Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
U.S. Treasury Sanctions Nobitex for IRGC-Linked Transactions
In June 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned Nobitex, Iran's largest cryptocurrency exchange, for facilitating transactions linked to the Islamic Revolutionary Guard Corps (IRGC), including those associated with IRGC-affiliated ransomware actors. Nobitex processed over 50% of Iran's digital asset inflows in 2025 and assisted the Central Bank of Iran in accessing hundreds of millions of dollars in stablecoins to support the Iranian rial. This action is part of the U.S. government's "Economic Fury" campaign targeting financial networks supporting terrorism and sanctions evasion. The sanctions underscore the increasing scrutiny of cryptocurrency platforms used to circumvent international sanctions and finance illicit activities. Organizations must enhance their compliance measures to prevent inadvertent involvement in such networks, as regulatory bodies intensify efforts to disrupt financial channels linked to state-sponsored cyber threats.
3 months ago
Kill Chain
Critical Vulnerability in Microsoft 365 Android Apps Exposes User Tokens
In May 2026, a critical vulnerability was discovered in several Microsoft 365 Android applications, including Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote. A development flag, 'IsDebugMode', was inadvertently left enabled in production builds, disabling the security check that restricts account-token sharing to trusted Microsoft apps. This oversight allowed any app on the same device to request and obtain the signed-in user's Microsoft account tokens without requiring a password, login screen, or permission prompt. Consequently, unauthorized applications could access emails, files, calendars, and send messages as the user, posing significant security risks. ([securityweek.com](https://www.securityweek.com/exclusive-how-one-line-of-code-put-billions-of-microsoft-android-app-downloads-at-risk/amp/?utm_source=openai)) This incident underscores the critical importance of rigorous security checks in the software development lifecycle, especially in mobile applications that handle sensitive user data. The ease with which a single misconfiguration can lead to widespread security breaches highlights the need for continuous monitoring and auditing of application settings. Organizations must prioritize updating affected applications and implementing robust security practices to prevent similar vulnerabilities in the future.
3 months ago
Kill Chain
Critical Vulnerability: Malicious Notifications Hijack Google Gemini on Android
In June 2026, a vulnerability was discovered in Google Gemini's voice assistant on Android devices, allowing malicious notifications from apps like WhatsApp, Slack, SMS, Signal, Instagram, or Messenger to hijack the assistant. This exploit enabled attackers to perform unauthorized actions such as opening windows, sending fake messages, initiating calls, or altering the assistant's memory, all without requiring a malicious app on the device. The attack leveraged Gemini's ability to process notifications as actionable context, effectively bypassing user consent mechanisms. This incident underscores the evolving threat landscape where attackers exploit trusted system features to execute malicious activities. It highlights the necessity for continuous security assessments and prompt patching of AI-driven functionalities to prevent unauthorized access and maintain user trust.
3 months ago
Kill Chain
Operation Dragon Weave: Unveiling China's Cyber Espionage Tactics
In May 2026, a cyber espionage campaign named Operation Dragon Weave targeted government, research, academic, technology, and financial sectors in the Czech Republic and Taiwan. Attackers employed spear-phishing emails with ZIP attachments containing malicious files. Victims opening these files initiated an infection chain deploying the AdaptixC2 agent, enabling data exfiltration and remote control. The campaign utilized two infection methods: one involving a malicious Windows Shortcut (LNK) file disguised as a PDF, and another using a Rust-based dropper. Both methods led to the execution of a Rust-based loader called RUSTCLOAK, which decrypted and ran the final payload, AZUREVEIL. AZUREVEIL leveraged Microsoft Azure Blob Storage for command-and-control, facilitating stealthy communication between infected systems and attackers. ([thehackernews.com](https://thehackernews.com/2026/06/china-aligned-groups-ramp-up-attacks.html?utm_source=openai)) This incident underscores the evolving sophistication of nation-state cyber threats, particularly those attributed to China. The use of legitimate cloud services like Azure for command-and-control highlights the challenges in detecting and mitigating such attacks. Organizations in targeted sectors should enhance their cybersecurity measures, including employee training on phishing tactics and implementing advanced threat detection systems. ([thehackernews.com](https://thehackernews.com/2026/06/china-aligned-groups-ramp-up-attacks.html?utm_source=openai))
3 months ago
Kill Chain
FBI Issues Warning on Kali365 Phishing Kit Targeting Microsoft 365 Accounts
In April 2026, the FBI identified 'Kali365,' a Phishing-as-a-Service (PhaaS) platform that enables attackers to hijack Microsoft 365 accounts by stealing OAuth tokens, effectively bypassing multi-factor authentication (MFA). Distributed primarily via Telegram, Kali365 provides AI-generated phishing lures and automated campaign templates, allowing even low-skilled cybercriminals to gain unauthorized access to services like Outlook, Teams, and OneDrive without needing user credentials. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260521?utm_source=openai)) The emergence of Kali365 underscores a significant shift in phishing tactics, highlighting the increasing sophistication and accessibility of PhaaS platforms. This development emphasizes the urgent need for organizations to enhance their security measures beyond traditional MFA, as attackers continue to exploit legitimate authentication workflows to gain unauthorized access.
3 months ago
Kill Chain
CISA Adds Two Known Exploited Vulnerabilities to Catalog
On June 2, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2022-0492, a Linux Kernel Improper Authentication Vulnerability, and CVE-2025-48595, an Android Framework Integer Overflow Vulnerability. Both vulnerabilities are actively exploited, posing significant risks to federal enterprises. CVE-2022-0492 allows unauthorized access to Linux systems, while CVE-2025-48595 enables local privilege escalation on Android devices without user interaction. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-48595?utm_source=openai)) The inclusion of these vulnerabilities in the KEV Catalog underscores the critical need for organizations to promptly address known security flaws. With active exploitation in the wild, timely remediation is essential to mitigate potential threats and protect sensitive information.
3 months ago
Kill Chain
Microsoft Build 2026: Integrating Security Across the Development Lifecycle
At Microsoft Build 2026, held on June 2, 2026, Microsoft unveiled a comprehensive suite of security tools and capabilities aimed at integrating security throughout the development lifecycle. Key announcements included the introduction of the Microsoft Security multi-model agentic scanning harness (codename MDASH), designed to proactively identify and validate exploitable vulnerabilities in codebases, and the integration between Microsoft Defender and GitHub Code Security to prioritize and remediate code vulnerabilities efficiently. Additionally, Microsoft introduced the Agent 365 SDK to help developers build secure, enterprise-ready AI agents by default, and announced Defender AI model scanning to verify the integrity of AI models before deployment. These initiatives reflect Microsoft's commitment to embedding security into the development process, enabling faster and more secure innovation without compromising control. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/06/02/microsoft-build-2026-securing-code-agents-and-models-across-the-development-lifecycle/?utm_source=openai)) The relevance of these announcements is underscored by the increasing complexity and sophistication of cyber threats, particularly those leveraging AI to exploit vulnerabilities. By integrating advanced security measures directly into development tools and workflows, Microsoft aims to empower developers and security teams to stay ahead of emerging threats, ensuring that security is a foundational aspect of the development process rather than an afterthought.
3 months ago
Kill Chain
CISA Urges Immediate Action on Actively Exploited Oracle WebLogic Vulnerability CVE-2024-21182
In June 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) mandated federal agencies to address a high-severity vulnerability in Oracle WebLogic Server, identified as CVE-2024-21182. This flaw, patched in July 2024, allows unauthenticated attackers to exploit the T3 and IIOP protocols, potentially leading to unauthorized access to critical data. Despite the availability of patches, over 1,500 WebLogic servers remained exposed online, making them susceptible to exploitation. The resurgence of attacks targeting CVE-2024-21182 underscores the persistent threat posed by unpatched vulnerabilities. Organizations are urged to prioritize timely patch management to mitigate risks associated with known exploits, especially those that have been previously addressed but continue to be exploited due to delayed remediation efforts.
3 months ago
Kill Chain
Google Addresses Actively Exploited Android Zero-Day CVE-2025-48595 in June 2026 Security Update
In June 2026, Google released security patches addressing 124 vulnerabilities in the Android operating system, notably including CVE-2025-48595. This high-severity zero-day flaw in the Android Framework allows local attackers to execute code and escalate privileges on devices running Android 14 and later. Exploitation does not require user interaction, suggesting potential use of malicious applications to gain unauthorized access. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/google-fixes-one-actively-exploited-android-zero-day-124-flaws/?utm_source=openai)) The active exploitation of CVE-2025-48595 underscores the persistent threat posed by zero-day vulnerabilities in widely used platforms. Organizations must prioritize timely application of security updates to mitigate risks associated with such flaws, especially given the increasing sophistication of targeted attacks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/google-fixes-one-actively-exploited-android-zero-day-124-flaws/?utm_source=openai))
3 months ago
Kill Chain
Gamaredon Exploits WinRAR Vulnerability to Deploy Malware in Ukraine
In January 2026, the Russian state-sponsored hacking group Gamaredon exploited a path traversal vulnerability in WinRAR (CVE-2025-8088) to target Ukrainian government entities. The attack began with spear-phishing emails containing malicious RAR archives that, when opened, deployed an HTML Application payload named GammaPhish. This payload downloaded a VBScript downloader called GammaLoad, which subsequently installed malware such as GammaWorm and GammaSteel. GammaWorm established persistence and propagated through network shares and USB drives, while GammaSteel exfiltrated sensitive files to attacker-controlled servers. This incident underscores the persistent threat posed by state-sponsored actors leveraging known vulnerabilities to conduct espionage and data theft. The use of legitimate platforms like Telegram for command-and-control communication highlights the evolving tactics employed to evade detection and maintain long-term access to targeted networks.
3 months ago
Kill Chain
Oracle WebLogic CVE-2024-21182: Active Exploitation and Urgent Patch Advisory
In July 2024, Oracle addressed a high-severity vulnerability (CVE-2024-21182) in its WebLogic Server, which allowed unauthenticated attackers to gain unauthorized access via T3 and IIOP protocols, potentially compromising critical data. Despite the patch, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog in June 2026, indicating active exploitation in the wild. This development underscores the persistent threat posed by unpatched vulnerabilities in widely used enterprise software. Organizations relying on Oracle WebLogic Server must ensure they have applied the necessary patches to mitigate potential risks associated with this flaw.
3 months ago
Kill Chain
Google's June 2026 Android Security Update: Addressing 124 Vulnerabilities, Including Actively Exploited CVE-2025-48595
In June 2026, Google released security updates addressing 124 vulnerabilities in the Android operating system, notably including CVE-2025-48595—a high-severity privilege escalation flaw in the Framework component. This vulnerability affects Android versions 14 through 16 QPR2 and allows attackers to gain elevated privileges without user interaction, potentially leading to full device compromise. Google has acknowledged indications of limited, targeted exploitation of this flaw in the wild. The active exploitation of CVE-2025-48595 underscores the persistent threat posed by privilege escalation vulnerabilities in widely used mobile platforms. Organizations and individuals are urged to promptly apply the June 2026 security patches to mitigate potential risks associated with this and other addressed vulnerabilities.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports