Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Legal Filing Prompt Injection Attack: When AI Security Meets the Courtroom
In August 2026, a novel attack vector emerged where an individual embedded hidden AI instructions within a legal court filing, attempting to manipulate AI systems that might process the document to rule in their favor. This prompt injection attack represents a sophisticated evolution of adversarial AI techniques, moving beyond traditional digital platforms into legal and governmental processes. The incident demonstrates how threat actors are adapting prompt injection methods to exploit AI systems in critical decision-making contexts, potentially compromising judicial integrity and administrative processes. This incident highlights the growing urgency around AI security as organizations increasingly deploy AI systems for document processing, legal research, and decision support. With the rapid adoption of AI in government, healthcare, and enterprise environments, similar prompt injection attacks could target any AI-powered system that processes external documents or user inputs.
2 weeks ago
Kill Chain
TerminalFix Malware Campaign Exploits Fake Cloudflare CAPTCHAs for Enterprise Network Access
In August 2026, Microsoft disclosed a sophisticated social engineering campaign called TerminalFix that uses fake Cloudflare CAPTCHA verifications on compromised websites to trick users into executing malicious PowerShell commands. The attack employs a multi-stage process involving DLL sideloading, steganographic payload extraction, Active Directory reconnaissance, and deployment of a Python-based reverse-tunnel implant that provides persistent network-level proxy access to attackers. This campaign represents a dangerous evolution of ClickFix techniques, specifically targeting enterprise environments across multiple sectors with the ability to escalate privileges, bypass security controls, exfiltrate data, and deploy ransomware. This incident highlights the growing sophistication of social engineering attacks that combine legitimate-looking interfaces with advanced post-exploitation techniques, reflecting the increased threat landscape complexity organizations face as attackers adapt their methods to bypass traditional security controls.
3 weeks ago
Kill Chain
TerminalFix Campaign: When Fake CAPTCHAs Lead to Network Tunneling
Microsoft Threat Intelligence discovered the TerminalFix campaign in August 2026, a sophisticated evolution of ClickFix attacks targeting organizations across multiple industries. The campaign uses compromised websites displaying fake Cloudflare CAPTCHA verification overlays to trick users into executing malicious PowerShell commands through Windows Terminal. Unlike traditional ClickFix variants that deliver single infostealers, TerminalFix deploys a complex multi-stage attack chain combining DLL sideloading, steganographic payload extraction from PNG images, extensive Active Directory reconnaissance, and a custom Python-based reverse tunnel implant that provides persistent network-level proxy access through compromised hosts. This campaign represents a significant escalation in social engineering attacks, as it transforms victim machines into network pivot points for lateral movement and potential ransomware deployment. The sophisticated combination of legitimate binary abuse, steganographic concealment, and persistent tunneling capabilities demonstrates advanced threat actor evolution in bypassing modern security controls.
3 weeks ago
Kill Chain
ATF Breach Exposes Critical Need for Federal Cybersecurity Enhancement
In early 2025, the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a cyberattack on a standalone computer system containing sensitive information about investigation targets. The Qilin ransomware group, a Russian-speaking financially-motivated threat actor, claimed responsibility for the breach. ATF officials quickly isolated the affected system, which was not connected to other agency networks including case management or laboratory systems. The incident was classified as a major incident by senior ATF officials, though the agency maintained its operational capabilities remained unaffected. This attack represents a concerning escalation in ransomware targeting against federal law enforcement agencies. The Qilin group has become one of the most active global ransomware threats since 2022, claiming hundreds of victims across more than 60 countries. Their targeting of a federal law enforcement agency marks a significant shift in threat actor boldness, particularly given the sensitive nature of ATF investigation data and the unlikely prospect of ransom payment from a government entity.
3 weeks ago
Kill Chain
ServiceNow AI Platform Hit by Three Critical Security Vulnerabilities
ServiceNow disclosed three critical maximum-severity vulnerabilities (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) in its AI Platform affecting over 100,000 enterprise applications at 85% of Fortune 500 companies. The flaws enable unauthenticated attackers to execute code injection, SQL injection, and privilege escalation attacks without user interaction. While no active exploitation has been confirmed, ServiceNow's history of targeted attacks and the platform's extensive enterprise adoption create significant risk exposure across critical business workflows. This disclosure highlights the growing attack surface of AI-integrated enterprise platforms as threat actors increasingly target foundational business infrastructure. The timing coincides with heightened scrutiny of platform security following recent high-profile breaches of similar enterprise SaaS providers.
3 weeks ago
Kill Chain
Critical Gitea Vulnerability Exposes 8,300+ Development Servers to Code Execution Attacks
Over 8,300 Internet-exposed Gitea servers remain vulnerable to CVE-2026-60004, a critical code injection flaw that allows authenticated attackers to execute arbitrary shell commands through the diffpatch API endpoint. The vulnerability, reported by Salesforce security researcher Shai Rod, enables remote code execution with Gitea service account privileges by submitting malicious patches. With Gitea's default self-registration feature enabled, unauthenticated attackers can register accounts, create repositories, and exploit the flaw without prior credentials. Despite patches being available since July 27, 2026, threat actors are actively exploiting unpatched servers to deploy cryptocurrency mining malware. This incident highlights the growing threat landscape targeting DevOps infrastructure and self-hosted development platforms. As organizations increasingly adopt cloud-native development practices and hybrid environments, securing code repositories and CI/CD pipelines has become critical to preventing supply chain attacks and protecting intellectual property.
3 weeks ago
Kill Chain
ownCloud Vulnerability CVE-2023-49105 Exploited in Philippine Nuclear Espionage Campaign
In August 2026, a Chinese-speaking threat actor exploited CVE-2023-49105, a critical ownCloud WebDAV authentication bypass vulnerability, to steal sensitive nuclear research data from a Philippine research body. The attacker used custom Python scripts to exploit the flaw's pre-signed URL mechanism, downloading 176 files totaling 372 MB including nuclear material records, strategic plans, reactor components, and employee data. The incident also involved a parallel attack on a Philippine marine engineering company serving the Navy, exploiting CVE-2024-28000 in WordPress LiteSpeed Cache plugin, highlighting coordinated cyber espionage targeting Philippine defense and nuclear sectors. This incident underscores the escalating cyber threats targeting critical infrastructure in the Asia-Pacific region amid South China Sea tensions, with state-affiliated actors increasingly focusing on nuclear and defense-related intelligence gathering through unpatched cloud collaboration platforms.
3 weeks ago
Kill Chain
PaperCut Zero-Day Exploits Force Double Emergency Patches for Critical RCE Flaws
In August 2026, PaperCut released emergency patches for two actively exploited zero-day vulnerabilities (CVE-2026-82078 and CVE-2026-81578) affecting PaperCut NG and MF print management software. The vulnerabilities allowed unauthenticated attackers to bypass authentication and achieve remote code execution on vulnerable servers. After security researchers discovered multiple bypass techniques for the initial patches, PaperCut was forced to release a second emergency patch with additional hardening measures. The attacks appear to be limited and targeted, with threat actors conducting system reconnaissance on compromised servers. This incident highlights the persistent threat to network-accessible management interfaces and the growing sophistication of attackers who can quickly develop bypass techniques for security patches. It underscores the critical importance of implementing zero-trust network segmentation and egress controls to limit the impact of successful initial compromises.
3 weeks ago
Kill Chain
Critical PaperCut Vulnerability Chain Enables Unauthenticated Remote Code Execution
In August 2026, threat actors actively exploited two chained vulnerabilities in PaperCut NG and MF print management software to achieve unauthenticated remote code execution. CVE-2026-81578 (CVSS 8.8) allows attackers to bypass authentication through improper access control, while CVE-2026-82078 (CVSS 9.4) enables unsafe dynamic class loading for arbitrary code execution. Huntress researchers observed limited exploitation targeting internet-facing instances, with attackers performing reconnaissance commands and deploying Java payloads to fingerprint systems and exfiltrate data before cleaning up evidence. This incident highlights the growing trend of vulnerability chaining attacks targeting enterprise infrastructure software, particularly as organizations increasingly rely on cloud-connected print management systems that often lack proper network segmentation and access controls.
3 weeks ago
Kill Chain
Berlin Government Refuses Ransom After Rhysida Steals 5.79TB of Citizen Data
In August 2026, the Rhysida ransomware group successfully infiltrated Berlin's state administrative network, exfiltrating 5.79 terabytes of data including personal information on over 12,000 individuals between August 7-12. The attackers gained initial access through compromised VPN credentials and deployed double extortion tactics, demanding ransom payment while threatening to leak stolen government data. Berlin's leadership, including Governing Mayor Kai Wegner, publicly refused to pay the ransom despite ongoing extortion attempts, maintaining operations while conducting forensic investigation with federal authorities. This incident highlights the continued evolution of ransomware groups targeting critical government infrastructure, particularly as threat actors like Rhysida increasingly focus on high-profile public sector victims to maximize pressure and potential payouts through leaked sensitive citizen data.
3 weeks ago
Kill Chain
NovaCookies Phishing Campaign Weaponizes DocuSign to Hijack Microsoft 365 Sessions
NovaCookies, a subscription-based phishing platform advertised on Telegram for $320 monthly, has compromised hundreds of organizations across the U.S., U.K., Germany, and U.A.E. by systematically targeting Microsoft 365 sessions. Operating as an Adversary-in-the-Middle proxy, the platform exploits legitimate DocuSign services to deliver counterfeit document-sharing notifications that bypass standard security filters. The attack uses OAuth error-redirect techniques to guide victims through legitimate Microsoft endpoints before routing them to phishing infrastructure, enabling real-time theft of credentials and multi-factor authentication codes. This incident highlights the evolving sophistication of phishing-as-a-service platforms that leverage trusted cloud services to evade detection, representing a growing trend where threat actors weaponize legitimate business applications to conduct large-scale credential harvesting operations against corporate networks.
3 weeks ago
Kill Chain
ZBT Router Backdoors: How Chinese Manufacturer Compromised Global Networks
In August 2026, security researchers discovered that Shenzhen Zhibotong Electronics Co. Ltd. (ZBT), a major Chinese router manufacturer, had embedded multiple backdoors in firmware across millions of white-label routers sold globally. The backdoors, dubbed 'EndlessDoors,' 'SpeakingStone,' and 'DarkLantern,' provided root-level access and command-and-control capabilities to attackers. With ZBT producing 3.57 million units annually and exporting to over 50 countries including the US, Canada, Germany, and Australia, the supply chain compromise potentially affected hundreds of thousands of edge devices in critical infrastructure, corporate networks, and remote installations like oil pipelines. This incident exemplifies the growing threat of nation-state supply chain attacks targeting network infrastructure, particularly as organizations increasingly deploy edge devices with cellular connectivity in remote locations that are difficult to monitor and update.
3 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports