NEW: Group Profiler — instant APT intel lookup. Try it →

Government — threat intelligence

Recent advisories whose title or summary heuristically matches the Government sector. Derived in-browser/at-edge from a keyword catalog — treat tags as a hint and open each source for ground truth. Counts and contents update hourly.

48 recent Government advisories

  1. INFO cisa-alerts · 1d ago

    Preparing for the Post-Quantum Era: A Call to Action

    CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (…

    check-point US
  2. INFO thehackernews · 1d ago

    Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

    Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been pu…

    symantec
  3. INFO thehackernews · 1d ago

    Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

    Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Progra…

    google
  4. INFO thehackernews · 2d ago

    Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

    A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to a…

    apache BR
  5. INFO checkpoint · 2d ago

    Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

    Research by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berbero…

    check-pointlinux-kernel BR
  6. MEDIUM thehackernews · 2d ago

    GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

    Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in ve…

  7. INFO the-record · 4d ago

    Berlin says it won’t pay ransom after hackers steal government data

    Governing Mayor Kai Wegner said on Friday that Berlin had received an extortion demand following the cyberattack, which was discovered in mid-August.

    DE
  8. INFO securityweek · 4d ago

    Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’

    The ruling is part of Anthropic's legal battle against the Pentagon after the government labeled the company as a supply chain risk earlier this year. The post Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’ app…

  9. INFO thehackernews · 6d ago

    Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

    Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement discl…

    DE
  10. INFO thehackernews · 7d ago

    APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

    Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt G…

    microsoft-windowsrecorded-future ROESTR
  11. INFO darkreading · 8d ago

    Russian Hackers Phish EU Officials Over Messaging Apps

    EU governments are trying to move away from popular messaging apps as nation-state threat groups shift their focus from email to Signal and WhatsApp.

    EU
  12. INFO thehackernews · 8d ago

    Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

    Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. "The samples employ diverse lure themes, suggesting an effort to appeal to a br…

    acronis KH
  13. INFO securityweek · 8d ago

    US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

    The operation focused on a group named QTFY, which offers hacking services to the Chinese government and others. The post US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks appeared first on SecurityWe…

    US
  14. CRITICAL EXPLOITED securityweek · 8d ago

    Recent Citrix NetScaler Vulnerability Exploited in the Wild

    CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452. The post Recent Citrix NetScaler Vulnerability Exploited in the Wild appeared first on SecurityWeek.

    citrix US
  15. INFO the-record · 9d ago

    US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate

    The DOJ said it disrupted Chinese state-backed tools used to scan, infect and exploit IoT devices for attacks on federal agencies and multiple industries.

    US
  16. INFO thehackernews · 9d ago

    U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

    The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economi…

    IR
  17. INFO the-record · 10d ago

    UK government seeks powers to secretly block risky tech suppliers

    The British government is seeking new powers to ban certain technology vendors from supplying companies working in the country’s critical sectors — potentially doing so in secret.

    GB
  18. INFO thehackernews · 11d ago

    Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

    Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to ta…

    cisco-network MM
  19. INFO securityweek · 14d ago

    Former NSA Director Paul Nakasone Launches National Security Advisory Firm

    The newly-formed Nakasone Group will counsel government leaders, corporations, prominent families, and other private clients confronting cybersecurity, geopolitical, and personal security risks. The post Former NSA Director Paul Nakasone La…

    US
  20. INFO darkreading · 14d ago

    Calling on Cyber Pros to Help Defend City Hall

    Government agencies with smaller budgets need support — and here's how you can help.

  21. INFO darkreading · 14d ago

    Calling on Cyber Pros to Help Defend City Hall

    Government agencies with smaller budgets need support — and here's how you can help.

  22. INFO thehackernews · 14d ago

    Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

    Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe,…

    google US
  23. INFO the-record · 14d ago

    China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware

    Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.

    KGKZTJ
  24. INFO darkreading · 14d ago

    What We Missed: Delta Flight Disrupted With Wi-Fi Hack

    In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy.

    US
  25. INFO talos-intel · 14d ago

    Is Cyber missing the Marque?

    In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber op…

  26. INFO EXPLOITED thehackernews · 14d ago

    AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

    The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammab…

    siemens US
  27. INFO EXPLOITED tenable-advisories · 15d ago

    Frequently asked questions about the active threat to Siemens S7 Series PLCs

    A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors.Key TakeawaysU…

    siemens
  28. INFO mandiant-blog · 15d ago

    Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

    Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in…

    US
  29. INFO cisa-news · 15d ago

    CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational Standards

    US
  30. INFO thehackernews · 15d ago

    Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

    A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurren…

    android UARUEU
  31. INFO darkreading · 15d ago

    Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks

    A nation-state threat actor is picking on immature organizations run by the Taliban, but failing against more prepared government agencies in India.

    AFIN
  32. INFO the-record · 15d ago

    NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology

    The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities.

    siemens US
  33. INFO thehackernews · 16d ago

    SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

    A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previ…

    KGKZTJ
  34. INFO the-record · 16d ago

    US charges Iranians for sprawling hacking campaign on government agencies, universities

    The Justice Department accused 17 alleged hackers with ties to the Iranian government of breaching email accounts at U.S. government agencies and stealing intellectual property from dozens of universities.

    US
  35. INFO darkreading · 16d ago

    China-Linked Hacker Shows AI Capabilities in APAC Attack

    In the first purported "near-autonomous" attack on a nation-state, a Chinese-language operator used a complex AI framework to target and compromise government agencies, likely in Taiwan.

    TW
  36. INFO the-record · 16d ago

    Berlin cuts two state ministries off government network after security breach

    The affected ministries — one responsible for urban development, construction and housing, and the other for mobility, transport, climate protection and the environment — have been isolated from government networks since Friday as a precaut…

    DE
  37. INFO EXPLOITED checkpoint · 18d ago

    17th August – Threat Intelligence Report

    For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of it…

    check-point CO
  38. INFO tenable-advisories · 20d ago

    The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

    Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive…

    tenable TW
  39. INFO darkreading · 21d ago

    Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office

    One Caledonian government agency reported a breach, thanks to a third party that may have serviced other agencies as well.

    GB
  40. INFO securityweek · 21d ago

    In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

    Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disruption. The post In Other News: Rapid7 Layo…

    KR
  41. INFO thehackernews · 21d ago

    China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud

    The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. "Both missions are administered from a si…

  42. INFO thehackernews · 22d ago

    North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring

    Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems companies …

    USKR
  43. INFO schneier · 22d ago

    Separating AI’s Technological Problems from Its Capitalism Problems

    This essay was written with Nathan E. Sanders, and originally appeared in Tech Policy Press. AI represents the first time we humans can do cognitive work outside of our bodies at scale. The only comparable moment is the early years of the i…

    check-point
  44. INFO EXPLOITED darkreading · 23d ago

    Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition

    Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.

    CO
  45. INFO EXPLOITED the-record · 23d ago

    CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign

    Researchers disclosed the bug to Microsoft after examining a long-running campaign by North Korean hackers to exploit the job application process.

    microsoft USKR
  46. INFO the-record · 24d ago

    Local governments in four states dealing with cyberattacks that have shut down services

    Municipalities in California, Oklahoma, Wisconsin and Texas are all recovering from disruptive cyberattacks that have affected government operations.

    US
  47. INFO EXPLOITED thehackernews · 24d ago

    Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

    Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public he…

    fortinetschneider-electric KR
  48. INFO EXPLOITED the-record · 24d ago

    FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure

    The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.

    KRUS

Other sectors: Healthcare ·Finance ·Energy ·Critical Infra ·Education ·Technology ·Telecom ·Defense ·Retail ·Transportation ·Legal Services

Also on ThreatFilter: cross-source corroborated CVEs · threat group directory · every source we track