Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2818 threat reports
Page 43 of 235

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Government Administration Threat Reports

Showing 505516 / 2818 reports
RefluXFS Vulnerability: Critical Linux Kernel Flaw Grants Root Access
Impact· HIGH

RefluXFS Vulnerability: Critical Linux Kernel Flaw Grants Root Access

In July 2026, a critical vulnerability known as RefluXFS (CVE-2026-64600) was disclosed in the Linux kernel's XFS filesystem. This nine-year-old race condition allows local attackers to overwrite protected files, such as /etc/passwd or SUID-root binaries, thereby gaining root privileges. The flaw affects systems running Linux kernel version 4.11 or later with XFS filesystems where reflink is enabled—a default setting in major enterprise Linux distributions. Exploitation is highly reliable, leaves no kernel log output, and the on-disk modifications persist across reboots. ([blog.qualys.com](https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600?utm_source=openai)) The discovery of RefluXFS underscores the persistent risk posed by longstanding vulnerabilities in widely used systems. Its exploitation bypasses standard security mechanisms, highlighting the need for continuous vigilance and prompt patching in the face of evolving threats. ([blog.qualys.com](https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Hackers Exploit Notepad++ Plugins to Install Malware - July 2026
Impact· HIGH

Hackers Exploit Notepad++ Plugins to Install Malware - July 2026

In July 2026, Ukraine's CERT-UA identified a cyberattack campaign by the threat group UAC-0099, which distributed a ZIP archive containing the legitimate Notepad++ application alongside a malicious plugin named LunchPoke. This plugin established persistence on infected systems. The attackers employed a VBS script disguised as a PDF to initiate the infection chain, leading to the installation of additional malware components, including BurnyBear and MatchBoil V2 loaders. The campaign primarily targeted organizations in Ukraine and is linked to the APT44 group, also known as Sandworm. This incident underscores the evolving tactics of threat actors who exploit trusted software to deliver malware, highlighting the need for organizations to scrutinize software sources and implement robust security measures to detect and prevent such sophisticated attacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Russian Hackers Exploit Zimbra Zero-Click Vulnerability (CVE-2025-66376) for Email Theft
Impact· MEDIUM

Russian Hackers Exploit Zimbra Zero-Click Vulnerability (CVE-2025-66376) for Email Theft

In July 2026, the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, exploited a zero-click vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite's Classic UI to target organizations across various sectors, including defense, government, education, and technology. By embedding malicious JavaScript in specially crafted HTML emails, the attackers executed scripts automatically upon email viewing, enabling the theft of account data without user interaction. This campaign led to unauthorized access to sensitive information, including emails, credentials, and two-factor authentication tokens, significantly compromising organizational security. The incident underscores the critical importance of timely software updates and robust email security measures. Despite the vulnerability being patched in November 2025, many organizations remained unpatched, highlighting a persistent challenge in cybersecurity hygiene. The exploitation of this flaw by a sophisticated threat actor emphasizes the need for continuous vigilance and proactive defense strategies to mitigate emerging cyber threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Russian Espionage Group Exploits Zimbra Zero-Day Vulnerability
Impact· MEDIUM

Russian Espionage Group Exploits Zimbra Zero-Day Vulnerability

In July 2025, the Russian state-sponsored threat group known as Laundry Bear initiated a sophisticated cyber-espionage campaign targeting Western government and commercial organizations. By exploiting a zero-day vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite's webmail client, the attackers deployed a 'view-based exploit' that activated upon merely viewing a malicious email. This allowed them to exfiltrate sensitive data, including recent emails, entire email directories, browser-saved passwords, and two-factor authentication recovery codes. The vulnerability was patched in November 2025, but unpatched systems remain at risk. ([nsa.gov](https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4553352/nsa-and-partners-alert-zimbra-collaboration-suite-users-of-a-russian-state-supp/?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors exploiting zero-day vulnerabilities. The use of 'zero-click' exploits, which require no user interaction beyond viewing an email, highlights the evolving sophistication of cyber threats and the critical need for timely patch management and robust cybersecurity measures. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/russian-hackers-zimbra-zero-day-us-ukraine-targets?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
TAG-195's Modular Malware: A New Era in Cyber Threats
Impact· MEDIUM

TAG-195's Modular Malware: A New Era in Cyber Threats

In July 2026, Insikt Group identified four new malware families—TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and ChromEggscalator—developed by TAG-195, also known as "Golden Chickens" or "Venom Spider." These developments signify a strategic shift towards modular, operator-driven tools within the TAG-195 malware-as-a-service (MaaS) ecosystem. The modularized ChonkyChicken variant employs a controller-and-plugin architecture, allowing the base implant to dynamically load specific capability modules from attacker-controlled infrastructure, thereby reducing its static detection footprint. All four malware families exhibit consistent command-and-control mechanisms, shared persistence methods, string obfuscation, and execution via legitimate Windows binaries. This evolution underscores TAG-195's commitment to enhancing the adaptability and stealth of its offerings, catering to a diverse range of operational requirements. The emergence of these advanced, modular malware families highlights the ongoing sophistication of MaaS providers and the necessity for organizations to bolster their detection and response strategies against such evolving threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
LummaStealer's 2026 Resurgence: The Role of CastleLoader and ClickFix Techniques
Impact· LOW

LummaStealer's 2026 Resurgence: The Role of CastleLoader and ClickFix Techniques

Between December 2025 and January 2026, cybersecurity researchers observed a significant resurgence of LummaStealer infections, facilitated by the deployment of CastleLoader malware through sophisticated ClickFix social engineering techniques. Attackers lured victims to malicious websites mimicking legitimate services, where fake CAPTCHA verifications tricked users into executing malicious PowerShell commands. These commands installed CastleLoader, which subsequently delivered LummaStealer, an infostealer targeting sensitive data such as credentials, cryptocurrency wallets, and session cookies. This campaign marked a notable evolution in malware delivery methods, combining advanced loaders with deceptive social engineering tactics to bypass traditional security measures. The resurgence of LummaStealer, despite previous law enforcement disruptions, underscores the adaptability and persistence of cybercriminals. The use of CastleLoader and ClickFix techniques highlights a trend towards more sophisticated and deceptive attack vectors, emphasizing the need for continuous vigilance and advanced security protocols to protect sensitive information.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Fake Bahrain Alert App Exploits Crisis to Deploy Android Spyware
Impact· HIGH

Fake Bahrain Alert App Exploits Crisis to Deploy Android Spyware

In July 2026, a malicious Android application named "BH Alert" emerged, masquerading as Bahrain's official civil-defense emergency alert app. Distributed through counterfeit Google Play Store and Bahraini government websites, the app exploited heightened public concern during Iranian missile strikes. Once installed, it deployed a sophisticated four-stage surveillance platform capable of harvesting lockscreen credentials, SMS messages, contacts, and screenshots, running banking-app overlays, and granting attackers full remote control over the device. This campaign underscores the increasing trend of threat actors leveraging trusted government applications during crises to disseminate advanced spyware. Organizations should be vigilant about such tactics, as similar methods have been observed in previous incidents, including a Trojanized version of Israel's "Red Alert" app distributed via phishing campaigns earlier this year.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Flaws in Microsoft's Passkey Implementation Uncovered
Impact· MEDIUM

Critical Flaws in Microsoft's Passkey Implementation Uncovered

In July 2026, security researchers identified critical vulnerabilities in Microsoft's passkey implementation within Windows 11 and Microsoft Entra ID. These flaws allowed attackers to exploit weaknesses reminiscent of traditional password attacks, enabling them to impersonate privileged users and bypass phishing-resistant multifactor authentication. The vulnerabilities were disclosed to Microsoft, which subsequently released patches to address the issues. This incident underscores the importance of thorough implementation and validation of security protocols, even when adopting advanced authentication methods like passkeys. Organizations must remain vigilant, ensuring that new technologies are deployed securely to prevent exploitation by threat actors.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Lampion Banking Trojan Resurfaces in Portugal: A 2026 Threat Analysis
Impact· MEDIUM

Lampion Banking Trojan Resurfaces in Portugal: A 2026 Threat Analysis

In July 2026, the Brazilian banking Trojan known as Lampion was identified in an active campaign targeting Portuguese users. The malware is disseminated through phishing emails that masquerade as financial and administrative communications, leading recipients to download malicious ZIP files. Once executed, Lampion establishes persistence, connects to a remote command-and-control server, and can inject overlays into banking websites to steal credentials. This campaign has resulted in significant data breaches and financial losses for affected individuals and organizations. The resurgence of Lampion underscores the persistent threat posed by banking Trojans, especially those leveraging social engineering tactics. Organizations must remain vigilant, as attackers continue to exploit language and cultural similarities to enhance the effectiveness of their campaigns.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
RefluXFS (CVE-2026-64600): Critical Linux Kernel XFS Vulnerability
Impact· HIGH

RefluXFS (CVE-2026-64600): Critical Linux Kernel XFS Vulnerability

On July 22, 2026, a critical vulnerability known as RefluXFS (CVE-2026-64600) was disclosed, affecting the Linux kernel's XFS filesystem. This flaw allows unprivileged local users to overwrite root-owned files, such as `/etc/passwd` or setuid-root binaries, by exploiting a race condition in the copy-on-write (CoW) mechanism. The exploit enables attackers to gain persistent root access without leaving traces in kernel logs, and the changes persist across reboots. Systems running Linux kernel version 4.11 or later with XFS filesystems created with `reflink=1` are vulnerable. Default installations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux are particularly at risk. ([blog.qualys.com](https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600?utm_source=openai)) The RefluXFS vulnerability underscores the importance of timely patch management and system monitoring. With over 16.4 million systems potentially affected, organizations must prioritize updating their Linux distributions and implementing security measures to prevent unauthorized access and potential data breaches. ([secnews.gr](https://www.secnews.gr/en/723207/refluxfs-cve-2026-64600-linux-xfs-16m-systems/?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Authentication Bypass in Check Point SmartConsole (CVE-2026-16232) Exploited
Impact· CRITICAL

Critical Authentication Bypass in Check Point SmartConsole (CVE-2026-16232) Exploited

In July 2026, Check Point identified a critical authentication bypass vulnerability (CVE-2026-16232) in its SmartConsole login process, allowing unauthenticated remote attackers to gain full administrative privileges. Exploitation requires internet access to the Management Server IP address and a configuration without Trusted Clients restrictions. Successful attacks enable modification of security policies and configurations. Check Point confirmed active exploitation affecting a limited number of customers. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-16232?utm_source=openai)) This incident underscores the escalating risks associated with exposed management interfaces and the necessity for stringent access controls. Organizations must prioritize timely patching and restrict management access to trusted IP addresses to mitigate such vulnerabilities.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Unveiling JadeProx: China's New Cyber Threat Targeting Critical Sectors
Impact· HIGH

Unveiling JadeProx: China's New Cyber Threat Targeting Critical Sectors

In mid-April 2026, cybersecurity firm Group-IB uncovered an exposed Alibaba Cloud server linked to a China-nexus operation named JadeProx. This operation targeted government, healthcare, and education sectors across Asia and Latin America using a previously undocumented Windows loader called TriBack Loader. The attackers exploited vulnerabilities in public-facing applications, deploying web shells to gain initial access, and utilized sophisticated techniques such as DLL sideloading and encrypted payloads to evade detection. Notably, the campaign included intrusions into a Vietnamese public hospital's medical imaging system and Malaysia's Ministry of Foreign Affairs. The discovery of JadeProx underscores the evolving tactics of state-sponsored threat actors, emphasizing the need for organizations to bolster their cybersecurity defenses. The use of advanced loaders like TriBack Loader highlights the importance of monitoring for novel malware strains and implementing robust security measures to protect sensitive data and critical infrastructure.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports