Validated Containment Architectures are here. →Explore

Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2383 threat reports
Page 139 of 199

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Government Administration Threat Reports

Showing 16571668 / 2383 reports
Critical GDCM Vulnerability Risks Healthcare Medical Imaging Workflows
Impact· high

Critical GDCM Vulnerability Risks Healthcare Medical Imaging Workflows

In December 2025, a significant vulnerability was disclosed in the Grassroots DICOM (GDCM) library, a critical open-source imaging component widely used in healthcare systems worldwide. Identified as CVE-2025-11266, this out-of-bounds write vulnerability could be triggered by simply opening a specially-crafted DICOM file, potentially crashing affected applications such as SimpleITK and medInria. The flaw, present in versions GDCM 3.0.24 and earlier, allows for denial-of-service and partial data and integrity impacts, increasing operational risk for healthcare environments that rely on medical imaging interoperability. This incident highlights the persistent risk posed by vulnerable third-party libraries in regulated industries like healthcare. The rise in supply chain threats and software dependencies magnifies the urgency for organizations to maintain rigorous patching practices and robust segmentation, as attackers increasingly target widely-deployed open-source components to disrupt critical services.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Johnson Controls iSTAR Ultra Vulnerabilities: 2025 Exposure of OT Systems
Impact· medium

Johnson Controls iSTAR Ultra Vulnerabilities: 2025 Exposure of OT Systems

In December 2025, Johnson Controls publicly disclosed critical vulnerabilities (CVE-2025-43873 and CVE-2025-43874) affecting several versions of its iSTAR Ultra and Edge G2 door controllers used in building automation across critical infrastructure sectors worldwide. These OS Command Injection flaws, exploitable remotely with low attack complexity and minimal user interaction, could allow attackers to gain full control of vulnerable devices, modify firmware, and potentially disrupt or compromise secure building environments. The vulnerabilities were responsibly reported by Reid Wightman of Dragos, and patches have been made available for affected products. This incident highlights increasing threats targeting operational technology (OT) in critical sectors, as cybercriminals and nation-state actors leverage software supply chain and device-level weaknesses for initial access. The prevalence of command injection vulnerabilities, coupled with rising demands for segmentation and zero trust architectures, elevates the urgency for organizations to update OT and IoT assets and enforce proactive defense strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Authentication Bypass Exposes Siemens Gridscale X Prepay ICS: 2025 Breach Analysis
Impact· low

Authentication Bypass Exposes Siemens Gridscale X Prepay ICS: 2025 Breach Analysis

In December 2025, Siemens disclosed critical vulnerabilities impacting its Gridscale X Prepay solution, widely used in energy infrastructure. The flaws—an observable response discrepancy (CVE-2025-40806) and authentication bypass via capture-replay (CVE-2025-40807)—could allow remote attackers to enumerate valid user names and circumvent lockouts, compromising operational security. Discovered by Kira of The Raven Security and coordinated via Siemens ProductCERT and CISA, these issues placed globally deployed ICS systems at risk of unauthorized access by leveraging predictable system responses and token replay, potentially impacting sensitive control environments. This incident highlights an ongoing trend of attackers exploiting authentication weaknesses in industrial control systems, underscoring the need for strict access management and timely vulnerability mitigation. With ICS assets increasingly targeted and regulatory scrutiny rising, implementing robust segmentation and monitoring is more crucial than ever.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Shanya Packer-as-a-Service: Ransomware’s New Obfuscation Arsenal
Impact· high

Shanya Packer-as-a-Service: Ransomware’s New Obfuscation Arsenal

In May 2024, security researchers uncovered an emerging Packer-as-a-Service (PaaS) called Shanya, designed to help ransomware operators evade modern enterprise defenses. Shanya provides advanced payload obfuscation capabilities to threat actors, enabling the delivery of ransomware that bypasses endpoint detection and response (EDR) solutions. Attackers using Shanya can rapidly pack malware before deployment, making it harder to analyze and detect. Early incidents showed Shanya-packed ransomware used to swiftly gain lateral movement across compromised environments, disrupt business operations, and facilitate significant data encryption and extortion campaigns. The rise of packers like Shanya signals a growing trend: ransomware groups are leveraging SaaS-style services to increase automation, evasion, and reach. With increased regulatory scrutiny on incident response and a surge in ransomware targeting sectors with critical operations, businesses must urgently strengthen detection and response strategies to address evolving malware delivery techniques.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
CISA & MITRE Unveil 2025 CWE Top 25: The Most Dangerous Software Weaknesses
Impact· medium

CISA & MITRE Unveil 2025 CWE Top 25: The Most Dangerous Software Weaknesses

On December 11, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) and MITRE's HSSEDI jointly released the 2025 CWE Top 25 Most Dangerous Software Weaknesses advisory. This annual compilation highlights the most critical security flaws that are routinely exploited by adversaries to gain unauthorized access, exfiltrate sensitive data, or disrupt operations. The advisory urges software vendors, developers, and enterprise security teams to integrate the Top 25 into their vulnerability management, procurement, and secure development practices, as the listed weaknesses are a leading cause of breaches and operational disruptions sector-wide. The 2025 iteration of the list arrives amid a surge in high-profile breaches linked to software supply chain vulnerabilities and regulatory pressure for Secure by Design practices. Organizations that fail to address these prevalent weaknesses remain at heightened risk of data compromise, operational downtime, and non-compliance with modern security frameworks.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft’s 2024 Zero-Day Exploitation: What Security Leaders Must Know
Impact· medium

Microsoft’s 2024 Zero-Day Exploitation: What Security Leaders Must Know

In June 2024, Microsoft released security updates addressing a critical zero-day vulnerability (CVE-2024-30051) that was actively exploited in the wild, targeting Windows operating systems. Threat actors leveraged this privilege escalation flaw to bypass security controls and gain elevated access privileges on compromised systems, potentially enabling further malware deployment and lateral movement. Nearly 50 vulnerabilities were patched in this cycle, with public proof-of-concept code available for several, raising the risk of rapid exploitation by cybercriminal groups and nation-state actors before widespread patch deployment. This incident underscores the persistent threat of zero-day vulnerabilities, the speed at which exploits circulate once publicly disclosed, and the substantial business risk posed to enterprises delaying patch management. Increasing regulatory scrutiny and evolving attack techniques demand urgent, proactive defense strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Storm-0249's Abuse of EDR Processes: A New Era of Stealth Attacks
Impact· low

Storm-0249's Abuse of EDR Processes: A New Era of Stealth Attacks

In early 2024, threat actor Storm-0249 launched a series of stealthy attacks by weaponizing Endpoint Detection and Response (EDR) platforms alongside native Windows utilities. As an initial access broker, the group circumvented traditional EDR defenses to gain persistent entry into multiple enterprise environments. Leveraging legitimate EDR processes for their own activities, Storm-0249 was able to evade security monitoring, escalate privileges, and facilitate lateral movement. These tactics led to compromised data and footholds that were subsequently sold to other cybercriminal groups, increasing the overall risk for targeted organizations. The emergence of sophisticated actors repurposing security tools for malicious objectives highlights an urgent industry focus on advanced detection, segmentation, and the continual evolution of zero trust strategies. This incident reflects a growing trend: motivated threat groups exploiting trusted processes to blend in and extend dwell time inside modern network environments.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Microsoft December 2025 Patch Tuesday: Critical & Exploited Vulnerabilities Exposed
Impact· low

Microsoft December 2025 Patch Tuesday: Critical & Exploited Vulnerabilities Exposed

In December 2025, Microsoft addressed 57 vulnerabilities as part of its Patch Tuesday update, including three critical flaws and one (CVE-2025-62221) already being actively exploited. The vulnerabilities spanned across numerous Microsoft products such as Office, Outlook, Exchange, PowerShell, and the Windows Cloud Files Mini Filter driver. Notably, CVE-2025-64671 affected GitHub Copilot plugins for JetBrains, potentially enabling remote code execution via AI-driven code assistance. Attackers exploited privilege escalation and remote-code execution vectors, posing significant risks to system integrity and user data. The rapid disclosure and exploitation of some flaws before patches were available highlighted increasing attacker sophistication and speed. Incidents such as this emphasize the urgent need for timely patch management, especially as software supply chains and AI integrations become more prevalent. Security teams must remain vigilant against fast-emerging threats, as even mainstream platforms like Microsoft continue to face ongoing and complex exploitation attempts.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Kubernetes NodeLogQuery (CVE-2024-9042): Command Injection Exploit Hits Windows Nodes
Impact· low

Kubernetes NodeLogQuery (CVE-2024-9042): Command Injection Exploit Hits Windows Nodes

In late 2024, a command injection vulnerability in Kubernetes' NodeLogQuery feature (CVE-2024-9042) was actively exploited, primarily impacting clusters running Windows nodes with log read permissions enabled. Attackers leveraged the '/logs/' API endpoint, injecting operating system commands via GET parameters or path elements to gain unauthorized system access. Victims included enterprise environments utilizing the beta NodeLogQuery feature, which was not enabled by default. The exploit techniques involved turning Kubernetes' logging capabilities into a remote code execution avenue, exposing sensitive workloads to further compromise and potential lateral movement. This incident underscores a broader trend in targeting Kubernetes clusters at the API layer, as adversaries evolve their exploitation of cloud-native misconfigurations and insecure default settings. The attack highlights the need for enhanced east-west traffic controls, static analysis of cluster policies, and real-time anomaly detection to intercept emerging exploitation patterns in cloud and hybrid infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Ashen Lepus Strikes: 2025 APT Breach Unveils Advanced Espionage Across Middle Eastern Diplomatic Targets
Impact· medium

Ashen Lepus Strikes: 2025 APT Breach Unveils Advanced Espionage Across Middle Eastern Diplomatic Targets

In late 2025, a Hamas-affiliated APT group known as Ashen Lepus (also referred to as WIRTE) executed a sophisticated cyber-espionage campaign targeting governmental and diplomatic organizations across multiple Middle Eastern countries. The attackers leveraged a novel modular malware suite called AshTag, delivered through decoy documents, DLL sideloading, and a carefully staged infection chain. The campaign made extensive use of in-memory payload delivery, advanced encryption, legitimate-themed subdomains for C2 communications, and the abuse of widely used file transfer tools like Rclone to exfiltrate sensitive, often diplomacy-related data. This incident marks a notable evolution in the operational security and technical sophistication of Middle Eastern espionage campaigns. It highlights the rising use of modular malware, infrastructure blending, and legitimate protocol abuse by regionally motivated threat actors, underscoring a trend where state-linked groups continue cyber operations despite geopolitical turmoil or ceasefires.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Microsoft Patches Critical Zero-Day in Windows: December 2025 Security Update
Impact· medium

Microsoft Patches Critical Zero-Day in Windows: December 2025 Security Update

In December 2025, Microsoft issued patches for 57 vulnerabilities across its product suite as part of its final Patch Tuesday of the year. Notably, the release addressed an actively exploited zero-day vulnerability, CVE-2025-62221, impacting the Windows Cloud Files Mini Filter Driver. This use-after-free flaw, with a CVSS score of 7.8, allowed attackers to potentially gain system-level privileges when chained with code execution bugs. Affecting all supported versions of Windows, the vulnerability drew immediate attention from CISA and the cybersecurity community due to its presence in production environments and ongoing exploitation. The incident underscores a persistent trend of attackers targeting foundational Windows components through privilege escalation and memory management bugs. With the rising complexity of Microsoft’s ecosystem and a continued increase in vulnerabilities—especially as AI-related issues proliferate—organizations face growing pressure to rapidly deploy patches and strengthen monitoring against sophisticated exploits.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Ukrainian Hacker Charged: Russian Hacktivist Attacks Underscore U.S. Critical Infrastructure Risks
Impact· high

Ukrainian Hacker Charged: Russian Hacktivist Attacks Underscore U.S. Critical Infrastructure Risks

In 2024, U.S. authorities charged a Ukrainian national for collaborating with Russian state-sponsored hacktivist groups in a series of high-profile cyberattacks against critical infrastructure. The targeted sectors included U.S. water systems, election infrastructure, and nuclear facilities. Leveraging advanced intrusion tools and lateral movement tactics, the attacker contributed to sophisticated campaigns aimed at espionage, disruption, and potential sabotage. These efforts underscore the persistent threat posed by coordinated state-aligned cyber actors and the increasing risk to essential public services worldwide. This case highlights how modern threat actors are expanding their focus from traditional targets to critical infrastructure with geo-political motives. The intersection of hacktivism, nation-state support, and escalating global tensions demands greater cyber defense readiness and robust compliance from both private and public sectors.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports