✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Breeze Comet Cybercrime Group: Direct Manipulation of Global Financial Payment Systems
Breeze Comet (formerly UNC5669) represents Brazil's most sophisticated cybercrime group, systematically infiltrating financial institutions across Brazil and expanding globally since 2024. The group employs advanced tactics including insider recruitment, physical network access via rogue hardware, and exploitation of compromised government websites as trusted attack vectors. Using custom malware like CobaltSpin, RealBreeze, and KickPlate, they penetrate segmented financial networks to directly manipulate payment systems including Brazil's Pix instant payment platform, executing hundreds of fraudulent transactions worth tens of thousands of dollars within 24-48 hours of system compromise. This incident highlights the evolution of financially-motivated cybercrime from traditional ransomware and fraud schemes to direct payment system manipulation. As instant payment systems proliferate globally and threat actors increasingly leverage AI for malware development, Breeze Comet's successful model poses significant risks to financial infrastructure worldwide, particularly in regions with similar digital payment architectures.
1 day ago
Kill Chain
Critical SonicWall SMA 1000 Zero-Days Under Active Exploitation: CVE-2026-83548 & CVE-2026-83549
In September 2026, attackers began actively exploiting two zero-day vulnerabilities in SonicWall SMA 1000 perimeter devices, enabling unauthenticated remote code execution. CVE-2026-83548, a critical SSRF vulnerability with a CVSS score of 10.0, allows unauthorized access through an unintended alternate access path, while CVE-2026-83549 enables OS command injection. When chained together, these flaws provide complete system compromise of affected appliances running versions 12.4.3-03453/12.5.0-02835 and older. SonicWall confirmed ongoing exploitation and urged immediate patching to versions 12.4.3-03526/12.5.0-02952 or higher. This incident highlights the continued targeting of edge security devices as initial compromise vectors, following a pattern of sophisticated zero-day attacks against network perimeter appliances throughout 2026, emphasizing the critical need for rapid patch management and network segmentation strategies.
1 day ago
Kill Chain
FalconFlank Zero-Day Targets CrowdStrike Falcon: When EDR Becomes the Attack Vector
In September 2026, security researcher Chaotic Eclipse released FalconFlank, a zero-day privilege escalation exploit targeting CrowdStrike Falcon endpoint security software. The vulnerability abuses office malicious macros remediation functionality within Falcon Sensor to achieve privilege escalation on fully updated Windows 11 25H2 and Windows Server 2025 systems. This disclosure follows the researcher's pattern of releasing proof-of-concept exploits for major endpoint security products, including recent vulnerabilities in Kaspersky and Microsoft Defender, highlighting systemic weaknesses in endpoint protection platforms. This incident underscores the growing trend of security researchers targeting endpoint detection and response (EDR) solutions themselves, exposing critical trust assumptions in enterprise security architectures and forcing organizations to reconsider their defense-in-depth strategies.
2 days ago
Kill Chain
Serbian Student Activists Targeted by Pegasus Zero-Click Spyware Campaign
In December 2025 through January 2026, NSO Group's Pegasus spyware infected the iPhone of a Serbian student protest movement member using a zero-click iMessage exploit. The attack was part of a broader surveillance campaign targeting at least 14 Serbian activists, opposition politicians, and student leaders coinciding with March 2026 local elections. Citizen Lab and SHARE Foundation confirmed the infection, while a separate incident involved NoviSpy Android malware deployed during police detention of another student activist. This incident highlights the escalating use of commercial spyware against civil society, particularly as authoritarian governments increasingly weaponize surveillance technology to suppress political dissent and monitor opposition movements ahead of critical elections.
2 days ago
Kill Chain
Threat Actors Weaponize Trusted Node.js Runtime for Stealth Malware Delivery
Since February 2026, threat actors have been weaponizing the legitimate Node.js JavaScript runtime (node.exe) to deliver malicious payloads in targeted attacks against government departments, technology companies, and hotels. The Symantec Threat Hunter Team identified this technique as particularly effective because node.exe is a trusted binary that can execute arbitrary JavaScript code while evading traditional security detection mechanisms. Attackers leverage the runtime's legitimate presence in enterprise environments to establish persistence, execute malware, and maintain command and control communications without triggering security alerts. This campaign reflects the growing trend of living-off-the-land tactics where attackers abuse legitimate system tools rather than deploying custom malware, making detection significantly more challenging for traditional security solutions and highlighting the need for behavioral analysis and runtime protection.
2 days ago
Kill Chain
Seven Critical Vulnerabilities Added to CISA's KEV Catalog Demand Immediate Action
On September 2, 2026, CISA added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, affecting critical enterprise systems including Sangoma Switchvox, SonicWall SMA1000 appliances, JFrog Artifactory, and other widely deployed platforms. The vulnerabilities span SQL injection, authentication bypass, command injection, and request smuggling attack vectors, with threat actors already leveraging these flaws to compromise federal and private sector networks. The additions coincide with CISA's new Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize rapid remediation of high-risk vulnerabilities that grant total system control. This incident highlights the accelerating pace of vulnerability exploitation as threat actors increasingly target authentication systems, web applications, and network appliances to establish persistent access. The rapid weaponization of these CVEs demonstrates the critical need for organizations to implement proactive vulnerability management and zero-trust security controls.
2 days ago
Kill Chain
Global RMM Phishing Campaign Exploits Legitimate Cloud Services Across 46 Countries
In September 2026, security researchers identified a sophisticated RMM phishing campaign spanning 46 countries, with the United States accounting for 45% of observed activity. The operation used fake documents mimicking tax forms, shipping notifications, and government communications to trick victims into installing legitimate remote monitoring and management software. Attackers leveraged rapidly rotating infrastructure on Vercel, GitHub Pages, and Netlify, with 94% of 425 identified URLs observed for only a single day. The campaign targeted education, technology, government, banking, and manufacturing sectors. This incident highlights the growing trend of threat actors abusing legitimate cloud services and software for malicious purposes, making detection increasingly challenging through traditional IOC-based approaches.
2 days ago
Kill Chain
Microsoft Teams Impersonation Campaign Exploits Remote Support Trust for Enterprise Access
Microsoft Threat Intelligence discovered a sophisticated social engineering campaign where threat actors impersonate IT support personnel through Microsoft Teams external collaboration to trick users into granting remote access. Once control is established via legitimate remote management tools, attackers deploy a malicious MSI package that stages a Node.js runtime and JavaScript implant for persistent command execution. The campaign progresses through extensive reconnaissance, Active Directory enumeration, and lateral movement via Windows Remote Management (WinRM) toward high-value assets including domain controllers, representing a precursor to ransomware deployment or data theft operations. This attack pattern demonstrates the evolving threat landscape where attackers leverage trusted enterprise collaboration platforms and legitimate administrative tools to bypass traditional security controls. The shift from commodity phishing to hands-on-keyboard operations targeting identity infrastructure reflects the increasing sophistication of modern threat actors seeking enterprise-wide access for high-impact cyberattacks.
2 days ago
Kill Chain
Critical Azure Privilege Escalation Flaw Exposes Hidden Risks in Cloud RBAC
In June 2026, NetSPI security researchers discovered a critical privilege escalation vulnerability in Microsoft Azure's Role-Based Access Control (RBAC) system. The vulnerability existed in the built-in 'Anyscale Platform Administrator Role' which contained unconstrained Microsoft.Authorization/roleAssignments/write permissions, allowing arbitrary escalation to Owner-level privileges without proper Attribute-Based Access Control (ABAC) restrictions. This finding highlighted broader security gaps in Azure's rapidly expanding attack surface, which now includes over 200 services, 897 built-in RBAC roles, and 22,018 different permissions. Microsoft addressed the issue within two weeks of disclosure by removing the problematic permissions from the affected role. This incident represents a critical trend in cloud security as organizations increasingly rely on complex cloud permission models that can contain hidden escalation paths, emphasizing the urgent need for granular permission auditing and zero-trust access controls in multi-cloud environments.
2 days ago
Kill Chain
AI-Powered Cyber Campaigns Expose New Threat Landscape in Latin America
Two sophisticated AI-enhanced cyber campaigns targeted organizations across Latin America in 2026, demonstrating how threat actors are integrating artificial intelligence into their attack workflows. The first campaign (CL-CRI-1131) targeted Mexican transportation companies and government entities using living-off-the-land techniques and self-hosted NextChat instances for AI assistance. The second campaign (CL-CRI-1163) focused on Brazilian financial institutions, employing custom remote access trojans and Go-based SOCKS5 proxies with AI-generated naming conventions. Both campaigns utilized commercial large language models like ChatGPT and Claude to overcome technical obstacles, generate exploit scripts, and streamline post-exploitation activities. Despite enhanced technical capabilities through AI integration, the attackers exposed their operations through poor operational security, including unsecured staging directories and publicly accessible NextChat interfaces. This represents a significant evolution in regional threat landscapes where diverse threat groups are independently adopting AI to accelerate their attack capabilities while maintaining fundamental security weaknesses that defenders can exploit.
2 days ago
Kill Chain
How Law Enforcement Finally Defeated the 23-Year Sality Botnet Empire
The Sality botnet, a Russia-based peer-to-peer malware operation that infected over 11 million devices during its 23-year lifespan, was successfully dismantled in January 2025 through a coordinated effort by CrowdStrike, law enforcement agencies, and the Shadowserver Foundation. The botnet's decentralized architecture, which historically made it resilient against takedown attempts, was ultimately exploited by researchers who manipulated its peer-to-peer communication system to permanently sever operator control. The operation involved domain seizures coordinated by the FBI, Justice Department, and European authorities, marking the end of one of the longest-running criminal botnets in cybersecurity history. This takedown demonstrates the evolving capabilities of law enforcement and private security firms to dismantle sophisticated peer-to-peer botnets, signaling a shift in the cybercrime landscape where even decentralized criminal infrastructure is no longer immune to coordinated disruption efforts.
2 days ago
Kill Chain
SonicWall SMA1000 Under Active Zero-Day Attack: CVE-2026-83548 & CVE-2026-83549
In September 2026, SonicWall disclosed that threat actors were actively exploiting two chained zero-day vulnerabilities in SMA1000 appliances used by large enterprises and critical infrastructure. CVE-2026-83548, a maximum-severity command injection flaw in the WorkPlace interface, is chained with CVE-2026-83549, a command injection vulnerability in the Management Console, enabling remote code execution attacks. The vulnerabilities affect SMA1000 6210, 7210, and 8200v models, with over 400 appliances potentially exposed online according to Shadowserver tracking. This incident highlights the escalating threat to secure remote access infrastructure, particularly as organizations increasingly rely on VPN appliances for hybrid work environments. The pattern of repeated SMA1000 zero-day exploitation throughout 2025-2026, including previous attacks by ransomware gangs confirmed by CISA, demonstrates how critical network infrastructure has become a prime target for sophisticated threat actors.
2 days ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports