Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2818 threat reports
Page 26 of 235

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Government Administration Threat Reports

Showing 301312 / 2818 reports
Critical 'ShieldBreak' Zero-Day in Microsoft Defender Exposes Windows Systems
Impact· HIGH

Critical 'ShieldBreak' Zero-Day in Microsoft Defender Exposes Windows Systems

In August 2026, security researcher Nightmare Eclipse disclosed a zero-day vulnerability named 'ShieldBreak' in Microsoft Defender, allowing local attackers to escalate privileges to SYSTEM level on fully patched Windows 10, Windows 11, and Windows Server systems. This exploit bypasses the previous 'RoguePlanet' vulnerability (CVE-2026-50656) patch, indicating that the initial fix was insufficient. Microsoft has acknowledged the issue, assigning it CVE-2026-69414, and is actively working on a security update to address the flaw. The rapid succession of critical vulnerabilities in Microsoft Defender underscores the persistent challenges in securing endpoint protection solutions. Organizations must remain vigilant, ensuring timely application of patches and considering additional layers of security to mitigate potential exploitation risks.

1 month ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
French Tax Authority Data Breach 2026: ZeroBytes Compromises 678,000 Records
Impact· HIGH

French Tax Authority Data Breach 2026: ZeroBytes Compromises 678,000 Records

In August 2026, the French Ministry of the Economy and Finance disclosed a significant data breach involving the General Directorate of Public Finances (DGFiP). A threat actor known as "ZeroBytes" accessed DGFiP systems, extracting sensitive data of approximately 678,000 individuals and professionals. The compromised information included tax data such as reference tax income, family quotient, withholding tax rates, company names, and SIREN numbers. Additionally, cadastral data related to property addresses and sizes were accessed. The breach was discovered when ZeroBytes listed the stolen database for sale on a hacking forum on August 12, 2026. Upon detection, the French tax administration promptly shut down access to sensitive systems and initiated an investigation with the National Cybersecurity Agency of France (ANSSI) to assess the full impact of the breach. Affected individuals were notified, and measures were taken to prevent further unauthorized access. This incident underscores the escalating trend of cyberattacks targeting governmental institutions, highlighting the critical need for robust cybersecurity measures and vigilant monitoring to protect sensitive citizen data.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Understanding Certighost (CVE-2026-54121): A Critical AD CS Vulnerability
Impact· HIGH

Understanding Certighost (CVE-2026-54121): A Critical AD CS Vulnerability

In July 2026, a critical vulnerability known as Certighost (CVE-2026-54121) was identified in Microsoft's Active Directory Certificate Services (AD CS). This flaw allowed authenticated, low-privileged domain users to exploit the certificate enrollment process, obtaining certificates that impersonate Domain Controllers. By leveraging this vulnerability, attackers could escalate their privileges, potentially leading to full domain compromise. Microsoft addressed this issue with a security update released on July 14, 2026. ([techcommunity.microsoft.com](https://techcommunity.microsoft.com/blog/MicrosoftThreatProtectionBlog/detecting-cve-2026-54121-certighost-with-microsoft-defender/4542861?utm_source=openai)) The release of a public proof-of-concept (PoC) exploit on July 24, 2026, heightened the urgency for organizations to apply the patch promptly. This incident underscores the critical importance of securing certificate authorities and regularly auditing Active Directory configurations to prevent privilege escalation attacks. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/07/27/certighost-cve-2026-54121-poc-exploit-released/?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Cavern C2 Framework's Evolution: Leveraging DNS and Google Apps Script for Stealth
Impact· HIGH

Cavern C2 Framework's Evolution: Leveraging DNS and Google Apps Script for Stealth

In August 2026, cybersecurity researchers identified advancements in the Cavern (aka Cav3rn) command-and-control (C2) framework, utilized by Iranian nation-state hackers targeting Israeli entities. The updated framework incorporates a complex C2 module that leverages DNS A-record responses to dynamically select between direct HTTPS communication and a Google Apps Script relay for each transaction. This evolution enhances the framework's ability to blend malicious traffic with legitimate network activity, complicating detection efforts. The Cavern framework, first documented in July 2026, is associated with the Cavern Manticore group, linked to Iran's Ministry of Intelligence and Security (MOIS), and shares overlaps with other Iranian threat actors such as MuddyWater and Lyceum. The modular architecture of Cavern facilitates various post-exploitation activities, including file operations, database enumeration, Active Directory reconnaissance, and network tunneling. The integration of legitimate services like Google Apps Script and Microsoft 365 calendars into its C2 channels underscores a strategic shift towards more covert and resilient communication methods. This development highlights the increasing sophistication of nation-state cyber operations and the challenges in detecting and mitigating such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
APT36's PATCHCORD Backdoor: A New Threat to South Asian Critical Infrastructure
Impact· HIGH

APT36's PATCHCORD Backdoor: A New Threat to South Asian Critical Infrastructure

In August 2026, a cyber espionage campaign attributed to the Pakistan-aligned threat actor APT36 (Transparent Tribe) targeted Afghan telecom providers and South Asian critical infrastructure. The attackers deployed a previously undocumented backdoor named PATCHCORD, delivered through sector-specific lures such as fake VPN installers impersonating Afghan Telecom. PATCHCORD establishes persistence by hijacking browser shortcuts and communicates with a command-and-control server to execute arbitrary commands, enumerate processes, and deploy additional payloads. The campaign also introduced SHEETCORD, a Go-based backdoor utilizing Google Sheets for command-and-control, delivered via domains impersonating India's National Informatics Center. This incident underscores the evolving tactics of APT36, highlighting their focus on critical infrastructure and the use of sophisticated malware to maintain long-term access and exfiltrate sensitive information. Organizations in the region should enhance their cybersecurity measures to detect and mitigate such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
GeoServer Zero-Day SQL Injection Vulnerability Leads to RCE
Impact· HIGH

GeoServer Zero-Day SQL Injection Vulnerability Leads to RCE

In August 2026, a critical zero-day SQL injection vulnerability was discovered in GeoServer's 'jsonArrayContains' function, potentially leading to remote code execution (RCE). The flaw was publicly disclosed on August 12, 2026, by researcher @q1uf3ng, and active exploitation attempts were observed within hours. Attackers probed vulnerable systems, triggering errors without further action, but the risk of full exploitation remained high. GeoServer released patches on August 14, 2026, addressing the issue in versions 3.0.1, 2.28.5, and 2.27.6. Organizations were advised to update immediately to mitigate the risk. This incident underscores the persistent threat posed by SQL injection vulnerabilities in widely used open-source platforms. The rapid exploitation attempts highlight the need for prompt patching and vigilant monitoring of geospatial data servers to prevent potential RCE attacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Jewelbug's Exploitation of XG-Web: A Dual Threat to Governments and Cryptocurrency Users
Impact· HIGH

Jewelbug's Exploitation of XG-Web: A Dual Threat to Governments and Cryptocurrency Users

In August 2026, the China-linked threat actor known as Jewelbug was identified conducting cyber espionage operations targeting governments and militaries, alongside engaging in cryptocurrency fraud. Utilizing a sophisticated tool named XG-Web, Jewelbug transformed victims' browsers into remote-control channels, enabling deep infiltration into host systems and internal networks. This dual-purpose framework facilitated both espionage against governmental entities across the Middle East, Southeast Asia, and South Asia, and financially motivated cryptocurrency fraud aimed at Chinese-speaking users. The group's operations were marked by the development of multiple generations of command-and-control code and a suite of implants affecting browsers, Windows endpoints, Linux servers, and network devices, all feeding into a centralized victim database. The significance of this incident lies in the convergence of state-sponsored cyber espionage and cybercrime within a single operational framework. Jewelbug's activities underscore the evolving landscape where nation-state actors increasingly blur the lines between political objectives and financial gain. This trend highlights the urgent need for organizations to adopt comprehensive cybersecurity measures that address both traditional espionage tactics and emerging cybercriminal methodologies.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
U.S. Private Sector Empowered to Combat Foreign Cybercriminals
Impact· LOW

U.S. Private Sector Empowered to Combat Foreign Cybercriminals

On August 12, 2026, President Donald Trump signed a memorandum instructing the National Coordination Center (NCC) to establish a program enabling vetted U.S. private sector companies to conduct cyber operations against foreign Transnational Criminal Organizations (TCOs). This initiative allows authorized firms to perform cyber surveillance and cyber effects operations, including accessing sensitive data and disrupting information systems, under federal oversight. The program aims to counter cyber-enabled crimes such as ransomware, phishing, and financial fraud targeting American citizens. This policy marks a significant expansion of the private sector's role in offensive cyber operations, raising legal and security considerations. Existing U.S. laws prohibit private entities from conducting cyber attacks without court authorization, and this development parallels international trends, such as Germany's recent legislation granting its intelligence agencies broader cyber capabilities.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Apple Issues Warnings on Mercenary Spyware Threats in 110 Countries
Impact· MEDIUM

Apple Issues Warnings on Mercenary Spyware Threats in 110 Countries

In August 2026, Apple issued threat notifications to users in 110 countries, alerting them to potential targeting by mercenary spyware attacks. These sophisticated attacks are designed to remotely compromise iPhones, often focusing on individuals such as journalists, activists, politicians, and diplomats. Apple emphasized the severity of these threats and advised recipients to take the notifications seriously. The prevalence of mercenary spyware attacks underscores the evolving landscape of cyber threats, highlighting the need for heightened vigilance and robust security measures among high-risk individuals and organizations.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Exploiting Chrome DevTools Protocol: A New Vector for Session Hijacking in Windows Browsers
Impact· MEDIUM

Exploiting Chrome DevTools Protocol: A New Vector for Session Hijacking in Windows Browsers

In August 2026, cybersecurity researchers disclosed a post-exploitation technique that leverages the Chrome DevTools Protocol (CDP) within active Google Chrome or Microsoft Edge processes on Windows systems. This method allows attackers with existing code execution capabilities to access cookies, saved data, and authenticated browser sessions without exploiting any specific browser vulnerabilities. The technique involves injecting code into running browser processes to activate the CDP, thereby exposing the browser's current context over a specified port. This approach builds upon prior research and tools, such as the CDP-Enable-BOF developed by SpecterOps, which facilitates the activation of the debugging server from within an existing browser process. The method requires a running browser process and is limited to x64 systems. The significance of this technique lies in its ability to bypass traditional security measures by operating within the authenticated context of the browser. This development underscores the evolving nature of post-exploitation strategies and highlights the need for robust detection mechanisms to identify unauthorized process injections and anomalous activities within browser processes.

1 month ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Mustang Panda's CoolClient Backdoor: A New Era of Stealth with Signed Rootkits
Impact· HIGH

Mustang Panda's CoolClient Backdoor: A New Era of Stealth with Signed Rootkits

In August 2026, the Chinese state-sponsored threat actor known as Mustang Panda (also referred to as HoneyMyte) deployed an enhanced version of their CoolClient backdoor, now incorporating a signed Windows kernel-mode rootkit. This advancement enables the malware to conceal and protect malicious processes, files, registry entries, and command-and-control (C2) communications, significantly bolstering its stealth capabilities. The campaign targeted government entities in Myanmar, Mongolia, Pakistan, and Russia, with CoolClient often deployed as a secondary backdoor following an initial PlugX infection. The rootkit is installed when the malware attains full access to the Service Control Manager and the SeTcbPrivilege privilege; otherwise, it proceeds without the driver component. Kaspersky's analysis revealed that the driver, named msagent.sys, is digitally signed with a certificate issued to Nanjing Ranyi Technology Co., Ltd., valid from August 2013 to September 2014. This development underscores the evolving sophistication of Mustang Panda's toolset and their persistent focus on governmental targets. The integration of a signed kernel-mode rootkit into CoolClient reflects a broader trend among advanced persistent threat (APT) groups toward enhancing malware stealth to evade detection. This incident highlights the critical need for organizations, especially government agencies, to implement robust endpoint detection and response (EDR) solutions capable of identifying and mitigating such sophisticated threats. Additionally, it emphasizes the importance of continuous monitoring and updating of security protocols to counteract the evolving tactics of state-sponsored cyber adversaries.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
China-Nexus APT Exploits VMware vCenter Vulnerability to Deploy Ransomware
Impact· CRITICAL

China-Nexus APT Exploits VMware vCenter Vulnerability to Deploy Ransomware

In August 2026, a suspected China-nexus advanced persistent threat (APT) exploited CVE-2026-59310, a critical directory-traversal vulnerability in VMware vCenter Server, to execute arbitrary code. This campaign compromised 361 unique IP addresses across 47 countries, including Germany, the U.S., Turkey, Iran, and France. The attackers deployed Babuk-derived ransomware on ESXi hosts, encrypting files with the ".babyk" extension, potentially as a smokescreen to distract defenders and hinder forensic analysis. This incident underscores the urgency for organizations to promptly apply security patches, especially for critical vulnerabilities in widely used infrastructure. The rapid exploitation following public disclosure highlights the need for proactive vulnerability management and robust incident response strategies to mitigate the risks posed by sophisticated threat actors.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports