✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Urgent: Microsoft SharePoint RCE Vulnerability (CVE-2026-45659) Under Active Exploitation
In May 2026, Microsoft disclosed a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint Server, stemming from the deserialization of untrusted data. This flaw allows authenticated attackers with minimal privileges to execute arbitrary code on unpatched SharePoint servers without user interaction. Despite the release of security updates on May 21, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) reported active exploitation of this vulnerability as of July 2, 2026, and added it to its Known Exploited Vulnerabilities Catalog, urging immediate remediation. The active exploitation of CVE-2026-45659 underscores the critical need for organizations to promptly apply security patches to prevent potential breaches. With over 10,000 SharePoint servers exposed online, the risk of widespread exploitation is significant, highlighting the importance of maintaining up-to-date systems to safeguard sensitive information.
3 weeks ago
Kill Chain
ConsentFix and ClickFix: Unveiling the New Era of Microsoft 365 Account Hijacking
In July 2026, a sophisticated social engineering attack known as ConsentFix emerged, targeting Microsoft 365 users. This attack exploits users' habitual responses to familiar prompts by presenting a seemingly legitimate authentication process. Victims receive phishing lures that lead them to a fake Microsoft sign-in page, where they are instructed to drag a localhost callback link into their browser. This action inadvertently grants attackers OAuth tokens, enabling unauthorized access to the victim's Microsoft 365 account without requiring passwords or bypassing multi-factor authentication. The attack is particularly insidious as it leverages routine user behaviors, making it difficult to detect and prevent. The ConsentFix attack underscores the evolving nature of cyber threats that exploit user trust and routine actions. As attackers continue to refine their methods, it is imperative for organizations to enhance user education on recognizing sophisticated phishing attempts and to implement robust security measures that can detect and mitigate such deceptive tactics.
3 weeks ago
Kill Chain
Anubis Ransomware Exploits Citrix Bleed 2 Vulnerability (CVE-2025-5777)
In July 2026, the Anubis ransomware group exploited the Citrix Bleed 2 vulnerability (CVE-2025-5777) to gain initial access to targeted systems. This critical flaw in Citrix NetScaler ADC and Gateway devices allows unauthenticated attackers to extract sensitive memory contents, including session tokens, enabling them to bypass multi-factor authentication and hijack user sessions. Anubis affiliates utilized legitimate Remote Management and Monitoring (RMM) tools such as ScreenConnect, Zoho Assist, and UltraVNC to maintain control over compromised systems, facilitating lateral movement and data encryption. ([thehackernews.com](https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.html?utm_source=openai)) The exploitation of CVE-2025-5777 underscores the persistent threat posed by ransomware groups leveraging known vulnerabilities and legitimate tools to evade detection. Organizations must prioritize timely patching of critical vulnerabilities and monitor for unauthorized use of RMM tools to mitigate such risks.
3 weeks ago
Kill Chain
Phishing Attacks Evolve: Adaptive Campaigns Target Devices and OS
In July 2026, sophisticated phishing campaigns emerged that dynamically adapt to a victim's device and operating system. Attackers utilize user-agent data to fingerprint victims, collecting information such as email addresses, browser details, device type, language, local time, screen size, and geolocation. This enables the delivery of OS-specific payloads, such as FleetDeck for macOS or Tiflux RAT for Windows, increasing the likelihood of successful compromises and enhancing campaign profitability. ([darkreading.com](https://www.darkreading.com/application-security/phishing-campaigns-auto-adapt-victims-device-os?utm_source=openai)) This trend underscores a significant evolution in phishing tactics, moving from generic attacks to highly targeted, platform-aware strategies. Organizations must enhance cross-platform monitoring and educate employees on recognizing sophisticated phishing attempts to mitigate these advanced threats.
3 weeks ago
Kill Chain
IBM and Red Hat's Project Lightwell: A New Era in Open-Source Security
In May 2026, IBM and Red Hat launched Project Lightwell, a $5 billion initiative aimed at enhancing open-source software security. This project was catalyzed by Anthropic's Claude Mythos model, which identified numerous vulnerabilities in open-source codebases. Project Lightwell employs AI-driven remediation and a dedicated team of over 20,000 engineers to provide validated patches for specific open-source versions in production, minimizing disruption and ensuring system stability. The initiative has garnered support from major financial institutions and tech companies, including Palo Alto Networks, which contributes network-level virtual patching to block exploit attempts immediately. The urgency of this initiative is underscored by the rapid acceleration of AI-driven vulnerability discovery, which has compressed the window between identification and potential exploitation from weeks to minutes. Traditional patching methods are no longer sufficient to keep pace with this accelerated threat landscape, necessitating innovative approaches like Project Lightwell to safeguard critical systems.
3 weeks ago
Kill Chain
Critical SharePoint RCE Vulnerability CVE-2026-45659 Under Active Exploitation
In May 2026, Microsoft addressed a critical remote code execution vulnerability (CVE-2026-45659) in SharePoint Server, stemming from the deserialization of untrusted data. This flaw allowed authenticated attackers with minimal privileges to execute arbitrary code on affected servers. Despite the availability of patches, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog in July 2026, indicating active exploitation in the wild. Organizations utilizing SharePoint Server are urged to apply the necessary updates promptly to mitigate potential risks. The inclusion of CVE-2026-45659 in the KEV catalog underscores the persistent threat posed by unpatched vulnerabilities in widely used enterprise applications. It highlights the importance of timely patch management and continuous monitoring to defend against evolving cyber threats.
3 weeks ago
Kill Chain
FortiBleed Credential Theft: A Gateway to Ransomware Attacks
In early 2026, the FortiBleed campaign emerged as a large-scale credential-harvesting operation targeting over 430,000 FortiGate firewalls across more than 150 countries. Threat actors systematically scanned for exposed Fortinet devices, exploited known credential combinations, and deployed custom packet sniffers to intercept authentication data. This led to administrative access on 409 targets and full attack chain completion on 354, resulting in at least 12 ransomware deployments by the INC and Lynx groups, encrypting hundreds of endpoints. ([thehackernews.com](https://thehackernews.com/2026/07/fortibleed-credential-theft-linked-to.html?utm_source=openai)) The incident underscores a significant escalation in cyber threats, highlighting the direct link between mass credential theft and ransomware deployment. Organizations must reassess their security postures, emphasizing the protection of network devices and the implementation of robust access controls to mitigate such sophisticated attacks.
3 weeks ago
Kill Chain
Critical SharePoint Server Vulnerability CVE-2026-45659 Actively Exploited
In May 2026, Microsoft disclosed CVE-2026-45659, a critical remote code execution vulnerability in SharePoint Server caused by deserialization of untrusted data. This flaw allows authenticated attackers with minimal permissions to execute arbitrary code over a network, potentially compromising sensitive data and system integrity. Despite the release of patches, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities Catalog on July 1, 2026, indicating active exploitation in the wild. The inclusion of CVE-2026-45659 in CISA's catalog underscores the urgency for organizations to apply the available patches promptly. The vulnerability's low attack complexity and the widespread use of SharePoint in enterprise environments heighten the risk of exploitation, emphasizing the need for immediate remediation to protect organizational assets.
3 weeks ago
Kill Chain
Critical Vulnerability in CubeSpace CW0057 Reaction Wheel Firmware
In July 2026, CubeSpace disclosed a vulnerability (CVE-2026-13743) in its CW0057 Reaction Wheel firmware versions prior to 5.0.20. This flaw allows attackers with physical access to upload malicious firmware without authentication, potentially compromising satellite operations. The issue stems from the device's reliance on CRC-32 integrity checks, which verify data integrity but not the authenticity of the firmware source. CubeSpace has released firmware version 5.0.20, introducing cryptographically verified secure boot, though this feature is not enabled by default and requires user activation. This incident underscores the critical importance of robust firmware authentication mechanisms in aerospace components. As satellites become increasingly integral to global communications and defense, ensuring the integrity of onboard systems is paramount. Organizations must proactively implement and enable security features to mitigate risks associated with unauthorized firmware modifications.
3 weeks ago
Kill Chain
ToddyCat's Umbrij Malware: A New Threat to Gmail Security
In June 2026, the advanced persistent threat group known as ToddyCat deployed a new malware tool named Umbrij to infiltrate corporate Gmail accounts. Utilizing a technique termed Shadow Token via Remote Debug (STRD), the attackers exploited active user sessions in Chromium-based browsers to obtain OAuth tokens, granting unauthorized access to Gmail and other Google services without requiring user credentials. This method allowed them to read emails, access calendars, and gather data from Google Drive, all while remaining undetected for extended periods. The emergence of Umbrij underscores a significant evolution in cyber-espionage tactics, highlighting the increasing sophistication of threat actors in bypassing traditional security measures. Organizations must reassess their security protocols, particularly concerning API access and browser session management, to mitigate such advanced threats.
3 weeks ago
Kill Chain
Urgent Alert: Active Exploitation of Oracle EBS CVE-2026-46817
In late June 2026, threat intelligence firm Defused detected active exploitation of a critical vulnerability (CVE-2026-46817) in Oracle's E-Business Suite (EBS) Payments module. This flaw, present in versions 12.2.3 through 12.2.15, allows unauthenticated attackers to execute arbitrary code via HTTP, potentially leading to full system compromise. The initial exploit attempts were observed on June 27, 2026, targeting the 'ibytransmit' endpoint to read sensitive files from the server. Oracle had released a patch for this vulnerability in May 2026, but the recent attacks indicate that many systems remain unpatched and vulnerable. This incident underscores the persistent threat posed by unpatched critical vulnerabilities in widely used enterprise applications. Organizations relying on Oracle EBS must prioritize applying security updates promptly to mitigate risks. The exploitation of CVE-2026-46817 highlights the need for continuous monitoring and proactive defense strategies to protect against emerging threats targeting enterprise resource planning (ERP) systems.
3 weeks ago
Kill Chain
Over 900 Oracle E-Business Instances Exposed to Ongoing Attacks
In late June 2026, over 900 Oracle E-Business Suite (EBS) instances were found exposed online, with active exploitation of a critical vulnerability (CVE-2026-46817) in the Oracle Payments component. This flaw allows unauthenticated attackers with HTTP access to take over vulnerable systems. Oracle released a patch in May 2026, but many systems remain unpatched, leading to successful attacks. The ongoing exploitation of CVE-2026-46817 underscores the persistent threat posed by unpatched enterprise systems. Organizations must prioritize timely application of security updates to mitigate risks associated with such vulnerabilities.
3 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports