Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Spain Arrests Anonymous Fénix Hacktivists for DDoS Attacks
In February 2026, Spanish authorities arrested four members of the hacktivist group 'Anonymous Fénix' for orchestrating distributed denial-of-service (DDoS) attacks against government ministries, political parties, and public institutions. The group initiated its activities in April 2023, intensifying efforts after the October 2024 DANA storm in Valencia, which resulted in significant casualties and damage. They utilized social media platforms like X and Telegram to disseminate anti-government messages and recruit participants for their cyber campaigns. The arrests, conducted in May 2025 and February 2026 across various Spanish cities, led to the judicial seizure of the group's online accounts and the closure of their communication channels. ([web.guardiacivil.es](https://web.guardiacivil.es/en/destacados/noticias/Detenidos-los-cuatro-principales-integrantes-del-grupo-hacktivista-Anonymous-Fenix-por-ciberataques-contra-organismos-publicos/?utm_source=openai)) This incident underscores the persistent threat posed by hacktivist groups leveraging socio-political events to justify cyberattacks. The use of DDoS tactics to disrupt critical government services highlights the need for robust cybersecurity measures and proactive monitoring of online platforms for recruitment and coordination activities.
6 months ago
Kill Chain
MuddyWater's Operation Olalampo: A New Era of Cyber Threats in MENA
In early 2026, the Iranian state-sponsored APT group MuddyWater launched 'Operation Olalampo,' targeting organizations across the Middle East and North Africa (MENA) region. The campaign utilized sophisticated spear-phishing emails with malicious Microsoft Office documents to deploy new malware families, including GhostFetch, HTTP_VIP, CHAR, and GhostBackDoor. These tools enabled the attackers to perform system reconnaissance, execute remote commands, and exfiltrate sensitive data, compromising entities in sectors such as telecommunications, government, and energy. This incident underscores a significant evolution in MuddyWater's tactics, notably their adoption of Rust-based malware and AI-assisted development processes. The group's enhanced capabilities and persistent targeting of critical infrastructure highlight the escalating cyber threat landscape in the MENA region, emphasizing the need for robust cybersecurity measures and vigilance against advanced persistent threats.
6 months ago
Kill Chain
APT28's Operation MacroMaze: A New Wave of Cyber Espionage
Between September 2025 and January 2026, the Russian state-sponsored threat actor APT28 conducted Operation MacroMaze, targeting entities in Western and Central Europe. The campaign utilized spear-phishing emails containing malicious Word documents with embedded macros. These macros exploited legitimate services like webhook[.]site for command-and-control and data exfiltration, employing techniques such as headless browser execution and keyboard simulation to evade detection. ([thehackernews.com](https://thehackernews.com/2026/02/apt28-targeted-european-entities-using.html?utm_source=openai)) This incident underscores the evolving tactics of APT28, highlighting their ability to adapt and leverage basic tools in sophisticated ways. The use of legitimate services for malicious purposes poses significant challenges for detection and mitigation, emphasizing the need for robust cybersecurity measures and continuous monitoring.
6 months ago
Kill Chain
Unveiling the Malicious JPEG Infostealer Campaign of February 2026
In February 2026, a sophisticated malware campaign was identified, leveraging steganographic techniques to embed malicious code within JPEG image files. Unsuspecting users were tricked into downloading these seemingly benign images, which, upon execution, initiated a multi-stage infection process. The primary payload was an infostealer designed to extract sensitive data, including browser credentials and system information, while maintaining communication with a command-and-control server. This method allowed attackers to exfiltrate data stealthily, minimizing detection by traditional security measures. This incident underscores the evolving tactics of cybercriminals, who are increasingly employing advanced obfuscation methods like steganography to bypass security defenses. The use of common file formats, such as JPEGs, as carriers for malware highlights the need for enhanced vigilance and the adoption of comprehensive security solutions capable of detecting such covert threats.
6 months ago
Kill Chain
Arkanix Stealer: A Brief Yet Impactful AI-Assisted Malware Campaign
In late 2025, the Arkanix Stealer emerged as an AI-assisted information-stealing malware, promoted on dark web forums and distributed through Discord channels. The malware targeted Windows systems, employing advanced evasion techniques to bypass security controls. It harvested sensitive data, including browser credentials, cryptocurrency wallets, VPN accounts, and system metadata, which was then exfiltrated to attacker-controlled infrastructure. The operation was short-lived, with the author dismantling the control panel and Discord server within two months, suggesting a quick financial gain motive. This incident underscores the growing trend of cybercriminals leveraging AI to rapidly develop and deploy sophisticated malware, reducing development time and costs. The swift emergence and disappearance of such threats pose significant challenges for detection and mitigation, highlighting the need for continuous vigilance and adaptive security measures.
7 months ago
Kill Chain
AI-Powered Cyberattack Compromises 600 Fortinet Firewalls in 2026
Between January 11 and February 18, 2026, a Russian-speaking threat actor utilized generative AI services to compromise over 600 FortiGate firewalls across 55 countries. The attacker exploited exposed management interfaces and weak credentials lacking multi-factor authentication, without leveraging any known vulnerabilities. Once access was gained, AI-assisted tools were employed to automate reconnaissance, extract configurations, and facilitate lateral movement within the networks. This campaign underscores the evolving threat landscape where AI technologies are being harnessed to amplify the capabilities of less sophisticated attackers, enabling them to execute large-scale intrusions with increased efficiency. Organizations must prioritize fundamental security measures, including securing management interfaces, enforcing strong authentication protocols, and maintaining vigilant monitoring to mitigate such AI-augmented threats.
7 months ago
Kill Chain
CISA Highlights Critical Roundcube Vulnerabilities Amid Active Exploitation
In February 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities affecting Roundcube webmail software to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation. The first, CVE-2025-49113, is a deserialization flaw allowing remote code execution by authenticated users due to improper validation of the '_from' parameter in 'upload.php'. The second, CVE-2025-68461, is a cross-site scripting vulnerability via the 'animate' tag in SVG documents. Both vulnerabilities have been exploited by threat actors, including nation-state groups like APT28 and Winter Vivern, to steal login credentials and spy on sensitive communications. ([thehackernews.com](https://thehackernews.com/2026/02/cisa-adds-two-actively-exploited.html?utm_source=openai)) The inclusion of these vulnerabilities in the KEV catalog underscores the persistent targeting of webmail platforms by sophisticated adversaries. Organizations using Roundcube are urged to apply the latest security patches promptly to mitigate potential risks. ([thehackernews.com](https://thehackernews.com/2026/02/cisa-adds-two-actively-exploited.html?utm_source=openai))
7 months ago
Kill Chain
Predator Spyware's Stealthy Bypass of iOS Recording Indicators
In February 2026, security researchers uncovered that Intellexa's Predator spyware can suppress iOS's camera and microphone recording indicators, allowing covert surveillance without user awareness. By injecting code into SpringBoard, the spyware intercepts sensor activity updates, preventing the green and orange dots from appearing when the camera or microphone is active. This technique requires prior full device compromise, including kernel-level access, and does not exploit new iOS vulnerabilities. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/predator-spyware-hooks-ios-springboard-to-hide-mic-camera-activity/?utm_source=openai)) This discovery highlights the evolving sophistication of commercial spyware and underscores the importance of maintaining up-to-date device security measures. Users should be aware that visual indicators alone may not reliably signal unauthorized access to device sensors, emphasizing the need for comprehensive security practices.
7 months ago
Kill Chain
AI-Assisted Cyber Attack Compromises 600+ FortiGate Devices in 2026
Between January 11 and February 18, 2026, a Russian-speaking, financially motivated threat actor exploited exposed management ports and weak credentials to compromise over 600 FortiGate devices across 55 countries. Utilizing commercial generative AI tools, the attacker automated scanning for vulnerable devices and executed authentication attempts, leading to unauthorized access and potential data exfiltration. This incident underscores the growing trend of cybercriminals leveraging AI to scale operations, enabling even low-skilled actors to conduct widespread attacks. Organizations must prioritize securing management interfaces, enforcing strong authentication mechanisms, and monitoring for unauthorized access to mitigate such threats.
7 months ago
Kill Chain
AI-Powered Cyberattack Compromises Hundreds of FortiGate Devices Globally
Between January 11 and February 18, 2026, a Russian-speaking, financially motivated threat actor leveraged commercial generative AI services to compromise over 600 FortiGate devices across more than 55 countries. The attackers exploited exposed management ports and weak, single-factor authentication credentials, without utilizing any known FortiGate vulnerabilities. This campaign enabled the threat actor to extract full device configurations, including credentials and network topology information, facilitating further post-exploitation activities such as Active Directory compromise and credential harvesting. ([aws.amazon.com](https://aws.amazon.com/blogs/security/ai-augmented-threat-actor-accesses-fortigate-devices-at-scale/?utm_source=openai)) This incident underscores the evolving threat landscape where AI tools lower the technical barrier for cybercriminals, allowing even those with limited skills to execute large-scale attacks. Organizations must prioritize fundamental security measures, including securing management interfaces, enforcing strong authentication protocols, and maintaining vigilant monitoring to detect and respond to such AI-augmented threats.
7 months ago
Kill Chain
Roundcube 2025 Remote Code Execution Vulnerability
In June 2025, a critical vulnerability (CVE-2025-49113) was identified in Roundcube Webmail versions prior to 1.5.10 and 1.6.11. This flaw allowed authenticated users to execute arbitrary code on the server due to improper validation of the '_from' parameter in the 'upload.php' script, leading to PHP object deserialization. Exploitation of this vulnerability could result in complete server compromise, unauthorized access to sensitive email data, and potential lateral movement within the network. ([feedly.com](https://feedly.com/cve/CVE-2025-49113?utm_source=openai)) The discovery of this vulnerability underscores the importance of rigorous input validation and prompt patch management. Organizations using affected versions of Roundcube Webmail are urged to upgrade to the latest versions to mitigate potential exploitation risks.
7 months ago
Kill Chain
Credential Theft Leads to Massive Data Breach at French Ministry of Finance
In late January 2026, the French Ministry of Finance reported a significant data breach involving unauthorized access to the national bank account registry, FICOBA. A threat actor exploited stolen credentials from a government official to access sensitive information on approximately 1.2 million bank accounts. The compromised data included bank account details (RIBs/IBANs), account holder identities, physical addresses, and, in some cases, taxpayer identification numbers. Upon detection, the Ministry promptly restricted the unauthorized access and initiated measures to notify affected individuals and financial institutions. This incident underscores the critical importance of robust access controls and credential management within governmental systems. The breach highlights the escalating risks associated with credential theft and the necessity for enhanced cybersecurity measures to protect sensitive financial data. Organizations are urged to reassess their security protocols to mitigate similar threats.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports