✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Critical WatchGuard Firebox VPN Flaw Exposes Businesses to Remote Attacks in 2025
In September 2025, WatchGuard revealed a critical remote code execution vulnerability (CVE-2025-9242) affecting its Firebox firewalls running Fireware OS 11.x, 12.x, and 2025.1. The flaw, caused by an out-of-bounds write in the iked process, could let unauthenticated attackers remotely execute code by exploiting VPN configurations utilizing IKEv2, even after vulnerable settings are removed if static gateway peers remain. While no active exploitation has been observed to date, the vulnerability exposes potentially 250,000 small and mid-sized business networks globally. This incident underscores the ongoing risks faced by organizations from appliance-level vulnerabilities in edge security devices, especially as attackers increasingly target VPN and firewall platforms in their campaigns. Recent ransomware activity and mandates from regulators have heightened industry awareness around patching and vigilance for these critical network components.
6 months ago
Kill Chain
Scattered Spider Strikes: 2024 Ransomware Attack on Transport for London Exposes Critical Gaps
In August 2024, Transport for London (TfL), a critical national infrastructure operator in the UK, suffered a significant ransomware attack attributed to the 'Scattered Spider' cybercrime collective. Law enforcement arrested two UK-based teenagers, believed to be key members of the group, after evidence tied them to not just the TfL breach but also a string of attacks targeting US healthcare and federal systems. The ransomware event caused extensive disruption to TfL’s internal and online systems, delayed refund processing, and ultimately led to a breach of customer data, including names, contact details, and addresses. Financial losses for TfL ran into the millions. This incident highlights both the growing capability and brazenness of young, English-speaking cybercriminals, as well as the expanding impact of ransomware on critical infrastructure and global enterprises. The subsequent law enforcement operation illustrates the increased regulatory scrutiny and international cooperation aimed at dismantling hacker collectives operating ransomware and extortion campaigns.
6 months ago
Kill Chain
RaccoonO365: Microsoft & Cloudflare Take Down Major Phishing-as-a-Service Network in 2024
In July 2024, Microsoft, in collaboration with Cloudflare and law enforcement, disrupted the RaccoonO365 Phishing-as-a-Service (PhaaS) operation, which enabled cybercriminals to launch large-scale phishing campaigns mimicking Microsoft 365 and other trusted brands. The service, run by Storm-2246 and attributed to Joshua Ogundipe, offered subscription-based kits that automated credential-theft campaigns targeting over 2,300 US organizations and at least 20 healthcare entities. The takedown involved seizing 338 domains, mapping the attack infrastructure, and revealing financial flows in cryptocurrency, shutting down an operation responsible for stealing at least 5,000 sets of credentials from 94 countries. This incident underscores the industrialization of phishing through subscription-based platforms and highlights how low-skill attackers are being enabled at scale. As phishing-as-a-service proliferates and leverages brand impersonation, organizations face escalating risks of credential theft and downstream ransomware or malware attacks.
6 months ago
Kill Chain
Microsoft's September 2025 Patch: Critical Azure & SMB Vulnerabilities Fixed
In September 2025, Microsoft released a critical security update addressing 80 vulnerabilities across its product suite, with particular focus on an SMB privilege escalation flaw and an Azure vulnerability rated CVSS 10.0. While eight of these vulnerabilities were classified as Critical and the rest as Important, none are reported to have been exploited in the wild at release. The patch release comes after public disclosures made some flaws widely known, elevating risk of exploitation. Microsoft urged organizations to immediately apply updates, highlighting the dangers posed by both privilege escalation and remote code execution vectors that could severely impact enterprise security. This incident underscores the continued rise in attacks targeting software supply chains and cloud platforms. With a surge in public disclosures and exploit tool availability, patch management has become both more challenging and more essential—particularly as attackers increasingly exploit unpatched vulnerabilities for lateral movement and privilege escalation.
6 months ago
Kill Chain
Google Chrome Zero-Day CVE-2025-10585: Exploit Puts Millions at Risk
In September 2025, Google addressed a critical security incident involving a zero-day vulnerability (CVE-2025-10585) within Chrome's V8 JavaScript and WebAssembly engine. This type confusion vulnerability was actively exploited in the wild, allowing attackers to execute arbitrary code in users’ browsers. The exploit’s ease of deployment and ability to bypass conventional browser defenses put millions of Chrome users at risk globally until Google released an urgent patch. The attack vector enabled threat actors to compromise targeted endpoints primarily through malicious web content. This incident highlights the ongoing proliferation and rapid exploitation of browser-based zero-days. Continuous advancements in attacker tactics—and their ability to weaponize browser vulnerabilities at scale—underscore the necessity for organizations to implement proactive patch management and behavioral threat detection aligned with zero trust strategies.
6 months ago
Kill Chain
SonicWall Cloud Backup Breach: Firewall Configurations Compromised, Credential Resets Urged
In September 2025, SonicWall disclosed a cloud security incident that exposed firewall configuration backup files tied to less than 5% of MySonicWall accounts, prompting a company-wide advisory to reset credentials for impacted users. The breach involved unauthorized access to backup firewall preference files hosted in SonicWall’s cloud backup service, which could potentially allow attackers insight into sensitive network policies and infrastructure details. Upon detection, SonicWall revoked affected credentials, reset authentication tokens, and notified regulatory authorities and end-users. The incident underscores operational risks associated with cloud-based configuration repositories and the downstream consequences for enterprise security posture. This breach highlights ongoing attacker focus on cloud storage services and device configuration files, which are increasingly targeted for initial access or lateral movement. As regulatory scrutiny grows and advanced threats seek out persistent footholds, organizations face mounting urgency to harden cloud storage, segment sensitive data, and enforce continuous credential hygiene.
6 months ago
Kill Chain
CountLoader: The Russian Ransomware Loader Redefining Post-Exploitation in 2025
In September 2025, cybersecurity researchers uncovered a major campaign involving CountLoader, a newly identified malware loader leveraged by Russian ransomware gangs. CountLoader has been deployed to infiltrate organizations by delivering post-exploitation tools such as Cobalt Strike, AdaptixC2, and the PureHVNC RAT via sophisticated phishing and initial access broker (IAB) operations. Notably, the loader is associated with affiliates of the LockBit ransomware group and is suspected to support both initial access sales and direct ransomware attacks. The campaign enabled attackers to establish stealthy persistence and remote control over compromised environments, amplifying threats of data theft, lateral movement, and disruptive encryption attacks. This incident highlights the growing adoption of multi-stage loader malware by established ransomware actors, blending traditional and cutting-edge post-exploitation tools for maximum impact. The tactics seen here illustrate the evolving, service-based ransomware ecosystem—one where payload delivery, access brokering, and command-and-control capabilities are modular and rapidly evolving in response to network defenses.
6 months ago
Kill Chain
GhostRedirector Backdoors Windows Servers with Malicious IIS Modules
In early 2024, ESET researchers uncovered a sophisticated cyber campaign known as GhostRedirector targeting Windows servers worldwide. The attacker employed a passive C++ backdoor and a malicious Microsoft IIS module, granting remote control and enabling the manipulation of Google search results. By compromising internet-facing IIS web servers, the threat actor covertly redirected visitors to malicious domains while maintaining persistent access through undetected, stealthy backdoors. The attack had the potential to facilitate broad influence operations, data exfiltration, and further deployment of malware on compromised networks. This incident highlights the growing risk of advanced web server threats utilizing legitimate application modules for stealthy persistence. Such tactics reflect a wider trend of attackers exploiting trusted infrastructure and automated SEO poisoning, challenging organizations to strengthen threat detection, zero trust controls, and incident response.
6 months ago
Kill Chain
HybridPetya Ransomware: UEFI Secure Boot Under Attack in 2024
In June 2024, ESET researchers discovered a ransomware variant dubbed HybridPetya, modeled after the infamous Petya/NotPetya malware, with a significant escalation in its capabilities. HybridPetya leverages the CVE-2024-7344 vulnerability to compromise UEFI-based systems, effectively bypassing Secure Boot protections on outdated hardware. Although not known to be active in broad campaigns, this bootkit joins a small group of malware capable of undermining the fundamental trust mechanisms securing modern machines, representing a sophisticated evolution in ransomware delivery and persistence techniques. HybridPetya’s emergence highlights the rapid adaptation of cybercriminals to harden malware against defensive controls. UEFI bootkit methods—once advanced nation-state territory—are now appearing in ransomware. Organizations must urgently review endpoint protections, hardware patching, and secure boot configurations to lower exposure to these new attack paths.
6 months ago
Kill Chain
HybridPetya Ransomware: UEFI Secure Boot Bypass Proof-of-Concept Shakes Firmware Security
In July 2025, ESET Research uncovered HybridPetya, a proof-of-concept ransomware closely mimicking the destructive Petya and NotPetya malware. HybridPetya features a novel UEFI bootkit component, capable of targeting both legacy and modern UEFI-based systems by exploiting CVE-2024-7344 to bypass Secure Boot protections. The malware operates by encrypting the Master File Table on NTFS partitions, leveraging advanced techniques such as malicious EFI application deployment and fake CHKDSK screens to evade detection. To date, ESET’s telemetry has found no evidence of HybridPetya in active attacks, and its development suggests an evolving threat landscape for ransomware targeting core system components. HybridPetya’s public discovery underscores an alarming trend: sophisticated ransomware is expanding its reach to firmware and boot processes, previously considered resilient to commodity malware. The rise of UEFI-targeting threats and Secure Boot bypass exploits highlights the urgent need for rigorous patch management and endpoint visibility, especially as new vulnerabilities (like CVE-2024-7344) become weaponized.
6 months ago
Kill Chain
SonicWall 2024 Breach: Cloud Portal Attack Exposes Firewall Configurations
In June 2024, SonicWall confirmed a security incident impacting its MySonicWall.com portal, where threat actors gained unauthorized access to backup firewall configuration files belonging to fewer than 5% of their customers. The attackers employed targeted brute-force attacks to access encrypted preference files stored in the cloud, potentially exposing sensitive network architecture and policy information. While SonicWall promptly disabled the affected backup feature, notified law enforcement and affected customers, and engaged incident response specialists, the exposure raises substantial risk of follow-on attacks and exploitation due to the detailed nature of the data compromised. This incident highlights a growing concern with threats targeting cloud-managed administrative platforms, especially those operated by key infrastructure vendors. As attackers pivot from device exploits to systemic attacks on cloud portals, organizations must scrutinize cloud data storage and vendor security practices more rigorously to mitigate downstream and supply chain risks.
6 months ago
Kill Chain
Microsoft Seizes RaccoonO365: 2024’s Largest Phishing-as-a-Service Credential Theft Takedown
In July 2024, Microsoft’s Digital Crimes Unit, in collaboration with law enforcement and cybersecurity partners, led a takedown of RaccoonO365—a subscription-based phishing-as-a-service platform operated by the threat group Storm-2246. Over 338 domains linked to RaccoonO365 were seized after being used to steal more than 5,000 Microsoft credentials across 94 countries since July 2024. The group’s kits, leveraging sophisticated evasion techniques and authentic-looking Microsoft branding, enabled cybercriminals to mount tax-themed and healthcare-targeted phishing campaigns, with sessions often bypassing multifactor authentication to harvest both passwords and session cookies. The breadth and pace of RaccoonO365’s operations highlight the commoditization and professionalization of cybercrime. This incident signals a shift towards scalable, as-a-service attack tools, increasing risks to organizations globally. Security teams must rapidly adapt to evolving TTPs and plug new identity-driven attack pathways, especially as phishing toolkits grow in accessibility and sophistication.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports