Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2818 threat reports
Page 191 of 235

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Government Administration Threat Reports

Showing 22812292 / 2818 reports
Dragon Breath Breaches Defenses: RONINGLOADER Deploys Gh0st RAT in Sophisticated 2025 Attack
Impact· medium

Dragon Breath Breaches Defenses: RONINGLOADER Deploys Gh0st RAT in Sophisticated 2025 Attack

In November 2025, the threat actor group known as Dragon Breath launched a targeted cyber campaign aimed at Chinese-speaking users, leveraging a sophisticated multi-stage loader called RONINGLOADER. By deploying trojanized NSIS installers disguised as popular applications like Google Chrome and Microsoft Teams, attackers successfully delivered a modified variant of Gh0st RAT. The malware chain allowed adversaries to bypass security tools, perform covert surveillance, and remotely exfiltrate sensitive data from compromised systems, achieving persistent access and extensive control over infected endpoints. This incident highlights the increasing use of advanced loader chains and tailored social engineering vectors to breach defenses. It reflects a broader trend in cyber threats shifting towards multi-stage, modular attacks capable of disabling endpoint protections and evading detection through highly customized payloads and targeted distribution tactics.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How ClickFix-Driven EVALUSION Attacks Delivered Amatera Stealer and NetSupport RAT in 2025
Impact· medium

How ClickFix-Driven EVALUSION Attacks Delivered Amatera Stealer and NetSupport RAT in 2025

In June 2025, a threat campaign tracked as 'EVALUSION' leveraged sophisticated ClickFix social engineering lures to distribute the Amatera Stealer and NetSupport RAT. Cybersecurity researchers observed the attackers primarily targeting organizations through crafted phishing emails and malicious web downloads, enticing victims to execute payloads. Once inside, Amatera Stealer—an evolution of previous AcridRain infostealer variants—exfiltrated credentials and system information, while NetSupport RAT enabled persistent remote control. This resulted in a significant compromise of sensitive data and elevated risks of follow-on attacks, including lateral movement and further intrusions across corporate networks. This incident highlights the rapid professionalization and diversification of infostealer toolkits. The growing adoption of ClickFix social engineering and commodity remote access tools by organized threat actors magnifies data exposure and regulatory risks, especially as hybrid and multi-cloud attack surfaces expand.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Microsoft Patch Tuesday November 2025: Zero-Day & Critical Vulnerabilities Impact Enterprise Security
Impact· medium

Microsoft Patch Tuesday November 2025: Zero-Day & Critical Vulnerabilities Impact Enterprise Security

In November 2025, Microsoft released patches to address over 60 vulnerabilities affecting Windows operating systems and a broad suite of its applications, including Office, SQL Server, Visual Studio, and Azure Monitor Agent. Notably, this cycle contained at least one actively exploited zero-day flaw (CVE-2025-62215), a memory corruption vulnerability requiring local access, as well as a critical GDI+ bug (CVE-2025-60274) impacting broad swathes of enterprise and third-party applications. Additionally, a low-complexity Office vulnerability (CVE-2025-62199) enabling remote code execution was highlighted as a high priority for patching. Some users also faced complications enrolling in an extended Windows 10 security update program, partially addressed by out-of-band releases. This incident underscores the ongoing acceleration of zero-day and high-impact vulnerabilities targeting ubiquitous enterprise software, making timely patch deployment mission-critical. As the cadence and exploitation of software vulnerabilities increases, organizations must bolster patch management processes and align with evolving regulatory pressures to minimize risk exposure.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fortinet 2025: Multi-Vector AI Campaign Disrupts Global Networks
Impact· medium

Fortinet 2025: Multi-Vector AI Campaign Disrupts Global Networks

In early November 2025, a coordinated multi-vector campaign targeted Fortinet infrastructure worldwide, exploiting unpatched vulnerabilities in FortiGate VPN appliances. Attackers—some with ties to Chinese state-affiliated threat groups—combined AI-driven phishing-as-a-service (PhaaS) toolkits, malicious code deployment, and supply chain manipulation to bypass legacy perimeter defenses. The campaign leveraged trusted encrypted channels and cloud infrastructure to evade detection, enabling lateral movement and data exfiltration from government agencies, finance firms, and Fortune 500 companies. Cleanup and containment efforts required full infrastructure reviews and forensic triage, disrupting operations across multiple sectors. This incident exemplifies the accelerating convergence of advanced attacker automation, trusted-tool abuse (AI, VPNs), and commercial cybercrime platforms. Organizations must urgently address gaps in segmentation, encrypted traffic inspection, and detection controls to withstand increasingly stealthy, multi-stage attacks.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fortinet FortiWeb WAF Zero-Day Breach: 2024 Vulnerability Exposes Perimeter Defenses
Impact· low

Fortinet FortiWeb WAF Zero-Day Breach: 2024 Vulnerability Exposes Perimeter Defenses

In early June 2024, Fortinet disclosed a critical remote code execution (RCE) vulnerability in its FortiWeb Web Application Firewall (WAF). Identified as CVE-2024-21762, this zero-day bug enables unauthenticated attackers to remotely execute administrative commands on affected WAF devices via specially crafted HTTP requests. Threat actors were observed actively exploiting the flaw in the wild before the vendor released patches, allowing them to potentially compromise sensitive networks, bypass perimeter defenses, and gain high-privilege access to protected applications. Burdened by the high privilege level of administrative access, compromised systems are exposed to data theft, operational disruption, or lateral movement within enterprise networks. The incident highlights an ongoing surge in zero-day exploitation of critical infrastructure solutions, particularly targeting network perimeter and cloud security devices. Preliminary evidence suggests opportunistic attackers and advanced persistent threats are both involved, driving renewed urgency for timely patching, actionable threat detection, and Zero Trust strategies across enterprise and cloud environments.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
The 2024 Finger Protocol ClickFix Malware Attack: Legacy Protocols Reused for Command and Control
Impact· low

The 2024 Finger Protocol ClickFix Malware Attack: Legacy Protocols Reused for Command and Control

In early 2024, security researchers uncovered that threat actors were actively abusing the decades-old 'finger' protocol—a remote access and user lookup protocol seldom used in modern networks—as a covert command and control (C2) channel for deploying ClickFix malware on Windows devices. Attackers leveraged the unencrypted and often overlooked finger service to quietly retrieve remote commands, allowing compromise of endpoints and escalation of persistent access across targeted corporate environments. The attacks often evaded traditional security controls, highlighting a resurgence of legacy protocol exploitation as a lateral movement and control method that bypasses common detection. This incident demonstrates the increased ingenuity of malware authors in repurposing overlooked network protocols to evade security controls. As threat actors broaden their toolkits to exploit legacy services, organizations with insufficient east-west segmentation, network visibility, or outdated protocol restrictions remain at risk of similar covert command and control attacks.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(low)
Read Report
Google Lawsuit Disrupts Lighthouse: Major Blow to Smishing Operations in 2024
Impact· medium

Google Lawsuit Disrupts Lighthouse: Major Blow to Smishing Operations in 2024

In early 2024, Google initiated legal action against the operators behind Lighthouse, an SMS phishing (smishing) platform used to impersonate legitimate services and lure victims into fraudulent payment schemes, such as fake unpaid road tolls. The suspected operators, commonly referred to as the Smishing Triad and believed to be based in China, leveraged the Lighthouse kit and Telegram groups to execute widespread phishing campaigns. Following Google's lawsuit in the Southern District of New York, Lighthouse's infrastructure, Telegram channels, and several associated domains were taken offline, significantly disrupting the group's activities and signaling a major blow to organized SMS phishing at scale. This incident underscores the growing role of civil litigation and collaboration between technology giants and threat intelligence firms in disrupting cybercriminal ecosystems. As smishing attacks rise in sophistication and frequency worldwide, organizations must ensure layered defenses and readiness for increasingly advanced social engineering threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ClickFix: How Attackers Exploited finger.exe for Stealthy Network Access in 2023
Impact· low

ClickFix: How Attackers Exploited finger.exe for Stealthy Network Access in 2023

In November 2023, organizations reported a wave of Living-off-the-Land (LotL) attacks known as ClickFix, in which adversaries abused the legacy finger.exe utility on Windows systems. Attackers exploited finger.exe to retrieve and execute malicious scripts by leveraging the finger protocol over TCP port 79, bypassing endpoint security tools that are often tuned for more common protocols. The technique allowed attackers to maintain stealthy communications and initial access, exposing corporate environments where outbound traffic controls were inadequate. No major ransomware group claimed responsibility, but the campaign highlighted increasing sophistication in LotL exploitation, putting enterprises at risk of lateral movement and data exfiltration. This incident is highly relevant given the resurgence of attackers abusing built-in OS utilities to evade detection, as well as increased regulatory scrutiny over encrypted and segmented internal network traffic. Organizations must reevaluate their defenses against legacy protocol abuse.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
RondoDox Botnet Exploits Unpatched XWiki Servers via CVE-2025-24893
Impact· medium

RondoDox Botnet Exploits Unpatched XWiki Servers via CVE-2025-24893

In November 2025, cybersecurity researchers identified a widescale campaign leveraging the RondoDox botnet to exploit unpatched XWiki server instances. Attackers targeted CVE-2025-24893—a critical eval injection vulnerability with a CVSS score of 9.8—allowing unauthenticated remote code execution through manipulated HTTP requests. Once compromised, affected XWiki servers were conscripted into the botnet, enabling further lateral spread and facilitating command-and-control capabilities for adversaries. Organizations reliant on XWiki for content collaboration faced outages, data exposure, and the threat of secondary attacks as RondoDox rapidly weaponized unremediated systems. The RondoDox campaign underscores a growing trend in the automated exploitation of high-severity vulnerabilities in open-source platforms. As threat actors increasingly target collaborative SaaS and wiki services, enterprises face heightened demands for rapid patch management, proactive threat detection, and adherence to zero trust principles to minimize supply chain risk.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Five US Citizens Plead Guilty: North Korean IT Worker Sanctions Evasion Exposed
Impact· high

Five US Citizens Plead Guilty: North Korean IT Worker Sanctions Evasion Exposed

In 2025, the U.S. Department of Justice announced that five U.S. citizens pleaded guilty to aiding North Korean nationals in infiltrating over 130 companies by posing as IT workers. The individuals—Audricus Phagnasay, Jason Salazar, Alexander Paul Travis, Oleksandr Didenko, and Erick—operated a fraudulent scheme that enabled North Korea to evade international sanctions. Using sophisticated tactics, the group helped launder the proceeds from illegal IT contracts with U.S. and global firms, providing North Korea with critical revenue streams to support prohibited activities, including weapons development. This incident highlights the growing trend of nation-state actors exploiting legitimate IT contracting channels to bypass international sanctions. Widespread remote work, talent shortages, and lax vendor verification have increased organizational exposure to similar fraud, raising urgent compliance and geopolitical risk for businesses worldwide.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Akira Ransomware Hits Nutanix VMs, Exposing Threats to Critical Sectors
Impact· high

Akira Ransomware Hits Nutanix VMs, Exposing Threats to Critical Sectors

In early 2024, the Akira ransomware-as-a-service (RaaS) operation expanded its attack capabilities by targeting Nutanix virtual machines, allowing it to compromise both Windows and Linux workloads within critical infrastructure and enterprise environments. Attackers exploited new vulnerabilities and lateral movement techniques to rapidly deploy ransomware, encrypting data at scale and causing significant business disruption among targeted organizations. Notably, Akira’s evolving tooling enabled them to bypass certain traditional detection measures and exfiltrate sensitive information to pressure victims into ransom payment. This campaign highlights the increasing sophistication of ransomware operators and the growing risk posed to hybrid and multicloud environments. The success of the Akira group against high-value sectors underscores the urgent need for advanced east-west traffic security, visibility, and robust segmentation strategies.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
FortiWeb CVE-2025-64446: Honeypot Reveals Automated Web App Exploits
Impact· low

FortiWeb CVE-2025-64446: Honeypot Reveals Automated Web App Exploits

In November 2025, researchers observed active exploit attempts targeting FortiWeb appliances via CVE-2025-64446. Attackers sent specially crafted POST requests to FortiWeb's administration interface, leveraging the vulnerability to create privileged admin accounts remotely. The attack, first detected in internet-facing honeypots, allowed adversaries potential unauthorized control over victim devices and lateral access to connected environments. Organizations using vulnerable firmware versions face the risk of compromise if patches are not applied. This incident highlights the rapid adoption and automation of new web application exploits by threat actors. With FortiWeb appliances deployed widely across critical infrastructure, mass exploitation attempts have increased urgency for organizations to implement robust patch management and web application security controls.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports