Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2818 threat reports
Page 164 of 235

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Government Administration Threat Reports

Showing 19571968 / 2818 reports
Mustang Panda’s 2025 Kernel Rootkit: How a Signed Driver Enabled Stealth Espionage in Asia
Impact· high

Mustang Panda’s 2025 Kernel Rootkit: How a Signed Driver Enabled Stealth Espionage in Asia

In mid-2025, the Chinese cyber espionage group Mustang Panda deployed a previously undocumented, signed kernel-mode rootkit to secretly load a TONESHELL backdoor variant during targeted attacks against government organizations in Southeast and East Asia—mainly Myanmar and Thailand. Leveraging a stolen legacy digital certificate, the attackers installed a Windows minifilter driver to inject TONESHELL into system processes, evade security controls, and shield their malware and associated files from detection. The backdoor enabled ongoing remote control, data exfiltration, and further malware deployments via encrypted channels, establishing persistent clandestine access. This incident is notable for its innovative use of signed kernel drivers to enhance stealth, resilience, and anti-forensic measures. It reflects a broader trend among sophisticated threat actors who increasingly leverage advanced rootkit technology and certificate abuse to bypass endpoint protections and remain undetected for extended periods.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
US Treasury Lifts Sanctions on Key Intellexa Predator Spyware Figures
Impact· medium

US Treasury Lifts Sanctions on Key Intellexa Predator Spyware Figures

In December 2025, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) removed three individuals previously sanctioned for their involvement with Intellexa and its Predator commercial spyware from the Specially Designated Nationals (SDN) list. The individuals—Merom Harpaz, Andrea Nicola Constantino Hermes Gambazzi, and Sara Aleksandra Fayssal Hamou—were linked to leadership and distribution roles within the Intellexa Consortium. Their removal followed a petition and OFAC’s evaluation that they had separated themselves from the Intellexa ecosystem, but no underlying details or independent confirmation were disclosed. The original sanctions stemmed from their roles in developing, distributing, and enabling Predator software, a tool implicated in high-profile surveillance of civil society figures, including journalists and activists, through stealth zero-day and social engineering attacks. This case underscores the continued risks posed by commercial spyware vendors and associated compliance exposures. Ongoing public reporting highlights Predator’s persistent activity despite regulatory efforts, as well as geopolitical pressures that drive international balkanization and new attack trends targeting sensitive sectors. With regulatory frameworks evolving and threat actors shifting tactics, the risk of spyware misuse for human rights abuses and espionage remains acute.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Over 10,000 Fortinet Firewalls Still Exposed to 2FA Bypass Attack in 2026
Impact· medium

Over 10,000 Fortinet Firewalls Still Exposed to 2FA Bypass Attack in 2026

In early January 2026, it was revealed that over 10,000 Fortinet FortiGate firewalls remain exposed to a critical authentication bypass vulnerability (CVE-2020-12812) first patched by Fortinet in July 2020. Attackers exploit this flaw by manipulating username case sensitivity to bypass two-factor authentication (2FA) on SSL VPNs—allowing unauthorized access to devices with unpatched software and certain LDAP configurations. Despite years of vendor and government warnings, more than 1,300 vulnerable systems in the United States alone are still online, placing organizations at ongoing risk of compromise. The persistence of this five-year-old flaw’s exploitation highlights chronic issues in vulnerability management and patch adoption within network infrastructure. Active targeting by both cybercriminal and state-backed actors, combined with evidence of ransomware deployment, underscores the need for continuous configuration hardening, zero trust adoption, and rapid remediation of exposed security controls.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Phishing Goes Cloud-Native: Google Cloud Application Integration Abused in 2026 Attack
Impact· medium

Phishing Goes Cloud-Native: Google Cloud Application Integration Abused in 2026 Attack

In early 2026, a sophisticated phishing campaign was uncovered in which cybercriminals leveraged Google Cloud’s Application Integration service to send deceptive emails that mimicked legitimate Google communications. By exploiting the inherent trust in Google’s cloud infrastructure, attackers generated emails from authentic Google addresses, increasing the likelihood of victims engaging with malicious links or sharing sensitive information. According to Check Point researchers, this multi-stage approach enabled attackers to bypass traditional email security measures, posing significant risks to organizations that rely heavily on cloud-based productivity suites for daily operations. This campaign highlights an emerging trend in the abuse of trusted SaaS and cloud platforms for targeted phishing attacks. As adversaries shift toward cloud-native TTPs and social engineering techniques, organizations must enhance detection, improve user awareness, and adapt inline controls to mitigate risks tied to trusted service abuse.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
IBM API Connect Critical Authentication Bypass (2025): What You Must Know
Impact· low

IBM API Connect Critical Authentication Bypass (2025): What You Must Know

In December 2025, IBM disclosed a critical security vulnerability (CVE-2025-13915) in its API Connect platform, rated 9.8 on the CVSS scale. The flaw allowed remote attackers to bypass authentication mechanisms and gain unauthorized access to exposed applications. Exploitation could enable attackers to manipulate sensitive workloads, extract confidential data, or pivot deeper into network environments. The incident highlighted how a simple authentication bypass in widely deployed enterprise middleware presents major risks for organizations relying on API-enabled digital ecosystems. This breach underscores the escalating sophistication of identity-focused attacks and the necessity for robust authentication and segmentation controls. With API-driven architectures proliferating in nearly every sector, such vulnerabilities are increasingly targeted; urgency is amplified by regulatory pressure and the rising adoption of zero trust frameworks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
How Transparent Tribe’s 2026 RAT Offensive Breached Indian Government & Academia
Impact· medium

How Transparent Tribe’s 2026 RAT Offensive Breached Indian Government & Academia

In early 2026, the advanced persistent threat group Transparent Tribe (APT36) launched a sophisticated cyber espionage campaign targeting Indian governmental and academic institutions. Attackers distributed spear-phishing emails containing ZIP archives with malicious Windows shortcut (LNK) files, disguised as legitimate PDFs. Upon execution, these files deployed remote access trojans (RATs) by loading encrypted payloads in-memory and displaying decoy documents to evade suspicion. The malware adapted its persistence techniques based on detected antivirus solutions and enabled functions such as file management, system reconnaissance, data exfiltration, and command execution via a dynamic command-and-control infrastructure. This incident highlights the persistent evolution of state-linked cyber threats and the rising use of multi-stage spear-phishing, evasive loaders, and context-aware persistence. As state-sponsored attacks become more adaptive and target the public sector, organizations face increased regulatory and operational pressure to fortify internal security controls and monitor lateral movement.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Flock Cloud Misconfiguration Exposes AI Camera Surveillance Feeds in 2026
Impact· high

Flock Cloud Misconfiguration Exposes AI Camera Surveillance Feeds in 2026

In January 2026, Flock, a prominent provider of AI-enabled surveillance technologies, faced a significant cybersecurity incident due to a cloud misconfiguration. Unauthorized online access was discovered, revealing live video streams from Flock’s advanced Condor pan-tilt-zoom cameras deployed in public areas and private properties. These cameras, designed for AI-driven facial and movement tracking, unintentionally exposed high-resolution footage of civilians—including children—across multiple locations, highlighting considerable privacy and operational risks. No evidence suggests the exposure was caused by active exploitation; instead, the open access points were a direct result of insufficient cloud security controls and misapplied access permissions. The incident triggered regulatory and public concern around surveillance, data protection, and compliance obligations, emphasizing the criticality of proper cloud configurations in the era of AI-driven physical security systems. This breach is indicative of a broader rise in cloud infrastructure misconfigurations exposing sensitive, AI-powered surveillance data. Regulatory agencies and industry groups are increasing pressure on technology vendors to enforce robust controls, with cloud and IoT security now considered foundational to protecting physical as well as digital environments.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
2025 Cloud Provider Breach: Multi-Vector Ransomware and the East-West Security Imperative
Impact· high

2025 Cloud Provider Breach: Multi-Vector Ransomware and the East-West Security Imperative

In early 2025, a sophisticated multi-vector cyberattack struck a leading multinational cloud services provider. Threat actors leveraged a combination of zero-day exploits, lateral movement, and exploited east-west traffic weaknesses to progressively compromise internal workloads across hybrid and multicloud environments. Utilizing encrypted channels, they evaded detection and ultimately deployed pervasive ransomware, resulting in widespread data exfiltration, service disruptions, and significant financial and reputational damage. Despite existing controls, gaps in segmentation and egress policy enforcement were exploited, with the incident exposing vulnerabilities in both cloud-native and on-premise environments. This breach highlights an escalating trend: attackers using complex, multi-stage TTPs that blend cloud-native exploits with traditional ransomware vectors. Security leaders must prioritize zero trust segmentation, real-time east-west inspection, and enforceable multicloud security controls to address rapidly evolving threat landscapes.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Thousands Breached: The 2024 Ivanti EPMM Zero-Day APT Campaign
Impact· low

Thousands Breached: The 2024 Ivanti EPMM Zero-Day APT Campaign

In April and May 2024, thousands of organizations worldwide were compromised after a Chinese state-sponsored advanced persistent threat (APT) group exploited multiple previously unknown zero-day vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) platform. The attackers used these flaws as entry points to gain administrative control, move laterally, and deploy persistent malware, leading to widespread data exfiltration and operational disruption. The campaign targeted government, critical infrastructure, and private sector entities, exploiting unpatched systems at scale before public disclosure, prompting rapid security advisories and emergency patching. This Ivanti EPMM incident underscores the growing sophistication of nation-state campaigns leveraging zero-day vulnerabilities for large-scale compromise. It highlights the urgent industry need for rigorous vulnerability management, zero trust architectures, and rapid detection in light of escalating APT tactics.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
ErrTraffic ClickFix: The 2024 Malware Campaign Exploiting Fake Browser Glitches
Impact· medium

ErrTraffic ClickFix: The 2024 Malware Campaign Exploiting Fake Browser Glitches

In March 2024, security researchers uncovered a large-scale cybercriminal campaign leveraging a service named ErrTraffic to automate 'ClickFix' attacks via fake browser glitches. Threat actors compromised legitimate websites, deploying scripts to simulate error pop-ups and glitches that tricked users into downloading malicious payloads or executing harmful actions. The attackers utilized advanced social engineering, presenting credible browser dialog impersonations, and used the campaign to rapidly distribute information-stealing malware across multiple geographies. The impact included significant compromises of user credentials and personal information, highlighting growing risk to businesses reliant on web applications. This incident is particularly notable as it demonstrates both evolving infostealer TTPs and the increasing sophistication of social engineering through browser-manipulation. The widespread adoption of automated 'glitch' services like ErrTraffic signals a broader shift towards commoditizing web-based attacks targeting both enterprises and individuals.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ESA 2024 External Server Breach: Lessons on Third-Party and Perimeter Security
Impact· medium

ESA 2024 External Server Breach: Lessons on Third-Party and Perimeter Security

In June 2024, the European Space Agency (ESA) confirmed a cybersecurity incident involving unauthorized access to external servers outside its core corporate IT network. These servers contained 'unclassified' information tied to ESA's collaborative engineering activities. The breach was detected and announced on June 24, with the agency rapidly taking down the compromised servers to contain the incident and beginning an internal investigation. No critical or classified ESA infrastructure was reportedly affected, and mission operations remained unaffected. This breach underscores persistent risks facing organizations collaborating with external partners and utilizing externally accessible infrastructure. Similar methodologies targeting non-core systems and lateral movements are increasing, highlighting the importance of robust segmentation, external system monitoring, and continuous risk assessment for third-party assets.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Silver Fox Exploits Income Tax Phishing to Deploy ValleyRAT in India (2025)
Impact· medium

Silver Fox Exploits Income Tax Phishing to Deploy ValleyRAT in India (2025)

In December 2025, the Chinese-origin threat group Silver Fox launched a sophisticated phishing campaign targeting Indian users with income tax-themed emails. Victims received emails purportedly from India’s Income Tax Department containing decoy PDF attachments. When recipients opened the PDFs, they were redirected to a malicious website serving a ZIP file with a trojanized installer. The infection leveraged DLL hijacking and a legitimate executable to sideload malware, ultimately installing ValleyRAT—a modular remote access trojan—by process hollowing. Once active, ValleyRAT enabled attackers to harvest credentials, establish persistence, and communicate via encrypted channels for ongoing control. This incident highlights the convergence of advanced phishing lures, supply chain manipulation, and evasive malware tailoring persistent access to high-value targets across public, financial, healthcare, and technology organizations. ValleyRAT’s modularity, anti-analysis features, and delayed communication underline a pivot towards low-noise, highly adaptive attacks exploiting human trust and regulatory touchpoints.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports