Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Multi-Vector Assault: How Three Threat Groups Coordinated Attacks on Russian Infrastructure
Three distinct threat groups - NightEagle, Hacking Cat, and Toy Ghouls - launched coordinated attacks against Russian enterprises throughout 2026, deploying backdoors, ransomware, and wipers. NightEagle leveraged compromised VPN credentials and the GhostContainer backdoor to target Microsoft Exchange servers, while pro-Ukrainian group Hacking Cat deployed Gorilla RAT and multi-platform Monkey ransomware variants. Toy Ghouls evolved from using leaked ransomware builders to developing custom Bird Agent backdoors that communicate via unconventional channels like MQTT brokers and Matrix messaging. This campaign demonstrates the increasing sophistication of multi-vector attacks and the growing trend of hacktivist groups collaborating to share custom toolsets, representing a significant escalation in cyber warfare targeting critical infrastructure.
3 days ago
Kill Chain
BragJack Attack Exposes Critical Security Flaws in Browser-Integrated AI Assistants
In 2026, security researchers at Forever Security demonstrated that malicious browser extensions could hijack AI assistants across five major Chromium-based browsers including Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. The attack, dubbed BragJack, exploited common extension permissions to seize control of trusted web pages that communicate with AI agents, allowing attackers to read local files, access cameras and microphones, and control AI functionality. The vulnerabilities were assigned CVE-2026-0628 (Chrome) and CVE-2026-55945 (Edge), with researchers earning approximately $20,000 in bug bounties across the affected platforms. This incident highlights the emerging security risks of browser-integrated AI agents as vendors race to embed autonomous AI capabilities directly into web browsers. The attack vectors demonstrate how traditional browser security boundaries are being challenged by AI integration, creating new pathways for privilege escalation and data exfiltration that require updated security models.
3 days ago
Kill Chain
Court Orders Transfer of Radaris Domains in Landmark Data Broker Privacy Case
In August 2024, a New Jersey court ordered the transfer of radaris.com and over a dozen related data broker domains to Atlas Data Privacy Corp following a lawsuit under Daniel's Law. The case arose after Radaris, operated by Russian-born brothers Igor and Dmitry Lubarsky, repeatedly ignored removal requests from law enforcement officials and engaged in legal delay tactics including creating shell companies across multiple jurisdictions. The court found Radaris in default after the company failed to mount an adequate defense, resulting in the loss of domains generating approximately $42,000 monthly revenue for the primary site alone. This landmark case demonstrates how privacy laws with meaningful enforcement mechanisms can effectively shut down non-compliant data brokers who have historically operated with impunity by exploiting jurisdictional complexities and procedural delays.
3 days ago
Kill Chain
Microsoft's Record Patch Tuesday Disaster: When AI-Driven Vulnerability Discovery Meets Reality
Microsoft issued emergency out-of-band patches in September 2026 to address critical failures caused by their record-breaking Patch Tuesday update that addressed 974 CVEs. The massive update, which surpassed the entire 2023 patching volume in a single month, caused widespread disruptions to Remote Desktop Services, Hyper-V virtual machines, and USB audio devices across enterprise environments. Organizations experienced RDP connection failures, server hangs, and Linux VM file share outages, forcing immediate remediation efforts and highlighting the operational risks of AI-accelerated vulnerability discovery and patching. This incident represents a watershed moment in patch management as AI-driven vulnerability discovery creates unprecedented patch volumes that overwhelm traditional testing cycles. The complexity of modern hybrid cloud environments makes comprehensive regression testing nearly impossible, while rapid threat exploitation timelines pressure organizations to deploy patches faster than ever before.
3 days ago
Kill Chain
Active Exploitation of WSO2 API Manager JWT Bypass Highlights Critical API Security Gaps
In September 2026, watchTowr researchers detected active exploitation of CVE-2026-5430, a critical JWT authentication bypass vulnerability in WSO2 API Manager products. The flaw allows attackers to forge JWT tokens with administrative privileges by using unsupported cryptographic algorithms that the system incorrectly validates. Threat actors are leveraging this vulnerability to gain unauthorized access to API backends, extract consumer keys and secrets, and potentially compromise entire API ecosystems. The vulnerability affects multiple WSO2 products including API Manager versions 4.1.0 through 4.6.0, with exploitation attempts captured in honeypot networks showing forged admin tokens being used for lateral movement. This incident highlights the growing sophistication of API-targeted attacks as organizations increasingly rely on API-first architectures. The vulnerability demonstrates how improper cryptographic validation can lead to complete administrative takeover, emphasizing the urgent need for robust API security controls and zero-trust verification mechanisms.
3 days ago
Kill Chain
N0va Phishing Campaign Exploits Trusted Business Platforms to Compromise Enterprise Identities
The N0va phishing campaign has emerged as a sophisticated threat targeting organizations across North America and Europe in 2026, focusing on government, technology, consulting, and healthcare sectors. Unlike traditional phishing attacks, N0va impersonates trusted business platforms including Microsoft Teams, SharePoint, OneDrive, DocuSign, and Google Drive, then guides victims through legitimate authentication flows to capture access and refresh tokens. Once successful, attackers abuse token-exchange mechanisms to establish SSO access across corporate resources, enabling access to email, files, and cloud applications without deploying obvious malware. The campaign's use of legitimate authentication processes and trusted brand impersonation makes detection challenging and can lead to significant financial losses, data exposure, operational disruption, and compliance violations. This incident highlights the evolving sophistication of identity-based attacks that exploit trust in legitimate business platforms and authentication mechanisms, representing a growing trend where attackers move beyond traditional malware deployment to abuse valid business processes for initial access and persistence.
3 days ago
Kill Chain
Critical Google Pixel Modem Flaw CVE-2026-58704 Exploited in Zero-Click Attacks
In September 2026, Google disclosed that CVE-2026-58704, a high-severity privilege escalation vulnerability in Pixel Cellular Modem components, was being exploited in the wild through limited, targeted attacks. The flaw allows remote attackers to bypass permission checks and escalate privileges without user interaction, making it exploitable as a zero-click attack. Google patched the vulnerability alongside 109 other security flaws in the September 2026 Pixel security update, with CISA adding it to the Known Exploited Vulnerabilities catalog and mandating federal agency remediation by September 19, 2026. This incident highlights the growing sophistication of mobile device attacks and the critical importance of securing cellular modem components that were previously considered peripheral attack surfaces. The zero-click nature of this exploit represents an evolution in mobile threat tactics, emphasizing the need for comprehensive mobile security strategies that extend beyond traditional application-layer protections.
3 days ago
Kill Chain
Google Pixel Authorization Flaw CVE-2026-58704 Under Active Attack
CISA added CVE-2026-58704, a Google Pixel improper authorization vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. This vulnerability affects Google Pixel mobile devices and allows attackers to bypass authorization controls, potentially gaining elevated access to device functions and sensitive data. The vulnerability poses significant risks to federal enterprises and organizations using Google Pixel devices in their mobile device management programs. Federal agencies are required under BOD 26-04 to prioritize rapid remediation of KEV vulnerabilities on publicly exposed assets that could grant total control post-exploitation. This addition reflects the growing threat landscape targeting mobile device vulnerabilities, particularly as organizations increasingly rely on mobile endpoints for business operations and remote work scenarios.
3 days ago
Kill Chain
Active Zero-Day Exploitation Targets Cisco Email Security Infrastructure
In September 2024, Cisco disclosed CVE-2026-76461, a critical zero-day vulnerability in Cisco Secure Email Gateway that was actively exploited by unknown threat actors before discovery and patching. The vulnerability allows unauthenticated remote attackers to execute commands with root privileges by sending specially crafted emails through the gateway, effectively granting complete control over the system. Cisco's security team identified active exploitation affecting multiple customers and conducted direct outreach to compromised organizations while implementing emergency mitigations for cloud-managed instances. This incident highlights the growing sophistication of attacks targeting email infrastructure as critical business communication channels become prime targets for espionage and lateral movement operations.
4 days ago
Kill Chain
Coast Guard and FBI Investigate Maritime Cyberattacks on Foreign Tankers
In August 2024, the U.S. Coast Guard and FBI conducted joint offshore security boardings of two foreign commercial tankers in the Gulf of Mexico following cyberattacks that compromised their networks. The first vessel, carrying oil and natural gas, was hacked while transiting the Strait of Gibraltar and lost communications for over 30 hours. Authorities investigated potential Iranian involvement or threat actors exploiting U.S.-Iran tensions, as part of broader concerns about 'dark fleets' carrying sanctioned oil using digital masking techniques. This incident highlights the growing convergence of cybersecurity threats with critical infrastructure and supply chain security, particularly as nation-state actors increasingly target maritime operations to disrupt global commerce and energy transportation networks.
4 days ago
Kill Chain
Critical Cisco Email Gateway Zero-Day Highlights Perimeter Security Risks
In September 2026, Cisco disclosed that threat actors were actively exploiting a critical zero-day vulnerability (CVE-2026-76461) in Cisco Secure Email Gateway appliances. The flaw stems from insufficient validation in email parsing logic, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges by sending crafted emails containing malicious SQL statements. CISA immediately added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies patch within three days. This incident represents the latest in a concerning pattern of Cisco security appliance compromises, with CISA flagging 98 Cisco vulnerabilities as actively exploited since 2021, including seven abused by ransomware gangs.
4 days ago
Kill Chain
Ransomware Gangs Exploit Critical VMware vCenter RCE Flaw (CVE-2026-59310)
In July 2026, Broadcom patched CVE-2026-59310, a critical directory traversal vulnerability in VMware vCenter's Syslog server that allows unauthenticated remote code execution. Despite urgent patching guidance, threat actors quickly began exploiting the flaw within weeks, with QUIRSO identifying over 361 compromised IP addresses across 47 countries. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog in August and recently flagged it as actively exploited by ransomware gangs, highlighting the critical risk to enterprise virtualization infrastructure. This incident underscores the accelerating timeline between vulnerability disclosure and ransomware exploitation, particularly targeting VMware environments that serve as high-value infrastructure targets for enterprise data access and lateral movement capabilities.
4 days ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports