✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Microsoft Releases Critical Patch for SharePoint RCE Vulnerability CVE-2026-45659
In May 2026, Microsoft addressed a critical remote code execution vulnerability, CVE-2026-45659, in SharePoint Server versions 2016, 2019, and Subscription Edition. This flaw arises from the deserialization of untrusted data, allowing authenticated attackers with minimal permissions to execute arbitrary code remotely without user interaction. The vulnerability has a CVSS score of 8.8, indicating high severity. ([thehackernews.com](https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html?utm_source=openai)) The prompt release of patches underscores the importance of timely updates, especially given SharePoint's role in storing sensitive corporate data. Organizations are urged to apply these updates promptly to mitigate potential exploitation risks. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/26/sharepoint-vulnerability-cve-2026-45659/?utm_source=openai))
2 months ago
Kill Chain
FBI Issues Warning on Kali365 Phishing Service Exploiting Microsoft 365 Accounts
In April 2026, the FBI identified 'Kali365,' a Phishing-as-a-Service (PhaaS) platform distributed via Telegram, enabling cybercriminals to hijack Microsoft 365 accounts. By exploiting Microsoft's OAuth 2.0 Device Authorization grant flow, attackers trick users into entering device codes on legitimate Microsoft pages, granting unauthorized access to services like Outlook, Teams, and OneDrive. This method bypasses multi-factor authentication (MFA) and does not require stealing user credentials. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/fbi-warns-of-kali365-phishing-service-targeting-microsoft-365-accounts/?utm_source=openai)) The emergence of Kali365 underscores a significant shift in cyber threats, where sophisticated phishing tools are now accessible to less-skilled attackers. This trend highlights the urgent need for organizations to reassess and strengthen their authentication protocols and user education to mitigate evolving phishing tactics. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260521?utm_source=openai))
2 months ago
Kill Chain
Dutch Authorities Dismantle Cyberattack Infrastructure Linked to Russian Operations
In May 2026, Dutch authorities arrested two individuals, aged 57 and 39, for allegedly providing IT infrastructure used by Russian entities to conduct cyberattacks and disinformation campaigns within the European Union. The arrests followed investigations into Stark Industries Solutions, a hosting provider sanctioned by the EU in 2025 for facilitating Russian cyber operations. The suspects, associated with MIRhosting and WorkTitans BV, were charged with violating sanctions laws by making economic resources available to sanctioned entities. During the operation, over 800 servers were seized from data centers in Dronten and Schiphol-Rijk. ([krebsonsecurity.com](https://krebsonsecurity.com/2026/05/netherlands-seizes-800-servers-arrests-2-for-aiding-cyberattacks/?utm_source=openai)) This incident underscores the persistent challenges in enforcing sanctions against entities that support state-sponsored cyber activities. Despite previous sanctions, the rebranding and asset transfers by Stark Industries highlight the adaptability of such organizations in evading regulatory measures. The case emphasizes the need for continuous monitoring and robust enforcement mechanisms to prevent the circumvention of international sanctions.
2 months ago
Kill Chain
Critical Drupal Core SQL Injection Vulnerability (CVE-2026-9082) Actively Exploited
In May 2026, a critical SQL injection vulnerability, identified as CVE-2026-9082, was discovered in Drupal Core's database abstraction API. This flaw specifically affects sites utilizing PostgreSQL databases, allowing unauthenticated attackers to execute arbitrary SQL commands. Successful exploitation can lead to information disclosure, privilege escalation, and potentially remote code execution. Drupal released patches for affected versions, including 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, and 11.3.10. ([drupal.org](https://www.drupal.org/sa-core-2026-004?utm_source=openai)) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on May 22, 2026, indicating active exploitation in the wild. Organizations are urged to apply the necessary patches promptly to mitigate potential risks. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-9082?utm_source=openai))
2 months ago
Kill Chain
CISA Adds CVE-2026-9082 to Known Exploited Vulnerabilities Catalog
On May 22, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-9082 to its Known Exploited Vulnerabilities Catalog. This highly critical SQL injection vulnerability affects Drupal core's database abstraction layer, specifically impacting sites using PostgreSQL databases. Exploitation of this flaw can lead to information disclosure, privilege escalation, and remote code execution. The vulnerability affects Drupal versions from 8.9.0 up to 11.3.9. ([drupal.org](https://www.drupal.org/sa-core-2026-004?utm_source=openai)) The inclusion of CVE-2026-9082 in CISA's catalog underscores the urgency for organizations to address this vulnerability promptly. Given the widespread use of Drupal for content management, unpatched systems are at significant risk of exploitation, potentially leading to severe security breaches.
2 months ago
Kill Chain
From Edge Appliance to Enterprise Compromise: Analyzing the 2026 Multi-Stage Linux Intrusion
In May 2026, a sophisticated cyber intrusion was identified, where attackers exploited vulnerabilities in F5 BIG-IP Access Policy Manager (APM) and Atlassian Confluence to gain unauthorized access to enterprise networks. The attackers initially compromised an internet-facing F5 BIG-IP appliance, leveraging a critical remote code execution vulnerability (CVE-2025-53521) to establish a foothold. They then moved laterally to an internal Linux host and exploited an unpatched Confluence server, obtaining credentials that facilitated further attacks against Active Directory. This multi-stage attack underscores the evolving threat landscape, where adversaries target edge appliances and internal applications to bypass traditional security controls. Organizations are urged to prioritize patch management, especially for internet-facing devices, and to implement robust monitoring across all network segments to detect and mitigate such complex attack chains.
2 months ago
Kill Chain
Understanding CVE-2026-0265: PAN-OS CAS Authentication Bypass
In May 2026, a critical authentication bypass vulnerability, CVE-2026-0265, was identified in Palo Alto Networks' PAN-OS software. This flaw allows unauthenticated attackers to forge JSON Web Tokens (JWTs) and gain unauthorized access to systems where the Cloud Authentication Service (CAS) is enabled. The vulnerability affects both GlobalProtect portals and management interfaces, potentially compromising VPN user sessions and administrative controls. Palo Alto Networks has released patches for affected versions, and organizations are urged to update to fixed versions or disable CAS to mitigate the risk. The discovery of CVE-2026-0265 underscores the ongoing challenges in securing authentication mechanisms within network infrastructure. As attackers continue to exploit such vulnerabilities, it is imperative for organizations to stay vigilant, apply timely patches, and adhere to best practices in access control to safeguard their systems against unauthorized access.
2 months ago
Kill Chain
FBI Issues Warning on Kali365 Phishing Platform Targeting Microsoft 365 Users
In April 2026, the FBI identified 'Kali365,' a Phishing-as-a-Service (PhaaS) platform that enables cybercriminals to hijack Microsoft 365 access tokens by exploiting OAuth device code authorizations. Distributed primarily via Telegram, Kali365 allows attackers to bypass multi-factor authentication (MFA) without intercepting user credentials. This method grants persistent access to Microsoft 365 services, including Outlook, Teams, and OneDrive, facilitating data theft, fraud, extortion, and potential ransomware attacks. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260521?utm_source=openai)) The emergence of Kali365 underscores a significant shift in phishing tactics, with attackers increasingly leveraging device code phishing to circumvent traditional security measures. This trend highlights the urgent need for organizations to reassess and strengthen their authentication protocols and user education to mitigate evolving threats. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/22/kali365-microsoft-365-phishing-fbi-warning/?utm_source=openai))
2 months ago
Kill Chain
Authorities Arrest KimWolf Botnet Operator in 2026
In May 2026, U.S. and Canadian authorities arrested Jacob Butler, a 23-year-old Canadian national known online as "Dort," for operating the KimWolf botnet. This botnet infected nearly two million devices worldwide, including digital photo frames, web cameras, and Android-based TV boxes. Butler allegedly sold access to this network through a DDoS-for-hire service, facilitating over 25,000 attacks that reached up to 30 terabits per second, causing financial losses exceeding $1 million for some victims. The KimWolf botnet was also linked to attacks targeting Department of Defense Information Network IP addresses. ([justice.gov](https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos?utm_source=openai)) The arrest underscores the escalating threat posed by large-scale botnets exploiting Internet of Things (IoT) devices. The KimWolf botnet's rapid expansion and its use in record-breaking DDoS attacks highlight the need for enhanced security measures and international cooperation to combat cybercrime. ([techradar.com](https://www.techradar.com/pro/security/a-massive-new-ddos-botnet-has-already-snared-1-8-million-devices-heres-what-we-know?utm_source=openai))
2 months ago
Kill Chain
Drupal CVE-2026-9082: Critical SQL Injection Vulnerability Exploited
In May 2026, a critical SQL injection vulnerability, CVE-2026-9082, was identified in Drupal's database abstraction API, specifically affecting sites using PostgreSQL. This flaw allows unauthenticated attackers to execute arbitrary SQL commands, potentially leading to information disclosure, privilege escalation, and remote code execution. Exploitation attempts have been observed in the wild, prompting Drupal to assign a risk score of 23 out of 25. Affected versions include Drupal 8.9.x, 10.4.x before 10.4.10, 10.5.x before 10.5.10, 10.6.x before 10.6.9, 11.0.x/11.1.x before 11.1.10, 11.2.x before 11.2.12, and 11.3.x before 11.3.10. Administrators are urged to update to the latest versions immediately. This incident underscores the persistent threat of SQL injection vulnerabilities in web applications, emphasizing the need for robust input validation and regular security updates. The active exploitation of this flaw highlights the importance of timely patching and vigilant monitoring to protect sensitive data and maintain system integrity.
2 months ago
Kill Chain
Trend Micro Apex One Zero-Day CVE-2026-34926 Exploited in the Wild
In May 2026, Trend Micro disclosed a directory traversal vulnerability (CVE-2026-34926) in its Apex One on-premise server, allowing local attackers with administrative privileges to inject malicious code. This flaw enables the deployment of malware to connected agents, compromising endpoint security. Despite the requirement for prior administrative access, at least one exploitation attempt has been observed in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities Catalog, mandating federal agencies to apply patches by June 4, 2026. This incident underscores the critical need for timely patch management and vigilant monitoring of endpoint security solutions to prevent potential breaches.
2 months ago
Kill Chain
Dutch Authorities Dismantle Hosting Firm Enabling Cyberattacks
In May 2026, the Dutch Fiscal Information and Investigation Service (FIOD) arrested two individuals and seized 800 servers associated with Stark Industries, a web hosting company implicated in facilitating cyberattacks, interference operations, and disinformation campaigns. The suspects, aged 57 and 39, were linked to providing infrastructure that supported actions undermining democracy and security, including information manipulation and disruption of public and economic systems. Stark Industries, founded in February 2022, was added to the European Union's list of sanctioned entities in May 2025. Following the sanctions, the company's infrastructure was transferred to a newly established Dutch entity, WorkTitans B.V., operating under the brand THE.Hosting, which investigators believe acted as a front for the sanctioned organization. The FIOD's coordinated raids in Dronten, Schiphol-Rijk, Enschede, and Almere resulted in the confiscation of servers, laptops, phones, and administrative records. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/netherlands-seizes-800-servers-of-hosting-firm-enabling-cyberattacks/amp/?utm_source=openai)) This incident underscores the persistent threat posed by cybercriminals leveraging hosting services to conduct malicious activities. The involvement of entities like WorkTitans B.V. highlights the challenges in enforcing sanctions and the need for continuous vigilance against infrastructure providers that may serve as conduits for cyberattacks. Organizations must remain proactive in monitoring and securing their networks against such threats.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports