✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Ukrainian Police Spoofed: SVG Fileless Phishing Delivers Amatera Stealer in Kyiv
In early 2024, cybercriminals conducted a sophisticated phishing campaign targeting organizations and individuals in Kyiv, Ukraine, by spoofing the National Police of Ukraine. The attackers distributed malicious emails containing Scalable Vector Graphics (SVG) files, which enabled fileless delivery of info-stealing malware such as Amatera Stealer and the cryptocurrency miner PureMiner. By leveraging social engineering and trusted police branding, they bypassed common security defenses, leading to the theft of sensitive credentials, system compromise, and potential financial losses. The breach highlights attackers’ growing reliance on fileless techniques and deceptive lures to infiltrate victims’ environments with minimal detection. This incident underlines a shift toward advanced, stealthy phishing tactics that weaponize graphics files and trusted institutional identities. The approach signifies an escalating trend in cybercrime, where threat actors continue to innovate to evade legacy controls and exploit user trust amid ongoing geopolitical unrest.
6 months ago
Kill Chain
2025’s Cyber Tsunami: Cisco 0-Day, Record DDoS & Multi-Vector Threats Unleashed
In September 2025, the global cybersecurity landscape faced a convergence of high-profile threats, including a critical Cisco 0-day vulnerability, record-breaking distributed denial-of-service (DDoS) attacks, an emergent LockBit 5.0 ransomware variant, multiple vulnerabilities targeting baseboard management controllers (BMC), and rapid expansion of the ShadowV2 botnet. Adversaries exploited the Cisco 0-day to gain privileged access, launched multi-vector DDoS assaults disrupting online services, compromised server hardware via BMC flaws, and weaponized the new LockBit variant for data extortion and ransomware. The combination of these attacks resulted in widespread operational instability, data breaches, and heightened risk exposure across cloud and on-premises environments. These incidents underscore the rapidly evolving threat landscape, marked by increasingly sophisticated and diverse attack vectors that target infrastructure, software, hardware, and supply chains simultaneously. The convergence of ransomware, DDoS, and zero-day exploitation—often driven by organized cybercriminal groups—signals an urgent need for organizations to adopt layered, zero trust security strategies and accelerate detection and response.
6 months ago
Kill Chain
CISA Expiration: The Looming Risk to U.S. Cyber Threat Intelligence Collaboration
In June 2024, the Cybersecurity Information Sharing Act (CISA) is poised to expire, potentially removing crucial liability protections that allow private and public entities to exchange cyber threat intelligence without fear of legal repercussions. If congressional reauthorization is not enacted, organizations may retreat from collaborative defense, risking increased exposure to sophisticated cyber threats like AI-driven attacks, ransomware, and advanced nation-state intrusions such as the recent Salt Typhoon telecommunications incidents. The expiration signals a return to pre-2015 conditions, where fear of litigation fostered information silos and hindered a unified defensive posture. This situation is particularly urgent given today’s rapidly evolving threat landscape, marked by automated attacks, cloud-scale lateral movement, and the surge of machine-driven identities. The outcome will shape both regulatory priorities and operational risk management for sectors relying on timely, actionable intelligence sharing.
6 months ago
Kill Chain
Akira Ransomware: MFA-Protected SonicWall VPNs Breached in 2024
In early 2024, the Akira ransomware group escalated its campaign by successfully breaching organizations through SonicWall SSL VPN appliances, even when multi-factor authentication (MFA) was enabled. Security researchers determined that Akira actors appeared to bypass one-time password (OTP) protections, potentially by leveraging previously obtained OTP seed information or exploiting weaknesses in authentication management. Following the VPN compromise, attackers moved laterally, exfiltrated data, and encrypted systems to demand substantial ransom payments. This attack vector enabled access to privileged internal resources, resulting in business disruption, data exposure, and financial losses for affected organizations. The incident underscores how ransomware operators are adapting to bypass commonly deployed defenses, specifically targeting VPN and MFA solutions. Such tactics highlight the urgent need for organizations to reassess remote access controls, authentication infrastructure, and visibility gaps, as similar techniques are increasingly observed in the wild.
6 months ago
Kill Chain
Dutch Teens Arrested for Espionage Attempt Targeting Europol via WiFi Sniffer
In September 2025, Dutch authorities arrested two 17-year-old boys who attempted to spy on Europol and other international entities in The Hague using WiFi sniffer devices. The teenagers, allegedly recruited via Telegram to work for Russian interests, conducted reconnaissance outside the offices of Europol, Eurojust, and the Canadian embassy, aiming to intercept wireless traffic. A tip-off from the Dutch intelligence service (AIVD) led to their arrest before any confirmed data breach occurred. Europol reported no compromise of its systems but is maintaining heightened vigilance. This incident underscores the evolving threat landscape where state-sponsored actors increasingly recruit and exploit minors for espionage activities. With attacks targeting wireless infrastructures and leveraging easily accessible tools, organizations must strengthen controls, enhance insider threat awareness, and expand security measures to non-traditional attack vectors.
6 months ago
Kill Chain
China-Linked PlugX and Bookworm Malware Strike Asian Telecoms in Advanced Attack
In mid-2025, a coordinated advanced persistent threat (APT) campaign linked to China targeted telecommunications and manufacturing entities across Central and South Asia. Attackers leveraged new PlugX and Bookworm malware variants, utilizing DLL side-loading techniques via legitimate applications to achieve persistence and evade detection. The intrusions allowed the threat actors to perform extensive reconnaissance, deploy additional payloads, and exfiltrate sensitive operational data from ASEAN and Asian telecom networks, demonstrating a high degree of stealth and sophistication in lateral movement. This incident underscores a growing uptick in nation-state cyber activity against Asian critical infrastructure, highlighting emerging malware evolution and increasingly covert lateral movement. With similar TTPs proliferating, organizations must elevate east-west traffic security and anomaly detection to stay ahead.
6 months ago
Kill Chain
Threat Insights: Nation-State Exploitation of Cisco ASA Zero-Days (ArcaneDoor 2025)
In September 2025, Cisco disclosed that a sophisticated nation-state threat actor, linked to the ArcaneDoor campaign, exploited multiple zero-day vulnerabilities in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. These attackers targeted government networks and critical infrastructure globally, leveraging CVE-2025-20333 and CVE-2025-20362, which enabled remote code execution, persistent malware installation, and data exfiltration. Advanced evasion tactics allowed the attackers to disrupt device logging and remain undetected for extended periods, while the deployment of custom malware such as RayInitiator and LINE VIPER provided long-term backdoor access to compromised environments. This case highlights growing trends in state-sponsored exploitation of perimeter devices and demonstrates how quickly nation-state TTPs can proliferate to broader criminal groups. The campaign triggered urgent mandates from CISA and NCSC for organizations—especially in the public sector—to patch and monitor edge infrastructure, emphasizing the escalating risk from zero-day vulnerabilities and the increasing sophistication of attacker methods.
6 months ago
Kill Chain
Volvo NA Employee SSNs Exposed in 2023 Supply Chain Ransomware Attack
In August 2023, Volvo Group North America (Volvo NA) suffered a significant data breach when its third-party HR software provider, Miljödata, was compromised by the DataCarry ransomware group. Attackers exploited weaknesses in Miljödata's cloud infrastructure, gaining unauthorized access and exfiltrating sensitive employee data—including names and Social Security numbers—belonging to nearly 20,000 Volvo NA employees. The incident, discovered days after the intrusion, led to a ransom demand before the stolen data was published on the Dark Web. While Volvo NA's own systems were not directly breached, the exposure of highly sensitive employee data has far-reaching implications for individual privacy and trust. This breach highlights growing risks from supply chain cyberattacks targeting SaaS providers and underscores the importance of rigorous third-party risk management. High-value employee PII leaks also raise urgent questions around operational resilience, compliance, and the potential for subsequent identity-driven fraud.
6 months ago
Kill Chain
GoAnywhere MFT Zero-Day (CVE-2025-10035): Anatomy of a 2025 Enterprise Breach
In September 2025, a maximum severity zero-day vulnerability (CVE-2025-10035) in Fortra’s GoAnywhere Managed File Transfer (MFT) platform was actively exploited in the wild. Attackers remotely injected commands via a deserialization flaw in the License Servlet, requiring only a forged license response signature to achieve pre-authentication remote code execution. The breach timeline reveals attackers gained access at least a week before public disclosure, establishing persistence via a backdoor admin account and deploying secondary payloads like SimpleHelp for ongoing access, with evidence of lateral movement reconnaissance. The incident underscores the increasing sophistication and rapid weaponization of zero-day exploits targeting widely used enterprise file transfer solutions. With high-profile breaches tied to vulnerabilities in GoAnywhere, pressure is mounting for organizations to reassess their exposure and incident response practices amid a sharp uptick in exploit automation and data exfiltration attacks.
6 months ago
Kill Chain
Cisco Firewall Zero-Day Incident: RayInitiator & LINE VIPER Malware Exposed
In September 2025, Cisco ASA firewalls faced a severe cybersecurity incident when threat actors leveraged recently disclosed zero-day vulnerabilities to secretly infiltrate network perimeters. The attackers exploited these flaws to deploy two newly discovered malware strains, RayInitiator and LINE VIPER, allowing them to bypass existing defenses, maintain persistence, and exfiltrate sensitive data from affected enterprises. This highly sophisticated campaign showcased advanced persistent threat (APT) tradecraft, utilizing encrypted command-and-control traffic and lateral movement within east-west network segments, impacting organizations across multiple sectors and creating significant operational and reputational risks. This incident underscores an emergent pattern of targeting network infrastructure devices with custom malware, reflecting broader shifts in attacker strategy. As attackers increasingly refine zero-day exploitation and expand their arsenal, organizations must adapt security postures to detect and respond to threats traversing both perimeter and internal network boundaries.
6 months ago
Kill Chain
Fortra GoAnywhere Zero-Day CVSS 10 Exploited Before Disclosure in 2025
In September 2025, a critical zero-day vulnerability (CVSS 10.0) in Fortra GoAnywhere Managed File Transfer software was actively exploited for at least a week before its public disclosure. Attackers leveraged the flaw to gain unauthorized access and potentially exfiltrate sensitive data from organizations using the platform, which is widely adopted in regulated sectors. The attack vector was weaponized rapidly by sophisticated threat groups and ransomware actors, highlighting systemic risks in third-party file transfer applications. The incident resulted in significant business disruption, data exposure, and triggered urgent patching activities across affected enterprises. This breach reflects a broader trend of adversaries increasingly targeting secure file transfer solutions via 0-day vulnerabilities, often achieving lateral movement and persistent footholds. It underscores the pressing need for proactive vulnerability management, real-time threat detection, and strong compliance practices amid rising regulatory scrutiny around data handling and supply chain exposures.
6 months ago
Kill Chain
SSL.com Certificate Abuse: Iranian APTs Sign Malware with Trusted Keys in 2024
In early 2024, multiple Iranian state-linked threat groups, including the Charming Kitten offshoot Subtle Snail, leveraged code-signing certificates issued by Houston-based SSL.com to digitally sign malware campaigns targeting organizations worldwide. Researchers discovered that the threat actors abused trusted certificates to bypass security controls and distribute malicious payloads, with their primary focus on espionage and data exfiltration. This compromised trust in legitimate software distribution channels and posed significant detection challenges for defenders, underscoring the evolving sophistication of APT campaigns tied to Iran. The incident highlights an uptick in supply chain and abuse-of-trust techniques among state-sponsored groups. Attackers are increasingly capitalizing on trusted processes—such as code signing—to slip past endpoint protection platforms, raising the regulatory and operational urgency for organizations dependent on digital certificate trust.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports