✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Armenia Detains Russian Tourist Mistaken for REvil Hacker
In June 2026, Armenian authorities detained Russian tourist Aleksandr Yuryevich Ermakov at Yerevan's Zvartnots airport, acting on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Gennadievich Ermakov. The U.S. alleges that the wanted individual participated in Sodinokibi/REvil attacks from April 2019 to July 2021, affecting over 1,000 victims, including entities in the Northern District of Texas. However, the detained man's lawyers assert that he is not the individual sought by the U.S., highlighting discrepancies in personal details and emphasizing that the actual suspect is serving a sentence in Russia, restricting his travel. This incident underscores the complexities and potential misidentifications in international cybercrime enforcement efforts, especially when dealing with common names and limited identifying information. It also highlights the ongoing global pursuit of REvil affiliates, reflecting the persistent threat posed by ransomware groups and the challenges in dismantling their networks.
1 week ago
Kill Chain
CISA Adds Three Exploited Vulnerabilities to KEV Catalog
On July 16, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. The vulnerabilities include two OS command injection flaws in Fortinet FortiSandbox (CVE-2026-25089 and CVE-2026-39808) and a deserialization of untrusted data vulnerability in Microsoft SharePoint (CVE-2026-58644). These vulnerabilities are commonly exploited by malicious actors and pose significant risks to federal enterprises. The inclusion of these vulnerabilities in the KEV Catalog underscores the critical need for organizations to prioritize patching and remediation efforts. With the increasing frequency of such exploits, it is imperative for entities to adopt risk-based vulnerability management practices to safeguard their systems against potential breaches.
1 week ago
Kill Chain
Scattered Spider's 2024 Cyberattack on Transport for London: A Case Study
Between August 31 and September 3, 2024, the cybercriminal group Scattered Spider executed a sophisticated cyberattack on Transport for London (TfL). Utilizing social engineering techniques, they infiltrated TfL's network, leading to significant disruptions in technical services, including the Oyster payment system and third-party APIs. The attack necessitated a mass password reset for all 28,000 TfL employees and resulted in financial losses estimated at £29 million. ([nationalcrimeagency.gov.uk](https://www.nationalcrimeagency.gov.uk/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted?utm_source=openai)) This incident underscores the escalating threat posed by cybercriminal groups employing advanced social engineering tactics to target critical infrastructure. Organizations must enhance their cybersecurity measures, particularly in employee training and network security protocols, to mitigate such risks.
1 week ago
Kill Chain
Spirals Ransomware Attack on South Asian IT Firm in June 2026
In June 2026, an IT services firm in South Asia fell victim to a rapid and sophisticated ransomware attack orchestrated by a previously unknown group deploying the 'Spirals' ransomware. The attackers gained initial access through a publicly exposed Internet Information Services (IIS) server, where they uploaded an ASP.NET web shell. Within a three-hour window, they established persistent access, disabled security software, extracted credentials, and moved laterally across the network. Less than 24 hours after the initial breach, the Spirals ransomware was deployed, encrypting files and exfiltrating sensitive data. The attackers threatened to publish the stolen data within six days unless a ransom was paid. This incident underscores the evolving threat landscape, where cybercriminals are executing attacks with unprecedented speed and efficiency. Organizations must reassess their security postures, particularly concerning publicly accessible services and rapid response capabilities, to mitigate such swift and damaging intrusions.
1 week ago
Kill Chain
Urgent: CISA Mandates Patching of Critical Oracle EBS Vulnerability Amid Active Exploitation
In May 2026, Oracle disclosed a critical vulnerability (CVE-2026-46817) in the File Transmission component of its E-Business Suite's Oracle Payments module, affecting versions 12.2.3 through 12.2.15. This flaw allows unauthenticated attackers with HTTP network access to fully compromise the Oracle Payments system. Despite the release of a security patch, by late June 2026, threat intelligence firm Defused observed active exploitation of this vulnerability in the wild. Consequently, on July 15, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-46817 to its Known Exploited Vulnerabilities Catalog and mandated federal agencies to apply the patch by July 18, 2026. This incident underscores the critical importance of timely patch management, especially for vulnerabilities with high CVSS scores and active exploitation. Organizations are urged to assess their exposure to CVE-2026-46817 and ensure that all affected systems are promptly updated to mitigate potential risks.
1 week ago
Kill Chain
Scattered Spider's 2024 Cyberattack on Transport for London: A Case Study
In August 2024, Transport for London (TfL) suffered a significant cyberattack orchestrated by the Scattered Spider hacking group. The breach disrupted internal systems and online services, including Dial-a-Ride, concessionary travel cards, digital payments, and contactless ticketing. Approximately 148 systems were rendered inoperable, and all 27,000 TfL employees were required to reset their passwords in person. The attack resulted in £29 million in losses and recovery costs, with potential economic damages estimated at up to £56 billion had the transport network been fully compromised. This incident underscores the escalating threat posed by cybercriminal groups like Scattered Spider, known for their sophisticated social engineering tactics and targeting of critical infrastructure. The successful prosecution of the perpetrators highlights the importance of early cooperation between organizations and law enforcement in mitigating cyber threats and bringing offenders to justice.
1 week ago
Kill Chain
GoSerpent Backdoor: A Persistent Threat to Southeast Asian Governments
The GoSerpent campaign is a sophisticated, multi-stage attack targeting government and diplomatic entities in Southeast Asia since at least 2021, with evolved variants deployed through 2026. The Go-based GoSerpent backdoor establishes persistent access and deploys ThumbcacheService for document collection, Mimikatz and QuarksDumpLocalHash for credential dumping, and later stages use Stowaway RAT and TmcLoader/TmcPayload to exfiltrate collected data via network shares using stolen credentials. The tight integration between collection, credential theft, and exfiltration components demonstrates advanced operational planning and long-term intelligence gathering objectives.
1 week ago
Kill Chain
HelloNet APT Campaign: Exploiting ViPNet Updates in 2026
In May 2026, a sophisticated Advanced Persistent Threat (APT) campaign named 'HelloNet' targeted major Russian organizations across sectors such as government, energy, transport, education, and logistics. Attackers exploited the ViPNet update system, a software suite for creating secure networks, to deploy malicious modules. By leveraging DLL Sideloading techniques, they achieved persistence and executed payloads that facilitated reconnaissance and data exfiltration. The campaign remains active, posing significant risks to affected entities. ([securelist.ru](https://securelist.ru/tr/hellonet-vipnet/116327/?utm_source=openai)) This incident underscores the growing trend of supply chain attacks, where trusted software update mechanisms are hijacked to distribute malware. Organizations must enhance their security postures by implementing robust monitoring of software updates and employing advanced threat detection systems to mitigate such risks.
1 week ago
Kill Chain
Scattered Spider Hackers Sentenced for 2024 TfL Cyberattack
Between August 31 and September 3, 2024, Transport for London (TfL) experienced a significant cyberattack orchestrated by the Scattered Spider hacking group. The attackers, Thalha Jubair and Owen Flowers, exploited social engineering techniques to infiltrate TfL's network, leading to the compromise of personal data belonging to approximately 10 million customers. The breach resulted in substantial operational disruptions, including the inoperability of 148 systems and the necessity for all 27,000 employees to reset their passwords in person. The financial impact was severe, with losses and recovery costs totaling £29 million. ([nationalcrimeagency.gov.uk](https://www.nationalcrimeagency.gov.uk/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted?utm_source=openai)) This incident underscores the escalating threat posed by sophisticated cybercriminal groups employing advanced social engineering tactics. Organizations must prioritize robust cybersecurity measures, including comprehensive employee training and the implementation of phishing-resistant multi-factor authentication, to mitigate the risks associated with such attacks.
1 week ago
Kill Chain
Iran's AI-Enhanced Asymmetric Warfare in 2026
Between January and June 2026, Iran leveraged artificial intelligence (AI) to enhance its longstanding hybrid warfare model, blending asymmetric military operations, cyber operations, information warfare, proxy attacks, and coercive state control. AI acted as a force multiplier, increasing the speed, scale, and effectiveness of Iranian operations. This strategic use of AI enabled Iran to compensate for conventional military and economic disadvantages, improving its cyber capabilities, accelerating propaganda production, and expanding the reach of information campaigns. ([intelligentciso.com](https://www.intelligentciso.com/2026/07/16/recorded-future-examines-irans-growing-use-of-ai-in-cyber-operations/?utm_source=openai)) The integration of AI into Iran's asymmetric tactics underscores the evolving nature of cyber threats, highlighting the need for organizations to bolster defenses against AI-enhanced operations. This development reflects a broader trend of state actors utilizing AI to amplify their cyber and information warfare capabilities, posing elevated risks to critical infrastructure and vital industries. ([intelligentciso.com](https://www.intelligentciso.com/2026/07/16/recorded-future-examines-irans-growing-use-of-ai-in-cyber-operations/?utm_source=openai))
1 week ago
Kill Chain
Identity Attacks Surpass Exploits as Leading Ransomware Cause in 2026
In 2026, identity-based attacks emerged as the leading cause of ransomware incidents, surpassing traditional vulnerability exploits. According to Sophos' State of Ransomware 2026 report, malicious emails (26%) and phishing (24%) accounted for half of all ransomware attack vectors, while exploited vulnerabilities declined to 18%. Notably, 67% of victims identified the ransomware attack as their most significant identity-related breach of the year. Despite the deployment of multifactor authentication (MFA) in 97% of credential-based attacks, these measures failed to prevent compromises, highlighting gaps in implementation and the evolving sophistication of attackers. This shift underscores the critical need for organizations to enhance their identity security frameworks. The prevalence of identity-driven attacks necessitates a reevaluation of current security protocols, emphasizing advanced email filtering, comprehensive MFA deployment, and regular phishing awareness training to mitigate the rising threat landscape.
1 week ago
Kill Chain
CISA Highlights Critical Vulnerabilities in Latest KEV Catalog Update
On July 15, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2023-4346 and CVE-2026-46817. CVE-2023-4346 pertains to the KNX Protocol's overly restrictive account lockout mechanism, potentially allowing attackers to purge devices and set unauthorized keys. CVE-2026-46817 affects Oracle E-Business Suite's Payments component, enabling unauthenticated attackers to compromise the system via HTTP, leading to potential full system takeover. Both vulnerabilities pose significant risks to federal enterprises and have been actively exploited. The inclusion of these vulnerabilities in the KEV Catalog underscores the persistent threat posed by unpatched systems. Organizations are urged to prioritize remediation efforts, especially for vulnerabilities known to be actively exploited, to mitigate potential breaches and maintain system integrity.
1 week ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports