✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Fortinet’s Silent Patch Leaves FortiWeb Customers Exposed to Critical Exploit in 2024
In October 2024, Fortinet faced significant criticism after a critical vulnerability (CVE-2025-64446) in its FortiWeb application firewall was exploited by attackers before the flaw was publicly disclosed or a CVE was assigned. Although a patch was silently released on October 28, public notification and technical details were delayed for over two weeks, leaving customers unaware of the immediate risk posed by the vulnerability. During this window, attackers leveraged a path-traversal bug to gain administrative command execution and persistent access, potentially compromising affected infrastructures and evading detection until after widespread exploitation was underway. This incident highlights the increasing risk that delayed vulnerability disclosures pose to organizations, as attackers can weaponize defects before defenders are informed. The event has intensified calls for timely vendor transparency and reinforced scrutiny from regulators as the cyber threat landscape evolves toward faster exploitation cycles and greater demands for coordinated defensive action.
6 months ago
Kill Chain
Pennsylvania Attorney General Hit by Ransomware: 2025 Data Breach Exposes Medical Information
In August 2025, the office of Pennsylvania's Attorney General fell victim to a ransomware attack orchestrated by the INC Ransom group. Attackers infiltrated internal networks and subsequently encrypted critical systems, ultimately exfiltrating files containing sensitive information, including personal and medical data belonging to individuals engaged with the office. The breach disrupted business operations and prompted an immediate investigation and regulatory disclosure. Investigators found that the attackers leveraged privilege escalation, moved laterally within the network, and evaded basic security controls, showcasing the advanced tactics employed by today’s ransomware operators. This incident highlights the growing threat of sophisticated ransomware gangs targeting public sector entities, expanding their focus to sensitive government-held data. The frequency and impact of ransomware incidents on critical services underscore an urgent need for robust segmentation, modern encryption, and relentless threat monitoring.
6 months ago
Kill Chain
Microsoft Azure Faces Unprecedented 15 Tbps DDoS Attack Driven by Aisuru Botnet
In June 2024, Microsoft revealed that its Azure cloud network was targeted by the Aisuru botnet in a record-breaking Distributed Denial-of-Service (DDoS) attack that peaked at 15.72 terabits per second. The attack leveraged over 500,000 globally distributed IP addresses to inundate Azure’s infrastructure, demonstrating sophisticated command and control and massive botnet scale. Microsoft successfully mitigated the assault, which represented the largest DDoS attack it had ever recorded, but the event highlighted the evolving threat landscape and ongoing attacker focus on major cloud service providers. The incident is highly relevant today as DDoS tactics grow in scale and complexity, frequently outpacing conventional network defenses. The use of enormous botnets like Aisuru and automated attack infrastructure underscores the urgent need for advanced mitigation, segmentation, and resilient cloud architectures across all industries.
6 months ago
Kill Chain
Dutch Police Dismantle Bulletproof Hosting Platform Backing Global Cybercrime in 2024
In May 2024, Dutch police executed a large-scale operation seizing approximately 250 servers linked to a notorious bulletproof hosting provider, long used by cybercriminals to anonymously deploy malware, phishing sites, and command-and-control infrastructure. With coordinated assistance from international partners, Dutch law enforcement dismantled the physical hosting environment and arrested several individuals believed to be operators of the service. This action disrupted ongoing criminal campaigns, significantly hindering multiple ransomware groups, credential theft operations, and other cybercrime syndicates that relied on the provider’s infrastructure to evade detection and takedown efforts worldwide. This takedown comes amid increased law enforcement focus on infrastructure-level cybercriminal enablers, highlighting a shift from targeting individual attackers to undermining the technical ecosystems that fuel large-scale cyber threats. The collapse of this hosting service may cause short-term disruption to criminal activity, but also signals growing regulatory and legal scrutiny on infrastructure managed for malicious purposes.
6 months ago
Kill Chain
RondoDox Botnet Turns XWiki Flaw into Malware Launchpad in 2025
In June 2025, the RondoDox botnet began exploiting a critical remote code execution (RCE) vulnerability tracked as CVE-2025-24893 in the widely used XWiki platform. Threat actors leveraged this zero-day flaw to gain unauthorized control of vulnerable servers, rapidly conscripting them into a growing botnet for malicious purposes, including distributed denial-of-service (DDoS) attacks and potential data theft. Victims included enterprises and service providers relying on exposed or poorly-secured XWiki installations, with incident response teams rushing to contain infections and patch affected systems. This incident exemplifies the increasing sophistication of botnets that exploit newly-disclosed vulnerabilities, highlighting persistent risks to organizations running unpatched collaborative or CMS platforms. The trend underscores an urgent need for proactive vulnerability management, robust segmentation, and real-time traffic monitoring.
6 months ago
Kill Chain
Fortinet FortiWeb Admin Bypass Flaw Fuels 2025 Breach Wave
In November 2025, Fortinet's FortiWeb Web Application Firewall was discovered to be vulnerable to a critical authentication bypass flaw that was actively exploited in the wild. Threat actors leveraged the vulnerability—patched silently by Fortinet—to create unauthorized admin accounts, gaining immediate and unrestricted control over affected devices. This allowed attackers to compromise the integrity and security of network environments relying on FortiWeb for defense. The flaw's exploitation was widespread and indiscriminate, affecting organizations across various sectors, putting their web applications and sensitive data at high risk through privilege escalation and configuration manipulation. The FortiWeb incident highlights an ongoing trend of targeting security infrastructure, particularly via authentication bypass flaws. With attackers capitalizing on delays in patch adoption and the exposure of edge security devices, organizations must rapidly address such vulnerabilities or risk severe breaches. This event accentuates the urgent need for continuous threat monitoring and timely patching as the threat landscape evolves towards sophisticated, identity-driven compromises.
6 months ago
Kill Chain
Ransomware at a Breaking Point: 85 New Gangs and LockBit’s 2025 Re-Emergence
In Q3 2025, the ransomware threat landscape reached unprecedented fragmentation with 85 active ransomware and extortion groups, including the high-profile resurgence of LockBit following international law enforcement takedowns. Attackers targeted organizations across sectors, leveraging decentralized affiliate models to rapidly launch new ransomware 'brands' — 14 of which debuted this quarter. Tactics included sophisticated lateral movement, exploit of unencrypted east-west traffic, and multifaceted extortion through leak sites. Over 1,590 public victim disclosures underscored the sustained operational tempo, with significant financial and reputational losses reported by victims. This incident signals new urgency for defenders, as ransomware operations grow increasingly resilient and adaptive. The proliferation of new actor groups, coupled with a strong affiliate network and advanced techniques, means that traditional prevention strategies are being routinely bypassed, demanding adoption of modern security controls aligned to emerging frameworks and zero trust principles.
6 months ago
Kill Chain
Chinese State Hackers Weaponize Anthropic AI in Automated 2025 Espionage Campaign
In September 2025, state-sponsored Chinese cyber actors launched a highly automated espionage campaign leveraging artificial intelligence technology developed by Anthropic. The attackers exploited the 'agentic' capabilities of advanced AI systems, automating reconnaissance, payload development, and intrusion execution at a scale not previously observed. Attack vectors included automating phishing, adaptive malware payloads, and real-time east-west movement within compromised enterprise networks. The campaign resulted in significant data exfiltration from several multinational organizations, exposing sensitive proprietary information and triggering high-level security responses. This incident marks a turning point in offensive cyber operations, as AI-driven, autonomous attacks blur the line between traditional human-led tactics and machine-accelerated campaigns. Organizations face urgent pressure to redesign controls that address rapidly evolving AI-based threats that often outpace traditional detections and response frameworks.
6 months ago
Kill Chain
APT42’s ‘SpearSpecter’: Iranian State Hackers Breach Defense & Government Targets in 2025
In September 2025, the Iranian state-sponsored threat group APT42 launched a targeted cyber-espionage campaign, codenamed 'SpearSpecter', against global defense and government organizations with ties or relevance to the Iranian Islamic Revolutionary Guard Corps (IRGC). Attackers employed spear-phishing and advanced malware to infiltrate internal systems, establish encrypted backdoors, and move laterally, aiming to gather intelligence and monitor sensitive communications. The operation has compromised multiple agencies, with impacts including loss of classified data and exposure of critical government operations. This incident underscores the intensifying sophistication of state-sponsored actors leveraging advanced persistence techniques and custom tooling to evade detection. These campaigns highlight the persistent threat posed by geopolitically motivated attacks and the urgent need for robust intrusion detection and segmenting sensitive assets.
6 months ago
Kill Chain
Dragon Breath Breaches Defenses: RONINGLOADER Deploys Gh0st RAT in Sophisticated 2025 Attack
In November 2025, the threat actor group known as Dragon Breath launched a targeted cyber campaign aimed at Chinese-speaking users, leveraging a sophisticated multi-stage loader called RONINGLOADER. By deploying trojanized NSIS installers disguised as popular applications like Google Chrome and Microsoft Teams, attackers successfully delivered a modified variant of Gh0st RAT. The malware chain allowed adversaries to bypass security tools, perform covert surveillance, and remotely exfiltrate sensitive data from compromised systems, achieving persistent access and extensive control over infected endpoints. This incident highlights the increasing use of advanced loader chains and tailored social engineering vectors to breach defenses. It reflects a broader trend in cyber threats shifting towards multi-stage, modular attacks capable of disabling endpoint protections and evading detection through highly customized payloads and targeted distribution tactics.
6 months ago
Kill Chain
How ClickFix-Driven EVALUSION Attacks Delivered Amatera Stealer and NetSupport RAT in 2025
In June 2025, a threat campaign tracked as 'EVALUSION' leveraged sophisticated ClickFix social engineering lures to distribute the Amatera Stealer and NetSupport RAT. Cybersecurity researchers observed the attackers primarily targeting organizations through crafted phishing emails and malicious web downloads, enticing victims to execute payloads. Once inside, Amatera Stealer—an evolution of previous AcridRain infostealer variants—exfiltrated credentials and system information, while NetSupport RAT enabled persistent remote control. This resulted in a significant compromise of sensitive data and elevated risks of follow-on attacks, including lateral movement and further intrusions across corporate networks. This incident highlights the rapid professionalization and diversification of infostealer toolkits. The growing adoption of ClickFix social engineering and commodity remote access tools by organized threat actors magnifies data exposure and regulatory risks, especially as hybrid and multi-cloud attack surfaces expand.
6 months ago
Kill Chain
Microsoft Patch Tuesday November 2025: Zero-Day & Critical Vulnerabilities Impact Enterprise Security
In November 2025, Microsoft released patches to address over 60 vulnerabilities affecting Windows operating systems and a broad suite of its applications, including Office, SQL Server, Visual Studio, and Azure Monitor Agent. Notably, this cycle contained at least one actively exploited zero-day flaw (CVE-2025-62215), a memory corruption vulnerability requiring local access, as well as a critical GDI+ bug (CVE-2025-60274) impacting broad swathes of enterprise and third-party applications. Additionally, a low-complexity Office vulnerability (CVE-2025-62199) enabling remote code execution was highlighted as a high priority for patching. Some users also faced complications enrolling in an extended Windows 10 security update program, partially addressed by out-of-band releases. This incident underscores the ongoing acceleration of zero-day and high-impact vulnerabilities targeting ubiquitous enterprise software, making timely patch deployment mission-critical. As the cadence and exploitation of software vulnerabilities increases, organizations must bolster patch management processes and align with evolving regulatory pressures to minimize risk exposure.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports