✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Secret Service Disrupts Extensive NYC Telecom Threat Targeting UN Assembly
In September 2025, the U.S. Secret Service disrupted a sophisticated illicit telecom infrastructure in the New York City area, uncovering more than 300 servers and over 100,000 SIM cards located near the United Nations General Assembly. The operation identified a network enabling encrypted, anonymous communications allegedly used by foreign actors, criminals, and potentially threat groups to coordinate activities and transmit assassination threats. Investigators warned that the scale of the system posed significant risk, including the theoretical ability to disable cellular networks and disrupt critical communications during high-security events. This incident highlights rising risks of criminal and nation-state actors leveraging physical telecom infrastructure to subvert detection, illustrating how sophisticated SIM farms and server farms can facilitate large-scale anonymity and attacks. The operation underscores heightened scrutiny on telecom supply chain security during high-profile events and the need for robust infrastructure monitoring.
6 months ago
Kill Chain
AT&T 2023: How Salt Typhoon Changed the APT Playbook
In 2023, the telecommunications giant AT&T was targeted by the advanced persistent threat group Salt Typhoon, which launched a sophisticated campaign exploiting unconventional vulnerabilities. Unlike conventional attacks, Salt Typhoon focused on endpoints lacking robust detection and response (EDR), hunted for network blind spots with minimal logging, and engaged in 'living off the land' attacks—leveraging legitimate administrative tools to evade detection and persist inside networks. This multi-pronged methodology enabled deep network infiltration before discovery, ultimately jeopardizing sensitive data and service availability across AT&T’s infrastructure. Following the breach, the company reported the threat group was successfully evicted from its systems. This incident has set a precedent, with numerous threat actors now adopting Salt Typhoon’s tactics to bypass traditional security controls. The breach highlights an urgent need for organizations to enhance monitoring, bolster endpoint visibility across all platforms, and adapt defenses for evolving attacker methodologies in critical infrastructure sectors.
6 months ago
Kill Chain
EDR-Freeze: Novel Windows WER Technique Suspends EDR and Antivirus Tools
In September 2025, a security researcher revealed a novel user-mode evasion technique leveraging Windows Error Reporting (WER) to suspend the operation of Endpoint Detection & Response (EDR) and antivirus software. The proof-of-concept tool, EDR-Freeze, exploits a race condition by combining the WerFaultSecure component with the MiniDumpWriteDump API. Attackers can indefinitely freeze security processes by suspending WerFaultSecure precisely as it is executing a memory dump of the target, effectively leaving EDR or AV tools inert without requiring kernel-level vulnerabilities. This design weakness bypasses typical Bring Your Own Vulnerable Driver (BYOVD) defences and leaves minimal forensic evidence. This incident underscores the increasing sophistication of EDR evasion by cyber adversaries, who are rapidly adopting stealthy, native Windows attack chains. Organizations must adapt detection and monitoring practices to keep pace as user-mode bypasses erode longstanding layers of endpoint protection. The wider prevalence of such techniques signals a strategic shift in attacker tradecraft and compels a reassessment of endpoint hardening and response automation.
6 months ago
Kill Chain
Microsoft Entra ID Flaw Exposed: How One Vulnerability Enabled Global Admin Impersonation
In September 2025, Microsoft disclosed a severe security flaw (CVE-2025-55241) affecting its Entra ID (formerly Azure Active Directory) service. The vulnerability, which received a maximum CVSS score of 10.0, allowed threat actors to bypass token validation and impersonate any user—including Global Administrators—across any tenant. Successful exploitation could grant attackers unrestricted access to sensitive data and resources within affected organizations, making this a high-impact privilege escalation incident. Microsoft responded swiftly, issuing a critical patch to contain the risk and urging immediate customer action. This incident highlights the ongoing trend of identity-based attacks against cloud platforms, emphasizing the necessity of robust access controls and vigilant monitoring. The discovery reinforces the risks of SaaS/IDaaS privilege escalation, as attackers increasingly target provider-side weaknesses to achieve large-scale compromise.
6 months ago
Kill Chain
Multi-Vector Cyberattack 2025: AI, Chrome 0-Day, DDR5 and npm Supply Chain Breach
In September 2025, a multifaceted wave of cyber threats was observed, including a Chrome zero-day exploit, AI-generated hacking toolkits, active exposure of DDR5 memory vulnerability (Rowhammer-based bit-flip attacks), and a virulent npm worm targeting the software supply chain. Attackers leveraged 0-day browser exploits to execute malicious code, engineered advanced AI tools for automation, and deployed the npm worm to laterally move via package dependencies. The surge in attack sophistication resulted in unauthorized access, rapid lateral movement, and significant operational disruption for developers and enterprises globally. This incident underscores an urgent pivot in attacker tactics—combining classic and novel vulnerabilities across infrastructure, code, and memory. The simultaneous exploitation of multiple vectors signals a broader trend of adaptive threat landscapes, increasing regulatory scrutiny, and the need for rapid detection, cross-layer visibility, and agile patching cycles.
6 months ago
Kill Chain
Critical Microsoft Entra ID Flaw Put Every Cloud Tenant at Risk in 2024
In early 2024, cybersecurity researchers uncovered a critical authentication flaw affecting Microsoft Entra ID (formerly Azure Active Directory), potentially enabling attackers to hijack any company's Entra ID tenant worldwide. By exploiting legacy identity features in combination with certain misconfigurations, attackers could bypass authentication controls and gain unauthorized administrative access, allowing full control over organizational resources in the affected tenants. Prompt discovery and responsible disclosure to Microsoft helped prevent active exploitation, though the underlying issue raised significant concern across the enterprise cloud ecosystem. This incident underscores the urgent need for organizations to continuously review legacy configurations, monitor identity security posture, and respond proactively to new classes of authentication bypass risks. With identity-based attacks rising across sectors, cloud environments are particularly vulnerable, highlighting zero trust best practices and ongoing vigilance as regulatory and threat environments evolve.
6 months ago
Kill Chain
2025 Picus Blue Report: Why Ransomware Still Evades Defenses
In early 2025, the Picus Blue Report identified a concerning trend in global ransomware attacks: despite widespread awareness of ransomware tactics, organizations failed to prevent over a third of attack attempts, with prevention rates plummeting to 62%. Far more alarming, only 3% of simulated data exfiltration attempts were effectively blocked, exposing substantial gaps in data security frameworks. Attackers leveraged a blend of known and emerging ransomware variants to infiltrate networks, bypassing traditional and next-gen defenses by exploiting east-west traffic and insufficient segmentation. This led to successful encryption and large-scale data theft, disrupting business continuity for multiple sectors globally. This incident underscores a broader industry challenge: as ransomware evolves, so do the techniques for bypassing established defenses. The drastic fall in exfiltration prevention highlights an urgent need for modernized controls, especially with the regulatory and reputational stakes of breaches rising sharply in 2025.
6 months ago
Kill Chain
Fortra GoAnywhere MFT 2024: License Servlet Zero-Day Exposes File Transfer Infrastructure
In June 2024, Fortra disclosed a critical vulnerability (CVE-2024-XXXX) in its GoAnywhere Managed File Transfer (MFT) product’s License Servlet, enabling unauthenticated attackers to execute system commands remotely via command injection. Researchers discovered that by submitting crafted requests to the vulnerable servlet, attackers could gain full control of affected servers. No authentication was required, significantly increasing the risk of exploitation. Fortra released immediate security updates and guidance after reports of active exploitation attempts surfaced. Impacted organizations primarily included enterprises leveraging GoAnywhere MFT for secure file transfers, resulting in heightened risk of data exfiltration and business disruption. This incident underscores the ongoing importance of timely patch management, especially for widely used secure transfer solutions. The vulnerability’s ease of exploitation and criticality reflects trends of attackers targeting third-party file transfer products—often for extortion or ransomware campaigns—prompting renewed regulatory and industry scrutiny.
6 months ago
Kill Chain
Inside the Ivanti EPMM 2025 Breach: How China-Linked APTs Exploited Zero-Day Flaws
In May 2025, advanced threat actors exploited two zero-day vulnerabilities (CVE-2025-4427 and CVE-2025-4428) in Ivanti Endpoint Manager Mobile (EPMM), targeting on-premise deployments. Attackers used an authentication bypass and code injection to deliver modular malware kits via crafted API requests, enabling them to gain initial access, perform reconnaissance, harvest credentials, and establish persistence within target environments. While Ivanti released patches shortly after discovery, the exploits were reportedly active before disclosure, affecting a limited set of organizations—primarily through an advanced persistent threat (APT) operation attributed by third-party researchers to a China-nexus espionage group. This incident underscores the growing trend of sophisticated supply chain and zero-day attacks on enterprise mobile device management (MDM) platforms, which are increasingly treated as high-value assets due to their access to sensitive business operations. Organizations must remain vigilant by prioritizing comprehensive patch management and strengthening internal traffic monitoring to mitigate similar risks.
6 months ago
Kill Chain
How 'ShadowLeak' Turned ChatGPT into a Data Exfiltration Channel
In mid-2024, security researchers uncovered a novel cyberattack—dubbed 'ShadowLeak'—that exploits OpenAI’s ChatGPT platform to surreptitiously exfiltrate emails and sensitive enterprise data. Threat actors leveraged covert techniques to route data through OpenAI’s infrastructure, effectively bypassing traditional network security controls and leaving virtually no forensic traces within the victim organization. The attack exploits the trusted status of sanctioned AI platforms inside corporate environments, making malicious exfiltration activity blend in with legitimate AI-assisted workflow traffic. As a result, internal monitoring and traditional DLP tools fail to identify or intercept the breach, putting confidential business communications and data at risk. This incident spotlights the growing risk posed by increasingly sophisticated methods of data exfiltration over legitimate AI services. With organizations accelerating the adoption of generative AI in critical business processes, attackers are exploiting technical and policy blind spots, making traditional perimeter defenses inadequate against such stealthy insider threats.
6 months ago
Kill Chain
Critical Fortra GoAnywhere 2025 Vulnerability Enables Command Injection Attacks
In early June 2025, Fortra disclosed a critical command injection vulnerability (CVE-2025-10035) in its GoAnywhere managed file transfer (MFT) solution. The flaw could be exploited by unauthenticated attackers if the management interface was exposed to the Internet, allowing remote code execution and potential takeover of affected servers. Fortra warned that active exploitation had been observed, and threat actors were leveraging the vulnerability to move laterally within compromised networks and facilitate data exfiltration. The incident affected a broad range of organizations reliant on GoAnywhere for secure file transfers, raising concerns about operational continuity and potential data exposure. The attack underscores the ongoing risk posed by internet-exposed enterprise services and highlights the urgent need for timely patching of high-severity vulnerabilities. Increasingly, ransomware and data theft campaigns are targeting known security flaws in widely-used third-party solutions, putting supply chains and regulatory compliance at risk.
6 months ago
Kill Chain
Gamaredon & Turla: Joint APT Campaign Strikes Ukraine in 2025
In early 2025, a previously unseen collaboration between advanced persistent threat groups Gamaredon and Turla was discovered in Ukraine. Utilizing ESET telemetry, researchers identified co-compromises in which Gamaredon provided initial access using spearphishing and malicious PowerShell-based tools (such as PteroGraphin and PteroOdd), allowing Turla to deploy its exclusive Kazuar backdoor on select high-value targets. The attacks, attributed to Russian FSB-linked groups, targeted governmental entities and leveraged encrypted channels, PowerShell scripting, and multi-stage malware delivery via compromised web services and cloud platforms. Impact was mainly concentrated on the potential exfiltration of sensitive national intelligence. This incident underscores a growing trend of threat actor collaboration within nation-state cyber operations, blurring lines between operational roles and increasing attack efficiency. The overlapping TTPs and use of novel access and persistence mechanisms signal heightened complexity in the Eastern European threat landscape, demanding urgent operational and strategic defensive improvements.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports