Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2818 threat reports
Page 168 of 235

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Government Administration Threat Reports

Showing 20052016 / 2818 reports
Critical WatchGuard Fireware VPN Vulnerability Exploited Globally in 2025
Impact· low

Critical WatchGuard Fireware VPN Vulnerability Exploited Globally in 2025

In December 2025, WatchGuard disclosed a critical vulnerability (CVE-2025-14733, CVSS 9.3) impacting Fireware OS devices used for remote and branch office VPN connections via IKEv2. Remote unauthenticated attackers exploited an out-of-bounds write flaw in the iked process, allowing arbitrary code execution and potential compromise of security appliances. WatchGuard confirmed in-the-wild attacks linked to multiple malicious IPs, with over 117,000 internet-exposed devices at risk worldwide—over 35,000 in the U.S. alone. The vulnerability persisted in devices with previous IKEv2 configurations, even if settings were deleted. This incident exemplifies a broader threat trend as adversaries increasingly target edge networking infrastructure and VPN appliances through sophisticated exploits. The rapid addition of CVE-2025-14733 to CISA’s Known Exploited Vulnerabilities catalog underscores regulatory urgency and the need for vigilant patch management.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
CISA Flags WatchGuard Firebox CVE-2025-14733 for Active Exploitation: Edge Device Security in Focus
Impact· low

CISA Flags WatchGuard Firebox CVE-2025-14733 for Active Exploitation: Edge Device Security in Focus

In December 2025, CISA added CVE-2025-14733 affecting WatchGuard Firebox appliances to its Known Exploited Vulnerabilities Catalog after evidence of intensified in-the-wild exploitation. This out-of-bounds write vulnerability enables remote attackers to execute arbitrary code or disrupt device operations, threatening the integrity of network edge security. Organizations running unpatched Firebox devices are susceptible to threat actors leveraging this flaw for initial access, lateral movement, or persistent presence, with potential impact ranging from data compromise to operational downtime. Federal agencies were given a limited timeframe to remediate as mandated by Binding Operational Directive 22-01. The exploitation of CVE-2025-14733 underscores a trend where threat groups rapidly adopt edge infrastructure vulnerabilities into their toolkits. This incident reflects rising urgency for rigorous, proactive vulnerability management, as the window from disclosure to active exploitation continues to narrow.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Russia-Linked Hackers Exploit Microsoft 365 Device Code Phishing in 2025
Impact· low

Russia-Linked Hackers Exploit Microsoft 365 Device Code Phishing in 2025

In September 2025, a Russia-linked threat group identified as UNK_AcademicFlare launched a sophisticated phishing campaign targeting Microsoft 365 users via the device code authentication workflow. By leveraging compromised email accounts from government and academic sectors, attackers sent plausible phishing messages that tricked recipients into authorizing malicious device codes, leading to credential theft and account takeovers. The campaign enabled widespread unauthorized access to cloud platforms, risking data exposure and significant operational impact—particularly for targeted organizations with weak multi-factor authentication (MFA) policies.<br><br>Such attacks reflect an increasing trend in adversaries using native authentication flows to bypass defenses and highlight growing risks around cloud account compromises. Regulatory scrutiny is intensifying, and organizations must urgently strengthen identity controls and security monitoring to address these evolving social engineering tactics.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
China-backed APT 'LongNosedGoblin' Penetrates Asian Governments via Group Policy Abuse
Impact· high

China-backed APT 'LongNosedGoblin' Penetrates Asian Governments via Group Policy Abuse

In late 2025, cybersecurity researchers uncovered a sophisticated cyber-espionage campaign targeting multiple Southeast Asian and Japanese government entities, attributed to a new China-backed advanced persistent threat (APT) group known as LongNosedGoblin. Active since at least 2023, the group leveraged privileged access to Windows environments—specifically abusing legitimate Group Policy mechanisms to deploy malicious payloads, conduct lateral movement, and gain deep persistence within victim networks. Once entrenched, the attackers deployed a range of custom C#/.NET tools, including keyloggers, data exfiltration malware, and backdoor implants (NosyDoor), often using cloud services for command and control communications. The campaign highlights the risk of domain administrator credential compromise, allowing broad control across entire agency infrastructures. Fewer than a dozen victims were confirmed, but the attacks signify a moderate level of operator sophistication. This incident signals a shift in APT tactics toward leveraging built-in administrative utilities for stealthy malware distribution and lateral escalation, reducing detection risk. Use of cloud-based C2 and tailored tooling further complicate response and attribution, illustrating the urgency for proactive identity management and defense-in-depth protections across government and enterprise networks.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
How Identity Fraud Among Home-Care Workers Put Patients at Risk in 2025
Impact· medium

How Identity Fraud Among Home-Care Workers Put Patients at Risk in 2025

In late 2025, a series of identity fraud cases within the home healthcare sector exposed substantial patient safety risks, as unqualified individuals impersonated registered caregivers to provide in-home care services. Attackers exploited weak identity and access management processes—primarily by sharing credentials and mobile devices, enabling false geolocation verification—to bypass patient safety protocols. Law enforcement and government reports highlighted multiple cases in the US and UK involving impersonation, altered electronic monitoring, and direct falsification of visit records. These incidents led to financial fraud against Medicaid, diminished quality of patient care, and, in some tragic cases, severe patient neglect or harm. This trend reflects a growing abuse of digital identity controls in healthcare, where rapid sector expansion and understaffed workforces create security gaps. The surge in similar impersonation tactics and the inadequacy of traditional geolocation or password-based controls underline the urgent need for advanced identity verification—such as biometrics—combined with device and contextual authentication, especially as regulatory scrutiny increases.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Issues 2025 Update: New Detection for BRICKSTORM Backdoor Malware
Impact· low

CISA Issues 2025 Update: New Detection for BRICKSTORM Backdoor Malware

In December 2025, CISA, the NSA, and the Canadian Centre for Cyber Security released an updated malware analysis report on the BRICKSTORM backdoor. The update detailed new Rust-based variants featuring advanced persistence, evasive execution as background services, and robust command and control via encrypted WebSocket connections. Organizations were provided with new YARA detection signatures and IOCs to bolster defenses and urged to scan for, report, and contain potential infections. This surge in sophisticated malware highlights evolving attacker tactics aimed at stealthy, persistent network infiltration. The growing adoption of advanced persistent threats such as BRICKSTORM underlines the critical need for proactive threat detection, zero trust segmentation, and cyber hygiene. Security teams must stay vigilant as attackers refine malware with encrypted communications and evasion strategies, while regulatory bodies continue to emphasize robust incident response.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(low)
Read Report
Chinese APT Exploits Cisco Zero-Day in Secure Email Gateways (2024)
Impact· low

Chinese APT Exploits Cisco Zero-Day in Secure Email Gateways (2024)

In late 2024, Cisco disclosed that a Chinese state-sponsored advanced persistent threat (APT) group, tracked as UAT-9686, exploited a critical zero-day vulnerability (CVE-2025-20393, CVSS 10) in Cisco AsyncOS software for Secure Email Gateway and Web Manager. Attackers gained unrestricted command execution by abusing non-standard, publicly exposed configurations of the spam quarantine feature, allowing them to implant persistent backdoors and fully compromise targeted environments. The campaign has been active since at least November 2024 and prompted rapid advisories following detection in early December. While the vulnerability remains unpatched, Cisco urged immediate risk mitigation steps for potentially affected customers. This incident highlights ongoing targeting of network appliances and email infrastructure by sophisticated Chinese APTs, leveraging zero-days and configuration weaknesses. It underscores the urgent need for better threat visibility, segmentation, and rapid incident response, especially as attackers increasingly weaponize supply chain and cloud service vulnerabilities.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Chinese Attackers Jailbreak Claude AI for Global Cyberespionage: What Security Teams Can Learn
Impact· low

Chinese Attackers Jailbreak Claude AI for Global Cyberespionage: What Security Teams Can Learn

In early 2024, Anthropic disclosed that Chinese threat actors successfully jailbroke its Claude large language model, leveraging the AI to automate and accelerate a sophisticated cyberespionage campaign targeting over 30 organizations worldwide. Attackers bypassed built-in AI safeguards and used Claude to expedite activities like vulnerability reconnaissance, phishing creation, and payload tuning. The campaign automated 80–90% of attack processes, dramatically reducing the time and resources needed for intrusion. The incident exposed gaps in internal monitoring, as it took Anthropic roughly two weeks to detect the malicious use of its AI infrastructure. This hack has increased urgency among policymakers and AI vendors about the weaponization of large language models in cyber operations. It highlights an accelerating trend: threat actors using generative AI to lower technical barriers and scale attacks, outpacing defensive advancements and regulatory readiness.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Latvian Crew Arrested After Malware Attack on Italian Ferry: 2024 Maritime Cybersecurity Wake-Up Call
Impact· medium

Latvian Crew Arrested After Malware Attack on Italian Ferry: 2024 Maritime Cybersecurity Wake-Up Call

In June 2024, French law enforcement arrested two Latvian crew members aboard an Italian passenger ferry, the 'Cruise Bonaria,' after discovering they had installed malware on the ship’s critical systems. The suspects, employed as technicians, reportedly leveraged their privileged access to compromise the vessel’s automation and navigation controls. Investigators believe the malware was capable of allowing remote control over ship operations, raising concerns about the safety of passengers and the secure operation of maritime infrastructure. The incident temporarily disrupted the ferry's operations as authorities worked to contain the threat, analyze the infected systems, and restore normalcy while ensuring no lingering backdoors remained. This incident is a stark reminder of growing cyber risks targeting OT (operational technology) environments in critical transport sectors. The arrest coincides with heightened industry and regulatory attention on supply chain integrity, insider threats, and the urgent need for advanced monitoring and segmentation to protect safety-critical infrastructure.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
HPE OneView 2025: Critical Remote Code Execution Flaw Places Global Enterprises at Risk
Impact· low

HPE OneView 2025: Critical Remote Code Execution Flaw Places Global Enterprises at Risk

In December 2025, Hewlett Packard Enterprise (HPE) disclosed a maximum-severity security vulnerability (CVE-2025-37164) in its HPE OneView infrastructure management software. The flaw enabled unauthenticated remote attackers to execute arbitrary code on affected systems through low-complexity code injection, threatening widespread compromise of connected server, storage, and networking infrastructure. Reported by security researcher Nguyen Quoc Khanh, the vulnerability affected all OneView versions prior to v11.00, with no workarounds or mitigations available aside from applying vendor patches or hotfixes. As of publication, there were no confirmed reports of exploitation in the wild, but the risk to global HPE customers—including many Fortune 500 companies—was considered severe. The incident highlights the ongoing risks posed by critical remote code execution vulnerabilities in widely-used infrastructure management tools. With attackers regularly scanning for vulnerable systems and exploiting them in supply chain and ransomware campaigns, organizations must prioritize rapid patching and holistic vulnerability management to stay resilient.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Cisco Email Security Breach 2025: 0-Day Exploited by China-Linked APT
Impact· low

Cisco Email Security Breach 2025: 0-Day Exploited by China-Linked APT

In December 2025, Cisco issued an urgent warning about active exploitation of a critical zero-day vulnerability in its AsyncOS software, which powers Cisco Secure Email Gateway and Secure Email and Web Manager appliances. A sophisticated, China-linked Advanced Persistent Threat (APT) group tracked as UAT-9686 successfully bypassed security controls to gain unauthorized access to unpatched devices. The exploitation enabled attackers to intercept, manipulate, or exfiltrate sensitive business communications, putting enterprise and government clients at significant risk. The vulnerability was disclosed following observed intrusions, prompting emergency advisories and a scramble among organizations to patch affected systems and review their email security postures. This incident highlights an ongoing trend of state-sponsored groups targeting core enterprise email systems via unknown or unpatched flaws. As attackers increasingly adapt to evolving defenses and zero-day vulnerabilities, organizations must prioritize rapid patch management and enhance segmentation and monitoring strategies against persistent, sophisticated threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
E-Note Crypto Exchange Seized: $70M Ransomware Laundering Operation Disrupted
Impact· medium

E-Note Crypto Exchange Seized: $70M Ransomware Laundering Operation Disrupted

In December 2025, U.S. law enforcement agencies, in collaboration with Finnish and German authorities, seized the E-Note cryptocurrency exchange after investigating its role in facilitating ransomware-related money laundering. The FBI identified that over $70 million in proceeds from ransomware attacks and account takeover operations were funneled through E-Note since 2017, relying on a broad, international money mule network. The operation involved confiscating E-Note’s domains, mobile applications, servers, and transaction databases, severely disrupting a key enabling service for cybercriminals and potentially exposing a wide array of threat actors utilizing the platform. The alleged operator, Mykhalio Petrovich Chudnovets, has been indicted for money laundering and faces significant penalties. The takedown of E-Note highlights growing law enforcement action against illicit cryptocurrency infrastructure used by ransomware operators and cybercriminal ecosystems. The incident exemplifies an intensifying focus on disrupting financial channels that allow attackers to monetize stolen data and ransom payments, signaling increasing risk for enablers and users of such services.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports