NEW: Group Profiler — instant APT intel lookup. Try it →

Government — threat intelligence

Recent advisories whose title or summary heuristically matches the Government sector. Derived in-browser/at-edge from a keyword catalog — treat tags as a hint and open each source for ground truth. The underlying feed updates hourly; this page is a snapshot from its last build (timestamped below).

50 recent Government advisories

Snapshot built . The live filter and the RSS feed reflect new items as they arrive.

  1. INFO EXPLOITED thehackernews ·

    Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

    The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The a…

    microsoft
  2. INFO thehackernews ·

    Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

    Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cam…

    ciscocisco-networkmicrosoft-365 TWINPH
  3. INFO darkreading ·

    SWIFT Banking & Government Middleware Enables RCE

    Patch middleware vulnerabilities now to avoid hardware-based MFA exploits in ultra-sensitive environments.

  4. INFO schneier ·

    Unidentified Flock Cameras in Florida

    St. Lucie County in Florida discovered (alt link) a dozen Flock cameras whose ownership it can’t identify, and that the county government had not permitted. I am reminded of the decade-old story of StingRay cell phone surveillance devices i…

    US
  5. INFO EXPLOITED the-record ·

    Mississippi mayor says ransomware incident led city to shut down systems

    Government services were temporarily disrupted by ransomware in Vicksburg, Mississippi. Mayor Willis Thompson said the FBI and other authorities are investigating.

    US
  6. INFO securityweek ·

    In Rare Move, Alleged Iranian State Hacker Extradited to US

    Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad. The post In Rare Move, Alleged Iranian State Hacker Extradited to US appear…

    US
  7. INFO securityweek ·

    AI Agents Aimed SQL Injection at US and Canadian Government Sites

    The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI. The post AI Agents Aimed SQL Injection at US and Canadian Government Sites appeared first on SecurityWeek.

    USCA
  8. INFO the-record ·

    Researchers find Chinese hacking campaigns targeting AI firms, Asian governments

    Two separate reports by cybersecurity companies highlight China-linked hacking operations, including a phishing campaign that impersonated Western experts.

  9. INFO microsoft-security-blog ·

    Preparing governments for an era of interconnected cyber risk

    According to this year’s Microsoft Digital Defense Report, government agencies and services were the sector most impacted by cyber threats in 2026, accounting for 27% of observed activity, up from 17% in 2025. The post Preparing governments…

    microsoft
  10. INFO securityweek ·

    Treasury Blacklists Most-Wanted ATM Malware Developer and His Network

    The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme. The post Treasury Blacklists Most-Wanted ATM Malware Developer and His Network appeared first on SecurityWeek.

    US
  11. INFO EXPLOITED securityweek ·

    Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

    Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772. The post Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks appeared first on SecurityWeek…

    citrix
  12. INFO schneier ·

    I Want Better Reporting on AI Genie Behavior

    AI systems are regularly completing tasks in ways that their prompters don’t want or intend. Some of them are disturbing, and some of them are dangerous. This is something I’ve been calling “genie behavior,” because I think that really gets…

  13. INFO thehackernews ·

    US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

    ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest expo…

    microsoft US
  14. INFO talos-intel ·

    China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

    Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred t…

    ciscocisco-network TWINPH
  15. INFO EXPLOITED thehackernews ·

    Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

    Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting an…

    citrix USEU
  16. INFO huntress-blog ·

    Determined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Servers

    Huntress SOC found a threat actor exploiting a file upload flaw in recreation management to breach 3 municipal servers and steal payment data.

    huntress
  17. INFO the-record ·

    OpenAI apologizes for agents breaching Australian government websites without authorization

    The artificial intelligence giant acknowledged it botched its response to the incidents and should have done more to promptly notify and work with the Australian government in the days after it discovered the breaches.

    AU
  18. INFO darkreading ·

    'NeedyMantis' Provides Long-Term Access to Compromised Networks

    Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related organizations.

    microsoft-windows
  19. INFO EXPLOITED mandiant-blog ·

    Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances

    Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gatew…

    citrix USCAEU
  20. INFO thehackernews ·

    Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

    Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecomm…

    microsoft-windows
  21. CRITICAL EXPLOITED securityweek ·

    Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

    CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28. The post Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks appeared first on SecurityWeek.

    microsoft US
  22. INFO securityweek ·

    OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure

    OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.” The post OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosu…

    US
  23. INFO securityweek ·

    CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks

    Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July. The post CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks appeared first on SecurityWeek.

    US
  24. INFO the-record ·

    Doubts grow over claims OpenAI agent hacked Australian Medicare portal

    Researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visitors to an unauthenticated endpoint.

    AU
  25. INFO securityweek ·

    OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data

    Australia disclosed that an OpenAI agent gained unauthorized access to non-public government information. The post OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data appeared first on SecurityWeek.

    AU
  26. INFO the-record ·

    OpenAI agent breached Australian government health website, Albanese says

    An OpenAI agent gained “unauthorized access” to “non-public files” from an Australian government health website in June, Prime Minister Anthony Albanese said.

    AU
  27. INFO thehackernews ·

    OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files

    An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said. The portal publishes aggregate figures, such as spending, and is …

    AU
  28. INFO thehackernews ·

    SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

    The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. "SideCopy campaign operations typically initiate through s…

    microsoft IN
  29. INFO checkpoint ·

    21st September – Threat Intelligence Report

    For the latest discoveries in cyber research for the week of 21st Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan’s Digital Agency, which operates the Government Solution Service used by multiple …

    check-point JP
  30. INFO greynoise-blog ·

    Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation

    GreyNoise has been tracking malicious use of an IP address since early June 2026 due to its frequent use in scans and attacks against a variety of technologies. We detail a few of the more notable intrusions we observed including the theft …

    wordpress
  31. INFO the-record ·

    Russia reports thousands of cyberattacks on election infrastructure during vote

    Claims by officials of cyberattacks against election infrastructure could not be independently verified. Russian officials provided little technical evidence about the attacks or who it claimed who was behind them.

    RU
  32. INFO securityweek ·

    TigerByte Cyber Emerges From Stealth With $3 Million in Funding

    The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA. The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.

    US
  33. INFO thehackernews ·

    Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

    The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler …

    zscalergithub INAF
  34. INFO the-record ·

    China’s FamousSparrow hackers target Latin America with new backdoor

    Alleged Chinese hackers are breaking into government agencies across Latin America using a new backdoor that researchers are calling “SparroWocky.”

    US
  35. INFO malwarebytes-labs ·

    Revolut phishing texts appear days after data breach

    Revolut customers received phishing texts only days after the digital bank acknowledged disclosing customer data to a government impostor.

  36. INFO securityweek ·

    Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

    Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months. The post Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom appeared first on SecurityWeek.

  37. INFO the-record ·

    Hackers claim breach of Russian election systems days before parliamentary vote

    An anonymous hacking group claimed to have broken into computer systems connected to Russia’s election infrastructure just days before the country begins voting for a new parliament.

    RU
  38. INFO the-record ·

    Israeli contractor BlackCore trained Angolan officials in online influence operations

    An Israeli influence-for-hire company trained Angolan government officials to run online influence operations, including by creating fake social media personas and media outlets, researchers found.

  39. INFO group-ib-blog ·

    HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack

    Group-IB Threat Intelligence analyzes HEAVYGRAM, a Telegram-based Windows backdoor attributed with moderate confidence to the Iran-linked threat actor Handala Hack. Active since Fall 2023, it has been used to surveil Iranian dissidents, jou…

    microsoft IR
  40. INFO securityweek ·

    US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware

    US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C. The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on Securi…

    USGBNL
  41. INFO cisa-alerts ·

    Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers

    Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptograp…

    US
  42. INFO schneier ·

    25 Years of Mass Surveillance Is Enough

    This essay was written with Cindy Cohn, and originally appeared in Lawfare. One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/tr…

  43. INFO EXPLOITED thehackernews ·

    China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

    A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tra…

    googlemicrosoft
  44. INFO the-record ·

    Hundreds of fake government websites target users in Central Asia

    The sites are designed to collect victims’ contact details, which scammers then use to target them through phone or email to steal money, personal information or gain access to their devices.

  45. INFO securityweek ·

    Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development

    China’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work together on AI. The post Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development appeared first on Secu…

  46. INFO securityweek ·

    Personal, Financial Info Exposed in Revolut Data Breach

    The company unintentionally disclosed users’ information to a third party impersonating a government agency. The post Personal, Financial Info Exposed in Revolut Data Breach appeared first on SecurityWeek.

  47. INFO checkpoint ·

    14th September – Threat Intelligence Report

    For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detec…

    check-point US
  48. INFO the-record ·

    Revolut handed customer data to fraudsters using government email account

    British fintech Revolut confirmed disclosing sensitive customer data to fraudsters who submitted emergency data requests from a legitimate government email account.

    UK
  49. INFO malwarebytes-labs ·

    Revolut gave customer IDs and financial data to a government impostor

    The digital bank was tricked into releasing sensitive customer information, including IDs, to an attacker using a legitimate government email domain.

  50. INFO darkreading ·

    CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate

    A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols.

    US

Other sectors: Healthcare ·Finance ·Energy ·Critical Infra ·Education ·Technology ·Telecom ·Defense ·Retail ·Transportation ·Legal Services

Threat groups reported to target Government

MITRE ATT&CK records 64 tracked groups with reported targeting of this sector. Each links to its ATT&CK profile: techniques by tactic, aliases, tooling and the groups closest to it by technique overlap. Reported targeting is not attribution of any specific advisory above.

admin@338 ·Ajax Security Team ·Andariel ·Aoqin Dragon ·AppleJeus ·APT-C-23 ·APT-C-36 ·APT1 ·APT12 ·APT17 ·APT18 ·APT28 ·APT29 ·APT30 ·APT32 ·APT37 ·APT38 ·APT42 ·Aquatic Panda ·Axiom ·BackdoorDiplomacy ·Cleaver ·CopyKittens ·CURIUM ·Daggerfly ·Dragonfly ·Earth Lusca ·Gamaredon Group ·HEXANE ·Higaisa ·Inception ·Ke3chang ·Kimsuky ·Lazarus Group ·Leviathan ·Lotus Blossom ·Machete ·Magic Hound ·menuPass ·Mofang ·Molerats ·Moonstone Sleet ·MoustachedBouncer ·MuddyWater ·Naikon ·OilRig ·Patchwork ·PLATINUM ·POLONIUM ·Putter Panda ·Rancor ·Sandworm Team ·Sidewinder ·Sowbug ·Star Blizzard ·Strider ·Threat Group-3390 ·ToddyCat ·Tonto Team ·Transparent Tribe ·Tropic Trooper ·Turla ·VOID MANTICORE ·Wizard Spider

Also on ThreatFilter: cross-source corroborated CVEs · threat group directory · every source we track