The Containment Era is here. →Explore

Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2329 threat reports
Page 3 of 195

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Government Administration Threat Reports

Showing 2536 / 2329 reports
RefluXFS (CVE-2026-64600): Critical Linux Kernel XFS Vulnerability
Impact· HIGH

RefluXFS (CVE-2026-64600): Critical Linux Kernel XFS Vulnerability

On July 22, 2026, a critical vulnerability known as RefluXFS (CVE-2026-64600) was disclosed, affecting the Linux kernel's XFS filesystem. This flaw allows unprivileged local users to overwrite root-owned files, such as `/etc/passwd` or setuid-root binaries, by exploiting a race condition in the copy-on-write (CoW) mechanism. The exploit enables attackers to gain persistent root access without leaving traces in kernel logs, and the changes persist across reboots. Systems running Linux kernel version 4.11 or later with XFS filesystems created with `reflink=1` are vulnerable. Default installations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux are particularly at risk. ([blog.qualys.com](https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600?utm_source=openai)) The RefluXFS vulnerability underscores the importance of timely patch management and system monitoring. With over 16.4 million systems potentially affected, organizations must prioritize updating their Linux distributions and implementing security measures to prevent unauthorized access and potential data breaches. ([secnews.gr](https://www.secnews.gr/en/723207/refluxfs-cve-2026-64600-linux-xfs-16m-systems/?utm_source=openai))

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Authentication Bypass in Check Point SmartConsole (CVE-2026-16232) Exploited
Impact· CRITICAL

Critical Authentication Bypass in Check Point SmartConsole (CVE-2026-16232) Exploited

In July 2026, Check Point identified a critical authentication bypass vulnerability (CVE-2026-16232) in its SmartConsole login process, allowing unauthenticated remote attackers to gain full administrative privileges. Exploitation requires internet access to the Management Server IP address and a configuration without Trusted Clients restrictions. Successful attacks enable modification of security policies and configurations. Check Point confirmed active exploitation affecting a limited number of customers. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-16232?utm_source=openai)) This incident underscores the escalating risks associated with exposed management interfaces and the necessity for stringent access controls. Organizations must prioritize timely patching and restrict management access to trusted IP addresses to mitigate such vulnerabilities.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Unveiling JadeProx: China's New Cyber Threat Targeting Critical Sectors
Impact· HIGH

Unveiling JadeProx: China's New Cyber Threat Targeting Critical Sectors

In mid-April 2026, cybersecurity firm Group-IB uncovered an exposed Alibaba Cloud server linked to a China-nexus operation named JadeProx. This operation targeted government, healthcare, and education sectors across Asia and Latin America using a previously undocumented Windows loader called TriBack Loader. The attackers exploited vulnerabilities in public-facing applications, deploying web shells to gain initial access, and utilized sophisticated techniques such as DLL sideloading and encrypted payloads to evade detection. Notably, the campaign included intrusions into a Vietnamese public hospital's medical imaging system and Malaysia's Ministry of Foreign Affairs. The discovery of JadeProx underscores the evolving tactics of state-sponsored threat actors, emphasizing the need for organizations to bolster their cybersecurity defenses. The use of advanced loaders like TriBack Loader highlights the importance of monitoring for novel malware strains and implementing robust security measures to protect sensitive data and critical infrastructure.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Adds Critical Vulnerabilities to Known Exploited Vulnerabilities Catalog
Impact· CRITICAL

CISA Adds Critical Vulnerabilities to Known Exploited Vulnerabilities Catalog

On July 22, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-16232 and CVE-2026-50522. CVE-2026-16232 is an authentication bypass vulnerability in Check Point SmartConsole, allowing unauthenticated remote attackers to gain administrative access and modify security policies. CVE-2026-50522 is a deserialization vulnerability in Microsoft SharePoint, enabling unauthorized remote code execution without authentication. Both vulnerabilities are actively exploited, posing significant risks to organizations using these platforms. The inclusion of these vulnerabilities in the KEV Catalog underscores the increasing trend of attackers targeting critical infrastructure through widely used enterprise applications. Organizations are urged to prioritize the remediation of these vulnerabilities to mitigate potential breaches and maintain compliance with security directives.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Chaos Ransomware's msaRAT: Exploiting Browsers for Stealthy C2 Channels
Impact· HIGH

Chaos Ransomware's msaRAT: Exploiting Browsers for Stealthy C2 Channels

In July 2026, the Chaos ransomware group deployed a new Rust-based remote access trojan (RAT) named msaRAT. This malware leverages the Chrome DevTools Protocol to control headless instances of Chrome or Edge browsers on compromised Windows machines, routing command-and-control (C2) traffic through WebRTC channels. By utilizing legitimate browser processes, msaRAT effectively conceals malicious communications, making detection and mitigation challenging for defenders. This incident underscores a growing trend among threat actors to exploit trusted applications and services to evade detection. The use of browser-mediated C2 channels highlights the need for enhanced behavior-based detection mechanisms and vigilant monitoring of legitimate application processes to identify and thwart such sophisticated attacks.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Russian Cyberespionage Campaign Exploits Zimbra Vulnerability CVE-2025-66376
Impact· MEDIUM

Russian Cyberespionage Campaign Exploits Zimbra Vulnerability CVE-2025-66376

In July 2025, a Russian state-sponsored cyberespionage group, identified as CL-STA-1114 (also known as Void Blizzard and LAUNDRY BEAR), initiated a campaign targeting Zimbra webmail users across sectors such as government, defense, transportation, and finance in regions including NATO member states, Ukraine, CIS countries, and Africa. The attackers exploited a zero-click vulnerability in the Zimbra Collaboration Suite (CVE-2025-66376), allowing them to inject malicious JavaScript payloads via specially crafted HTML emails. This exploit enabled the exfiltration of sensitive data, including login credentials, email archives, and search histories, without any user interaction. The continued exploitation of CVE-2025-66376 underscores the critical need for organizations to promptly apply security patches and enhance their email security measures. The sophistication of this attack, particularly its zero-click nature, highlights the evolving tactics of nation-state actors and the importance of proactive defense strategies to protect sensitive information.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
White House Accuses Moonshot AI of Distilling Anthropic's Fable Model
Impact· HIGH

White House Accuses Moonshot AI of Distilling Anthropic's Fable Model

In July 2026, the White House accused Chinese AI company Moonshot AI of illicitly distilling Anthropic's Fable model to develop their own Kimi K3 model. This process involved creating a sophisticated internal platform to conduct large-scale distillation against U.S. models, allowing them to switch between multiple methods of access to avoid detection. The U.S. government expressed concerns over the unauthorized use of proprietary technology and the potential national security implications. ([cyberscoop.com](https://cyberscoop.com/white-house-accuses-moonshot-ai-anthropic-model-distillation/?utm_source=openai)) This incident underscores the escalating tensions in the global AI race, highlighting the challenges in protecting intellectual property and the need for robust cybersecurity measures to prevent unauthorized access and replication of advanced AI models.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Orders Immediate Patching of Langflow RCE Vulnerability CVE-2026-0770
Impact· CRITICAL

CISA Orders Immediate Patching of Langflow RCE Vulnerability CVE-2026-0770

In July 2026, the Cybersecurity and Infrastructure Security Agency (CISA) mandated U.S. federal agencies to urgently patch a critical vulnerability in Langflow, a visual framework for building AI agents. Identified as CVE-2026-0770, this flaw allows unauthenticated attackers to execute arbitrary code with root privileges by exploiting the 'exec_globals' parameter in the 'validate' endpoint. Exploitation attempts were first observed on June 27, 2026, with over 220 incidents from 64 unique IP addresses, leading to malware deployment and unauthorized access to sensitive data. This incident underscores the escalating threats targeting AI development tools and the necessity for robust security measures. The active exploitation of CVE-2026-0770 highlights the importance of prompt vulnerability management and the need for organizations to stay vigilant against emerging attack vectors in AI frameworks.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
South Korea's Diplomatic Academy Data Breach: A 10-Month Undetected Cyberattack
Impact· HIGH

South Korea's Diplomatic Academy Data Breach: A 10-Month Undetected Cyberattack

In April 2025, an unidentified threat actor exploited a zero-day vulnerability in the Korea National Diplomatic Academy's online education system, maintaining unauthorized access until February 2026. This breach exposed personal information—including names, user IDs, email addresses, and encrypted passwords—of approximately 10,000 individuals associated with South Korea's Ministry of Foreign Affairs, including current and former diplomats. The compromised system, established in 2022 for remote training during the COVID-19 pandemic, was taken offline in February 2026 upon detection of the intrusion. This incident underscores the escalating sophistication of cyberattacks targeting governmental institutions and the critical need for robust cybersecurity measures. The prolonged undetected access highlights vulnerabilities in monitoring and threat detection systems, emphasizing the importance of regular security audits and timely patch management to mitigate potential breaches.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Ubuntu snap-confine Vulnerability (CVE-2026-8933) Grants Local Root Access
Impact· HIGH

Critical Ubuntu snap-confine Vulnerability (CVE-2026-8933) Grants Local Root Access

In July 2026, a high-severity local privilege escalation vulnerability, CVE-2026-8933, was identified in Ubuntu's snap-confine component. This flaw allows unprivileged local users to gain root access on default installations of Ubuntu Desktop versions 24.04, 25.10, and 26.04. The vulnerability arises from improper initialization of privilege boundaries in snap-confine when configured with set-capabilities, enabling attackers to execute arbitrary code with full root privileges. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-8933?utm_source=openai)) This incident underscores the critical importance of promptly addressing privilege escalation vulnerabilities, especially in widely used operating systems like Ubuntu. Organizations must ensure timely application of security patches to mitigate potential risks associated with such flaws.

4 days ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in Adobe Acrobat Chrome Extension Exposes User Data
Impact· HIGH

Critical Vulnerability in Adobe Acrobat Chrome Extension Exposes User Data

In June 2026, a critical vulnerability (CVE-2026-48294) was identified in the Adobe Acrobat PDF Extension for Chrome, affecting versions up to 26.5.2.2. This Universal Cross-Site Scripting (UXSS) flaw allowed attackers to bypass the browser's same-origin policy, enabling unauthorized access to users' session data across different web origins. Exploitation required user interaction, such as visiting a maliciously crafted URL or interacting with a compromised webpage. The vulnerability was promptly patched by Adobe following its disclosure. The incident underscores the persistent risks associated with browser extensions, especially those with extensive user bases like Adobe Acrobat's, which boasts over 314 million users. It highlights the importance of regular security assessments and prompt patching to mitigate potential data breaches stemming from such vulnerabilities.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Cloudflare's Defense Against a Massive Multi-Vector DDoS Attack in 2026
Impact· HIGH

Cloudflare's Defense Against a Massive Multi-Vector DDoS Attack in 2026

In July 2026, Cloudflare successfully mitigated a massive multi-vector distributed denial-of-service (DDoS) attack that peaked at nearly 2 terabits per second. The attack was orchestrated using approximately 15,000 bots running variants of the Mirai malware, which had compromised Internet of Things (IoT) devices and unpatched GitLab instances. The assault combined DNS amplification attacks and UDP floods, aiming to overwhelm Cloudflare's infrastructure. The swift and effective response by Cloudflare prevented any significant service disruptions. ([computing.co.uk](https://www.computing.co.uk/news/4040452/cloudflare-blocked-multi-vector-ddos-attack-peaked-tbps?utm_source=openai)) This incident underscores the escalating sophistication and scale of DDoS attacks, highlighting the critical need for robust, adaptive defense mechanisms. The exploitation of IoT devices and unpatched software as attack vectors emphasizes the importance of comprehensive security practices, including regular patching and monitoring of networked devices.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports