoft Patch Tuesday January 2026: Actively Exploited Zero-Day and Critical Vulnerabilities

In January 2026, Microsoft released updates addressing 113 vulnerabilities across its Windows operating systems and supported software, including eight critical flaws and an actively exploited zero-day, CVE-2026-20805, in Desktop Window Manager (DWM). Despite a moderate CVSS of 5.5, this bug exposes address layout information, enabling attackers to chain it with other vulnerabilities for reliable compromise. Additionally, two critical Microsoft Office remote code execution flaws allowed attacks via specially crafted emails, and legacy modem driver vulnerabilities posed new elevation-of-privilege risks. Failure to patch exposes organizations to memory exploit chains, lateral movement, and potential system-level compromise affecting even fully updated environments. This incident highlights the ongoing threat of exploited zero-day vulnerabilities and the importance of timely patching amidst evolving attacker tactics. The rise of attacks leveraging old device drivers and exploitation chains underscores the need for risk-based vulnerability management and proactive security control validation.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Shadow#Reactor Delivers Remcos RAT Through Text File Phishing in 2024
Impact· low

Shadow#Reactor Delivers Remcos RAT Through Text File Phishing in 2024

In mid-2024, a threat group known as Shadow#Reactor orchestrated a sophisticated phishing campaign to deliver the Remcos Remote Access Trojan (RAT). Leveraging seemingly benign text files as carriers for malicious scripts, attackers bypassed security solutions and enticed targets to unwittingly initiate the infection through trusted system utilities. The campaign’s stealth allowed the attackers to establish command and control, enabling surveillance, credential theft, and potential lateral movement within the impacted organizations. This incident exemplifies the evolution of social engineering and malware delivery tactics that evade conventional defenses. The rise in attackers abusing native utilities with unobtrusive file types serves as a stark warning for organizations to re-evaluate endpoint protections and user awareness, especially as threat actors target a wide range of industries with novel bait methods.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Microsoft 2026 Zero-Day: Patch Tuesday Attack Signals New Wave of Exploits
Impact· medium

Microsoft 2026 Zero-Day: Patch Tuesday Attack Signals New Wave of Exploits

On January 13, 2026, Microsoft disclosed the exploitation of a previously unknown zero-day vulnerability affecting multiple versions of Windows, as attackers leveraged the flaw ahead of the company's first Patch Tuesday of the year. The vulnerability enabled adversaries to bypass encryption and lateral movement safeguards, allowing them to access sensitive data and escalate privileges within corporate networks. The incident prompted Microsoft to release urgent security updates patching 112 CVEs, double the typical monthly total, as organizations worldwide scrambled to assess exposure and mitigate risk. Early evidence suggests sophisticated threat actors utilized tailored malware and covert tools to evade traditional defenses and achieve widespread compromise. This event is emblematic of an escalating trend in which zero-day exploits are increasingly leveraged by attackers against major vendors. With rising regulatory pressure for rapid remediation and ongoing vulnerabilities in encryption and segmentation controls, the breach reinforces the importance of proactive threat detection and multi-layered defense strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft's January 2026 Patch Tuesday: Zero-Day and Critical Vulnerabilities Raise Enterprise Risks
Impact· medium

Microsoft's January 2026 Patch Tuesday: Zero-Day and Critical Vulnerabilities Raise Enterprise Risks

In January 2026, Microsoft released security patches addressing 113 vulnerabilities across its software portfolio, including eight critical flaws and one zero-day actively exploited at the time of disclosure. The scope of impacted components ranges from Microsoft Office and SharePoint to Windows LSASS and the Desktop Window Manager, with several vulnerabilities allowing remote code execution, privilege escalation, or information disclosure. Notably, the LSASS remote code execution vulnerability (CVE-2026-20854) drew historical comparisons to past infamous Windows attacks, though it required user authentication to exploit. Organizations reliant on Microsoft technologies were urged to update immediately as attackers began leveraging weaknesses, particularly the zero-day (CVE-2026-20805) targeting Desktop Window Manager, actively being exploited in the wild. This incident underscores a continued trend of complex, multi-pronged attacks exploiting both newly disclosed and previously published vulnerabilities. With an uptick in information disclosure and privilege escalation avenues, patch management, vulnerability monitoring, and robust detection controls remain mission-critical for modern enterprises as attackers race to weaponize disclosed flaws faster than ever before.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
MongoDB ‘MongoBleed’ (CVE-2025-14847): Critical Memory Leak Exposes Credentials
Impact· medium

MongoDB ‘MongoBleed’ (CVE-2025-14847): Critical Memory Leak Exposes Credentials

In December 2025, MongoDB disclosed a critical vulnerability, CVE-2025-14847 ("MongoBleed"), allowing unauthenticated attackers to exploit a flaw in the server's handling of zlib-compressed network messages. By manipulating the compression headers, attackers could trigger the leak of uninitialized heap memory, which often included sensitive data like credentials and PII. The issue stemmed from improper validation of data sizes in pre-authentication network protocols, enabling large-scale data exposure from any reachable MongoDB server. Over 146,000 vulnerable instances were identified as exposed to the internet, with active exploitation observed and a public proof-of-concept released. MongoBleed highlights the resurgence of memory disclosure flaws as attackers shift targets to exposed cloud and database services. Its automated exploitation at scale and inclusion in CISA's Known Exploited Vulnerabilities catalog signal increased regulatory and operational urgency for immediate patching and segmentation of critical data services.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
ServiceNow Patches Critical AI User Impersonation Flaw in 2025
Impact· low

ServiceNow Patches Critical AI User Impersonation Flaw in 2025

In October 2025, ServiceNow addressed a critical vulnerability (CVE-2025-12420) in its AI platform that enabled unauthenticated attackers to impersonate legitimate users and execute unauthorized activities. Discovered by AppOmni, the flaw impacted the Now Assist AI Agents and Virtual Agent API components. Attackers could have leveraged agent-to-agent collaboration features to escalate privileges, bypass user access controls, and modify or access sensitive records, even with certain protection features enabled. ServiceNow rapidly deployed patches to its cloud customers and provided updates for self-hosted users, stating there was no evidence of active exploitation prior to patch release. This incident underscores the risks associated with AI agent configurability, as well as the need for organizations to enforce strict configuration and segmentation in enterprise AI deployments. The case brings to light a growing trend: sophisticated exploitation of AI agent collaboration and the mounting regulatory and security focus on securing AI-powered enterprise systems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Microsoft's 2026 Zero-Day: Desktop Window Manager Exploited in Active Attacks
Impact· medium

Microsoft's 2026 Zero-Day: Desktop Window Manager Exploited in Active Attacks

In January 2026, Microsoft released security patches for 112 vulnerabilities across its product suite, including one actively exploited zero-day affecting Desktop Window Manager (CVE-2026-20805). This information disclosure vulnerability, rated CVSS 5.5, allows unauthorized local attackers to gain access to sensitive system information via memory leaks, potentially facilitating further privilege escalation or data theft. Although exploitation requires local access, threat actors have used similar flaws historically to escalate privileges, and the exposure of memory details can undermine systemic defenses, pathing the way for broader compromise and regulatory exposure. This incident underscores the evolving sophistication of threat actors, who increasingly leverage information disclosure vulnerabilities as stepping stones for multi-stage attacks. The active exploitation of such a zero-day highlights the importance of rapid remediation, comprehensive patch management, and heightened vigilance amid rising regulatory scrutiny and a surge in blended TTPs targeting enterprise environments.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
React2Shell and the December 2025 CVE Tsunami: Multi-Vector Exploitation at Scale
Impact· high

React2Shell and the December 2025 CVE Tsunami: Multi-Vector Exploitation at Scale

In December 2025, a record-setting wave of critical vulnerabilities led to a 120% surge in high-severity exploits globally, with 22 CVEs actively targeted—double the previous month. The standout event was the mass exploitation of Meta's React Server Components (CVE-2025-55182, dubbed "React2Shell"), which allowed unauthenticated remote code execution and became a magnet for a variety of threat actors, including China-linked groups Earth Lamia and Jackpot Panda plus a mix of financially motivated and state-aligned attackers. Attackers leveraged new and legacy vulnerabilities to deploy malware, pivot across internal networks, and compromise key infrastructure across vendors like Google, Fortinet, Cisco, Microsoft, and more. The incident highlights a dangerous shift: modern web frameworks are becoming high-value targets, attack toolkits are rapidly weaponizing zero-days, and threat actors now freely cycle between old and new vulnerabilities. Organizations operating React/Next.js or affected platforms face urgent patching requirements amid heightened regulatory attention and persistent adversarial activity.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
2024 Ransomware Attack on Global Utility: Speed, Sophistication, and Credential Theft
Impact· high

2024 Ransomware Attack on Global Utility: Speed, Sophistication, and Credential Theft

In March 2024, a leading global utility company suffered a large-scale ransomware attack executed by the BlackBasta threat group. Attackers initially gained entry by exploiting an externally-facing VPN with compromised credentials, bypassing multifactor authentication controls. Upon entry, the threat actors rapidly performed reconnaissance, escalated privileges, and moved laterally using legitimate remote management tools and credential dumping techniques, deploying ransomware payloads across hundreds of critical systems within 48 hours. The incident resulted in massive operational disruptions, including temporary shutdowns of power generation facilities and significant data exfiltration, while the attackers leveraged double extortion to pressure the company into paying a multimillion-dollar ransom. This breach exemplifies the growing sophistication and speed of multi-stage ransomware campaigns targeting critical infrastructure. The incident highlights the importance of pre-encryption detection, intelligence-driven defense, and robust access controls as ransomware groups continue to exploit hybrid environments and rapidly weaponize vulnerabilities.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
CISA Flags Critical Exploited Windows Vulnerability: CVE-2026-20805
Impact· medium

CISA Flags Critical Exploited Windows Vulnerability: CVE-2026-20805

In January 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20805, a Microsoft Windows Information Disclosure Vulnerability, to its Known Exploited Vulnerabilities Catalog following evidence of active exploitation. Attackers have leveraged this vulnerability as an entry vector to access sensitive data from federal and private sector Windows machines, potentially exposing unencrypted or inadequately protected data in transit. The incident highlights the ongoing risk to government and enterprise environments from timely, opportunistic exploitation of unpatched known vulnerabilities, particularly those enabling information disclosure and lateral movement within networks. This addition to CISA’s KEV Catalog underscores intensifying efforts by cybercriminals to rapidly weaponize newly disclosed vulnerabilities, especially those impacting widely-deployed products like Microsoft Windows. Regulatory and operational pressure is mounting for organizations to accelerate remediation practices as adversaries increasingly automate exploitation processes.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
FBI Warns of Kimsuky APT’s Advanced QR Code Phishing (Quishing) Attacks
Impact· low

FBI Warns of Kimsuky APT’s Advanced QR Code Phishing (Quishing) Attacks

In early 2024, the FBI issued an alert warning of advanced quishing (QR-code phishing) campaigns conducted by North Korean state-sponsored group Kimsuky. The group targeted US and foreign government agencies, NGOs, and academic institutions by sending emails laden with malicious QR codes, which, when scanned, redirected victims to credential-harvesting sites. The campaign relied on the growing trust in QR codes and the challenges of securing email and mobile workflows. While no major data breach was announced, the intent was information theft and espionage, representing a significant risk to critical institutions’ security and reputation. This incident highlights the evolution of phishing techniques—from simple emails to advanced, device-hopping attacks using QR codes—mirroring a wider global threat trend. Organizations are urged to update security controls and awareness programs, as quishing is now surging across industries.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
GoBruteforcer Botnet Hits 50K+ Linux Servers with AI-Powered Brute Force
Impact· medium

GoBruteforcer Botnet Hits 50K+ Linux Servers with AI-Powered Brute Force

In early 2024, researchers identified a powerful new variant of the GoBruteforcer botnet actively targeting over 50,000 Linux servers worldwide. The attackers leveraged automated brute-force attacks in combination with AI-generated configurations to compromise servers running popular services such as SSH, MySQL, and Redis. Once inside, the botnet deployed additional malware to expand its network, launch further attacks, and facilitate potential data theft or service disruption, posing significant operational risks to exposed organizations. This campaign highlights the evolving nature of automated botnets, now leveraging AI tools to speed up attacks and evade detection. With Linux servers widely used in cloud and enterprise environments, the incident underscores the urgent need for improved credential hygiene, segmentation, and real-time traffic monitoring as botnets increasingly target critical infrastructure at scale.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports