Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2818 threat reports
Page 226 of 235

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Government Administration Threat Reports

Showing 27012712 / 2818 reports
Obscura Ransomware 2025: What Enterprises Must Learn About Active Directory Attacks
Impact· high

Obscura Ransomware 2025: What Enterprises Must Learn About Active Directory Attacks

In late August 2025, a newly discovered ransomware variant named Obscura was identified executing across several hosts within an enterprise network. The attack leveraged the organization's Active Directory infrastructure, using the NETLOGON share to automatically deploy a Go-based ransomware binary across all domain controllers and affected endpoints. The attackers created malicious scheduled tasks for persistent execution and attempted to enable remote desktop for potential lateral movement. The ransomware also attempted to disable endpoint recovery options, and the ransom note indicated both data encryption and exfiltration of sensitive company information. Limited security agent coverage hampered detection and response, amplifying the operational disruption and risk of sensitive data exposure. This incident underscores the evolving sophistication of ransomware actors in targeting critical authentication infrastructure and automated deployment mechanisms. As attackers increasingly combine data theft with operational disruption and target identity systems, organizations face heightened regulatory, financial, and reputational risks, warranting renewed focus on segmentation, visibility, and endpoint security.

8 months ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Unpatched SMS Flaw in OnePlus Phones Leaves User Messages Exposed
Impact· medium

Unpatched SMS Flaw in OnePlus Phones Leaves User Messages Exposed

In September 2025, a critical, still-unpatched vulnerability (CVE-2025-10184) was publicly disclosed in OnePlus smartphones running OxygenOS 12 through 15. Discovered by Rapid7, the flaw enables any installed app—without explicit permissions or user input—to access and exfiltrate SMS content and metadata on affected devices. This exposure was caused by insecurely exported content providers in the custom Android Telephony package, allowing SQL injection-style inference attacks. Despite multiple disclosure attempts, OnePlus did not respond for over four months; the details, including a proof of concept, were disclosed publicly to accelerate a fix. The case underscores rising risks from insecure mobile customizations and vendor slow response, especially as attackers increasingly exploit flaws in widely deployed consumer devices. With the proliferation of mobile-centric attacks and regulatory scrutiny on data privacy, this breach highlights the urgent need for robust patch management and proactive mobile security.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Cisco's 2025 SNMP Zero-Day: Credential Compromise Drives Network Device Exploit Surge
Impact· high

Cisco's 2025 SNMP Zero-Day: Credential Compromise Drives Network Device Exploit Surge

In September 2025, Cisco disclosed a high-severity zero-day vulnerability (CVE-2025-20352) affecting IOS and IOS XE network infrastructure devices. The flaw, a stack-based buffer overflow in the SNMP subsystem, allowed remote, authenticated attackers with low privileges to cause denial-of-service and, in some cases, permitted high-privileged attackers to fully compromise devices. Exploitation was detected after local administrator credentials were stolen, enabling threat actors to send malicious SNMP packets over IPv4/IPv6, impacting unpatched devices globally. Immediate patching was recommended as no workarounds existed except tightly restricting SNMP access. This incident underscores the criticality of timely patching and robust identity and network access controls, as attackers increasingly target network infrastructure via both credential compromise and protocol-level vulnerabilities. Industry-wide, it marks an escalating trend of high-impact, infrastructure-level exploits requiring urgent coordinated response.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Supermicro’s 2025 BMC Firmware Flaws Expose Critical Backdoor Risks
Impact· medium

Supermicro’s 2025 BMC Firmware Flaws Expose Critical Backdoor Risks

In September 2025, Supermicro disclosed critical firmware vulnerabilities (CVE-2025-7937 and CVE-2025-6198) affecting its server Baseboard Management Controller (BMC). Security researchers at Binarly demonstrated that attackers could leverage these flaws to bypass firmware signature verification and the BMC root of trust, allowing deployment of persistent, malicious firmware on widely used Supermicro servers. Exploits could grant adversaries complete, long-term control over both the BMC and host OS, enabling stealthy persistence and reliable evasion of security controls, while systems appeared to be running valid, signed code. Supermicro confirmed the vulnerabilities, releasing firmware patches, but proof-of-concept exploits are already public. This incident underscores the evolving challenge of hardware-level attacks, as advanced threat actors increasingly target supply chain and firmware layers to establish persistent, hard-to-detect footholds. Recent regulatory pressure and rising incidents of firmware-based threats highlight the urgency for security teams to elevate visibility and controls across hardware trust boundaries.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Attackers Leverage Pandoc SSRF Vulnerability CVE-2025-51591 to Breach AWS IMDS
Impact· low

Attackers Leverage Pandoc SSRF Vulnerability CVE-2025-51591 to Breach AWS IMDS

In September 2025, threat actors exploited a newly disclosed Server-Side Request Forgery (SSRF) vulnerability in the open-source Linux utility Pandoc (CVE-2025-51591), targeting Amazon Web Services (AWS) cloud environments. The attackers leveraged the flaw to send unauthorized requests to the AWS Instance Metadata Service (IMDS), allowing them to obtain EC2 role credentials and elevate cloud permissions. Security researchers, including Wiz, observed active exploitation in the wild, leading to unauthorized access and potential data exfiltration from affected AWS infrastructure. Organizations relying on Pandoc as part of their cloud automation workflows face heightened risk of credential compromise and lateral movement across accounts. This incident underscores a fast-evolving cloud threat landscape, where attackers exploit supply-chain and open-source vulnerabilities to traverse trusted infrastructure and target sensitive identity and metadata services. The rapid weaponization of CVE-2025-51591 mirrors the broader trend of SSRF attacks on cloud metadata, driving urgent calls for proactive detection, segmentation, and credential management in multi-cloud environments.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
State-Sponsored Actors Breach Libraesva ESG via Command Injection Vulnerability
Impact· low

State-Sponsored Actors Breach Libraesva ESG via Command Injection Vulnerability

In September 2025, Libraesva disclosed a command injection vulnerability (CVE-2025-59689, CVSS 6.1) affecting its Email Security Gateway (ESG) platform, which was actively exploited by state-sponsored threat actors. Attackers leveraged maliciously-crafted email payloads to trigger remote command execution, bypassing ESG protections and potentially gaining persistent access to targeted networks. The intrusion method allowed attackers to move laterally and exfiltrate sensitive data, underscoring the risks posed by the exploitation of security appliances themselves. Libraesva released emergency patches and urged customers to upgrade immediately, as evidence emerged of ongoing targeted campaigns against critical sectors. This incident highlights the increasing use of email gateway exploits by sophisticated adversaries, aligning with a wider trend of targeting security infrastructure for initial access. With command injection flaws on the rise and ransomware operators adopting similar approaches, organizations face escalating pressure to rapidly patch vulnerabilities and reinforce segmentation and anomaly detection across their environments.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
YiBackdoor: A Sophisticated Backdoor Malware Campaign Bridging IcedID and Latrodectus
Impact· low

YiBackdoor: A Sophisticated Backdoor Malware Campaign Bridging IcedID and Latrodectus

In June 2025, researchers discovered YiBackdoor, a novel malware family exhibiting significant source code overlaps with the notorious IcedID and Latrodectus strains. Campaigns leveraging YiBackdoor execute advanced backdoor techniques that establish remote access, command execution, and data exfiltration within compromised environments. YiBackdoor is typically deployed as part of a multi-stage attack campaign, using phishing or malicious attachments as its primary entry vector. Its detection signaled the emergence of new collaborative threats between criminal malware groups, raising concerns over increased code sharing and tool evolution. This incident highlights growing technical sophistication and cross-pollination between established malware actors. The use of YiBackdoor in conjunction with IcedID and Latrodectus demonstrates adversary agility and the accelerated pace of malware innovation, elevating the threat to enterprises reliant on traditional detection models.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
RedNovember: 2025 Chinese State Cyber Espionage Campaign Hits Global Governments
Impact· low

RedNovember: 2025 Chinese State Cyber Espionage Campaign Hits Global Governments

In mid-2025, a Chinese state-sponsored threat group known as RedNovember (previously tracked as TAG-100) orchestrated a widespread cyber espionage campaign targeting government and private sector organizations across Africa, Asia, North America, South America, and Oceania. The attackers leveraged sophisticated tools including the Pantegana backdoor and Cobalt Strike to establish persistence, perform lateral movement, and exfiltrate sensitive data. Entry vectors included spear-phishing emails and exploitation of known network vulnerabilities, allowing RedNovember to stealthily compromise high-value systems and harvest intelligence for extended periods before discovery. The impact included unauthorized access to confidential government documents and disruption of critical data workloads. This incident underscores the persistent evolution of state-sponsored attack tactics, with RedNovember employing advanced, evasive techniques and custom malware. The growing use of encrypted command-and-control traffic and living-off-the-land strategies sets a concerning precedent, especially for government agencies and regulated enterprises facing a surge in sophisticated espionage operations.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
UNC6148 Installs OVERSTEP Backdoor in SonicWall SMA Devices: 2024 APT Breach Analysis
Impact· medium

UNC6148 Installs OVERSTEP Backdoor in SonicWall SMA Devices: 2024 APT Breach Analysis

In early 2024, a sophisticated threat actor group identified as UNC6148 targeted SonicWall Secure Mobile Access (SMA) appliances with a newly discovered backdoor malware named 'OVERSTEP'. By exploiting unpatched vulnerabilities, attackers gained unauthorized access, deployed persistent hidden software, exfiltrated credentials, and established remote control over affected devices. The compromise allowed lateral movement within victim networks, providing attackers with ongoing access to sensitive data and resources while evading detection for extended periods. Organizations using SonicWall SMA were particularly at risk of operational disruptions, data breaches, and unauthorized exposure of business-critical systems. This incident exemplifies the growing trend of supply-chain and edge-device attacks by advanced persistent threats (APTs). The deployment of stealthy backdoors like OVERSTEP signals increased sophistication and automation among threat actors, further pressuring organizations to improve detection, patch management, and east-west segmentation strategies.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Russian Disinformation Group Rybar Orchestrates REST Media Election Campaign in Moldova
Impact· high

Russian Disinformation Group Rybar Orchestrates REST Media Election Campaign in Moldova

In June 2024, researchers revealed that REST Media, an online outlet targeting Moldova’s elections, is actually a front for the Russian disinformation group Rybar. Rybar, already sanctioned by the EU and wanted by the U.S., used REST Media to amplify anti-EU narratives and undermine the Party of Action and Solidarity, leveraging platforms like TikTok, Telegram, and X to achieve millions of views. Technical forensics linked REST Media’s online infrastructure and production workflows directly to Rybar, demonstrating operational overlap and deliberate efforts at obfuscation. The campaign exploited Moldova's fragmented media regulations, using cloaked registration accounts, privacy services, and anonymized hosting, making attribution complex while rapidly expanding its influence ahead of key elections. This incident exemplifies the growing sophistication of state-sponsored information operations, exploiting both technology and weak local controls. As hybrid threats, including coordinated disinformation and cyberattacks, continue to undermine democratic processes across Eastern Europe, organizations and governments face mounting regulatory, reputational, and operational risks from similar campaigns.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Brickstorm: The Next-Level Chinese APT Breach Impacting SaaS & Legal Sectors in 2025
Impact· medium

Brickstorm: The Next-Level Chinese APT Breach Impacting SaaS & Legal Sectors in 2025

In 2025, a highly sophisticated cyberespionage campaign attributed to a suspected Chinese advanced persistent threat (APT), utilizing malware later dubbed 'Brickstorm,' successfully infiltrated multiple US legal services and tech supply chain organizations. The attackers leveraged undisclosed zero-day vulnerabilities to gain initial access, maintain exceptional stealth with average dwell times of over 400 days, and move laterally into downstream customers. Their campaign targeted proprietary source code and sensitive trade/national security intelligence, making detection challenging through advanced cleanup techniques and non-overlapping infrastructure. This incident is particularly significant as it represents a new echelon of APT supply chain intrusions, echoing a rise in strategic, multi-year campaigns focusing on SaaS and cloud intermediaries. It highlights the growing need for robust east-west visibility, zero trust segmentation, and supply chain security amid evolving TTPs that routinely outpace traditional detection and response capabilities.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
UNC6148 Rootkit Attack on SonicWall SMA100 Devices in 2025
Impact· high

UNC6148 Rootkit Attack on SonicWall SMA100 Devices in 2025

In September 2025, SonicWall released a critical firmware update for its SMA 100 series products in response to a sophisticated attack campaign orchestrated by threat actor UNC6148. This incident involved the deployment of the OVERSTEP user-mode rootkit on end-of-life SMA 100 devices, providing persistent unauthorized access, stealing sensitive configuration and certificate data, and enabling lateral movement. Attackers exploited vulnerabilities in legacy firmware to maintain remote access—even post firmware upgrades—compromising credentials, OTP seeds, and digital certificates, with notable overlaps to prior Abyss ransomware operations. The incident underscores the growing threat posed by ransomware groups leveraging supply chain devices and persistent malware in network appliances. With a surge in rootkit-enabled persistence and a rise in zero-day exploitations targeting network edge devices, organizations must prioritize timely patching and end-of-life device management to curb risk exposure.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports