Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
CISA Flags Critical WatchGuard Fireware Flaw: 54,000 Fireboxes at Risk from Unauthenticated Attacks
In November 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-9242, a critical out-of-bounds write vulnerability in WatchGuard Fireware OS, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. Attackers leveraged this flaw—rated CVSS 9.3—to gain unauthenticated remote access to over 54,000 exposed WatchGuard Firebox appliances worldwide, enabling potential system compromise and lateral network movement. The vulnerability affects Fireware OS versions 11.10.2 through recent releases, putting a significant number of network security devices at risk. This incident highlights the urgent need for aggressive patching and improved visibility into network infrastructure exposures. With attackers increasingly targeting edge devices and exploiting unpatched vulnerabilities, organizations must prioritize vulnerability management and zero trust network segmentation to contain emerging threats.
8 months ago
Kill Chain
When Vulnerabilities Strike at Machine Speed: The 2026 Supply Chain Attack
In early 2026, a sophisticated global supply chain attack exploited vulnerabilities in widely used software components just hours after new CVEs were publicly disclosed. Threat actors weaponized exploit code at unprecedented speed, targeting unpatched enterprise systems across cloud, hybrid, and on-prem environments. The adversaries leveraged compromised update channels and lateral east-west movement to deploy malicious payloads, exfiltrate data, and disrupt critical services. Businesses faced operational downtime, data loss, and compliance exposures as traditional patch cycles failed to keep pace with machine-speed attacks. This breach underscores how the rapid turn from vulnerability disclosure to global exploitation has become a defining security risk. The event highlights the urgent need for automation, zero trust segmentation, and machine-speed threat detection to mitigate threats that now outpace human-led response.
8 months ago
Kill Chain
2025 Siemens Spectrum Power 4 Flaws: Privilege Escalation in Critical ICS
In November 2025, Siemens disclosed a set of severe vulnerabilities impacting its Spectrum Power 4 platform, a widely deployed solution in the global energy sector. Discovered by researchers at Limes Security and reported through Siemens ProductCERT, these issues include incorrect use of privileged APIs, flawed privilege assignment, and insecure permissions, collectively enabling remote and local attackers to execute arbitrary code with administrative privileges or extract sensitive credentials. While there are currently no reports of active exploitation, the vulnerabilities expose critical infrastructure operators to the risk of operational disruption and data compromise. This incident highlights persistent threats due to weak privilege controls and insecure configurations in industrial control systems (ICS), which are increasingly targeted by sophisticated actors. With the energy sector classified as critical infrastructure, such exposures have regulatory, safety, and reputational consequences, driving renewed urgency for timely patch management and robust network segmentation.
8 months ago
Kill Chain
CitrixBleed 2: New Zero-Day Storm Hits Identity and Network Gateways
In early 2025, security teams discovered active exploitation of two newly identified zero-day vulnerabilities: CVE-2025-5777 in Citrix NetScaler and CVE-2025-20337 in Cisco Identity Service Engine (ISE). An advanced persistent threat (APT) group rapidly targeted both flaws, focusing on critical infrastructure where identity and access management systems form the backbone of secure connectivity. Attackers leveraged these zero-days to bypass authentication and elevate privileges, enabling lateral movement across east-west network segments and exfiltrating sensitive data. The incident underscores the risks posed by unpatched identity infrastructure in enterprise environments, leading to operational disruptions and an urgent patch response from affected vendors. This breach highlights a surge in sophisticated campaigns targeting the convergence of networking and identity technologies. The focus on identity-driven systems, rapid weaponization of zero-day exploits, and threat actors’ ability to pivot between vendors reinforce the growing challenge organizations face in defending mission-critical services amid a shifting risk landscape.
8 months ago
Kill Chain
SmartApeSG Leverages ClickFix Fake CAPTCHA Pages to Spread NetSupport RAT (2024)
In November 2024, the SmartApeSG campaign shifted tactics by leveraging ClickFix-style fake CAPTCHA pages to deliver the NetSupport RAT, a powerful remote access trojan. Threat actors compromised websites by injecting malicious scripts that, under specific conditions, displayed convincing 'verify you are human' prompts. Unsuspecting users, influenced by the fraudulent CAPTCHA, executed clipboard-injected commands that downloaded and ran NetSupport RAT on their Windows systems, establishing persistent access via Start Menu shortcuts. The campaign was notable for its adaptation and the regular rotation of malicious infrastructure. This incident highlights a rising trend of social engineering combined with hands-on-keyboard malware delivery. The use of fake CAPTCHA solutions is proliferating, making traditional email-filter and endpoint controls less effective. Organizations should be aware of evolving attack chains and regularly review user education programs to counter these sophisticated lures.
8 months ago
Kill Chain
Breakdown: 2024 FormBook Infostealer Delivered via Multi-Stage Script Obfuscation
In November 2024, a sophisticated email campaign delivered the FormBook infostealer via a series of obfuscated scripts. Attackers distributed malicious ZIP email attachments containing an obfuscated VBS file, which initiated multiple layers of PowerShell-based deobfuscation and payload retrieval. The staged infection successfully bypassed standard detection tools by employing complex anti-analysis techniques, eventually injecting FormBook into a legitimate process and establishing command and control through a remote server. Impacts included potential credential theft, session hijacking, and risk of lateral movement within affected organizations. This incident highlights the increasing use of multi-stage script-based delivery vectors and advanced obfuscation in commodity malware campaigns. Detection challenges are heightened as attackers combine legacy script formats and cloud hosting services to evade conventional endpoint security controls and deliver persistent infostealing payloads.
8 months ago
Kill Chain
OpenAI’s Sora 2 Release Fuels New Deepfake Security Risks in 2024
In late 2024, OpenAI released Sora 2, a powerful AI-powered video generation model, without the robust guardrails needed to prevent deepfake abuse. Within weeks, numerous instances emerged of Sora 2 being used to create convincing disinformation, impersonate public figures, and generate unmoderated content, despite minimal or easily removable watermarking. The lack of initial safeguards—such as restrictions on political figures or copyrighted content—and insufficient content provenance led to viral circulation of malicious deepfakes and nonconsensual depictions, raising significant operational, reputational, and regulatory risks for both OpenAI and affected individuals. This incident highlights a critical phase in AI/ML risk management: rapid technology advancement is outpacing the establishment and enforcement of ethical and technical controls. Growing regulatory and societal scrutiny underscores the need for defensible guardrails, provenance tracking, and collaborative risk governance to address the threats posed by generative AI deepfakes.
8 months ago
Kill Chain
Amazon Detects APT Group Exploiting Cisco & Citrix Zero-Days in 2024
In summer 2024, Amazon’s threat intelligence team identified that an advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (CVE-2025-20337) and Citrix NetScaler (CVE-2025-5777), months before official patches were released. The attackers leveraged custom malware with advanced evasion capabilities, demonstrating a deep understanding of enterprise Java and network edge products. Exploitation was detected as early as May, prior to vendor disclosure, allowing the threat actor prolonged access to target environments for likely espionage purposes. Massive exploitation attempts followed public disclosure, impacting thousands of organizations globally. This incident underscores the increased speed and sophistication with which threat groups are identifying and weaponizing zero-day vulnerabilities in critical network and identity infrastructure. The trend poses escalating risks for organizations relying on edge devices, making timely patching and layered defenses more crucial than ever.
8 months ago
Kill Chain
Rhadamanthys Infostealer Brought Down: Lessons from a Major Malware Disruption
In June 2024, law enforcement and security vendors successfully disrupted the Rhadamanthys infostealer operation, a prominent 'malware-as-a-service' offering used by cybercriminals to harvest sensitive data from infected devices. The takedown resulted in many malware operators reporting loss of access to their command-and-control servers, crippling active campaigns and rendering stolen data inaccessible. This disruption impacted both the malware's customers and the broader illicit ecosystem that depended on Rhadamanthys for credential theft, data exfiltration, and distribution of stolen information for financial gain. The incident highlights growing law enforcement coordination targeting infostealer infrastructure and criminal-as-a-service marketplaces. As infostealers proliferate with new evasion methods, their disruption remains a critical priority for organizations and defenders seeking to reduce exposure to credential theft and secondary breaches.
8 months ago
Kill Chain
Synnovis 2024 Ransomware Breach: UK Healthcare Services and Patient Data Exposed
In June 2024, Synnovis, a leading UK pathology services provider, suffered a significant ransomware attack that led to operational disruption and the exposure of sensitive patient data. The attack, attributed to Russian-speaking threat actor group Qilin, resulted in widespread IT outages across London hospitals, delaying critical healthcare procedures and temporarily halting diagnostic services. Investigations revealed that attackers were able to steal files containing patient information before encrypting core systems, underscoring the vulnerability of healthcare organizations to ransomware campaigns targeting their critical infrastructure. This incident is emblematic of a surge in highly targeted ransomware attacks against the healthcare sector globally. With a marked increase in double-extortion tactics and operationally disruptive attacks, this event highlights escalating cyber risk, increasing regulatory oversight, and the urgent need for robust cyber-resilience in healthcare.
8 months ago
Kill Chain
Citrix & Cisco Face 2025 Zero-Day Onslaught: Custom Malware Targets Network Cores
In early 2025, a sophisticated threat actor leveraged zero-day vulnerabilities—CVE-2025-5777 ('Citrix Bleed 2') in NetScaler ADC/Gateway and CVE-2025-20337 in Cisco Identity Services Engine (ISE)—to gain initial access into targeted enterprise environments. Exploiting these flaws before vendor patches were available, attackers deployed custom malware to establish persistent command-and-control and facilitate lateral movement, affecting sensitive east-west and outbound network traffic. The advanced nature of this attack enabled the evasion of traditional security controls, resulting in unauthorized access to confidential data and business operations disruptions. This breach highlights a critical evolution in adversary tradecraft: coordinated and simultaneous exploitation of zero-day flaws in widely deployed network infrastructure. With threat actors increasingly chaining vulnerabilities to maximize impact, proactive threat detection and effective segmentation are more essential than ever for organizations seeking resilience against such rapid exploitation campaigns.
8 months ago
Kill Chain
Google Sues to Dismantle Chinese 'Lighthouse' Phishing Platform Orchestrating US Toll Scams
In June 2024, Google filed a lawsuit to dismantle the 'Lighthouse' phishing-as-a-service (PhaaS) platform operated out of China. Lighthouse enabled global cybercriminals to launch large-scale SMS phishing campaigns, targeting U.S. residents by impersonating the U.S. Postal Service and E-ZPass toll systems. Attackers used automated infrastructure to send convincing text messages, directing victims to fraudulent sites designed to steal credit card and personal information. The campaign resulted in substantial financial losses for consumers and posed major operational risks to U.S. businesses and government agencies. This incident underscores the growing sophistication and accessibility of phishing-as-a-service offerings. With such turnkey solutions readily available on the dark web, attackers are able to scale campaigns with minimal technical skill, escalating both the frequency and severity of credential theft and fraud worldwide.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports