Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Active Exploitation of Critical Zimbra RCE Vulnerability Threatens Email Infrastructure Worldwide
In August 2026, CERT Polska warned that attackers are actively exploiting CVE-2026-73570, a critical remote code execution vulnerability in Zimbra Collaboration Suite. The flaw allows unauthenticated attackers to execute arbitrary commands through improper sanitization in the SNMP monitoring component. With over 12,100 Zimbra servers exposed online globally, this vulnerability poses significant risks to hundreds of millions of users across businesses and government agencies worldwide. The Zimbra security team released a patch in version 10.1.20 on July 20, 2026. This incident highlights the ongoing trend of nation-state actors and cybercriminals targeting collaboration platforms for initial access and credential harvesting. Zimbra vulnerabilities have been consistently exploited by Russian APT groups including Winter Vivern, APT29, and APT28, making rapid patching and monitoring critical for organizations.
1 month ago
Kill Chain
Critical MLflow AI Platform Vulnerability Exploited for Cloud Credential Theft
CISA added CVE-2026-64849, a critical DNS-rebinding server-side request forgery vulnerability in MLflow's webhook delivery system, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The flaw allows unauthenticated attackers to remotely access internal services and cloud metadata configurations on unpatched MLflow instances, enabling theft of AWS IAM credentials and other sensitive data. MLflow, an open-source AI engineering platform with over 30 million monthly downloads, patched the vulnerability in version 3.15.0, but federal agencies have only two weeks to secure their systems under BOD 26-04. This incident highlights the growing attack surface created by AI infrastructure components as organizations rapidly adopt machine learning platforms without adequate security hardening, making AI systems prime targets for credential theft and lateral movement.
1 month ago
Kill Chain
Manic Android Malware Introduces Peer-to-Peer Data Exfiltration via Nearby Devices
The Manic Android malware, active since February 2026, represents a sophisticated mobile threat targeting banking, government, and cryptocurrency applications across Central and Western Europe, with primary focus on Ukraine. This malware employs transparent overlays to capture user inputs, leverages Android Accessibility services for comprehensive device control, and implements an innovative peer-to-peer data exfiltration mechanism using Wi-Fi Direct and Bluetooth connections through nearby infected devices. Manic can intercept SMS messages, capture lock PINs, monitor screens, collect location data, and provide remote access to operators via WebRTC sessions, targeting over 169 applications including banking, eID, payment, and authenticator apps. This incident highlights the evolving sophistication of mobile banking malware and the increasing threat to critical infrastructure applications, particularly government eID systems, as attackers develop novel exfiltration methods that bypass traditional network-based security controls.
1 month ago
Kill Chain
Critical Citrix NetScaler Authentication Bypass Vulnerabilities Demand Immediate Action
On August 20, 2026, Citrix disclosed two critical vulnerabilities affecting NetScaler Gateway and NetScaler ADC appliances. The most severe flaw, CVE-2026-19490, allows remote unauthenticated attackers to bypass authentication when appliances are configured as AAA virtual servers or Gateway services with SAML Action enabled. The second vulnerability, CVE-2026-19489, enables denial-of-service attacks when SIP ALG is enabled on large-scale NAT configurations. With over 24,000 NetScaler instances exposed online and Citrix's history of 22 exploited vulnerabilities in five years, immediate patching is critical. This incident highlights the continuing trend of authentication bypass vulnerabilities targeting enterprise network infrastructure, particularly VPN and remote access solutions that became critical during hybrid work adoption and remain prime targets for initial access in modern cyber campaigns.
1 month ago
Kill Chain
Russian APT29 Clusters Weaponize OAuth and WhatsApp in Sophisticated 2026 Espionage Campaign
Between March and August 2026, three suspected Russian cyber espionage clusters (UNC6293, UNC7005, and UNC5976) conducted sophisticated authentication-focused attacks targeting academics, diplomats, defense personnel, and think tank researchers across Europe and the United States. The threat actors, linked to APT29/Ice Relic operations, exploited legitimate OAuth flows, WhatsApp device linking, and captive Wi-Fi portals to compromise personal accounts through highly targeted phishing campaigns. Their operations included the CaptiveCrunch campaign that hijacked hotel and airport Wi-Fi networks, deployed CornFlake RAT and ChocoShell infostealers, and potentially compromised managed service providers in supply chain attacks affecting approximately 70 victim locations globally. These incidents highlight the evolving threat landscape where state-sponsored actors increasingly abuse legitimate authentication mechanisms and trusted infrastructure to bypass traditional security controls, making detection significantly more challenging for organizations.
1 month ago
Kill Chain
How Pakistan's Transparent Tribe Exploited Cybersecurity Gaps in Afghan Infrastructure
Pakistan's Transparent Tribe (APT36) conducted an active cyber espionage campaign against Afghan government and telecommunications organizations from December 2025 through August 2026, deploying new malware variants including Patchcord and Sheetcord backdoors. The threat actor successfully compromised an Afghan Telecom IT officer and an international company's Afghan subsidiary, stealing sensitive data and WhatsApp communications for further social engineering attacks. While attacks against Indian government agencies including the Ministries of Defense and Foreign Affairs were attempted, these were unsuccessful due to India's superior cybersecurity defenses and proactive blocking by CERT-In. This incident highlights the growing sophistication of regional APT groups targeting countries with immature cybersecurity infrastructures, particularly in the context of heightened geopolitical tensions in South Asia and the Taliban's governance challenges in Afghanistan.
1 month ago
Kill Chain
NASA Spacecraft Control Vulnerability Highlights Critical Infrastructure Security Gaps
In August 2026, Cycode security researchers disclosed critical vulnerabilities in NASA's AIT-GUI spacecraft control software that allowed unauthenticated attackers to issue arbitrary commands to spacecraft and instruments. The flaw chain, rated 9.4 CVSS, affected AIT-GUI versions 2.5.1 and earlier, exposing command endpoints without authentication, authorization, or CSRF protection. Attackers could execute server-side scripts, run command sequences, and issue spacecraft commands via simple HTTP POST requests to the web interface that bound to all network interfaces by default. This incident highlights the growing risk of AI-assisted vulnerability research and the critical need for secure-by-default configurations in operational technology environments. As space infrastructure becomes increasingly digitized and interconnected, authentication gaps in command and control systems represent existential risks to mission-critical operations.
1 month ago
Kill Chain
Manic Malware Breaks the Air Gap: How Wi-Fi Mesh Networks Enable Data Theft from Offline Devices
The Manic Android malware campaign emerged in February 2026, targeting Ukrainian banks, government services, and Russian financial institutions through sophisticated phishing sites and dropper applications. This hybrid banking malware and spyware employs a novel Wi-Fi mesh technique that enables infected devices to relay stolen data through nearby compromised devices with internet access, allowing data exfiltration even when the primary device is offline. The malware monitors 169 package IDs across financial, government, and messaging applications, utilizing accessibility services abuse and transparent overlays to capture sensitive data including PIN codes, authentication credentials, and location information. This incident represents a significant evolution in mobile threats, demonstrating how attackers are adapting to air-gapped security measures and developing mesh-based exfiltration techniques. The campaign's timing amid ongoing geopolitical tensions and its focus on Ukrainian infrastructure highlights the intersection of cybercrime and nation-state activities, making mobile device security and network segmentation increasingly critical for organizational defense strategies.
1 month ago
Kill Chain
SilkParasite APT's Advanced RATs Target Central Asian Governments
In late 2025, the Chinese-nexus advanced persistent threat (APT) group known as SilkParasite initiated a cyber-espionage campaign targeting government organizations across Central Asia, including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. Utilizing spear-phishing emails with regionally tailored Office documents, often within password-protected RAR archives, the attackers deployed a suite of seven remote access Trojans (RATs), five of which were previously undocumented. These RATs enabled long-term access to sensitive governmental systems, facilitating intelligence gathering and potential disruption of critical operations. This incident underscores the evolving sophistication of state-sponsored cyber threats, particularly the use of modular and AI-assisted malware designed to evade detection. The strategic focus on Central Asian governments highlights a shift in geopolitical cyber-espionage activities, emphasizing the need for enhanced cybersecurity measures and international cooperation to mitigate such threats.
1 month ago
Kill Chain
China-Linked AI Cyberattack Targets Taiwan Government in 2026
In early July 2026, a sophisticated cyberattack targeted Taiwan's government agencies and critical infrastructure. Over four days, attackers employed autonomous AI agents to compromise 85 government accounts, exfiltrate over 2,500 personnel records, and infiltrate the nuclear safety agency and multiple energy companies. The AI-driven system utilized open-source frameworks like Hermes and OpenClaw to autonomously map networks, identify vulnerabilities, and adapt strategies in real-time, all while masquerading as legitimate penetration tests. The attack did not rely on zero-day exploits but exploited existing security weaknesses such as exposed APIs and weak authentication mechanisms. Internal communications in Simplified Chinese suggest a high probability of Chinese state-sponsored involvement. This incident underscores the escalating threat of AI-driven cyberattacks, highlighting the need for enhanced identity management and advanced behavioral monitoring to counteract machine-driven intrusions with human-like coordination and minimal oversight.
1 month ago
Kill Chain
Critical Vulnerabilities in macOS, SharePoint, vCenter, and IKE Under Active Exploitation
In August 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. These vulnerabilities include CVE-2026-65400 affecting Apple macOS, CVE-2026-55040 in Microsoft SharePoint, CVE-2026-59310 in VMware vCenter, and CVE-2026-33824 in Microsoft Internet Key Exchange (IKE) Service Extensions. Exploitation of these flaws has led to unauthorized access, deployment of cryptocurrency miners, backdoors, and ransomware attacks across multiple countries. The active exploitation of these vulnerabilities underscores the persistent threat posed by sophisticated cyber actors targeting widely used enterprise systems. Organizations are urged to prioritize patching and implement robust security measures to mitigate potential risks associated with these exploits.
1 month ago
Kill Chain
Critical Vulnerabilities Discovered in CISA's Malcolm Tool
In August 2026, multiple vulnerabilities were identified in CISA's Malcolm network traffic analysis tool, including CVE-2026-55676, CVE-2026-63133, CVE-2026-63134, CVE-2026-63177, CVE-2026-19670, and CVE-2026-19671. These flaws ranged from unbounded archive extraction leading to denial-of-service conditions to path traversal issues allowing unauthorized access. Exploitation of these vulnerabilities could enable attackers to execute arbitrary code, create unauthorized directories, or cause service disruptions. CISA promptly released patches to address these issues, urging users to update to the latest versions to mitigate potential risks. ([vulners.com](https://vulners.com/nvd/NVD%3ACVE-2026-63133?utm_source=openai)) The discovery of these vulnerabilities underscores the critical importance of timely software updates and vigilant monitoring of security advisories. As cyber threats continue to evolve, organizations must prioritize the implementation of patches and adhere to best practices to safeguard their systems against potential exploits.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports