✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
F5’s 2023 Supply Chain Breach: When Nation-State Attacks Undermine U.S. Cyber Readiness
In October 2023, a significant nation-state supply chain attack targeted F5, a leading provider of network and application security solutions. Threat actors believed to be linked to China successfully gained unauthorized access to F5's source code and undisclosed vulnerabilities, providing them with intimate knowledge required to craft advanced exploits capable of bypassing traditional security defenses. BIG-IP, F5's flagship product, is widely deployed by major enterprises, federal agencies, healthcare institutions, and utilities, making the impact of this breach exceptionally far-reaching. In response, CISA issued an emergency directive urging federal agencies to promptly patch vulnerable systems, citing the potential for cascading impacts across critical infrastructure. This incident is particularly relevant as it underscores the growing sophistication of supply chain attacks, where adversaries target foundational software providers instead of individual end-users. The breach comes amidst rising threats from nation-state actors and highlights the urgent need for proactive security controls, rapid patching, and improved cross-sector collaboration to strengthen cyber resilience.
6 months ago
Kill Chain
Curly COMrades: Russian Hackers Hide Malware in Hyper-V Linux VMs to Evade Detection
In early 2024, threat intelligence analysts uncovered a sophisticated campaign by the Russian-backed group Curly COMrades, wherein attackers abused Microsoft's Hyper-V virtualization feature to bypass endpoint detection on target Windows systems. The attackers covertly deployed an Alpine Linux virtual machine, invisible to conventional security tools, and used it as a persistent foothold to run malware, facilitate lateral movement, and exfiltrate sensitive data. This technique allowed them to mask malicious processes and evade established EDR and antivirus solutions, posing serious risks to affected organizations. This incident highlights an alarming evolution in advanced persistent threat tactics, with adversaries exploiting virtualization infrastructure to evade modern security controls. As virtualized environments and cloud workloads proliferate, organizations must harden hypervisors, enhance east-west security, and advance detection capabilities to fend off similar stealthy threats.
6 months ago
Kill Chain
Top Browser Sandbox Threats: How Attackers Slip Past Security in 2024
In early 2024, a surge of browser-based attacks demonstrated the ability of sophisticated threat actors to bypass modern browser sandboxing, leveraging native browser features and vulnerable extensions to conduct credential theft, lateral movement, and data exfiltration. According to insights from Keep Aware and BleepingComputer, attackers exploit browser quirks and weaknesses such as unsanctioned extension access, credential harvesting via phishing overlays, and abuse of session tokens, often evading signature-based detection tools. Organizations affected by such campaigns have faced unauthorized data access, exposure of credentials, and in some cases, secondary compromise of internal systems. This incident highlights the evolving attack surface at the browser layer, where traditional endpoint and network protections may no longer suffice. As browser usage grows in enterprise settings and attackers refine tactics to evade sandboxing controls, security teams must re-examine their strategy for real-time browser-layer visibility and enforcement.
6 months ago
Kill Chain
Miljödata Data Breach Exposes 1.5 Million Swedish Records in 2024
In early June 2024, Swedish IT service provider Miljödata disclosed a significant data breach that exposed the personal information of approximately 1.5 million individuals. The Swedish Authority for Privacy Protection (IMY) launched an investigation after attackers gained unauthorized access to Miljödata's systems, compromising data from various organizations reliant on its software. Initial reports indicate a threat actor leveraged vulnerabilities in Miljödata's infrastructure to exfiltrate large datasets, with the breach's discovery prompting immediate shutdowns and incident response procedures. This breach underscores the increasing vulnerability of critical software suppliers to large-scale attacks. As supply chain incidents rise globally, regulators and businesses face mounting pressure to modernize controls against unencrypted data transfer, lateral movement, and delayed anomaly detection.
6 months ago
Kill Chain
Akira Ransomware’s Disputed Data Breach: What Happened at Apache OpenOffice (2024)
In June 2024, the Akira ransomware group publicly claimed responsibility for a data breach affecting Apache OpenOffice, alleging the theft of 23 GB of sensitive corporate documents. Despite these assertions, the Apache Software Foundation conducted an internal investigation and officially disputed any evidence of compromise or unauthorized access, stating there were no indications of a breach in their infrastructure. This incident highlights the ongoing challenge organizations face with threat actor claims that may not always be substantiated but can cause reputational risk and user concern. Similar ransomware campaigns have surged in 2024, with groups leveraging public exposure even without confirming access to target data. The situation underscores the importance of proactive communication, transparent incident response, and technical validation as attackers increasingly use psychological pressure tactics in addition to technical intrusions.
6 months ago
Kill Chain
Operation SkyCloak: Tor-Enabled OpenSSH Backdoor Infiltrates Defense Networks
In November 2025, a sophisticated cyber campaign dubbed 'Operation SkyCloak' was uncovered, targeting Russian and Belarusian defense sectors. Attackers distributed weaponized attachments via phishing emails, successfully implanting a persistent OpenSSH-based backdoor on compromised hosts. To conceal its activity, the malware leverages a customized Tor hidden service with obfs4 protocol, facilitating covert command-and-control and persistent unauthorized access. This campaign demonstrates advanced threat actor operational security, targeting high-value government and defense assets to enable espionage and data exfiltration. The use of Tor-enabled backdoors in defense-related attacks is surging, marking a shift towards more covert, untraceable threat tactics. This incident exemplifies the growing adoption of anonymized infrastructure by attackers to evade detection, highlighting urgent requirements for east-west traffic inspection, advanced threat detection, and zero trust segmentation for critical sectors.
6 months ago
Kill Chain
2025 Ransomware Tsunami: Why Real-Time Data Is Now Essential for Defense
In early 2025, organizations worldwide faced a dramatic surge in ransomware attacks, as threat actors embraced data-driven approaches and leveraged AI, new exploit techniques, and ransomware-as-a-service (RaaS) business models. Attackers rapidly escalated compromise using stolen credentials, lateral movement, and encrypted communications, bypassing traditional detection tools and reducing dwell time to under an hour. With nearly half of breaches attributed to ransomware and a sharp increase in identity-driven attacks, countless organizations experienced significant operational disruptions, financial losses, and reputational damage. This incident highlights a macro-shift in the threat environment: traditional signature-based or static ransomware detection methods are now largely ineffective against modern, fast-moving adversaries. The exponential rise of hands-on, machine-speed attacks and infostealer-driven access means organizations urgently need real-time, intelligence-led detection and response capabilities.
6 months ago
Kill Chain
Microsoft Teams Vulnerabilities: 2025’s Wake-Up Call for Application Security
In March 2025, security researchers uncovered four critical vulnerabilities in Microsoft Teams that allowed attackers to manipulate conversations and impersonate trusted colleagues without detection. By exploiting flaws in message handling and notifications, adversaries could initiate convincing phishing and social engineering attacks, posing as legitimate users and altering message content retroactively. These flaws were exploitable until Microsoft was notified through responsible disclosure, enabling potential internal threat activity or external compromise before patches were issued. This incident highlights the growing risks of business collaboration platforms as prime targets for socially engineered attacks. With enterprise reliance on unified communications, attackers are innovating new tactics to undermine trust, emphasizing the urgent need for proactive application security and real-time threat monitoring controls.
6 months ago
Kill Chain
CISA Flags Active Exploitation of 2025 Gladinet CentreStack, Triofox, and CWP Control Web Panel Flaws
In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA) identified and announced active exploitation of two critical vulnerabilities: CVE-2025-11371 in Gladinet CentreStack and Triofox (files or directories exposed to external parties), and CVE-2025-48703 in CWP Control Web Panel (an OS command injection flaw). Threat actors are leveraging these weaknesses to gain unauthorized file access or execute malicious code within affected environments, targeting organizations across sectors. The vulnerabilities enable lateral movement, data exfiltration, and potentially full compromise, with significant risk to sensitive data, business operations, and regulatory posture for organizations running vulnerable systems. This announcement underscores a broader trend of attackers exploiting unpatched software vulnerabilities in common enterprise tools. With automatic exploitation kits and a growing focus on file-sharing and web panel infrastructure, organizations face urgent pressure to accelerate vulnerability management and adopt Zero Trust practices to contain and monitor internal threats.
6 months ago
Kill Chain
IDIS ICM Viewer 2025: Critical Application Vulnerability Risk Exposed
In November 2025, IDIS disclosed a critical vulnerability (CVE-2025-12556) in its ICM Viewer application, enabling remote attackers to execute arbitrary code via improper neutralization of argument delimiters—a classic argument injection flaw. The vulnerability, scored CVSS v4 8.7, affected version 1.6.0.10 and allowed exploitation through low-complexity attacks requiring only limited privileges. The flaw could provide adversaries with broad control over vulnerable systems, directly impacting critical communications infrastructure deployed worldwide and potentially undermining operational continuity and data integrity. This incident highlights the growing risk posed by supply chain and application-layer vulnerabilities in industrial and communications networks. The prevalence of remote, low-complexity exploits underscores the urgent need for robust patch management and defense-in-depth approaches, especially as regulators intensify scrutiny of critical infrastructure cybersecurity.
6 months ago
Kill Chain
Survision LPR Cameras: Unauthenticated Access Vulnerability (CVE-2025-12108)
In November 2025, a critical vulnerability (CVE-2025-12108) was disclosed in Survision License Plate Recognition (LPR) cameras, affecting all product versions globally. The flaw stems from missing authentication safeguards, allowing threat actors to remotely access device configuration wizards without credentials. This enables full system compromise—enabling attackers to alter settings, exfiltrate data, or use compromised cameras as entry points for broader attacks on commercial infrastructure. Researchers at Microsec identified the issue and notified stakeholders, prompting immediate remediation efforts and a firmware update (v3.5) from Survision. No confirmed active exploitation has been reported so far. With physical security increasingly integrated with digital management systems, unauthenticated access to surveillance infrastructure exposes environments to cyber-physical risks. The urgency of this disclosure reflects a broader industry trend: attackers actively seek exposed IoT and operational tech lacking basic authentication, prompting rising regulatory scrutiny and heightened compliance mandates.
6 months ago
Kill Chain
Global Airports at Risk: Radiometrics VizAir 2025 Unauthenticated Access Exposes Critical Infrastructure
In November 2025, critical vulnerabilities were publicly disclosed in Radiometrics VizAir, a system widely deployed in global airport transportation infrastructure. The flaws (CVE-2025-61945, CVE-2025-54863, CVE-2025-61956) permit unauthenticated remote attackers to manipulate weather parameters, runway settings, and extract sensitive meteorological data via missing authentication controls and exposed credentials. Exploitation could disrupt airport operations, mislead air traffic control and pilots, and create hazardous flight conditions by disabling vital alerts or injecting false data. The vulnerabilities were reported by a security researcher and were assigned the highest CVSS score of 10.0, reflecting severe risk to operational safety. This incident highlights the escalating risk facing critical infrastructure as attackers increasingly target operational technology systems with low-complexity, high-impact exploits. Given the global reliance on secure flight operations, the breach underscores the urgency for robust authentication, segmentation, and credential management controls across transportation-critical systems.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports