✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Microsoft 2026: Storm-2755's Payroll Pirate Attack Exposes MFA Vulnerabilities
In April 2026, Microsoft identified a financially motivated threat actor, Storm-2755, targeting Canadian employees through sophisticated 'payroll pirate' attacks. The attackers employed adversary-in-the-middle (AiTM) techniques, using malicious Microsoft 365 sign-in pages to intercept authentication tokens and session cookies. This method allowed them to bypass traditional multi-factor authentication (MFA) and gain unauthorized access to employee accounts. Once inside, they created inbox rules to conceal communications from human resources and manipulated payroll systems, such as Workday, to redirect salary payments to accounts under their control. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/09/investigating-storm-2755-payroll-pirate-attacks-targeting-canadian-employees/?utm_source=openai)) This incident underscores the evolving nature of business email compromise (BEC) schemes, highlighting the need for organizations to implement phishing-resistant MFA solutions and monitor for anomalous activities within their systems. The use of AiTM tactics to circumvent standard security measures signifies a shift in cybercriminal strategies, emphasizing the importance of continuous vigilance and adaptive security protocols. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/09/investigating-storm-2755-payroll-pirate-attacks-targeting-canadian-employees/?utm_source=openai))
3 months ago
Kill Chain
Iranian Cyberattack on U.S. Industrial Devices in 2026
In March 2026, Iranian state-sponsored hackers targeted U.S. critical infrastructure by exploiting internet-exposed Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs). These attacks led to operational disruptions and financial losses across sectors including government services, water and wastewater systems, and energy. The attackers extracted device project files and manipulated human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, compromising industrial processes. ([techcrunch.com](https://techcrunch.com/2026/04/07/iranian-hackers-are-targeting-american-critical-infrastructure-u-s-agencies-warn/?utm_source=openai)) This incident underscores the escalating cyber threats from nation-state actors targeting critical infrastructure. The exploitation of industrial control systems highlights the urgent need for enhanced cybersecurity measures, including network segmentation, regular patching, and the implementation of multifactor authentication to protect against such sophisticated attacks.
3 months ago
Kill Chain
Qualys 2026 Report Highlights Urgent Need for Automated Vulnerability Management
In March 2026, Qualys released a comprehensive analysis of over one billion remediation records from the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, spanning 10,000 organizations over four years. The study revealed that despite a 6.5-fold increase in remediation efforts since 2022, 63% of critical vulnerabilities remained unpatched after seven days, up from 56% in previous years. Alarmingly, 88% of 52 high-profile weaponized vulnerabilities were patched slower than they were exploited, with half being weaponized before any patch was available. This indicates a systemic failure in current vulnerability management practices to keep pace with the rapid exploitation timelines of threat actors. The findings underscore the urgent need for organizations to adopt autonomous, closed-loop risk operations to effectively mitigate vulnerabilities in real-time. The traditional manual remediation processes are proving inadequate against the accelerating threat landscape, necessitating a paradigm shift towards automated and proactive security measures.
3 months ago
Kill Chain
APT28's PRISMEX Malware Campaign: A Threat to Global Security
In early 2026, the Russian state-sponsored group APT28, also known as Fancy Bear, launched a sophisticated cyber-espionage campaign targeting Ukraine and its NATO allies. The operation, active since at least September 2025 and intensifying in January 2026, involved the deployment of a modular malware suite named PRISMEX. This suite utilized advanced steganography, Component Object Model (COM) hijacking, and exploited newly disclosed vulnerabilities, including CVE-2026-21509 and CVE-2026-21513, to infiltrate defense supply chains and critical infrastructure sectors. The campaign's strategic focus on supply chains and operational planning capabilities underscores a shift toward operational disruption, potentially paving the way for more destructive activities. ([thehackernews.com](https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html?utm_source=openai)) The PRISMEX campaign highlights the persistent and evolving threat posed by APT28, emphasizing the necessity for organizations to adopt proactive cybersecurity measures. The rapid weaponization of vulnerabilities and the use of sophisticated techniques like steganography and cloud service abuse demonstrate the group's advanced capabilities. This incident serves as a critical reminder for entities within targeted sectors to enhance their security postures and remain vigilant against such advanced persistent threats. ([thehackernews.com](https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html?utm_source=openai))
3 months ago
Kill Chain
Obfuscated JavaScript Phishing Attack Delivers FormBook Malware - April 2026
In April 2026, a sophisticated phishing campaign was identified, distributing the FormBook infostealer malware through obfuscated JavaScript files. The attack began with phishing emails containing RAR archives that, when extracted, revealed large, obfuscated JavaScript files. These scripts utilized Windows-specific ActiveXObjects to establish persistence via scheduled tasks and dropped multiple files, including AES-encrypted data and .NET DLLs. The payloads were decrypted and executed using PowerShell scripts, ultimately injecting the FormBook malware into legitimate processes like MSBuild.exe. This multi-stage attack chain effectively evaded traditional detection mechanisms by leveraging obfuscation, encryption, and living-off-the-land techniques. The resurgence of such sophisticated phishing campaigns underscores the evolving tactics of threat actors and the necessity for organizations to enhance their email security measures and endpoint detection capabilities to mitigate the risks associated with advanced malware delivery methods.
3 months ago
Kill Chain
FBI Dismantles APT28's Global Router-Based Espionage Network
In April 2026, the FBI, in collaboration with international partners, executed Operation Masquerade to dismantle a sophisticated cyberespionage campaign orchestrated by APT28, also known as Fancy Bear or Forest Blizzard. This Russian state-sponsored group had compromised over 18,000 TP-Link routers across more than 120 countries, infiltrating over 200 organizations. By exploiting vulnerabilities in these routers, APT28 altered DNS settings to redirect internet traffic through attacker-controlled servers, enabling the interception of sensitive data, including credentials for Microsoft Outlook and Office 365 services. The operation involved sending commands to reset the compromised routers' DNS settings, effectively severing the attackers' access and mitigating further data exfiltration. ([justice.gov](https://www.justice.gov/opa/pr/justice-department-conducts-court-authorized-disruption-dns-hijacking-network-controlled?utm_source=openai)) This incident underscores the escalating threat posed by nation-state actors targeting network infrastructure to conduct large-scale espionage. The use of DNS hijacking to perform adversary-in-the-middle attacks highlights the need for organizations to secure all network devices, including SOHO routers, and to implement robust monitoring and response strategies to detect and mitigate such sophisticated threats. ([ncsc.gov.uk](https://www.ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dns-hijacking-operations?utm_source=openai))
3 months ago
Kill Chain
Iranian Cyberattacks on U.S. Critical Infrastructure: A 2026 Analysis
In March 2026, Iranian-affiliated cyber actors initiated a series of attacks targeting U.S. critical infrastructure sectors, including energy, water, and government services. These attackers exploited vulnerabilities in internet-exposed Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), leading to operational disruptions and financial losses. The Cybersecurity and Infrastructure Security Agency (CISA), along with other federal agencies, issued a joint advisory warning of these ongoing threats and provided mitigation strategies to affected organizations. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/us-warns-of-iranian-hackers-targeting-critical-infrastructure/?utm_source=openai)) This incident underscores the escalating cyber threat landscape, particularly from nation-state actors targeting industrial control systems. Organizations must prioritize securing operational technology environments to prevent similar disruptions and safeguard critical services.
3 months ago
Kill Chain
Google's 2026 Announcement: Accelerating the Shift to Post-Quantum Cryptography by 2029
In March 2026, Google announced an accelerated timeline to migrate its systems to post-quantum cryptography (PQC) by 2029, moving up from the previously anticipated mid-2030s. This decision was driven by rapid advancements in quantum computing, particularly in hardware development, error correction, and factoring resource estimates, which suggest that quantum computers capable of breaking current encryption methods could emerge sooner than expected. Google's proactive approach aims to safeguard its systems, devices, and data against potential quantum threats. ([blog.google](https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/?utm_source=openai)) This move underscores the urgency for organizations to assess and enhance their cryptographic resilience. The looming possibility of quantum computers rendering existing encryption obsolete necessitates immediate action to transition to quantum-resistant algorithms, ensuring the continued security of sensitive information in the near future.
3 months ago
Kill Chain
Adobe Reader Zero-Day Exploit Uncovered in December 2025
In December 2025, attackers began exploiting a zero-day vulnerability in Adobe Reader by distributing maliciously crafted PDF documents. These documents, often containing Russian-language lures related to the Russian oil and gas industry, leveraged an unpatched flaw in Adobe Reader to steal data from compromised systems and potentially execute remote code, granting attackers full control over affected machines. This incident underscores the persistent threat posed by zero-day vulnerabilities and the importance of timely software updates. The use of industry-specific lures highlights the evolving tactics of threat actors targeting specific sectors.
3 months ago
Kill Chain
Eurail 2025 Data Breach: A Wake-Up Call for Travel Industry Cybersecurity
In late December 2025, Eurail B.V., a Netherlands-based travel company, experienced a significant data breach when unauthorized actors accessed its network and exfiltrated files containing sensitive customer information. The breach, which occurred on December 26, 2025, was discovered on January 5, 2026, and confirmed on February 25, 2026. Approximately 308,777 individuals were affected, with compromised data including names, passport numbers, dates of birth, email addresses, postal addresses, phone numbers, bank account references (IBANs), and health-related information. ([claimdepot.com](https://www.claimdepot.com/data-breach/eurail-2026?utm_source=openai)) This incident underscores the escalating threat landscape targeting the travel industry, where personal data is highly valuable. The breach highlights the critical need for robust cybersecurity measures, including regular system audits, employee training, and comprehensive incident response plans to mitigate potential risks and protect customer information.
3 months ago
Kill Chain
ChipSoft Ransomware Attack: A Wake-Up Call for Healthcare Cybersecurity
In April 2026, ChipSoft, a leading Dutch healthcare software provider serving approximately 70% of the country's hospitals, suffered a ransomware attack. The incident led to the company's website going offline and raised concerns about potential unauthorized access to patient records. In response, several hospitals disconnected their systems as a precautionary measure. The full extent of the data breach remains under investigation. This attack underscores the escalating threat of ransomware targeting critical healthcare infrastructure. The incident highlights the urgent need for robust cybersecurity measures and comprehensive incident response plans to protect sensitive patient data and ensure the continuity of healthcare services.
3 months ago
Kill Chain
Google Chrome 2026: Device Bound Session Credentials Enhance Security Against Infostealer Threats
In April 2026, Google introduced Device Bound Session Credentials (DBSC) in Chrome 146 for Windows, aiming to combat the escalating threat of session cookie theft by infostealer malware. DBSC cryptographically binds authentication sessions to a user's specific device using hardware-backed security modules like the Trusted Platform Module (TPM). This binding ensures that even if session cookies are exfiltrated, they cannot be utilized on unauthorized devices, thereby mitigating unauthorized access to user accounts. ([security.googleblog.com](https://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html?utm_source=openai)) The deployment of DBSC is particularly timely given the rise of sophisticated infostealer malware, such as LummaC2, which harvests session cookies to bypass traditional authentication mechanisms, including multi-factor authentication (MFA). By rendering stolen session cookies ineffective on unauthorized devices, DBSC addresses a critical vulnerability in current web authentication practices. ([security.googleblog.com](https://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html?utm_source=openai))
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports