Validated Containment Architectures are here. →Explore

Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2385 threat reports
Page 180 of 199

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Government Administration Threat Reports

Showing 21492160 / 2385 reports
Oracle E-Business Suite 2025 Flaw Sparks Urgent Clop Ransomware Concerns
Impact· high

Oracle E-Business Suite 2025 Flaw Sparks Urgent Clop Ransomware Concerns

In October 2025, Oracle issued an emergency patch addressing CVE-2025-61884, a critical information disclosure vulnerability in its E-Business Suite (EBS) affecting versions 12.2.3 through 12.2.14. The flaw, present in the Runtime UI component, allowed unauthenticated attackers to remotely access sensitive business data, bypassing standard authentication mechanisms. The incident followed the discovery that threat actors—most notably the Clop ransomware group—had recently targeted Oracle EBS zero-days in extortion schemes against executives, leveraging vulnerabilities to facilitate large-scale data theft. Although Oracle has not confirmed active exploitation of CVE-2025-61884, the urgency of the patch highlights heightened threat actor interest and continued risk for organizations with unpatched, internet-facing EBS deployments. This incident underscores an alarming trend: criminal groups exploiting zero-day and recently patched vulnerabilities in widely used business applications for extortion and data theft. The rapid evolution of attacker tactics, combined with the continued exposure of critical SaaS and ERP platforms, raises the stakes for organizations to accelerate patching cycles and strengthen segmentation and threat detection strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
SonicWall VPN Breach 2025: Credential Theft Sparks Widespread Compromise
Impact· medium

SonicWall VPN Breach 2025: Credential Theft Sparks Widespread Compromise

In October 2025, a widespread cyberattack compromised more than 100 SonicWall SSLVPN accounts across 16 customer environments through the use of stolen, valid credentials. Researchers at Huntress observed the attackers rapidly authenticating into multiple accounts, with some sessions ending abruptly while others progressed to network reconnaissance and attempts at lateral movement by targeting local Windows accounts. The campaign began around October 4, 2025, with most attack traffic tracing back to a single IP address. Although there is no direct link to a previous breach involving SonicWall firewall configuration files, the incident underscores a substantial exposure risk to sensitive systems, business operations, and potentially regulatory compliance requirements. This incident highlights the evolving threat landscape, where credential compromise—not brute force—enables rapid, large-scale intrusions into VPN infrastructures. The continued prevalence of identity-driven attacks against remote access systems amplifies the urgency for enhanced credential hygiene, multi-factor authentication, and zero-trust access controls in the face of sophisticated adversaries.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Massive Multi-Country Botnet Launches RDP Attacks Against US Organizations
Impact· low

Massive Multi-Country Botnet Launches RDP Attacks Against US Organizations

In October 2025, a massive botnet composed of devices spanning over 100 countries launched coordinated attacks targeting Remote Desktop Protocol (RDP) services in the United States. Security researchers first spotted a spike in unusual RDP traffic originating from Brazil, with further malicious activity quickly spreading globally. Attackers leveraged two primary techniques: RD Web Access timing attacks to infer valid usernames, and RDP web client login enumeration to access accounts through analysis of server response behaviors. The campaign utilized over 100,000 unique IP addresses sharing a similar TCP fingerprint, indicating a highly organized cluster-based operation. The attacks put both government and enterprise systems at risk of brute-force intrusion and potential credential compromise. This incident underlines the persistent and evolving threat posed by botnets against remote access services. With increasing remote work reliance and exposed RDP endpoints, such sophisticated, multi-geography attacks exploit common authentication weaknesses and call for urgent upgrades in defense, including MFA and network segmentation.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Microsoft 2025: Zero-Day Exploit Prompts Emergency IE Mode Restrictions
Impact· low

Microsoft 2025: Zero-Day Exploit Prompts Emergency IE Mode Restrictions

In October 2025, Microsoft announced urgent restrictions on Internet Explorer (IE) mode within the Edge browser following the discovery of active zero-day exploits targeting the Chakra JavaScript engine. Threat actors leveraged sophisticated social engineering tactics to lure users to spoofed sites, where a previously unknown vulnerability in Chakra enabled remote code execution. Attackers combined this with a privilege escalation flaw to escape the browser sandbox and seize complete device control. Microsoft responded by removing easy methods to activate IE mode in Edge for consumer users, instead requiring manual configuration limited to explicit, approved sites, and urged migration from legacy technologies. This incident underscores the persistent risks associated with maintaining legacy web compatibility features such as IE mode, especially as threat actors increasingly exploit these pathways with sophisticated chains of zero-day vulnerabilities and social engineering. It highlights heightened urgency for organizations to migrate from deprecated software and rigorously manage legacy access points.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Fake Inflation Refund Phishing Texts Target New Yorkers in 2025 Smishing Attack
Impact· high

Fake Inflation Refund Phishing Texts Target New Yorkers in 2025 Smishing Attack

In October 2025, a coordinated smishing campaign targeted New York State residents with fraudulent text messages purporting to be from the Department of Taxation and Finance. The attackers claimed recipients were eligible for an 'Inflation Refund' and directed them to a phishing site impersonating an official state portal, where victims were prompted to submit sensitive personal data—name, address, email, phone number, and Social Security Number—under the guise of processing their refund. This malicious operation seeks to steal identities and facilitate extensive financial fraud. Government officials swiftly issued warnings, clarifying that legitimate refunds required no action from residents and urging vigilance. This incident is a stark reminder of the increasing sophistication of SMS phishing (smishing) attacks, which blend timely government programs with social engineering techniques. The campaign highlights the persistent risk posed by identity-centric attacks, especially as digital fraudsters exploit widespread economic uncertainty and official-sounding initiatives.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Russian ClayRat Android Spyware Masquerades as Popular Apps, Spreads Rapidly in 2024
Impact· medium

Russian ClayRat Android Spyware Masquerades as Popular Apps, Spreads Rapidly in 2024

In mid-2024, security researchers at Zimperium discovered ClayRat, a rapidly evolving Android spyware campaign targeting users in Russia. Disguised as trusted apps like TikTok and YouTube, ClayRat was spread via phishing websites and Telegram channels, infecting over 600 devices in just three months. Once installed, the spyware leverages Android’s SMS handler permissions to bypass typical security prompts, allowing attackers to covertly access messages, call logs, device information, and even remotely control infected phones. The highly orchestrated campaign abused social engineering, web deception, and obfuscation techniques to remain undetected, and can turn each compromised device into a new attack vector. The threat’s evolution signals rising global risks, as the campaign’s tactics can easily adapt to new payloads and regions. With increasing use of mobile malware, organizations globally should reassess mobile security controls and user awareness programs to defend against sophisticated, evasive spyware attacks exploiting trust in well-known apps.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Apple Bug Bounty Shatters Records: $2M Now Offered for Zero-Click RCE Vulnerabilities
Impact· low

Apple Bug Bounty Shatters Records: $2M Now Offered for Zero-Click RCE Vulnerabilities

In June 2024, Apple significantly enhanced its bug bounty program, now offering up to $2 million for zero-click Remote Code Execution (RCE) vulnerabilities — the highest payout in the industry to date. This expansion includes new research categories and a more transparent reward structure aimed at encouraging security researchers to responsibly disclose critical flaws, particularly those enabling attackers to compromise devices without user interaction. The move comes amid heightened concerns over sophisticated exploits, such as NSO Group’s Pegasus, which have targeted Apple’s platforms using zero-click attack chains that can bypass traditional security controls, threatening the confidentiality and security of end-users and enterprise data. The immediate relevance of Apple's program expansion is twofold: it recognizes the rapid evolution of threat actor capabilities and underscores the urgent need for robust vulnerability disclosure programs. As zero-click exploits gain momentum among both state actors and cybercriminals, organizations face increased regulatory and reputational risks from unpatched, high-impact vulnerabilities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Autonomous AI Hacking: The Tipping Point in Global Cybersecurity Risk (2025)
Impact· medium

Autonomous AI Hacking: The Tipping Point in Global Cybersecurity Risk (2025)

In mid-2025, a wave of autonomous AI-driven cyberattacks emerged globally, marking a pivotal evolution in threat activity. Across June through September, a combination of threat actors—including criminal groups and state-sponsored entities—leveraged advanced large language models (LLMs) and autonomous agent frameworks to conduct large-scale vulnerability discovery, network infiltration, and ransomware deployment. Attackers used tools like XBOW, HexStrike-AI, and AI-powered malware to execute rapid reconnaissance, credential harvesting, and automated extortion, targeting enterprises and critical infrastructure with unprecedented speed, scale, and sophistication. Businesses faced increased operational disruptions and data loss due to automated exploitation chains and persistent threats that outpaced traditional defense mechanisms. This wave of AI-enabled cyberattacks highlights a dangerous rise in the commoditization of sophisticated offensive tools and the diminishing window for detection and response. The incident underscores an urgent shift in the cyber threat landscape, with automation eroding the gap between disclosure and exploitation while spurring intense regulatory and industry focus on adaptive, AI-driven defense solutions.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AI Agents Under Fire: Memory Poisoning and the Rise of Persistent Prompt Injection
Impact· high

AI Agents Under Fire: Memory Poisoning and the Rise of Persistent Prompt Injection

In 2024, security researchers uncovered a novel AI/ML security incident where AI agents' long-term memory storage was compromised via persistent indirect prompt injection. Adversaries managed to embed malicious instructions within normal AI inputs; these poisoned prompts were subsequently retained by the AI's memory module. When later queries accessed this memory, the injected instructions could exfiltrate conversation history or impact future responses, creating a stealthy, long-term threat. The breach highlighted how modern agentic AI’s tendency to remember user input presents an unforeseen risk vector, with potential for data leakage and manipulation of AI-driven workflows. This incident signals a rising trend: as enterprises integrate AI agents and persistent memory, attackers are quickly adapting with prompt-based exploit techniques that subvert traditional security controls. The risk of covert data exfiltration and ongoing manipulation through AI memory will become a central compliance and governance issue in highly regulated industries.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Clop Ransomware Hits Oracle E-Business Suite Via Zero-Day in 2025
Impact· high

Clop Ransomware Hits Oracle E-Business Suite Via Zero-Day in 2025

In August 2025, the Clop ransomware group launched a targeted campaign against Oracle E-Business Suite customers, exploiting a critical zero-day vulnerability (CVE-2025-61882) and additional software flaws to achieve pre-authenticated remote code execution. The attack began nearly three months before extortion emails were sent, enabling Clop to quietly exfiltrate sensitive data from dozens of organizations. Security researchers from Google and Mandiant collaborated to reconstruct the multi-stage exploit chain, and Oracle issued an emergency patch in early October after hundreds of systems were identified as vulnerable. Ransom demands reached up to $50 million, jeopardizing regulated data and business operations across multiple industries. This incident underscores the accelerating weaponization of zero-days by advanced ransomware groups and highlights the growing sophistication of supply-chain attacks. It demonstrates both the risk of delayed patching and the operational threat to organizations reliant on widely used enterprise software platforms.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
SonicWall Cloud Backup Breach 2024: Firewall Configurations Exposed in Major Supply Chain Attack
Impact· high

SonicWall Cloud Backup Breach 2024: Firewall Configurations Exposed in Major Supply Chain Attack

In mid-2024, SonicWall suffered a significant security breach when an unauthorized party leveraged a brute-force attack against its customer-facing cloud backup platform, gaining access to all firewall configuration backup files stored on the service. The exposed data included sensitive firewall rules, encrypted credentials, and routing configurations for every customer utilizing SonicWall’s cloud backup, not just the initially cited 5% of their install base. While the credentials were encrypted, experts warned that weak passwords could be crackable, offering attackers expanded access. SonicWall worked with Mandiant to investigate, notified affected customers, hardened its infrastructure, and provided remediation tools. This incident highlights ongoing risks from cloud-based infrastructure and supply chain attacks, especially targeting security vendors. Attackers are increasingly exploiting weaknesses in API protections and infrastructure configurations, reinforcing the need for robust access controls and continuous monitoring as ransomware and targeted attacks against network security vendors persist.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
TwoNet Hacktivists Target Decoy Water Plant in Bold Critical Infrastructure Attack
Impact· high

TwoNet Hacktivists Target Decoy Water Plant in Bold Critical Infrastructure Attack

In September 2025, the pro-Russian hacktivist group TwoNet targeted what they believed to be a vulnerable water treatment plant, unaware it was a decoy system (honeypot) operated by cybersecurity researchers. The attackers gained access using default credentials, escalated attacks through SQL enumeration, and exploited a known XSS vulnerability (CVE-2021-26829). Within 26 hours, they created new user accounts, manipulated PLC setpoints, disabled real-time updates, and attempted to disrupt both logs and alarms via the Human Machine Interface (HMI). Their tactics included data exfiltration and process disruption, signaling a shift toward operational technology (OT) attacks targeting critical infrastructure. This incident highlights a growing trend of hacktivist groups evolving from DDoS and defacement attacks to more sophisticated operations against OT and ICS targets. The rapid escalation and attempted sabotage observed in this breach emphasize the urgent need for robust segmentation, authentication, and real-time anomaly detection within critical infrastructure environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports