The Containment Era is here. →Explore

Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2347 threat reports
Page 38 of 196

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Government Administration Threat Reports

Showing 445456 / 2347 reports
Critical Cisco Unified CM Vulnerability CVE-2026-20230: Public Exploit Code Released
Impact· HIGH

Critical Cisco Unified CM Vulnerability CVE-2026-20230: Public Exploit Code Released

In June 2026, Cisco disclosed a critical server-side request forgery (SSRF) vulnerability, identified as CVE-2026-20230, in its Unified Communications Manager (Unified CM) and Unified CM Session Management Edition. This flaw allows unauthenticated, remote attackers to send crafted HTTP requests, enabling them to write files to the underlying operating system and potentially escalate privileges to root. The vulnerability resides in the WebDialer service, which is disabled by default. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-cucm-ssrf-cXPnHcW.html?utm_source=openai)) The public release of proof-of-concept exploit code has heightened the urgency for organizations to address this vulnerability promptly. Given the critical nature of Unified CM in enterprise telephony infrastructure, successful exploitation could lead to significant operational disruptions and unauthorized access to sensitive communications. ([techtimes.com](https://www.techtimes.com/articles/317782/20260604/cisco-unified-cm-ssrf-flaw-cve-2026-20230-public-exploit-code-opens-path-root.htm?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft 365 Android Apps Vulnerability Exposes User Tokens
Impact· MEDIUM

Microsoft 365 Android Apps Vulnerability Exposes User Tokens

In June 2026, a significant security vulnerability was discovered in several Microsoft 365 Android applications, including Word, Excel, PowerPoint, OneNote, Loop, and Microsoft 365 Copilot. Researchers at Enclave identified that a debug setting, intended for testing purposes, was inadvertently left enabled in production versions of these apps. This oversight disabled critical security controls, allowing any app on the same device to request and receive Microsoft authentication tokens without proper authorization checks. Consequently, malicious applications could gain unauthorized access to user accounts, potentially compromising emails, files, and other sensitive data. Microsoft promptly addressed the issue by releasing updates and assigning CVEs such as CVE-2026-41100, CVE-2026-41101, CVE-2026-41102, and CVE-2026-42832 to track the vulnerabilities. This incident underscores the critical importance of rigorous security practices in software development, particularly in managing authentication tokens. The exposure highlights the potential risks associated with residual debug settings in production environments, emphasizing the need for comprehensive code reviews and security audits to prevent similar vulnerabilities in the future.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
China-Linked Cyber Espionage Escalates in Latin America: A 2026 Overview
Impact· CRITICAL

China-Linked Cyber Espionage Escalates in Latin America: A 2026 Overview

In early 2026, China-linked cyber espionage groups, notably FamousSparrow and NegativeGlimmer, intensified operations targeting Latin American nations, including Venezuela and Panama. These groups infiltrated government agencies to gather intelligence on maritime shipping, oil production, and other strategic sectors. Their tactics involved exploiting unpatched servers and deploying custom malware to maintain persistent access. This surge in cyber activities underscores the escalating geopolitical tensions in the region, with state-sponsored actors leveraging cyber operations to advance national interests. Organizations must prioritize robust cybersecurity measures to mitigate the risks posed by such sophisticated threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SideCopy's Xeno RAT Attack on Afghan Finance Ministry: A Case Study
Impact· MEDIUM

SideCopy's Xeno RAT Attack on Afghan Finance Ministry: A Case Study

In May 2025, the Pakistan-linked APT group SideCopy initiated a cyberespionage campaign targeting Afghanistan's Ministry of Finance and provincial finance offices. The attackers employed spear-phishing emails containing ZIP archives with malicious LNK files disguised as PDFs. These files, when executed, utilized mshta.exe to fetch an HTA payload from a compromised Afghan education domain, leading to the deployment of Xeno RAT 1.8.7. This malware enabled remote command execution, data exfiltration, and system monitoring, including keystroke logging and screenshot capture. The campaign demonstrated a deliberate approach to defense evasion by leveraging Pashto-language lures and hosting payloads on Afghan government infrastructure to blend malicious traffic with legitimate state communications. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/pakistan-spies-afghan-finance-ministry-xeno-rat?utm_source=openai)) This incident underscores the persistent threat posed by nation-state actors employing sophisticated social engineering tactics and leveraging local infrastructure to conduct espionage. Organizations, especially governmental entities, must enhance their cybersecurity posture by implementing robust email filtering, user education on phishing threats, and continuous monitoring for indicators of compromise to mitigate such risks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Vulnerability in Mirasvit Full Page Cache Warmer: Immediate Action Required
Impact· CRITICAL

Critical Vulnerability in Mirasvit Full Page Cache Warmer: Immediate Action Required

In May 2026, a critical vulnerability (CVE-2026-45247) was identified in Mirasvit's Full Page Cache Warmer extension for Magento 2, versions prior to 1.11.12. This flaw allows unauthenticated attackers to execute arbitrary code on affected servers by exploiting a PHP object injection via the 'CacheWarmer' cookie. The vulnerability arises from the unsafe use of PHP's 'unserialize()' function, enabling remote code execution without authentication. ([sansec.io](https://sansec.io/research/mirasvit-cache-warmer-object-injection?utm_source=openai)) The inclusion of this vulnerability in CISA's Known Exploited Vulnerabilities catalog underscores its active exploitation and the significant risk it poses to e-commerce platforms. Organizations using the affected versions are urged to update to version 1.11.12 immediately to mitigate potential breaches and data compromises. ([blog.gridinsoft.com](https://blog.gridinsoft.com/mirasvit-cve-2026-45247-cachewarmer-rce/?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
TA4922's Global Expansion: A New Cyber Threat Landscape
Impact· HIGH

TA4922's Global Expansion: A New Cyber Threat Landscape

In early 2026, the China-linked cybercrime group TA4922 expanded its operations beyond East Asia, targeting organizations in the U.K., Germany, Italy, and South Africa. The group employed sophisticated phishing campaigns using localized lures related to tax filings, payroll, and compliance to deliver malware such as ValleyRAT (Winos 4.0), Atlas RAT, RomulusLoader, and SilentRunLoader. These attacks aimed to gain unauthorized access for data theft, fraud, and persistent access. ([proofpoint.com](https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global?utm_source=openai)) This incident underscores the evolving threat landscape, where financially motivated cybercriminals are rapidly adapting their tactics and expanding their reach globally. Organizations must remain vigilant against such sophisticated phishing campaigns and enhance their cybersecurity measures to mitigate these risks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Introducing WasmForge: Revolutionizing Offensive Security with WebAssembly
Impact· HIGH

Introducing WasmForge: Revolutionizing Offensive Security with WebAssembly

In June 2026, Praetorian introduced WasmForge, a tool designed to compile Go-based offensive security tools like Sliver into WebAssembly (WASM). This approach enables the creation of binaries that can evade traditional Endpoint Detection and Response (EDR) systems by disguising the tool's signature and behavior. WasmForge achieves this by embedding the WASM module into a Go binary, which acts as a loader, effectively obfuscating the tool's presence and functionality. The release of WasmForge highlights a significant advancement in offensive security methodologies, emphasizing the continuous evolution of evasion techniques. This development underscores the necessity for defensive strategies to adapt rapidly, as threat actors increasingly leverage sophisticated tools to bypass conventional security measures.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Alerts on Active Exploitation of Android and Linux Vulnerabilities
Impact· HIGH

CISA Alerts on Active Exploitation of Android and Linux Vulnerabilities

In June 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2025-48595 and CVE-2022-0492. CVE-2025-48595 is a high-severity integer overflow vulnerability in the Android Framework affecting versions 14 through 16, allowing local privilege escalation without user interaction. CVE-2022-0492 is a privilege escalation flaw in the Linux kernel's cgroups v1 subsystem, enabling attackers to bypass namespace isolation and potentially gain root access on host systems. Both vulnerabilities have been actively exploited in the wild, prompting immediate patching and mitigation efforts. The inclusion of these vulnerabilities in the KEV catalog underscores the persistent threat posed by privilege escalation flaws in widely used operating systems. Organizations are urged to prioritize the application of security updates to mitigate potential exploitation risks and protect their systems from unauthorized access and control.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Chinese Hackers Deploy Atlas RAT in European Cyberattacks
Impact· HIGH

Chinese Hackers Deploy Atlas RAT in European Cyberattacks

In early 2026, the Chinese-speaking cybercrime group TA4922 expanded its operations to Europe, targeting organizations in Germany, Italy, the United Kingdom, and South Africa. Utilizing sophisticated phishing campaigns, the group deployed the previously undocumented Atlas RAT malware to gain unauthorized access to networks for financial fraud, data theft, and potential sale of access. The malware's capabilities include system reconnaissance, targeted file theft, keylogging, and audio and webcam recording. This incident underscores a significant shift in TA4922's targeting strategy and highlights the evolving threat landscape where financially motivated cybercriminals employ advanced tools and tactics. Organizations must remain vigilant against such threats, emphasizing the need for robust cybersecurity measures and continuous monitoring to detect and mitigate potential breaches.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
U.S. Treasury Sanctions Nobitex for IRGC-Linked Transactions
Impact· HIGH

U.S. Treasury Sanctions Nobitex for IRGC-Linked Transactions

In June 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned Nobitex, Iran's largest cryptocurrency exchange, for facilitating transactions linked to the Islamic Revolutionary Guard Corps (IRGC), including those associated with IRGC-affiliated ransomware actors. Nobitex processed over 50% of Iran's digital asset inflows in 2025 and assisted the Central Bank of Iran in accessing hundreds of millions of dollars in stablecoins to support the Iranian rial. This action is part of the U.S. government's "Economic Fury" campaign targeting financial networks supporting terrorism and sanctions evasion. The sanctions underscore the increasing scrutiny of cryptocurrency platforms used to circumvent international sanctions and finance illicit activities. Organizations must enhance their compliance measures to prevent inadvertent involvement in such networks, as regulatory bodies intensify efforts to disrupt financial channels linked to state-sponsored cyber threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in Microsoft 365 Android Apps Exposes User Tokens
Impact· MEDIUM

Critical Vulnerability in Microsoft 365 Android Apps Exposes User Tokens

In May 2026, a critical vulnerability was discovered in several Microsoft 365 Android applications, including Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote. A development flag, 'IsDebugMode', was inadvertently left enabled in production builds, disabling the security check that restricts account-token sharing to trusted Microsoft apps. This oversight allowed any app on the same device to request and obtain the signed-in user's Microsoft account tokens without requiring a password, login screen, or permission prompt. Consequently, unauthorized applications could access emails, files, calendars, and send messages as the user, posing significant security risks. ([securityweek.com](https://www.securityweek.com/exclusive-how-one-line-of-code-put-billions-of-microsoft-android-app-downloads-at-risk/amp/?utm_source=openai)) This incident underscores the critical importance of rigorous security checks in the software development lifecycle, especially in mobile applications that handle sensitive user data. The ease with which a single misconfiguration can lead to widespread security breaches highlights the need for continuous monitoring and auditing of application settings. Organizations must prioritize updating affected applications and implementing robust security practices to prevent similar vulnerabilities in the future.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability: Malicious Notifications Hijack Google Gemini on Android
Impact· MEDIUM

Critical Vulnerability: Malicious Notifications Hijack Google Gemini on Android

In June 2026, a vulnerability was discovered in Google Gemini's voice assistant on Android devices, allowing malicious notifications from apps like WhatsApp, Slack, SMS, Signal, Instagram, or Messenger to hijack the assistant. This exploit enabled attackers to perform unauthorized actions such as opening windows, sending fake messages, initiating calls, or altering the assistant's memory, all without requiring a malicious app on the device. The attack leveraged Gemini's ability to process notifications as actionable context, effectively bypassing user consent mechanisms. This incident underscores the evolving threat landscape where attackers exploit trusted system features to execute malicious activities. It highlights the necessity for continuous security assessments and prompt patching of AI-driven functionalities to prevent unauthorized access and maintain user trust.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports