Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Nimbus Manticore's 2026 Cyber Campaign: Unveiling NightLedger and Covert Tunneling Techniques
In July 2026, the Iranian state-sponsored hacking group known as Nimbus Manticore (also referred to as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) launched a series of cyber attacks targeting entities across the Middle East, Africa, and South Asia. The group employed a previously undocumented Windows backdoor named NightLedger, along with two custom WebSocket-based tunnelers, BridgeHead and ArcBridge, to maintain covert access to compromised systems. These tools enabled the attackers to perform reconnaissance, execute commands, and establish covert network access, effectively turning victim systems into relay nodes for further malicious activities. This incident underscores the evolving tactics of state-sponsored threat actors, who are increasingly developing and deploying sophisticated malware to achieve persistent access and control over targeted networks. The use of custom tunneling tools and backdoors highlights the need for organizations to enhance their detection and response capabilities to counter such advanced threats.
1 month ago
Kill Chain
Critical DHCPv6 Vulnerability in OpenWrt's odhcpd Service
In June 2026, OpenWrt released version 25.12.5 to address multiple vulnerabilities in its odhcpd service, notably CVE-2026-53921—a critical stack buffer overflow in the DHCPv6 IA reply serialization. This flaw allows unauthenticated attackers on the local network to send crafted DHCPv6 REQUEST packets, potentially leading to remote code execution with root privileges. The vulnerability is particularly concerning due to the default-enabled status of odhcpd and the common lack of security mitigations like stack canaries and ASLR in embedded devices. ([openwrt.org](https://openwrt.org/releases/25.12/notes-25.12.5?utm_source=openai)) The release also addressed other vulnerabilities, including CVE-2026-53918 (use-after-free in the DHCPv6 IA handler) and CVE-2026-53920 (stack memory disclosure via truncated DHCPv6 options). These fixes underscore the importance of timely updates to mitigate risks associated with network services enabled by default. ([openwrt.org](https://openwrt.org/releases/25.12/notes-25.12.5?utm_source=openai))
1 month ago
Kill Chain
Over 24,000 BMC Interfaces Expose IPMI Password Hashes: A Critical Security Alert
In July 2026, cybersecurity researchers identified over 36,000 Baseboard Management Controller (BMC) interfaces exposing the Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of these, 24,650 interfaces disclosed password-derived authentication hashes before login due to a vulnerability inherent in the IPMI v2.0 specification (CVE-2013-4786). This flaw allows remote attackers to obtain password hashes and conduct offline password guessing attacks, potentially compromising server management systems. The widespread exposure of BMCs with default or weak passwords, especially in modern AI data centers hosting multiple tenants, underscores a significant security risk. Attackers exploiting this vulnerability can gain persistent access, bypass traditional security controls, and threaten the integrity of shared infrastructure, highlighting the urgent need for enhanced security measures in server management protocols.
1 month ago
Kill Chain
Exploiting Azure VMs via Salt Minion Extension: A Security Analysis
In July 2026, security researchers identified a method by which attackers could exploit Azure Virtual Machines (VMs) by deploying the Salt Minion extension to execute arbitrary code. By leveraging the 'Microsoft.Compute/virtualMachines/extensions/write' permission, an attacker can install the Salt Minion extension on a target VM, connecting it to a rogue Salt Master under their control. This setup allows the attacker to push malicious states to the VM, achieving code execution with root privileges. The attack is particularly stealthy as it utilizes legitimate administrative tools, making detection challenging. This incident underscores the critical need for organizations to monitor and restrict the use of VM extensions, especially those that can establish outbound connections. As cloud environments become increasingly complex, ensuring that only authorized extensions are deployed and that their configurations are regularly audited is essential to prevent such exploitation.
1 month ago
Kill Chain
Critical Certighost Vulnerability (CVE-2026-54121) Exploit Released
In July 2026, security researchers disclosed a critical vulnerability in Microsoft's Active Directory Certificate Services (AD CS), identified as CVE-2026-54121 and nicknamed 'Certighost'. This flaw allows authenticated attackers to manipulate machine account attributes, obtaining certificates that enable them to authenticate as domain controllers via PKINIT, potentially compromising entire Windows domains. Microsoft addressed this vulnerability in their July 2026 Patch Tuesday updates. The release of a proof-of-concept exploit for Certighost underscores the urgency for organizations to apply the provided patches promptly. Failure to do so leaves systems susceptible to domain-wide compromise, emphasizing the critical need for timely security updates and vigilant monitoring of Active Directory environments.
1 month ago
Kill Chain
Critical Zero-Day Vulnerability in Arista VeloCloud Orchestrator Exploited
In July 2026, Arista Networks disclosed a critical command injection vulnerability (CVE-2026-16812) in its on-premises VeloCloud Orchestrator (VCO) deployments. This unauthenticated OS command injection flaw, with a CVSS score of 10.0, allows remote attackers to access privileged internal functionalities, potentially compromising the confidentiality, integrity, and availability of the orchestrator and the data it manages. The vulnerability affects VCO versions 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. Hosted and Dedicated VCO deployments were patched prior to the advisory and are not affected. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/?utm_source=openai)) The exploitation of this zero-day vulnerability underscores the increasing sophistication of cyber threats targeting network management systems. Organizations are urged to promptly apply the provided patches, restrict access to the VCO web interface to administrative networks, and monitor for indicators of compromise, including connections from known malicious IP addresses and unauthorized configuration changes. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/?utm_source=openai))
1 month ago
Kill Chain
Unveiling Cruciferra: The Crypter Redefining Malware Evasion
In July 2026, cybersecurity researchers identified 'Cruciferra,' a sophisticated crypter service utilized by multiple cybercriminal groups to deliver various malware, including remote access trojans (RATs) and information stealers. Cruciferra employs advanced evasion techniques such as Bring Your Own Vulnerable Driver (BYOVD), Process Ghosting, and over 90 custom encryption routines to bypass security defenses. The service has been linked to campaigns targeting sectors like financial services, healthcare, and government, with phishing emails serving as the primary delivery method. ([infosecurity-magazine.com](https://www.infosecurity-magazine.com/news/cruciferra-crypter-process-ghosting/?utm_source=openai)) The emergence of Cruciferra underscores the evolving complexity of malware delivery mechanisms and the increasing accessibility of sophisticated tools to cybercriminals. This trend highlights the necessity for organizations to enhance their security measures, focusing on advanced threat detection and user education to mitigate the risks posed by such advanced obfuscation techniques.
1 month ago
Kill Chain
TELESHIM: Exploiting Telegram for Covert C2 in Middle East Government Attacks
In July 2026, cybersecurity researchers identified a sophisticated cyber-espionage campaign targeting government entities in the Middle East. The campaign, attributed to a threat actor with ties to East Asia, deployed previously undocumented malware families named TELESHIM, MIXEDKEY, and BINDCLOAK. The attack chain began with the use of ISO image files containing a legitimate ASUSTek executable, which sideloaded a malicious DLL to deploy the TELESHIM backdoor. TELESHIM notably abused the Telegram API for command-and-control (C2) communications, allowing the attackers to blend malicious traffic with legitimate network activity. The operation demonstrated advanced techniques, including DLL sideloading, environmental keying, and heavy code obfuscation, indicating a high level of operational security and a focus on long-term espionage and data exfiltration. ([zscaler.com](https://www.zscaler.com/blogs/security-research/targeted-attack-government-entities-middle-east-part-1?utm_source=openai)) This incident underscores a growing trend of threat actors leveraging popular communication platforms like Telegram for covert C2 channels, complicating detection and mitigation efforts. The use of such legitimate services for malicious purposes highlights the need for organizations to enhance their monitoring capabilities and adopt more sophisticated threat detection mechanisms to identify and respond to these evolving tactics.
1 month ago
Kill Chain
Critical vBulletin Pre-Auth RCE Vulnerability (CVE-2026-61511) Exploited
In July 2026, a critical vulnerability (CVE-2026-61511) was discovered in vBulletin versions 5.x through 5.7.5 and 6.x through 6.2.1, allowing unauthenticated remote code execution. The flaw resides in the vB5_Template_Runtime::runMaths() method, where an attacker can exploit insufficient input validation to execute arbitrary PHP code via the pagenav[pagenumber] parameter. This vulnerability enables attackers to gain full control over affected servers without requiring authentication or user interaction. The public release of exploit details has heightened the risk of widespread attacks, emphasizing the urgency for administrators to apply the available patches immediately. This incident underscores the critical importance of timely software updates and robust input validation to prevent unauthorized access and potential data breaches.
1 month ago
Kill Chain
ESAFENET CDG 3 Default Password Exploitation in 2026
In July 2026, security researchers observed increased scanning activity targeting ESAFENET's CDG 3 Document Management System, specifically exploiting default administrative credentials. ESAFENET, a company specializing in secure document management and data leakage prevention, has previously faced vulnerabilities such as SQL Injection and Cross-Site Scripting. The current scans focus on the 'secadmin' account with the default password 'Est@Spc820', which, despite meeting complexity requirements, is widely known and documented in exploit scripts. This exploitation could grant unauthorized access to sensitive documents and administrative functions, posing significant security risks. The resurgence of attacks leveraging default credentials underscores the critical need for organizations to change default passwords upon deployment. This incident highlights the ongoing threat posed by default credentials and the importance of proactive security measures to prevent unauthorized access.
1 month ago
Kill Chain
DevMan RaaS Platform: A New Era in Organized Cybercrime
In April 2025, the DevMan ransomware-as-a-service (RaaS) operation emerged, initially affiliating with groups like Qilin, DragonForce, Apos, and RansomHub. By July 2025, DevMan transitioned into an independent RaaS platform, offering affiliates a centralized web portal for payload generation, financial management, victim communication, and operational coordination. This portal streamlined the ransomware deployment process, integrating access brokerage with ransomware execution, and imposed strict completion timelines on affiliates. The operation has claimed 184 victims to date, with nearly 50 located in the U.S., targeting sectors such as technology, healthcare, financial services, professional services, and government. The evolution of DevMan underscores a significant shift in the ransomware landscape, where threat actors are developing sophisticated, centralized platforms to enhance operational efficiency and scalability. This trend highlights the increasing professionalization of cybercriminal enterprises and the need for organizations to bolster their cybersecurity defenses against such organized threats.
1 month ago
Kill Chain
The Rise of Residential Proxy Botnets: A New Cybersecurity Challenge
In July 2026, Lumen Technologies' Black Lotus Labs reported a significant surge in botnets utilizing residential proxy networks, with nearly 60 million compromised IP addresses globally. Approximately 25% of these infected IPs are located in the United States. Notably, the IPIDEA botnet, after a coordinated takedown in January, rebounded to half its size within hours and has since expanded to about 10 million IPs. This rapid recovery underscores the resilience and adaptability of such botnets. ([cyberscoop.com](https://cyberscoop.com/botnets-residential-proxy-networks-proliferate-lumen-black-lotus-labs/?utm_source=openai)) The proliferation of these botnets is driven by a growing market demand for residential IPs, enabling cybercriminals to mask malicious activities within legitimate traffic. The increasing availability of vulnerable devices, coupled with the cessation of security updates for older products, exacerbates the issue. ([cyberscoop.com](https://cyberscoop.com/botnets-residential-proxy-networks-proliferate-lumen-black-lotus-labs/?utm_source=openai))
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports