Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
CISA Flags Fortinet CVE-2025-59718: Improper Signature Verification Under Active Exploitation
In December 2025, CISA added CVE-2025-59718 to its Known Exploited Vulnerabilities catalog, citing confirmed active exploitation targeting Fortinet's multiple products. This vulnerability involves improper verification of cryptographic signatures, allowing attackers to bypass security controls, execute unauthorized code, or escalate privileges on affected devices. Federal agencies, per BOD 22-01, must remediate this critical issue by the mandated deadline to protect their networks. The flaw’s exploitation risks device compromise and potential lateral movement by sophisticated threat actors, with broad implications for data integrity and operational continuity across affected organizations. This alert reflects the escalating trend of attackers rapidly weaponizing supply chain or cryptographic flaws in core network infrastructure. As organizations increasingly rely on complex integrations and encrypted communications, such vulnerabilities underscore persistent challenges in managing risk and ensuring trust in critical systems.
8 months ago
Kill Chain
Parked Domains Weaponized: Inside the 2025 Typosquatting Malvertising Surge
In late 2025, security researchers uncovered that over 90% of parked domains—unused, expired, or misspelled web addresses—were actively redirecting visitors to malicious destinations, including scams, malware, and deceptive subscription offers. Utilizing techniques like device fingerprinting, IP geolocation, and chained redirects, threat actors profited by manipulating the domain parking ecosystem, turning innocuous navigation mistakes into vectors for malware delivery and fraud. The campaign targeted high-profile brands and government offices, often bypassing detection by profiling user access (e.g., residential IPs or VPN use), with some domains weaponized for business email compromise. This incident highlights an alarming shift: parked and typo domains are now a primary malvertising risk, not a minor threat. As domain registration and ad platform policies evolve, attackers rapidly adapt, exploiting weaknesses in digital trust and endpoint security. Organizations must broaden threat detection and policy enforcement to address direct navigation attacks and affiliate-driven malvertising.
8 months ago
Kill Chain
Critical RADIUS MD5 Vulnerability Exposes Hitachi Energy Infrastructure — 2025 Analysis
In December 2025, Hitachi Energy disclosed a critical vulnerability (CVE-2024-3596) impacting their AFS, AFR, and AFF series infrastructure hardware, widely deployed in the global energy sector. The issue centers on improper enforcement of message integrity in RADIUS communications, allowing attackers in a local network to exploit a chosen-prefix collision attack against the MD5 response authenticator. This could let a malicious actor forge RADIUS authentication responses — potentially leading to unauthorized network access, disruption of critical systems, or exfiltration of sensitive data. The flaw carries a CVSS score of 9.0 (critical), but exploitation requires high attack complexity. This case highlights the continued risks posed by legacy authentication protocols and cryptographic weaknesses within operational technology environments. As adversaries increasingly target energy and critical infrastructure supply chains, prioritizing secure authentication and traffic integrity mechanisms is vital to maintaining resilience and regulatory compliance.
8 months ago
Kill Chain
Güralp Systems 2025: Unauthenticated DoS Threat Hits Critical OT Devices
In December 2025, Güralp Systems disclosed a vulnerability affecting its Fortimus, Minimus, and Certimus Series devices, widely deployed in critical manufacturing and infrastructure sectors globally. The flaw (CVE-2025-14466) in the devices' web interface allows unauthenticated attackers on the network to send specially crafted HTTP requests, forcing the web service to restart and causing a temporary denial-of-service (DoS) condition. While the process automatically recovers, repeated exploitation could severely impact system availability for organizations relying on these seismic monitoring instruments. This type of DoS vulnerability is increasingly significant as threat actors increasingly target industrial control devices and operational technology (OT) with low-complexity attacks from unauthenticated vectors. Regulatory scrutiny of ICS network hygiene and cross-industry best practices is intensifying, pushing organizations to proactively address resource allocation and network exposure.
8 months ago
Kill Chain
Opexus 2024 Insider Breach: Lax Vetting Enables Sensitive Federal Data Theft
In February 2024, Opexus, a federal IT services provider, suffered a significant internal data breach at the hands of recently terminated employees, Muneeb and Sohaib Akhter. Despite passing standard background checks, the Akhter twins—who had prior convictions for cybercrimes—were able to exploit their insider access minutes after being fired, deleting and exfiltrating sensitive data from U.S. government agencies, including DHS, IRS, and EEOC. Key company missteps included inadequate offboarding controls, missed red flags in hiring, and delayed user account revocation, compounding the impact on critical federal data and operations. This breach underscores rising risks linked to insider threats, especially among trusted staff with privileged access. Failures in vetting, change management, and technical safeguards contributed to the severity and highlight the urgent need for robust zero trust, continuous monitoring, and improved personnel screening, particularly for organizations entrusted with sensitive public sector data.
8 months ago
Kill Chain
Apple Patches 2025 WebKit Zero-Day Exploits Used in Sophisticated Spyware Attacks
In December 2025, Apple urgently released patches for two zero-day vulnerabilities in its WebKit browser engine—CVE-2025-43529 and CVE-2025-14174—after reports of their exploitation in highly sophisticated attacks targeting specific individuals. Discovered in collaboration with Google's Threat Analysis Group, these vulnerabilities enabled potential arbitrary code execution via malicious web content due to use-after-free and memory corruption flaws. The vulnerabilities overlapped with a mysterious zero-day Google patched in Chrome, underlining the risk of cross-platform exposure via shared components. Affected devices included iOS, iPadOS, and macOS, with rapid patch distribution through emergency security advisories. This incident spotlights a growing trend of highly targeted, advanced exploitation chains, frequently leveraging zero-day flaws used in commercial spyware and state-level operations. It underscores the increasing urgency for organizations and individuals to maintain aggressive patch hygiene and layered endpoint defenses as anonymous, sophisticated exploitations proliferate.
8 months ago
Kill Chain
French Interior Ministry 2024 Email Server Breach: What Happened & Key Lessons
In June 2024, the French Interior Ministry confirmed a significant cyberattack that targeted its internal email servers. Threat actors conducted a sophisticated intrusion into the ministry's IT infrastructure, accessing and potentially exfiltrating sensitive email communications. The breach was detected after suspicious activity was found on the email systems. While no citizen data has reportedly been compromised, the attack forced authorities to rapidly isolate affected servers and implement remedial security protocols, causing temporary disruption to some official communications and raising concerns about government data confidentiality and resilience. This incident is emblematic of an increasing trend of targeted attacks on government email and communication systems. With attackers becoming more adept at breaching core administrative platforms, nations are under heightened pressure to bolster segmentation, encryption in transit, and detection capabilities to safeguard critical infrastructure.
8 months ago
Kill Chain
How Google's 2024 Research Uncovered Chinese APT Exploitation of React2Shell
In June 2024, Google's Threat Analysis Group expanded the attribution of recent attacks exploiting the critical "React2Shell" remote code execution vulnerability to at least five more Chinese nation-state hacking groups. These attackers leveraged the unpatched React2Shell flaw to gain unauthorized access to systems across multiple sectors, using sophisticated spear-phishing and lateral movement techniques to deploy malware and establish persistence. The affected organizations experienced potential data exposure, operational interruptions, and increased remediation costs while scrambling to patch impacted environments. This incident highlights the evolving capabilities and coordination among multiple Chinese APTs targeting software supply chain weaknesses. The React2Shell exploitation surge demonstrates a significant escalation in the speed and scale of zero-day abuse by coordinated state-affiliated groups. Organizations face heightened urgency to accelerate vulnerability management and enhance east-west traffic monitoring as attackers rapidly weaponize public vulnerabilities.
8 months ago
Kill Chain
VolkLocker Ransomware Thwarted by Leaked Master Key: Lessons from the CyberVolk 2025 Attack
In August 2025, the pro-Russian hacktivist group known as CyberVolk (aka GLORIAMIST) launched VolkLocker, a new ransomware-as-a-service aimed at both Windows and Linux systems. SentinelOne researchers discovered that VolkLocker suffered a critical security flaw: a hard-coded master key was inadvertently left in test artifacts, enabling anyone to decrypt files encrypted by the ransomware, bypassing ransom payments. Attackers used typical RaaS deployment methods, leveraging phishing and malicious attachments for initial access. While the group attempted to extort victims, the encryption flaw significantly undermined their efforts. The incident highlights the increased frequency and complexity of ransomware-as-a-service offerings, while underscoring the role of sloppy operator security in containing damage. As similar attacks proliferate, organizations must prioritize incident response and security validation against emerging threats.
8 months ago
Kill Chain
CISA Adds Apple & Gladinet Vulnerabilities to Known Exploited List (2025)
In December 2025, the Cybersecurity & Infrastructure Security Agency (CISA) added CVE-2025-14611 (Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability) and CVE-2025-43529 (Apple Multiple Products Use-After-Free WebKit Vulnerability) to its Known Exploited Vulnerabilities (KEV) Catalog following confirmed reports of active exploitation. These flaws allow attackers to gain unauthorized access, execute arbitrary code, and compromise sensitive data by leveraging weaknesses in encryption and browser components. Federal Civilian Executive Branch (FCEB) agencies are mandated to remediate these vulnerabilities by the stipulated deadlines to mitigate risks to critical government infrastructure. These additions reflect an ongoing surge in sophisticated vulnerability exploitation targeting both proprietary business platforms and widely used consumer products. Emerging attacker tactics and the regulatory environment reinforce the importance of robust, timely vulnerability management—underscoring that prioritizing patching of KEV-listed CVEs is now a best practice for all organizations.
8 months ago
Kill Chain
VolkLocker 2025: Flaw in CyberVolk Ransomware Lets Victims Self-Decrpyt
In December 2025, the pro-Russia hacktivist group CyberVolk launched a new version of its VolkLocker ransomware-as-a-service (RaaS), targeting public sector and government organizations. The attackers leveraged Telegram automation for command-and-control, and conducted attacks on both Windows and Linux systems. However, investigators discovered a critical flaw: the ransomware stored its master encryption key in plaintext in the %TEMP% directory, allowing victims to recover encrypted files independently without paying ransom. This lapse likely resulted from debug functionality inadvertently left in production, significantly weakening the group's operations and credibility. This incident is highly relevant as ransomware groups are modernizing with advanced automation—but basic operational mistakes can undermine even sophisticated threat actors. For blue teams, it offers a real-world example of why continuous code auditing and rapid incident response are crucial, while for attackers, it’s a cautionary tale regarding quality control in criminal tooling.
8 months ago
Kill Chain
10 Critical November 2025 CVEs: Quality Over Quantity in Exploitation Trends
In November 2025, a sharp 69% drop in reported critical vulnerabilities masked a surge in the intensity of exploitation campaigns. Threat intelligence from Recorded Future revealed 10 high-risk CVEs—including two critical Fortinet FortiWeb flaws—actively targeted by threat actors. Notably, the LANDFALL spyware campaign weaponized Samsung's image processing vulnerability for zero-click remote attacks, while seven of ten vulnerabilities had public proof-of-concept code released. Vulnerabilities included OS command injection, out-of-bounds writes, access control failures, and issues affecting major vendors such as Microsoft, Oracle, and Google. This incident highlights how attackers are shifting to fewer but far more impactful vulnerabilities, emphasizing quality over quantity in their exploitation. Security teams must adapt, maintaining vigilance even during perceived lulls and prioritizing fast patching, advanced monitoring, and comprehensive exposure management to counter rapidly evolving threats.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports