Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Researchers Uncover 84 Critical Flaws in 4G and 5G Core Networks
In July 2026, researchers from Singapore's Nanyang Technological University disclosed 84 security vulnerabilities in 4G and 5G core networks, collectively termed implicit trust errors (iTrue). These flaws, found in open-source LTE/5G core implementations, stem from unchecked trust between core network functions, enabling attackers to execute denial-of-service (DoS) attacks and session hijacking by exploiting signaling interfaces like GTP-C and PFCP. The vulnerabilities affect widely used open-source LTE/5G cores, including Open5GS, free5GC, OpenAirInterface, SD-Core, and eUPF. The study highlights the risks associated with cloud-native deployments, where traditional physical isolation is replaced by software-defined architectures, increasing the attack surface. The researchers developed an LLM-assisted system, iFinder, to identify these vulnerabilities, emphasizing the need for rigorous validation and resource checks in core network components to prevent such exploits.
1 month ago
Kill Chain
Critical Vulnerability in NASA's cFS Health & Safety Application: CVE-2026-18064
In July 2026, a critical vulnerability (CVE-2026-18064) was identified in NASA's Core Flight System (cFS) Health & Safety (HS) Application versions up to 7.0.1. This flaw, stemming from an incomplete fix for a previous issue (CVE-2026-15352), allows attackers to trigger a NULL pointer dereference, leading to application crashes and potential denial-of-service conditions. The vulnerability affects systems worldwide, given cFS's deployment across various space missions. ([vulners.com](https://vulners.com/ics/ICSA-26-197-03?utm_source=openai)) This incident underscores the challenges in fully remediating software vulnerabilities and highlights the importance of thorough testing and validation processes. Organizations relying on cFS should prioritize updating to the latest software versions and implement robust monitoring to detect and mitigate potential exploitation attempts.
1 month ago
Kill Chain
Iran's Exploitation of SS7 Vulnerabilities to Track U.S. Military Personnel in 2026
In early 2026, Iranian state-sponsored actors exploited vulnerabilities in the Signaling System 7 (SS7) protocol to track the real-time locations of U.S. military personnel stationed across the Middle East. By sending malicious signaling messages through the global telecom infrastructure, they obtained continuous location data of specific high-value targets, leading to several injuries from subsequent strikes. This campaign underscores the persistent risks associated with legacy telecom protocols and the urgent need for enhanced security measures. The incident highlights the critical importance of securing mobile communications, especially for military operations. As adversaries continue to exploit known vulnerabilities, it is imperative for organizations to implement robust encryption, network segmentation, and continuous monitoring to mitigate such threats.
1 month ago
Kill Chain
Russian Hackers Exploit Exchange OWA Zero-Day (CVE-2026-42897)
In May 2026, the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, exploited a zero-day vulnerability (CVE-2026-42897) in Microsoft Exchange's Outlook Web Access (OWA). This cross-site scripting (XSS) flaw allowed attackers to execute arbitrary JavaScript in users' browsers by sending specially crafted emails. Upon opening these emails in OWA, the embedded malicious code executed, leading to the deployment of a sophisticated backdoor named OWAReaper. This malware enabled long-term access to victims' mailboxes, even after system restorations or credential changes. The campaign targeted various organizations, including government entities in the U.S. and Europe, as well as companies in the telecommunications, financial, hospitality, and aerospace sectors. The incident underscores the evolving tactics of state-sponsored threat actors and the critical need for organizations to promptly apply security patches and enhance email security measures. The exploitation of webmail platforms through XSS vulnerabilities highlights the importance of comprehensive security strategies to protect against sophisticated cyber espionage campaigns.
1 month ago
Kill Chain
SQL Injection Exploit Leads to Server Compromise and Malicious Payload Deployment
In June 2026, Huntress Labs investigated a security incident where attackers exploited an SQL injection vulnerability in a web application to gain unauthorized access to a Microsoft SQL Server. Once inside, the attackers conducted reconnaissance, enabled Remote Desktop Protocol, created administrative user accounts, disabled Windows Defender, and installed malicious IIS modules and cryptocurrency mining software. This methodical approach highlights the importance of securing web applications against SQL injection vulnerabilities and monitoring for post-compromise activities. The incident underscores the persistent threat posed by SQL injection attacks, a technique that remains prevalent despite being well-known and preventable. Organizations must prioritize regular security assessments, implement robust input validation, and maintain vigilant monitoring to detect and respond to such intrusions effectively.
1 month ago
Kill Chain
Google Chrome's AI-Driven Security Overhaul in 2026
In 2026, Google significantly enhanced Chrome's security by integrating artificial intelligence (AI) into its vulnerability management processes. This initiative led to the identification and remediation of 1,072 security vulnerabilities across Chrome versions 149 and 150, surpassing the total number of fixes in the previous 23 releases combined. The AI-driven approach encompassed various stages, including flaw discovery, report reproduction, severity assessment, developer assignment, patch generation, and testing. Notably, this system uncovered a 13-year-old sandbox escape vulnerability that could have allowed compromised renderers to access local files. The adoption of AI in vulnerability management underscores a broader industry trend towards leveraging machine learning for proactive security measures. As cyber threats become more sophisticated, integrating AI tools enables organizations to detect and address vulnerabilities more efficiently, reducing the window of opportunity for potential exploits.
1 month ago
Kill Chain
KT Corporation Fined $39 Million for Massive Data Breach
Between October 2024 and September 2025, KT Corporation, South Korea's largest telecommunications provider, experienced a significant data breach due to a compromised femtocell device. Attackers exploited a lost femtocell's valid authentication certificate to intercept sensitive customer data, including mobile phone numbers and authentication codes, leading to fraudulent micropayments totaling approximately $167,400. Additionally, in March 2024, 38 KT servers were infected with the BPFDoor malware, a stealthy Linux backdoor linked to the China-nexus Red Menshen espionage group, which remained undetected for over a year. This incident underscores the critical need for robust security measures in telecommunications infrastructure, especially concerning device authentication and network monitoring. The prolonged undetected presence of advanced malware like BPFDoor highlights the evolving sophistication of cyber threats targeting critical sectors.
1 month ago
Kill Chain
Unveiling the 'Flying Eagle' Mobile RAT Threat in China - 2026
In July 2026, Chinese cybercriminals utilized the 'Flying Eagle' malware-as-a-service (MaaS) platform to distribute sophisticated mobile Remote Access Trojans (RATs). These RATs were embedded in counterfeit applications mimicking legitimate services, leading to widespread financial data theft and unauthorized access to sensitive user information. The campaign's scale and the advanced capabilities of the malware underscore a significant escalation in mobile cyber threats. This incident highlights the growing trend of MaaS platforms enabling less skilled threat actors to execute complex attacks, increasing the frequency and sophistication of mobile malware campaigns. Organizations must enhance their mobile security measures and user education to mitigate these evolving threats.
1 month ago
Kill Chain
Southeast Asian Cybercriminal Syndicates' Global Expansion in 2025
In 2025, Southeast Asian cybercriminal syndicates evolved into sophisticated transnational networks, leveraging advanced technologies such as artificial intelligence, encrypted messaging platforms, and cryptocurrencies to conduct large-scale cyber-enabled fraud. These operations resulted in estimated losses between $88.3 billion and $114.1 billion across East Asia, Southeast Asia, Australia, and New Zealand. The syndicates' activities encompassed a range of illicit markets, including human trafficking, drug smuggling, and illegal online gambling, facilitated by a shared financial and operational infrastructure. ([jurist.org](https://www.jurist.org/news/2026/07/un-report-exposes-explosive-growth-of-southeast-asian-crime-syndicates/?utm_source=openai)) The rapid expansion and technological advancement of these criminal networks underscore the urgent need for enhanced international cooperation and adaptive law enforcement strategies. Their ability to exploit emerging technologies and jurisdictional loopholes poses a significant threat to global economic stability and security. ([breitbart.com](https://www.breitbart.com/crime/2026/07/22/u-n-report-transnational-gangs-use-drugs-cybercrime-and-slavery-to-loot-southeast-asia/amp/?utm_source=openai))
1 month ago
Kill Chain
Cisco FMC Zero-Day Exploitation: Understanding CVE-2026-20316
In July 2026, a security vulnerability identified as CVE-2026-20316 was discovered in Cisco Secure Firewall Management Center (FMC) Software. This flaw allowed unauthenticated, remote attackers to log in using static credentials associated with a low-privilege account, potentially granting access to sensitive data. Cisco released hotfixes to address this issue across multiple software versions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. The exploitation of CVE-2026-20316 underscores the persistent threat posed by zero-day vulnerabilities in critical network infrastructure. Organizations are urged to apply the provided patches promptly and review their security configurations to mitigate potential risks associated with such vulnerabilities.
1 month ago
Kill Chain
Russian Hackers Exploit Microsoft OWA Vulnerability CVE-2026-42897
In July 2026, Russian state-sponsored threat actors, identified as Laundry Bear (also known as TA488 or Void Blizzard), exploited a cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA), designated as CVE-2026-42897. This flaw allowed attackers to execute arbitrary JavaScript code when a user opened a specially crafted email in OWA, leading to unauthorized access and data exfiltration. The campaign targeted U.S. and European government entities, as well as sectors including telecommunications, financial services, hospitality, and aerospace. This incident underscores a concerning trend of sophisticated, state-sponsored cyber attacks leveraging zero-day vulnerabilities to gain persistent access to critical systems. The rapid exploitation of such flaws highlights the urgent need for organizations to implement robust patch management processes and enhance their cybersecurity defenses to mitigate evolving threats.
1 month ago
Kill Chain
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
In July 2026, South Korean authorities and security firms disclosed a state-sponsored campaign that compromised trusted domestic websites to exploit vulnerabilities in the financial-security software AnySign4PC. Attackers used these sites to deliver SIGNBT or COPPERHEDGE backdoors to visitors without prompts or user-initiated downloads. The Korea Internet & Security Agency (KISA) identified AnySign4PC versions 1.1.4.4 through 1.1.4.6 as vulnerable, recommending an upgrade to version 1.1.5.0. AhnLab reported related attacks at 72 organizations and identified 15 legitimate websites used as watering holes, with overlaps to previous Gunra ransomware attacks. This incident underscores the persistent threat of supply chain attacks targeting widely used software. Organizations must remain vigilant, ensuring timely updates and monitoring for unauthorized access to prevent similar exploits.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports