Validated Containment Architectures are here. →Explore

Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2390 threat reports
Page 190 of 200

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Government Administration Threat Reports

Showing 22692280 / 2390 reports
Russia-Backed Disinformation Targets Moldova's 2024 Election
Impact· high

Russia-Backed Disinformation Targets Moldova's 2024 Election

In early 2024, cybersecurity researchers uncovered a coordinated Russian disinformation campaign aimed at Moldova’s upcoming national elections. Threat actors, believed to be linked to state-sponsored Russian groups, leveraged social media platforms, fake news websites, and malicious amplification techniques to spread false narratives and undermine trust in Moldova’s electoral process. The campaign, tracked back to tactics active since 2022, included distribution of forged documents and coordinated inauthentic behavior to influence public perception and destabilize the region ahead of the vote. This incident reflects a broader surge in state-backed information operations targeting elections across Europe and globally. Such campaigns erode democratic institutions, manipulate public opinion, and heighten information security risks for governments and citizens. Organizations and governments must strengthen their capabilities to detect and mitigate influence operations and protect democratic processes.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Federal Agency Breach: GeoServer Zero-Day Exposes Gaps in 2024 Cyber Defense
Impact· medium

Federal Agency Breach: GeoServer Zero-Day Exposes Gaps in 2024 Cyber Defense

In July 2024, attackers exploited CVE-2024-36401—a critical remote code execution vulnerability in the open source GeoServer mapping server—less than two weeks after public disclosure, to breach a US federal civilian executive branch (FCEB) agency. The adversaries gained initial access to public-facing GeoServer instances, subsequently moving laterally through the network using living-off-the-land techniques, dropping web shells (including China Chopper), leveraging brute force and privilege escalation attacks, and establishing command-and-control with open-source tools. Due to delayed patching and inadequate incident response, attackers remained undetected for three weeks, compromising additional servers and extracting sensitive information related to geospatial data and internal credentials. This incident exemplifies the growing risk posed by rapid, post-disclosure exploitation of critical vulnerabilities, particularly those affecting widely deployed open source software. The breach also highlights persistent gaps in vulnerability management, security operations, and incident response readiness at major organizations, driving new urgency around patch timeliness and comprehensive monitoring.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Stately Taurus: 2022 Bookworm APT Campaign Unveiled in Southeast Asia
Impact· medium

Stately Taurus: 2022 Bookworm APT Campaign Unveiled in Southeast Asia

In 2022, cybersecurity researchers traced sophisticated spear-phishing attacks against government and commercial entities in Southeast Asia to Stately Taurus, a Chinese advanced persistent threat (APT) group active since at least 2012. Using the Bookworm malware, a modular remote access trojan (RAT) with advanced C2 and lateral movement capabilities, the threat actor gained initial access via tailored phishing emails, followed by persistence and data exfiltration. Detailed code analysis, shared infrastructure, unique PDB paths, and parallel tooling (e.g., ToneShell) confirmed high-confidence attribution. The campaign exposed OPSEC artifacts and overlapping infrastructure, confirming Stately Taurus’s long-term commitment to targeted espionage. This incident underscores a broader surge in targeted APT campaigns using modular malware and sophisticated infrastructure reuse. The precision of the Unit 42 Attribution Framework exemplifies the growing emphasis on multi-layered, evidence-based attribution, which is now critical as state-linked groups automate and diversify their attack techniques.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Cisco SNMP Zero-Day: Active Exploits Target IOS XE Network Devices in 2025
Impact· high

Cisco SNMP Zero-Day: Active Exploits Target IOS XE Network Devices in 2025

In September 2025, Cisco disclosed a critical vulnerability (CVE-2025-20352) affecting its IOS and IOS XE operating systems, actively exploited via the SNMP subsystem. The flaw stems from a stack-based buffer overflow that allows authenticated remote attackers to trigger denial-of-service or potentially achieve root-level remote code execution. Attackers utilized crafted SNMP packets over both IPv4 and IPv6 to compromise devices with SNMP enabled, including popular models like the Meraki MS390 and Catalyst 9300. Cisco confirmed attacks in the wild following credential compromise, urging immediate patching, as no reliable workarounds exist. This incident highlights the ongoing risks associated with ubiquitous network protocols like SNMP and the necessity of rapid response to zero-day exploits within core infrastructure. The rise of attacks targeting network management systems signals both increased attacker sophistication and heightened regulatory scrutiny.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Obscura Ransomware 2025: What Enterprises Must Learn About Active Directory Attacks
Impact· high

Obscura Ransomware 2025: What Enterprises Must Learn About Active Directory Attacks

In late August 2025, a newly discovered ransomware variant named Obscura was identified executing across several hosts within an enterprise network. The attack leveraged the organization's Active Directory infrastructure, using the NETLOGON share to automatically deploy a Go-based ransomware binary across all domain controllers and affected endpoints. The attackers created malicious scheduled tasks for persistent execution and attempted to enable remote desktop for potential lateral movement. The ransomware also attempted to disable endpoint recovery options, and the ransom note indicated both data encryption and exfiltration of sensitive company information. Limited security agent coverage hampered detection and response, amplifying the operational disruption and risk of sensitive data exposure. This incident underscores the evolving sophistication of ransomware actors in targeting critical authentication infrastructure and automated deployment mechanisms. As attackers increasingly combine data theft with operational disruption and target identity systems, organizations face heightened regulatory, financial, and reputational risks, warranting renewed focus on segmentation, visibility, and endpoint security.

6 months ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Unpatched SMS Flaw in OnePlus Phones Leaves User Messages Exposed
Impact· medium

Unpatched SMS Flaw in OnePlus Phones Leaves User Messages Exposed

In September 2025, a critical, still-unpatched vulnerability (CVE-2025-10184) was publicly disclosed in OnePlus smartphones running OxygenOS 12 through 15. Discovered by Rapid7, the flaw enables any installed app—without explicit permissions or user input—to access and exfiltrate SMS content and metadata on affected devices. This exposure was caused by insecurely exported content providers in the custom Android Telephony package, allowing SQL injection-style inference attacks. Despite multiple disclosure attempts, OnePlus did not respond for over four months; the details, including a proof of concept, were disclosed publicly to accelerate a fix. The case underscores rising risks from insecure mobile customizations and vendor slow response, especially as attackers increasingly exploit flaws in widely deployed consumer devices. With the proliferation of mobile-centric attacks and regulatory scrutiny on data privacy, this breach highlights the urgent need for robust patch management and proactive mobile security.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Cisco's 2025 SNMP Zero-Day: Credential Compromise Drives Network Device Exploit Surge
Impact· high

Cisco's 2025 SNMP Zero-Day: Credential Compromise Drives Network Device Exploit Surge

In September 2025, Cisco disclosed a high-severity zero-day vulnerability (CVE-2025-20352) affecting IOS and IOS XE network infrastructure devices. The flaw, a stack-based buffer overflow in the SNMP subsystem, allowed remote, authenticated attackers with low privileges to cause denial-of-service and, in some cases, permitted high-privileged attackers to fully compromise devices. Exploitation was detected after local administrator credentials were stolen, enabling threat actors to send malicious SNMP packets over IPv4/IPv6, impacting unpatched devices globally. Immediate patching was recommended as no workarounds existed except tightly restricting SNMP access. This incident underscores the criticality of timely patching and robust identity and network access controls, as attackers increasingly target network infrastructure via both credential compromise and protocol-level vulnerabilities. Industry-wide, it marks an escalating trend of high-impact, infrastructure-level exploits requiring urgent coordinated response.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Supermicro’s 2025 BMC Firmware Flaws Expose Critical Backdoor Risks
Impact· medium

Supermicro’s 2025 BMC Firmware Flaws Expose Critical Backdoor Risks

In September 2025, Supermicro disclosed critical firmware vulnerabilities (CVE-2025-7937 and CVE-2025-6198) affecting its server Baseboard Management Controller (BMC). Security researchers at Binarly demonstrated that attackers could leverage these flaws to bypass firmware signature verification and the BMC root of trust, allowing deployment of persistent, malicious firmware on widely used Supermicro servers. Exploits could grant adversaries complete, long-term control over both the BMC and host OS, enabling stealthy persistence and reliable evasion of security controls, while systems appeared to be running valid, signed code. Supermicro confirmed the vulnerabilities, releasing firmware patches, but proof-of-concept exploits are already public. This incident underscores the evolving challenge of hardware-level attacks, as advanced threat actors increasingly target supply chain and firmware layers to establish persistent, hard-to-detect footholds. Recent regulatory pressure and rising incidents of firmware-based threats highlight the urgency for security teams to elevate visibility and controls across hardware trust boundaries.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Attackers Leverage Pandoc SSRF Vulnerability CVE-2025-51591 to Breach AWS IMDS
Impact· low

Attackers Leverage Pandoc SSRF Vulnerability CVE-2025-51591 to Breach AWS IMDS

In September 2025, threat actors exploited a newly disclosed Server-Side Request Forgery (SSRF) vulnerability in the open-source Linux utility Pandoc (CVE-2025-51591), targeting Amazon Web Services (AWS) cloud environments. The attackers leveraged the flaw to send unauthorized requests to the AWS Instance Metadata Service (IMDS), allowing them to obtain EC2 role credentials and elevate cloud permissions. Security researchers, including Wiz, observed active exploitation in the wild, leading to unauthorized access and potential data exfiltration from affected AWS infrastructure. Organizations relying on Pandoc as part of their cloud automation workflows face heightened risk of credential compromise and lateral movement across accounts. This incident underscores a fast-evolving cloud threat landscape, where attackers exploit supply-chain and open-source vulnerabilities to traverse trusted infrastructure and target sensitive identity and metadata services. The rapid weaponization of CVE-2025-51591 mirrors the broader trend of SSRF attacks on cloud metadata, driving urgent calls for proactive detection, segmentation, and credential management in multi-cloud environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
State-Sponsored Actors Breach Libraesva ESG via Command Injection Vulnerability
Impact· low

State-Sponsored Actors Breach Libraesva ESG via Command Injection Vulnerability

In September 2025, Libraesva disclosed a command injection vulnerability (CVE-2025-59689, CVSS 6.1) affecting its Email Security Gateway (ESG) platform, which was actively exploited by state-sponsored threat actors. Attackers leveraged maliciously-crafted email payloads to trigger remote command execution, bypassing ESG protections and potentially gaining persistent access to targeted networks. The intrusion method allowed attackers to move laterally and exfiltrate sensitive data, underscoring the risks posed by the exploitation of security appliances themselves. Libraesva released emergency patches and urged customers to upgrade immediately, as evidence emerged of ongoing targeted campaigns against critical sectors. This incident highlights the increasing use of email gateway exploits by sophisticated adversaries, aligning with a wider trend of targeting security infrastructure for initial access. With command injection flaws on the rise and ransomware operators adopting similar approaches, organizations face escalating pressure to rapidly patch vulnerabilities and reinforce segmentation and anomaly detection across their environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
YiBackdoor: A Sophisticated Backdoor Malware Campaign Bridging IcedID and Latrodectus
Impact· low

YiBackdoor: A Sophisticated Backdoor Malware Campaign Bridging IcedID and Latrodectus

In June 2025, researchers discovered YiBackdoor, a novel malware family exhibiting significant source code overlaps with the notorious IcedID and Latrodectus strains. Campaigns leveraging YiBackdoor execute advanced backdoor techniques that establish remote access, command execution, and data exfiltration within compromised environments. YiBackdoor is typically deployed as part of a multi-stage attack campaign, using phishing or malicious attachments as its primary entry vector. Its detection signaled the emergence of new collaborative threats between criminal malware groups, raising concerns over increased code sharing and tool evolution. This incident highlights growing technical sophistication and cross-pollination between established malware actors. The use of YiBackdoor in conjunction with IcedID and Latrodectus demonstrates adversary agility and the accelerated pace of malware innovation, elevating the threat to enterprises reliant on traditional detection models.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
RedNovember: 2025 Chinese State Cyber Espionage Campaign Hits Global Governments
Impact· low

RedNovember: 2025 Chinese State Cyber Espionage Campaign Hits Global Governments

In mid-2025, a Chinese state-sponsored threat group known as RedNovember (previously tracked as TAG-100) orchestrated a widespread cyber espionage campaign targeting government and private sector organizations across Africa, Asia, North America, South America, and Oceania. The attackers leveraged sophisticated tools including the Pantegana backdoor and Cobalt Strike to establish persistence, perform lateral movement, and exfiltrate sensitive data. Entry vectors included spear-phishing emails and exploitation of known network vulnerabilities, allowing RedNovember to stealthily compromise high-value systems and harvest intelligence for extended periods before discovery. The impact included unauthorized access to confidential government documents and disruption of critical data workloads. This incident underscores the persistent evolution of state-sponsored attack tactics, with RedNovember employing advanced, evasive techniques and custom malware. The growing use of encrypted command-and-control traffic and living-off-the-land strategies sets a concerning precedent, especially for government agencies and regulated enterprises facing a surge in sophisticated espionage operations.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports