Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2818 threat reports
Page 214 of 235

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Government Administration Threat Reports

Showing 25572568 / 2818 reports
Nation-State Breach of F5 Sparks CISA Emergency Directive for Federal Agencies
Impact· medium

Nation-State Breach of F5 Sparks CISA Emergency Directive for Federal Agencies

In mid-2024, F5 Networks disclosed that a sophisticated nation-state attacker gained prolonged, unauthorized access to its internal systems, compromising BIG-IP source code and undisclosed vulnerability details. The breach, detected in August, prompted the US Cybersecurity and Infrastructure Security Agency (CISA) to issue an emergency directive compelling federal agencies to immediately identify, patch, or disconnect thousands of F5 products in their environments. While no direct federal compromises have been reported yet, the theft of sensitive product and security information could facilitate widespread exploitation across both federal agencies and private organizations relying on F5 systems. This incident underscores heightened risks to supply chain integrity and critical infrastructure posed by persistent nation-state campaigns. With attackers targeting widely deployed technology vendors, government and industry face urgent pressure to enhance monitoring, rapid patching, and zero trust defenses to mitigate risks from downstream exploitation of software supply chains.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
F5 2025 Breach: Nation-State Attackers Target BIG-IP Source Code
Impact· high

F5 2025 Breach: Nation-State Attackers Target BIG-IP Source Code

In August 2025, cybersecurity giant F5 detected a sophisticated breach by nation-state hackers who gained unauthorized access to its BIG-IP product development environment and engineering knowledge management platforms. Over an extended period, attackers exfiltrated undisclosed BIG-IP vulnerabilities, product source code, and select customer configuration information. F5 asserts no evidence that the attackers modified software, exploited the stolen vulnerabilities in active attacks, or that critical customer data was exposed. Response actions included credential rotations, hardening of development environments, enhanced threat detection, and external code audits by firms such as CrowdStrike, Mandiant, NCC Group, and IOActive. F5 also proactively issued security updates and guidance to impacted customers. This incident underscores the growing trend of sophisticated, supply-chain-oriented intrusions targeting technology providers with a wide enterprise customer base. It illustrates the strategic value of source code and zero-day exploits to well-resourced threat actors, and raises ongoing concerns about the security of key software infrastructure used widely across industries.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Microsoft Windows Server 2025 Update Breaks Active Directory Sync
Impact· medium

Microsoft Windows Server 2025 Update Breaks Active Directory Sync

In September 2025, Microsoft’s security updates for Windows Server 2025 triggered Active Directory (AD) Domain Services synchronization issues, specifically affecting environments with large AD security groups exceeding 10,000 members. The incident, stemming from update KB5065426, disrupted vital processes like Microsoft Entra Connect Sync, resulting in incomplete directory synchronization. Microsoft quickly acknowledged the bug, issued a temporary registry-based workaround, and warned that improper registry modifications carried significant risks. The root cause is connected to directory synchronization controls that do not yet officially support Windows Server 2025. This event highlights the increasing operational risk organizations face from software update regressions affecting core identity infrastructure. In an era of widespread cloud adoption and hybrid identity services, such failures can severely impact business continuity and compliance, amplifying the urgency for robust change management and pre-deployment validation.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
F5 2025 Supply Chain Breach: BIG-IP Vulnerabilities Exposed by State Hackers
Impact· low

F5 2025 Supply Chain Breach: BIG-IP Vulnerabilities Exposed by State Hackers

In August 2025, cybersecurity company F5 detected a sophisticated supply chain attack resulting in the theft of source code and undisclosed vulnerabilities affecting its flagship BIG-IP products. The breach, attributed to state-sponsored hackers, did not lead to immediate exploitation but exposed potentially critical flaws. F5 responded by rapidly developing and releasing security patches for 44 vulnerabilities, proactively urging its global clientele—including many Fortune 500 companies and federal agencies—to update systems and implement enhanced monitoring. No evidence was found of modifications to the supply chain or active use of the stolen information as of disclosure. This incident highlights mounting concerns around supply chain security and zero-day vulnerability exposure, particularly within critical infrastructure and cloud environments. The breach also triggered regulatory intervention, with CISA issuing emergency directives for federal agencies, underscoring rising government attention to third-party risks and broader cybersecurity resilience in the face of advanced persistent threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Capita Hit by Black Basta Ransomware: 6.6 Million Impacted in 2023 Breach
Impact· high

Capita Hit by Black Basta Ransomware: 6.6 Million Impacted in 2023 Breach

In March 2023, UK outsourcing giant Capita suffered a major data breach after an employee downloaded a malicious file, giving threat actors access to internal systems. The Black Basta ransomware gang exploited delayed response and weak access controls to maintain persistence for 58 hours, move laterally, and exfiltrate nearly a terabyte of sensitive data covering 6.6 million individuals, including customers of over 325 pension providers. The attackers deployed ransomware, resetting passwords and disrupting access, forcing Capita to take some systems offline and ultimately resulting in a £14 million regulatory fine after failing to meet key security requirements. This breach highlights the growing menace of ransomware operations targeting supply chain and service providers, with regulatory authorities emphasizing rapid response, robust access controls, and continuous security testing. Organizations face increased scrutiny to maintain strong cybersecurity baselines as attackers evolve tactics and exploit internal weaknesses.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
PowerSchool 2024 Data Breach: College Student Sentenced for Massive Attack
Impact· high

PowerSchool 2024 Data Breach: College Student Sentenced for Massive Attack

In December 2024, PowerSchool, a major provider of cloud-based education technology, suffered a significant data breach orchestrated by 19-year-old college student Matthew D. Lane from Worcester, Massachusetts. Lane infiltrated PowerSchool’s systems by exploiting a combination of credential theft and vulnerabilities in internal access controls, enabling him to exfiltrate large volumes of sensitive student and faculty data over several weeks. Law enforcement investigation led to his arrest and subsequent sentencing to four years in prison, highlighting both the sophistication of modern attackers and the sensitivity of educational data targeted. The case is especially relevant as threat actors increasingly set their sights on critical SaaS platforms and education technology, exploiting gaps in zero trust implementation and east-west traffic visibility. The incident underscores a rising trend in data breaches against public sector organizations and the urgent need for robust controls in cloud and hybrid environments.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
2025 Mysterious Elephant Attack: Asia-Pacific Government Cyber-Espionage Exposed
Impact· medium

2025 Mysterious Elephant Attack: Asia-Pacific Government Cyber-Espionage Exposed

In early 2025, the Mysterious Elephant advanced persistent threat group launched a sophisticated campaign targeting government and foreign affairs entities across Pakistan, Bangladesh, Afghanistan, Nepal, and Sri Lanka. Utilizing spear phishing emails, exploit kits, and malicious documents as entry vectors, the group deployed custom and open-source malware—such as BabShell, MemLoader HidenDesk, and ChromeStealer—to gain persistent network access, move laterally, and exfiltrate sensitive data. Their tooling leveraged advanced evasion tactics and targeted WhatsApp data for exfiltration, compromising documents, images, and browser credentials. The operation demonstrates considerable code reuse and customized tooling, posing a significant disruption to national and diplomatic processes in the region. Mysterious Elephant’s shift to tailored malware, WhatsApp-specific exfiltration, and cloud-based infrastructure highlights a broader threat landscape trend: state-sponsored actors refining tactics for targeted governmental espionage. This underscores the importance of proactive monitoring and cross-border information sharing to address escalating nation-state risks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Microsoft Patch Tuesday Ring-fences 172 Flaws and Ends Windows 10 Support
Impact· medium

Microsoft Patch Tuesday Ring-fences 172 Flaws and Ends Windows 10 Support

In October 2025, Microsoft’s Patch Tuesday delivered critical security updates addressing 172 vulnerabilities in Windows operating systems, including two zero-days actively exploited in the wild. The first, CVE-2025-24990, is a flaw in the long-bundled Agere Modem driver exploited by attackers and removed entirely by Microsoft. The second, CVE-2025-59230, impacted Windows Remote Access Connection Manager (RasMan), risking privilege escalation through compromised VPN and remote access services. Remote code execution bugs in Office Preview Pane and a critical risk to Windows Server Update Services (WSUS) put both endpoints and patching infrastructure at significant risk. This large wave of vulnerabilities coincided with the end of official support for Windows 10, Exchange Server 2016, and other Microsoft products. The combination of zero-day exploitation and the end-of-life for popular products highlights the urgent need for proactive vulnerability management and secure migration paths as cybercriminals increasingly exploit outdated software.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Microsoft’s October 2025 Patch Tuesday Highlights Critical Vulnerabilities and End-of-Support Urgency
Impact· low

Microsoft’s October 2025 Patch Tuesday Highlights Critical Vulnerabilities and End-of-Support Urgency

In October 2025, Microsoft released security updates addressing 157 vulnerabilities across several on-premises products as part of its Patch Tuesday initiative. Eight vulnerabilities were rated critical, with impacted platforms including Windows 10, Office 2016/2019, Exchange Server 2016/2019, and various core components (e.g., Excel, Remote Desktop, SharePoint). While no active exploitation was reported at the time of disclosure, the sheer number and severity of these flaws—including several involving remote code execution and privilege escalation—pose significant risks for enterprises relying on legacy or end-of-support software. Organizations dependent on affected Microsoft software are urged to apply patches promptly and consider their exposure, particularly as support for key products ends and attackers often target unpatched environments. This Patch Tuesday is highly relevant as attackers consistently exploit newly disclosed vulnerabilities, especially in widely deployed systems, for lateral movement and data exfiltration. With mainstream support ending for core Microsoft products, the window of exposure and regulatory risk grows for companies slow to adopt updated versions or enhanced security controls.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Python Infostealer Exposes New Clipboard Image Attack Vector in 2024
Impact· medium

Python Infostealer Exposes New Clipboard Image Attack Vector in 2024

In October 2024, a new Python-based infostealer was discovered leveraging the clipboard’s picture functionality to stealthily exfiltrate screenshots and images from victim machines. The malware, observed in the wild using Telegram for command-and-control, exploits the common trust in clipboard features by targeting not only text but also graphical data such as screenshots often exchanged for reporting or documentation. Notably, the malware’s code contained Vietnamese-language comments, and a sample analyzed had a low detection score on VirusTotal, indicating low awareness and potential for widespread impact. This incident highlights the evolution of infostealer tactics as they expand data theft payloads beyond credentials and text, exploiting overlooked vectors like clipboard images. Such techniques present new challenges for organizations as attackers increasingly focus on fileless, cross-platform exfiltration and abuse of trusted collaboration workflows.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
PhantomVAI Loader in 2024: Advanced Malware Delivery and Infostealer Risks
Impact· medium

PhantomVAI Loader in 2024: Advanced Malware Delivery and Infostealer Risks

In early 2024, cybersecurity researchers at Palo Alto Networks Unit 42 identified PhantomVAI, a new loader malware designed to deliver a variety of infostealers such as Lumma Stealer and LokiBot. The campaign uses advanced steganography and heavily obfuscated scripts to evade detection, enabling attackers to distribute payloads through malicious downloads and compromised websites. PhantomVAI’s modular design allows cybercriminals to easily switch the delivered malware, raising the risk for rapid adaptation against defense mechanisms. Affected organizations may experience credential compromise, data exfiltration, and exposure of sensitive information. This incident exemplifies the increasing sophistication of malware loaders and highlights a growing trend toward customizable, evasive attack tools targeting businesses worldwide. As attackers continue to automate and obfuscate their delivery methods, organizations must enhance their monitoring and threat detection to keep pace with evolving threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Microsoft Patch Tuesday: October 2025 Brings Critical Zero-Day Exploits
Impact· medium

Microsoft Patch Tuesday: October 2025 Brings Critical Zero-Day Exploits

In October 2025, Microsoft disclosed and patched 175 vulnerabilities affecting its major products, marking the year's largest vulnerability release from the company. Notably, two zero-day vulnerabilities (CVE-2025-24990 in the Agere Windows Modem Driver and CVE-2025-59230 in Windows Remote Access Connection Manager) were discovered to be actively exploited in the wild. Attackers leveraging these flaws could elevate privileges, potentially gaining administrative or system-level access across all supported Windows versions. Microsoft acted promptly, removing the vulnerable modem driver and providing fixes for the Remote Access Connection Manager, with the U.S. Cybersecurity and Infrastructure Security Agency adding both zero-days to its known exploited catalog. This incident underscores the persistent threat posed by zero-day exploits and highlights the increasing rate at which attackers are targeting system-level services and third-party drivers. The surge of high-severity vulnerabilities, along with rapid exploitation, demonstrates the need for organizations to strengthen vulnerability and privilege management programs to respond to modern attack trends.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports