Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Cloudflare Thwarts Record-Breaking 22.2 Tbps DDoS Assault in 2025
In September 2025, Cloudflare successfully mitigated a record-breaking Distributed Denial-of-Service (DDoS) attack that peaked at 22.2 Tbps and 10.6 billion packets per second. Orchestrated over just 40 seconds, the massive volumetric attack overwhelmed network infrastructure, pushing the limits of firewalls, routers, and load balancers. Prior research links recent large-scale DDoS campaigns—including those hitting Cloudflare—to the AISURU botnet, which leveraged a sudden increase in infected devices globally, stemming in part from exploited router firmware vulnerabilities. Business impact was minimized due to Cloudflare’s rapid mitigation, but the attack underscores the ever-increasing scale and sophistication of DDoS threats. Record-breaking DDoS attacks are climbing in frequency and intensity, with attackers exploiting IoT vulnerabilities and leveraging formidable botnets. This surge highlights the urgent need for resilient, scalable mitigation strategies, and amplifies ongoing regulatory and industry pressure to strengthen defenses against large-scale infrastructure threats.
8 months ago
Kill Chain
State-Sponsored Command Injection Breach Targets Libraesva ESG in 2025
In September 2025, Libraesva, a widely used email security gateway provider, identified and patched a medium-severity vulnerability, CVE-2025-59689, actively exploited by a state-sponsored threat actor. The flaw involved improper sanitization in the handling of compressed email attachments, allowing attackers to execute arbitrary shell commands from non-privileged user accounts. The exploit targeted a specific appliance, highlighting both the technical skill and tactical precision of the attacker. Libraesva’s emergency fix was deployed within 17 hours to cloud and on-premise environments, and an automated scan for indicators of compromise was also released. Organizations running unsupported product versions must upgrade manually to remain protected. This incident exemplifies the growing sophistication and focus of state-linked adversaries exploiting command injection flaws in trusted security layers like email gateways. As supply-chain and infrastructure-focused attacks increase across sectors, organizations face mounting regulatory and operational pressure to maintain up-to-date security and swift response mechanisms.
8 months ago
Kill Chain
BadIIS Malware Spreads via SEO Poisoning in Operation Rewrite
In September 2025, cybersecurity analysts uncovered a targeted campaign in East and Southeast Asia, particularly Vietnam, orchestrated by a Chinese-speaking threat actor dubbed CL-UNK-1037. Using a custom malware named BadIIS, the group launched "Operation Rewrite" by employing SEO poisoning to direct unsuspecting users to compromised websites. These sites served as a launch point for deploying BadIIS, which stealthily redirected traffic, established persistent web shells, and enabled lateral movement within infected infrastructure. The attacks leveraged trusted search results to compromise both organizations and individuals, aiming to establish long-term footholds and facilitate future malicious operations. This incident highlights the increasing sophistication of adversaries leveraging advanced social engineering and technical tactics like SEO poisoning. The blending of supply chain and web application compromise with persistent malware demonstrates evolving TTPs that bypass conventional detection, emphasizing the urgent need for multilayered security and continuous vigilance for all organizations.
8 months ago
Kill Chain
SolarWinds 2025 RCE Flaw: What CVE-2025-26399 Means for Enterprise Security
In September 2025, SolarWinds disclosed a critical vulnerability (CVE-2025-26399, CVSS 9.8) in its Web Help Desk software, allowing remote code execution via deserialization of untrusted data. Attackers could exploit this flaw to execute arbitrary commands on affected systems, potentially leading to full compromise of customer environments. SolarWinds released urgent hotfixes to address the flaw after it was identified during routine security testing, emphasizing the risk to organizations running unpatched instances exposed to the internet. This incident underscores the persistent threat posed by software supply chain vulnerabilities and insecure coding practices in widely used IT management platforms. With high-profile supply chain attacks on the rise, rapid vulnerability disclosure and patching are now critical to minimizing both direct exploitation and regulatory exposure.
8 months ago
Kill Chain
US Secret Service Seizes Massive SIM Server Network Threatening Government Officials
In September 2025, the U.S. Secret Service announced it had dismantled a large-scale illicit telecommunications infrastructure across the New York tri-state area, seizing over 300 SIM servers and 100,000 SIM cards. These devices, co-located at multiple sites, were used by unknown malicious actors to facilitate threats against U.S. government officials, particularly near the United Nations. Investigators discovered that this network enabled covert communications and potentially enabled bypasses of monitoring controls, raising national security concerns. The takedown required coordinated federal action to secure the assets, neutralize the risk, and support ongoing intelligence operations. This incident highlights the ongoing evolution and physical sophistication of threat actor infrastructure, especially targeting high-profile government personnel. The scale and automation facilitated by such hardware underline the growing intersection of physical and cyber threats and serve as a wake-up call for risk teams facing advanced, hybrid attack models.
8 months ago
Kill Chain
Supermicro BMC Supply-Chain Bugs Reveal Firmware Trust Weaknesses in 2025
In September 2025, researchers unveiled two medium-severity vulnerabilities affecting Supermicro's Baseboard Management Controller (BMC) firmware. Attackers could leverage improper cryptographic signature validation to bypass root-of-trust controls, allowing the deployment of malicious firmware images through supply-chain vectors. The flaws enable an adversary to compromise hardware integrity, potentially resulting in persistent access, data exfiltration, and disruption within enterprise server environments. Supermicro promptly released firmware updates and provided mitigation guidance as exploitation risks became public. This incident reflects an unsettling rise in supply-chain attacks targeting device firmware and hardware trust anchors. It underscores both the growing sophistication of attacker techniques and the criticality of maintaining robust verification, anomaly detection, and real-time firmware integrity validation for modern IT infrastructure.
8 months ago
Kill Chain
Iranian APT Extends Reach: 2024 Nimbus Manticore Malware Hits Europe
In early 2024, a sophisticated Iran-backed threat group known as “Nimbus Manticore” launched targeted cyberattacks against several European organizations using enhanced variants of its custom malware. The attackers leveraged spear-phishing emails embedding malicious attachments as their initial access vector, resulting in the deployment of advanced payloads that enabled persistent access and lateral movement within affected networks. Once inside, the group utilized encrypted communication channels and east-west movement to exfiltrate sensitive data and evade common detection mechanisms. The incident has caused operational disruptions and triggered regulatory notifications in multiple EU member states. This breach illustrates a strategic expansion of Iran-linked APT operations beyond their traditional region, pointing to escalating risks for European enterprises. The exposed techniques underscore the necessity for advanced detection, robust internal segmentation, and regulatory alignment as attackers increasingly shift tactics to bypass perimeter controls.
8 months ago
Kill Chain
Operation Rewrite: 2025 Chinese-Speaking Threat Actor Turns BadIIS Modules into Weaponized SEO Poisons
In March 2025, cybersecurity researchers uncovered Operation Rewrite, a large-scale search engine optimization (SEO) poisoning campaign attributed to a Chinese-speaking threat actor tracked as CL-UNK-1037, with links to Group 9 and DragonRank. Attackers compromised web and application servers, deploying malicious native IIS modules dubbed "BadIIS" to intercept, modify, and proxy web traffic. By injecting SEO content and redirecting legitimate visitors, the attackers increased rankings for illicit sites, harvested sensitive data, and exfiltrated web application source code. Multiple server types—web servers, domain controllers, and high-value hosts—were compromised, indicating substantial operational impact and risk to affected organizations and individuals.
8 months ago
Kill Chain
Secret Service Disrupts Extensive NYC Telecom Threat Targeting UN Assembly
In September 2025, the U.S. Secret Service disrupted a sophisticated illicit telecom infrastructure in the New York City area, uncovering more than 300 servers and over 100,000 SIM cards located near the United Nations General Assembly. The operation identified a network enabling encrypted, anonymous communications allegedly used by foreign actors, criminals, and potentially threat groups to coordinate activities and transmit assassination threats. Investigators warned that the scale of the system posed significant risk, including the theoretical ability to disable cellular networks and disrupt critical communications during high-security events. This incident highlights rising risks of criminal and nation-state actors leveraging physical telecom infrastructure to subvert detection, illustrating how sophisticated SIM farms and server farms can facilitate large-scale anonymity and attacks. The operation underscores heightened scrutiny on telecom supply chain security during high-profile events and the need for robust infrastructure monitoring.
8 months ago
Kill Chain
AT&T 2023: How Salt Typhoon Changed the APT Playbook
In 2023, the telecommunications giant AT&T was targeted by the advanced persistent threat group Salt Typhoon, which launched a sophisticated campaign exploiting unconventional vulnerabilities. Unlike conventional attacks, Salt Typhoon focused on endpoints lacking robust detection and response (EDR), hunted for network blind spots with minimal logging, and engaged in 'living off the land' attacks—leveraging legitimate administrative tools to evade detection and persist inside networks. This multi-pronged methodology enabled deep network infiltration before discovery, ultimately jeopardizing sensitive data and service availability across AT&T’s infrastructure. Following the breach, the company reported the threat group was successfully evicted from its systems. This incident has set a precedent, with numerous threat actors now adopting Salt Typhoon’s tactics to bypass traditional security controls. The breach highlights an urgent need for organizations to enhance monitoring, bolster endpoint visibility across all platforms, and adapt defenses for evolving attacker methodologies in critical infrastructure sectors.
8 months ago
Kill Chain
EDR-Freeze: Novel Windows WER Technique Suspends EDR and Antivirus Tools
In September 2025, a security researcher revealed a novel user-mode evasion technique leveraging Windows Error Reporting (WER) to suspend the operation of Endpoint Detection & Response (EDR) and antivirus software. The proof-of-concept tool, EDR-Freeze, exploits a race condition by combining the WerFaultSecure component with the MiniDumpWriteDump API. Attackers can indefinitely freeze security processes by suspending WerFaultSecure precisely as it is executing a memory dump of the target, effectively leaving EDR or AV tools inert without requiring kernel-level vulnerabilities. This design weakness bypasses typical Bring Your Own Vulnerable Driver (BYOVD) defences and leaves minimal forensic evidence. This incident underscores the increasing sophistication of EDR evasion by cyber adversaries, who are rapidly adopting stealthy, native Windows attack chains. Organizations must adapt detection and monitoring practices to keep pace as user-mode bypasses erode longstanding layers of endpoint protection. The wider prevalence of such techniques signals a strategic shift in attacker tradecraft and compels a reassessment of endpoint hardening and response automation.
8 months ago
Kill Chain
Microsoft Entra ID Flaw Exposed: How One Vulnerability Enabled Global Admin Impersonation
In September 2025, Microsoft disclosed a severe security flaw (CVE-2025-55241) affecting its Entra ID (formerly Azure Active Directory) service. The vulnerability, which received a maximum CVSS score of 10.0, allowed threat actors to bypass token validation and impersonate any user—including Global Administrators—across any tenant. Successful exploitation could grant attackers unrestricted access to sensitive data and resources within affected organizations, making this a high-impact privilege escalation incident. Microsoft responded swiftly, issuing a critical patch to contain the risk and urging immediate customer action. This incident highlights the ongoing trend of identity-based attacks against cloud platforms, emphasizing the necessity of robust access controls and vigilant monitoring. The discovery reinforces the risks of SaaS/IDaaS privilege escalation, as attackers increasingly target provider-side weaknesses to achieve large-scale compromise.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports