Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2818 threat reports
Page 16 of 235

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Government Administration Threat Reports

Showing 181192 / 2818 reports
Inside the Sality Botnet Takedown: How Authorities Turned P2P Architecture Against Itself
Impact· MEDIUM

Inside the Sality Botnet Takedown: How Authorities Turned P2P Architecture Against Itself

In August 2026, the U.S. Department of Justice led a coordinated international operation to disrupt the Sality botnet, a peer-to-peer malware network operating since 2003. Law enforcement from the U.S., Bulgaria, Hungary, and Romania, working with CrowdStrike and Shadowserver Foundation, executed a sophisticated sinkhole operation that turned Sality's decentralized architecture against itself. The botnet, operated by the Russian threat group Salty Spider from Bashkortostan, had infected over 15,000 machines worldwide and generated at least $150,000 through cryptocurrency theft via clipboard hijacking malware. The operation demonstrates evolving law enforcement capabilities against resilient P2P botnets that traditionally evade conventional takedown methods. This disruption highlights the increasing sophistication of international cybercrime enforcement and the vulnerability of even decentralized criminal infrastructure to coordinated technical and legal action, particularly relevant as threat actors increasingly adopt P2P architectures to avoid single points of failure.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical GeoNetwork Vulnerabilities Threaten 121 Government Geoportals Worldwide
Impact· HIGH

Critical GeoNetwork Vulnerabilities Threaten 121 Government Geoportals Worldwide

In July 2026, GeoNetwork, an open-source geospatial metadata catalog used by government agencies worldwide, patched two critical vulnerabilities that could be chained together for unauthenticated remote code execution. CVE-2026-63219 (CVSS 8.6) allows anonymous file uploads to the formatter directory, while CVE-2026-58400 (CVSS 9.1) enables malicious XSLT stylesheets to execute operating system commands through the Saxon transformation engine. Security researcher Rafael Castilho identified 121 exposed instances across 39 countries, with 89% belonging to government, military, or national agencies running the vulnerable software behind critical geoportal infrastructure. This incident highlights the growing targeting of geospatial infrastructure, following recent exploitation of GeoServer vulnerabilities for cryptocurrency mining and backdoor deployment. As governments increasingly digitize spatial data services and critical infrastructure mapping, these specialized systems present attractive targets for nation-state actors and cybercriminals seeking to compromise sensitive geographic intelligence.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SonicWall SMA 1000 Zero-Day Attack Chain: CVE-2026-83548 & CVE-2026-83549 Analysis
Impact· CRITICAL

SonicWall SMA 1000 Zero-Day Attack Chain: CVE-2026-83548 & CVE-2026-83549 Analysis

In September 2026, SonicWall disclosed two zero-day vulnerabilities (CVE-2026-83548 and CVE-2026-83549) in its Secure Mobile Access 1000 series VPN appliances that were actively exploited by attackers. The vulnerabilities allow threat actors to chain a pre-authentication server-side request forgery (SSRF) flaw with a post-authentication command injection vulnerability to achieve remote code execution on affected devices. SonicWall confirmed active exploitation and recommended immediate patching, system reimaging if compromised, and password resets for all affected appliances. This incident highlights the continued targeting of enterprise VPN infrastructure by sophisticated threat actors, reflecting a broader trend of attacks against network perimeter devices that became critical during remote work adoption and remain attractive targets for initial access operations.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Chinese Cybercriminals Turn Brazilian Government Sites into Gambling Traffic Redirectors
Impact· MEDIUM

Chinese Cybercriminals Turn Brazilian Government Sites into Gambling Traffic Redirectors

The Chinese-speaking Gambling Goblin cybercrime cluster has been compromising Brazilian government and educational web servers since mid-2025, installing malicious Apache modules to redirect visitors to attacker-controlled gambling and sports betting pages. The campaign leverages compromised high-reputation .gov.br domains to manipulate search engine optimization at scale, with modules reverse-proxying traffic while stripping security headers to allow malicious content execution. Linked to the Earth Berberoka threat group, the operation deploys sophisticated tooling including custom downloaders, modular backdoors, and credential stealers to maintain persistent access to government infrastructure. This incident highlights the growing trend of SEO manipulation attacks targeting government domains for cybercriminal profit, particularly as Brazil's newly regulated online betting market creates lucrative opportunities for threat actors to exploit trusted infrastructure for financial gain.

2 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Silver Fox Supply Chain Attack: How Counterfeit Software Sites Compromise Enterprise Networks
Impact· HIGH

Silver Fox Supply Chain Attack: How Counterfeit Software Sites Compromise Enterprise Networks

Microsoft Defender Experts has identified an active malware campaign using counterfeit software download websites to distribute malicious installers targeting organizations across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The campaign primarily affects China-based operations and Chinese-speaking users through high-fidelity clones of legitimate vendor sites offering popular software downloads. Once executed, the malicious installers deploy persistent malware that weakens security protections, establishes command and control connections, and enables potential data exfiltration through encrypted channels. This incident highlights the growing sophistication of supply chain attacks targeting software distribution channels, coinciding with increased regulatory focus on software supply chain security and the rise of AI-powered security evasion techniques.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Leaked Russian Documents Expose Systematic Cyber Warfare Training Pipeline
Impact· HIGH

Leaked Russian Documents Expose Systematic Cyber Warfare Training Pipeline

In September 2026, leaked training materials from Russia's Bauman Moscow State Technical University exposed the institutional framework behind Russian state-sponsored cyber operations. The documents revealed Department No. 4's role as a pipeline for recruiting students into GRU units including Sandworm (Military Unit 74455) and APT28, showing formalized pathways from university recruitment to military cyber roles. The leak provided unprecedented insight into how Russia systematically develops cyber capabilities through supervised technical and ideological preparation of students before their assignment to intelligence and cyber warfare units. This exposure comes as Russian cyber operations have intensified against critical infrastructure globally, with increased focus on destructive attacks and espionage campaigns targeting government and private sector networks across multiple domains.

2 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Serbian Activists Targeted in Largest Documented Pegasus and NoviSpy Spyware Campaign
Impact· HIGH

Serbian Activists Targeted in Largest Documented Pegasus and NoviSpy Spyware Campaign

In early 2026, researchers discovered the first confirmed Pegasus spyware infection of the year alongside NoviSpy variant infections targeting 14 Serbian individuals, including student activists, a parliament member, and local government official. The SHARE Foundation documented this as the largest wave of surveillance in Serbia to date, coinciding with local elections and student protests following the 2024 Novi Sad railway station collapse. Pegasus infections utilized zero-click exploits from December 2025 to January 2026, while NoviSpy variants were deployed during police detention and questioning of activists. This incident highlights the continued weaponization of commercial spyware against civil society and democratic movements, demonstrating how state-sponsored surveillance capabilities are increasingly deployed to suppress political dissent and monitor opposition activities during critical electoral periods.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
FBI Warns of Sophisticated OAuth Consent Phishing Campaign Targeting Prominent Figures
Impact· HIGH

FBI Warns of Sophisticated OAuth Consent Phishing Campaign Targeting Prominent Figures

The FBI issued a public alert in late 2025 regarding a sophisticated OAuth consent phishing campaign targeting high-profile individuals, their family members, and associates through commercial messaging applications. Attackers impersonate government officials, journalists, and public personalities to trick victims into granting access to legitimate cloud services like Microsoft or Google under the pretense of reviewing documents. Once OAuth permissions are granted, attackers gain persistent access to emails, files, and sensitive data that cannot be revoked simply by changing passwords, requiring victims to manually invalidate tokens in application security settings. This campaign highlights the growing trend of identity-centric attacks that bypass traditional security measures including multi-factor authentication, representing a significant evolution in social engineering tactics that exploit trusted authentication protocols against prominent targets.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
PaperCut Zero-Day Attack: How Print Infrastructure Became the New Attack Vector
Impact· CRITICAL

PaperCut Zero-Day Attack: How Print Infrastructure Became the New Attack Vector

Two critical zero-day vulnerabilities in PaperCut NG and MF print management software (CVE-2026-81578 and CVE-2026-82078) were actively exploited by threat actors in August 2026 for data theft attacks. The flaws can be chained to bypass authentication and achieve remote code execution on vulnerable servers used by over 100 million users across 70,000 organizations globally. PaperCut Software released three emergency patches within a week to address the vulnerabilities, but threat intelligence indicates attackers are exploiting these flaws to dump database tables and steal sensitive data from exposed servers. With over 800 PaperCut servers still exposed online and a history of ransomware groups targeting similar vulnerabilities, this incident highlights the critical risk posed by internet-facing print management infrastructure. This incident underscores the growing trend of attackers targeting enterprise software zero-days for immediate data theft rather than prolonged persistence, reflecting the increasing sophistication and speed of modern threat actors in monetizing newly discovered vulnerabilities.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Exchange Server Vulnerability Leaves 22,000 Organizations at Risk
Impact· HIGH

Critical Exchange Server Vulnerability Leaves 22,000 Organizations at Risk

In September 2026, security researchers discovered that nearly 22,000 Microsoft Exchange servers remained vulnerable to CVE-2026-62911, a high-severity authentication bypass vulnerability affecting Exchange Server 2016, 2019, and Subscription Edition. The flaw allows attackers with basic privileges to execute capture-replay attacks and hijack all user mailboxes on targeted servers. Despite Microsoft patching the vulnerability in August 2026, most servers remain unpatched, with Germany showing 85% of on-premises Exchange installations still vulnerable. The Netherlands NCSC reported that exploit code is already publicly available online. This incident highlights the persistent challenge of legacy system security as Exchange 2016 and 2019 reached end-of-support in October 2026, with Extended Security Updates ending the same month, leaving organizations exposed to mounting authentication bypass attacks.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
TerminalFix Campaign Exposes Enterprise Vulnerability to PowerShell Social Engineering
Impact· HIGH

TerminalFix Campaign Exposes Enterprise Vulnerability to PowerShell Social Engineering

The TerminalFix campaign represents a sophisticated evolution of ClickFix social engineering attacks, targeting enterprise networks through fake Cloudflare CAPTCHA overlays that trick users into executing malicious PowerShell commands. First documented by Microsoft researchers in August 2026, this multistage attack establishes persistent access through DLL sideloading, steganographic payloads hidden in PNG images, and Python-based reverse tunnels that provide direct access to internal networks. The campaign has successfully compromised organizations across multiple industries, with attackers leveraging this access for privilege escalation, security control bypass, data exfiltration, and ransomware deployment. This incident highlights the growing sophistication of social engineering attacks that bypass traditional security controls by manipulating user trust and exploiting legitimate system tools like PowerShell for malicious purposes.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
The Rise of Repeatable Cybercrime: How ClickFix Became 2026's Dominant Attack Vector
Impact· HIGH

The Rise of Repeatable Cybercrime: How ClickFix Became 2026's Dominant Attack Vector

In 2026, cybercriminals have shifted from developing sophisticated new attack methods to perfecting repeatable, scalable procedures that work consistently across targets. Microsoft's threat intelligence team identified ClickFix as the most common initial access method, accounting for 47% of observed attacks. This social engineering technique tricks users into executing malicious commands by placing them on their clipboard through deceptive web pages. Bitdefender's analysis of 700,000 security incidents revealed that 84% of high-severity breaches involved legitimate administrative tools already present on victim systems, demonstrating the widespread adoption of 'living off the land' tactics. This trend represents a fundamental evolution in cybercrime business models, where threat actors prioritize operational efficiency over technical innovation. The shift coincides with declining ransom payments and increased victim volumes, forcing attackers to optimize for cost-effectiveness and repeatability rather than sophistication.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports