Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Over 6,000 SmarterMail Servers Hijacked via Critical Authentication Bypass (2026)
In January 2026, over 6,000 SmarterMail servers were found exposed online and vulnerable due to a critical authentication bypass vulnerability (CVE-2026-23760). This flaw in the password reset API allowed unauthenticated attackers to reset administrator passwords, granting them full administrative access and enabling remote code execution on affected servers. Reports of in-the-wild exploitation emerged within days of public disclosure, prompting both mass, automated hijacking attacks and urgent guidance from governmental agencies. The vulnerability impacted organizations globally, particularly across North America and Asia, and posed significant risk to business continuity, privacy, and service integrity. This incident underlines rapid attacker adoption of zero-day vulnerabilities and the risks of delayed patching for internet-exposed business systems. With threat actors leveraging automation and targeting widely-used administrative interfaces, organizations must adopt faster patch cycles and stronger access controls to reduce exposure to similar authentication bypass attacks.
7 months ago
Kill Chain
HoneyMyte 2025 Cyberespionage Hits: Updated CoolClient and Credential Theft Campaigns
Between 2024 and 2025, the advanced persistent threat group HoneyMyte (aka Mustang Panda, Bronze President) orchestrated advanced espionage campaigns targeting government entities across Southeast Asia, Mongolia, Malaysia, Myanmar, and Europe. Using updated CoolClient backdoors, custom browser credential stealers, and sophisticated prying scripts, HoneyMyte achieved persistent access, broad network infiltration, and the theft of sensitive documents, credentials, and operational intelligence. Attackers exploited signed DLL sideloading, launched post-exploitation scripts, and used public file-sharing services for covert exfiltration, successfully bypassing traditional defense layers and maintaining long-term surveillance on official targets. This incident highlights the evolving techniques of APT campaigns with growing reliance on multi-stage malware, encrypted traffic, and cloud-based exfiltration channels. The sophistication and persistence demonstrated by HoneyMyte reflect a broader rise in state-sponsored cyber espionage, posing continuing challenges for organizations' detection and regulatory compliance efforts in 2025.
7 months ago
Kill Chain
Mustang Panda’s CoolClient Infostealer: 2026 Global Espionage Campaign Unveiled
In January 2026, Chinese state-sponsored group Mustang Panda leveraged an updated version of its CoolClient backdoor to conduct targeted espionage campaigns against government organizations in Myanmar, Mongolia, Malaysia, Russia, and Pakistan. The attackers used legitimate Sangfor software for initial infection and subsequently deployed tailored infostealers that extracted login credentials from major browsers, monitored clipboard data, and profiled compromised systems. The operation featured advanced tactics such as DLL side-loading, remote shell plugins, encrypted multi-stage payloads, and the use of public cloud services (via hardcoded tokens) for stealthy data exfiltration. This breach highlights the rapid advancement and operational innovation among state-backed APT actors, particularly regarding infostealer deployment and C2 evasion using legitimate cloud infrastructure. Organizations in APAC, government, and critical infrastructure sectors remain top targets as attacker toolsets evolve to bypass both endpoint and network security controls.
7 months ago
Kill Chain
2026 Fortinet Zero-Day SSO Breach: How Authentication Bypass Exposed Critical Devices
In January 2026, Fortinet disclosed a critical zero-day vulnerability (CVE-2026-24858) in its FortiCloud SSO authentication mechanism that allowed attackers to bypass security controls and gain unauthorized administrative access to FortiOS, FortiManager, and FortiAnalyzer devices. By leveraging rogue FortiCloud accounts, threat actors exploited an alternate authentication path—even on fully patched systems—to create new local admin and VPN-enabled accounts, exfiltrating firewall configuration data from customer environments within seconds. Fortinet mitigated active attacks by disabling vulnerable FortiCloud SSO connections and initiating global blocks before a patch was available, but over 25,000 devices were at risk during the attack window. This incident is highly relevant due to the growing sophistication and automation of supply chain and SSO-based attacks, with adversaries increasingly targeting trusted cloud management platforms. The event underscores the need for stricter access controls, rapid incident response capabilities, and heightened vigilance around identity infrastructure, especially as SAML and SSO adoption expands in modern enterprises.
7 months ago
Kill Chain
Cellbreak: Critical Grist-Core Vulnerability Enables Remote Code Execution
In January 2026, a critical vulnerability (CVE-2026-24002, codename Cellbreak, CVSS 9.1) was disclosed in Grist-Core, an open-source spreadsheet-database platform. The flaw enabled attackers to leverage malicious spreadsheet formulas for remote code execution (RCE) on self-hosted Grist-Core servers. This vulnerability could grant adversaries full foothold on affected systems, leading to potential data exfiltration, lateral movement, and operational disruption for organizations running vulnerable deployments. Security researchers at Cyera Research Labs made the discovery public after coordinated disclosure and a patch release by Grist developers. The incident is particularly relevant due to the sharp increase in attacks targeting spreadsheet and application logic vulnerabilities—especially in open-source business tools. As attackers pivot toward supply chain and SaaS entry points, control weaknesses involving user-supplied formulas and embedded code in collaborative apps persist as a high-risk vector.
7 months ago
Kill Chain
Microsoft Office 2026 Zero-Day Forces Emergency Patch After Widespread Exploitation
In January 2026, Microsoft urgently released an out-of-band security update to address a high-severity zero-day vulnerability, CVE-2026-21509, in Microsoft Office. This security feature bypass flaw allowed attackers to exploit untrusted inputs, enabling unauthorized code execution through manipulated Office documents. The active exploitation of this vulnerability led to significant exposure for organizations relying on Office, making endpoints susceptible to malware deployment and data compromise. Microsoft’s swift emergency patch was in response to in-the-wild attacks observed by security researchers and incident response teams. This incident underscores the persistent threat of zero-day exploits targeting widely used productivity platforms. Attacker tactics are evolving to bypass conventional controls, driving urgency around proactive patch management and advanced threat detection to mitigate business disruption and data loss.
7 months ago
Kill Chain
Pakistan-Linked APT Launches Gopher Strike & Sheet Attack Against Indian Government in 2025
In September 2025, cybersecurity researchers uncovered coordinated cyber campaigns—dubbed Gopher Strike and Sheet Attack—targeting Indian government entities. Attributed to a Pakistan-linked Advanced Persistent Threat (APT) group, the operations leveraged novel, undocumented tactics involving phishing and multi-stage malware to compromise government networks. Attackers exploited existing security gaps, conducted lateral movement, and exfiltrated sensitive data, threatening the confidentiality and integrity of official communications. The campaigns remained undetected for an extended period, highlighting the advanced tradecraft and persistent nature of the threat actor. These incidents underscore the growing risk posed by state-aligned actors employing increasingly sophisticated tactics to target critical government infrastructure. The discovery of new tools and techniques in these attacks signals an escalation in South Asian regional cyber conflict and emphasizes the need for updated security controls and rapid detection capabilities.
7 months ago
Kill Chain
Sandworm Wiper Campaign Frustrated at Poland Power Grid
In May 2024, cyber researchers reported a high-profile attack attempt targeting Poland’s power grid infrastructure. The operation was attributed to Sandworm, a Russian APT group notorious for wiper malware and sabotage against critical national infrastructure. Attackers leveraged custom malware designed to disrupt grid operations, but strong detection and security controls reportedly thwarted the attempt, preventing widespread outages. The incident highlighted Sandworm’s persistent focus on critical infrastructure in Central Europe and their evolving tactics for sabotaging operational technology environments. This case underscores a larger trend of state-aligned threat actors targeting energy and critical infrastructure in Europe, leveraging specialized wiper tools and lateral movement techniques. It also emphasizes increasing cross-border cyber risk as geopolitical tensions escalate and underscores new regulatory scrutiny for critical sectors.
7 months ago
Kill Chain
CISA Flags Five Actively Exploited Vulnerabilities in 2026 KEV Catalog Update
In January 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added five high-risk vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation. These include flaws in the Linux Kernel, SmarterTools SmarterMail, Microsoft Office, and GNU InetUtils. Threat actors exploited these vulnerabilities through methods such as authentication bypass, unrestricted file upload, security feature bypass, and argument injection, targeting both federal and private sector networks. Rapid exploitation can lead to unauthorized access, data exfiltration, or further compromise of organizational systems if not promptly remediated. This evolving threat landscape highlights an ongoing wave of opportunistic and targeted attacks leveraging widely used enterprise, email, and infrastructure software. The addition of these CVEs to the KEV Catalog underscores regulatory pressure and the increased urgency for organizations of all sizes to prioritize patch management and mitigate exposure to active threats.
7 months ago
Kill Chain
VMware vCenter RCE Flaw Actively Exploited: What Security Teams Need to Know
In January 2026, a critical vulnerability (CVE-2024-37079) in VMware vCenter Server was confirmed as actively exploited in the wild. This heap overflow flaw within the DCERPC protocol implementation enables unauthenticated remote attackers with network access to execute arbitrary code on vulnerable vCenter Server systems. The compromise does not require user interaction or elevated privileges, making attacks relatively low-effort and high-impact. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a directive mandating all federal agencies to remediate the issue within three weeks, underscoring its urgency and operational risk. No temporary mitigations exist, leaving patching as the sole defense for affected environments. This incident highlights a continued trend of attackers targeting management and orchestration layers in hybrid-cloud and virtualized infrastructures. The lack of workarounds, combined with rapid weaponization, points to increasing risks for organizations who delay patching and underlines regulatory pressure on timely remediation for critical zero-day vulnerabilities.
7 months ago
Kill Chain
Microsoft Patches Active Office Zero-Day: What Your Security Team Must Know
In June 2024, Microsoft urgently released security patches addressing a high-severity zero-day vulnerability in Microsoft Office. Threat actors exploited this flaw in-the-wild prior to disclosure, using malicious documents to achieve remote code execution and gain access to targeted systems without user awareness. The vulnerability impacted multiple Office versions, with proof-of-concept exploits circulating even before patch release. Microsoft’s security teams identified active exploitation, prompting swift response to curb potential corporate data exposure, loss of confidentiality, and operational disruption for both private and public sector users worldwide. This incident spotlights the persistent risk of zero-day exploits in mainstream productivity software. It underscores both attackers’ increasing sophistication in rapidly weaponizing new vulnerabilities and the escalating need for organizations to prioritize timely patch application and robust monitoring to mitigate the business impact of emerging threats.
7 months ago
Kill Chain
Blackmoon Malware Hits Indian Taxpayers Through Sophisticated Phishing in 2026
In January 2026, Indian users became the focus of a sophisticated cyber espionage campaign involving tax-themed phishing emails masquerading as legitimate communications from the Income Tax Department of India. These emails distributed malicious archive files, which, once opened, executed the infostealer Blackmoon malware. This multi-stage attack enabled threat actors to quietly exfiltrate personal and financial information from compromised systems, potentially exposing sensitive tax details and compromising the victims' digital environments. The attackers applied advanced phishing techniques and evasion tactics to bypass traditional security defenses and maintain persistent access. This incident highlights a broader trend in targeted social engineering attacks leveraging local themes and timely events to increase victim engagement. The resurgence of infostealer malware like Blackmoon underscores the importance of endpoint protection, awareness training, and zero trust controls, particularly in high-risk seasons such as tax filing periods.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports