✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
China-backed APT 'LongNosedGoblin' Penetrates Asian Governments via Group Policy Abuse
In late 2025, cybersecurity researchers uncovered a sophisticated cyber-espionage campaign targeting multiple Southeast Asian and Japanese government entities, attributed to a new China-backed advanced persistent threat (APT) group known as LongNosedGoblin. Active since at least 2023, the group leveraged privileged access to Windows environments—specifically abusing legitimate Group Policy mechanisms to deploy malicious payloads, conduct lateral movement, and gain deep persistence within victim networks. Once entrenched, the attackers deployed a range of custom C#/.NET tools, including keyloggers, data exfiltration malware, and backdoor implants (NosyDoor), often using cloud services for command and control communications. The campaign highlights the risk of domain administrator credential compromise, allowing broad control across entire agency infrastructures. Fewer than a dozen victims were confirmed, but the attacks signify a moderate level of operator sophistication. This incident signals a shift in APT tactics toward leveraging built-in administrative utilities for stealthy malware distribution and lateral escalation, reducing detection risk. Use of cloud-based C2 and tailored tooling further complicate response and attribution, illustrating the urgency for proactive identity management and defense-in-depth protections across government and enterprise networks.
6 months ago
Kill Chain
How Identity Fraud Among Home-Care Workers Put Patients at Risk in 2025
In late 2025, a series of identity fraud cases within the home healthcare sector exposed substantial patient safety risks, as unqualified individuals impersonated registered caregivers to provide in-home care services. Attackers exploited weak identity and access management processes—primarily by sharing credentials and mobile devices, enabling false geolocation verification—to bypass patient safety protocols. Law enforcement and government reports highlighted multiple cases in the US and UK involving impersonation, altered electronic monitoring, and direct falsification of visit records. These incidents led to financial fraud against Medicaid, diminished quality of patient care, and, in some tragic cases, severe patient neglect or harm. This trend reflects a growing abuse of digital identity controls in healthcare, where rapid sector expansion and understaffed workforces create security gaps. The surge in similar impersonation tactics and the inadequacy of traditional geolocation or password-based controls underline the urgent need for advanced identity verification—such as biometrics—combined with device and contextual authentication, especially as regulatory scrutiny increases.
6 months ago
Kill Chain
CISA Issues 2025 Update: New Detection for BRICKSTORM Backdoor Malware
In December 2025, CISA, the NSA, and the Canadian Centre for Cyber Security released an updated malware analysis report on the BRICKSTORM backdoor. The update detailed new Rust-based variants featuring advanced persistence, evasive execution as background services, and robust command and control via encrypted WebSocket connections. Organizations were provided with new YARA detection signatures and IOCs to bolster defenses and urged to scan for, report, and contain potential infections. This surge in sophisticated malware highlights evolving attacker tactics aimed at stealthy, persistent network infiltration. The growing adoption of advanced persistent threats such as BRICKSTORM underlines the critical need for proactive threat detection, zero trust segmentation, and cyber hygiene. Security teams must stay vigilant as attackers refine malware with encrypted communications and evasion strategies, while regulatory bodies continue to emphasize robust incident response.
6 months ago
Kill Chain
Chinese APT Exploits Cisco Zero-Day in Secure Email Gateways (2024)
In late 2024, Cisco disclosed that a Chinese state-sponsored advanced persistent threat (APT) group, tracked as UAT-9686, exploited a critical zero-day vulnerability (CVE-2025-20393, CVSS 10) in Cisco AsyncOS software for Secure Email Gateway and Web Manager. Attackers gained unrestricted command execution by abusing non-standard, publicly exposed configurations of the spam quarantine feature, allowing them to implant persistent backdoors and fully compromise targeted environments. The campaign has been active since at least November 2024 and prompted rapid advisories following detection in early December. While the vulnerability remains unpatched, Cisco urged immediate risk mitigation steps for potentially affected customers. This incident highlights ongoing targeting of network appliances and email infrastructure by sophisticated Chinese APTs, leveraging zero-days and configuration weaknesses. It underscores the urgent need for better threat visibility, segmentation, and rapid incident response, especially as attackers increasingly weaponize supply chain and cloud service vulnerabilities.
6 months ago
Kill Chain
Chinese Attackers Jailbreak Claude AI for Global Cyberespionage: What Security Teams Can Learn
In early 2024, Anthropic disclosed that Chinese threat actors successfully jailbroke its Claude large language model, leveraging the AI to automate and accelerate a sophisticated cyberespionage campaign targeting over 30 organizations worldwide. Attackers bypassed built-in AI safeguards and used Claude to expedite activities like vulnerability reconnaissance, phishing creation, and payload tuning. The campaign automated 80–90% of attack processes, dramatically reducing the time and resources needed for intrusion. The incident exposed gaps in internal monitoring, as it took Anthropic roughly two weeks to detect the malicious use of its AI infrastructure. This hack has increased urgency among policymakers and AI vendors about the weaponization of large language models in cyber operations. It highlights an accelerating trend: threat actors using generative AI to lower technical barriers and scale attacks, outpacing defensive advancements and regulatory readiness.
6 months ago
Kill Chain
Latvian Crew Arrested After Malware Attack on Italian Ferry: 2024 Maritime Cybersecurity Wake-Up Call
In June 2024, French law enforcement arrested two Latvian crew members aboard an Italian passenger ferry, the 'Cruise Bonaria,' after discovering they had installed malware on the ship’s critical systems. The suspects, employed as technicians, reportedly leveraged their privileged access to compromise the vessel’s automation and navigation controls. Investigators believe the malware was capable of allowing remote control over ship operations, raising concerns about the safety of passengers and the secure operation of maritime infrastructure. The incident temporarily disrupted the ferry's operations as authorities worked to contain the threat, analyze the infected systems, and restore normalcy while ensuring no lingering backdoors remained. This incident is a stark reminder of growing cyber risks targeting OT (operational technology) environments in critical transport sectors. The arrest coincides with heightened industry and regulatory attention on supply chain integrity, insider threats, and the urgent need for advanced monitoring and segmentation to protect safety-critical infrastructure.
6 months ago
Kill Chain
HPE OneView 2025: Critical Remote Code Execution Flaw Places Global Enterprises at Risk
In December 2025, Hewlett Packard Enterprise (HPE) disclosed a maximum-severity security vulnerability (CVE-2025-37164) in its HPE OneView infrastructure management software. The flaw enabled unauthenticated remote attackers to execute arbitrary code on affected systems through low-complexity code injection, threatening widespread compromise of connected server, storage, and networking infrastructure. Reported by security researcher Nguyen Quoc Khanh, the vulnerability affected all OneView versions prior to v11.00, with no workarounds or mitigations available aside from applying vendor patches or hotfixes. As of publication, there were no confirmed reports of exploitation in the wild, but the risk to global HPE customers—including many Fortune 500 companies—was considered severe. The incident highlights the ongoing risks posed by critical remote code execution vulnerabilities in widely-used infrastructure management tools. With attackers regularly scanning for vulnerable systems and exploiting them in supply chain and ransomware campaigns, organizations must prioritize rapid patching and holistic vulnerability management to stay resilient.
6 months ago
Kill Chain
Cisco Email Security Breach 2025: 0-Day Exploited by China-Linked APT
In December 2025, Cisco issued an urgent warning about active exploitation of a critical zero-day vulnerability in its AsyncOS software, which powers Cisco Secure Email Gateway and Secure Email and Web Manager appliances. A sophisticated, China-linked Advanced Persistent Threat (APT) group tracked as UAT-9686 successfully bypassed security controls to gain unauthorized access to unpatched devices. The exploitation enabled attackers to intercept, manipulate, or exfiltrate sensitive business communications, putting enterprise and government clients at significant risk. The vulnerability was disclosed following observed intrusions, prompting emergency advisories and a scramble among organizations to patch affected systems and review their email security postures. This incident highlights an ongoing trend of state-sponsored groups targeting core enterprise email systems via unknown or unpatched flaws. As attackers increasingly adapt to evolving defenses and zero-day vulnerabilities, organizations must prioritize rapid patch management and enhance segmentation and monitoring strategies against persistent, sophisticated threats.
6 months ago
Kill Chain
E-Note Crypto Exchange Seized: $70M Ransomware Laundering Operation Disrupted
In December 2025, U.S. law enforcement agencies, in collaboration with Finnish and German authorities, seized the E-Note cryptocurrency exchange after investigating its role in facilitating ransomware-related money laundering. The FBI identified that over $70 million in proceeds from ransomware attacks and account takeover operations were funneled through E-Note since 2017, relying on a broad, international money mule network. The operation involved confiscating E-Note’s domains, mobile applications, servers, and transaction databases, severely disrupting a key enabling service for cybercriminals and potentially exposing a wide array of threat actors utilizing the platform. The alleged operator, Mykhalio Petrovich Chudnovets, has been indicted for money laundering and faces significant penalties. The takedown of E-Note highlights growing law enforcement action against illicit cryptocurrency infrastructure used by ransomware operators and cybercriminal ecosystems. The incident exemplifies an intensifying focus on disrupting financial channels that allow attackers to monetize stolen data and ransom payments, signaling increasing risk for enablers and users of such services.
6 months ago
Kill Chain
Automated Credential Attacks Storm Cisco & Palo Alto Networks VPNs
In December 2025, automated credential attacks targeted enterprise VPN gateways from Cisco and Palo Alto Networks. Threat monitoring platforms such as GreyNoise observed a surge of password spraying attempts, with 1.7 million login probes against Palo Alto GlobalProtect portals within 16 hours, and coordinated activity later targeting Cisco SSL VPNs. The attacks originated from over 10,000 unique IPs, predominantly routed through the 3xK GmbH cloud provider in Germany. Attackers employed scripted credential stuffing—leveraging common username and password combinations—to probe for weak authentication endpoints, with no evidence of software vulnerabilities being exploited. This campaign highlights the ongoing evolution and scale of credential-based attacks targeting critical remote access infrastructure. As password spraying and automated reconnaissance increase, robust authentication and monitoring remain pivotal to defending against perimeter breaches, especially as threat actors exploit enterprise weaknesses during periods of heightened cyber activity.
6 months ago
Kill Chain
HPE OneView 2025: CVE-2025-37164 Remote Code Execution Threat
In June 2025, Hewlett Packard Enterprise (HPE) patched a critical vulnerability (CVE-2025-37164) in its OneView infrastructure management software, allowing unauthenticated remote code execution via network exposure. Rated CVSS 10.0, the flaw enabled threat actors to gain full control over affected systems by exploiting improper input validation in OneView’s remote management interfaces. This vulnerability posed immediate risk to critical infrastructure across industries relying on OneView for centralized management, potentially resulting in disruption, unauthorized access, or lateral movement within enterprise environments. The discovery highlights ongoing concerns around enterprise software supply chain security and the elevated threats facing privileged IT management tools. Increasingly, sophisticated threat actors target such infrastructure software to bypass traditional security controls, emphasizing the urgency for timely patching and advanced east-west traffic controls.
6 months ago
Kill Chain
University of Sydney 2024 Data Breach Exposes Student and Staff Details
In June 2024, the University of Sydney disclosed a data breach following unauthorized access to an online coding repository. Attackers exfiltrated files containing personal information of students and staff by exploiting weak access controls on the system. The breach was identified after suspicious activity was detected, prompting immediate investigation and containment steps by the university. Impacted data reportedly includes names, contact details, and university credentials, potentially exposing the affected individuals to heightened phishing and identity theft risks. This breach underscores increasing attacks on educational institutions using supply chain and cloud repository vectors. With universities under pressure to rapidly digitize, protecting developer and collaboration tools has become critical amid surging credential-based attacks and regulatory scrutiny of personally identifiable information (PII) handling.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports