Validated Containment Architectures are here. →Explore

Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2383 threat reports
Page 145 of 199

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Government Administration Threat Reports

Showing 17291740 / 2383 reports
Iskra iHUB 2025: Missing Authentication Exposes Critical Energy Infrastructure
Impact· medium

Iskra iHUB 2025: Missing Authentication Exposes Critical Energy Infrastructure

In December 2025, a critical vulnerability (CVE-2025-13510) was disclosed for Iskra iHUB and iHUB Lite smart metering gateways, extensively used in the global energy sector. The devices exposed a web management interface lacking authentication, allowing remote attackers to reconfigure settings, update firmware, or manipulate connected systems without needing valid credentials. Reported by researcher Souvik Kandar and publicized by CISA, the issue affected all versions of these products, placing energy utilities at heightened risk. Successful exploitation could compromise grid operations, disrupt data collection, and enable broader attacks on critical infrastructure. This incident underscores the persistent risk of weak or missing authentication in industrial control systems amid heightened regulatory scrutiny. As similar vulnerabilities drive attacks on critical infrastructure worldwide, energy sector organizations must urgently reevaluate their security postures against remotely exploitable threats and adopt robust access controls in alignment with zero trust principles.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Critical RCE Flaw in Industrial Video & Control Longwatch Threatens Global OT Networks
Impact· medium

Critical RCE Flaw in Industrial Video & Control Longwatch Threatens Global OT Networks

In December 2025, a critical remote code execution vulnerability (CVE-2025-13658) was discovered in Industrial Video & Control’s Longwatch systems (versions 6.309 to 6.334). An unauthenticated attacker could exploit a lack of access controls and code signing via an exposed HTTP endpoint, gaining SYSTEM-level privileges across vulnerable energy and water infrastructure deployments worldwide. This exploitation method requires minimal technical expertise and impacts operational technology (OT) integrity in sectors fundamental to public safety. This vulnerability exemplifies persistent gaps in OT device security and comes amid heightened global concerns around the security of essential infrastructure. With regulatory scrutiny and sophistication of attacker tactics increasing, organizations must urgently address privilege escalation routes and remote code execution exposures within their ICS/SCADA environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Ransomware Halts CodeRED Emergency Alert System in 2024
Impact· high

Ransomware Halts CodeRED Emergency Alert System in 2024

In June 2024, the CodeRED emergency alert platform experienced a major operational disruption after being targeted by the Inc ransomware gang. Attackers infiltrated the organization's systems, encrypted critical servers, and exfiltrated sensitive subscriber data, causing CodeRED to take its emergency alert services offline. Initial entry occurred through a phishing campaign, allowing lateral movement and the deployment of ransomware across east-west traffic. The attack compromised both the confidentiality and availability of data, significantly impacting public safety communication in affected regions. This incident highlights the escalating threat ransomware groups pose to critical infrastructure and public safety technology providers. As attackers target essential services with increasingly sophisticated methods, robust east-west security controls, zero trust segmentation, and real-time threat detection have become urgent priorities for organizations in all sectors.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
SharePoint 2025: ToolShell In-Memory Exploit Bypasses Defenses
Impact· low

SharePoint 2025: ToolShell In-Memory Exploit Bypasses Defenses

In August 2025, Microsoft SharePoint servers were targeted by an advanced exploit chain known as ToolShell, leveraging newly disclosed vulnerabilities CVE-2025-53770 and CVE-2025-53771. Threat actors bypassed authentication and exploited deserialization flaws on on-premises SharePoint Server 2016, 2019, and Subscription editions. Initial attacks involved file-based web shells easily detected by EDRs, but adversaries quickly shifted to highly evasive in-memory payloads, rendering detection challenging and enabling the extraction of machine keys or the execution of PowerShell commands for data exfiltration and deeper system compromise. The incident underscores the growing risks of sophisticated post-exploit activity and lack of robust network detection. This breach highlights a wider threat: attackers are increasingly adapting their techniques to evade endpoint protections by using fileless, memory-resident malware and targeting enterprise collaboration platforms. As such attack patterns spread, organizations must urgently reinforce defenses and monitor network-level traffic for signs of exploitation, especially with remote work and critical business data gravitating to such platforms.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Tomiris Unleashes 'Havoc': 2024 CIS Government Cyber-Espionage Explained
Impact· medium

Tomiris Unleashes 'Havoc': 2024 CIS Government Cyber-Espionage Explained

In early 2024, the Russian-speaking APT group Tomiris launched a sophisticated cyber-espionage campaign targeting government and diplomatic organizations in several CIS nations and Central Asia. Attackers leveraged new malware tools and refined tactics, initially gaining access via spear-phishing and malicious email attachments designed to exploit trust within diplomatic correspondence chains. Once inside, the group deployed covert tools for lateral movement, maintained persistence, and exfiltrated sensitive diplomatic communications and internal documents. The breach had significant operational security implications, exposing strategic discussions and potentially undermining ongoing government initiatives. This incident exemplifies the ongoing risk posed by advanced persistent threats in geopolitical hotspots, with Tomiris demonstrating evolving tradecraft and adaptability. Organizations are urged to review east-west security, segmentation, and monitoring practices as similar espionage campaigns are increasingly targeting public sector networks.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Google Issues Urgent Patch for 107 Android Vulnerabilities, Two Actively Exploited Zero-Days
Impact· high

Google Issues Urgent Patch for 107 Android Vulnerabilities, Two Actively Exploited Zero-Days

In December 2025, Google released a significant Android security update that addressed 107 vulnerabilities, including two zero-day flaws (CVE-2025-48633 and CVE-2025-48572) already being actively exploited in the wild. These high-severity issues in the Android framework allowed threat actors to access sensitive information and escalate privileges, posing a substantial threat to user data and device functionality. The update also remedied several critical vulnerabilities impacting the kernel, system, and multiple vendor components such as MediaTek, Unisoc, and Qualcomm. This incident highlights the intricate security landscape of mobile operating systems and the evolving tactics of cyber adversaries in exploiting vendor fragmentation and delayed patch cycles. The breadth and urgency of this patch reflects growing concerns around mobile platform vulnerabilities, especially as targeted exploitation of zero-days intensifies. With attackers rapidly leveraging gaps before they’re widely recognized or patched, organizations face increased pressure to maintain real-time vulnerability management and swift patch deployment to minimize exposure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Authorities Dismantle Cryptomixer: $28 Million in Bitcoin Seized Amid Europol-Led Takedown
Impact· medium

Authorities Dismantle Cryptomixer: $28 Million in Bitcoin Seized Amid Europol-Led Takedown

In June 2024, European authorities executed a coordinated operation to dismantle Cryptomixer, a cryptocurrency mixing service reportedly used to launder over $1.5 billion for global cybercriminals. Operation Olympia involved Europol, Eurojust, and law enforcement agencies from Germany and Switzerland, resulting in the seizure of nearly $28 million in Bitcoin, three physical servers, the cryptomixer.io domain, and over 12 terabytes of data. Cryptomixer functioned as an anonymizing layer for a multitude of cybercrimes, including ransomware, payment card fraud, and trafficking in illicit goods, allowing threat actors to evade detection and launder stolen assets. This takedown demonstrates mounting regulatory and law enforcement pressure on cryptocurrency-based money laundering infrastructure. The case highlights a shift among advanced threat groups—such as the North Korean Lazarus Group—from prioritizing anonymity to speed and automation in financial cybercrime operations, reflecting evolving cybercriminal tactics and the urgent need for robust digital asset tracking controls.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ShadyPanda: 4.3 Million Impacted in Massive Malicious Browser Extension Attack (2024)
Impact· medium

ShadyPanda: 4.3 Million Impacted in Massive Malicious Browser Extension Attack (2024)

In early 2024, the ShadyPanda campaign targeted users of Chrome and Edge browsers by distributing over 4.3 million malicious extensions disguised as legitimate utilities. Attackers leveraged browser extension supply chains—often through fraudulent developer accounts and aggressive social engineering—to gain access to users’ browsing data, credentials, and sensitive online activity. The malware evolved over time, adapting to evade security controls and harnessing sophisticated capabilities to extract data, redirect web sessions, and facilitate persistent surveillance, affecting millions globally and highlighting gaps in browser marketplace vetting. This incident exemplifies a rapid escalation in supply-chain attacks focusing on widely used platforms like web browsers. The surge in malicious browser extension campaigns underscores the increasing sophistication of threat actors and the urgent need for organizations and individuals to be vigilant about third-party software, browser hygiene, and visibility into user-installed code.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Tomiris Leverages Public-Service Implants for Stealthy Government Attacks
Impact· low

Tomiris Leverages Public-Service Implants for Stealthy Government Attacks

In late 2025, the state-sponsored threat actor Tomiris escalated its attacks against government entities and intergovernmental organizations, primarily in Russia and neighboring regions. The group notably shifted its tactics by deploying custom remote access implants that leveraged public cloud services, such as Telegram and Discord, as command-and-control (C2) channels. This allowed Tomiris to disguise their network traffic among legitimate service use, evading conventional perimeter defenses and security controls. The compromise enabled attackers to maintain persistent access, deploy additional payloads, and potentially exfiltrate sensitive diplomatic and policy data. This incident is significant due to its demonstration of the evolving sophistication in APT tactics: the use of ubiquitous public platforms for C2, making detection and attribution harder. It also highlights the urgency for zero trust architectures, enhanced traffic monitoring, and cloud-centric security controls as industries face an increase in nation-state and intelligence-motivated threats.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CISA Flags OpenPLC ScadaBR XSS Flaw (CVE-2021-26829) as Actively Exploited in ICS Environments
Impact· low

CISA Flags OpenPLC ScadaBR XSS Flaw (CVE-2021-26829) as Actively Exploited in ICS Environments

In June 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2021-26829—a cross-site scripting (XSS) vulnerability affecting OpenPLC ScadaBR software—to its Known Exploited Vulnerabilities catalog following evidence of active exploitation. The flaw impacts both Windows and Linux versions of ScadaBR, a commonly used open-source SCADA platform. Attackers leveraged the XSS flaw to execute arbitrary scripts, posing significant risk to system integrity and exposing critical infrastructure operators to potential business disruption, data compromise, and malicious control of automation processes. This incident reflects the growing trend of adversaries targeting industrial control systems (ICS) via supply chain and application-layer vulnerabilities. With regulatory scrutiny rising and CISA actively tracking exploited flaws, securing OT and SCADA environments is critical to mitigate operational and safety risks posed by unpatched vulnerabilities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
November 2025 Cybersecurity Review: Akira, Operation Endgame, and AI Data Exposure
Impact· medium

November 2025 Cybersecurity Review: Akira, Operation Endgame, and AI Data Exposure

In November 2025, the cybersecurity landscape was rocked by a surge of major incidents spanning data exposure at leading AI companies, a high-profile ransomware campaign by the Akira gang, and an unprecedented law enforcement operation targeting prolific malware families. Attackers leveraged advanced lateral movement and encryption bypass techniques, with Akira exfiltrating critical business data and setting new records for ransom hauls. Meanwhile, Operation Endgame—an international collaborative effort—dismantled several prominent malware botnets, arresting key operators and seizing digital infrastructure, all while organizations scrambled to contain threats and patch vulnerabilities across multi-cloud and hybrid environments. This period highlights a convergence of advanced extortion, data privacy, and large-scale coordinated response, reflecting escalating threat sophistication and the increasing pressure on organizations to meet evolving compliance and security demands.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AI-Fueled LLMs Put Advanced Attacks in Reach for Novice Hackers (2024)
Impact· medium

AI-Fueled LLMs Put Advanced Attacks in Reach for Novice Hackers (2024)

In early 2024, cybersecurity researchers observed a surge in the use of malicious, unrestricted large language models (LLMs) such as WormGPT 4 and KawaiiGPT. These AI-powered tools have been weaponized to generate sophisticated attack scripts—including ransomware encryptors and custom code for lateral movement—allowing even low-skilled threat actors to execute complex cyberattacks. Access to these malicious LLMs was facilitated via underground markets, democratizing advanced techniques and increasing the frequency and complexity of attacks targeting organizations across multiple sectors. This incident underscores a growing trend where AI-enabled cyber threats lower the barrier to entry for attackers. As malicious LLMs gain capabilities and proliferation increases, organizations face heightened risks from a new wave of adversaries and must adapt their defenses to address evolving, AI-driven tactics.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports