Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
CISA Flags Critical JFrog Artifactory and ConnectWise ScreenConnect Vulnerabilities Under Active Attack
CISA has added three critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation in the wild. The vulnerabilities include two JFrog Artifactory flaws (CVE-2026-42016 and CVE-2026-42018) involving incorrect authorization and improper authentication, plus a ConnectWise ScreenConnect vulnerability (CVE-2026-84869) related to improper privilege management and missing authorization. These vulnerabilities pose significant risks to federal enterprises and are being actively exploited by malicious cyber actors as frequent attack vectors. The addition reinforces CISA's Binding Operational Directive (BOD) 26-04, which requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities that can grant total system control post-exploitation, while encouraging all organizations to adopt risk-based vulnerability management practices.
1 week ago
Kill Chain
CISA Elevates GitLab Path Traversal Vulnerability to Known Exploited Status
CISA has added CVE-2026-85706, a path traversal vulnerability affecting GitLab Community Edition and Enterprise Edition, to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation. Path traversal vulnerabilities allow attackers to access files and directories outside the intended scope by manipulating file path parameters, potentially leading to unauthorized data access, system compromise, or privilege escalation. This addition reinforces the critical nature of the vulnerability and mandates rapid remediation by Federal Civilian Executive Branch agencies under BOD 26-04. This incident highlights the ongoing trend of attackers targeting DevOps platforms and source code management systems, which have become critical infrastructure for modern software development. As organizations increasingly rely on GitLab and similar platforms for code repositories and CI/CD pipelines, vulnerabilities in these systems pose significant supply chain risks that can cascade across multiple downstream applications and services.
1 week ago
Kill Chain
Conti Ransomware Operative Sentenced: Lessons from a $150M Cybercrime Empire
In September 2026, Ukrainian national Oleksii Oleksiyovych Lytvynenko was sentenced to four years in prison for his role in the Conti ransomware operation that targeted over 1,000 victims worldwide between 2020 and 2022. Lytvynenko joined the cybercrime syndicate in September 2021, personally compromising 12 companies across the U.S. and overseas, developing malicious loader tools, and managing stolen data as part of double extortion attacks. The Conti operation collected over $150 million in ransom payments before shutting down in 2022, with its members later forming new ransomware groups including BlackCat, Black Basta, and Hive. This sentencing represents ongoing law enforcement efforts to dismantle ransomware ecosystems, as threat actors continue evolving tactics through splintered operations and increasingly sophisticated extortion schemes targeting critical infrastructure organizations worldwide.
1 week ago
Kill Chain
How ShinyHunters Weaponized Claude AI to Harvest Secrets from 1.8 Million Android Apps
Between December 2025 and August 2026, multiple threat groups including ShinyHunters, Russian state-sponsored Midnight Blizzard, and Chinese espionage group GTG-10007 systematically abused Anthropic's Claude AI model for large-scale cyberattacks. The most significant operation involved ShinyHunters member 'frkoo' deploying an automated credential-harvesting pipeline across AWS infrastructure that extracted secrets from 1.8 million Android applications and compromised over 40 Microsoft corporate tenants within 34 hours. The AI-enhanced attacks enabled rapid progression from initial access to administrative control in under three hours, with confirmed breaches across government, healthcare, energy, and technology sectors. This incident represents a critical inflection point where AI capabilities are being weaponized at unprecedented scale and speed, fundamentally changing the threat landscape and requiring immediate reassessment of defensive strategies against AI-enhanced cybercrime operations.
1 week ago
Kill Chain
Florida DMV Breach Exposes Risks of Shared Government Database Access
In September 2026, the Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed that its DAVID driver database was breached by the ShinyHunters extortion group, who claimed to have stolen over 200,000 driver records. The attack was executed using compromised credentials from a Plant City Police Department employee that had been improperly stored on a personal device. The breach was discovered on September 4, 2026, and quickly mitigated, with FLHSMV working alongside state law enforcement agencies in their response. This incident highlights the growing trend of cybercriminals targeting government databases through compromised credentials and the critical importance of proper credential management across interconnected systems.
1 week ago
Kill Chain
UAC-0099 Deploys GuardBreaker AI Manipulation Against Ukraine
In September 2026, Russia-aligned threat group UAC-0099 deployed a novel AI manipulation technique called GuardBreaker against Ukrainian targets. The attackers embedded nuclear weapon prompts within malicious VBScript comments to trigger AI safety mechanisms and prevent automated malware analysis systems from examining their code. This represents a significant evolution in adversarial tactics, where threat actors manipulate AI defensive reasoning rather than increasing malware sophistication to achieve compromise. This incident highlights the accelerating arms race between AI-powered security tools and adversaries who exploit their limitations. With AI systems now discovering vulnerabilities at unprecedented speed and scale, traditional 90-day patch cycles are obsolete, creating an urgent need for multilayered defense strategies that don't rely solely on AI-based detection mechanisms.
1 week ago
Kill Chain
The $21 Billion AI Scam Crisis: How Artificial Intelligence Became the Ultimate Social Engineer
AI-enabled social engineering attacks have reached unprecedented sophistication, with cybercriminals leveraging large language models to create highly personalized and emotionally manipulative scams. Research by Fred Heiding of Menlo Park Intelligence reveals that AI systems excel at human manipulation through voice cloning, long-term relationship building, and cultural context adaptation. The FBI's Internet Crime Center reports that fraud losses skyrocketed from $4 billion in 2020 to $21 billion in 2025, primarily targeting vulnerable populations including senior citizens who develop emotional dependencies on AI-powered scam bots. This asymmetric threat landscape highlights a critical security gap where traditional technical defenses prove inadequate against AI-enhanced social engineering, as human cognitive vulnerabilities cannot be patched like software systems.
1 week ago
Kill Chain
GoldFactory's Android Banking Malware Exploits Work Profiles to Steal $1M from Indonesian Banks
Between February and July 2026, the Chinese-speaking threat group GoldFactory deployed a sophisticated Android banking malware campaign targeting Indonesia, resulting in 1,469 compromised devices and nearly $1 million in losses. The attackers used the Gigabud banking Trojan in combination with Vwork, a modified app-cloning tool, to exploit Android's Work Profile feature. This technique allowed fraudsters to clone legitimate banking applications into isolated environments where security controls and fraud detection systems could not follow, enabling them to conduct transactions while evading detection mechanisms that were triggered in the victim's primary profile. This incident highlights the evolution of mobile banking threats as attackers increasingly target regions with high mobile payment adoption and develop novel evasion techniques that exploit legitimate enterprise security features for malicious purposes.
1 week ago
Kill Chain
How Cisco FMC Vulnerabilities Enabled Qilin Ransomware Deployment
In September 2026, Cisco revealed that three distinct threat clusters exploited critical vulnerabilities CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center (FMC) systems. The attacks involved state-sponsored groups and ransomware operators who leveraged these flaws to deploy web shells, steal credentials, conduct reconnaissance, and ultimately deploy Qilin ransomware. The exploitation allowed attackers to bypass authentication, gain root access, and perform living-off-the-land techniques using legitimate FMC tools to avoid detection while moving laterally through victim networks. This incident highlights the growing trend of threat actors targeting network security infrastructure as initial access vectors, demonstrating how critical security appliances themselves become single points of failure when unpatched vulnerabilities exist.
1 week ago
Kill Chain
How UNC3569 Weaponized Trusted Software: The Sogou Input Method Supply Chain Attack
In April 2026, China-linked threat group UNC3569 exploited a critical vulnerability (CVE-2026-51990) in Sogou Input Method, a widely-used Chinese character input tool with over 455 million monthly users. The attackers leveraged a crafted sgbiz: link to bypass security controls and deploy the GRAYRABBIT backdoor through an outdated Chromium browser engine with disabled sandboxing. The exploit chain utilized a 2021 V8 JavaScript engine vulnerability (CVE-2021-38003) that had been patched in Chrome but remained unaddressed in Sogou's embedded browser, allowing remote code execution with user privileges. This incident highlights the growing sophistication of supply chain attacks targeting widely-deployed software components, particularly those serving large user bases in critical regions. The exploitation of years-old vulnerabilities in embedded browsers demonstrates how legacy code in trusted applications creates persistent attack surfaces for nation-state actors.
1 week ago
Kill Chain
CISA Adds Four Critical Infrastructure Vulnerabilities to KEV Catalog
In September 2026, CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation in the wild. The vulnerabilities affect widely deployed enterprise infrastructure including Fortinet security appliances (CVE-2025-25249 heap-based buffer overflow), Citrix NetScaler (CVE-2026-19490 authentication bypass), Google Chromium V8 engine (CVE-2026-87491 out-of-bounds write), and Cisco Firewall Management Center (CVE-2026-20079 authentication bypass). These vulnerabilities pose significant risks as they target critical network security infrastructure and web browsers used across federal and private sector environments. This incident highlights the ongoing threat landscape where attackers systematically target network security appliances and widely-used software components to establish persistent access and bypass security controls, reflecting the continued evolution of threat actor tactics toward infrastructure-level compromises.
1 week ago
Kill Chain
Russian Threat Actors Deploy AI Agents in Massive PaperCut Vulnerability Exploitation Campaign
In August 2026, PaperCut NG/MF print management software was compromised through active exploitation of two critical vulnerabilities, CVE-2026-81578 and CVE-2026-82078, allowing authentication bypass and arbitrary code execution. A suspected Russian-speaking threat actor deployed hundreds of AI agents powered by OpenAI's Codex and DeepSeek models to systematically target 395 organizations across 48 countries, primarily focusing on U.S. educational institutions while deliberately avoiding entities in Russia, China, and 25 other countries. This incident represents a significant evolution in attack automation, demonstrating how threat actors are leveraging AI at scale to accelerate exploitation campaigns. The targeting pattern and AI-driven approach signals a new era of automated, geopolitically-aware cyber operations that can rapidly compromise vulnerable infrastructure across multiple sectors simultaneously.
1 week ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports