✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Karakurt Ransomware Negotiator Sentenced to 102 Months in Prison
In May 2026, Latvian national Deniss Zolotarjovs was sentenced to 102 months in U.S. federal prison for his role as a negotiator in the Karakurt ransomware group. Operating between June 2021 and August 2023, Zolotarjovs was instrumental in extorting over 54 companies, leading to more than $56 million in losses. He employed aggressive tactics, including leveraging sensitive data such as children's health records, to pressure victims into paying ransoms. This sentencing marks a significant milestone in the fight against international cybercrime, highlighting the global reach of law enforcement agencies in apprehending and prosecuting cybercriminals. The case underscores the persistent threat posed by ransomware groups and the importance of robust cybersecurity measures to protect sensitive information.
2 months ago
Kill Chain
PamDOORa: A New Threat to Linux Authentication Security
In May 2026, cybersecurity researchers uncovered a new Linux backdoor named PamDOORa, advertised on the Rehub Russian cybercrime forum for $1,600 by a threat actor known as "darkworm." PamDOORa is a Pluggable Authentication Module (PAM)-based post-exploitation toolkit that enables persistent SSH access through a magic password and specific TCP port combination. Additionally, it can harvest credentials from all legitimate users who authenticate through the compromised system. The backdoor also incorporates anti-forensic capabilities to tamper with authentication logs, effectively erasing traces of malicious activity. The emergence of PamDOORa highlights a growing trend of sophisticated Linux-based malware targeting authentication mechanisms to establish persistent access and exfiltrate sensitive credentials. This development underscores the need for organizations to implement robust monitoring and auditing of authentication processes to detect and mitigate such threats.
2 months ago
Kill Chain
Critical Vulnerability in MAXHUB Pivot Client Application: CVE-2025-53704
In December 2025, a critical vulnerability (CVE-2025-53704) was identified in the MAXHUB Pivot client application versions prior to v1.36.2. This flaw involved a weak password recovery mechanism, allowing remote attackers to request password resets and gain unauthorized access to user accounts without prior authentication. The vulnerability posed significant risks, including potential data breaches and unauthorized control over affected systems. The incident underscores the importance of robust authentication mechanisms and timely software updates. Organizations are advised to upgrade to version 1.36.2 or newer to mitigate this risk. This case highlights the ongoing need for vigilance against authentication vulnerabilities in widely used applications.
2 months ago
Kill Chain
CISA Adds CVE-2026-6973 to Known Exploited Vulnerabilities Catalog
On May 7, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-6973 to its Known Exploited Vulnerabilities (KEV) catalog. This high-severity vulnerability affects Ivanti Endpoint Manager Mobile (EPMM) versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1, allowing authenticated users with administrative privileges to execute arbitrary code remotely. Ivanti has released patches to address this issue and urges organizations to update their systems promptly. ([redpacketsecurity.com](https://www.redpacketsecurity.com/cve-alert-cve-2026-6973-ivanti-endpoint-manager-mobile/?utm_source=openai)) The inclusion of CVE-2026-6973 in the KEV catalog underscores the ongoing threat posed by vulnerabilities in widely used enterprise management tools. Organizations are advised to prioritize the remediation of such vulnerabilities to mitigate potential risks to their networks and data. ([cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=openai))
2 months ago
Kill Chain
Critical Ivanti EPMM Zero-Day CVE-2026-6973 Exploited in the Wild
In May 2026, Ivanti disclosed a critical zero-day vulnerability, CVE-2026-6973, in its Endpoint Manager Mobile (EPMM) software. This flaw allows authenticated users with administrative privileges to execute remote code, potentially compromising the entire mobile device management infrastructure. The vulnerability has been actively exploited in the wild, with Ivanti confirming limited instances of exploitation. To mitigate this risk, Ivanti released patches for EPMM versions 12.6.1.1, 12.7.0.1, and 12.8.0.1, urging all on-premises EPMM customers to apply these updates immediately. ([thehackernews.com](https://thehackernews.com/2026/05/ivanti-epmm-cve-2026-6973-rce-under.html?utm_source=openai)) This incident underscores the persistent targeting of mobile device management systems by threat actors, highlighting the critical need for organizations to maintain up-to-date security measures and promptly apply vendor-released patches to protect sensitive data and infrastructure.
2 months ago
Kill Chain
Critical Ivanti EPMM Vulnerability (CVE-2026-6973) Under Active Exploitation
In May 2026, Ivanti disclosed a high-severity vulnerability (CVE-2026-6973) in its Endpoint Manager Mobile (EPMM) software, which allows authenticated administrative users to execute remote code due to improper input validation. This flaw affects EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1. Exploitation of this vulnerability has been observed in a limited number of cases, potentially leading to full system compromise. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply patches by May 10, 2026. Organizations are urged to update their EPMM installations promptly to mitigate the risk of exploitation.
2 months ago
Kill Chain
State-Sponsored Exploitation of Palo Alto Networks Firewall Zero-Day (CVE-2026-0300)
In early April 2026, Palo Alto Networks identified a critical buffer overflow vulnerability (CVE-2026-0300) in the User-ID Authentication Portal of its PAN-OS software, affecting PA-Series and VM-Series firewalls. This flaw allows unauthenticated attackers to execute arbitrary code with root privileges by sending specially crafted packets. Exploitation attempts began on April 9, with successful breaches occurring a week later. Attackers deployed tools like Earthworm and ReverseSocks5 to establish covert communications and bypass network defenses. This incident underscores a growing trend of state-sponsored actors targeting network edge devices, which often lack comprehensive logging and security measures. Organizations are urged to implement robust access controls and promptly apply security patches to mitigate such vulnerabilities. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/07/state-sponsored-hackers-zero-day-attacks-palo-alto-firewalls/?utm_source=openai))
2 months ago
Kill Chain
Americans Sentenced for Operating 'Laptop Farms' Aiding North Korean IT Workers
In May 2026, U.S. nationals Matthew Isaac Knoot and Erick Ntekereze Prince were each sentenced to 18 months in prison for operating 'laptop farms' that enabled North Korean IT workers to fraudulently secure remote employment at nearly 70 American companies. Knoot managed a laptop farm from his Nashville residence between July 2022 and August 2023, facilitating over $250,000 in payments to North Korean workers. Prince, through his company Taggcar Inc., assisted at least three North Korean IT workers in obtaining remote positions from June 2020 to August 2024, resulting in more than $943,000 in salaries, with the majority routed overseas. The schemes caused significant financial and security repercussions for the victim companies, including over $1.5 million in remediation costs. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/americans-sentenced-for-running-laptop-farms-for-north-korea/?utm_source=openai)) This incident underscores the persistent threat posed by North Korean cyber operations, which exploit remote work opportunities to infiltrate Western companies. The use of 'laptop farms' highlights the evolving tactics employed to circumvent security measures, emphasizing the need for robust identity verification and cybersecurity protocols in remote hiring processes.
2 months ago
Kill Chain
Critical Zero-Day Vulnerability in Ivanti EPMM: CVE-2026-6973 Under Active Exploitation
In May 2026, Ivanti disclosed a high-severity remote code execution vulnerability, CVE-2026-6973, in its Endpoint Manager Mobile (EPMM) software. This flaw, stemming from improper input validation, allows authenticated users with administrative privileges to execute arbitrary code on affected systems running EPMM versions 12.8.0.0 and earlier. Ivanti confirmed limited exploitation of this zero-day vulnerability in the wild and urged customers to update to patched versions 12.6.1.1, 12.7.0.1, or 12.8.0.1 to mitigate the risk. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-6973 to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply the fixes by May 10, 2026. This incident underscores the persistent threat posed by zero-day vulnerabilities and the critical importance of timely patching to maintain system security. ([securityaffairs.com](https://securityaffairs.com/191822/security/u-s-cisa-adds-a-flaw-in-ivanti-endpoint-manager-mobile-epmm-to-its-known-exploited-vulnerabilities-catalog.html?utm_source=openai))
2 months ago
Kill Chain
ACSC Alerts on ClickFix Attacks Distributing Vidar Stealer via Compromised WordPress Sites
In May 2026, the Australian Cyber Security Centre (ACSC) identified a malware campaign targeting Australian organizations through compromised WordPress websites. Attackers employed the 'ClickFix' social engineering technique, presenting users with fake Cloudflare verification prompts that instructed them to execute malicious PowerShell commands. This led to the installation of Vidar Stealer, an information-stealing malware capable of exfiltrating credentials, browser data, cryptocurrency wallets, and system information. The campaign exploited user trust in legitimate websites to facilitate malware distribution. This incident underscores the evolving sophistication of social engineering attacks and the persistent threat posed by infostealer malware. Organizations must remain vigilant, as such techniques can bypass traditional security measures by manipulating user behavior. The ACSC's advisory highlights the need for enhanced security awareness and technical controls to mitigate these risks.
2 months ago
Kill Chain
Critical Microsoft Vulnerabilities Exploited in Q1 2026: A Call for Immediate Action
In Q1 2026, threat actors exploited three critical vulnerabilities—CVE-2026-21509, CVE-2026-21514, and CVE-2026-21513—to compromise systems running Microsoft Office and Windows OS components. These vulnerabilities allowed attackers to bypass security features, execute malicious code, and escalate privileges, leading to unauthorized access and potential data breaches. The exploitation of these flaws underscores the importance of timely software updates and robust security measures to mitigate such risks. The active exploitation of these vulnerabilities highlights a broader trend of attackers leveraging newly discovered flaws to infiltrate systems. Organizations must remain vigilant, ensuring prompt patch management and adopting comprehensive security strategies to defend against evolving threats.
2 months ago
Kill Chain
Quantum Risk Explained: Immediate Threats to Cryptography in 2026
In 2026, advancements in quantum computing have significantly reduced the cost and complexity of breaking traditional cryptographic systems, posing immediate threats to data security. Techniques like Shor's algorithm can now be executed with fewer qubits, making previously secure encryption methods vulnerable. Organizations must urgently assess and upgrade their cryptographic protocols to mitigate these emerging risks. ([techradar.com](https://www.techradar.com/pro/encryption-breaking-technology-is-now-20x-cheaper-and-ceos-should-be-very-worried?utm_source=openai)) The urgency is underscored by the potential for 'harvest now, decrypt later' attacks, where adversaries collect encrypted data today to decrypt once quantum capabilities mature. This scenario highlights the need for immediate action to protect sensitive information from future quantum decryption threats. ([deloitte.com](https://www.deloitte.com/us/en/insights/topics/technology-management/tech-trends/2025/tech-trends-quantum-computing-and-cybersecurity.html?utm_source=openai))
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports