Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Critical Authentication Bypass Vulnerability Discovered in pac4j-jwt Java Library
In March 2026, a critical authentication bypass vulnerability (CVE-2026-29000) was discovered in the pac4j-jwt Java library, affecting versions prior to 4.5.9, 5.7.9, and 6.3.3. This flaw allows remote attackers to forge authentication tokens by exploiting improper verification of cryptographic signatures in the JwtAuthenticator component when processing encrypted JSON Web Tokens (JWTs). By crafting a JWE-wrapped PlainJWT with arbitrary subject and role claims, attackers can bypass signature verification and authenticate as any user, including administrators. ([arcticwolf.com](https://arcticwolf.com/resources/blog/cve-2026-29000/?utm_source=openai)) The vulnerability poses a significant risk due to the widespread use of pac4j-jwt in various Java applications and frameworks. Organizations utilizing affected versions are urged to upgrade to the latest fixed releases immediately to mitigate potential exploitation. ([arcticwolf.com](https://arcticwolf.com/resources/blog/cve-2026-29000/?utm_source=openai))
6 months ago
Kill Chain
Microsoft's March 2026 Patch Tuesday: Addressing 83 Vulnerabilities, Including Two Publicly Disclosed Zero-Days
In March 2026, Microsoft released its Patch Tuesday updates, addressing 83 vulnerabilities across its software portfolio, including Windows, Office, SQL Server, Azure, and .NET. Notably, this release included two publicly disclosed zero-day vulnerabilities: CVE-2026-21262, an elevation of privilege flaw in Microsoft SQL Server, and CVE-2026-26127, a denial-of-service vulnerability in .NET. Additionally, six vulnerabilities were identified as more likely to be exploited, emphasizing the importance of timely patch application. This update marks the first in six months without any actively exploited zero-day vulnerabilities, indicating a positive trend in Microsoft's vulnerability management efforts. ([cyberscoop.com](https://cyberscoop.com/microsoft-patch-tuesday-march-2026/?utm_source=openai)) The absence of actively exploited zero-day vulnerabilities in this release suggests improved security measures and proactive patching strategies. However, the presence of publicly disclosed vulnerabilities underscores the need for organizations to remain vigilant and prioritize the deployment of these updates to mitigate potential risks.
6 months ago
Kill Chain
APT28's Exploitation of Microsoft Office Vulnerability: A Deep Dive
In early 2026, the Russian state-sponsored hacking group APT28, also known as Fancy Bear, exploited a newly disclosed Microsoft Office vulnerability (CVE-2026-21509) to target Ukrainian government agencies. The attackers distributed malicious documents via phishing emails, leading to the deployment of the COVENANT malware framework and the BEARDSHELL backdoor, facilitating long-term surveillance and data exfiltration. This campaign underscores the rapid weaponization of zero-day vulnerabilities by nation-state actors and highlights the persistent cyber threats facing governmental institutions. Organizations are urged to promptly apply security patches and enhance their cybersecurity measures to mitigate such sophisticated attacks.
6 months ago
Kill Chain
Critical Ivanti EPM Vulnerability Exploited: Immediate Action Required
In February 2026, a critical authentication bypass vulnerability (CVE-2026-1603) was identified in Ivanti Endpoint Manager (EPM) versions prior to 2024 SU5. This flaw allows remote, unauthenticated attackers to access stored credential data by exploiting improper authentication mechanisms, specifically through malformed header concatenation in the WSAuth.dll component. Successful exploitation enables attackers to retrieve encrypted credential blobs for high-privilege accounts, potentially compromising the entire endpoint management trust model and facilitating lateral movement within networks. ([dbugs.ptsecurity.com](https://dbugs.ptsecurity.com/vulnerability/CVE-2026-1603?utm_source=openai)) The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-1603 to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation in the wild. Organizations are urged to upgrade to Ivanti EPM 2024 SU5 immediately to mitigate this risk. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-recently-patched-ivanti-epm-flaw-now-actively-exploited/?utm_source=openai))
6 months ago
Kill Chain
Microsoft's March 2026 Patch Tuesday: Addressing Critical Zero-Day Vulnerabilities
In March 2026, Microsoft released its Patch Tuesday updates, addressing 79 vulnerabilities across various products, including Windows, Office, Azure, SQL Server, and .NET. Notably, two zero-day vulnerabilities were publicly disclosed prior to the release: CVE-2026-21262, an elevation of privilege flaw in SQL Server, and CVE-2026-26127, a denial-of-service vulnerability in .NET. While these vulnerabilities were publicly known, there was no evidence of active exploitation at the time of the update. Organizations are advised to prioritize patching these vulnerabilities to mitigate potential risks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/microsoft/microsoft-march-2026-patch-tuesday-fixes-2-zero-days-79-flaws/?utm_source=openai)) The disclosure of these zero-day vulnerabilities underscores the critical importance of timely patch management. Even in the absence of active exploitation, publicly known vulnerabilities can quickly become targets for cybercriminals. This incident highlights the need for organizations to maintain robust vulnerability management practices to protect their systems and data.
6 months ago
Kill Chain
CISA Adds SolarWinds, Ivanti, and Workspace One Vulnerabilities to KEV Catalog
In March 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. These include CVE-2021-22054, a server-side request forgery in Omnissa Workspace One UEM; CVE-2025-26399, a deserialization flaw in SolarWinds Web Help Desk; and CVE-2026-1603, an authentication bypass in Ivanti Endpoint Manager. Exploitation of these vulnerabilities allows unauthorized access to sensitive information and remote code execution on affected systems. ([thehackernews.com](https://thehackernews.com/2026/03/cisa-flags-solarwinds-ivanti-and.html?utm_source=openai)) The inclusion of these vulnerabilities in the KEV catalog underscores the persistent threat posed by unpatched software flaws. Organizations are urged to apply the necessary patches promptly to mitigate potential risks associated with these actively exploited vulnerabilities.
6 months ago
Kill Chain
BeatBanker: The Dual-Mode Android Malware Threatening Brazilian Users in 2026
In March 2026, cybersecurity researchers identified 'BeatBanker,' a sophisticated Android malware campaign targeting users in Brazil. Disguised as legitimate applications, including a fake Google Play Store and a counterfeit Starlink app, BeatBanker employs phishing tactics to infiltrate devices. Once installed, it operates as both a cryptocurrency miner and a banking Trojan, enabling attackers to hijack devices, steal financial credentials, and manipulate cryptocurrency transactions. Notably, the malware maintains persistence by continuously playing an inaudible audio file, preventing system termination. The campaign has evolved to deploy the BTMOB remote administration tool, granting attackers full control over compromised devices. This incident underscores the escalating complexity of mobile malware threats and the critical need for users to download apps exclusively from official sources, scrutinize app permissions, and keep their systems updated to mitigate such risks.
6 months ago
Kill Chain
Microsoft SharePoint 2025 ToolShell Zero-Day Exploitation
In July 2025, a critical zero-day vulnerability, CVE-2025-53770, was discovered in Microsoft SharePoint, allowing unauthenticated remote code execution. Dubbed 'ToolShell,' this exploit enabled attackers to gain full control over affected servers, leading to data exfiltration and deployment of ransomware. The vulnerability stemmed from an incomplete fix of a 2020 issue, CVE-2020-1147, and was actively exploited by Chinese state-affiliated groups, including Storm-2603, Linen Typhoon, and Violet Typhoon. Over 400 organizations worldwide, including U.S. federal agencies and the National Nuclear Security Administration, were compromised. Microsoft released emergency patches for SharePoint Server 2019 and SharePoint Subscription Edition, but SharePoint Enterprise Server 2016 remained unpatched at the time. Organizations were urged to apply patches, rotate machine keys, and implement additional security measures to mitigate the threat. ([windowscentral.com](https://www.windowscentral.com/software-apps/were-witnessing-an-urgent-and-active-threat-microsoft-sharepoint-toolshell-vulnerability-is-being-attacked-globally?utm_source=openai)) This incident underscores the escalating risk of zero-day vulnerabilities and the rapid exploitation timelines by sophisticated threat actors. The 'ToolShell' attacks highlight the critical need for organizations to maintain vigilant patch management, continuous monitoring, and robust incident response strategies to defend against evolving cyber threats.
6 months ago
Kill Chain
APT28's Stealthy Cyber-Espionage Tactics Target Ukrainian Military in 2026
In April 2024, the Russian state-sponsored hacking group APT28 initiated a cyber-espionage campaign targeting Ukrainian military personnel. Utilizing spear-phishing messages sent via the Signal messaging app, attackers distributed malicious Microsoft Word documents embedded with macros. Once enabled, these macros triggered a multi-stage infection chain, deploying the COVENANT framework and the BEARDSHELL backdoor. The malware leveraged legitimate cloud services like Icedrive and Koofr for command-and-control communications, facilitating long-term surveillance and data exfiltration. ([thehackernews.com](https://thehackernews.com/2026/03/apt28-uses-beardshell-and-covenant.html?utm_source=openai)) This incident underscores the evolving tactics of state-sponsored actors, who increasingly exploit trusted platforms and sophisticated obfuscation techniques to evade detection. The use of legitimate cloud services for command-and-control highlights the challenges in distinguishing malicious activity from normal network traffic, emphasizing the need for advanced threat detection mechanisms. ([scworld.com](https://www.scworld.com/news/fancy-bear-attacks-abuse-office-macros-legitimate-cloud-services?utm_source=openai))
6 months ago
Kill Chain
LeakyLooker Vulnerabilities: A Wake-Up Call for Cloud Security
In March 2026, Tenable Research disclosed nine critical cross-tenant vulnerabilities, collectively termed 'LeakyLooker,' in Google Looker Studio. These flaws allowed attackers to execute arbitrary SQL queries on victims' databases, leading to potential data exfiltration, insertion, and deletion across Google Cloud Platform (GCP) services. The vulnerabilities affected organizations utilizing connectors such as Google Sheets, BigQuery, Spanner, PostgreSQL, MySQL, and Cloud Storage. Google addressed these issues following responsible disclosure in June 2025. The 'LeakyLooker' vulnerabilities underscore the evolving threat landscape in cloud environments, highlighting the necessity for robust security measures and continuous monitoring. Organizations must remain vigilant against cross-tenant vulnerabilities to safeguard sensitive data and maintain compliance with industry standards.
6 months ago
Kill Chain
FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials
In early 2026, threat actors exploited vulnerabilities and weak credentials in FortiGate Next-Generation Firewall (NGFW) appliances to breach networks across healthcare, government, and managed service providers. By accessing these devices, attackers extracted configuration files containing service account credentials and network topology information, enabling unauthorized access to Active Directory environments and the enrollment of rogue workstations. The breaches were detected during lateral movement phases, preventing further escalation. ([sentinelone.com](https://www.sentinelone.com/blog/fortigate-edge-intrusions/?utm_source=openai)) This incident underscores the critical importance of securing network infrastructure devices, as their compromise can lead to significant data breaches and operational disruptions. The exploitation of such devices highlights the evolving tactics of threat actors targeting essential security appliances to gain deeper access into organizational networks. ([sentinelone.com](https://www.sentinelone.com/blog/fortigate-edge-intrusions/?utm_source=openai))
6 months ago
Kill Chain
CISA Adds Three Known Exploited Vulnerabilities to Catalog
On March 9, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. These vulnerabilities include CVE-2021-22054, a Server-Side Request Forgery (SSRF) in VMware Workspace ONE UEM; CVE-2025-26399, an unauthenticated deserialization flaw in SolarWinds Web Help Desk's AjaxProxy component; and CVE-2026-1603, an authentication bypass in Ivanti Endpoint Manager (EPM). Each of these flaws presents significant risks, such as unauthorized access, remote code execution, and credential disclosure, potentially leading to full enterprise compromise. The inclusion of these vulnerabilities in the KEV Catalog underscores the persistent threat posed by unpatched software. Organizations are urged to prioritize remediation efforts to mitigate the risks associated with these actively exploited vulnerabilities.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports