Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
UNC6508's Prolonged Infiltration of REDCap Servers Exposes Medical Research Vulnerabilities
Between September 2023 and November 2025, the Chinese state-sponsored group UNC6508 infiltrated vulnerable REDCap servers at a North American medical research institution. They deployed custom malware named Infinitered, which harvested credentials and established a backdoor, enabling prolonged data exfiltration. The attackers exploited REDCap's widespread use in medical research to access sensitive information undetected for over a year. This incident underscores the persistent threat posed by nation-state actors targeting critical research sectors. The sophisticated methods employed, including the abuse of legitimate features for data exfiltration, highlight the evolving tactics in cyberespionage campaigns.
3 months ago
Kill Chain
Council of Europe Probes ShinyHunters Data Breach Allegations
In June 2026, the Council of Europe, representing 46 member states and over 700 million people, began investigating claims by the cyber extortion group ShinyHunters of a significant data breach. ShinyHunters alleged they had stolen over 429,000 documents containing sensitive HR and payroll data from multiple departments, including payslips, personnel files, and CVs, encompassing personal and financial information such as names, dates of birth, addresses, salaries, and bank account details. The group threatened to leak the data if their demands were not met by June 16, 2026. This incident underscores the escalating threat posed by cyber extortion groups like ShinyHunters, who have been linked to numerous high-profile data breaches targeting organizations worldwide. Their tactics often involve exfiltrating large volumes of sensitive data and leveraging it for ransom, highlighting the critical need for robust cybersecurity measures and proactive threat detection to safeguard organizational data.
3 months ago
Kill Chain
Critical Zero-Day Vulnerability in Cisco SD-WAN vManage Exploited in the Wild
In June 2026, Cisco disclosed a critical vulnerability (CVE-2026-20262) in its Catalyst SD-WAN Manager, formerly known as SD-WAN vManage. This flaw allowed authenticated remote attackers with low-level privileges to execute arbitrary commands as root by exploiting insufficient input validation during file uploads. The vulnerability affected all deployment types, including on-premises, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP). Cisco's Product Security Incident Response Team (PSIRT) became aware of active exploitation of this zero-day vulnerability earlier in the month and strongly advised customers to apply the released security updates promptly. The exploitation of CVE-2026-20262 underscores a concerning trend of attackers targeting critical infrastructure components through zero-day vulnerabilities. Organizations must remain vigilant, ensuring timely patch management and robust security practices to mitigate such risks.
3 months ago
Kill Chain
DOJ's Landmark Seizure of Deepfake Sites Under TAKE IT DOWN Act
In June 2026, the U.S. Department of Justice (DOJ) seized the domains CFAKE.com and SOCFAKE.com, which hosted nonconsensual AI-generated nude images and videos of women, including politicians, celebrities, and royalty. This action marked the first publicly announced domain seizure under the TAKE IT DOWN Act, a law enacted in May 2025 to combat the distribution of nonconsensual intimate imagery, including deepfakes. The DOJ's operation, in coordination with authorities from Italy and France, underscores the international effort to address the proliferation of such exploitative content. The enforcement of the TAKE IT DOWN Act highlights the growing concern over the misuse of artificial intelligence to create and disseminate deepfake pornography. As AI technology becomes more accessible, the potential for abuse increases, necessitating robust legal frameworks and international cooperation to protect individuals from digital exploitation.
3 months ago
Kill Chain
UNC6508's Year-Long Espionage on U.S. Research Institutions
Between September 2023 and November 2025, the China-aligned threat actor UNC6508 conducted a covert cyber-espionage campaign targeting U.S. academic, medical, and military research institutions. The attackers exploited vulnerabilities in REDCap servers to deploy custom malware named Infinitered, enabling them to steal credentials and maintain persistent access. This operation led to the exfiltration of sensitive data related to defense intelligence, military strategy, artificial intelligence, and medical research. ([darkreading.com](https://www.darkreading.com/threat-intelligence/china-nexus-actor-us-researchers-undetected?utm_source=openai)) This incident underscores the evolving sophistication of state-sponsored cyber threats, highlighting the need for enhanced security measures in research institutions. The use of tailored malware and novel data exfiltration techniques by UNC6508 reflects a broader trend of advanced persistent threats employing innovative methods to achieve their objectives.
3 months ago
Kill Chain
U.S. Government Restricts Access to Anthropic's Advanced AI Models
In June 2026, the U.S. government issued an export control directive requiring Anthropic to suspend access to its advanced AI models, Fable 5 and Mythos 5, for all foreign nationals, including those within the United States. This action was taken due to national security concerns over potential vulnerabilities that could allow the models to be exploited for identifying software flaws. As a result, Anthropic disabled these models for all users to ensure compliance. This unprecedented move underscores the growing tension between technological advancement and national security, highlighting the challenges in regulating AI technologies. The directive has sparked international debate over the balance between innovation and security, with European leaders expressing concerns about overreliance on American AI providers and advocating for greater technological sovereignty.
3 months ago
Kill Chain
Palo Alto Networks PAN-OS GlobalProtect VPN Authentication Bypass Vulnerability (CVE-2026-0257)
In May 2026, Palo Alto Networks disclosed CVE-2026-0257, a high-severity authentication bypass vulnerability in the GlobalProtect portal and gateway components of PAN-OS software. This flaw allows unauthenticated remote attackers to forge valid session cookies, enabling unauthorized VPN connections into corporate networks. Active exploitation of this vulnerability was observed starting May 17, 2026, with attackers attempting to access GlobalProtect portals. While no post-access behavior or lateral movement has been identified, the potential for unauthorized access to sensitive internal resources poses a significant risk. The inclusion of CVE-2026-0257 in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog underscores the urgency for organizations to address this issue. The active exploitation highlights a broader trend of attackers targeting VPN infrastructures to gain unauthorized access, emphasizing the need for robust authentication mechanisms and timely patch management to mitigate such threats.
3 months ago
Kill Chain
Sniper Dz Scams Exploit Fake Facebook Offers to Target MENA Users
In June 2026, cybersecurity researchers uncovered a series of fraudulent activities targeting users in the Middle East and North Africa (MENA) region. Cybercriminals employed fake Facebook accounts impersonating politicians, public figures, and trusted organizations to promote deceptive offers such as free mobile internet packages and financial compensations. Victims who clicked on these offers were redirected through a series of intermediary websites leading to phishing pages and monetization schemes, including browser notification abuse and premium SMS subscriptions. This incident highlights the evolving tactics of cybercriminals who exploit social engineering and trusted platforms to deceive users. The use of legitimate services like link-aggregation platforms and browser notifications underscores the need for heightened vigilance and advanced security measures to protect against such sophisticated scams.
3 months ago
Kill Chain
Microsoft 365 Copilot 'SearchLeak' Vulnerability Exposes Sensitive Data
In June 2026, Varonis Threat Labs identified a critical vulnerability in Microsoft 365 Copilot, termed 'SearchLeak'. This flaw allowed attackers to craft a single-click link that, when accessed by a user, could exfiltrate sensitive data such as emails, calendar details, and indexed files without any further interaction. The attack exploited a combination of AI prompt injection and web vulnerabilities, enabling unauthorized access to a user's Microsoft Graph data. Microsoft assigned CVE-2026-42824 to this issue and has since mitigated the flaw on its backend, with no known exploitation in the wild. This incident underscores the evolving nature of cyber threats targeting AI-integrated platforms. As organizations increasingly adopt AI-driven tools, it is imperative to implement robust security measures to prevent similar vulnerabilities. Continuous monitoring and prompt patching are essential to safeguard sensitive information against emerging attack vectors.
3 months ago
Kill Chain
Anthropic's AI Models Disabled Amid National Security Concerns
In June 2026, the U.S. government ordered Anthropic to suspend foreign access to its advanced AI models, Fable 5 and Mythos 5, citing national security concerns over potential 'jailbreaking' vulnerabilities that could bypass safety restrictions. This directive led Anthropic to disable these models entirely to comply with export controls, affecting both foreign nationals and certain employees. The incident underscores the challenges in balancing AI innovation with security, as similar capabilities exist in other publicly accessible models. The government's stringent response highlights the growing scrutiny over AI technologies and their potential misuse, emphasizing the need for robust security measures and regulatory frameworks in the rapidly evolving AI landscape.
3 months ago
Kill Chain
Operation Highland: Unveiling a Decade of Stealthy Cyber-Espionage
In 2026, cybersecurity researchers uncovered 'Operation Highland,' a decade-long cyber-espionage campaign by the Chinese state-sponsored group Velvet Ant. Beginning in 2016, the attackers initially compromised internet-facing servers, deploying modified GS-Netcat reverse shells for encrypted remote access. They then installed custom SOCKS5 proxies to tunnel traffic, enabling access to isolated networks. By backdooring Linux Pluggable Authentication Modules (PAM) and OpenSSH components, Velvet Ant harvested credentials and maintained persistent access, effectively embedding themselves within the authentication process. This allowed them to monitor administrative activities and exfiltrate sensitive data undetected for ten years. The discovery of this prolonged intrusion underscores the evolving sophistication of state-sponsored cyber threats. It highlights the critical need for organizations to implement robust monitoring of authentication systems, conduct regular integrity checks of security components, and adopt a zero-trust security model to mitigate the risk of such stealthy and persistent attacks.
3 months ago
Kill Chain
Former IT Employee Sentenced for Prolonged Cyberattacks on School District
In June 2026, Ezekiel Dean Potter, a former senior IT support specialist at Saydel Community School District in Des Moines, Iowa, was sentenced to 21 months in prison for conducting a series of unauthorized cyberattacks against his former employer. After his termination in April 2023, Potter retained access credentials and over the next 21 months, he deleted the district's Facebook page, disrupted access to educational platforms, and reset employee usernames and passwords, causing significant operational disruptions and financial losses estimated at tens of thousands of dollars. This incident underscores the critical importance of promptly revoking access credentials of departing employees and implementing robust monitoring systems to detect unauthorized access. The case highlights the potential risks posed by insider threats and the necessity for organizations to enforce strict access control policies to safeguard their digital assets.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports