✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Coruna Exploit Kit: Unveiling the First Mass-Scale iOS Attack
In early 2026, security researchers uncovered the 'Coruna' exploit kit, a sophisticated suite of hacking tools capable of compromising iPhones running older iOS versions. Initially identified in February 2025 during a surveillance vendor's attempt to deploy spyware on behalf of a government client, Coruna was later observed in attacks targeting Ukrainian users by a Russian espionage group and subsequently by financially motivated hackers in China. The exploit kit chains together multiple vulnerabilities, allowing attackers to bypass iOS defenses and gain full control over targeted devices. ([techcrunch.com](https://techcrunch.com/2026/03/03/a-suite-of-government-hacking-tools-targeting-iphones-is-now-being-used-by-cybercriminals/?utm_source=openai)) The proliferation of Coruna underscores the risks associated with the leakage of advanced cyber tools originally developed for government use. Similar to the EternalBlue exploit that fueled the WannaCry and NotPetya attacks in 2017, Coruna's widespread availability has enabled various threat actors to conduct mass-scale attacks on iOS devices, affecting at least 42,000 devices to date.
4 months ago
Kill Chain
University of Hawaiʻi Cancer Center's 2025 Ransomware Attack: A Wake-Up Call for Research Institutions
In August 2025, the University of Hawaiʻi Cancer Center's Epidemiology Division experienced a ransomware attack that encrypted and potentially exfiltrated sensitive data. The breach affected approximately 1.24 million individuals, exposing personal information such as Social Security numbers, driver's license numbers, and health-related data. The university engaged with cybersecurity experts and the attackers to obtain a decryption tool and secure assurances that the stolen data was destroyed. There was no impact on clinical operations, patient care, or student records. ([hawaii.edu](https://www.hawaii.edu/news/2026/02/27/notice-of-cyberattack-uh-cancer-center/?utm_source=openai)) This incident underscores the growing threat of ransomware attacks targeting research institutions and the critical importance of robust cybersecurity measures to protect sensitive personal and health information. Organizations must remain vigilant and proactive in implementing comprehensive security protocols to mitigate such risks.
4 months ago
Kill Chain
AWS Data Centers in Middle East Damaged by Drone Strikes
In early March 2026, Amazon Web Services (AWS) experienced significant disruptions after drone strikes targeted its data centers in the Middle East. Two facilities in the United Arab Emirates (UAE) were directly hit, while a third in Bahrain sustained damage from a nearby strike. These attacks resulted in structural damage, power outages, and water damage due to fire suppression efforts, leading to elevated error rates and degraded availability for services such as Amazon EC2, Amazon S3, and Amazon DynamoDB. AWS is collaborating with local authorities to restore services, but recovery is expected to be prolonged due to the extent of the physical damage. This incident underscores the vulnerability of critical cloud infrastructure to physical attacks, especially in regions experiencing geopolitical tensions. Organizations relying on cloud services are reminded of the importance of robust disaster recovery plans and the need to consider geographic redundancy to mitigate risks associated with localized disruptions.
4 months ago
Kill Chain
LexisNexis Data Breach: A Wake-Up Call for Third-Party Platform Security
In December 2024, LexisNexis Risk Solutions experienced a data breach when an unauthorized party accessed data stored on GitHub, a third-party platform used for software development. The breach, discovered in April 2025, exposed personal information of over 364,000 individuals, including names, contact details, Social Security numbers, driver's license numbers, and dates of birth. The company has since notified affected individuals and offered two years of complimentary identity protection and credit monitoring services. This incident underscores the critical importance of securing third-party platforms and the potential risks associated with their use. Organizations must ensure robust security measures are in place to protect sensitive data, especially when utilizing external services for development purposes.
4 months ago
Kill Chain
Chrome's 2026 Vulnerability: A Wake-Up Call for Browser Security
In January 2026, a high-severity vulnerability (CVE-2026-0628) was identified in Google Chrome's WebView component, allowing attackers to escalate privileges via malicious extensions. This flaw, present in versions prior to 143.0.7499.192, enabled unauthorized script or HTML injection into privileged pages, potentially granting access to sensitive resources. Google promptly addressed the issue by releasing a patch on January 7, 2026. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-0628?utm_source=openai)) The incident underscores the critical importance of timely software updates and vigilant extension management. As browser vulnerabilities continue to be a prime target for cyber threats, organizations must prioritize regular patching and educate users on the risks associated with unverified extensions to mitigate potential security breaches.
4 months ago
Kill Chain
Microsoft 2026 OAuth Redirection Abuse: A New Phishing Threat
In early March 2026, Microsoft identified a sophisticated phishing campaign targeting government and public-sector organizations. Attackers exploited the OAuth 2.0 redirection mechanism to bypass traditional email and browser defenses, redirecting users from legitimate authentication pages to malicious sites. This technique involved crafting OAuth authorization requests with parameters designed to trigger authentication errors, leading to redirects that facilitated malware delivery or credential harvesting. The campaign underscores the evolving tactics of threat actors in leveraging trusted authentication flows to compromise user accounts and deliver malicious payloads. This incident highlights a growing trend in the abuse of OAuth mechanisms for phishing and malware distribution. Organizations must remain vigilant, as attackers continue to refine their methods to exploit authentication protocols, emphasizing the need for robust security measures and user education to mitigate such threats.
4 months ago
Kill Chain
SloppyLemming's Dual Malware Assault on South Asian Governments
Between January 2025 and January 2026, the threat actor known as SloppyLemming executed a series of cyber-espionage attacks targeting government entities and critical infrastructure in Pakistan and Bangladesh. Utilizing spear-phishing emails with malicious PDF and Excel attachments, the group deployed two distinct malware strains: BurrowShell, a backdoor facilitating file manipulation and network tunneling, and a Rust-based keylogger designed for information theft and network reconnaissance. These sophisticated attacks underscore the evolving tactics of nation-state actors in the region. The campaign's reliance on advanced techniques, such as disguising command-and-control traffic as legitimate Windows Update communications and exploiting Cloudflare Workers infrastructure, highlights the increasing complexity of cyber threats facing South Asian nations. This incident serves as a critical reminder for organizations to bolster their cybersecurity defenses against state-sponsored attacks.
4 months ago
Kill Chain
Starkiller Phishing Kit: A New Era of MFA Bypass Attacks
In early 2026, cybersecurity researchers uncovered 'Starkiller,' a sophisticated phishing-as-a-service (PhaaS) platform developed by the cybercrime group Jinkusu. Unlike traditional phishing kits that rely on static HTML clones, Starkiller employs a headless Chrome browser within a Docker container to proxy legitimate login pages in real-time. This adversary-in-the-middle (AiTM) approach allows attackers to intercept user credentials and session tokens, effectively bypassing multi-factor authentication (MFA) mechanisms. The platform's user-friendly control panel enables even low-skilled cybercriminals to launch advanced phishing campaigns, posing a significant threat to organizations relying solely on conventional MFA for security. ([abnormal.ai](https://abnormal.ai/blog/starkiller-phishing-kit?utm_source=openai)) The emergence of Starkiller underscores a critical shift in the cyber threat landscape, highlighting the limitations of traditional MFA solutions against evolving phishing techniques. Organizations must adopt phishing-resistant authentication methods, such as FIDO2/WebAuthn-based hardware security keys, and implement continuous monitoring for anomalous session behaviors to mitigate the risks posed by such advanced phishing platforms. ([bytearchitect.io](https://bytearchitect.io/network-security/Starkiller-Phishing-Kit-Why-MFA-Fails-Against-Real-Time-Reverse-Proxies/?utm_source=openai))
4 months ago
Kill Chain
Microsoft Warns of OAuth Redirect Abuse Delivering Malware to Government Targets
In March 2026, Microsoft identified phishing campaigns exploiting OAuth's standard redirection mechanisms to deliver malware to government and public-sector organizations. Attackers created malicious applications with redirect URLs pointing to rogue domains hosting malware. They distributed OAuth phishing links prompting recipients to authenticate via these applications using intentionally invalid scopes. This process redirected users to attacker-controlled pages, leading to inadvertent malware downloads. The payloads, often in ZIP archives, executed PowerShell commands upon opening, resulting in host reconnaissance, DLL side-loading, and connections to external command-and-control servers. Phishing emails employed lures such as e-signature requests, Teams recordings, and financial themes, sent through mass-sending tools and custom solutions developed in Python and Node.js. Microsoft has since removed several malicious OAuth applications and advises organizations to limit user consent, periodically review application permissions, and remove unused or overprivileged apps. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/?utm_source=openai))
4 months ago
Kill Chain
AI-Assisted FortiGate Breach 2026: A Wake-Up Call for Network Security
Between January 11 and February 18, 2026, a Russian-speaking, financially motivated threat actor utilized multiple commercial generative AI services to compromise over 600 Fortinet FortiGate firewalls across more than 55 countries. The attacker exploited exposed management interfaces and weak credentials lacking multi-factor authentication, without leveraging any known FortiGate vulnerabilities. This campaign underscores the growing trend of cybercriminals employing AI tools to automate and scale attacks, significantly reducing the technical expertise required to execute large-scale intrusions. The incident highlights the urgent need for organizations to secure management interfaces, enforce strong authentication mechanisms, and stay vigilant against AI-assisted cyber threats.
4 months ago
Kill Chain
Cybercriminals Exploit Fake Tech Support to Deploy Havoc C2 Framework
In February 2026, a sophisticated cyberattack campaign was identified targeting multiple organizations. Threat actors impersonated IT support personnel, initiating contact through spam emails followed by phone calls. They convinced victims to grant remote access via tools like AnyDesk, leading to the deployment of a customized version of the Havoc command-and-control (C2) framework. This allowed rapid lateral movement within networks, with the attackers compromising multiple endpoints within hours, indicating objectives of data exfiltration or ransomware deployment. This incident underscores the evolving tactics of cybercriminals, combining social engineering with advanced malware to infiltrate organizations. The use of open-source C2 frameworks like Havoc, customized to evade detection, highlights the need for enhanced vigilance and updated security protocols to counter such multifaceted threats.
4 months ago
Kill Chain
Project Compass: Unveiling the Arrests in 'The Com' Cybercrime Network
In January 2025, Europol initiated Project Compass, a coordinated international operation targeting 'The Com,' a decentralized cybercriminal collective known for engaging in ransomware attacks, financial extortion, and the exploitation of minors. Over the course of the year, the operation led to the arrest of 30 individuals and the identification of 179 additional suspects across 28 countries. Investigators also identified 62 victims, with four being directly safeguarded from further harm. 'The Com' primarily consists of English-speaking individuals aged 16 to 25, who utilize social media platforms, messaging applications, and online gaming environments to recruit and exploit young people. The group's decentralized structure and use of various online platforms have made it particularly challenging for law enforcement to disrupt their activities. The success of Project Compass underscores the importance of international collaboration in combating cybercrime and highlights the ongoing threat posed by such decentralized networks. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/27/europol-the-com-network-arrests/?utm_source=openai)) The significance of this operation is underscored by the increasing prevalence of cybercriminal groups targeting vulnerable populations through online platforms. The arrest of key members of 'The Com' serves as a critical reminder of the need for continuous vigilance and proactive measures to protect minors from online exploitation. Additionally, the operation highlights the evolving tactics of cybercriminals, who are increasingly leveraging decentralized networks and social engineering techniques to perpetrate their crimes. ([darkreading.com](https://www.darkreading.com/threat-intelligence/30-alleged-members-the-com-arrested-project-compass/?utm_source=openai))
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports