✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
SonicWall 2024 Cloud Backup Breach: Nation-State Attack Exposes Supply Chain Risks
In 2024, SonicWall disclosed a major supply-chain security incident where a state-sponsored threat actor exploited an API flaw to access the company's firewall cloud backup service. This breach, initially downplayed, resulted in the exposure and exfiltration of firewall configuration files for all customers leveraging SonicWall’s cloud backup. These files contained sensitive data such as firewall rules, encrypted credentials, and routing details, representing a significant risk for impacted organizations. An investigation by Mandiant confirmed the full scale of the compromise, though the specific country or threat group responsible remains undisclosed. This attack is especially relevant due to increasing targeting of security vendors and the potential for cascading risk across the customer base. The incident underscores persistent concerns over supply-chain vulnerabilities and the sophistication of nation-state actors focusing on critical infrastructure providers.
6 months ago
Kill Chain
Nation-State Breach Hits Congressional Budget Office: 2024 Lessons
In early June 2024, the Congressional Budget Office (CBO), a key federal agency supplying budget and economic analysis to Congress, experienced a cybersecurity breach by a suspected nation-state actor. Attackers reportedly infiltrated CBO systems and may have accessed sensitive communications between lawmakers and agency researchers. Upon discovery, CBO moved quickly to contain the incident, implemented additional monitoring, and strengthened security controls. The breach echoed previous attacks on congressional entities by sophisticated threat actors aiming to compromise confidential governmental data and influence legislative processes. This incident highlights increasing targeting of government research bodies by foreign espionage groups seeking sensitive intelligence. With agencies routinely handling politically sensitive and high-value data, robust cybersecurity defenses and rapid incident response are now critical amid heightened global threat actor activity.
6 months ago
Kill Chain
Sandworm Deploys Data Wipers in Sophisticated Attack on Ukraine’s Grain Sector
In early 2024, Russian state-backed threat actor Sandworm orchestrated a series of cyberattacks using multiple data-wiping malware families against Ukraine’s grain sector, education, and government organizations. These attacks involved deploying destructive wiper malware to erase data and disrupt critical operations, with the attackers leveraging lateral movement and advanced intrusion techniques to maximize impact. The campaign caused significant operational downtime, data loss, and posed a direct threat to Ukraine’s primary revenue source, severely impacting the grain production and export processes during a period of geopolitical tension. This incident reflects a trend of increased use of wiper malware in state-sponsored cyberwarfare, targeting national critical infrastructure. Organizations globally are urged to bolster their defenses, as these techniques are being replicated by other well-resourced threat actors beyond the Ukraine conflict.
6 months ago
Kill Chain
Cisco's 2024 Critical UCCX Flaw Exposes Root-Level Risks
In June 2024, Cisco disclosed a critical vulnerability (CVE-2024-20253) in its Unified Contact Center Express (UCCX) software, which could allow remote attackers to execute arbitrary commands with root privileges on affected systems. The flaw, which is due to improper validation of user-supplied input, does not require user authentication and is rated 9.9 out of 10 in severity. Malicious actors exploiting this vulnerability could gain full control over the underlying infrastructure, potentially leading to data breaches, service interruptions, or lateral movement within an organization's network. Cisco has issued security patches, and there are currently no reports of exploitation in the wild. The incident underscores the urgent need for prompt patch management and reinforces the trend of attackers rapidly leveraging zero-day and critical vulnerabilities in widely deployed enterprise platforms. Organizations must prioritize vulnerability management and maintain strict network segmentation to contain similar risks in their environments.
6 months ago
Kill Chain
ClickFix Evolves: Multi-OS Malware Delivered with Social Engineering and Video Tutorials
In early 2024, cybersecurity researchers observed a sharp evolution in the ClickFix malware campaign, which began targeting users with tailored multi-operating system payloads accompanied by step-by-step video tutorials to aid self-infection. The attackers employed social engineering by pressuring victims with countdown timers and offering clear, OS-specific instructions, effectively lowering the barrier for successful compromise. Leveraging these tactics, the malware operators could achieve widespread distribution, enabling credential theft and system control on both Windows and macOS platforms, and increasing risk of lateral movement across enterprise environments. This incident highlights a broader trend of combining technical innovation with advanced social engineering, making malware delivery easier and more efficient. The streamlined, multi-OS approach and use of multimedia content signal a significant shift in attacker tactics, accelerating the threat landscape and challenging traditional security awareness programs.
6 months ago
Kill Chain
SonicWall Cloud Backup Breach: How State-Sponsored Attackers Exploited API Weaknesses in 2025
In September 2025, SonicWall confirmed that state-sponsored threat actors orchestrated a security breach targeting its cloud backup environment. The attackers exploited an API vulnerability to gain unauthorized access to firewall configuration backup files stored in a specific cloud deployment. SonicWall's investigation determined the breach was limited to the exposure of these configuration files, with no evidence of lateral movement or impact to production systems. The breach prompted immediate containment actions, disclosure to affected customers, and a global review of cloud access controls and incident response procedures. This incident underscores the increasing risk posed by sophisticated, nation-state adversaries targeting cloud environments and API endpoints. It highlights how misconfigurations and insufficient segmentation in cloud infrastructure can facilitate data exposure, driving industry-wide reassessment of cloud-native security and compliance practices.
6 months ago
Kill Chain
How Ransomware Crippled Nevada State Agencies in 2025
In August 2025, the State of Nevada experienced a significant ransomware attack that disrupted the operations of over 60 state agencies, including those responsible for health and public safety. Attackers gained unauthorized access to internal systems, likely through a compromised credential or exposed remote access service. They rapidly deployed ransomware across the network, encrypting critical data and rendering multiple state services inaccessible while officials initiated emergency response protocols. The impact included delayed or suspended services for residents and a comprehensive recovery process lasting several weeks. This incident underscores a persistent trend: ransomware threat actors are increasingly targeting government entities, leveraging lateral movement and broad access to cripple essential public services. As attacks escalate and recovery costs rise, organizations face greater pressure to modernize segmentation, detection, and incident response strategies.
6 months ago
Kill Chain
Curly COMrades Weaponize Hyper-V: How Linux VMs Helped Evade Detection in 2025 Breach
In October 2025, the advanced persistent threat group Curly COMrades launched a sophisticated attack campaign exploiting Windows Hyper-V virtualization to evade endpoint detection and response (EDR) solutions. By covertly enabling Hyper-V on targeted systems, attackers deployed a minimal Alpine Linux-based virtual machine (VM) hidden within Windows hosts. This VM served as an isolated enclave to execute custom malware and facilitate command-and-control activities, significantly complicating detection and forensics for defenders. Victims experienced unauthorized data access and increased potential for lateral movement, while standard EDR tools failed to monitor the malicious payloads running inside the guest VM. This attack highlights a growing trend of leveraging virtualization and container technologies to bypass security controls. As organizations increasingly adopt hybrid and multi-cloud environments, adversaries are developing novel methods to mask malicious operations from traditional detection mechanisms, underscoring the need for advanced visibility and zero trust segmentation.
6 months ago
Kill Chain
Cisco Firewall DoS Attack: How CVE-2025-20333 & CVE-2025-20362 Disrupted Critical Networks
In November 2025, Cisco disclosed a vulnerability exploitation campaign targeting its Secure Firewall ASA and Threat Defense (FTD) devices. Threat actors actively weaponized two zero-day vulnerabilities, CVE-2025-20333 and CVE-2025-20362, to force vulnerable appliances to unexpectedly reload, resulting in denial-of-service (DoS) conditions that disrupted network operations. Affected organizations saw service disruptions, increased operational risk, and potential visibility gaps, especially where patch management or segmentation was lacking. Cisco responded by recommending immediate updates, enhanced monitoring, and deployment of compensating security controls until all devices are patched. This incident underscores a continuing trend of attackers rapidly exploiting unpatched firewall vulnerabilities, threatening the network perimeter’s reliability. The rise in sophisticated DoS tactics against infrastructure devices points to an urgent need for proactive patching, segmentation, and visibility into both perimeter and east-west traffic.
6 months ago
Kill Chain
Phishing Attack Delivers Kalambur Backdoor via Trojanized ESET Installers in Ukraine
In May 2025, a Russia-aligned threat group tracked as InedibleOchotense conducted a spear-phishing campaign targeting Ukrainian organizations. Attackers impersonated Slovak security company ESET, delivering phishing emails and Signal messages containing malicious links to trojanized ESET installers. When unsuspecting victims executed these files, a previously undocumented backdoor named Kalambur was installed, granting attackers covert access to compromised systems and enabling persistent network reconnaissance, command execution, and data exfiltration. The impersonation of a well-known cybersecurity firm lent the campaign added credibility, elevating its success rate and risk to targeted entities. This incident is a stark illustration of evolving phishing TTPs that exploit software supply chain trust and employ realistic impersonation. The campaign highlights the enduring threat posed by nation-state actors employing sophisticated lures, and underscores the urgent need for vigilant software validation, phishing awareness, and robust protective controls across organizations operating in high-risk geopolitical regions.
6 months ago
Kill Chain
Coinbase Hit by 2024 Phishing Attack Orchestrated by Scattered Spider
In February 2024, cryptocurrency exchange Coinbase experienced a sophisticated phishing attack executed by the 0ktapus (Scattered Spider) threat actor. Attackers sent targeted SMS and email messages to select Coinbase employees, impersonating IT support and leveraging social engineering to harvest login credentials and multi-factor authentication codes. They subsequently accessed internal dashboards, potentially viewing sensitive customer data. Prompt monitoring enabled Coinbase’s security team to detect the unusual access and contain the breach before widespread damage occurred, mitigating customer impact and avoiding direct financial loss. This incident highlights the increasing sophistication of phishing campaigns targeting high-value organizations, particularly those with significant user assets like Coinbase. Advanced phishing, often enabled by multi-stage social engineering and MFA bypass techniques, is intensifying across critical sector organizations in 2024.
6 months ago
Kill Chain
Ubia Ubox IoT Cameras Exposed: 2025 Credential Vulnerability Risks
In November 2025, a critical vulnerability (CVE-2025-12636) was disclosed in Ubia's Ubox smart camera platform, affecting version 1.1.124. The issue—insufficiently protected credentials—enables a remote attacker with low complexity to exploit API credential weaknesses, providing unauthorized access to live camera feeds and the ability to modify device settings. No public exploitation has yet been reported, but the vulnerability impacts commercial facilities worldwide, especially enterprises deploying these IoT cameras without network segmentation or backend isolation. Ubia did not engage with CISA coordination efforts. This incident exemplifies the ongoing risks associated with insecure IoT/ICS deployments and the lack of vendor responsiveness. With increased regulatory scrutiny and attacker interest in operational technology, ensuring proper credential management and network segmentation is an urgent priority for organizations using connected surveillance systems.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports