Tag: government sector
14 articles

Florida DMV Breach Exposed via Stolen Police Credentials
A data breach at the Florida DMV exposed sensitive information after an international cybercriminal group compromised the system using stolen police credentials. The breach was quickly identified and mitigated on September 4, 2026, and no further unauthorized access has occurred.

US Targets 45% of Global RMM Phishing Campaign
The US has become the primary target of a massive global phishing campaign, accounting for nearly 45% of all observed activity, with education, technology, and government sectors being hit the hardest. This widespread operation, linked to 601 cases across 46 countries, has also prominently targeted banking, finance, and manufacturing industries.

CISA Red Team Exposes Defense Gap Between Water, Government Sectors
In a recent test, CISA's red team uncovered a shocking vulnerability in a government organization, breaching its defenses with ease by sending phishing emails from an internal address, then moving undetected to sensitive systems and cloud resources. The team was able to gain elevated privileges and spread laterally, exposing a significant gap in the organization's security.

China-nexus Operation QUICSILVER Targets Myanmar with QUICAgent Backdoor
Meet Operation QUICSILVER, a sneaky cyber espionage campaign targeting Myanmar's government and tech sectors with a multi-stage backdoor delivery chain, likely orchestrated by a China-nexus threat actor. The attack begins with clever social-engineering lures disguised as official materials, like graduation invites and fake holiday messages.

Scottish Prosecutors Investigate Supplier After Staff Data Compromised
A data security breach has hit a Scottish Government partner, compromising sensitive information of around 300 Crown Office and Procurator Fiscal Service (COPFS) staff who took part in a public sector survey. The incident is under investigation, but COPFS confirms its own systems remain secure.

Jewelbug Hacker Group Exposes Dual Threat of Espionage and Crypto Fraud
Meet Jewelbug, a China-based hacker group that's been wreaking havoc with a dual threat of espionage and crypto fraud, leaving a trail of over a million compromised implant check-ins and thousands of stolen credentials in its wake. By cleverly injecting a single malicious script into a shared webmail template, Jewelbug gained write access to sensitive government webmail accounts, making off with valuable data.

Hackers Deploy AI for Near-Autonomous Attack on Taiwan Government
In a chilling first, hackers unleashed a near-autonomous AI-driven cyber attack on the Taiwanese government, extracting over 2,500 personnel records with alarming ease. This groundbreaking attack was able to adapt and evolve mid-operation, all without human intervention.

South Korea's Diplomacy Hit by Months-Long Data Breach
South Korea's Ministry of Foreign Affairs has issued a warning after a months-long data breach compromised the personal info of thousands of diplomats and staff worldwide, including 350 government attachés overseas. The breach, which hit the National Diplomatic Academy's online education system, has prompted officials to urge caution when receiving emails from unknown sources.

Iran-Linked Cavern Manticore Targets Israel with Modular Cyber Attacks
Meet Cavern Manticore, a highly skilled and disciplined cyber threat group with ties to Iran, targeting Israel's defense and government sectors with modular attacks. Their sophisticated tactics have allowed them to infiltrate organizations with alarming speed and precision.

Mustang Panda Exploits Zoho WorkDrive in Indian Government Attacks
Meet the sneaky hackers known as Mustang Panda, who've been using a clever trick to steal sensitive info from Indian government machines - by hiding in plain sight within legitimate cloud traffic on Zoho WorkDrive. Their covert operation went undetected for 10 days, blending in seamlessly with routine cloud activity.

Chinese Hackers Target Southeast Asia's Energy, Government Sectors
Chinese hackers have launched a stealthy assault on Southeast Asia's energy and government sectors, infiltrating at least ten organizations between October and December 2025. This sophisticated threat, tracked as CL-STA-1062, has been lurking in the shadows since March 2022, using clever tactics like hard-coded encryption keys to evade detection.

CISA Warns Fortinet Users of Credential Exposure After FortiBleed Leak
Fortinet users are being warned by CISA to take immediate action to protect themselves from credential exposure after a massive leak, known as FortiBleed, exposed nearly 74,000 firewall and VPN credentials. Take steps now to secure your devices and prevent malicious cyber actors from exploiting your compromised credentials.

Managed Detection and Response Targets Gaps in Cyber Defenses
State, local, tribal, and territorial organizations, along with their schools, are facing a perfect storm of rising cyber threats, limited staff, and tight budgets - making it tough to stay ahead of attacks. Managed Detection and Response can help bridge the gaps in their cyber defenses, providing the support and visibility needed to respond quickly and effectively.

AgingFly Malware Targets Ukraine Govt, Hospitals in Data Heist
A newly discovered malware called AgingFly is targeting Ukraine's government and hospitals, stealing sensitive online identity keys and putting public services at risk. This fresh threat siphons authentication data from popular web browsers and messaging apps, sparking urgent concern.