Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2818 threat reports
Page 30 of 235

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Government Administration Threat Reports

Showing 349360 / 2818 reports
CISA Adds Three Known Exploited Vulnerabilities to Catalog
Impact· CRITICAL

CISA Adds Three Known Exploited Vulnerabilities to Catalog

On August 11, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. The vulnerabilities are: CVE-2026-20349 affecting Cisco Secure Firewall ASA and FTD, CVE-2026-68820 in Microsoft Windows Ancillary Function Driver for WinSock, and CVE-2026-72898 in Metabase. These vulnerabilities are frequently targeted by malicious actors and pose significant risks to federal enterprises. CISA's Binding Operational Directive (BOD) 26-04 mandates federal agencies to prioritize remediation of high-risk vulnerabilities listed in the KEV Catalog. While BOD 26-04 applies to federal agencies, CISA encourages all organizations to adopt risk-based vulnerability management practices and address these vulnerabilities promptly.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Massive Discovery: 737 Malicious Chrome VPN Extensions Compromising User Security
Impact· MEDIUM

Massive Discovery: 737 Malicious Chrome VPN Extensions Compromising User Security

In August 2026, security researchers uncovered 737 malicious Chrome VPN and proxy extensions primarily targeting Russian-speaking users. These extensions, published across at least 40 developer accounts, amassed over 75,000 installs. They impersonated 66 established VPN brands, including Proton VPN, NordVPN, and ExpressVPN, to lure users. Once installed, the extensions routed users' entire browser sessions through SOCKS5 proxies controlled by the threat actors, enabling them to intercept and monitor all browser traffic. This adversary-in-the-middle (AitM) position allowed the attackers to observe browser destinations, source IP addresses, TLS SNI values, and any unencrypted HTTP request bodies. This incident underscores the growing sophistication of cyber threats targeting browser extensions. The attackers' ability to impersonate reputable VPN services highlights the need for users to exercise caution when installing browser add-ons. It also emphasizes the importance of robust vetting processes within browser extension marketplaces to prevent the distribution of malicious software.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Metabase CVE-2026-72898: Critical SQL Injection Vulnerability Exposed
Impact· CRITICAL

Metabase CVE-2026-72898: Critical SQL Injection Vulnerability Exposed

In August 2026, a critical unauthenticated SQL injection vulnerability (CVE-2026-72898) was discovered in Metabase's password reset functionality. This flaw allows remote attackers to execute arbitrary SQL commands against the Metabase application database without authentication, potentially leading to full administrative access and data exfiltration. Metabase has confirmed active exploitation of this vulnerability in the wild, emphasizing the urgency for immediate remediation. The rapid exploitation of CVE-2026-72898 underscores a growing trend of attackers swiftly leveraging newly disclosed vulnerabilities. Organizations must prioritize timely patching and adopt proactive security measures to mitigate risks associated with such critical flaws.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Gunra Ransomware's Escalating Threat to Government Agencies in 2026
Impact· CRITICAL

Gunra Ransomware's Escalating Threat to Government Agencies in 2026

In August 2026, U.S. federal agencies and South Korea's National Policy Agency issued a joint advisory warning government and critical infrastructure organizations worldwide about the Gunra ransomware group's activities. Emerging in April 2025, Gunra utilizes a double-extortion model, encrypting data and threatening public disclosure to coerce ransom payments. The group exploits vulnerabilities in Fortinet firewalls (CVE-2024-55591 and CVE-2025-24472) and SSH access controls in VPN gateways to gain initial access. Initially targeting Windows systems, Gunra expanded to cross-platform attacks with a Linux variant introduced in mid-2025. In January 2026, they launched a ransomware-as-a-service (RaaS) platform, recruiting affiliates and initial access brokers to broaden their reach. This advisory underscores the escalating threat posed by Gunra, especially to government and critical infrastructure sectors. The group's rapid evolution, from leveraging leaked Conti ransomware code to establishing a RaaS platform, highlights the increasing sophistication and commercialization of ransomware operations. Organizations are urged to patch known vulnerabilities, implement network segmentation, and maintain offline backups to mitigate potential attacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
CISA Confirms Exploitation of SharePoint Vulnerability CVE-2026-45659
Impact· HIGH

CISA Confirms Exploitation of SharePoint Vulnerability CVE-2026-45659

In May 2026, Microsoft disclosed CVE-2026-45659, a high-severity remote code execution vulnerability in SharePoint Server, stemming from the deserialization of untrusted data. This flaw allows authenticated attackers with minimal privileges to execute arbitrary code on unpatched servers. By July 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities Catalog, confirming active exploitation by ransomware groups. Organizations utilizing SharePoint Server are urged to apply the latest patches promptly to mitigate this risk. The exploitation of CVE-2026-45659 underscores a broader trend of threat actors targeting collaboration platforms to deploy ransomware. This incident highlights the critical need for organizations to maintain rigorous patch management practices and to monitor for signs of compromise, especially in widely used enterprise applications.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Cisco ClamAV Vulnerabilities: Immediate Action Required
Impact· HIGH

Cisco ClamAV Vulnerabilities: Immediate Action Required

In August 2026, Cisco disclosed two high-severity vulnerabilities (CVE-2026-20337 and CVE-2026-20338) in ClamAV's ZIP archive parser, affecting versions 1.5.0 through 1.5.3. These flaws, due to improper boundary checks and memory handling, allow unauthenticated remote attackers to crash the ClamAV scanning process, leading to denial-of-service (DoS) conditions. Proof-of-concept exploit code is publicly available, though no active exploitation has been reported. The vulnerabilities are particularly critical on Windows platforms, where ClamAV operates with elevated privileges. The disclosure underscores the persistent risk of DoS attacks targeting antivirus solutions. Organizations relying on ClamAV should promptly update to version 1.5.4 to mitigate potential threats. This incident highlights the importance of timely patch management and the need for continuous monitoring of security advisories to protect against emerging vulnerabilities.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Surge in DDoS Attacks Over 1 Tbps in Q2 2026
Impact· HIGH

Surge in DDoS Attacks Over 1 Tbps in Q2 2026

In the second quarter of 2026, Cloudflare reported a significant escalation in Distributed Denial-of-Service (DDoS) attacks, mitigating over 800 network-layer incidents exceeding 1 terabit per second (Tbps). This marks a more than fivefold increase from the 130 such attacks recorded in the first quarter. The surge included a record-breaking attack peaking at 31.4 Tbps, orchestrated by the Aisuru/Kimwolf botnet. Despite the rise in massive attacks, the majority remained relatively small and brief, with 96.62% below 50 Mbps and 90.6% concluding within 10 minutes. This trend underscores the evolving threat landscape, where attackers are leveraging increasingly sophisticated methods to launch high-volume DDoS attacks. The shift towards DNS-related and reflection/amplification techniques, along with the targeting of sectors like Media, Production, and Publishing, highlights the need for robust and adaptive cybersecurity measures to mitigate these growing threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Cisco ASA and FTD VPN Vulnerability CVE-2026-20349: Immediate Action Required
Impact· HIGH

Critical Cisco ASA and FTD VPN Vulnerability CVE-2026-20349: Immediate Action Required

In August 2026, Cisco disclosed a high-severity denial-of-service (DoS) vulnerability, identified as CVE-2026-20349, affecting Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software. This flaw allows unauthenticated, remote attackers to crash affected devices by sending crafted HTTP requests to the Remote Access SSL VPN service. Exploitation results in device reloads, causing significant operational disruptions. The active exploitation of CVE-2026-20349 underscores the critical need for organizations to promptly apply security patches. This incident highlights the persistent threat landscape targeting network infrastructure and the importance of maintaining up-to-date defenses to mitigate potential attacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Sandworm's Sophisticated Attack: Trojanized WireGuard VPN Client Targets IT Professionals
Impact· HIGH

Sandworm's Sophisticated Attack: Trojanized WireGuard VPN Client Targets IT Professionals

In May 2026, the Russian state-sponsored hacking group Sandworm, specifically its sub-cluster UAC-0145, initiated a sophisticated social engineering campaign targeting IT professionals. Posing as recruiters from reputable IT firms, they engaged victims through fake job offers, leading to interviews conducted over Zoom. During these sessions, candidates were instructed to download a trojanized WireGuard VPN client named 'SopraVPN' from a deceptive SourceForge page. This malicious software, once installed, executed embedded PowerShell code, enabling the attackers to establish persistent access to the victims' systems. The campaign's primary objective was to infiltrate and compromise critical infrastructure and government entities, leveraging the trust and technical expertise of IT professionals to gain unauthorized access to sensitive networks. This incident underscores the evolving tactics of nation-state actors, who are increasingly employing advanced social engineering techniques to bypass traditional security measures. Organizations must remain vigilant, ensuring that their recruitment processes are secure and that employees are educated about potential cyber threats. The use of trojanized software in targeted attacks highlights the necessity for robust endpoint detection and response solutions to detect and mitigate such sophisticated threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Project CAV3RN's Evolving Tactics: Leveraging Google Apps Script and DNS for Stealthy C2
Impact· LOW

Project CAV3RN's Evolving Tactics: Leveraging Google Apps Script and DNS for Stealthy C2

In August 2026, Kaspersky researchers identified an evolution in the Project CAV3RN cyberespionage framework, which has been targeting Israeli organizations since December 2025. The latest development involves a sophisticated command-and-control (C2) module that utilizes Google Apps Script as a relay and employs DNS-based mechanisms for C2 channel selection. This approach allows the malware to blend its communication with legitimate network traffic, thereby evading traditional detection methods. The framework's modular design and rapid development indicate a persistent and adaptable threat. The significance of this incident lies in the increasing trend of threat actors leveraging legitimate cloud services to obfuscate malicious activities. By integrating Google Apps Script and DNS-based techniques, Project CAV3RN exemplifies the challenges in distinguishing between normal and malicious network behavior, underscoring the need for advanced detection strategies.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
DeadLock Ransomware's Innovative Use of Blockchain Technology
Impact· LOW

DeadLock Ransomware's Innovative Use of Blockchain Technology

In July 2025, the DeadLock ransomware group emerged, employing double extortion tactics to encrypt victim environments and threaten the public release of exfiltrated data. Notably, DeadLock utilizes decentralized infrastructure, combining the Session messaging network with blockchain-backed services, specifically Polygon smart contracts, to store and deliver resources throughout the extortion process. This approach enhances the group's operational resilience by making their infrastructure harder to disrupt. As of August 2026, DeadLock has claimed 96 victims, primarily in Italy, Spain, Poland, Türkiye, and the U.S. The group's innovative use of blockchain technology for command-and-control operations signifies a concerning trend in ransomware tactics. By leveraging decentralized platforms, DeadLock demonstrates an evolution in cybercriminal strategies, posing new challenges for traditional defense mechanisms and takedown efforts.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft's August 2026 Patch Tuesday: Addressing 398 Vulnerabilities Including Active Zero-Day Exploits
Impact· CRITICAL

Microsoft's August 2026 Patch Tuesday: Addressing 398 Vulnerabilities Including Active Zero-Day Exploits

In August 2026, Microsoft released a comprehensive security update addressing 398 vulnerabilities, including CVE-2026-68820, a zero-day flaw actively exploited in the wild. This vulnerability resides in the Windows kernel's Ancillary Function Driver for WinSock (afd.sys) and allows attackers with existing access to escalate privileges to SYSTEM level by exploiting a race condition. Notably, the Lazarus Group has been linked to the exploitation of this flaw in their Operation Dream Job campaign. Additionally, the update addressed four critical remote code execution vulnerabilities (CVE-2026-62878, CVE-2026-62893, CVE-2026-62815, and CVE-2026-59124) that require no user interaction, emphasizing the urgency for organizations to apply these patches promptly. The release also completed a two-part fix for a SharePoint vulnerability chain, with the initial authentication bypass (CVE-2026-55040) patched in July and the subsequent remote code execution component (CVE-2026-63520) addressed in August. This underscores the importance of timely patch management to mitigate potential exploitation risks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports