Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2818 threat reports
Page 14 of 235

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Government Administration Threat Reports

Showing 157168 / 2818 reports
Thomson Reuters C-Track Breach: When Court System Security Fails
Impact· HIGH

Thomson Reuters C-Track Breach: When Court System Security Fails

In March 2026, an unauthorized party accessed Thomson Reuters' C-Track court case management platform, exposing sensitive data from courts across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. The breach, discovered on June 30, 2026, compromised backup files containing Social Security numbers, driver's license numbers, medical information, and sealed court documents. The unauthorized access persisted for nearly four months, affecting critical judicial systems that handle confidential legal proceedings and personal data of court users. This incident highlights the growing threat to government and legal infrastructure, particularly as courts increasingly rely on cloud-based case management systems. With ransomware groups actively targeting government entities and judicial systems becoming prime targets for data theft, this breach underscores the urgent need for enhanced security controls around privileged data access and cloud backup environments.

2 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Cisco Nexus 9000 Vulnerability Exposes Network Infrastructure to Root-Level Compromise
Impact· CRITICAL

Critical Cisco Nexus 9000 Vulnerability Exposes Network Infrastructure to Root-Level Compromise

In September 2026, Cisco disclosed CVE-2026-20212, a critical vulnerability with a CVSS score of 9.8 affecting Silicon One-based Nexus 9000 switches. The flaw stems from binding to unrestricted IP addresses, exposing TCP ports 43210 and 43211 in the default Layer 3 VRF instance. Unauthenticated remote attackers can exploit this vulnerability to execute arbitrary code with root privileges by sending crafted input to the exposed service, potentially causing device crashes and complete system compromise across affected enterprise network infrastructure. This incident highlights the accelerating threat landscape where AI-powered vulnerability discovery is shrinking the window between disclosure and exploitation. With critical network infrastructure increasingly targeted by nation-state actors like the China-nexus Fire Ant group, organizations face urgent pressure to implement comprehensive network segmentation and zero-trust controls.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
AI-Powered Cyber Threats Surge in H1 2026: 215 Exploited Vulnerabilities Signal New Attack Era
Impact· LOW

AI-Powered Cyber Threats Surge in H1 2026: 215 Exploited Vulnerabilities Signal New Attack Era

The first half of 2026 witnessed a 34% surge in actively exploited vulnerabilities, reaching 215 CVEs compared to 161 in H1 2025. Threat actors increasingly leveraged AI-enabled capabilities to enhance traditional attack methods, with malware like PromptSpy using generative AI for improved persistence and CANFAIL employing LLM-generated decoy logic. Microsoft remained the most targeted vendor with 40 exploited CVEs, while attackers focused on network-accessible vulnerabilities requiring no authentication. The campaign demonstrated how adversaries are blending malicious activities with legitimate tools and trusted services, making detection significantly more challenging. This trend represents a critical evolution in cyber warfare where AI augments rather than replaces established intrusion techniques. Organizations face compressed remediation timelines as AI-assisted vulnerability research accelerates exploit development, while attackers abuse trusted platforms and routine workflows to evade detection systems designed for traditional threat patterns.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
AWS CloudTrail Forensics: Defending Against Cross-Account Attacks and Crypto Mining
Impact· HIGH

AWS CloudTrail Forensics: Defending Against Cross-Account Attacks and Crypto Mining

AWS released a comprehensive incident response guide demonstrating two critical attack scenarios affecting cloud environments in 2025. The first scenario involves a cross-account S3 data deletion attack where threat actors assumed roles from trusted accounts, performed reconnaissance through ListBuckets operations, and executed scripted deletions of financial reports, PII databases, and production backups within a 13-second window. The second scenario showcases cryptocurrency mining operations deployed through AWS CloudFormation, where attackers leveraged console credentials without MFA to create the 'CRYPTO' stack containing EC2 instances for mining operations. Both incidents highlight the sophistication of modern cloud-native attacks that exploit legitimate AWS services and cross-account trust relationships. These attack patterns are increasingly relevant as organizations accelerate cloud adoption while struggling with proper access controls, zero trust implementation, and multi-cloud visibility. The incidents underscore the critical need for enhanced CloudTrail monitoring, cross-account access reviews, and comprehensive egress security policies.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Multi-Stage AWS Attack: From SSRF to Unauthorized AI Model Access
Impact· MEDIUM

Multi-Stage AWS Attack: From SSRF to Unauthorized AI Model Access

A sophisticated multi-stage attack demonstrated how web application vulnerabilities can cascade into unauthorized AI service access across AWS regions. The incident began with a Server-Side Request Forgery (SSRF) vulnerability in a web application that allowed attackers to exploit IMDSv1 endpoints and harvest temporary AWS credentials from an EC2 instance's webdev role. Using these compromised credentials, the threat actor conducted permission boundary testing, established console access without MFA, and ultimately pivoted to Amazon Bedrock services across multiple regions, successfully invoking AI models and consuming computational resources. This attack chain highlights critical gaps in cloud security architecture, particularly the dangerous combination of overprivileged IAM roles, legacy metadata service configurations, and inconsistent cross-region security controls that enabled lateral movement from a simple web vulnerability to unauthorized AI infrastructure access.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Massive Identity Verification Breach: 153M Driver's Licenses Compromised at IDScan.net
Impact· CRITICAL

Massive Identity Verification Breach: 153M Driver's Licenses Compromised at IDScan.net

In September 2026, a new identity theft service called Nexus launched on the dark web selling digital scans of over 153 million drivers licenses from the United States and Canada. The breach appears to originate from Louisiana-based identity verification company IDScan.net, which provides services to major clients including Hertz, Target, FedEx, and numerous marijuana dispensaries. The stolen data includes infrared and ultraviolet scans with timestamps indicating continuous exfiltration over more than a year, prompting an FBI investigation by the New Orleans field office. This massive identity document breach represents one of the largest exposures of state-issued identification data in U.S. history, with attackers offering licenses of high-profile government officials including Defense Secretary Pete Hegseth and FBI leadership. The incident highlights critical vulnerabilities in third-party identity verification systems that process over 21 million verifications monthly across 20,000 locations worldwide.

2 weeks ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
The AI Vulnerability Surge: Why 2026's 'Vulnpocalypse' May Be More Manageable Than Expected
Impact· MEDIUM

The AI Vulnerability Surge: Why 2026's 'Vulnpocalypse' May Be More Manageable Than Expected

New research from Echo analyzing nearly 40,000 CVE lifecycles reveals that while AI tools like Anthropic's Claude Mythos have dramatically accelerated vulnerability discovery, the anticipated 'Vulnpocalypse' may be more manageable than feared. Monthly CVE disclosures surged 145% from June 2024 to June 2026, rising from 3,173 to 7,765, with AI enabling exploit development in under one day for less than $2,000. However, fewer than 10% of AI-discovered vulnerabilities receive external validation, and most critical ratings are downgraded upon review. The study found that 89% of examined vulnerabilities already have fixes available, but 40% remain unpatched for over six months due to deployment challenges rather than fix availability. Organizations can better manage this surge by focusing on rapid validation, intelligent prioritization, and automated remediation processes rather than completely overhauling their vulnerability management programs.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(low)
Read Report
The AI Cybercrime Revolution: How Artificial Intelligence Tilts the Playing Field Toward Attackers
Impact· HIGH

The AI Cybercrime Revolution: How Artificial Intelligence Tilts the Playing Field Toward Attackers

In 2026, artificial intelligence is fundamentally transforming the cybercrime landscape by dramatically compressing attack timelines and lowering entry barriers for threat actors. Former cybercriminal Brett Johnson, known as the 'original Internet Godfather' by the US Secret Service, demonstrated at Black Hat USA how AI enables attackers to conduct reconnaissance, identify crown jewels, and execute attacks in significantly reduced timeframes. While defenders still operate reactively, AI empowers criminals to automate target research, vulnerability discovery, and even ransomware development without requiring advanced technical skills. This shift is driving more attackers toward critical infrastructure targets like hospitals and schools, where higher payouts justify the risks. The technology's learning-based nature means it benefits attackers more than defenders, as it must observe successful attacks to improve, creating an inherent advantage for malicious actors in the current threat landscape.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Breeze Comet Cybercrime Group: Direct Manipulation of Global Financial Payment Systems
Impact· HIGH

Breeze Comet Cybercrime Group: Direct Manipulation of Global Financial Payment Systems

Breeze Comet (formerly UNC5669) represents Brazil's most sophisticated cybercrime group, systematically infiltrating financial institutions across Brazil and expanding globally since 2024. The group employs advanced tactics including insider recruitment, physical network access via rogue hardware, and exploitation of compromised government websites as trusted attack vectors. Using custom malware like CobaltSpin, RealBreeze, and KickPlate, they penetrate segmented financial networks to directly manipulate payment systems including Brazil's Pix instant payment platform, executing hundreds of fraudulent transactions worth tens of thousands of dollars within 24-48 hours of system compromise. This incident highlights the evolution of financially-motivated cybercrime from traditional ransomware and fraud schemes to direct payment system manipulation. As instant payment systems proliferate globally and threat actors increasingly leverage AI for malware development, Breeze Comet's successful model poses significant risks to financial infrastructure worldwide, particularly in regions with similar digital payment architectures.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical SonicWall SMA 1000 Zero-Days Under Active Exploitation: CVE-2026-83548 & CVE-2026-83549
Impact· CRITICAL

Critical SonicWall SMA 1000 Zero-Days Under Active Exploitation: CVE-2026-83548 & CVE-2026-83549

In September 2026, attackers began actively exploiting two zero-day vulnerabilities in SonicWall SMA 1000 perimeter devices, enabling unauthenticated remote code execution. CVE-2026-83548, a critical SSRF vulnerability with a CVSS score of 10.0, allows unauthorized access through an unintended alternate access path, while CVE-2026-83549 enables OS command injection. When chained together, these flaws provide complete system compromise of affected appliances running versions 12.4.3-03453/12.5.0-02835 and older. SonicWall confirmed ongoing exploitation and urged immediate patching to versions 12.4.3-03526/12.5.0-02952 or higher. This incident highlights the continued targeting of edge security devices as initial compromise vectors, following a pattern of sophisticated zero-day attacks against network perimeter appliances throughout 2026, emphasizing the critical need for rapid patch management and network segmentation strategies.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
FalconFlank Zero-Day Targets CrowdStrike Falcon: When EDR Becomes the Attack Vector
Impact· MEDIUM

FalconFlank Zero-Day Targets CrowdStrike Falcon: When EDR Becomes the Attack Vector

In September 2026, security researcher Chaotic Eclipse released FalconFlank, a zero-day privilege escalation exploit targeting CrowdStrike Falcon endpoint security software. The vulnerability abuses office malicious macros remediation functionality within Falcon Sensor to achieve privilege escalation on fully updated Windows 11 25H2 and Windows Server 2025 systems. This disclosure follows the researcher's pattern of releasing proof-of-concept exploits for major endpoint security products, including recent vulnerabilities in Kaspersky and Microsoft Defender, highlighting systemic weaknesses in endpoint protection platforms. This incident underscores the growing trend of security researchers targeting endpoint detection and response (EDR) solutions themselves, exposing critical trust assumptions in enterprise security architectures and forcing organizations to reconsider their defense-in-depth strategies.

2 weeks ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Serbian Student Activists Targeted by Pegasus Zero-Click Spyware Campaign
Impact· HIGH

Serbian Student Activists Targeted by Pegasus Zero-Click Spyware Campaign

In December 2025 through January 2026, NSO Group's Pegasus spyware infected the iPhone of a Serbian student protest movement member using a zero-click iMessage exploit. The attack was part of a broader surveillance campaign targeting at least 14 Serbian activists, opposition politicians, and student leaders coinciding with March 2026 local elections. Citizen Lab and SHARE Foundation confirmed the infection, while a separate incident involved NoviSpy Android malware deployed during police detention of another student activist. This incident highlights the escalating use of commercial spyware against civil society, particularly as authoritarian governments increasingly weaponize surveillance technology to suppress political dissent and monitor opposition movements ahead of critical elections.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports