✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Sha1-Hulud 2025: The Multi-Vector Threat Campaign that Redefined Cloud Security
In December 2025, security researchers observed a sophisticated multi-vector attack campaign, dubbed 'Sha1-Hulud,' targeting organizations across North America, Europe, and Asia. The campaign leveraged vulnerabilities in remote management tools such as ScreenConnect and MacSync to gain initial access, then proceeded laterally using encrypted traffic, zero trust segmentation evasion, and cloud-native pivoting. Attackers deployed covert remote access tools and exploited gaps in cloud firewall and egress controls to move data out, leaving organizations grappling with data theft, systems downtime, and regulatory exposure. This incident is notable for its integration of advanced encryption bypass, multicloud movement, and the blending of traditional and cloud-native evasion tactics. The convergence of infrastructure and cloud threats highlights the need for ubiquitous visibility, modern segmentation, and coordinated policy enforcement in response to increasingly diverse and distributed attacks.
6 months ago
Kill Chain
Axis Communications 2025: Critical Camera System Vulnerabilities Threaten OT Security
In December 2025, Axis Communications disclosed multiple critical vulnerabilities affecting their Camera Station Pro, Camera Station, and Device Manager products. The issues, discovered by cybersecurity researchers from Claroty Team82, include flaws such as deserialization of untrusted data, improper certificate validation, authentication bypass, and local privilege escalation. These vulnerabilities could allow an attacker to remotely execute arbitrary code, intercept communications via man-in-the-middle attacks, or bypass authentication mechanisms, significantly compromising the security posture of organizations using these systems globally. Patches are now available and users are urged to upgrade immediately. This incident highlights a growing trend in targeting surveillance and control infrastructure, reflecting the increased attention threat actors are placing on operational technology and critical manufacturing environments. The convergence of IT and OT risks, as well as heightened regulatory expectations, make robust security controls for IoT and camera systems more critical than ever.
6 months ago
Kill Chain
Advantech WebAccess/SCADA 2025: Critical Vulnerabilities Threaten Industrial Control Systems
In December 2025, critical vulnerabilities were disclosed in Advantech WebAccess/SCADA software (version 9.2.1), widely used across critical manufacturing, energy, and water infrastructure worldwide. Discovered by Pellera Technologies, the weaknesses included multiple instances of path traversal (CVE-2025-14850, CVE-2025-67653, CVE-2025-14848), unrestricted file upload (CVE-2025-14849), and SQL injection (CVE-2025-46268). Exploitation could enable a remote, authenticated attacker to read or modify sensitive database content, delete files, or execute arbitrary code on impacted systems, significantly increasing cyber-physical risk for operations. Advantech advised immediate upgrades to v9.2.2 to remediate these flaws. This incident underscores ongoing challenges in the security of industrial control systems amid rising cyber threats targeting critical infrastructure. With no current evidence of public exploitation, practitioners must remain vigilant due to the highly impactful nature of the vulnerabilities and their corresponding attack surface across essential industries.
6 months ago
Kill Chain
Cellik RAT’s Google Play Store Infiltration Exposes Mobile Security Gaps
In June 2024, cybersecurity researchers uncovered that the Cellik Android Remote Access Trojan (RAT) was being distributed through malicious applications on the official Google Play Store. The Cellik RAT allows attackers to remotely control infected Android devices, harvest sensitive credentials, and exfiltrate private data without the user’s knowledge. Threat actors used advanced evasion tactics, including app generation within Play Store guidelines and encrypted communications, to bypass traditional defenses. The incident highlights weaknesses in mobile app review processes and demonstrates the continued use of popular app stores as distribution vectors for sophisticated malware campaigns. This breach is especially notable as attackers continue to exploit trusted platforms like the Google Play Store, elevating risk for both individuals and enterprises. The emergence of Cellik marks an uptick in mobile RAT sophistication and underscores the urgent need for stronger app vetting and threat detection on mainstream digital ecosystems.
6 months ago
Kill Chain
Critical Fortinet Flaws: Active Attacks Compromise Admin Accounts & Configs
In May 2024, threat actors began actively exploiting multiple critical vulnerabilities in Fortinet network devices, specifically targeting admin accounts to gain unauthorized access. Once authenticated, attackers exported sensitive device configurations containing hashed credentials and other proprietary information. The exploit allows lateral movement and increases the risk of sensitive enterprise data exposure, with widespread impacts noted across sectors relying on network infrastructure security. Fortinet urged immediate mitigation after observing attacks in the wild, with rapid patch releases and threat intelligence sharing. This incident highlights a concerning trend of attackers leveraging zero-day or freshly-disclosed vulnerabilities in widely deployed network appliances. As targeting of privileged accounts and network infrastructure rises, organizations must enhance monitoring, patch management, and segmentation strategies to prevent systemic compromise.
6 months ago
Kill Chain
Dormant No More: Prince of Persia APT's Sophisticated Espionage Tactics Unveiled in 2025
In December 2025, security researchers revealed that the dormant Iranian advanced persistent threat (APT) group "Prince of Persia" (also known as "Infy") had remained operational for years, despite perceived inactivity. Leveraging upgraded versions of their Foudre and Tonnerre malware families, the group engaged in persistent cyber espionage targeting Iranian dissidents, as well as individuals in Iraq, Turkey, India, Europe, and Canada. The attackers employed advanced cryptographic techniques for command-and-control (C2) communication—such as RSA signature verification for dynamically generated C2 domains and Telegram-based channels—enabling stealthy, resilient infrastructure and evading traditional detection or takedown efforts. The group’s sophisticated use of operational security, government support, and resilient infrastructure sets it apart from typical regional APTs. This incident underscores increasing sophistication among state-backed APT groups and highlights modern approaches to persistence and evasion, particularly as threat actors adopt novel uses of cryptography and messaging platforms for infrastructure protection. It warns organizations worldwide to review their readiness against stealthy advanced campaigns that evade known countermeasures.
6 months ago
Kill Chain
React2Shell Breach: 2025’s Most Widespread Mass Exploitation Campaign
In December 2025, the React2Shell vulnerability (CVE-2025-55182) triggered a global mass exploitation campaign targeting organizations across critical infrastructure, government, and private sectors. Following public disclosure, a record number of exploits surfaced, enabling unauthenticated attackers to gain remote code execution, deploy backdoors, and move laterally within networks. High-profile cybercriminal, ransomware, and nation-state actors—including several Chinese espionage groups—converged to leverage React2Shell for data theft, ransomware deployment, and persistent access. More than 60 organizations confirmed compromise, with hundreds of machines affected, some suffering rapid ransomware execution within minutes of initial access. This incident is notable for both its rapid exploitation timeline and evolving threat actor diversity. The widespread availability of public exploits and patch bypasses underscores the urgent need for robust patch management, active detection, east-west traffic controls, and zero trust segmentation as attackers swiftly weaponize newly disclosed vulnerabilities at unprecedented speed.
6 months ago
Kill Chain
Microsoft 2025 MSMQ and IIS Outage: A Cautionary Tale of Security Permissions Gone Wrong
In December 2025, Microsoft enterprise customers experienced widespread outages in applications and IIS web services following the deployment of Patch Tuesday updates (KB5071546, KB5071544, KB5071543). These updates introduced changes to the Message Queuing (MSMQ) security model, restricting NTFS permissions on the C:\Windows\System32\MSMQ\storage folder. As a result, non-administrator MSMQ users lost write access, causing MSMQ to fail and IIS sites to return misleading 'insufficient resources' errors. This affected core business processes dependent on MSMQ, with no immediate fix available; Microsoft urged affected organizations to reach out for mitigation guidance. This incident highlights ongoing risks from software supply chain updates and privileged permission management changes at the operating system level. As cloud workloads and zero-trust architectures become more prevalent, enterprises must strengthen configuration management and anomaly response to avoid business disruption from untested or misconfigured OS-level security changes.
6 months ago
Kill Chain
DOJ Takes Down E-Note: Ransomware Laundering Hub Disrupted in 2024 Crackdown
In early 2024, the US Department of Justice, in partnership with international law enforcement, dismantled the E-Note cryptocurrency exchange—a major online infrastructure used for laundering illicit proceeds from ransomware and cybercrime. Authorities indicted Mykhalio Petrovich Chudnovets, a Russian national alleged to have operated E-Note since 2010, with facilitating the transfer of over $70 million in stolen or extorted funds from attacks targeting sectors like healthcare and critical infrastructure. Federal and state agencies seized E-Note servers, websites, and mobile apps, obtaining customer and transaction data to further map criminal networks. This takedown highlights cybercriminals’ growing use of specialized laundering platforms to enable ransomware and account takeover monetization at scale. As regulatory scrutiny intensifies and attacker infrastructure becomes more modular and resilient, law enforcement action against these enablers is an increasing priority.
6 months ago
Kill Chain
WhatsApp GhostPairing: How Device Linking Fueled 2024 Account Hijacks
In mid-2024, threat actors launched a sophisticated social engineering campaign dubbed 'GhostPairing' to hijack WhatsApp accounts by abusing the platform's legitimate device-linking feature. Attackers initiated account compromise by tricking victims into sharing pairing codes, which allowed unauthorized access to their WhatsApp accounts on new devices without triggering standard multi-factor authentication. Once inside, attackers could impersonate victims, access chat histories, and leverage compromised accounts for further malicious activity. The attack exploited inherent trust in WhatsApp's device linking and its secure communication channels, highlighting risks even in end-to-end encrypted environments. This incident underscores the growing trend of attackers subverting user authentication processes, exploiting legitimate features for account takeover, and using highly convincing social engineering methods. With messaging apps central to both business and personal communications, the security and user-awareness gaps demonstrated here remain acutely relevant.
6 months ago
Kill Chain
Cisco 2025 AsyncOS Zero-Day: UAT-9686 Exploitation of Email Gateway Appliances
In late November 2025, Cisco discovered a major cybersecurity incident involving active exploitation of an unpatched zero-day vulnerability (CVE-2025-20393) in its AsyncOS operating system, impacting Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances. The flaw, leveraged exclusively on internet-facing appliances with non-standard configurations, enables remote code execution as root when the Spam Quarantine feature is exposed. Attribution points to UAT-9686, a Chinese-nexus advanced persistent threat actor, utilizing malware such as AquaShell, AquaTunnel, Chisel, and AquaPurge for backdoor access, lateral movement, and log deletion. The campaign has resulted in persistent compromise, requiring full appliance rebuilds for remediation. This incident underscores the persisting risk that unpatched zero-days pose to enterprise infrastructure, particularly from advanced threat actors using sophisticated malware implant chains. It illustrates a broader industry trend of increasingly swift exploitation of newly discovered vulnerabilities and public toolkits by nation-state actors.
6 months ago
Kill Chain
SonicWall SMA1000 Zero-Day Breach: 2025’s Wake-Up Call for Secure Network Access
In December 2025, SonicWall disclosed active exploitation of two chained zero-day vulnerabilities (CVE-2025-40602 and CVE-2025-23006) in its SMA1000 Appliance Management Console (AMC). Attackers combined a local privilege escalation flaw with a critical pre-authentication deserialization vulnerability to achieve unauthenticated remote code execution with root privileges on exposed appliances. These devices, used by large organizations for secure VPN access, became an attractive target, with at least 950 systems publicly accessible at the time of disclosure. The threats originated from advanced actors leveraging these weaknesses to bypass security controls and gain deep network access. This incident highlights the persistent risk to network infrastructure from zero-day chaining and the ongoing focus of sophisticated attackers on secure remote access gateways. Heightened regulatory focus, increasing state-sponsored attack campaigns, and renewed emphasis on timely patch management are making such incidents highly relevant for CISOs and infrastructure owners today.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports