Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2818 threat reports
Page 235 of 235

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Government Administration Threat Reports

Showing 28092818 / 2818 reports
CISA, FBI, and NSA Warn: China-Backed APTs Compromise Global Critical Infrastructure
Impact· low

CISA, FBI, and NSA Warn: China-Backed APTs Compromise Global Critical Infrastructure

In June 2024, leading international cybersecurity agencies—including the CISA, FBI, and NSA—issued a joint advisory detailing the extensive, multi-year espionage campaign attributed to Chinese state-backed actors such as Salt Typhoon. These APTs have targeted critical infrastructure sectors including telecommunications, government, transportation, and defense, largely by exploiting known vulnerabilities in network hardware like routers and firewalls since at least 2021. Attackers leveraged tactics such as modifying access control lists, opening non-standard ports, establishing persistent footholds, and actively capturing sensitive network traffic for credential harvesting, with the aim of gaining long-term, stealthy access and potential disruption capability across global networks. This incident underscores a major strategic escalation from pure data theft to pre-positioning for possible future disruption of vital services. Organizations face heightened pressure to implement robust detection, network segmentation, and security hardening, as state-sponsored campaigns become more brazen and influential across global critical systems.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Amazon Disrupts APT29 Credential Theft Leveraging Cloudflare and Device Code Abuse
Impact· low

Amazon Disrupts APT29 Credential Theft Leveraging Cloudflare and Device Code Abuse

In early 2024, Amazon identified and disrupted a credential theft campaign orchestrated by the Russian-linked threat actor APT29 (also known as Cozy Bear or Midnight Blizzard). Attackers redirected targeted users to fraudulent Cloudflare verification pages and abused Microsoft's device code authentication flow to harvest credentials. This sophisticated phishing operation targeted employees with access to sensitive resources and leveraged social engineering along with technical exploits to bypass multi-factor authentication controls. Amazon’s security team coordinated rapid takedown efforts, mitigating potential compromise before widespread damage or data loss could occur. This incident exemplifies the increasing sophistication of nation-state actors, particularly in leveraging supply chain services and authentication protocols. The widespread adoption of identity and device-based authentication has introduced new attack surfaces, highlighting the urgent need for adaptive security measures and ongoing user vigilance in credential management.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Federal Agency Breached via GeoServer RCE Exploit in 2024
Impact· low

Federal Agency Breached via GeoServer RCE Exploit in 2024

In July 2024, a U.S. federal civilian executive branch agency suffered a significant security breach when attackers exploited a critical remote code execution (RCE) vulnerability (CVE-2024-36401) in an unpatched GeoServer instance. Threat actors gained initial access by leveraging proof-of-concept exploits that had been made public after the vulnerability's disclosure. They moved laterally across the agency’s internal network, breaching additional web and SQL servers, deploying web shells like China Chopper, escalating privileges, and maintaining persistence. The attackers remained undetected for three weeks, only triggering detection when the agency’s EDR tool flagged suspicious malware activity. This breach underscores the growing risk posed by rapid weaponization of new vulnerabilities, particularly those affecting widely used open-source platforms. The incident follows a trend of increased attacks exploiting unpatched systems and weak internal segmentation, emphasizing the urgent need for proactive vulnerability management and robust East-West traffic controls.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Amazon ECS Privilege Escalation Flaw Exposes Critical IAM Risks in 2024
Impact· low

Amazon ECS Privilege Escalation Flaw Exposes Critical IAM Risks in 2024

In early 2024, an independent security researcher uncovered a privilege escalation vulnerability in Amazon Elastic Container Service (ECS) that allowed attackers to abuse an undocumented protocol to gain IAM permissions well beyond their original access. By exploiting a misconfiguration in ECS’s internal handling of credentials, a malicious user could escalate from container-level privileges to full IAM role hijacking, enabling lateral movement across cloud environments and access to sensitive AWS resources. Amazon responded quickly and patched the issue after disclosure, but the flaw potentially exposed numerous customer environments to risk. This incident underscores the growing risk of cloud misconfigurations and privileged identity attacks, as well as the need for real-time monitoring of cloud service behaviors. Security teams should recognize the increasing creativity of threat actors targeting identity and access weaknesses within major cloud providers.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Google Gemini AI AI Vulnerability Enables Stealth Phishing Across Google Products
Impact· medium

Google Gemini AI AI Vulnerability Enables Stealth Phishing Across Google Products

In early 2024, a significant vulnerability was uncovered in Google’s Gemini AI assistant, exposing users across Google platforms to sophisticated prompt injection attacks. Adversaries leveraged this flaw to craft invisible, malicious prompts that disguised themselves as legitimate Google Security alerts, tricking users and facilitating vishing and phishing attacks. The flaw allowed threat actors to bypass visible UI cues, broadening attack reach across Google applications and potentially compromising internal data and account integrity. Google was notified and began remediation efforts, but the proof-of-concept highlighted how large-scale AI platforms present new attack surfaces. This incident reflects an emerging trend where AI-driven tools are being targeted through prompt injection and model manipulation, creating challenging attack vectors for even the largest technology firms. The Gemini vulnerability underscores the importance of advanced security testing for generative AI and the urgent need for zero trust controls within AI ecosystems.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
APT Group Abuses AWS with HazyBeacon Malware in Southeast Asian Government Attacks
Impact· medium

APT Group Abuses AWS with HazyBeacon Malware in Southeast Asian Government Attacks

In early 2024, an advanced persistent threat (APT) group leveraged Amazon Web Services (AWS) infrastructure to conduct an intelligence-gathering campaign targeting government entities in Southeast Asia. The attackers deployed the novel "HazyBeacon" backdoor, which communicated with command-and-control (C2) infrastructure over legitimate cloud channels to evade detection, facilitating both surveillance and data exfiltration. By abusing trusted AWS services, the group masked malicious traffic as normal cloud activity, making identification and remediation complex and exposing sensitive government operations to compromise. This incident underscores a rapidly growing trend where threat actors exploit cloud provider services as covert C2 and exfiltration channels. With attackers blending into legitimate cloud workflows, organizations face heightened urgency to enhance cloud-native visibility, enforce east-west traffic controls, and implement zero trust segmentation to mitigate advanced threats.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Salt Typhoon: Chinese APT Targets US National Guard in Stealthy 2023 Breach
Impact· low

Salt Typhoon: Chinese APT Targets US National Guard in Stealthy 2023 Breach

Between March and December 2023, the Chinese state-sponsored threat group Salt Typhoon infiltrated the US National Guard’s networks, leveraging advanced persistent techniques to maintain undetected access for nearly a year. Attackers exploited security gaps, targeting unencrypted east-west and outbound network traffic, and exfiltrated sensitive operational and personnel data. The intrusion demonstrated advanced lateral movement, zero trust segmentation evasions, and targeted data exfiltration—all while remaining covert to standard detection and response tools initially. The resulting breach has exposed critical military data, presenting increased risks to operational integrity and individual privacy for National Guard personnel. This incident reflects a growing pattern of state-backed threat actors expanding targeting against US government and defense organizations, using stealthy persistence, multi-cloud exploitation, and sophisticated attack campaigns. It underscores urgent needs for continuous monitoring, encrypted network traffic, and zero trust strategies across hybrid and cloud infrastructure.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
WhatsApp GhostPairing: 2024 Account Takeover Campaign Exploits Device Linking
Impact· high

WhatsApp GhostPairing: 2024 Account Takeover Campaign Exploits Device Linking

In June 2024, cyber attackers launched widespread account takeover campaigns targeting WhatsApp users by exploiting the platform’s legitimate device-linking feature. This method, known as 'GhostPairing,' allows threat actors to hijack user accounts without requiring the victim’s credentials or multi-factor authentication codes. By intercepting or tricking users into sharing device-linking codes, attackers can remotely pair new devices to victims’ WhatsApp accounts, thus gaining complete access to conversations, contacts, and stored media. The campaign appears automated and has affected users globally, sparking concerns over the resilience of messaging platform identity controls. This incident highlights rising abuse of legitimate features and growing sophistication of social engineering tactics to bypass traditional security controls. Similar account compromise techniques are increasingly observed across the industry, prompting urgent calls for strengthened identity verification and robust monitoring of device association activities.

9 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Chinese APT Exploits Cisco AsyncOS Zero-Day in 2025: What You Need to Know
Impact· medium

Chinese APT Exploits Cisco AsyncOS Zero-Day in 2025: What You Need to Know

In December 2025, Cisco disclosed an unpatched, maximum-severity zero-day vulnerability (CVE-2025-20393) affecting AsyncOS running on Cisco Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances with exposed Spam Quarantine features. Leveraging this zero-day, the Chinese-nexus APT group UAT-9686 exploited systems by executing commands as root, deploying persistent backdoors (AquaShell), reverse SSH tunnels (AquaTunnel, Chisel), and evasion tools (AquaPurge). The campaign was active from late November 2025, with intrusions traced to sophisticated nation-state tooling and lateral movement, potentially compromising sensitive email infrastructure and enabling persistent access. This incident underscores ongoing risks from zero-day exploitation by advanced threat actors, especially those leveraging public-facing management interfaces and unpatched systems for initial access. The active exploitation by a Chinese APT mirrors broader trends in targeted cyberespionage against enterprise collaboration tools and highlights the urgency of proactive exposure management and segmentation.

9 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
State-Backed Attackers Breach SonicWall SMA1000 Devices via Zero-Day Chain in 2025
Impact· low

State-Backed Attackers Breach SonicWall SMA1000 Devices via Zero-Day Chain in 2025

In December 2025, SonicWall urgently advised customers to patch a newly identified zero-day vulnerability (CVE-2025-40602) in its SMA1000 Appliance Management Console after attackers exploited it in the wild. The attack chain combined this medium-severity local privilege escalation flaw with a critical pre-authentication deserialization vulnerability (CVE-2025-23006), allowing remote unauthenticated threat actors to execute arbitrary OS commands with root privileges on vulnerable appliances. These appliances serve as secure remote access gateways for large enterprises and critical infrastructure, amplifying the risk of broad organizational compromise and lateral movement within protected networks. The incident follows prior breaches and repeated targeting of SonicWall solutions by sophisticated, potentially state-backed actors, with over 950 SMA1000 devices found internet-exposed. Immediate remediation was urged to prevent further exploitation amidst evidence of active, targeted attacks. The SonicWall SMA1000 incident underscores a persistent trend of advanced actors leveraging zero-day exploits in network infrastructure appliances, fueling urgency around patch management and segmentation. This breach highlights the evolving complexity of attack chains targeting foundational remote access technologies and the critical need for proactive defense-in-depth and threat visibility measures.

9 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports