Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
ShinyHunters' 2026 Breach of Instructure's Canvas LMS: A Wake-Up Call for Educational Cybersecurity
In early May 2026, Instructure, the company behind the Canvas learning management system, suffered a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers accessed personal information of approximately 275 million individuals across nearly 9,000 educational institutions worldwide. Compromised data included names, email addresses, student ID numbers, and billions of private messages exchanged between students and educators. Although Instructure reported that passwords and financial information were not affected, the breach led to widespread disruptions, including defaced login portals and service outages during critical academic periods. ([techradar.com](https://www.techradar.com/pro/security/canvas-school-login-portals-hacked-as-instructure-hack-apparently-gets-even-worse?utm_source=openai)) This incident underscores the escalating threat posed by cyber extortion groups targeting large-scale educational platforms. The breach highlights the vulnerabilities inherent in centralized educational systems and the potential for significant operational disruptions and data privacy concerns. Educational institutions must reassess their cybersecurity strategies to mitigate risks associated with third-party service providers and ensure the protection of sensitive user information. ([insidehighered.com](https://www.insidehighered.com/news/tech-innovation/administrative-tech/2026/05/05/pay-or-leak-hackers-target-big-higher-ed-vendor?utm_source=openai))
4 months ago
Kill Chain
Urgent Alert: 'Dirty Frag' Linux Vulnerability (CVE-2026-43284) Poses Severe Security Risk
In May 2026, a critical Linux kernel vulnerability known as 'Dirty Frag' (CVE-2026-43284) was disclosed, enabling local privilege escalation from unprivileged user to root access. This flaw affects multiple Linux distributions, including Ubuntu, RHEL, CentOS Stream, AlmaLinux, Fedora, openSUSE, and OpenShift. Exploitation can occur through various vectors such as compromised SSH accounts, web-shell access, container escapes, or abuse of low-privileged service accounts. Once exploited, attackers can disable security tools, access sensitive credentials, tamper with logs, and establish persistent access. The 'Dirty Frag' vulnerability is particularly concerning due to its multiple kernel attack paths involving rxrpc and esp/xfrm networking components, which enhance exploitation reliability. Unlike traditional race-condition-dependent exploits, 'Dirty Frag' offers a more consistent method for privilege escalation across vulnerable environments. Organizations are urged to apply patches promptly and implement interim mitigations to protect their systems.
4 months ago
Kill Chain
Critical 'Dirty Frag' Zero-Day Exposes Major Linux Distributions to Root Exploits
In May 2026, security researcher Hyunwoo Kim disclosed a critical Linux zero-day vulnerability named 'Dirty Frag.' This exploit allows local attackers to gain root privileges on major Linux distributions, including Ubuntu, Red Hat Enterprise Linux, CentOS Stream, AlmaLinux, openSUSE Tumbleweed, and Fedora. The vulnerability chains two kernel flaws—the xfrm-ESP Page-Cache Write and the RxRPC Page-Cache Write—to modify protected system files in memory without authorization, leading to privilege escalation. Notably, 'Dirty Frag' is a deterministic logic bug that does not depend on race conditions, ensuring a high success rate for attackers. The disclosure of 'Dirty Frag' follows closely on the heels of the 'Copy Fail' vulnerability (CVE-2026-31431), highlighting a concerning trend of critical Linux kernel flaws being exploited in the wild. The rapid succession of these vulnerabilities underscores the urgent need for organizations to prioritize timely patching and robust security measures to protect their systems from potential exploits.
4 months ago
Kill Chain
Former Government Contractors Convicted for Deleting Federal Databases
In February 2025, twin brothers Muneeb and Sohaib Akhter, both 34 and former federal contractors, were terminated from their positions after their prior felony convictions for unauthorized access to U.S. State Department systems were discovered. Immediately following their dismissal, they accessed their employer's systems without authorization, deleting approximately 96 government databases containing sensitive information, including investigative documents and Freedom of Information Act records. They also attempted to cover their tracks by seeking guidance from an AI assistant on clearing system logs and wiping company-issued laptops before returning them. This incident underscores the critical need for stringent access controls and monitoring mechanisms to prevent insider threats, especially from individuals with prior offenses. The case highlights the potential risks associated with rehiring individuals with a history of cyber offenses and the importance of comprehensive background checks and continuous monitoring to safeguard sensitive government data.
4 months ago
Kill Chain
Urgent: Patch Ivanti EPMM Zero-Day Vulnerability CVE-2026-6973 Now
In May 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) mandated federal agencies to patch a high-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM), identified as CVE-2026-6973. This flaw allows authenticated users with administrative privileges to execute arbitrary code remotely on affected systems. Ivanti released patches for versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 to address this issue. At the time of disclosure, exploitation was reported to be limited, but the potential for significant impact necessitated immediate action. The urgency of this directive underscores the critical nature of timely vulnerability management. With over 800 Ivanti EPMM appliances exposed online, unpatched systems remain susceptible to exploitation, highlighting the importance of proactive security measures in safeguarding organizational infrastructure.
4 months ago
Kill Chain
CVE-2025-68670: Critical Remote Code Execution Vulnerability in xrdp Server
In December 2025, Kaspersky identified a critical remote code execution (RCE) vulnerability, CVE-2025-68670, in the xrdp server—a widely used open-source implementation of the Remote Desktop Protocol (RDP) for Linux systems. The flaw resides in the xrdp_wm_parse_domain_information function, which processes domain names during the Secure Settings Exchange phase of an RDP connection. By sending a specially crafted domain name, an unauthenticated attacker can exploit this vulnerability to execute arbitrary code on the target server, potentially leading to full system compromise. The xrdp maintainers promptly addressed the issue by releasing patches in versions 0.10.5, 0.9.27, and 0.10.4.1, accompanied by a security bulletin detailing the vulnerability and mitigation steps. This incident underscores the critical importance of regular security assessments and timely patch management, especially for widely used open-source software. Organizations relying on xrdp for remote desktop services should ensure they have applied the necessary updates to protect against potential exploitation of this vulnerability.
4 months ago
Kill Chain
ShinyHunters Breach Canvas: 275 Million Users' Data Exposed
In early May 2026, the cybercriminal group ShinyHunters executed a data extortion attack on Instructure's Canvas learning management system, compromising personal information of approximately 275 million users across nearly 9,000 educational institutions worldwide. The breach exposed names, email addresses, student ID numbers, and private messages between students and faculty. The attackers defaced Canvas login pages with ransom demands, leading to widespread disruptions during critical academic periods, including final exams. ([apnews.com](https://apnews.com/article/446c240d5aeb1b1a1e3795fb92237563?utm_source=openai)) This incident underscores the escalating threat of cyberattacks targeting educational platforms, highlighting the urgent need for robust cybersecurity measures in the education sector. The timing of the attack, coinciding with final exams, emphasizes the potential for significant operational impact and the importance of proactive defense strategies against such threats.
4 months ago
Kill Chain
Karakurt Ransomware Negotiator Sentenced to 102 Months in Prison
In May 2026, Latvian national Deniss Zolotarjovs was sentenced to 102 months in U.S. federal prison for his role as a negotiator in the Karakurt ransomware group. Operating between June 2021 and August 2023, Zolotarjovs was instrumental in extorting over 54 companies, leading to more than $56 million in losses. He employed aggressive tactics, including leveraging sensitive data such as children's health records, to pressure victims into paying ransoms. This sentencing marks a significant milestone in the fight against international cybercrime, highlighting the global reach of law enforcement agencies in apprehending and prosecuting cybercriminals. The case underscores the persistent threat posed by ransomware groups and the importance of robust cybersecurity measures to protect sensitive information.
4 months ago
Kill Chain
PamDOORa: A New Threat to Linux Authentication Security
In May 2026, cybersecurity researchers uncovered a new Linux backdoor named PamDOORa, advertised on the Rehub Russian cybercrime forum for $1,600 by a threat actor known as "darkworm." PamDOORa is a Pluggable Authentication Module (PAM)-based post-exploitation toolkit that enables persistent SSH access through a magic password and specific TCP port combination. Additionally, it can harvest credentials from all legitimate users who authenticate through the compromised system. The backdoor also incorporates anti-forensic capabilities to tamper with authentication logs, effectively erasing traces of malicious activity. The emergence of PamDOORa highlights a growing trend of sophisticated Linux-based malware targeting authentication mechanisms to establish persistent access and exfiltrate sensitive credentials. This development underscores the need for organizations to implement robust monitoring and auditing of authentication processes to detect and mitigate such threats.
4 months ago
Kill Chain
Critical Vulnerability in MAXHUB Pivot Client Application: CVE-2025-53704
In December 2025, a critical vulnerability (CVE-2025-53704) was identified in the MAXHUB Pivot client application versions prior to v1.36.2. This flaw involved a weak password recovery mechanism, allowing remote attackers to request password resets and gain unauthorized access to user accounts without prior authentication. The vulnerability posed significant risks, including potential data breaches and unauthorized control over affected systems. The incident underscores the importance of robust authentication mechanisms and timely software updates. Organizations are advised to upgrade to version 1.36.2 or newer to mitigate this risk. This case highlights the ongoing need for vigilance against authentication vulnerabilities in widely used applications.
4 months ago
Kill Chain
CISA Adds CVE-2026-6973 to Known Exploited Vulnerabilities Catalog
On May 7, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-6973 to its Known Exploited Vulnerabilities (KEV) catalog. This high-severity vulnerability affects Ivanti Endpoint Manager Mobile (EPMM) versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1, allowing authenticated users with administrative privileges to execute arbitrary code remotely. Ivanti has released patches to address this issue and urges organizations to update their systems promptly. ([redpacketsecurity.com](https://www.redpacketsecurity.com/cve-alert-cve-2026-6973-ivanti-endpoint-manager-mobile/?utm_source=openai)) The inclusion of CVE-2026-6973 in the KEV catalog underscores the ongoing threat posed by vulnerabilities in widely used enterprise management tools. Organizations are advised to prioritize the remediation of such vulnerabilities to mitigate potential risks to their networks and data. ([cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=openai))
4 months ago
Kill Chain
Critical Ivanti EPMM Zero-Day CVE-2026-6973 Exploited in the Wild
In May 2026, Ivanti disclosed a critical zero-day vulnerability, CVE-2026-6973, in its Endpoint Manager Mobile (EPMM) software. This flaw allows authenticated users with administrative privileges to execute remote code, potentially compromising the entire mobile device management infrastructure. The vulnerability has been actively exploited in the wild, with Ivanti confirming limited instances of exploitation. To mitigate this risk, Ivanti released patches for EPMM versions 12.6.1.1, 12.7.0.1, and 12.8.0.1, urging all on-premises EPMM customers to apply these updates immediately. ([thehackernews.com](https://thehackernews.com/2026/05/ivanti-epmm-cve-2026-6973-rce-under.html?utm_source=openai)) This incident underscores the persistent targeting of mobile device management systems by threat actors, highlighting the critical need for organizations to maintain up-to-date security measures and promptly apply vendor-released patches to protect sensitive data and infrastructure.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports