Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Automated Credential Attacks Storm Cisco & Palo Alto Networks VPNs
In December 2025, automated credential attacks targeted enterprise VPN gateways from Cisco and Palo Alto Networks. Threat monitoring platforms such as GreyNoise observed a surge of password spraying attempts, with 1.7 million login probes against Palo Alto GlobalProtect portals within 16 hours, and coordinated activity later targeting Cisco SSL VPNs. The attacks originated from over 10,000 unique IPs, predominantly routed through the 3xK GmbH cloud provider in Germany. Attackers employed scripted credential stuffing—leveraging common username and password combinations—to probe for weak authentication endpoints, with no evidence of software vulnerabilities being exploited. This campaign highlights the ongoing evolution and scale of credential-based attacks targeting critical remote access infrastructure. As password spraying and automated reconnaissance increase, robust authentication and monitoring remain pivotal to defending against perimeter breaches, especially as threat actors exploit enterprise weaknesses during periods of heightened cyber activity.
8 months ago
Kill Chain
HPE OneView 2025: CVE-2025-37164 Remote Code Execution Threat
In June 2025, Hewlett Packard Enterprise (HPE) patched a critical vulnerability (CVE-2025-37164) in its OneView infrastructure management software, allowing unauthenticated remote code execution via network exposure. Rated CVSS 10.0, the flaw enabled threat actors to gain full control over affected systems by exploiting improper input validation in OneView’s remote management interfaces. This vulnerability posed immediate risk to critical infrastructure across industries relying on OneView for centralized management, potentially resulting in disruption, unauthorized access, or lateral movement within enterprise environments. The discovery highlights ongoing concerns around enterprise software supply chain security and the elevated threats facing privileged IT management tools. Increasingly, sophisticated threat actors target such infrastructure software to bypass traditional security controls, emphasizing the urgency for timely patching and advanced east-west traffic controls.
8 months ago
Kill Chain
University of Sydney 2024 Data Breach Exposes Student and Staff Details
In June 2024, the University of Sydney disclosed a data breach following unauthorized access to an online coding repository. Attackers exfiltrated files containing personal information of students and staff by exploiting weak access controls on the system. The breach was identified after suspicious activity was detected, prompting immediate investigation and containment steps by the university. Impacted data reportedly includes names, contact details, and university credentials, potentially exposing the affected individuals to heightened phishing and identity theft risks. This breach underscores increasing attacks on educational institutions using supply chain and cloud repository vectors. With universities under pressure to rapidly digitize, protecting developer and collaboration tools has become critical amid surging credential-based attacks and regulatory scrutiny of personally identifiable information (PII) handling.
8 months ago
Kill Chain
Sha1-Hulud 2025: The Multi-Vector Threat Campaign that Redefined Cloud Security
In December 2025, security researchers observed a sophisticated multi-vector attack campaign, dubbed 'Sha1-Hulud,' targeting organizations across North America, Europe, and Asia. The campaign leveraged vulnerabilities in remote management tools such as ScreenConnect and MacSync to gain initial access, then proceeded laterally using encrypted traffic, zero trust segmentation evasion, and cloud-native pivoting. Attackers deployed covert remote access tools and exploited gaps in cloud firewall and egress controls to move data out, leaving organizations grappling with data theft, systems downtime, and regulatory exposure. This incident is notable for its integration of advanced encryption bypass, multicloud movement, and the blending of traditional and cloud-native evasion tactics. The convergence of infrastructure and cloud threats highlights the need for ubiquitous visibility, modern segmentation, and coordinated policy enforcement in response to increasingly diverse and distributed attacks.
8 months ago
Kill Chain
Axis Communications 2025: Critical Camera System Vulnerabilities Threaten OT Security
In December 2025, Axis Communications disclosed multiple critical vulnerabilities affecting their Camera Station Pro, Camera Station, and Device Manager products. The issues, discovered by cybersecurity researchers from Claroty Team82, include flaws such as deserialization of untrusted data, improper certificate validation, authentication bypass, and local privilege escalation. These vulnerabilities could allow an attacker to remotely execute arbitrary code, intercept communications via man-in-the-middle attacks, or bypass authentication mechanisms, significantly compromising the security posture of organizations using these systems globally. Patches are now available and users are urged to upgrade immediately. This incident highlights a growing trend in targeting surveillance and control infrastructure, reflecting the increased attention threat actors are placing on operational technology and critical manufacturing environments. The convergence of IT and OT risks, as well as heightened regulatory expectations, make robust security controls for IoT and camera systems more critical than ever.
8 months ago
Kill Chain
Advantech WebAccess/SCADA 2025: Critical Vulnerabilities Threaten Industrial Control Systems
In December 2025, critical vulnerabilities were disclosed in Advantech WebAccess/SCADA software (version 9.2.1), widely used across critical manufacturing, energy, and water infrastructure worldwide. Discovered by Pellera Technologies, the weaknesses included multiple instances of path traversal (CVE-2025-14850, CVE-2025-67653, CVE-2025-14848), unrestricted file upload (CVE-2025-14849), and SQL injection (CVE-2025-46268). Exploitation could enable a remote, authenticated attacker to read or modify sensitive database content, delete files, or execute arbitrary code on impacted systems, significantly increasing cyber-physical risk for operations. Advantech advised immediate upgrades to v9.2.2 to remediate these flaws. This incident underscores ongoing challenges in the security of industrial control systems amid rising cyber threats targeting critical infrastructure. With no current evidence of public exploitation, practitioners must remain vigilant due to the highly impactful nature of the vulnerabilities and their corresponding attack surface across essential industries.
8 months ago
Kill Chain
Cellik RAT’s Google Play Store Infiltration Exposes Mobile Security Gaps
In June 2024, cybersecurity researchers uncovered that the Cellik Android Remote Access Trojan (RAT) was being distributed through malicious applications on the official Google Play Store. The Cellik RAT allows attackers to remotely control infected Android devices, harvest sensitive credentials, and exfiltrate private data without the user’s knowledge. Threat actors used advanced evasion tactics, including app generation within Play Store guidelines and encrypted communications, to bypass traditional defenses. The incident highlights weaknesses in mobile app review processes and demonstrates the continued use of popular app stores as distribution vectors for sophisticated malware campaigns. This breach is especially notable as attackers continue to exploit trusted platforms like the Google Play Store, elevating risk for both individuals and enterprises. The emergence of Cellik marks an uptick in mobile RAT sophistication and underscores the urgent need for stronger app vetting and threat detection on mainstream digital ecosystems.
8 months ago
Kill Chain
Critical Fortinet Flaws: Active Attacks Compromise Admin Accounts & Configs
In May 2024, threat actors began actively exploiting multiple critical vulnerabilities in Fortinet network devices, specifically targeting admin accounts to gain unauthorized access. Once authenticated, attackers exported sensitive device configurations containing hashed credentials and other proprietary information. The exploit allows lateral movement and increases the risk of sensitive enterprise data exposure, with widespread impacts noted across sectors relying on network infrastructure security. Fortinet urged immediate mitigation after observing attacks in the wild, with rapid patch releases and threat intelligence sharing. This incident highlights a concerning trend of attackers leveraging zero-day or freshly-disclosed vulnerabilities in widely deployed network appliances. As targeting of privileged accounts and network infrastructure rises, organizations must enhance monitoring, patch management, and segmentation strategies to prevent systemic compromise.
8 months ago
Kill Chain
Dormant No More: Prince of Persia APT's Sophisticated Espionage Tactics Unveiled in 2025
In December 2025, security researchers revealed that the dormant Iranian advanced persistent threat (APT) group "Prince of Persia" (also known as "Infy") had remained operational for years, despite perceived inactivity. Leveraging upgraded versions of their Foudre and Tonnerre malware families, the group engaged in persistent cyber espionage targeting Iranian dissidents, as well as individuals in Iraq, Turkey, India, Europe, and Canada. The attackers employed advanced cryptographic techniques for command-and-control (C2) communication—such as RSA signature verification for dynamically generated C2 domains and Telegram-based channels—enabling stealthy, resilient infrastructure and evading traditional detection or takedown efforts. The group’s sophisticated use of operational security, government support, and resilient infrastructure sets it apart from typical regional APTs. This incident underscores increasing sophistication among state-backed APT groups and highlights modern approaches to persistence and evasion, particularly as threat actors adopt novel uses of cryptography and messaging platforms for infrastructure protection. It warns organizations worldwide to review their readiness against stealthy advanced campaigns that evade known countermeasures.
8 months ago
Kill Chain
React2Shell Breach: 2025’s Most Widespread Mass Exploitation Campaign
In December 2025, the React2Shell vulnerability (CVE-2025-55182) triggered a global mass exploitation campaign targeting organizations across critical infrastructure, government, and private sectors. Following public disclosure, a record number of exploits surfaced, enabling unauthenticated attackers to gain remote code execution, deploy backdoors, and move laterally within networks. High-profile cybercriminal, ransomware, and nation-state actors—including several Chinese espionage groups—converged to leverage React2Shell for data theft, ransomware deployment, and persistent access. More than 60 organizations confirmed compromise, with hundreds of machines affected, some suffering rapid ransomware execution within minutes of initial access. This incident is notable for both its rapid exploitation timeline and evolving threat actor diversity. The widespread availability of public exploits and patch bypasses underscores the urgent need for robust patch management, active detection, east-west traffic controls, and zero trust segmentation as attackers swiftly weaponize newly disclosed vulnerabilities at unprecedented speed.
8 months ago
Kill Chain
Microsoft 2025 MSMQ and IIS Outage: A Cautionary Tale of Security Permissions Gone Wrong
In December 2025, Microsoft enterprise customers experienced widespread outages in applications and IIS web services following the deployment of Patch Tuesday updates (KB5071546, KB5071544, KB5071543). These updates introduced changes to the Message Queuing (MSMQ) security model, restricting NTFS permissions on the C:\Windows\System32\MSMQ\storage folder. As a result, non-administrator MSMQ users lost write access, causing MSMQ to fail and IIS sites to return misleading 'insufficient resources' errors. This affected core business processes dependent on MSMQ, with no immediate fix available; Microsoft urged affected organizations to reach out for mitigation guidance. This incident highlights ongoing risks from software supply chain updates and privileged permission management changes at the operating system level. As cloud workloads and zero-trust architectures become more prevalent, enterprises must strengthen configuration management and anomaly response to avoid business disruption from untested or misconfigured OS-level security changes.
8 months ago
Kill Chain
DOJ Takes Down E-Note: Ransomware Laundering Hub Disrupted in 2024 Crackdown
In early 2024, the US Department of Justice, in partnership with international law enforcement, dismantled the E-Note cryptocurrency exchange—a major online infrastructure used for laundering illicit proceeds from ransomware and cybercrime. Authorities indicted Mykhalio Petrovich Chudnovets, a Russian national alleged to have operated E-Note since 2010, with facilitating the transfer of over $70 million in stolen or extorted funds from attacks targeting sectors like healthcare and critical infrastructure. Federal and state agencies seized E-Note servers, websites, and mobile apps, obtaining customer and transaction data to further map criminal networks. This takedown highlights cybercriminals’ growing use of specialized laundering platforms to enable ransomware and account takeover monetization at scale. As regulatory scrutiny intensifies and attacker infrastructure becomes more modular and resilient, law enforcement action against these enablers is an increasing priority.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports