Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2818 threat reports
Page 3 of 235

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Government Administration Threat Reports

Showing 2536 / 2818 reports
Chinese APT FamousSparrow Targets Latin America with Advanced SparroWocky Backdoor
Impact· HIGH

Chinese APT FamousSparrow Targets Latin America with Advanced SparroWocky Backdoor

In August 2025, the China-aligned state-sponsored threat actor FamousSparrow began deploying a new backdoor called SparroWocky across multiple Latin American countries including Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The modular C++ backdoor replaced their previous SparrowDoor implant and targeted governmental entities through DLL sideloading techniques. SparroWocky features advanced capabilities including file execution, TCP proxy functionality, command execution, data exfiltration, screenshot capture, and self-deletion mechanisms while leveraging open-source tools like Mbed TLS for secure C2 communications. This campaign represents the evolving sophistication of Chinese APT groups who are increasingly integrating open-source offensive tools directly into custom malware rather than using them as separate utilities. The geographic focus on Latin America suggests either a formal mandate or opportunistic targeting based on current geopolitical circumstances, highlighting the global reach of state-sponsored cyber espionage operations.

2 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Adds Two Critical Vulnerabilities to KEV Catalog: Cisco ISE and Acronis Backup Under Active Attack
Impact· CRITICAL

CISA Adds Two Critical Vulnerabilities to KEV Catalog: Cisco ISE and Acronis Backup Under Active Attack

CISA added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog in September 2026: CVE-2026-76460 affecting Cisco Identity Services Engine's privileged API usage, and CVE-2026-87886 involving Acronis Backup's incorrect default permissions. Both vulnerabilities are actively exploited in the wild and pose significant risks to federal enterprises. The additions reinforce CISA's Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize rapid remediation of high-risk vulnerabilities on publicly exposed assets that could grant total system control post-exploitation. These KEV additions highlight the ongoing evolution of threat actor tactics targeting identity management systems and backup infrastructure, critical components in modern enterprise security architectures that attackers increasingly exploit for persistence and lateral movement.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
LausivLoader Dissected: How Modern Malware Uses Steganography and Multi-Stage Execution
Impact· MEDIUM

LausivLoader Dissected: How Modern Malware Uses Steganography and Multi-Stage Execution

In August 2023, security researchers analyzed a sophisticated LausivLoader malware campaign that utilized multi-stage execution chains to evade detection. The attack began with a malspam email containing a fake purchase quotation request, delivering a JavaScript file disguised as a business document. The malware employed innovative inter-process communication techniques, using environment variables to pass data between JavaScript and PowerShell stages, ultimately downloading encrypted payloads hidden within PNG image files using steganography. This multi-layered approach demonstrates advanced evasion tactics including AMSI bypassing, process hollowing, and scheduled task persistence mechanisms. This incident highlights the evolution of commodity malware loaders toward more sophisticated obfuscation and persistence techniques, reflecting broader trends in cybercriminal operations that leverage legitimate system features for malicious purposes.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(low)
Read Report
How Automated Credential Testing Tools Expose Identity Security Gaps
Impact· MEDIUM

How Automated Credential Testing Tools Expose Identity Security Gaps

Praetorian's enhanced Brutus credential testing engine demonstrates the persistent vulnerability of organizations to identity-based attacks in 2024. The tool now automates the complete attack chain from personnel discovery through credential validation across 14 additional protocols including industrial systems like OPC UA and infrastructure management interfaces like IPMI. Brutus systematically identifies organizational personnel through multiple sources, generates username variations, tests credentials against discovered services, and maintains persistence of confirmed credentials for reuse across future assessments. This evolution reflects how attackers continue to exploit weak credential hygiene and password reuse as the primary attack vector into enterprise environments. This development highlights the ongoing reality that most successful cyberattacks still begin with compromised credentials rather than sophisticated zero-day exploits, emphasizing the critical need for robust identity security measures and comprehensive credential management programs.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
FBI Disrupts NightmareStresser: Major DDoS-for-Hire Takedown Exposes Cybercrime-as-a-Service Threats
Impact· LOW

FBI Disrupts NightmareStresser: Major DDoS-for-Hire Takedown Exposes Cybercrime-as-a-Service Threats

In December 2024, the FBI and Royal Canadian Mounted Police seized the primary domain and associated websites of NightmareStresser, one of the longest-running and most popular DDoS-for-hire services used by cybercriminals globally. Operating since at least 2022, the service facilitated hundreds of thousands of DDoS attacks against educational institutions, government agencies, gaming platforms, and millions of individuals worldwide. The takedown was part of Operation PowerOFF, an ongoing international effort targeting IP stressers and booter services that make DDoS attacks accessible to non-technical users through user-friendly interfaces and tutorials. This incident highlights the persistent threat of commoditized cyber attack services that democratize sophisticated attack capabilities, enabling script kiddies and low-skilled threat actors to launch disruptive campaigns against critical infrastructure and services with minimal technical expertise required.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
How Iranian Cyber Operations Target the Hidden Infrastructure Behind U.S. Military Power
Impact· HIGH

How Iranian Cyber Operations Target the Hidden Infrastructure Behind U.S. Military Power

Iranian cyber operations are increasingly targeting the interconnected civilian infrastructure that supports U.S. military operations, including commercial railroads, ports, utilities, and defense contractors. Rather than pursuing catastrophic single attacks, Iranian threat groups are conducting persistent, volume-based campaigns across multiple smaller targets to strain response capabilities and disrupt military logistics chains. Recent attacks on water utilities across 12 states and a four-day power plant outage in the UK demonstrate this strategy of imposing cumulative operational strain rather than seeking headline-grabbing breaches. This threat model reflects Iran's adaptation to prolonged conflict scenarios, where creating sustained disruption across military-supporting infrastructure becomes more strategically valuable than traditional espionage or single-point failures.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Google Patches Actively Exploited Android Zero-Day CVE-2026-58704 on Pixel Devices
Impact· HIGH

Google Patches Actively Exploited Android Zero-Day CVE-2026-58704 on Pixel Devices

In September 2026, Google addressed CVE-2026-58704, a high-severity zero-day vulnerability in Android Pixel devices that was actively exploited in targeted attacks. The flaw stems from improper authorization and protection mechanism failures in the Modem subcomponent, allowing attackers with adjacent network access to escalate privileges without user interaction. Google's security update patched this vulnerability along with 109 other security issues, including 12 remote code execution and 89 privilege escalation flaws rated critical or high severity. This incident highlights the growing sophistication of mobile device attacks and the critical importance of rapid patch deployment in enterprise environments where mobile devices access corporate networks and sensitive data.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical ScreenConnect Vulnerability CVE-2026-84869 Under Active Attack
Impact· CRITICAL

Critical ScreenConnect Vulnerability CVE-2026-84869 Under Active Attack

In September 2026, CISA added ConnectWise ScreenConnect vulnerability CVE-2026-84869 to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The critical-severity flaw allows attackers with basic privileges to transfer and execute files through active remote sessions without authorization or host confirmation. The vulnerability affects ScreenConnect clients and enables low-complexity attacks requiring no user interaction, prompting CISA to order federal agencies to patch within three days. Over 1,000 vulnerable ScreenConnect instances remain exposed online according to Shadowserver tracking. This incident highlights the ongoing targeting of remote access tools by both ransomware groups and state-sponsored actors, with ScreenConnect facing its fourth CISA-flagged vulnerability since 2024. The exploitation underscores the critical security risks posed by widely-deployed MSP platforms that provide privileged access to thousands of customer environments.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Spain Documents First AI Agent Cyberattack: The Dawn of Autonomous Threats
Impact· MEDIUM

Spain Documents First AI Agent Cyberattack: The Dawn of Autonomous Threats

In September 2026, Spain's Data Protection Agency (AEPD) received the first official notification of an AI-powered data breach, marking a significant milestone in cybersecurity. An autonomous AI agent, powered by a large language model, conducted a sophisticated attack by searching for vulnerabilities, logging into systems, probing applications for security flaws, and ultimately modifying personal data while accessing sensitive financial documents. The attack demonstrated machine-speed reconnaissance, access, and exploitation capabilities that traditional manual security responses were inadequate to counter. This incident represents the emergence of a new threat paradigm where AI agents can simultaneously analyze assets, test access methods, and adapt behavior in real-time, fundamentally changing the speed and scale of cyber operations.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Iranian State Hackers Deploy CHOSEN BRICK Malware in Global Espionage Campaign
Impact· HIGH

Iranian State Hackers Deploy CHOSEN BRICK Malware in Global Espionage Campaign

Iranian state-linked hackers deployed CHOSEN BRICK malware in a sophisticated espionage campaign targeting dissidents, activists, and journalists in the U.S., U.K., and Netherlands throughout 2026. The attack began with social engineering via WhatsApp and Telegram, where threat actors impersonated trusted contacts to deliver malicious files disguised as legitimate applications like Norton Antivirus, Adobe Flash Player, and KeePass. Once installed, CHOSEN BRICK established persistence through Windows Registry modifications, evaded detection by adding Microsoft Defender exclusions, and exfiltrated sensitive data including email communications, Telegram and WhatsApp messages, screenshots, and audio recordings through Telegram bots and cloud storage services. This campaign exemplifies the growing sophistication of nation-state actors leveraging popular communication platforms and cloud infrastructure for command-and-control operations, highlighting the urgent need for enhanced detection capabilities against encrypted communications channels and cloud-based data exfiltration.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Windows 11 KB5124008 Security Update Disrupts Enterprise Domain Authentication
Impact· MEDIUM

Windows 11 KB5124008 Security Update Disrupts Enterprise Domain Authentication

In September 2026, Microsoft's Windows 11 KB5124008 security update disrupted domain trust relationships across enterprise environments, preventing users from authenticating with valid Active Directory credentials. The issue stems from the update automatically enabling Machine Identity Isolation in enforcement mode, which breaks the secure channel between domain-joined computers and Active Directory controllers. Affected organizations experienced widespread login failures, with some reporting 11 out of 256 devices losing domain trust, forcing administrators to either uninstall the update or manually repair secure channels using PowerShell commands. This incident highlights the growing complexity of Windows security features and their potential to disrupt enterprise operations when not properly tested or communicated, emphasizing the critical need for comprehensive update testing in hybrid identity environments.

3 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
NightEagle APT Deploys GhostContainer Backdoor in Russian Enterprise Attacks
Impact· CRITICAL

NightEagle APT Deploys GhostContainer Backdoor in Russian Enterprise Attacks

NightEagle (APT-Q-95), an advanced persistent threat group active since 2023, has expanded operations from Asia to target Russian enterprises in 2024. The group employs compromised VPN credentials for initial access, deploys the GhostContainer backdoor on Microsoft Exchange servers, and utilizes legitimate Microsoft dev tunnels combined with rdp2tcp for covert traffic redirection. Attackers leverage RDP lateral movement, exploit CVE-2019-0708 (BlueKeep), and conduct DCSync attacks to compromise Active Directory infrastructure. The sophisticated campaign demonstrates advanced evasion techniques including AMSI bypass and virtual channel manipulation. This incident highlights the growing trend of APT groups expanding geographic targets while incorporating legitimate cloud services for persistence and evasion. As threat actors increasingly abuse trusted platforms like Microsoft dev tunnels, organizations face heightened challenges in detecting malicious traffic among legitimate communications.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports