✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
FortiBleed: Unprecedented Exposure of Fortinet Credentials in 2026
In June 2026, a significant cybersecurity incident known as 'FortiBleed' was uncovered, exposing nearly 74,000 Fortinet firewall and VPN credentials. Security researcher Volodymyr 'Bob' Diachenko discovered a server containing valid Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords for 73,932 firewall URLs worldwide. The exposed data also included organizational details such as industry, revenue, and employee count, suggesting the information was compiled to facilitate future attacks. Threat intelligence company Hudson Rock described this as one of the largest known collections of compromised Fortinet credentials, spanning 21,632 unique domains across 194 countries. The 'FortiBleed' incident underscores the critical importance of securing network devices against credential-based attacks. Organizations are urged to implement robust password policies, enable multifactor authentication, and regularly monitor for unauthorized access to mitigate such threats.
1 month ago
Kill Chain
CISA Confirms Active Exploitation of Splunk Enterprise Vulnerability CVE-2026-20253
In June 2026, a critical vulnerability (CVE-2026-20253) was identified in Splunk Enterprise versions 10.2.0 to 10.2.3 and 10.0.0 to 10.0.6, allowing unauthenticated remote attackers to create or truncate arbitrary files via a PostgreSQL sidecar service endpoint lacking authentication controls. This flaw enables potential remote code execution, posing significant risks to affected systems. ([advisory.splunk.com](https://advisory.splunk.com/advisories/SVD-2026-0603?utm_source=openai)) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation of this vulnerability and has mandated federal agencies to patch their systems by June 22, 2026.
1 month ago
Kill Chain
Texas Parks and Wildlife Department Data Breach Exposes Over 3 Million Records
In June 2026, the Texas Parks and Wildlife Department (TPWD) disclosed a significant data breach involving its license system vendor, exposing personal information of over 3 million individuals. The compromised data includes driver's license information, passport numbers, email addresses, phone numbers, and residential addresses. Notably, Social Security numbers, dates of birth, and financial information were not affected. The breach was detected by the Texas Cyber Command, prompting an immediate investigation and the implementation of enhanced security measures. ([tpwd.texas.gov](https://tpwd.texas.gov/about/notification-of-data-security-incident/?utm_source=openai)) This incident underscores the escalating risks associated with third-party vendors in data security. Organizations are increasingly vulnerable to breaches through external partners, highlighting the necessity for stringent vendor management and comprehensive security protocols to safeguard sensitive information.
1 month ago
Kill Chain
The Gentlemen RaaS Unleashes GentleKiller: A New EDR Evasion Framework
In June 2026, The Gentlemen ransomware-as-a-service (RaaS) operation was identified as actively developing and distributing a suite of endpoint detection and response (EDR) termination tools, collectively known as the GentleKiller framework. This framework targets approximately 400 processes associated with 48 distinct security programs, effectively disabling system defenses prior to deploying ransomware payloads. The Gentlemen group has demonstrated rapid operationalization of newly disclosed proof-of-concept exploits, often integrating them within days of public release. The Gentlemen's ability to swiftly adapt and enhance their EDR evasion techniques underscores a significant evolution in ransomware tactics, emphasizing the need for organizations to implement robust, multi-layered security measures. The group's extensive use of the bring your own vulnerable driver (BYOVD) technique highlights the importance of monitoring and controlling driver installations to prevent such attacks.
1 month ago
Kill Chain
FortiBleed Campaign: A Wake-Up Call for Credential Security
In June 2026, the 'FortiBleed' campaign was uncovered, revealing that cybercriminals had compromised approximately 73,932 Fortinet FortiGate firewalls across 194 countries. The attackers, identified as Russian-speaking, executed over 1.1 billion credential attempts against FortiGate VPN instances and 2.1 billion against Microsoft SQL Server systems. They exploited weak or default credentials and intercepted SSL VPN authentication hashes, which were cracked using a 45-GPU cluster managed through Hashtopolis. This led to unauthorized access to internal Active Directory environments, affecting sectors such as government, telecommunications, financial services, healthcare, manufacturing, and critical infrastructure. Notably, a Turkish NATO defense contractor reportedly lost classified documents due to this breach. This incident underscores the critical importance of robust credential management and the implementation of multi-factor authentication (MFA). The scale and sophistication of the FortiBleed campaign highlight the evolving tactics of threat actors and the necessity for organizations to proactively secure their network devices and monitor for unauthorized access.
1 month ago
Kill Chain
Critical Vulnerability in Schneider Electric's EasyLogic T150 and Saitel DP Devices
In May 2026, Schneider Electric disclosed a critical vulnerability (CVE-2026-6865) in its EasyLogic T150 and Saitel DP Remote Terminal Units (RTUs) and Controllers. This path traversal flaw allows unauthorized access to sensitive files, potentially compromising system integrity. Affected versions include EasyLogic T150 firmware up to 11.06.31 and Saitel DP firmware up to 11.06.36. Schneider Electric has released firmware updates to address this issue. This incident underscores the persistent risks in industrial control systems, especially within critical infrastructure sectors like energy and manufacturing. Organizations must prioritize timely patching and robust access controls to mitigate such vulnerabilities.
1 month ago
Kill Chain
Critical Security Alert: AVer PTC Cameras Vulnerable to Remote Code Execution (CVE-2026-40624)
In June 2026, a critical vulnerability (CVE-2026-40624) was identified in AVer PTC series cameras, including models PTC500S, PTC115, PTC500+, and PTC115+. This flaw allows remote, unauthenticated attackers to execute arbitrary code via specially crafted web requests, potentially leading to full device compromise. The vulnerability affects all firmware versions of these models. AVer has released firmware updates to address this issue, and users are strongly advised to apply these patches promptly to mitigate the risk of exploitation. This incident underscores the ongoing security challenges in IoT devices, particularly in the surveillance sector. The ease of exploitation and the critical nature of the affected devices highlight the importance of regular firmware updates and robust network security practices to protect against emerging threats.
1 month ago
Kill Chain
Fortinet Credential Exposure 2026: Massive 'FortiBleed' Campaign
In June 2026, a significant cybersecurity incident known as 'FortiBleed' exposed credentials associated with approximately 74,000 Fortinet devices, including firewalls and VPN gateways. Security researchers discovered a massive archive containing FortiGate firewall URLs, usernames, emails, and plaintext passwords from major corporations such as Chevron, Samsung, Foxconn, and Toyota. The attackers, reportedly Russian-speaking, executed over 1.1 billion credential attempts against 320,000 FortiGate VPN instances, leading to the compromise of Active Directory environments and, in some cases, the exfiltration of classified documents. Fortinet responded by emphasizing best practices like regular credential updates and enabling multi-factor authentication (MFA) to mitigate risks. This incident underscores the critical importance of robust credential management and the implementation of MFA, especially for internet-facing systems. The scale and sophistication of the 'FortiBleed' campaign highlight the evolving tactics of cyber adversaries and the necessity for organizations to proactively secure their network infrastructures.
1 month ago
Kill Chain
Anthropic's Fable 5 AI Model Suspended Amid National Security Concerns
In June 2026, Anthropic released its advanced AI model, Fable 5, designed to autonomously identify and exploit software vulnerabilities. Shortly after its release, the U.S. government classified Fable 5 as a potential national security threat, citing concerns over its capability to be 'jailbroken' and misused by malicious actors. Consequently, Anthropic was ordered to suspend access to the model for all foreign nationals, leading the company to disable Fable 5 entirely due to the inability to selectively restrict access. This abrupt shutdown has sparked significant debate within the cybersecurity community, with experts arguing that such restrictions may hinder defensive research more than deter malicious use. The incident underscores the challenges in balancing AI innovation with national security and the need for clear regulatory frameworks to manage the dual-use nature of advanced AI technologies.
1 month ago
Kill Chain
Critical NGINX Vulnerabilities CVE-2026-42530 and CVE-2026-42055 Disclosed by F5
In June 2026, F5 disclosed two critical vulnerabilities in NGINX, identified as CVE-2026-42530 and CVE-2026-42055. These flaws reside in the ngx_http_v3_module and the ngx_http_proxy_v2_module/ngx_http_grpc_module, respectively. Unauthenticated remote attackers can exploit these vulnerabilities to cause denial-of-service conditions or execute arbitrary code on systems with non-default configurations. Exploitation leads to use-after-free or heap-based buffer overflow in the NGINX worker process, potentially resulting in system crashes or code execution, especially on systems where Address Space Layout Randomization (ASLR) is disabled or bypassed. The disclosure underscores the persistent risk posed by vulnerabilities in widely used web server software. Organizations relying on NGINX should promptly apply the provided security patches or implement recommended mitigations to prevent potential exploitation. This incident highlights the importance of regular security assessments and timely updates to maintain system integrity.
1 month ago
Kill Chain
Apple Addresses Critical Bluetooth Vulnerability in Beats Studio Buds
In June 2026, Apple addressed a critical vulnerability (CVE-2025-20701) in its Beats Studio Buds wireless earbuds. This flaw allowed attackers within Bluetooth range to access the device's microphone without user consent, potentially enabling eavesdropping on conversations. The issue originated from a missing authentication mechanism in the Airoha Bluetooth audio SDK used in the earbuds. Apple released firmware update 1B211 to mitigate this risk, which is automatically applied when the earbuds are paired with an iPhone, iPad, or Mac. This incident underscores the importance of securing Bluetooth devices against unauthorized access. As wireless peripherals become more prevalent, ensuring robust authentication protocols is crucial to prevent potential breaches and protect user privacy.
1 month ago
Kill Chain
Gentlemen Ransomware's Advanced EDR Killers: A 2026 Threat Analysis
In June 2026, the Gentlemen ransomware-as-a-service (RaaS) operation was observed actively developing and deploying a suite of endpoint detection and response (EDR) killer tools to evade detection during attacks. The primary tool, dubbed 'GentleKiller,' has at least eight variants that impersonate legitimate security products such as Kaspersky, Valorant, Javelin, and WatchDog. These tools utilize the 'bring your own vulnerable driver' (BYOVD) technique to gain kernel-level privileges and disable security processes, targeting over 400 processes associated with approximately 48 security vendors, including Microsoft, CrowdStrike, and SentinelOne. The binaries are protected using commercial packers like Enigma and Themida, and some variants employ stolen digital signatures to further obfuscate their malicious activities. This development underscores a growing trend among ransomware operators to enhance their evasion capabilities by systematically disabling security defenses, thereby increasing the success rate of their attacks. Organizations must remain vigilant and adopt comprehensive security measures to detect and mitigate such sophisticated threats.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports