Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2818 threat reports
Page 29 of 235

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Government Administration Threat Reports

Showing 337348 / 2818 reports
Lazarus Group's Operation Dream Job: Exploiting Windows Zero-Day to Target Defense Firms
Impact· HIGH

Lazarus Group's Operation Dream Job: Exploiting Windows Zero-Day to Target Defense Firms

In July 2026, the North Korean state-sponsored Lazarus Group exploited a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies in Europe and India. This vulnerability, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys), allowed attackers to escalate local privileges to SYSTEM level. The group utilized this exploit in their Operation Dream Job campaign, delivering malicious payloads through fraudulent recruitment offers to employees in defense, aerospace, and aviation organizations. The attacks led to unauthorized access, data exfiltration, and deployment of advanced malware, including the FudModule rootkit and the Troy backdoor, compromising sensitive military technologies such as surveillance sensors, drones, and robotics. This incident underscores the persistent threat posed by nation-state actors leveraging zero-day vulnerabilities to infiltrate critical sectors. The Lazarus Group's continued evolution in tactics, including the use of sophisticated malware and exploitation of legitimate web infrastructure, highlights the need for organizations to adopt proactive cybersecurity measures, such as timely patch management, employee training on social engineering tactics, and robust network monitoring to detect and mitigate such advanced persistent threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Hundreds of Fake Chrome VPN Extensions Compromise User Security
Impact· MEDIUM

Hundreds of Fake Chrome VPN Extensions Compromise User Security

In August 2026, researchers uncovered a campaign involving over 737 malicious Chrome browser extensions that impersonated reputable VPN services such as Proton VPN, NordVPN, and ExpressVPN. These extensions, downloaded nearly 75,000 times primarily by Russian users, rerouted all browser traffic through SOCKS5 proxies controlled by a single operator. This setup allowed the threat actor to monitor users' browsing activities, including destination URLs and any unencrypted data transmitted over HTTP. The extensions employed deceptive tactics, including advertising non-existent premium server locations and using misleading disclosures to evade detection. Despite Google's removal of over 200 of these extensions, more than 500 remained available in the Chrome Web Store at the time of discovery. This incident underscores the persistent threat posed by malicious browser extensions and highlights the need for vigilant scrutiny of browser add-ons. Users are advised to verify the authenticity of extensions before installation and to regularly review and manage their browser's proxy settings to prevent unauthorized data interception.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Understanding the 'Plug and Pwn' Attack: A New Threat to Windows Systems
Impact· HIGH

Understanding the 'Plug and Pwn' Attack: A New Threat to Windows Systems

In August 2026, security researchers unveiled the 'Plug and Pwn' attack, exploiting Windows' Plug and Play feature to gain SYSTEM privileges by emulating USB devices. By presenting fake USB hardware, attackers could trigger Windows to install vulnerable vendor software automatically, leading to unauthorized access. Notably, some attack vectors required no user interaction or physical device connection, utilizing Remote Desktop Protocol (RDP) to achieve the same outcome. This method underscores significant vulnerabilities in Windows' device installation processes, potentially allowing attackers to execute arbitrary code with elevated privileges. The 'Plug and Pwn' attack highlights the evolving sophistication of hardware-based exploits and the critical need for organizations to reassess endpoint security measures. As attackers increasingly leverage legitimate system functionalities for malicious purposes, it becomes imperative to implement stringent device installation policies and monitor for anomalous hardware behaviors to mitigate such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Lazarus Group's Operation Dream Job: Exploiting Windows Zero-Day to Deploy 'Troy' Backdoor
Impact· HIGH

Lazarus Group's Operation Dream Job: Exploiting Windows Zero-Day to Deploy 'Troy' Backdoor

In August 2026, the North Korean state-sponsored Lazarus Group exploited a zero-day vulnerability, CVE-2026-68820, in the Windows Ancillary Function Driver for WinSock (AFD.sys) to target defense and aerospace companies across France, Germany, Brazil, and India. Utilizing their 'Operation Dream Job' campaign, they lured professionals with fake job offers, leading victims to download malicious PDFs or trojanized PDF viewers. This method facilitated the deployment of a new backdoor named 'Troy,' granting the attackers remote access and control over compromised systems. The campaign's sophistication underscores the persistent threat posed by Lazarus Group to critical industries worldwide. This incident highlights the evolving tactics of nation-state actors in leveraging zero-day vulnerabilities combined with social engineering to infiltrate high-value targets. Organizations must remain vigilant, ensuring timely patching of vulnerabilities and educating employees about the risks of unsolicited job offers and phishing attempts.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
City-Forum Data Theft Attacks: A Wake-Up Call for SaaS Security
Impact· HIGH

City-Forum Data Theft Attacks: A Wake-Up Call for SaaS Security

In August 2026, a data theft campaign named 'City-Forum' was identified, targeting misconfigured Salesforce Experience Cloud and ServiceNow customer portals. The attackers exploited overly permissive sharing rules and portal configurations, allowing unauthorized access to sensitive data through anonymous guest accounts. The campaign, traced to the IP address 158.220.87.79 associated with the domain city-forum.com, has been active since at least March 2025, affecting various sectors including telecommunications, finance, enterprise software, and public services. The 'City-Forum' attacks underscore the critical importance of securing SaaS platforms against unauthorized access. Organizations must review and tighten guest-user permissions and sharing settings to prevent data exposure. This incident highlights a growing trend of cybercriminals exploiting misconfigurations in widely used platforms, emphasizing the need for continuous monitoring and proactive security measures.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft's August 2026 Patch Tuesday: Addressing 398 Security Vulnerabilities
Impact· HIGH

Microsoft's August 2026 Patch Tuesday: Addressing 398 Security Vulnerabilities

In August 2026, Microsoft released patches for 398 security vulnerabilities across its Windows operating systems and supported software. Among these, CVE-2026-68820, a privilege escalation flaw in the afd.sys component, was actively exploited. This vulnerability allows attackers to elevate privileges by exploiting race conditions in the Windows socket driver. Additionally, two other vulnerabilities, CVE-2026-62832 and CVE-2026-72971, were publicly disclosed prior to the patch release, highlighting the critical need for timely updates. The increasing volume of vulnerabilities, attributed to AI-driven discovery methods, underscores the necessity for organizations to enhance their patch management processes. The active exploitation of CVE-2026-68820 emphasizes the urgency of applying these patches promptly to mitigate potential security breaches.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Gunra Ransomware's 2026 Exploitation of Fortinet Vulnerabilities: A Wake-Up Call for Cybersecurity
Impact· CRITICAL

Gunra Ransomware's 2026 Exploitation of Fortinet Vulnerabilities: A Wake-Up Call for Cybersecurity

In early 2026, the Gunra ransomware group, a Ransomware-as-a-Service (RaaS) operation, exploited known vulnerabilities in Fortinet products, notably CVE-2026-24858, to bypass multi-factor authentication (MFA) and gain unauthorized access to critical infrastructure and government organizations worldwide. Utilizing the leaked Conti ransomware code, Gunra executed double-extortion attacks, encrypting data and threatening to publish stolen information unless ransoms were paid. The group's operations expanded through a structured affiliate program, targeting sectors such as healthcare, finance, manufacturing, transportation, and government services. ([shellcodex.com](https://shellcodex.com/ransomware/group/gunra?utm_source=openai)) This incident underscores the persistent threat posed by ransomware groups leveraging known vulnerabilities and the importance of timely patching and robust security measures. The exploitation of Fortinet flaws highlights the need for organizations to prioritize vulnerability management and implement comprehensive security protocols to mitigate such risks. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-22572/?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Ransomware Attack Disrupts Colombian Justice Ministry Amid Political Transition
Impact· MEDIUM

Ransomware Attack Disrupts Colombian Justice Ministry Amid Political Transition

In early August 2026, Colombia's Ministry of Justice experienced a ransomware attack that disrupted several public-facing services, including those related to illicit-drug monitoring and legal processes. The incident occurred just days before the nation's presidential transition, highlighting the vulnerability of critical government infrastructure during periods of political change. While some files were encrypted, acting Minister of Justice Cielo Rusinque confirmed that no data was exfiltrated. This attack is part of a broader trend of increasing cyber threats targeting Colombian government agencies and critical infrastructure. In the past year, exploit attempts in the country have more than tripled, with attackers focusing on exposed and potentially vulnerable systems. The incident underscores the urgent need for enhanced cybersecurity measures to protect national assets, especially during times of political transition.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Cisco ASA and FTD Vulnerability (CVE-2026-20349) Exploited in the Wild
Impact· HIGH

Critical Cisco ASA and FTD Vulnerability (CVE-2026-20349) Exploited in the Wild

In August 2026, Cisco disclosed a high-severity vulnerability (CVE-2026-20349) in its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. This flaw allows unauthenticated remote attackers to trigger a denial-of-service (DoS) condition by sending crafted HTTP requests to the Remote Access SSL VPN service on affected devices. Exploitation results in device reloads, causing service disruptions. The vulnerability affects devices with specific configurations, including IKEv2 Remote Access VPN, SSL-VPN, and Zero Trust Network Access2. Cisco has released software updates to address this issue, as no workarounds are available. The active exploitation of CVE-2026-20349 underscores the critical need for organizations to promptly apply security patches to network infrastructure devices. Delayed responses to such vulnerabilities can lead to significant operational disruptions and potential security breaches. This incident highlights the importance of maintaining up-to-date systems and monitoring for emerging threats to ensure network resilience.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
ShieldBreak Zero-Day PoC Exposes Microsoft Defender Patch Bypass
Impact· HIGH

ShieldBreak Zero-Day PoC Exposes Microsoft Defender Patch Bypass

In August 2026, security researcher Chaotic Eclipse released a proof-of-concept (PoC) for a new Microsoft zero-day vulnerability named ShieldBreak. This vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656, also known as RoguePlanet. RoguePlanet is a race condition that, if exploited, allows an attacker to spawn a shell with SYSTEM-level privileges, enabling the execution of arbitrary code or unauthorized actions. Despite Microsoft's release of a patch in July 2026 to address RoguePlanet, the ShieldBreak PoC indicates that the patch is ineffective, as it can be fully bypassed, maintaining a 100% success rate in tests on Windows 11 25H2 and Windows Server 2025. The release of ShieldBreak underscores the persistent challenges in effectively patching critical vulnerabilities. It highlights the need for organizations to adopt comprehensive security measures beyond relying solely on vendor patches. This incident also emphasizes the importance of continuous monitoring and rapid response strategies to mitigate potential exploits that can arise even after patches are applied.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
LiteLLM Supply Chain Attack: A Wake-Up Call for Open-Source Security
Impact· HIGH

LiteLLM Supply Chain Attack: A Wake-Up Call for Open-Source Security

In March 2026, versions 1.82.7 and 1.82.8 of LiteLLM, an open-source AI gateway, were compromised and published on PyPI. These versions contained credential-stealing code capable of harvesting sensitive information such as cloud keys, SSH keys, Kubernetes tokens, and database passwords. The malicious packages were available for approximately 40 minutes before being quarantined. Subsequent analysis by CloudSEK revealed that the attackers had exfiltrated data from approximately 2,500 organizations, including major corporations like NVIDIA, Cisco, Deloitte, Volkswagen, FedEx, Siemens, and X Corp. This incident underscores the escalating threat of supply chain attacks targeting widely used open-source components. Organizations are urged to implement stringent security measures, including regular audits of third-party dependencies, to mitigate the risk of similar breaches.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Global Exploitation of VMware vCenter Vulnerability CVE-2026-59310
Impact· CRITICAL

Global Exploitation of VMware vCenter Vulnerability CVE-2026-59310

In early August 2026, threat actors began exploiting CVE-2026-59310, a critical directory-traversal vulnerability in VMware vCenter Server, allowing unauthenticated remote code execution. Despite Broadcom's release of patches in late July, attackers leveraged this flaw to deploy persistent access mechanisms, notably using reverse_ssh to maintain control over compromised systems. The campaign affected 361 unique IP addresses across 47 countries, with significant concentrations in Germany, the U.S., Turkey, Iran, and France. This incident underscores the rapid weaponization of disclosed vulnerabilities by advanced persistent threat actors, emphasizing the necessity for organizations to promptly apply security patches and monitor for unauthorized outbound connections indicative of compromise.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports