Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2818 threat reports
Page 70 of 235

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Government Administration Threat Reports

Showing 829840 / 2818 reports
ShinyHunters' Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
Impact· CRITICAL

ShinyHunters' Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)

Between May 27 and June 9, 2026, the cyber extortion group ShinyHunters exploited a zero-day vulnerability (CVE-2026-35273) in Oracle's PeopleSoft software, specifically targeting the Environment Management Hub (EMHub). This critical flaw allowed unauthenticated remote code execution, leading to the compromise of over 100 organizations, predominantly in the higher education sector. The attackers exfiltrated sensitive data from approximately 300 PeopleSoft instances, including personal and financial information of students and staff. Oracle released a security advisory and patch on June 10, 2026, urging immediate action to mitigate the risk. ([darkreading.com](https://www.darkreading.com/vulnerabilities-threats/shinyhunters-oracle-zero-day-higher-ed?utm_source=openai)) This incident underscores the increasing targeting of educational institutions by cybercriminals exploiting unpatched vulnerabilities in widely used enterprise software. The rapid exploitation of zero-day vulnerabilities highlights the necessity for organizations to implement proactive vulnerability management and incident response strategies to protect sensitive data and maintain operational integrity.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Anthropic Halts AI Models Fable 5 and Mythos 5 Following U.S. Government Directive
Impact· HIGH

Anthropic Halts AI Models Fable 5 and Mythos 5 Following U.S. Government Directive

In June 2026, the U.S. government issued an export control directive requiring Anthropic to suspend access to its advanced AI models, Fable 5 and Mythos 5, for all foreign nationals, including those within the United States. This directive, citing national security concerns, led Anthropic to disable these models globally to ensure compliance. The order also affected foreign national employees of Anthropic, highlighting the broad scope of the government's action. ([tomshardware.com](https://www.tomshardware.com/tech-industry/artificial-intelligence/us-export-control-order-forces-anthropic-to-disable-claude-fable-5-and-mythos-5-worldwide?utm_source=openai)) This incident underscores the increasing regulatory scrutiny over advanced AI technologies and their potential implications for national security. Organizations developing or utilizing such technologies must stay vigilant to evolving compliance requirements and assess the impact of governmental directives on their operations and international collaborations.

3 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in Splunk Enterprise: CVE-2026-20253
Impact· CRITICAL

Critical Vulnerability in Splunk Enterprise: CVE-2026-20253

In June 2026, a critical vulnerability (CVE-2026-20253) was identified in Splunk Enterprise versions below 10.2.4 and 10.0.7, allowing unauthenticated users to perform arbitrary file operations via a PostgreSQL sidecar service endpoint lacking authentication controls. This flaw could lead to remote code execution, data destruction, and full system compromise. Splunk has released patches to address this issue, urging immediate updates to mitigate potential exploitation. The disclosure of CVE-2026-20253 underscores the ongoing risks associated with unauthenticated access points in enterprise software. Organizations are advised to review their security postures, apply the latest patches promptly, and implement robust access controls to prevent similar vulnerabilities from being exploited.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Unauthenticated RCE Vulnerability in Oracle PeopleSoft Exploited: CVE-2026-35273
Impact· CRITICAL

Critical Unauthenticated RCE Vulnerability in Oracle PeopleSoft Exploited: CVE-2026-35273

In early June 2026, Oracle disclosed a critical vulnerability (CVE-2026-35273) in its PeopleSoft Enterprise PeopleTools, specifically within the Updates Environment Management component. This flaw, present in versions 8.61 and 8.62, allows unauthenticated attackers with network access via HTTP to execute remote code, potentially leading to full system compromise. The vulnerability was actively exploited between May 27 and June 9, 2026, before Oracle released a patch on June 10. Over 100 organizations were affected, with data exfiltration reported from nearly 300 PeopleSoft instances. The cyber extortion group ShinyHunters is believed to be behind these attacks, though some experts suggest possible impersonation. ([techradar.com](https://www.techradar.com/pro/security/oracle-warns-customers-of-critical-peoplesoft-attack-after-hundreds-of-servers-hacked-by-apparent-shinyhunters-data-theft-attacks?utm_source=openai)) This incident underscores the persistent threat posed by unauthenticated remote code execution vulnerabilities in widely used enterprise applications. The rapid exploitation of CVE-2026-35273 highlights the importance of timely patch management and proactive monitoring to detect and mitigate such threats before they can cause significant damage.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ShinyHunters' Exploitation of Oracle PeopleSoft CVE-2026-35273: A Wake-Up Call for Higher Education
Impact· CRITICAL

ShinyHunters' Exploitation of Oracle PeopleSoft CVE-2026-35273: A Wake-Up Call for Higher Education

In late May 2026, the cybercriminal group ShinyHunters exploited a zero-day vulnerability, CVE-2026-35273, in Oracle PeopleSoft PeopleTools versions 8.61 and 8.62. This flaw allowed unauthenticated remote code execution, leading to the compromise of over 100 organizations, predominantly in the U.S. higher education sector. The University of Nottingham confirmed significant student data theft following the group's data leak. Oracle disclosed the vulnerability on June 10, 2026, and released a critical patch, urging immediate application to mitigate further risks. This incident underscores the critical importance of timely patch management and proactive vulnerability monitoring. The exploitation of unpatched systems by threat actors like ShinyHunters highlights the need for organizations to enhance their cybersecurity posture to prevent similar breaches.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Conti Ransomware Member Pleads Guilty to Wire Fraud Conspiracy
Impact· HIGH

Conti Ransomware Member Pleads Guilty to Wire Fraud Conspiracy

In June 2026, Ukrainian national Oleksii Lytvynenko pleaded guilty to conspiracy to commit wire fraud for his role in the Conti ransomware group. Lytvynenko admitted to joining Conti in September 2021, developing malware used in attacks, and possessing data from 12 victims, including eight in the United States. Conti was responsible for over 1,000 ransomware attacks globally, resulting in at least $150 million in ransom payments. Lytvynenko faces up to 20 years in prison, with sentencing scheduled for September 10, 2026. This case underscores the persistent threat posed by ransomware groups and highlights the importance of international cooperation in combating cybercrime. Organizations should remain vigilant, as threat actors continue to evolve their tactics and rebrand under new identities, necessitating robust cybersecurity measures and proactive defense strategies.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Tchap Messenger Breach: Data of 73,000 French Government Employees Exposed
Impact· MEDIUM

Tchap Messenger Breach: Data of 73,000 French Government Employees Exposed

In June 2026, the French government's encrypted messaging platform, Tchap, experienced a security breach when a threat actor gained access through a compromised user account. This intrusion led to the exposure of data from public chat rooms, affecting over 73,000 public sector employees. The compromised information included users' names, email addresses, avatar images, and their affiliated public sector organizations. Private conversations remained encrypted and were not accessed during the breach. This incident underscores the persistent threat posed by social engineering attacks and highlights the importance of securing even internal communication platforms. Organizations must remain vigilant and continuously enhance their security measures to protect sensitive information from unauthorized access.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Urgent: CISA's Directive on Patching Critical Ivanti Sentry Vulnerability
Impact· CRITICAL

Urgent: CISA's Directive on Patching Critical Ivanti Sentry Vulnerability

In June 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a directive mandating federal agencies to patch a critical vulnerability (CVE-2026-10520) in Ivanti Sentry devices within three days. This OS command injection flaw allows unauthenticated remote attackers to execute code with root privileges. Despite Ivanti's initial statement of no evidence of exploitation, reports emerged of attackers backdooring exposed Sentry gateways. This incident underscores the escalating threat landscape where critical vulnerabilities are rapidly exploited. Organizations must prioritize timely patching and robust vulnerability management to mitigate risks associated with such high-severity flaws.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Ukrainian National's Guilty Plea Highlights Ongoing Ransomware Threats
Impact· HIGH

Ukrainian National's Guilty Plea Highlights Ongoing Ransomware Threats

In June 2026, Ukrainian national Oleksii Oleksiyovych Lytvynenko pleaded guilty to conspiracy to commit wire fraud for his involvement in the Conti ransomware attacks between 2021 and 2022. Lytvynenko and his co-conspirators deployed Conti ransomware on victim networks in the United States and abroad, stealing data and encrypting devices to extort Bitcoin ransom payments. He admitted to possessing data stolen from eight U.S. victims and four overseas victims and to developing malware loaders used in these attacks. The Conti ransomware operation, active from 2019 to 2022, targeted over 1,000 victims worldwide, collecting over $150 million in ransom payments. The group was known for large-scale attacks against healthcare organizations, governments, and enterprises before shutting down in 2022 following internal leaks and increased law enforcement pressure. Former Conti members have since splintered into other ransomware groups, including BlackCat, Black Basta, and Hive.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Arch Linux AUR Compromise 2026: A Wake-Up Call for Open-Source Security
Impact· HIGH

Arch Linux AUR Compromise 2026: A Wake-Up Call for Open-Source Security

In June 2026, over 400 packages in the Arch User Repository (AUR) were compromised to distribute a Linux rootkit and infostealer malware. Attackers spoofed trusted publishers to inject malicious preinstall scripts that downloaded and executed the 'atomic-lockfile' npm package. This malware targeted sensitive information, including credentials and access tokens, and utilized eBPF rootkit capabilities to conceal its presence. The incident underscores the vulnerabilities inherent in community-maintained repositories and the critical need for stringent package verification processes. This breach highlights the escalating threat of supply chain attacks, particularly within open-source ecosystems. Organizations must enhance their security postures by implementing robust monitoring and validation mechanisms to detect and prevent such infiltrations.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
China-Linked Hackers Backdoor Linux Login Systems for Nearly a Decade
Impact· MEDIUM

China-Linked Hackers Backdoor Linux Login Systems for Nearly a Decade

In June 2026, cybersecurity firm Sygnia uncovered that the China-linked threat group known as Velvet Ant had infiltrated Linux systems by backdooring the Pluggable Authentication Modules (PAM) and OpenSSH components, enabling unauthorized access and credential harvesting. This sophisticated attack, which began as early as 2016, involved replacing trusted login programs with malicious versions, allowing the attackers to maintain persistent access and evade detection. The incident underscores the evolving tactics of nation-state actors targeting critical infrastructure components that are often overlooked, highlighting the need for organizations to implement rigorous integrity checks and continuous monitoring of authentication systems to detect and mitigate such stealthy intrusions.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Google's Legal Battle Against AI-Driven Smishing Attacks
Impact· HIGH

Google's Legal Battle Against AI-Driven Smishing Attacks

In June 2026, Google initiated legal action against a Chinese cybercrime network known as 'Outsider Enterprise.' This group utilized Google's Gemini AI to create and distribute phishing-as-a-service (PhaaS) kits, enabling the generation of fraudulent websites and the dispatch of massive SMS phishing ('smishing') campaigns. These campaigns impersonated reputable brands, deceiving recipients into providing personal and financial information. The operation involved over 9,000 fake websites and more than 1 million fraudulent web domains, leading to financial losses estimated in the millions and affecting hundreds of thousands of victims. ([techcrunch.com](https://techcrunch.com/2026/06/12/google-sues-alleged-chinese-cybercrime-operation-that-used-ai-to-send-scam-texts/?utm_source=openai)) This incident underscores the escalating threat posed by cybercriminals leveraging advanced AI technologies to conduct large-scale, sophisticated phishing attacks. The use of AI in such malicious activities highlights the urgent need for enhanced security measures and regulatory frameworks to combat AI-driven cyber threats effectively.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports