Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Critical Vulnerabilities Disclosed in Hitachi Energy Power Grid Control Systems
CISA published advisory ICSA-26-260-03 disclosing critical vulnerabilities in Hitachi Energy's FACTS Control Platform (FCP) affecting multiple versions from 3.4.0 to 4.1.1 when deployed with the GWS component. The vulnerabilities include SQL injection (CVE-2024-4872), path traversal (CVE-2024-3980), session hijacking (CVE-2024-3982), missing authentication (CVE-2024-7940), and open redirect (CVE-2024-7941) with CVSS scores ranging from 4.3 to 9.9. These flaws could allow authenticated attackers to execute code injection, access critical system files, hijack sessions, and redirect users to malicious sites, potentially compromising the confidentiality, integrity, and availability of critical power grid infrastructure. This disclosure highlights the growing cybersecurity challenges facing operational technology in the energy sector, particularly as industrial control systems become increasingly connected and targeted by sophisticated threat actors seeking to disrupt critical infrastructure operations.
1 day ago
Kill Chain
Critical Linux Kernel Vulnerabilities Added to CISA KEV Catalog
CISA has added two critical Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog in September 2026, following evidence of active exploitation in the wild. CVE-2025-39964, a race condition vulnerability, and CVE-2026-53266, an out-of-bounds write vulnerability, both target the Linux kernel and can grant attackers total system control post-exploitation. These additions reinforce the agency's Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize rapid remediation of high-risk vulnerabilities on publicly exposed assets that could lead to complete system compromise. The identification of these actively exploited kernel vulnerabilities highlights the ongoing evolution of threat actor tactics targeting foundational infrastructure components. As organizations increasingly adopt cloud-native and hybrid architectures, kernel-level vulnerabilities represent critical attack surfaces that can bypass traditional security controls and enable privilege escalation across entire computing environments.
1 day ago
Kill Chain
APT36 Evolves Tactics with Rust Malware and GitHub Infrastructure in Operation RapidRust
In September 2026, the Pakistan-aligned threat group Transparent Tribe (APT36) launched Operation RapidRust, targeting government and defense entities in India and Afghanistan with four new malware families: RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The campaign utilized innovative command-and-control infrastructure through private GitHub repositories and typosquatted domains mimicking Indian news organizations. The sophisticated attack chain involved a Rust-based backdoor for encrypted communications, USB propagation tools, and cross-platform file stealers capable of exfiltrating up to 5GB of sensitive data per execution. This incident highlights the evolving threat landscape where nation-state actors increasingly leverage legitimate cloud services for malicious infrastructure while expanding their technical capabilities across multiple operating systems and attack vectors.
1 day ago
Kill Chain
Cisco ISE Zero-Day CVE-2026-76460: When Network Access Controls Become Attack Vectors
Cisco disclosed CVE-2026-76460, a maximum-severity zero-day vulnerability in Cisco Identity Services Engine (ISE) that was actively exploited before disclosure in December 2026. The vulnerability allows remote attackers to bypass authentication and gain full administrative control of ISE devices through an API flaw. Compromised ISE systems enable attackers to modify network access policies, extract stored credentials, delete audit logs, and move laterally across all network segments controlled by the device. This represents Cisco's second actively exploited zero-day disclosure within two days, highlighting an escalation in targeted attacks against critical network infrastructure. This incident underscores the growing sophistication of attacks targeting network access control systems and the critical importance of zero-trust architecture as traditional perimeter-based security models continue to fail against advanced persistent threats.
2 days ago
Kill Chain
Critical Cisco ISE Zero-Day Highlights Identity Infrastructure Attack Trends
In September 2026, Cisco disclosed CVE-2026-76460, a maximum-severity authentication bypass vulnerability in Identity Services Engine (ISE) and ISE Passive Identity Connector being actively exploited by threat actors. The flaw allows remote attackers to bypass authentication on API endpoints through crafted requests, gaining unauthorized access to affected devices without any configuration requirements. Cisco's PSIRT confirmed active exploitation in the wild, prompting CISA to add the vulnerability to its Known Exploited Vulnerabilities catalog with a mandatory three-day patching deadline for federal agencies. This incident highlights the escalating targeting of identity and access management infrastructure, as threat actors increasingly focus on bypassing authentication controls to establish persistent network access and facilitate lateral movement in Zero Trust environments.
2 days ago
Kill Chain
FamousSparrow's SparroWocky Backdoor Targets Latin American Governments
The China-linked espionage group FamousSparrow has been conducting a sustained campaign against government organizations across Latin America using their new SparroWocky backdoor malware. From mid-2025 through 2026, the group targeted organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, replacing their previous SparrowDoor backdoor with this more advanced C++ malware. SparroWocky features sophisticated anti-analysis capabilities, modular architecture, and comprehensive data collection functions including screenshot capture, file manipulation, and proxy operations. The attacks aimed to gather intelligence on Latin American governments' responses to increasing U.S. pressure on Chinese economic interests, demonstrating China's strategic focus on regional geopolitical intelligence gathering. This campaign highlights the evolution of Chinese state-sponsored cyber espionage capabilities and their expanding focus on Latin American targets amid growing geopolitical tensions. The sophisticated evasion techniques and sustained operations demonstrate the increasing threat posed by well-resourced nation-state actors to regional government infrastructure and diplomatic communications.
2 days ago
Kill Chain
Microsoft's September 2026 Updates Break Windows Domain Authentication
Microsoft's September 2026 security updates KB5124008 and KB5124012 introduced critical domain authentication failures affecting Windows 11 enterprise environments. The updates automatically enabled Machine Identity Isolation enforcement mode, breaking domain trust relationships for organizations not running Windows Server 2025 Domain Functional Level. Affected users experienced credential validation errors despite correct usernames and passwords, requiring immediate registry modifications and secure channel resets to restore domain access. This incident highlights the risks of automatic security feature enforcement without proper infrastructure compatibility validation. The authentication failures demonstrate how security hardening measures can inadvertently create operational disruptions in hybrid enterprise environments, emphasizing the need for careful deployment planning and compatibility assessment before implementing new identity isolation mechanisms.
2 days ago
Kill Chain
FBI Dismantles NightmareStresser: The Rise and Fall of a Major DDoS Empire
On September 17, 2026, the FBI seized the NightmareStresser DDoS-for-hire platform, one of the world's longest-running booter services that enabled cybercriminals to launch massive distributed denial-of-service attacks. The platform, operating through nightmare-stresser.com and nightmarestresser.org domains, boasted over 566,000 registered users and 52 dedicated servers capable of generating attacks up to 200 Gbps. Since 2022, NightmareStresser facilitated hundreds of thousands of DDoS attacks targeting victims worldwide, leveraging compromised IoT devices and routers as attack infrastructure. This seizure highlights the escalating threat of commoditized DDoS services that democratize cyberattacks, enabling even non-technical actors to launch sophisticated infrastructure attacks. The continued evolution of booter services represents a persistent challenge to organizations' availability and business continuity, particularly as these platforms increasingly target critical infrastructure and essential services.
2 days ago
Kill Chain
AI-Powered Credential Harvesting: How Autonomous Attacks Are Rewriting Cybercrime Economics
In September 2026, Google Threat Intelligence Group documented sophisticated AI-powered credential harvesting campaigns where threat actors compromised cloud infrastructure and deployed multi-agent attack frameworks in under six hours. These autonomous systems managed vulnerability scanning, troubleshooting, and IP rotation with minimal human intervention, harvesting thousands of third-party credentials. The attacks demonstrated AI's ability to dramatically increase the speed and scale of credential theft operations, with AI-assisted phishing campaigns achieving 54% click-through rates compared to 12% for traditional methods. This incident represents a critical inflection point where AI transforms cybercrime economics, making credential theft operations exponentially more efficient and scalable while traditional authentication mechanisms struggle to distinguish between legitimate users and AI-powered attackers using stolen credentials.
2 days ago
Kill Chain
MovieReaper Campaign Exploits Torrent Supply Chain with Blockchain-Resilient C2
The MovieReaper campaign, active since October 2025, represents a sophisticated multi-stage malware operation targeting users across multiple countries through compromised torrent trackers. Threat actors compromised the itorrents.org repository, causing legitimate torrent sites to inadvertently distribute malicious files disguised as popular movies like 'The Odyssey (2026).' The attack chain employs advanced evasion techniques, uses Solana blockchain for C2 resilience, and deploys a modular framework capable of comprehensive file system access and data exfiltration. Victims span individuals and organizations across Europe, Asia, and Africa, including sectors like government, IT, retail, and transportation. This incident highlights the evolving sophistication of supply chain attacks targeting content distribution platforms and the increasing use of blockchain infrastructure to create resilient command and control networks that resist traditional takedown efforts.
2 days ago
Kill Chain
Critical Cisco ISE Zero-Day Exploited in Wild: CVE-2026-76460 Authentication Bypass
In September 2026, Cisco disclosed CVE-2026-76460, a maximum-severity zero-day vulnerability (CVSS 10.0) affecting Identity Services Engine (ISE) and ISE Passive Identity Connector. The flaw allows unauthenticated remote attackers to bypass authentication through insufficient controls on an API endpoint, granting unauthorized access to the web-based management interface and potentially root-level command execution. Cisco confirmed active exploitation in the wild, prompting CISA to add the vulnerability to its Known Exploited Vulnerabilities catalog with a mandatory patching deadline of September 19, 2026, for federal agencies. This incident highlights the escalating threat landscape targeting critical network infrastructure components, particularly identity and access management systems that serve as foundational security controls for enterprise zero trust architectures.
2 days ago
Kill Chain
NightmareStresser Takedown: How US Authorities Disrupted a Massive DDoS Empire
In September 2026, the U.S. Department of Justice seized two domains associated with NightmareStresser, a distributed denial-of-service (DDoS)-for-hire service that facilitated hundreds of thousands of attacks since 2022. The platform operated with over 566,000 registered users across 52 servers, targeting educational institutions, government agencies, gaming platforms, and millions of individuals worldwide. The service offered advanced Layer 4 and Layer 7 attack capabilities, cryptocurrency payment options, and claimed 24/7 availability over eight years of operation. This seizure represents a critical escalation in the ongoing battle against cybercrime-as-a-service platforms, highlighting the urgent need for organizations to implement comprehensive DDoS protection and network security measures as these attacks continue to evolve in sophistication and scale.
2 days ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports