Validated Containment Architectures are here. →Explore

Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2371 threat reports
Page 86 of 198

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Government Administration Threat Reports

Showing 10211032 / 2371 reports
DarkSword Exploit Kit: A 2026 Cybersecurity Threat Targeting iOS Devices
Impact· HIGH

DarkSword Exploit Kit: A 2026 Cybersecurity Threat Targeting iOS Devices

In March 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) mandated federal agencies to patch three iOS vulnerabilities exploited by the DarkSword exploit kit. These vulnerabilities, identified as CVE-2025-31277, CVE-2025-43510, and CVE-2025-43520, were leveraged in cyberespionage and cryptocurrency theft attacks. The DarkSword framework enabled attackers to escape sandboxes, escalate privileges, and execute remote code on unpatched iPhones running iOS versions 18.4 through 18.7. Threat groups, including UNC6353—a suspected Russian espionage entity—utilized DarkSword to deploy malware such as GhostBlade, GhostKnife, and GhostSaber, facilitating data exfiltration and unauthorized code execution. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-warns-of-apple-flaws-exploited-in-spyware-crypto-theft-attacks/?utm_source=openai)) This incident underscores the escalating sophistication of mobile exploit kits and the critical need for timely patching of known vulnerabilities. The involvement of state-sponsored actors in deploying such advanced tools highlights the persistent threat to both governmental and private sector entities, emphasizing the importance of robust cybersecurity measures and vigilance against emerging attack vectors.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Handala Hackers Exploit Telegram for Malware Attacks in 2026
Impact· MEDIUM

Handala Hackers Exploit Telegram for Malware Attacks in 2026

In March 2026, the FBI issued a warning about Iranian state-sponsored hackers, specifically the Handala group, utilizing Telegram as command-and-control infrastructure in malware attacks. These attacks targeted journalists critical of the Iranian government, dissidents, and opposition groups worldwide. The attackers employed social engineering tactics to infect Windows devices, enabling the exfiltration of screenshots and files from compromised systems. This activity led to intelligence collection, data leaks, and reputational harm to the victims. The incident underscores the evolving tactics of state-sponsored cyber actors, who are increasingly leveraging popular communication platforms like Telegram for malicious purposes. This trend highlights the need for heightened vigilance and robust cybersecurity measures to protect against sophisticated social engineering and malware deployment strategies.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
TeamPCP's 2026 Kubernetes Wiper Attack: A Wake-Up Call for Cloud Security
Impact· HIGH

TeamPCP's 2026 Kubernetes Wiper Attack: A Wake-Up Call for Cloud Security

In March 2026, the cybercriminal group TeamPCP launched a targeted wiper malware attack against Kubernetes clusters, specifically aiming to destroy systems configured for Iran. The attackers exploited misconfigured cloud environments to deploy a malicious script that wiped all machines identified with Iranian locale settings. This campaign followed TeamPCP's previous supply-chain attack on the Trivy vulnerability scanner and the NPM-based 'CanisterWorm' campaign. The wiper attack resulted in significant operational disruptions for affected organizations, highlighting the group's evolving tactics and the critical need for robust cloud security configurations. This incident underscores the increasing sophistication of cyber threats targeting cloud infrastructures and the geopolitical motivations driving such attacks. Organizations must prioritize securing their cloud environments, regularly audit configurations, and implement comprehensive monitoring to detect and mitigate similar threats.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft IRS Phishing Campaign 2026: A Deep Dive
Impact· HIGH

Microsoft IRS Phishing Campaign 2026: A Deep Dive

In March 2026, Microsoft identified a sophisticated phishing campaign exploiting the U.S. tax season to target over 29,000 users across 10,000 organizations. Attackers impersonated the Internal Revenue Service (IRS), sending emails that prompted recipients to download a fake 'IRS Transcript Viewer.' This malicious software facilitated the deployment of Remote Monitoring and Management (RMM) tools like ScreenConnect, granting attackers persistent access to compromised systems. The campaign predominantly affected sectors such as financial services, technology, and retail, with 95% of targets located in the U.S. This incident underscores a growing trend where cybercriminals leverage trusted brands and urgent themes to deceive users. The use of legitimate RMM tools for malicious purposes highlights the evolving tactics of threat actors, emphasizing the need for heightened vigilance and robust security measures during periods of increased cyber threat activity.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
AWS Bedrock SCP Bypass Vulnerability Resolved in 2026
Impact· HIGH

AWS Bedrock SCP Bypass Vulnerability Resolved in 2026

Between December 4, 2025, and January 26, 2026, AWS Bedrock experienced a security vulnerability where Service Control Policies (SCPs) were not fully enforced when using long-term API keys on the bedrock-mantle endpoint. This flaw allowed unauthorized actions that could bypass established security controls. AWS has since resolved the issue and confirmed that no customers were impacted. ([sonraisecurity.com](https://sonraisecurity.com/blog/cracks-in-the-bedrock/?utm_source=openai)) This incident underscores the critical importance of continuous monitoring and timely patching in cloud environments. Organizations must remain vigilant to ensure that security policies are effectively enforced to prevent potential breaches.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Phishing Campaign Targets Multiple Sectors with Advanced Evasion Techniques
Impact· HIGH

Phishing Campaign Targets Multiple Sectors with Advanced Evasion Techniques

In early 2026, a sophisticated phishing campaign targeted the healthcare, government, hospitality, and education sectors across multiple countries. Attackers employed advanced evasion techniques, including the use of hidden text and zero-font tactics, to bypass traditional email security measures. The campaign involved sending emails that appeared to be from legitimate sources, such as internal IT departments or trusted vendors, tricking recipients into clicking malicious links or downloading malware. Once compromised, attackers gained unauthorized access to sensitive information, leading to data breaches and operational disruptions. This incident underscores the increasing sophistication of phishing attacks and the need for organizations to enhance their cybersecurity defenses. The use of advanced evasion techniques highlights the importance of continuous monitoring, employee training, and the implementation of multi-factor authentication to mitigate such threats.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(low)
Read Report
CISA Flags Critical Vulnerabilities in Apple, Craft CMS, and Laravel Livewire
Impact· CRITICAL

CISA Flags Critical Vulnerabilities in Apple, Craft CMS, and Laravel Livewire

In March 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added multiple vulnerabilities affecting Apple products, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities (KEV) catalog. Notably, CVE-2025-31277, a memory corruption issue in Apple's WebKit, was exploited by the 'DarkSword' malware, impacting over 220 million iPhones running iOS versions 18.4 through 18.7. Additionally, CVE-2025-23209, a code injection vulnerability in Craft CMS, allowed remote code execution in installations with compromised security keys. CISA mandated federal agencies to patch these vulnerabilities by April 3, 2026. The inclusion of these vulnerabilities in the KEV catalog underscores the increasing sophistication of cyber threats targeting widely-used platforms. Organizations are urged to prioritize patching to mitigate potential exploits and protect sensitive data from unauthorized access.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Unauthenticated RCE Vulnerability in Oracle Identity Manager (CVE-2025-61757)
Impact· CRITICAL

Critical Unauthenticated RCE Vulnerability in Oracle Identity Manager (CVE-2025-61757)

In October 2025, Oracle disclosed a critical vulnerability (CVE-2025-61757) in Oracle Identity Manager, a key component of Oracle Fusion Middleware. This flaw, with a CVSS score of 9.8, allows unauthenticated remote code execution via HTTP, enabling attackers to fully compromise affected systems. The vulnerability arises from missing authentication checks in the REST WebServices component, permitting unauthorized access and control over the Identity Manager. ([hipaajournal.com](https://www.hipaajournal.com/critical-flaw-oracle-identity-manager-nov-2025/?utm_source=openai)) The exploitation of this vulnerability has been observed in the wild, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities catalog and mandate federal agencies to apply patches by December 12, 2025. Organizations using Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are urged to apply the October 2025 Critical Patch Update immediately to mitigate potential risks. ([securityweek.com](https://www.securityweek.com/cisa-confirms-exploitation-of-recent-oracle-identity-manager-vulnerability/?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Russian Hackers Exploit Signal and WhatsApp in Sophisticated Phishing Campaign
Impact· HIGH

Russian Hackers Exploit Signal and WhatsApp in Sophisticated Phishing Campaign

In March 2026, Dutch intelligence agencies reported a large-scale global cyber campaign by Russian state-sponsored hackers targeting Signal and WhatsApp accounts of dignitaries, military personnel, and journalists. The attackers employed social engineering techniques, such as impersonating support chatbots, to deceive users into revealing security verification codes and PINs. This allowed unauthorized access to individual accounts, enabling the interception of sensitive communications. Notably, the campaign did not exploit technical vulnerabilities within the messaging platforms themselves but rather manipulated legitimate security features through phishing tactics. ([english.aivd.nl](https://english.aivd.nl/latest/news/2026/03/09/russia-targets-signal-and-whatsapp-accounts-in-cyber-campaign?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors utilizing sophisticated social engineering methods to compromise secure communication channels. The focus on widely used encrypted messaging applications highlights the need for heightened vigilance and robust security practices among high-profile individuals and organizations to safeguard sensitive information.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Oracle Fusion Middleware 2026 Critical RCE Vulnerability
Impact· CRITICAL

Oracle Fusion Middleware 2026 Critical RCE Vulnerability

In January 2026, Oracle disclosed a critical remote code execution (RCE) vulnerability, CVE-2026-21962, affecting Oracle Fusion Middleware components, including Oracle HTTP Server and WebLogic Server Proxy Plug-ins. This flaw allows unauthenticated attackers with network access via HTTP to compromise affected servers, potentially leading to unauthorized creation, deletion, or modification of critical data. The vulnerability impacts versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 of the affected components. Oracle released patches as part of their January 2026 Critical Patch Update to address this issue. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-21962?utm_source=openai)) The exploitation of this vulnerability underscores the persistent threat posed by unauthenticated RCE flaws in widely used enterprise software. Organizations are urged to apply the provided patches promptly to mitigate potential risks associated with this vulnerability.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Russian Hackers Exploit Social Engineering to Access Signal and WhatsApp Accounts
Impact· MEDIUM

Russian Hackers Exploit Social Engineering to Access Signal and WhatsApp Accounts

In March 2026, Dutch intelligence agencies reported a large-scale global cyber campaign orchestrated by Russian state-sponsored hackers targeting Signal and WhatsApp accounts of government officials, military personnel, and journalists. The attackers employed sophisticated phishing and social engineering techniques, such as impersonating support chatbots, to deceive users into revealing security verification codes and passcodes. This enabled unauthorized access to individual and group conversations, potentially exposing sensitive information. ([themoscowtimes.com](https://www.themoscowtimes.com/2026/03/09/russian-hackers-targeting-messaging-apps-dutch-spies-say-a92164?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors in exploiting widely-used encrypted messaging platforms. Despite the robust end-to-end encryption of these applications, the human element remains a critical vulnerability. Organizations must enhance user awareness and implement stringent security protocols to mitigate such social engineering threats.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Russian Hackers Exploit Social Engineering to Access Signal and WhatsApp Accounts
Impact· HIGH

Russian Hackers Exploit Social Engineering to Access Signal and WhatsApp Accounts

In March 2026, Dutch intelligence agencies reported a large-scale global cyber campaign by Russian state-sponsored hackers targeting Signal and WhatsApp accounts of dignitaries, military personnel, civil servants, and journalists. The attackers employed social engineering techniques, such as impersonating Signal support chatbots, to deceive users into revealing verification and PIN codes. This allowed them to gain unauthorized access to accounts, read messages, and infiltrate group chats. The campaign exploited legitimate app features like 'linked devices' to maintain persistent access without the users' knowledge. ([english.aivd.nl](https://english.aivd.nl/latest/news/2026/03/09/russia-targets-signal-and-whatsapp-accounts-in-cyber-campaign?utm_source=openai)) This incident underscores the increasing sophistication of state-sponsored cyber operations and highlights the vulnerabilities associated with social engineering tactics. It serves as a critical reminder for organizations and individuals to exercise heightened vigilance, especially when using encrypted messaging platforms for sensitive communications.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports