Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
U.S. Military's Covert Use of GPS for Encrypted Key Distribution Unveiled
In June 2026, security researcher Steven Murdoch uncovered that the U.S. military has been utilizing public GPS signals to broadcast encrypted cryptographic keys for nearly two decades. This method effectively transformed GPS satellites into global 'numbers stations,' enabling the Over-the-Air Distribution (OTAD) and Over-the-Air Rekeying (OTAR) systems to remotely update cryptographic keys for military GPS receivers worldwide. The discovery highlights the military's innovative approach to secure key distribution without relying on physical couriers. ([404media.co](https://www.404media.co/the-u-s-military-quietly-turned-gps-into-a-global-numbers-station-evidence-suggests/?utm_source=openai)) This revelation underscores the critical importance of secure key management in military operations and the potential for leveraging existing infrastructure for covert communications. It also raises questions about the transparency of such methods and their implications for both military and civilian users of GPS technology.
3 months ago
Kill Chain
Cisco SD-WAN Zero-Day CVE-2026-20245: A Critical Security Alert
In June 2026, Cisco disclosed CVE-2026-20245, a zero-day vulnerability in its Catalyst SD-WAN Manager, marking the seventh such exploit in their SD-WAN products that year. This flaw allows authenticated attackers with netadmin privileges to execute arbitrary commands as root by uploading a crafted file, potentially leading to unauthorized configuration changes on edge devices. Exploitation requires valid credentials or prior exploitation of vulnerabilities like CVE-2026-20182 or CVE-2026-20127. Cisco has observed limited cases where this vulnerability resulted in configuration changes pushed to edge devices. As of now, no patch or workaround is available, and the company advises upgrading to fixed software released in May 2026 as a protective measure. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/06/05/cisco-sd-wan-cve-2026-20245-0-day-exploited/?utm_source=openai)) The recurrence of such vulnerabilities underscores the critical need for organizations to maintain rigorous access controls and promptly apply security updates. The exploitation of multiple zero-days within a short period highlights the evolving threat landscape targeting network infrastructure, emphasizing the importance of proactive vulnerability management and continuous monitoring to safeguard against potential breaches.
3 months ago
Kill Chain
Meta Challenges NSO Group Over New WhatsApp Spyware Attacks
In June 2026, Meta identified and disrupted a spear-phishing campaign linked to the Israeli spyware firm NSO Group, targeting WhatsApp users. This activity violated a permanent injunction issued in 2025, which barred NSO from engaging with WhatsApp and its users. The campaign involved deceptive messages designed to lure individuals into clicking malicious links, leading to external websites, and the creation of test accounts and groups within WhatsApp. Meta responded by filing a contempt-of-court complaint against NSO Group for defying the court order. ([cyberscoop.com](https://cyberscoop.com/meta-contempt-complaint-nso-group-spyware/?utm_source=openai)) This incident underscores the persistent threat posed by spyware vendors and the challenges in enforcing legal actions against them. It highlights the need for continuous vigilance and robust security measures to protect users from sophisticated cyber threats.
3 months ago
Kill Chain
Check Point VPN Zero-Day Exploited by Qilin Ransomware
In early May 2026, Check Point identified a critical authentication bypass vulnerability, CVE-2026-50751, in its Remote Access VPN and Mobile Access products configured with the deprecated IKEv1 protocol. This flaw allows unauthenticated remote attackers to establish VPN connections without valid credentials. Exploitation began on May 7, 2026, affecting a limited number of organizations globally, with at least one incident linked to the Qilin ransomware group. Check Point has released patches and mitigation measures to address this vulnerability. The exploitation of CVE-2026-50751 underscores the risks associated with using outdated protocols like IKEv1. Organizations are urged to update their systems promptly and transition to more secure configurations to prevent unauthorized access and potential ransomware attacks.
3 months ago
Kill Chain
Critical Gogs Vulnerability Patched: Argument Injection Leads to RCE
In June 2026, a critical argument injection vulnerability was discovered in Gogs, a self-hosted Git service. This flaw allowed authenticated users to execute remote code, potentially compromising servers, accessing private repositories, stealing credentials, and altering source code. The vulnerability affected all Gogs releases up to and including 0.14.2 and 0.15.0+dev. Rapid7 security researcher Jonah Burgess identified the issue, noting that default configurations with open registration enabled made exploitation easier. Gogs maintainers released version 0.14.3 on June 7, 2026, to address this flaw. This incident underscores the importance of timely patching and vigilant configuration management. The prevalence of similar vulnerabilities highlights the need for organizations to proactively secure their development environments against emerging threats.
3 months ago
Kill Chain
WhatsApp Thwarts NSO Group's Latest Spyware Phishing Attacks
In June 2026, WhatsApp identified and disrupted spear-phishing campaigns linked to the NSO Group, an Israeli spyware vendor known for its Pegasus tool. These attacks involved social engineering tactics, attempting to lure users into clicking malicious links that redirected them to external websites, aiming to deploy spyware. This activity violated a 2025 U.S. court injunction that barred NSO from targeting WhatsApp and its users. Meta, WhatsApp's parent company, responded by filing a federal court contempt order against NSO for this breach. This incident underscores the persistent threat posed by commercial spyware vendors and highlights the importance of robust security measures and legal frameworks to protect user privacy and national security.
3 months ago
Kill Chain
Meta Thwarts NSO Group's Latest WhatsApp Phishing Scheme
In June 2026, Meta identified and disrupted spear-phishing attempts linked to the Israeli spyware vendor NSO Group. These attacks aimed to deceive users into clicking malicious links, redirecting them to external websites outside of WhatsApp. Meta also discovered that NSO Group had created test accounts and groups on WhatsApp, which were subsequently removed. This activity violated a permanent injunction issued in 2025 that barred NSO from targeting WhatsApp and its users. In response, Meta filed a federal court contempt order against NSO Group for breaching this injunction. ([about.fb.com](https://about.fb.com/news/2026/06/fighting-spyware-an-update-from-whatsapp/?utm_source=openai)) This incident underscores the persistent threat posed by spyware vendors like NSO Group, who continue to develop and deploy sophisticated attacks against communication platforms. The recurrence of such activities highlights the need for ongoing vigilance and robust security measures to protect user privacy and maintain platform integrity.
3 months ago
Kill Chain
Massive Exploitation of Ghost CMS Vulnerability CVE-2026-26980
In May 2026, a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS was exploited to compromise over 700 websites, including those of Harvard University, Oxford University, and DuckDuckGo. Attackers injected malicious JavaScript into these sites, presenting visitors with fake Cloudflare verification prompts that, when followed, installed malware on their systems. This vulnerability, with a CVSS score of 9.4, allowed unauthenticated attackers to read arbitrary data from the database, leading to widespread data breaches and malware distribution. ([techtimes.com](https://www.techtimes.com/articles/317134/20260525/ghost-cms-sql-injection-hits-700-sites-harvard-duckduckgo-serve-fake-cloudflare-malware.htm?utm_source=openai)) The exploitation of this vulnerability underscores the critical importance of timely patch management. Despite a patch being available since February 2026, many organizations failed to apply it, resulting in significant security incidents. This case highlights the ongoing risks associated with unpatched software and the necessity for organizations to maintain robust vulnerability management practices. ([techradar.com](https://www.techradar.com/pro/security/ghost-cms-flaw-hijacked-to-target-hundreds-of-websites-with-clickfix-attacks-heres-how-to-stay-safe?utm_source=openai))
3 months ago
Kill Chain
VerdantBamboo's Prolonged Cyber Espionage via BRICKSTORM Backdoor
In September 2025, cybersecurity firm Volexity identified a prolonged cyber espionage campaign by the Chinese state-sponsored group VerdantBamboo, also known as UNC5221. The attackers exploited a local privilege escalation vulnerability in an Egnyte Storage Sync appliance to deploy a BSD variant of the BRICKSTORM backdoor, maintaining undetected access for at least 18 months. This access facilitated further infiltration into the victim's Microsoft 365 environment and the deployment of additional malware, including PLENET and AGENTPSD, on various network appliances. The campaign underscores the increasing targeting of network appliances and storage systems by sophisticated threat actors, exploiting their lack of endpoint detection capabilities to establish long-term persistence. Organizations are urged to enhance monitoring and security measures for such devices to mitigate similar threats.
3 months ago
Kill Chain
Critical Check Point VPN Flaw Exploited: CVE-2026-50751
In early June 2026, Check Point Software Technologies disclosed active exploitation of a critical vulnerability, CVE-2026-50751, affecting their Remote Access VPN and Mobile Access products configured with the deprecated IKEv1 key exchange protocol. This flaw allows unauthenticated remote attackers to bypass user authentication and establish unauthorized VPN connections. Exploitation has been observed since at least May 7, 2026, with increased activity in early June, including incidents linked to a Qilin ransomware affiliate. ([blog.checkpoint.com](https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/amp/?utm_source=openai)) The incident underscores the risks associated with using outdated protocols like IKEv1, which, despite being deprecated, remain in use for legacy compatibility. Organizations are urged to disable IKEv1 and apply security updates to mitigate this vulnerability. ([blog.checkpoint.com](https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/amp/?utm_source=openai))
3 months ago
Kill Chain
AI-Generated Phishing Attacks Overwhelm SOCs in 2026
In early 2026, organizations experienced a surge in AI-generated phishing attacks, leading to an overwhelming increase in security alerts. These sophisticated campaigns utilized generative AI to craft convincing emails and evade traditional detection methods, significantly burdening Security Operations Centers (SOCs). As a result, SOCs faced challenges in effectively triaging and responding to the high volume of alerts, with only 37% of daily security alerts being investigated. This escalation in alert volume not only strained resources but also increased the risk of overlooking genuine threats, thereby elevating the overall cost and complexity of cybersecurity operations. ([prnewswire.com](https://www.prnewswire.com/news-releases/new-research-reveals-enterprises-investigate-just-37-of-daily-security-alerts-as-ai-expands-in-the-soc-302717184.html?utm_source=openai)) The proliferation of AI-driven phishing attacks underscores the urgent need for organizations to adapt their cybersecurity strategies. Traditional defense mechanisms are proving inadequate against the scale and sophistication of these threats. Implementing advanced AI-powered defenses and enhancing SOC capabilities are critical to effectively manage and mitigate the risks associated with AI-generated phishing campaigns.
3 months ago
Kill Chain
CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog
In early June 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a high-severity vulnerability, CVE-2026-28318, affecting SolarWinds Serv-U, to its Known Exploited Vulnerabilities (KEV) catalog. This denial-of-service (DoS) flaw allows unauthenticated attackers to crash the Serv-U service by sending specially crafted POST requests with the 'Content-Encoding: deflate' header. The vulnerability has a CVSS score of 7.5 and is actively being exploited in the wild. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-28318?utm_source=openai)) The inclusion of this vulnerability in the KEV catalog underscores the critical need for organizations to promptly apply security patches. Unpatched systems remain susceptible to service disruptions, which can have significant operational and financial impacts. ([scworld.com](https://www.scworld.com/brief/hackers-actively-exploit-solarwinds-serv-u-flaw-to-crash-servers-cisa-warns?utm_source=openai))
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports