Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Interlock Ransomware's Exploitation of Cisco Firewall Vulnerabilities
In late 2025, the Interlock ransomware group exploited a critical vulnerability in Cisco's Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices, identified as CVE-2025-20333. This buffer overflow flaw allowed unauthenticated remote code execution, enabling attackers to gain full control over affected devices. The exploitation led to significant data breaches and operational disruptions across multiple organizations. Despite Cisco's prompt release of patches, many systems remained unpatched, leaving them vulnerable to attacks. ([techradar.com](https://www.techradar.com/pro/security/around-50-000-cisco-firewalls-are-vulnerable-to-attack-so-patch-now?utm_source=openai)) This incident underscores the persistent threat posed by ransomware groups targeting network infrastructure vulnerabilities. It highlights the critical importance of timely patch management and robust security practices to mitigate such risks.
6 months ago
Kill Chain
CISA Highlights Five Actively Exploited Vulnerabilities in March 2026
In March 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. These include CVE-2025-31277 and CVE-2025-43520, both affecting Apple products with buffer overflow vulnerabilities that could lead to arbitrary code execution. CVE-2025-32432 pertains to Craft CMS, allowing code injection through improper input validation. CVE-2025-43510, another Apple-related issue, involves improper locking, potentially causing unexpected memory changes. Lastly, CVE-2025-54068 affects Laravel Livewire, enabling arbitrary code injection via the component hydration process. The inclusion of these vulnerabilities underscores the persistent threat posed by unpatched software. Organizations are urged to prioritize remediation to mitigate risks associated with these actively exploited flaws. This action aligns with CISA's Binding Operational Directive 22-01, emphasizing the importance of addressing known vulnerabilities to protect federal networks and urging all organizations to adopt similar practices.
6 months ago
Kill Chain
Critical Vulnerability in Cisco Secure Firewall Management Center: CVE-2026-20131
In March 2026, a critical vulnerability (CVE-2026-20131) was identified in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. This flaw allows unauthenticated, remote attackers to execute arbitrary Java code as root by exploiting insecure deserialization of user-supplied Java byte streams. Successful exploitation could lead to full system compromise, granting attackers complete control over affected devices. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh?utm_source=openai)) The vulnerability underscores the persistent risks associated with deserialization flaws in network management systems. Organizations are urged to apply Cisco's security patches promptly and restrict public internet access to FMC management interfaces to mitigate potential exploitation. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh?utm_source=openai))
6 months ago
Kill Chain
EDR Killer Malware Exploits Vulnerable Drivers to Disable Security Tools
In early February 2026, threat actors exploited compromised SonicWall SSLVPN credentials to infiltrate a corporate network. Once inside, they deployed a custom 'EDR killer' malware that utilized a signed but revoked EnCase forensic driver to disable 59 endpoint detection and response (EDR) and antivirus tools. This 'Bring Your Own Vulnerable Driver' (BYOVD) technique allowed attackers to gain kernel-level access, effectively neutralizing security defenses and facilitating further malicious activities. The intrusion was disrupted before ransomware deployment, but it underscores the growing trend of adversaries weaponizing legitimate drivers to bypass endpoint security measures. ([huntress.com](https://www.huntress.com/blog/encase-byovd-edr-killer?utm_source=openai)) This incident highlights the critical need for organizations to enforce multi-factor authentication (MFA) on VPN access, regularly update and monitor security tools, and implement strict controls over driver installations to prevent the exploitation of vulnerable drivers. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/05/edr-killer-vulnerable-encase-driver/?utm_source=openai))
6 months ago
Kill Chain
Schneider Electric's 2026 Hard-Coded Credentials Vulnerability: What You Need to Know
In March 2026, Schneider Electric disclosed a critical vulnerability in its EcoStruxure IT Data Center Expert software, identified as CVE-2025-13957. This flaw involves hard-coded credentials that, if exploited, could lead to information disclosure and remote code execution, particularly when the SOCKS Proxy feature is enabled. The affected versions include EcoStruxure IT Data Center Expert v9.0 and prior. Schneider Electric has released version 9.1 to address this issue and recommends users update promptly to mitigate potential risks. ([cyber.gc.ca](https://www.cyber.gc.ca/en/alerts-advisories/control-systems-schneider-electric-security-advisory-av26-210?utm_source=openai)) This incident underscores the persistent threat posed by hard-coded credentials in critical infrastructure software. Organizations are urged to review their systems for similar vulnerabilities and implement robust credential management practices to prevent unauthorized access and potential operational disruptions.
6 months ago
Kill Chain
Siemens SICAM SIAPP SDK Vulnerabilities: What You Need to Know
In March 2026, Siemens disclosed multiple vulnerabilities in its SICAM SIAPP SDK versions prior to 2.1.7. These vulnerabilities include out-of-bounds write, stack-based buffer overflow, improper handling of length parameter inconsistency, and external control of file name or path. Exploitation could lead to denial of service, data corruption, or arbitrary code execution. Siemens has released version 2.1.7 to address these issues and recommends users update promptly. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-903736.html?utm_source=openai)) This incident underscores the critical importance of timely software updates and robust input validation in industrial control systems to prevent potential exploitation and ensure operational integrity.
6 months ago
Kill Chain
Interlock Ransomware's 2026 Exploitation of Cisco Firewall Vulnerability
In early 2026, the Interlock ransomware group exploited a zero-day vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC) Software, allowing unauthenticated remote code execution as root. This critical flaw, due to insecure deserialization of user-supplied Java byte streams, enabled attackers to gain full control over affected devices. The exploitation began on January 26, 2026, 36 days prior to Cisco's public disclosure on March 4, 2026. Interlock's campaign involved deploying custom remote access trojans, reconnaissance scripts, and evasion techniques, leading to significant operational disruptions for targeted organizations. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh?utm_source=openai)) This incident underscores the persistent threat posed by ransomware groups leveraging zero-day vulnerabilities. Organizations must prioritize timely patching, implement defense-in-depth strategies, and maintain continuous threat monitoring to mitigate such risks.
6 months ago
Kill Chain
DarkSword iOS Exploit Kit: A New Threat in 2026
In early 2026, cybersecurity researchers discovered 'DarkSword,' an advanced iOS exploit kit attributed to Russian hackers. This toolkit repurposes vulnerabilities believed to have been originally developed by the U.S. government. DarkSword targets iOS devices through sophisticated attack chains, enabling unauthorized access to sensitive user data, including messages, passwords, and cryptocurrency wallets. The exploit kit has been deployed in espionage campaigns against individuals in Ukraine, Saudi Arabia, Turkey, and Malaysia, affecting potentially millions of iPhone users worldwide. The emergence of DarkSword underscores the escalating trend of nation-state actors leveraging leaked or repurposed cyber tools to conduct widespread surveillance and financial theft. This incident highlights the critical need for robust cybersecurity measures and timely software updates to mitigate the risks posed by such sophisticated threats.
6 months ago
Kill Chain
LeakNet Ransomware's Innovative Use of ClickFix and Deno Runtime in 2026 Attacks
In March 2026, the LeakNet ransomware group initiated a sophisticated attack campaign leveraging the ClickFix social engineering technique and the Deno JavaScript runtime. By presenting fake prompts, they tricked users into executing malicious commands, leading to the deployment of a Deno-based loader that executed JavaScript payloads directly in system memory. This method minimized forensic evidence and enhanced evasion of traditional security measures. The adoption of legitimate tools like Deno for malicious purposes underscores a growing trend among threat actors to evade detection. Organizations must remain vigilant against such evolving tactics, emphasizing the need for comprehensive security awareness training and advanced threat detection mechanisms.
6 months ago
Kill Chain
EU Sanctions Chinese and Iranian Firms for Cyberattacks in 2026
In March 2026, the European Union imposed sanctions on three companies—two Chinese and one Iranian—and two individuals for their involvement in cyberattacks targeting devices and critical infrastructure across multiple EU member states. Integrity Technology Group, a Beijing-based firm, provided technical support that led to the compromise of over 65,000 devices between 2022 and 2023. Anxun Information Technology, also from China, offered hacking services aimed at critical infrastructure. The Iranian company, Emennet Pasargad, was implicated in influence campaigns and the compromise of an SMS service in Sweden. The two sanctioned individuals are co-founders of Anxun Information Technology, believed to have played significant roles in these cyberattacks. This action underscores the EU's commitment to addressing state-sponsored cyber threats and protecting its member states' critical infrastructure. The sanctions include asset freezes and travel bans, reflecting the severity of the offenses and the EU's resolve to deter future cyberattacks.
6 months ago
Kill Chain
Critical Wing FTP Server Vulnerability Exploited: Immediate Action Required
In July 2025, a critical vulnerability (CVE-2025-47812) was discovered in Wing FTP Server, allowing unauthenticated attackers to execute arbitrary Lua code via null byte injection in the username parameter. This flaw enables remote code execution with elevated privileges, potentially leading to full system compromise. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on July 14, 2025, with a remediation deadline of August 4, 2025. Organizations are urged to update to Wing FTP Server version 7.4.4 or later to mitigate this risk. ([gbhackers.com](https://gbhackers.com/cisa-issues-alert-on-wing-ftp-server-vulnerability/?utm_source=openai)) The active exploitation of this vulnerability underscores the persistent threat posed by unpatched software vulnerabilities. It highlights the importance of timely patch management and continuous monitoring to prevent potential system compromises and data breaches.
6 months ago
Kill Chain
Konni's 2026 Phishing Attack Deploys AI-Generated EndRAT via KakaoTalk
In early 2026, the North Korean state-sponsored hacking group Konni launched a sophisticated phishing campaign targeting blockchain developers in Japan, Australia, and India. The attackers utilized AI-generated PowerShell malware, delivered through malicious emails disguised as financial notices. These emails contained ZIP files with Windows shortcuts that executed embedded PowerShell loaders, leading to the deployment of the EndRAT backdoor. This malware enabled the attackers to establish persistence, evade detection, and gain unauthorized access to development environments, potentially compromising sensitive blockchain-related resources and infrastructure. This incident underscores a significant evolution in cyber threat tactics, highlighting the increasing use of artificial intelligence by threat actors to enhance the sophistication and effectiveness of their attacks. The targeting of blockchain developers indicates a strategic shift towards compromising emerging financial technologies, emphasizing the need for heightened vigilance and advanced security measures within the industry.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports