✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Critical WatchGuard Firebox Firewall Flaw Enables RCE Attacks in 2025
In December 2025, WatchGuard disclosed a critical remote code execution (RCE) vulnerability (CVE-2025-14733) impacting numerous Firebox firewall models running Fireware OS versions 11.x and later. The flaw, stemming from an out-of-bounds write bug, allows unauthenticated attackers to deploy malicious code on unpatched devices via low-complexity attacks, without user interaction. Exploitation is linked to IKEv2 VPN configurations, including those previously deleted but with lingering branch office VPN settings, making many organizations vulnerable. Active exploitation was observed, prompting WatchGuard to provide urgent mitigation steps and indicators of compromise to aid detection and response. The incident poses serious risks to over 250,000 businesses worldwide, as Firebox devices are extensively used in SMBs and managed service environments. This breach highlights the ongoing escalation of attacks targeting network infrastructure, particularly security appliances that underpin VPN and edge services. With similar device vulnerabilities making headlines throughout 2025, attackers are increasingly exploiting remote access flaws to establish persistence, demonstrating a worrying trend for organizations that depend on always-on network security.
6 months ago
Kill Chain
Denmark’s Water Utility Cyberattack: Hybrid Warfare Hits Critical Infrastructure in 2025
In December 2025, Danish authorities publicly attributed a destructive cyberattack on a major water utility to Russian state-sponsored groups, primarily Z-Pentest. The attackers penetrated critical operational systems, disrupting water infrastructure and threatening essential services. Danish intelligence described the operation as part of Russia’s ongoing hybrid war strategy, which includes leveraging hacktivist proxies to create insecurity and punish countries supporting Ukraine. Simultaneously, NoName057(16) conducted a DDoS campaign targeting Danish election infrastructure, further elevating national security concerns. This incident underscores the rising threat posed by nation-state actors actively targeting vital infrastructure across Europe. The use of both destructive intrusions and disruptive tactics during sensitive political periods reflects a broader trend of cyber operations designed to undermine public trust and exploit operational technology vulnerabilities on a global scale.
6 months ago
Kill Chain
Fortinet SSO Bypass: 25,000 Devices at Risk from Critical CVE-2025-59718 Exploit
In December 2025, over 25,000 internet-exposed Fortinet devices with FortiCloud Single Sign-On (SSO) enabled were found vulnerable to an actively exploited authentication bypass flaw (CVE-2025-59718/CVE-2025-59719). Threat actors leveraged a malicious SAML message to compromise admin accounts via the SSO interface, gaining unauthorized access to system configuration files that revealed credentials, service details, network layouts, and firewall policies. The wide exposure was confirmed by independent scans, while U.S. government agencies were urgently mandated by CISA to patch within a week due to mounting exploitation. This incident highlights the persistent risk posed by poorly secured administrative interfaces, unpatched vulnerabilities, and credential-access techniques. Escalating regulatory pressure and attacker focus on identity-driven infrastructure demonstrate the need for robust segmentation and detection across all exposed assets.
6 months ago
Kill Chain
Microsoft 365 Under Siege: OAuth Device Code Phishing Attacks Surge in 2025
In late 2025, Microsoft 365 accounts across multiple sectors were targeted in a sophisticated phishing campaign leveraging OAuth device code authorization. Threat actors, including financially motivated group TA2723 and a Russia-aligned group tracked as UNK_AcademicFlare, deceived victims into entering attacker-provided device codes on legitimate Microsoft login portals. This granted attacker-controlled applications elevated access to organizational email and data, bypassing credentials and even multi-factor authentication protections. Attackers utilized phishing kits such as SquarePhish and Graphish, and orchestrated lures mimicking document sharing or salary bonus notifications to maximize engagement and scale. Notably, state-aligned campaigns exploited compromised government accounts to build rapport, targeting U.S. and European government, academic, and transportation sectors. These OAuth-based phishing attacks mark a significant escalation in adversary techniques focusing on authorization abuse rather than credential theft. The surge in such activity since September 2025 demonstrates the growing adaptation of sophisticated phishing kits and highlights a strategic shift toward targeting identity and cloud permissions, reflecting evolving attack surfaces and regulatory scrutiny in cloud security.
6 months ago
Kill Chain
UEFI Firmware Vulnerability Leaves Major Motherboards Open to Early-Boot DMA Attacks
In December 2025, researchers disclosed a critical hardware/firmware vulnerability impacting various ASRock, ASUS, GIGABYTE, and MSI motherboards. The flaw allows threat actors to launch direct memory access (DMA) attacks during the early boot process, bypassing typical Unified Extensible Firmware Interface (UEFI) and Input–Output Memory Management Unit (IOMMU) protections. Attackers can exploit this window to inject code or access sensitive memory before system defenses activate. The incident exposes endpoints to risk of credential theft, persistent malware implants, and lateral movement, with potential compromise of high-value IT and OT assets. This incident is highly relevant as firmware attacks and supply chain risks escalate, especially with the push towards Zero Trust security architectures. Hardware-level exposures pose challenges that traditional endpoint or network controls may not immediately mitigate, requiring urgent attention to firmware security and early-boot exploit detection.
6 months ago
Kill Chain
Nigerian Authorities Arrest Raccoon0365 Phishing Platform Developer Linked to Microsoft 365 Attacks
In December 2025, Nigerian authorities arrested three individuals linked to the Raccoon0365 phishing platform, which was responsible for widespread credential theft targeting Microsoft 365 users. The service enabled cybercriminals to create convincing fake Microsoft login pages, facilitating business email compromise, data breaches, and significant financial losses across 94 countries. The investigation and arrests were made possible through intelligence provided by Microsoft via the FBI, leading to the apprehension of the platform's alleged developer and the recovery of digital evidence. Raccoon0365 operated via a Telegram channel with over 800 members, selling access to the phishing kits for cryptocurrency and leveraging Cloudflare infrastructure with compromised credentials. This incident is highly relevant as phishing-as-a-service (PhaaS) platforms continue to industrialize credential theft and make sophisticated attacks broadly accessible. The disruption of Raccoon0365 illustrates the importance of global collaboration, threat intelligence sharing, and proactive law enforcement action in curbing cybercrime.
6 months ago
Kill Chain
New DCOM Object Abuse Enables Lateral Movement via Control Panel (2024)
In early 2024, new research revealed an undisclosed vulnerability in Microsoft Windows, where adversaries can abuse the Distributed Component Object Model (DCOM) to achieve lateral movement and persistence by exploiting Control Panel item registration. Attackers can remotely trigger the loading of malicious DLLs via the COpenControlPanel DCOM object, circumventing common defenses and security controls in enterprise environments. By registering rogue DLLs within specific Windows registry keys and leveraging remote registry manipulation, threat actors obtain both initial code execution and ongoing persistence, with minimal user interaction and limited detection from traditional endpoint defenses. This exposure highlights a shift toward advanced lateral movement techniques exploiting legitimate system components. With the rapid evolution of attacker TTPs, especially those bypassing modern endpoint protections and leveraging system internals, organizations face increased risk of undetected breaches and regulatory scrutiny. Proactive monitoring and refined segmentation are now essential to close these newly exposed attack paths.
6 months ago
Kill Chain
Cloud Atlas 2025: APT Espionage Hits Russian and Belarusian Organizations via Cloud-Based Implants
In the first half of 2025, the persistent threat group Cloud Atlas launched a series of sophisticated cyber-espionage campaigns targeting organizations in Russia and Belarus. Attackers employed spear-phishing emails with weaponized Microsoft Office documents exploiting CVE-2018-0802, initiating a complex multi-stage infection chain. Custom implants such as VBShower, VBCloud, CloudAtlas, and PowerShower enabled attackers to establish persistent access, exfiltrate sensitive data, steal credentials, and abuse cloud-based C2 channels. Multiple sectors were affected, including telecommunications, construction, government, and manufacturing, with operations characterized by stealthy lateral movement, DLL hijacking, and multi-layered payload delivery. This incident is significant due to Cloud Atlas's use of novel, previously undocumented toolsets and cloud service abuse, reflecting a trend among APT actors toward cloud-based, modular attacks. It highlights the urgent need for heightened east-west security, advanced threat visibility, and multi-layered cloud controls, amid continued evolution of state-sponsored threat tactics.
6 months ago
Kill Chain
Nigeria Arrests Developer Behind RaccoonO365 Phishing Attacks on Microsoft 365
In December 2025, Nigerian authorities arrested three high-profile cybercriminals, including the developer behind the notorious RaccoonO365 Phishing-as-a-Service (PhaaS) operation. RaccoonO365 enabled widespread Microsoft 365 phishing campaigns targeting large global corporations, facilitating credential theft and unauthorized access through sophisticated phishing kits and email lures. The Nigeria Police Force National Cybercrime Centre (NPF–NCCC) led the investigation, collaborating with international law enforcement agencies to dismantle core elements of the PhaaS infrastructure. The disruption has limited the proliferation of phishing tools contributing to corporate account compromises and subsequent business email compromise (BEC) incidents. This case underscores the persistent evolution and professionalization of phishing-as-a-service marketplaces, often operated across borders. It highlights an increased law enforcement focus on targeting not only the end-users but also the developers and operators of cybercriminal toolkits enabling downstream attacks.
6 months ago
Kill Chain
Critical WatchGuard Fireware VPN Vulnerability Exploited Globally in 2025
In December 2025, WatchGuard disclosed a critical vulnerability (CVE-2025-14733, CVSS 9.3) impacting Fireware OS devices used for remote and branch office VPN connections via IKEv2. Remote unauthenticated attackers exploited an out-of-bounds write flaw in the iked process, allowing arbitrary code execution and potential compromise of security appliances. WatchGuard confirmed in-the-wild attacks linked to multiple malicious IPs, with over 117,000 internet-exposed devices at risk worldwide—over 35,000 in the U.S. alone. The vulnerability persisted in devices with previous IKEv2 configurations, even if settings were deleted. This incident exemplifies a broader threat trend as adversaries increasingly target edge networking infrastructure and VPN appliances through sophisticated exploits. The rapid addition of CVE-2025-14733 to CISA’s Known Exploited Vulnerabilities catalog underscores regulatory urgency and the need for vigilant patch management.
6 months ago
Kill Chain
CISA Flags WatchGuard Firebox CVE-2025-14733 for Active Exploitation: Edge Device Security in Focus
In December 2025, CISA added CVE-2025-14733 affecting WatchGuard Firebox appliances to its Known Exploited Vulnerabilities Catalog after evidence of intensified in-the-wild exploitation. This out-of-bounds write vulnerability enables remote attackers to execute arbitrary code or disrupt device operations, threatening the integrity of network edge security. Organizations running unpatched Firebox devices are susceptible to threat actors leveraging this flaw for initial access, lateral movement, or persistent presence, with potential impact ranging from data compromise to operational downtime. Federal agencies were given a limited timeframe to remediate as mandated by Binding Operational Directive 22-01. The exploitation of CVE-2025-14733 underscores a trend where threat groups rapidly adopt edge infrastructure vulnerabilities into their toolkits. This incident reflects rising urgency for rigorous, proactive vulnerability management, as the window from disclosure to active exploitation continues to narrow.
6 months ago
Kill Chain
Russia-Linked Hackers Exploit Microsoft 365 Device Code Phishing in 2025
In September 2025, a Russia-linked threat group identified as UNK_AcademicFlare launched a sophisticated phishing campaign targeting Microsoft 365 users via the device code authentication workflow. By leveraging compromised email accounts from government and academic sectors, attackers sent plausible phishing messages that tricked recipients into authorizing malicious device codes, leading to credential theft and account takeovers. The campaign enabled widespread unauthorized access to cloud platforms, risking data exposure and significant operational impact—particularly for targeted organizations with weak multi-factor authentication (MFA) policies.<br><br>Such attacks reflect an increasing trend in adversaries using native authentication flows to bypass defenses and highlight growing risks around cloud account compromises. Regulatory scrutiny is intensifying, and organizations must urgently strengthen identity controls and security monitoring to address these evolving social engineering tactics.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports