Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2822 threat reports
Page 121 of 236

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Government Administration Threat Reports

Showing 14411452 / 2822 reports
Bearlyfy's 2025 Ransomware Campaign Against Russian Companies
Impact· HIGH

Bearlyfy's 2025 Ransomware Campaign Against Russian Companies

In early 2025, the pro-Ukrainian cyber group Bearlyfy initiated a series of over 70 ransomware attacks targeting Russian companies. Employing custom strains like GenieLocker, Bearlyfy exploited vulnerabilities in public-facing applications to gain initial access, subsequently encrypting critical data and demanding ransoms. The group's operations have caused significant disruptions across various sectors in Russia. This incident underscores a growing trend of politically motivated cyberattacks, where hacktivist groups leverage ransomware to inflict economic damage. The Bearlyfy attacks highlight the evolving landscape of cyber threats, emphasizing the need for robust security measures to protect against both financially and ideologically driven adversaries.

5 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Apple Issues Urgent Update for 'DarkSword' Exploit in 2026
Impact· CRITICAL

Apple Issues Urgent Update for 'DarkSword' Exploit in 2026

In March 2026, Apple issued urgent lock screen notifications to users of older iPhone and iPad models, warning them of active web-based exploits targeting outdated iOS versions. The 'DarkSword' exploit, which had been used by surveillance groups, became widely accessible after its code was leaked online, enabling attackers to exfiltrate sensitive data from devices running iOS versions 18.4 to 18.7. Apple responded by releasing security updates for iOS versions 15 through 26 and advised users on older systems to upgrade immediately to mitigate the risk. ([tomsguide.com](https://www.tomsguide.com/phones/iphones/darksword-exploit-just-went-global-millions-of-iphones-now-wide-open-to-hackers?utm_source=openai)) This incident underscores the critical importance of keeping devices updated to the latest software versions. The public availability of the 'DarkSword' exploit highlights the rapid dissemination of vulnerabilities and the necessity for users to remain vigilant against emerging threats. ([techradar.com](https://www.techradar.com/phones/update-your-iphone-now-apple-issues-a-rare-warning-to-ios-users-as-a-new-hacker-threat-is-discovered?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Coruna Exploit Kit: A Case Study in the Commercialization of Nation-State Cyber Tools
Impact· HIGH

Coruna Exploit Kit: A Case Study in the Commercialization of Nation-State Cyber Tools

In February 2025, Google's Threat Intelligence Group (GTIG) identified 'Coruna,' a sophisticated iOS exploit kit comprising 23 vulnerabilities across five exploit chains, targeting devices running iOS 13 through 17.2.1. Initially deployed by a surveillance vendor for government clients, Coruna was later utilized by Russian state actors in espionage campaigns against Ukrainian users. By December 2025, the exploit kit had proliferated to financially motivated Chinese cybercriminals, who employed it to steal cryptocurrency from over 42,000 iOS devices via malicious websites. This rapid transition from state-sponsored espionage to widespread financial crime underscores the growing commercialization and accessibility of nation-state-level cyber tools. The Coruna incident highlights the urgent need for organizations to stay vigilant against advanced threats, as sophisticated exploit kits once exclusive to government entities are increasingly available to cybercriminals, posing significant risks to both individuals and enterprises.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Coruna iOS Exploit Framework: Evolution from Espionage to Cybercrime
Impact· HIGH

Coruna iOS Exploit Framework: Evolution from Espionage to Cybercrime

In 2025, the Coruna exploit kit emerged as a sophisticated tool targeting iPhones running iOS versions 13.0 through 17.2.1. Initially observed in February 2025, it was used by a surveillance vendor's client, later appearing in attacks by Russian espionage groups against Ukrainian users, and subsequently by financially motivated Chinese hackers. Coruna comprises five full iOS exploit chains leveraging 23 vulnerabilities, including CVE-2023-32434 and CVE-2023-38606, previously exploited in Operation Triangulation. The kit's evolution suggests a continuous development from earlier frameworks, now capable of compromising modern hardware, including Apple's A17 and M3 chips. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/03/03/coruna-ios-exploit-kit/?utm_source=openai)) The proliferation of Coruna underscores the escalating risk of advanced exploit kits transitioning from state-sponsored espionage to widespread cybercrime. This trend highlights the urgent need for organizations to implement robust security measures, including timely software updates and advanced threat detection systems, to mitigate the risks posed by such sophisticated tools.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
International Operation Dismantles LeakBase Cybercrime Forum in 2026
Impact· HIGH

International Operation Dismantles LeakBase Cybercrime Forum in 2026

In early March 2026, an international law enforcement operation led by the FBI and Europol dismantled LeakBase, one of the world's largest cybercrime forums. Established in 2021, LeakBase had over 142,000 members and facilitated the trade of stolen data, including account credentials and financial information. The coordinated effort spanned 14 countries, resulting in the seizure of the forum's domains and databases, as well as multiple arrests and searches targeting the platform's most active users. This operation underscores the growing global collaboration in combating cybercrime and highlights the increasing focus on dismantling platforms that facilitate the sale of stolen data. The takedown of LeakBase serves as a significant deterrent to cybercriminals and emphasizes the importance of international cooperation in addressing the evolving cyber threat landscape.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Coruna Exploit Kit: A Cautionary Tale of Advanced Hacking Tools in Cybercriminal Hands
Impact· HIGH

Coruna Exploit Kit: A Cautionary Tale of Advanced Hacking Tools in Cybercriminal Hands

In 2025, the Coruna exploit kit emerged as a sophisticated tool targeting iPhones running iOS versions 13.0 through 17.2.1. Initially deployed by a surveillance vendor for government clients, Coruna was later utilized by Russian espionage groups in attacks against Ukrainian users and by financially motivated hackers in China. The kit comprises five exploit chains and 23 vulnerabilities, including CVE-2023-32434 and CVE-2023-38606, previously exploited in Operation Triangulation. These vulnerabilities enable remote code execution and privilege escalation, granting attackers full control over affected devices. ([techcrunch.com](https://techcrunch.com/2026/03/03/a-suite-of-government-hacking-tools-targeting-iphones-is-now-being-used-by-cybercriminals/?utm_source=openai)) The proliferation of Coruna underscores the risks associated with the leakage of government-grade hacking tools into the broader cybercriminal ecosystem. This incident highlights the urgent need for organizations to implement robust security measures, promptly apply software updates, and monitor for emerging threats to protect sensitive data and maintain operational integrity. ([techcrunch.com](https://techcrunch.com/2026/03/03/a-suite-of-government-hacking-tools-targeting-iphones-is-now-being-used-by-cybercriminals/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Understanding the Coruna iOS Exploit Kit: A 2026 Security Threat
Impact· HIGH

Understanding the Coruna iOS Exploit Kit: A 2026 Security Threat

In early 2026, the Coruna iOS exploit kit emerged as a significant threat, targeting iPhones running iOS versions 13.0 through 17.2.1. This sophisticated toolkit comprises 23 exploits, including zero-day vulnerabilities, enabling attackers to execute zero-click attacks via iMessage. Initially developed for government surveillance, Coruna has since been adopted by cybercriminal groups, leading to widespread data breaches and financial losses. The kit's capabilities allow for full device compromise, granting unauthorized access to sensitive information and enabling remote control of infected devices. The proliferation of Coruna underscores the evolving landscape of mobile threats and the critical need for robust security measures to protect against advanced exploit kits. Organizations and individuals must prioritize timely software updates, implement comprehensive security protocols, and remain vigilant against emerging threats to safeguard their digital assets.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Unveiling Red Menshen's 2026 BPFDoor Espionage in Telecom Networks
Impact· HIGH

Unveiling Red Menshen's 2026 BPFDoor Espionage in Telecom Networks

In 2026, the China-linked threat actor Red Menshen, also known as Earth Bluecrow, conducted a prolonged cyber espionage campaign targeting telecommunications networks across the Middle East and Asia. Utilizing the stealthy Linux backdoor BPFDoor, the group infiltrated critical infrastructure, including Home Subscriber Servers (HSS), to exfiltrate sensitive subscriber data. BPFDoor's advanced evasion techniques allowed it to bypass traditional security measures, enabling Red Menshen to maintain persistent access and conduct surveillance undetected for extended periods. This incident underscores the increasing sophistication of nation-state cyber threats targeting telecom infrastructure. The use of kernel-level implants and passive backdoors like BPFDoor highlights the need for enhanced detection capabilities and proactive security measures to protect critical communication networks from such covert operations.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Unveiling the Scarlet Goldfinch 2025 ClickFix Malware Campaign
Impact· MEDIUM

Unveiling the Scarlet Goldfinch 2025 ClickFix Malware Campaign

In 2025, the Scarlet Goldfinch threat actor launched a sophisticated malware campaign utilizing the ClickFix social engineering technique. This method deceived users into executing malicious commands under the guise of routine system verifications, leading to the installation of NetSupport Manager, a remote access tool. The campaign primarily targeted Windows systems, exploiting compromised websites to display fake browser update prompts, which, when acted upon, initiated the malware download and execution process. ([redcanary.com](https://redcanary.com/threat-detection-report/threats/scarlet-goldfinch/?utm_source=openai)) The significance of this incident lies in the evolution of social engineering tactics, highlighting the increasing sophistication of threat actors in bypassing traditional security measures. The widespread use of ClickFix underscores the necessity for enhanced user education and the implementation of robust security protocols to mitigate such deceptive attack vectors.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
OpenCode Systems 2026 Access Control Vulnerability Exposes SMS Messages
Impact· HIGH

OpenCode Systems 2026 Access Control Vulnerability Exposes SMS Messages

In March 2026, a significant security vulnerability (CVE-2025-70614) was identified in OpenCode Systems' OC Messaging and USSD Gateway version 6.32.2. This flaw allowed authenticated users with low privileges to access SMS messages beyond their authorized scope by manipulating company or tenant identifier parameters. The vulnerability posed a substantial risk to data confidentiality across multi-tenant environments. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2025-70614/?utm_source=openai)) The incident underscores the critical importance of robust access control mechanisms in multi-tenant systems. Organizations are urged to review and strengthen their access control policies to prevent similar vulnerabilities and protect sensitive information.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Authentication Bypass Vulnerability in TP-Link Routers Exposes Networks to Attack
Impact· HIGH

Critical Authentication Bypass Vulnerability in TP-Link Routers Exposes Networks to Attack

In March 2026, TP-Link disclosed a critical authentication bypass vulnerability (CVE-2026-0834) affecting Archer C20 v6.0 and Archer AX53 v1.0 routers. This flaw resides in the TP-Link Device Debug Protocol (TDDP) module, allowing unauthenticated attackers on the same network to execute administrative commands, such as factory resets and reboots, without credentials. Exploitation of this vulnerability can lead to complete configuration loss and service disruption. This incident underscores the persistent risks associated with network infrastructure vulnerabilities, particularly in consumer-grade routers. The exploitation of such flaws can facilitate broader cyberattacks, including the formation of botnets and unauthorized access to sensitive information. Organizations and individuals must prioritize timely firmware updates and implement robust network security measures to mitigate these risks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Red Menshen's BPFDoor Malware: A 2026 Telecom Security Wake-Up Call
Impact· CRITICAL

Red Menshen's BPFDoor Malware: A 2026 Telecom Security Wake-Up Call

In early 2026, the Chinese state-sponsored Advanced Persistent Threat (APT) group known as Red Menshen executed a sophisticated cyber-espionage campaign targeting telecommunications providers across multiple regions, including South America and Southeast Asia. Utilizing an advanced variant of their BPFDoor malware, the attackers exploited vulnerabilities in edge network devices to gain initial access. Once inside, they deployed custom Linux-based implants to establish persistent backdoors, enabling them to conduct extensive reconnaissance and exfiltrate sensitive subscriber data over an extended period. The stealthy nature of BPFDoor allowed the attackers to bypass traditional security measures, remaining undetected for months. This breach underscores the evolving tactics of nation-state actors in targeting critical infrastructure sectors, particularly telecommunications, to gather intelligence and potentially disrupt services. The incident highlights the urgent need for enhanced security measures, including robust monitoring of network edge devices and the implementation of advanced threat detection systems to identify and mitigate such sophisticated attacks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports