Validated Containment Architectures are here. →Explore

Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2371 threat reports
Page 93 of 198

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Government Administration Threat Reports

Showing 11051116 / 2371 reports
Critical Unauthenticated Access Vulnerability in Honeywell IQ4x BMS Controllers (2026)
Impact· HIGH

Critical Unauthenticated Access Vulnerability in Honeywell IQ4x BMS Controllers (2026)

In March 2026, a critical vulnerability (CVE-2026-3611) was identified in Honeywell's IQ4x Building Management System (BMS) controllers. The flaw allows unauthenticated access to the web-based Human-Machine Interface (HMI) in factory-default configurations, enabling remote attackers to create administrative accounts, manipulate building controls, and potentially lock out legitimate operators. This vulnerability affects multiple models, including IQ4E, IQ412, IQ422, IQ4NC, IQ41x, IQ3, and IQECO, across firmware versions from v3.50_3.44 to v4.36_build_4.3.7.9. ([community.itbible.org](https://community.itbible.org/t/honeywell-iq4x-bms-controller/2685?utm_source=openai)) The discovery underscores the critical need for secure default configurations in industrial control systems. With thousands of these controllers potentially exposed online, the risk of unauthorized access to critical infrastructure is heightened, emphasizing the importance of immediate remediation and robust security practices in operational technology environments. ([cybersecuritynews.com](https://cybersecuritynews.com/thousand-of-honeywell-controllers-exposed/?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in Ceragon and Siklu's EtherHaul and MultiHaul Devices (CVE-2025-57176)
Impact· CRITICAL

Critical Vulnerability in Ceragon and Siklu's EtherHaul and MultiHaul Devices (CVE-2025-57176)

In September 2025, a critical vulnerability (CVE-2025-57176) was identified in Ceragon Networks and Siklu Communication's EtherHaul and MultiHaul series devices. The 'rfpiped' service on TCP port 555 allowed unauthenticated file uploads to any writable location on the device. This flaw, present in firmware versions 7.4.0 through 10.7.3, utilized weak encryption for metadata and transmitted file contents in cleartext, lacking authentication and path validation. Exploitation could lead to unauthorized access and control over affected devices. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-57176?utm_source=openai)) This incident underscores the persistent risks associated with inadequate authentication mechanisms in network devices. Organizations must prioritize regular firmware updates and implement robust access controls to mitigate such vulnerabilities.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Unveiling Critical Reverse Proxy Header Vulnerabilities in 2025
Impact· CRITICAL

Unveiling Critical Reverse Proxy Header Vulnerabilities in 2025

In 2025, critical vulnerabilities were identified in reverse proxy applications, notably Fabio and OAuth2-Proxy, exposing significant security risks. CVE-2025-48865 in Fabio allowed attackers to manipulate or remove security-critical headers like X-Forwarded-Host and X-Real-IP by exploiting the HTTP Connection header, potentially leading to access control bypasses. Similarly, CVE-2025-64484 in OAuth2-Proxy enabled authenticated users to inject underscore variants of X-Forwarded-* headers, bypassing the proxy's filtering logic and potentially escalating privileges in upstream applications. These vulnerabilities underscore the importance of stringent header validation and normalization practices in reverse proxy configurations. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-48865?utm_source=openai)) The discovery of these vulnerabilities highlights a systemic issue in how reverse proxies handle HTTP headers, emphasizing the need for organizations to reassess and fortify their security measures to prevent similar exploits.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SolarWinds Web Help Desk 2025 AjaxProxy RCE Vulnerability
Impact· CRITICAL

SolarWinds Web Help Desk 2025 AjaxProxy RCE Vulnerability

In September 2025, a critical vulnerability (CVE-2025-26399) was identified in SolarWinds Web Help Desk, allowing unauthenticated remote attackers to execute arbitrary code on affected systems. This flaw, rooted in insecure deserialization within the AjaxProxy component, enables attackers to run commands on the host machine without authentication. Despite previous patches for related vulnerabilities (CVE-2024-28986 and CVE-2024-28988), this issue persisted, leading to active exploitation in the wild. Organizations using versions up to 12.8.7 are at significant risk and should apply the latest hotfix immediately. The recurrence of such vulnerabilities underscores the importance of comprehensive security reviews and prompt patch management. As attackers increasingly exploit deserialization flaws, organizations must prioritize securing their software supply chains and implementing robust monitoring to detect and respond to such threats promptly.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Sednit's Resurgence: Advanced Cyber Espionage Targeting Ukrainian Military (2024-2026)
Impact· HIGH

Sednit's Resurgence: Advanced Cyber Espionage Targeting Ukrainian Military (2024-2026)

Between April 2024 and March 2026, the Russian state-sponsored group Sednit (also known as APT28 or Fancy Bear) reactivated its advanced development team, deploying sophisticated implants named BeardShell and Covenant to conduct prolonged surveillance on Ukrainian military personnel. These tools, leveraging legitimate cloud services for command and control, demonstrate a direct code lineage to Sednit's earlier malware from the 2010s, indicating a resurgence in their cyber espionage capabilities. This resurgence underscores the persistent threat posed by nation-state actors employing advanced techniques to infiltrate and monitor critical military infrastructures, highlighting the need for continuous vigilance and adaptive cybersecurity measures.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Authentication Bypass Vulnerability Discovered in pac4j-jwt Java Library
Impact· CRITICAL

Critical Authentication Bypass Vulnerability Discovered in pac4j-jwt Java Library

In March 2026, a critical authentication bypass vulnerability (CVE-2026-29000) was discovered in the pac4j-jwt Java library, affecting versions prior to 4.5.9, 5.7.9, and 6.3.3. This flaw allows remote attackers to forge authentication tokens by exploiting improper verification of cryptographic signatures in the JwtAuthenticator component when processing encrypted JSON Web Tokens (JWTs). By crafting a JWE-wrapped PlainJWT with arbitrary subject and role claims, attackers can bypass signature verification and authenticate as any user, including administrators. ([arcticwolf.com](https://arcticwolf.com/resources/blog/cve-2026-29000/?utm_source=openai)) The vulnerability poses a significant risk due to the widespread use of pac4j-jwt in various Java applications and frameworks. Organizations utilizing affected versions are urged to upgrade to the latest fixed releases immediately to mitigate potential exploitation. ([arcticwolf.com](https://arcticwolf.com/resources/blog/cve-2026-29000/?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Microsoft's March 2026 Patch Tuesday: Addressing 83 Vulnerabilities, Including Two Publicly Disclosed Zero-Days
Impact· HIGH

Microsoft's March 2026 Patch Tuesday: Addressing 83 Vulnerabilities, Including Two Publicly Disclosed Zero-Days

In March 2026, Microsoft released its Patch Tuesday updates, addressing 83 vulnerabilities across its software portfolio, including Windows, Office, SQL Server, Azure, and .NET. Notably, this release included two publicly disclosed zero-day vulnerabilities: CVE-2026-21262, an elevation of privilege flaw in Microsoft SQL Server, and CVE-2026-26127, a denial-of-service vulnerability in .NET. Additionally, six vulnerabilities were identified as more likely to be exploited, emphasizing the importance of timely patch application. This update marks the first in six months without any actively exploited zero-day vulnerabilities, indicating a positive trend in Microsoft's vulnerability management efforts. ([cyberscoop.com](https://cyberscoop.com/microsoft-patch-tuesday-march-2026/?utm_source=openai)) The absence of actively exploited zero-day vulnerabilities in this release suggests improved security measures and proactive patching strategies. However, the presence of publicly disclosed vulnerabilities underscores the need for organizations to remain vigilant and prioritize the deployment of these updates to mitigate potential risks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
APT28's Exploitation of Microsoft Office Vulnerability: A Deep Dive
Impact· HIGH

APT28's Exploitation of Microsoft Office Vulnerability: A Deep Dive

In early 2026, the Russian state-sponsored hacking group APT28, also known as Fancy Bear, exploited a newly disclosed Microsoft Office vulnerability (CVE-2026-21509) to target Ukrainian government agencies. The attackers distributed malicious documents via phishing emails, leading to the deployment of the COVENANT malware framework and the BEARDSHELL backdoor, facilitating long-term surveillance and data exfiltration. This campaign underscores the rapid weaponization of zero-day vulnerabilities by nation-state actors and highlights the persistent cyber threats facing governmental institutions. Organizations are urged to promptly apply security patches and enhance their cybersecurity measures to mitigate such sophisticated attacks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Ivanti EPM Vulnerability Exploited: Immediate Action Required
Impact· HIGH

Critical Ivanti EPM Vulnerability Exploited: Immediate Action Required

In February 2026, a critical authentication bypass vulnerability (CVE-2026-1603) was identified in Ivanti Endpoint Manager (EPM) versions prior to 2024 SU5. This flaw allows remote, unauthenticated attackers to access stored credential data by exploiting improper authentication mechanisms, specifically through malformed header concatenation in the WSAuth.dll component. Successful exploitation enables attackers to retrieve encrypted credential blobs for high-privilege accounts, potentially compromising the entire endpoint management trust model and facilitating lateral movement within networks. ([dbugs.ptsecurity.com](https://dbugs.ptsecurity.com/vulnerability/CVE-2026-1603?utm_source=openai)) The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-1603 to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation in the wild. Organizations are urged to upgrade to Ivanti EPM 2024 SU5 immediately to mitigate this risk. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-recently-patched-ivanti-epm-flaw-now-actively-exploited/?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Microsoft's March 2026 Patch Tuesday: Addressing Critical Zero-Day Vulnerabilities
Impact· HIGH

Microsoft's March 2026 Patch Tuesday: Addressing Critical Zero-Day Vulnerabilities

In March 2026, Microsoft released its Patch Tuesday updates, addressing 79 vulnerabilities across various products, including Windows, Office, Azure, SQL Server, and .NET. Notably, two zero-day vulnerabilities were publicly disclosed prior to the release: CVE-2026-21262, an elevation of privilege flaw in SQL Server, and CVE-2026-26127, a denial-of-service vulnerability in .NET. While these vulnerabilities were publicly known, there was no evidence of active exploitation at the time of the update. Organizations are advised to prioritize patching these vulnerabilities to mitigate potential risks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2026-patch-tuesday-fixes-2-zero-days-79-flaws/?utm_source=openai)) The disclosure of these zero-day vulnerabilities underscores the critical importance of timely patch management. Even in the absence of active exploitation, publicly known vulnerabilities can quickly become targets for cybercriminals. This incident highlights the need for organizations to maintain robust vulnerability management practices to protect their systems and data.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Adds SolarWinds, Ivanti, and Workspace One Vulnerabilities to KEV Catalog
Impact· CRITICAL

CISA Adds SolarWinds, Ivanti, and Workspace One Vulnerabilities to KEV Catalog

In March 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. These include CVE-2021-22054, a server-side request forgery in Omnissa Workspace One UEM; CVE-2025-26399, a deserialization flaw in SolarWinds Web Help Desk; and CVE-2026-1603, an authentication bypass in Ivanti Endpoint Manager. Exploitation of these vulnerabilities allows unauthorized access to sensitive information and remote code execution on affected systems. ([thehackernews.com](https://thehackernews.com/2026/03/cisa-flags-solarwinds-ivanti-and.html?utm_source=openai)) The inclusion of these vulnerabilities in the KEV catalog underscores the persistent threat posed by unpatched software flaws. Organizations are urged to apply the necessary patches promptly to mitigate potential risks associated with these actively exploited vulnerabilities.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
BeatBanker: The Dual-Mode Android Malware Threatening Brazilian Users in 2026
Impact· HIGH

BeatBanker: The Dual-Mode Android Malware Threatening Brazilian Users in 2026

In March 2026, cybersecurity researchers identified 'BeatBanker,' a sophisticated Android malware campaign targeting users in Brazil. Disguised as legitimate applications, including a fake Google Play Store and a counterfeit Starlink app, BeatBanker employs phishing tactics to infiltrate devices. Once installed, it operates as both a cryptocurrency miner and a banking Trojan, enabling attackers to hijack devices, steal financial credentials, and manipulate cryptocurrency transactions. Notably, the malware maintains persistence by continuously playing an inaudible audio file, preventing system termination. The campaign has evolved to deploy the BTMOB remote administration tool, granting attackers full control over compromised devices. This incident underscores the escalating complexity of mobile malware threats and the critical need for users to download apps exclusively from official sources, scrutinize app permissions, and keep their systems updated to mitigate such risks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports