Validated Containment Architectures are here. →Explore

Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2367 threat reports
Page 76 of 198

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Government Administration Threat Reports

Showing 901912 / 2367 reports
FBI's 2025 Cybercrime Report: A 26% Surge to $21 Billion in Losses
Impact· CRITICAL

FBI's 2025 Cybercrime Report: A 26% Surge to $21 Billion in Losses

In 2025, the FBI's Internet Crime Complaint Center (IC3) reported that Americans lost nearly $21 billion to cyber-enabled crimes, marking a 26% increase from the previous year. The most prevalent incidents included phishing attacks, extortion, and investment scams, with cryptocurrency-related fraud accounting for over $11 billion in losses. Notably, individuals over the age of 60 were disproportionately affected, reporting $7.7 billion in losses, a 37% rise from 2024. Additionally, the FBI highlighted the emergence of AI-driven scams, which resulted in 22,300 complaints and $893 million in losses, involving tactics such as voice cloning and deepfake videos. This surge underscores the evolving sophistication of cybercriminals, who are increasingly leveraging advanced technologies like artificial intelligence to enhance the effectiveness of their schemes. The significant financial impact on older adults highlights the urgent need for targeted education and robust cybersecurity measures to protect vulnerable populations from these emerging threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
APT28's 2025 DNS Hijacking Campaign: A Wake-Up Call for Network Security
Impact· HIGH

APT28's 2025 DNS Hijacking Campaign: A Wake-Up Call for Network Security

In 2025, the Russian state-sponsored cyber group APT28, also known as Fancy Bear, exploited vulnerabilities in MikroTik and TP-Link routers to conduct a large-scale DNS hijacking campaign. By compromising these routers, APT28 redirected internet traffic through attacker-controlled servers, enabling adversary-in-the-middle attacks that harvested credentials from web and email services. This operation targeted a broad range of victims, including organizations linked to the UK Ministry of Defence and NATO logistics contractors, posing significant risks of credential theft, data manipulation, and broader network compromise. ([ncsc.gov.uk](https://www.ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dns-hijacking-operations?utm_source=openai)) This incident underscores the critical importance of securing network infrastructure against sophisticated state-sponsored threats. The exploitation of widely used routers highlights the need for organizations to implement robust security measures, including regular firmware updates, strong authentication protocols, and continuous monitoring to detect and mitigate such attacks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Russia Hacked Routers to Steal Microsoft Office Tokens
Impact· HIGH

Russia Hacked Routers to Steal Microsoft Office Tokens

In April 2026, Russian state-sponsored hackers, identified as APT28 (also known as Fancy Bear or Forest Blizzard), exploited vulnerabilities in outdated MikroTik and TP-Link routers to hijack DNS settings. This allowed them to intercept Microsoft Office authentication tokens from users across more than 18,000 networks without deploying malware. The attackers targeted government agencies, law enforcement, and third-party email providers, compromising over 200 organizations and 5,000 consumer devices. ([cyberkendra.com](https://www.cyberkendra.com/2026/04/your-router-is-spying-on-you-and.html?utm_source=openai)) This incident underscores the critical need for organizations to secure network infrastructure, especially as remote work increases reliance on home and small office routers. Ensuring devices are updated and monitoring for unauthorized DNS changes are essential to prevent similar attacks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Fortinet's 2026 Unauthenticated API Access Bypass: A Critical Security Alert
Impact· CRITICAL

Fortinet's 2026 Unauthenticated API Access Bypass: A Critical Security Alert

In April 2026, Fortinet disclosed a critical vulnerability (CVE-2026-35616) in its FortiClient Endpoint Management Server (EMS) versions 7.4.5 and 7.4.6. This improper access control flaw allowed unauthenticated attackers to execute unauthorized code or commands via crafted API requests. The vulnerability was actively exploited in the wild, prompting Fortinet to release emergency hotfixes and advise customers to apply them immediately. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/?utm_source=openai)) The incident underscores the persistent targeting of Fortinet products by threat actors, highlighting the importance of timely patch management and vigilant monitoring of security advisories to mitigate risks associated with zero-day vulnerabilities. ([tenable.com](https://www.tenable.com/blog/cve-2026-35616-fortinet-forticlientems-improper-access-control-vulnerability-exploited-in-the?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Forest Blizzard's 2026 SOHO Router DNS Hijacking: A Wake-Up Call for Network Security
Impact· CRITICAL

Forest Blizzard's 2026 SOHO Router DNS Hijacking: A Wake-Up Call for Network Security

In April 2026, the Russian state-sponsored group Forest Blizzard exploited vulnerabilities in small office/home office (SOHO) routers to perform DNS hijacking and adversary-in-the-middle (AiTM) attacks. By compromising these routers, they redirected DNS requests through attacker-controlled servers, enabling interception of sensitive communications. This campaign affected over 200 organizations and 5,000 consumer devices, primarily targeting sectors such as government, IT, telecommunications, and energy. The attackers leveraged the compromised infrastructure to collect intelligence and potentially facilitate further malicious activities. This incident underscores the critical need for securing SOHO devices, as they can serve as entry points for sophisticated cyberattacks. Organizations must prioritize regular firmware updates, enforce strong authentication measures, and monitor network traffic for anomalies to mitigate such threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Fortinet FortiClientEMS 2026 Improper Access Control Vulnerability
Impact· CRITICAL

Fortinet FortiClientEMS 2026 Improper Access Control Vulnerability

In April 2026, Fortinet disclosed a critical improper access control vulnerability (CVE-2026-35616) in FortiClient Endpoint Management Server (EMS) versions 7.4.5 and 7.4.6. This flaw allows unauthenticated attackers to execute unauthorized code or commands via crafted requests, leading to potential remote code execution and privilege escalation. The vulnerability has been actively exploited in the wild, prompting Fortinet to release emergency hotfixes and advise immediate patching to mitigate the risk. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/?utm_source=openai)) The exploitation of CVE-2026-35616 underscores the persistent targeting of Fortinet products by threat actors. Organizations are urged to apply the provided hotfixes promptly and monitor their systems for any signs of compromise to maintain robust security postures. ([tenable.com](https://www.tenable.com/blog/cve-2026-35616-fortinet-forticlientems-improper-access-control-vulnerability-exploited-in-the?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fortinet EMS Vulnerability CVE-2026-35616: Immediate Action Required
Impact· CRITICAL

Fortinet EMS Vulnerability CVE-2026-35616: Immediate Action Required

In April 2026, a critical vulnerability (CVE-2026-35616) was discovered in Fortinet's FortiClient Enterprise Management Server (EMS). This flaw allowed unauthenticated attackers to bypass authentication controls and execute arbitrary code via specially crafted requests. Fortinet released emergency hotfixes to address the issue, urging immediate application to prevent exploitation. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) mandated federal agencies to patch affected systems by April 9, 2026, highlighting the significant risk posed by this vulnerability. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-fortinet-flaw-exploited-in-attacks-by-friday/?utm_source=openai)) The exploitation of CVE-2026-35616 underscores the persistent threat of zero-day vulnerabilities in widely used enterprise solutions. Organizations are reminded of the critical importance of timely patch management and proactive security measures to mitigate such risks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
BKA Unmasks REvil Leaders Behind 130 German Ransomware Attacks
Impact· CRITICAL

BKA Unmasks REvil Leaders Behind 130 German Ransomware Attacks

In April 2026, Germany's Federal Criminal Police Office (BKA) unmasked the identities of two key figures associated with the REvil ransomware-as-a-service (RaaS) operation. Daniil Maksimovich Shchukin, known online as 'UNKN,' and Anatoly Sergeevitsch Kravchuk were linked to 130 ransomware attacks across Germany, resulting in over €35.4 million in damages. The REvil group, active from 2019 to 2021, targeted high-profile organizations, demanding substantial ransoms in exchange for decrypting and not leaking data. ([thehackernews.com](https://thehackernews.com/2026/04/bka-identifies-revil-leaders-behind-130.html?utm_source=openai)) This revelation underscores the persistent threat posed by sophisticated ransomware groups and highlights the importance of international cooperation in cybercrime investigations. Organizations must remain vigilant, as the tactics employed by groups like REvil continue to evolve, posing significant risks to global cybersecurity.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Understanding the BlueHammer Windows Zero-Day Exploit
Impact· MEDIUM

Understanding the BlueHammer Windows Zero-Day Exploit

In April 2026, a security researcher operating under the alias 'Chaotic Eclipse' publicly disclosed a Windows zero-day vulnerability named 'BlueHammer.' This local privilege escalation flaw allows attackers to gain SYSTEM-level access by exploiting a combination of time-of-check to time-of-use (TOCTOU) and path confusion vulnerabilities. The researcher released proof-of-concept (PoC) code on GitHub, expressing dissatisfaction with Microsoft's handling of the disclosure process. As of the disclosure date, no official patch has been released, leaving systems vulnerable to potential exploitation. The public release of the BlueHammer exploit underscores the ongoing challenges in vulnerability disclosure and patch management. Organizations must remain vigilant, as unpatched zero-day vulnerabilities can be rapidly weaponized by threat actors, leading to significant security breaches and operational disruptions.

3 months ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Qilin and Warlock Ransomware Utilize BYOVD to Disable EDR Tools
Impact· CRITICAL

Qilin and Warlock Ransomware Utilize BYOVD to Disable EDR Tools

In April 2026, cybersecurity researchers from Cisco Talos and Trend Micro identified that the Qilin and Warlock ransomware groups are employing the 'Bring Your Own Vulnerable Driver' (BYOVD) technique to disable endpoint detection and response (EDR) tools on compromised systems. This method involves deploying malicious DLLs, such as 'msimg32.dll,' to initiate multi-stage infection chains that terminate over 300 EDR drivers from various security vendors. By leveraging vulnerable drivers like 'rwdrv.sys' and 'hlpdrv.sys,' these ransomware groups effectively neutralize security defenses, facilitating the encryption of files and demanding ransoms from victims. ([thehackernews.com](https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html?utm_source=openai)) The adoption of BYOVD tactics by Qilin and Warlock underscores a significant evolution in ransomware strategies, highlighting the increasing sophistication of threat actors in circumventing traditional security measures. This trend necessitates enhanced vigilance and the implementation of advanced security protocols to detect and mitigate such evasive techniques.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
North Korean Hackers Compromise Axios JavaScript Library in 2026 Supply Chain Attack
Impact· HIGH

North Korean Hackers Compromise Axios JavaScript Library in 2026 Supply Chain Attack

In late March 2026, the widely-used JavaScript library Axios, with over 100 million weekly downloads, was compromised in a sophisticated supply chain attack. Threat actors, identified as the North Korean group UNC1069, gained access to a maintainer's npm account and released two malicious versions of the package: axios@1.14.1 and axios@0.30.4. These versions included a trojan-laden dependency, 'plain-crypto-js@4.2.1', which executed a post-install script to deploy a cross-platform Remote Access Trojan (RAT) targeting macOS, Windows, and Linux systems. The malware connected to a command-and-control server, retrieved system-specific payloads, and erased its tracks to evade detection. The malicious packages were available for approximately three hours before removal, potentially affecting numerous developers and organizations. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/axios-npm-package-compromised-in-supply-chain-attack-that-deployed-a-cross-platform-rat?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks, where trusted software components are weaponized to distribute malware. The rapid detection and removal of the compromised packages highlight the importance of vigilant monitoring and swift response mechanisms. Organizations are urged to review their software supply chain security practices, implement robust access controls, and ensure the integrity of their development environments to mitigate such risks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations
Impact· HIGH

Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations

In March 2026, an Iran-linked threat actor executed a coordinated password-spraying campaign targeting Microsoft 365 environments across Israel and the United Arab Emirates. The attacks occurred in three waves on March 3, 13, and 23, affecting over 300 organizations in Israel and more than 25 in the UAE. Primary targets included municipalities, technology firms, transportation, and healthcare sectors. Attackers utilized rotating Tor exit nodes for scanning and employed VPN services geolocated within Israel to bypass geo-fencing restrictions. Once valid credentials were obtained, they accessed and exfiltrated sensitive data, including personal emails. ([thehackernews.com](https://thehackernews.com/2026/04/iran-linked-password-spraying-campaign.html?utm_source=openai)) This incident underscores the escalating cyber threats in the Middle East, particularly those linked to nation-state actors. The use of password-spraying techniques highlights the critical need for robust authentication measures and vigilant monitoring to detect and mitigate unauthorized access attempts.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports