Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
ClickFix Campaigns Weaponize Trust: How Attackers Abuse Legitimate Services
ClickFix campaigns represent a sophisticated social engineering attack vector where threat actors disguise malicious PowerShell scripts as legitimate software fixes or updates. These campaigns typically begin with phishing emails or compromised websites that present users with fake error messages, prompting them to copy and execute PowerShell commands that appear to resolve technical issues. The attacks leverage trusted platforms like GitHub, Discord, and legitimate cloud services to host malicious payloads, making detection more challenging for traditional security tools. Once executed, the malicious scripts establish persistent access through various techniques including scheduled tasks, registry modifications, and deployment of remote access tools, allowing attackers to maintain long-term presence in compromised environments. ClickFix campaigns have gained significant traction in 2024 as organizations increasingly adopt cloud-first strategies and remote work models, creating expanded attack surfaces that threat actors exploit through social engineering rather than traditional technical vulnerabilities.
1 week ago
Kill Chain
Critical FreeIPA Vulnerability Exposes Enterprise Authentication Infrastructure to Anonymous Attackers
In September 2026, Red Hat disclosed a critical vulnerability chain in FreeIPA (CVE-2026-76578) with a CVSS score of 9.8 that allows anonymous clients to create reusable administrator credentials without authentication. The flaw exploits a weakness in FreeIPA's access control rules combined with a secondary vulnerability in 389 Directory Server (CVE-2026-76560), enabling attackers to bypass authentication mechanisms and gain administrative privileges on Linux domain controllers. Red Hat successfully reproduced the attack chain twice on default installations, demonstrating how unauthenticated attackers can inject Kerberos identities and obtain administrator group membership. This vulnerability highlights the growing sophistication of identity-based attacks targeting enterprise authentication infrastructure, particularly as organizations increasingly rely on centralized identity management systems for zero trust architectures and cloud-native environments.
1 week ago
Kill Chain
When AI Attacks AI: The 2026 Autonomous Agent Credential Harvesting Campaign
In September 2026, threat actors deployed autonomous AI agent frameworks to conduct large-scale credential harvesting operations, compromising thousands of third-party credentials in under six hours. Google Threat Intelligence Group identified multiple financially motivated groups, including TeamPCP, leveraging AI-assisted tools like DUSTMAKER malware to target AI coding assistants, cloud environments, and supply chains across PyPI, npm, and Docker Hub repositories. The attacks demonstrated unprecedented automation capabilities, with AI systems autonomously managing vulnerability scanning, real-time troubleshooting, and IP rotation without human intervention. This incident represents a critical escalation in AI-enabled cyber threats, coinciding with the rapid adoption of generative AI tools in enterprise environments and the emergence of 'abliterated' open-weight models that bypass safety guardrails.
1 week ago
Kill Chain
WeChat Zero-Click Worm: How 1.4 Billion Users Were at Risk from Incoming Calls
In July 2026, security researchers at Calif discovered a critical zero-click vulnerability in WeChat that allowed attackers to take complete control of user accounts through incoming calls without any user interaction. The exploit worked by leveraging WeChat's contact trust system, enabling worm-like propagation where compromised accounts could automatically infect other contacts. Affecting WeChat's 1.4 billion user base across iPhone and Android platforms, the vulnerability granted attackers full access to messages, payments, and WeChat's extensive ecosystem of mini-programs and services. Tencent patched the flaw in August 2026 versions 8.0.77 for Android and 8.0.76 for iOS. This incident highlights the growing sophistication of mobile application attacks and the critical importance of securing communication platforms that serve as digital wallets and business ecosystems, particularly as zero-click exploits become increasingly weaponized against high-value messaging applications.
1 week ago
Kill Chain
July 2024 Water Utility Attacks Expose Critical Infrastructure Blind Spots
In July 2024, over 100 water and wastewater treatment systems across multiple states were compromised through vulnerable industrial controllers connected directly to public cellular networks. CISA identified the widespread campaign targeting Rockwell Allen-Bradley, Schneider Electric, and Siemens equipment, with attackers gaining operational control and causing service disruptions including pump station failures and boil-water advisories. The incidents exposed critical infrastructure gaps where operational technology exists outside traditional IT security boundaries, with many systems invisible to network scans but trackable through carrier invoices. This campaign highlights the urgent need for comprehensive network visibility and microsegmentation in critical infrastructure, as traditional network perimeter defenses fail to protect cellular-connected industrial control systems that operate independently of municipal IT networks.
1 week ago
Kill Chain
How BigBear Phishing Service Defeated MFA at 258 Organizations
In September 2026, the BigBear 2.0 phishing-as-a-service platform successfully compromised 258 organizations by bypassing multi-factor authentication on Microsoft 365 accounts. Using an Evilginx2-based adversary-in-the-middle framework across 42 VPS nodes, the operation captured over 5,000 credentials including 474 complete MFA bypasses, 1,032 plaintext passwords, and 4,148 session cookies. The service employed custom JavaScript to disable FIDO2/WebAuthn authentication and used geo-matched residential proxies across 69 countries to evade detection by Microsoft's security systems. This incident highlights the evolving sophistication of phishing-as-a-service platforms that can defeat traditional MFA implementations, demonstrating the urgent need for phishing-resistant authentication methods and comprehensive identity security strategies as threat actors increasingly commercialize advanced bypass techniques.
1 week ago
Kill Chain
PEEP Malware Transforms Chrome and Edge Into Persistent Backdoors
In September 2026, cybersecurity researchers disclosed PEEP, a sophisticated post-exploitation toolkit that transforms Chrome and Edge browsers into persistent backdoors. The malware, derived from the open-source RedExt framework, masquerades as a Smart Bookmarks extension and bypasses browser security by manipulating Chromium's Secure Preferences integrity values. Once deployed on compromised systems, PEEP establishes command-and-control communications via plaintext HTTP, exfiltrates browsing data and credentials, and enables remote command execution through a native messaging host. The toolkit demonstrates advanced persistence techniques and represents a significant evolution in browser-based post-compromise frameworks. This incident highlights the growing sophistication of browser-based attack vectors as threat actors increasingly leverage trusted applications to maintain persistence and evade detection in enterprise environments.
1 week ago
Kill Chain
Telerik UI Padding Oracle Exploit: CVE-2026-13181 RCE Chain Puts Web Apps at Risk
In July 2026, Progress Software patched a critical vulnerability chain in Telerik UI for ASP.NET AJAX (CVE-2026-13181) that allows unauthenticated remote code execution. Security firm TantoSec released a working exploit in September 2026, demonstrating how attackers can chain a padding oracle vulnerability with unguarded type resolution to achieve code execution on vulnerable web applications. The attack requires specific non-default configurations including custom encryption keys, affecting versions 2010.1.309 through 2026.2.519. While no confirmed exploitation has been reported for these specific CVEs, the Telerik component has a history of being targeted by ransomware groups and nation-state actors through previous vulnerabilities. This incident highlights the persistent risks in web application components and the importance of timely patching, especially given Telerik's history as a favored target for sophisticated threat actors seeking initial access to enterprise networks.
1 week ago
Kill Chain
PaperCut Vulnerabilities Exploited in Massive Credential Theft Campaign Against Schools
In September 2026, threat actors actively exploited two chained PaperCut vulnerabilities (CVE-2026-81578 and CVE-2026-82078) to conduct widespread credential theft attacks against educational institutions across the United States and Europe. The attack chain leveraged an authentication bypass vulnerability followed by remote code execution to deploy registry harvesting tools, Metasploit payloads, and create privileged accounts on compromised print management servers. Arctic Wolf researchers observed attackers systematically extracting Windows registry hives, searching configuration files for sensitive credentials, and establishing persistent access through Meterpreter sessions, targeting organizations from K-12 schools to major universities. This campaign highlights the continued targeting of educational infrastructure, which often lacks robust security controls and runs legacy systems with delayed patching cycles, making institutions particularly vulnerable to supply chain and third-party application exploits.
2 weeks ago
Kill Chain
CISA Flags Critical Chrome V8 Vulnerability CVE-2026-85046 for Active Exploitation
CISA added CVE-2026-85046, a Google Chromium V8 type confusion vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog on September 4, 2026, based on evidence of active exploitation. Type confusion vulnerabilities in browser engines allow attackers to bypass memory protections and achieve arbitrary code execution, making them highly valuable for threat actors targeting end users. The vulnerability poses significant risks to federal enterprises and requires immediate patching under BOD 26-04. Browser-based attacks continue to represent a critical threat vector as organizations increasingly rely on web applications and remote work environments. V8 engine vulnerabilities are particularly concerning due to Chrome's widespread adoption and the potential for supply chain attacks through compromised websites.
2 weeks ago
Kill Chain
Serbian Government Spyware Campaign Threatens EU Accession Amid Surveillance Scandal
In 2024, Serbian government authorities conducted systematic surveillance operations against student activists and political opposition using Pegasus and NoviSpy spyware. The SHARE Foundation, in collaboration with Amnesty International and The Citizen Lab, discovered infections on activists' phones, with evidence linking NoviSpy deployments directly to Serbian state authorities. The campaign targeted individuals ahead of elections, representing a coordinated effort to suppress political dissent through digital surveillance. This surveillance operation has prompted 29 European Parliament members to demand delays in Serbia's EU accession process until a full investigation is completed and rule-of-law accountability is established. This incident exemplifies the growing trend of nation-state actors weaponizing commercial spyware against civil society, particularly in countries seeking international legitimacy while simultaneously suppressing domestic opposition through sophisticated surveillance technologies.
2 weeks ago
Kill Chain
Chrome Zero-Day CVE-2026-85046: Enterprise Defense Against Browser Exploitation
In September 2026, Google patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome's V8 JavaScript engine that was actively exploited in the wild. The zero-day flaw, discovered by security researcher Salvatore Gulizia, could be triggered through specially crafted HTML pages containing malicious JavaScript, potentially enabling remote code execution within Chrome's sandboxed renderer process. This marked the sixth actively exploited Chrome zero-day patched by Google in 2026, highlighting an escalating pattern of browser-based attacks targeting the widely-used V8 engine across multiple incidents throughout the year. This incident underscores the current surge in browser exploitation campaigns as attackers increasingly target client-side vulnerabilities to establish initial access, particularly through JavaScript engines that process untrusted web content at scale across millions of users daily.
2 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports