Validated Containment Architectures are here. →Explore

Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2383 threat reports
Page 149 of 199

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Government Administration Threat Reports

Showing 17771788 / 2383 reports
Matrix Push C2 Phishing Exposes Fileless Browser Attacks in 2025
Impact· medium

Matrix Push C2 Phishing Exposes Fileless Browser Attacks in 2025

In November 2025, a sophisticated phishing campaign was uncovered utilizing a novel command-and-control (C2) platform called Matrix Push C2. The threat actors exploited browser push notifications, fake alerts, and fileless redirection to lure users across multiple operating systems into interacting with malicious links. Researchers observed that the campaign delivered phishing payloads without traditional downloads, thereby evading many endpoint defenses and expanding its cross-platform reach. Impacted organizations reported heightened risks of credential theft, business email compromise, and data exfiltration stemming from the hard-to-detect, browser-native behavior of Matrix Push C2. This incident highlights the escalating threat of fileless attacks and creative social engineering, particularly as businesses increasingly rely on browser-based workflows. The abuse of browser notifications as a phishing vector presents a growing challenge for security teams and underscores the importance of proactive browser and endpoint defenses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
APT31 Orchestrates Stealthy Cloud-Based Attack on Russian IT Firms (2024–2025)
Impact· medium

APT31 Orchestrates Stealthy Cloud-Based Attack on Russian IT Firms (2024–2025)

Between 2024 and 2025, the advanced persistent threat group APT31, linked to China, conducted a series of covert cyberattacks against Russia’s IT sector, specifically targeting firms involved in government contracting. Leveraging cloud services and encrypted traffic, the attackers infiltrated networks while remaining undetected for long periods. APT31 employed sophisticated lateral movement, abuse of multicloud visibility gaps, and zero trust segmentation bypasses, resulting in the exfiltration of sensitive data and potential compromise of government-integrator communication flows. This incident reflects growing tensions and evolving threat tactics in state-sponsored cyberespionage, where cloud infrastructure, stealthy east-west movements, and advanced evasion are exploited. The attack underscores the critical need for enforced segmentation, robust cloud-native security, and proactive anomaly detection to defend against advanced persistent threats targeting the IT supply chain.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
LINE Messaging Bugs Expose Millions to Asian Cyber Espionage in 2024
Impact· high

LINE Messaging Bugs Expose Millions to Asian Cyber Espionage in 2024

In June 2024, security researchers disclosed several critical vulnerabilities in the LINE messaging app, widely used across Asia, arising from its use of a proprietary and flawed cryptographic protocol. The bugs enable attackers to intercept and replay message traffic, impersonate users, and siphon sensitive chat data, despite the app's claims of end-to-end encryption. No specific threat actor has been confirmed, but the flaws create opportunities for state-sponsored espionage and criminal data compromise. The weaknesses persist in both in-app and network-level communication, putting millions of users’ private conversations at risk. This incident highlights the dangers of custom security implementations and is of urgent concern given LINE’s importance in business and personal use across Asia. With attackers increasingly targeting messaging platforms and governments ramping up regulatory scrutiny around privacy and secure communications, organizations must prioritize rigorous security architecture and compliance.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Hacker Exposes 2.3TB in FS Italiane / Almaviva Supply Chain Breach (2024)
Impact· medium

Hacker Exposes 2.3TB in FS Italiane / Almaviva Supply Chain Breach (2024)

In June 2024, a hacker reportedly breached the systems of Almaviva, an Italian IT provider serving FS Italiane Group, the nation’s railway operator. The attacker claimed to have exfiltrated 2.3TB of sensitive corporate data—including documents, contracts, financial information, and communications—garnered by exploiting weaknesses in the supplier’s defenses. Although FS Italiane’s operational technology was not directly compromised, the breach of Almaviva’s infrastructure exposed highly confidential client and business data, raising concerns about third-party risks and data privacy for an array of Italian public sector organizations. This incident highlights a worrying trend of attackers targeting IT services providers as a conduit for large-scale data breaches against critical infrastructure operators. With supply chain vulnerabilities on the rise, organizations must urgently reassess their vendor risk management and network segmentation strategies to prevent similar cascading impacts.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Scattered Spider Strikes: 2024 Transport for London Cyber Breach
Impact· medium

Scattered Spider Strikes: 2024 Transport for London Cyber Breach

In August 2024, Transport for London (TfL), the body responsible for the UK's capital city transit system, suffered a major cyber incident allegedly orchestrated by members of the Scattered Spider cybercriminal group. Attackers exploited weaknesses in TfL's digital infrastructure to gain unauthorized access, compromising sensitive customer data and disrupting critical services. The breach, which resulted in millions of pounds in damages and regulatory scrutiny, underscored the growing threat that organized cybercriminal gangs pose to public-sector organizations. Two British teenagers have since been arrested and charged, though they have pleaded not guilty in court. This incident highlights the increasing trend of skilled threat actors leveraging sophisticated tactics—such as social engineering and lateral movement—to target essential services. Heightened regulatory pressure and public concern reinforce the urgent need for robust cybersecurity measures across critical infrastructure sectors.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
ToddyCat APT: How a Persistent Attacker Breached Outlook and Microsoft 365 Email in 2024
Impact· medium

ToddyCat APT: How a Persistent Attacker Breached Outlook and Microsoft 365 Email in 2024

Between mid-2024 and early 2025, the ToddyCat advanced persistent threat (APT) group executed a sophisticated campaign targeting organizations' internal infrastructures to covertly access business email. Initially leveraging a new PowerShell variant of their TomBerBil tool to extract credentials, cookies, and encryption keys from browsers via SMB on privileged hosts, the group also introduced additional tools—TCSectorCopy and XstReader—to capture locked Outlook OST files and exfiltrate their contents. When detection increased, ToddyCat shifted to harvesting OAuth 2.0 tokens for Microsoft 365 mail through memory dumping, enhancing their ability to bypass on-host monitoring and access cloud emails externally. This campaign resulted in extensive compromise of sensitive correspondence, credentials, and lateral movement across impacted domains. This incident underscores the rapidly evolving tactics of nation-state groups to overcome modern defenses, highlighting trends in cross-cloud compromise, credential harvesting, and exploitation of endpoint-to-cloud trust boundaries. ToddyCat's use of both system-level and identity-driven attacks mirrors the increasing prevalence of multifaceted cyber threat techniques.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Grafana 2025: Critical Admin Spoofing Flaw Demands Immediate Response
Impact· medium

Grafana 2025: Critical Admin Spoofing Flaw Demands Immediate Response

In June 2025, Grafana Labs disclosed a critical security vulnerability (CVE-2025-41115) affecting its Enterprise platform, enabling attackers to register new users and assign them administrator privileges or escalate existing privileges through crafted requests. This flaw made it possible for unauthorized actors to gain full control over instances, potentially compromising sensitive data dashboards and associated integrations. Grafana responded by releasing urgent patches, issuing advisories, and recommending immediate action to all Enterprise customers to prevent exploitation in production environments. This incident is particularly notable given the increasing threat posed by privilege escalation vulnerabilities in widely deployed SaaS and cloud-native products. Enterprises leveraging Grafana or other observability platforms must remain vigilant as attackers increasingly target misconfigurations and logic flaws to bypass identity-based controls and gain elevated access.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CrowdStrike Insider Breach: How Scattered Lapsus$ Exploited Trusted Access in 2024
Impact· high

CrowdStrike Insider Breach: How Scattered Lapsus$ Exploited Trusted Access in 2024

In early 2024, cybersecurity firm CrowdStrike identified an insider threat after discovering that an employee had shared screenshots of internal systems with external threat actors. The images, which were later leaked on Telegram by the Scattered Lapsus$ Hunters group, exposed sensitive details about CrowdStrike’s infrastructure and internal processes. CrowdStrike swiftly conducted an internal investigation, isolated the breach, and collaborated with law enforcement to mitigate potential risks. The incident highlights the growing challenge organizations face in protecting against trusted insiders acting maliciously or under external influence. This breach is particularly relevant given the increasing frequency of insider-driven attacks and the adoption of social engineering by advanced threat groups to bypass traditional perimeter defenses. The incident underscores the need for organizations to enhance their monitoring of internal activities and emphasize zero trust models.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
SolarWinds 2020: Unpacking the Supply Chain Breach and SEC Fallout
Impact· low

SolarWinds 2020: Unpacking the Supply Chain Breach and SEC Fallout

In late 2020, SolarWinds experienced a massive supply chain attack when advanced threat actors compromised the company's Orion software update mechanism. Attackers, attributed to Russia’s APT29 (Cozy Bear), injected malicious code into official software updates, giving them covert backdoor access to the systems of approximately 18,000 SolarWinds customers, including U.S. government agencies and Fortune 500 firms. The attack vectors enabled months of undetected lateral movement, extensive data exfiltration, and widespread compromise of critical infrastructure and networks. The breach also triggered broad regulatory and legal scrutiny, including an SEC lawsuit alleging inadequate disclosures and misrepresentation of cybersecurity practices by SolarWinds and top executives. The SolarWinds attack remains highly relevant as it catalyzed global focus on supply chain security, regulatory enforcement, and the rise of sophisticated software supply chain threats. Its legacy informs today’s cyber hygiene mandates and the zero trust adoption trending across both public and private sectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
APT24’s BADAUDIO: Multi-Year Espionage Hits Taiwan and 1,000+ Domains
Impact· high

APT24’s BADAUDIO: Multi-Year Espionage Hits Taiwan and 1,000+ Domains

In late 2025, a Chinese state-linked threat actor identified as APT24 orchestrated a protracted cyber espionage campaign targeting over 1,000 organizations across Taiwan and neighboring regions. Utilizing a newly discovered malware strain dubbed BADAUDIO, APT24 gained undetected remote access by exploiting vulnerabilities in key infrastructure and moving laterally within networks, leveraging encrypted east-west and outbound traffic. The threat actors pivoted from broad web compromises to highly targeted tactics, establishing persistent footholds and exfiltrating sensitive data over nearly three years. The incident underscored the advanced methods and patience employed by APT groups against critical sectors. This campaign highlights a growing trend toward sustained, stealthy cyber operations by nation-state actors, using modular malware and cloud-oriented infrastructure to evade traditional security tools. The breach is prompting urgent reviews of segmentation, traffic encryption, and real-time detection capabilities across industries facing heightened geopolitical cyber risk.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Major Grafana SCIM Security Flaw Exposes Enterprises to Privilege Escalation Attacks
Impact· medium

Major Grafana SCIM Security Flaw Exposes Enterprises to Privilege Escalation Attacks

In June 2025, Grafana disclosed a critical application vulnerability (CVE-2025-41115, CVSS 10.0) affecting its System for Cross-domain Identity Management (SCIM) component. Exploitable under certain configurations, this flaw allowed unauthenticated attackers to impersonate users and escalate privileges across affected Grafana instances. The issue stemmed from improper validation within the SCIM API, which enabled threat actors to provision accounts and assign administrative rights remotely. Grafana promptly released security patches and urged customers to update immediately as exploitation could lead to full compromise of monitoring infrastructure and sensitive business data. This incident underscores the ongoing threat of privilege escalation via identity management flaws, especially as identity-driven attacks and supply chain risks escalate. The rise in zero-day exploits targeting management interfaces highlights the urgent need for continuous application security assessments and rapid patch management.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Oracle Fusion Middleware Vulnerability (CVE-2025-61757) Actively Exploited
Impact· low

Critical Oracle Fusion Middleware Vulnerability (CVE-2025-61757) Actively Exploited

In November 2025, CISA added CVE-2025-61757—a critical authentication bypass in Oracle Fusion Middleware—to its Known Exploited Vulnerabilities (KEV) Catalog after confirmed evidence of active exploitation. The flaw permits remote, unauthenticated attackers to access critical functions in affected Oracle Fusion Middleware environments, enabling privilege escalation, lateral movement, and potential data exfiltration. The vulnerability represents a significant threat to both public and private organizations relying on Oracle’s middleware technologies, particularly within the federal enterprise, as attackers rapidly weaponize such exposures before widespread patching can occur. This incident highlights an ongoing trend of attackers swiftly exploiting newly published vulnerabilities, emphasizing the necessity for organizations to prioritize timely patching and robust vulnerability management. With regulatory mandates and threat actor innovation intersecting, the urgency to remediate critical middleware exposures has never been greater.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports