Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
MongoBleed 2025: Global Memory Leak Puts MongoDB Data at Risk
In December 2025, a high-severity vulnerability named MongoBleed (CVE-2025-14847) was identified in multiple MongoDB versions with default settings, allowing unauthenticated attackers to leak sensitive server memory, including credentials and access tokens. Public disclosure and proof-of-concept code triggered a surge in exploitation, leaving more than 75,000 vulnerable instances exposed globally. Security researchers highlight the ease of exploitation, scale of potentially affected organizations, and absence of forensic evidence, which complicates post-incident investigations and raises the risk of undetected data exposure. Countries most affected include China, the United States, and several European and Asian nations. This incident underscores the urgent risk posed by memory-leak vulnerabilities in widely deployed open-source technologies and highlights the accelerating cycle from disclosure to weaponization. It also signals how reduced staffing during holiday periods can hinder detection and response, contributing to lingering risks and delayed mitigation.
8 months ago
Kill Chain
HoneyMyte APT Unleashes Kernel-Mode Rootkit with ToneShell Backdoor in Southeast Asia
In early 2025, the HoneyMyte APT group launched a targeted cyberespionage campaign against government organizations in Southeast and East Asia, primarily Myanmar and Thailand. Leveraging a stolen digital certificate, HoneyMyte deployed a malicious kernel-mode rootkit disguised as a signed driver to inject the advanced ToneShell backdoor into high-privilege system processes. The attack chain delivered full process, registry, and file protection for malicious activity, making removal and detection by security tools exceedingly challenging. The backdoor enabled covert remote access, data exfiltration, and command execution via communications camouflaged to resemble legitimate encrypted TLS traffic. This incident is a stark example of modern APT evolution, showcasing new levels of stealth and persistence through kernel-level threats and advanced obfuscation. It highlights a broader shift towards supply-chain and trusted-cert abuse, increasing risk for public sector and critical infrastructure targets in the Asia-Pacific region.
8 months ago
Kill Chain
CISA Adds MongoDB CVE-2025-14847 to KEV Catalog Amid Active Exploitation
In December 2025, CISA added CVE-2025-14847 to its Known Exploited Vulnerabilities (KEV) Catalog following confirmation of active exploitation in the wild. The vulnerability, found in MongoDB and MongoDB Server, involves improper handling of length parameter inconsistencies, potentially enabling attackers to compromise data confidentiality and integrity through specially crafted requests. This flaw has become an attractive initial attack vector for threat actors targeting federal and private sector systems. The KEV listing triggers urgent remediation directives for federal agencies and strongly recommends private organizations act quickly to mitigate system and data risks. The designation of this MongoDB vulnerability underlines the continued focus of both attackers and defenders on widely used open-source software. As exploitation of unpatched vulnerabilities accelerates, industry and government face mounting regulatory and operational pressure to prioritize swift vulnerability management amid a rapidly evolving attack landscape.
8 months ago
Kill Chain
MongoDB Global Breach: Exploiting MongoBleed (CVE-2025-14847) for Data Exposure
In December 2025, a major security vulnerability (CVE-2025-14847), dubbed MongoBleed, was exploited globally across more than 87,000 MongoDB instances. This high-severity flaw in the default zlib compression feature of MongoDB servers enabled unauthenticated attackers to remotely leak sensitive information, including credentials and API keys, by sending specially crafted network packets that expose uninitialized heap memory. First disclosed by OX Security and corroborated by Wiz, the vulnerability’s impact is magnified in cloud environments and internet-exposed infrastructure, prompting urgent mitigation actions worldwide. The MongoBleed incident marks a significant escalation in memory exposure and pre-authentication exploitation methods targeting widely adopted cloud database technologies. The attack's broad reach and urgency have galvanized regulators and security teams, emphasizing the need for timely patching, network exposure reduction, and enhanced security policies for infrastructure software.
8 months ago
Kill Chain
Salt Typhoon’s 2025 Onslaught: How a Nation-State Breached US Telecoms
In 2025, the Chinese state-sponsored APT group Salt Typhoon (Operator Panda) executed a series of sophisticated cyber-espionage operations targeting major US telecom companies and government agencies, including Verizon, AT&T, Lumen Technologies, Viasat, and the US National Guard. Exploiting vulnerabilities in internet-exposed network devices—such as routers, VPN appliances, and security gear—Salt Typhoon bypassed traditional endpoint defenses and established persistent access over the course of nearly a year. Their campaigns involved targeting wiretapping infrastructure and internal communications, enabling data exfiltration and pre-positioning for further attacks. This incident underscores the escalating risk posed by advanced nation-state attackers exploiting unpatched edge devices. With a surge in supply-chain attacks, east-west lateral movement, and strain on government cyber resources following budget cuts, organizations must prioritize zero trust segmentation, unified network visibility, and proactive threat detection to combat evolving cross-domain adversaries.
8 months ago
Kill Chain
CISA Alerts: Digiever NVR Botnet Exploitation via CVE-2023-52163
In December 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) flagged an actively exploited vulnerability (CVE-2023-52163, CVSS 8.8) in Digiever DS-2105 Pro network video recorders. Attackers exploited a missing authorization flaw to perform remote code execution via command injection, requiring authentication. Security researchers confirmed that this vulnerability enabled the deployment of IoT botnets such as Mirai and ShadowV2, allowing attackers to gain persistent control and leverage compromised devices for further attacks. The product’s end-of-life status means no patch is available, compounding organizational risk for operators of affected models. This incident is part of a broader trend of threat actors targeting unpatched and unsupported IoT devices for malware delivery and botnet growth. With critical infrastructure and surveillance systems at risk, timely mitigation is paramount amid surging exploitation and regulatory pressure for proactive defense.
8 months ago
Kill Chain
Active Exploitation of Fortinet SSL VPN 2FA Bypass Shows Criticality of Patch Hygiene
In December 2025, Fortinet disclosed ongoing, active exploitation of a previously known vulnerability (CVE-2020-12812) affecting FortiOS SSL VPN devices. The flaw allows attackers to bypass two-factor authentication (2FA) by manipulating the case sensitivity of usernames when certain configurations are in place, specifically when integrating local users with LDAP groups. This misconfiguration enables unauthorized access for administrative and VPN users, as attackers can skip required 2FA checks and authenticate directly via LDAP. The vulnerability, originally patched in 2020, has resurfaced due to a large number of unpatched and exposed Fortinet devices, with over 9,700 instances still vulnerable worldwide as of January 2026. This incident exemplifies the persistent risk of legacy vulnerabilities, particularly in Internet-facing VPN and perimeter security devices. Attackers are increasingly revisiting older weaknesses to target unpatched infrastructure, elevating the urgency for ongoing patch management and configuration reviews in enterprise environments.
8 months ago
Kill Chain
Critical MongoDB Flaw Exposes Sensitive Server Memory to Unauthenticated Threats
In December 2025, a critical security flaw (CVE-2025-14847) was publicly disclosed in multiple versions of MongoDB, exposing organizations to the risk of uninitialized memory disclosure by unauthenticated attackers. The flaw stems from improper handling of length parameter inconsistencies within zlib compressed protocol headers, allowing remote, unauthenticated clients to read uninitialized heap memory. Impacted versions span major MongoDB releases 3.6 through 8.2, potentially exposing sensitive data in server memory. MongoDB responded by releasing patches and advised urgent upgrades or the disabling of zlib compression. This incident gains heightened significance as memory disclosure vulnerabilities enable threat actors to harvest sensitive information without authentication. The vulnerability underscores the increasing importance of rigorous software supply chain security and timely patch management amid a growing landscape of data exposure risks in widely used open-source technologies.
8 months ago
Kill Chain
Evasive Panda APT Uses DNS Poisoning for Prolonged Espionage: 2022–2024 Campaign
Between November 2022 and November 2024, the China-linked Evasive Panda APT group conducted a sophisticated cyber espionage campaign targeting entities in Türkiye, China, and India. The attackers leveraged DNS poisoning techniques to redirect requests for popular software updates (such as SohuVA and Tencent QQ) to attacker-controlled infrastructure. Through adversary-in-the-middle attacks, victims received trojanized loaders, which proceeded to fetch and decrypt highly targeted MgBot backdoors. The attack chain involved supply chain and AitM vectors, advanced encryption and obfuscation methods, and allowed persistent compromise and broad data theft, including keylogging and credential exfiltration. This campaign highlights the growing sophistication of APT operations exploiting core network infrastructure such as DNS to evade perimeter defenses. The increased prevalence of similar DNS-manipulation campaigns and targeted malware delivery emphasizes the urgent need for robust segmentation, encrypted traffic, and thorough network and endpoint visibility.
8 months ago
Kill Chain
How a Latvian Insider Hacked an Italian Ferry's IoT Systems in 2025
In December 2025, an Italian ferry operator experienced a significant cybersecurity breach when a Latvian national was arrested for installing malware directly onto the vessel's onboard systems. Unlike a remote attack, the malware was physically introduced, potentially via a compromised insider or unauthorized access point. This compromised the ferry's IoT devices, impacting operational systems and potentially exposing sensitive data in transit. The incident raised immediate safety and privacy concerns and temporarily disrupted critical ferry services, drawing attention to the security of maritime transportation and IoT infrastructure. This event illustrates the mounting risks associated with connected operational technology in critical transportation sectors. As attackers increasingly target IoT and cyber-physical systems — particularly with the rise of insider-enabled methods — organizations must prioritize endpoint hardening, east-west traffic monitoring, and full-stack threat detection to safeguard vital infrastructure.
8 months ago
Kill Chain
2025's Stealth Loader and AI Exploit Wave: How Multi-Vector Attacks Redefined Cybersecurity
In late 2025, a coordinated wave of global cyber attacks leveraged stealthy multi-vector campaigns with commodity loaders, AI-powered exploits, and social engineering. Attackers weaponized legitimate tools like Nezha for post-exploitation, orchestrated large-scale phishing using fake updates and PoC exploits, and targeted both enterprise and consumer platforms. These campaigns saw loaders like Caminho deliver diverse malware such as XWorm, PureLogs, and RATs into manufacturing, government, and IT networks across several regions. Simultaneously, attackers abused vulnerabilities in AI assistants and exploited weaknesses in NFC-enabled Android malware, achieving persistent access, privilege escalation, data exfiltration, and lateral movement—all while skillfully blending malicious traffic with normal system behaviors. This incident highlights a sharp evolution in attack methods as threat actors increasingly favor low-noise, blended tradecraft over traditional smash-and-grab approaches. With the convergence of signature evasion, AI system manipulation, and commodity loader sharing, defenders must shift toward integrated, threat-aware security architectures. These incidents mark a critical inflection point, signaling a persistent rise in invisible, multi-layered threats fueled by automation and attacker collaboration.
8 months ago
Kill Chain
Operation Sentinel: Global Crackdown on African Cybercrime Syndicates in 2024
In June 2024, Operation Sentinel saw a sweeping law enforcement crackdown on African-based cybercrime syndicates, with authorities across 19 countries arresting 574 individuals and recovering over $3 million in illicit funds. The syndicates, operating throughout sub-Saharan Africa, orchestrated widespread business email compromise (BEC), digital extortion, and ransomware attacks. The multi-vector threat campaign exploited unencrypted traffic, lateral movement within networks, and common gaps in segmentation and egress controls. The collective action disrupted dozens of criminal infrastructures, protected strategic sectors, and exposed critical weaknesses across hybrid and cloud-connected environments. This operation underscores the growing collaboration between threat actors spanning continents, the use of sophisticated tactics like lateral movement, and heightened regulatory scrutiny. As hybrid work and cloud adoption accelerate, organizations face increasing risks from financially motivated cybercriminals exploiting east-west security gaps and insufficient threat detection.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports