By industry

Government security news

All industries →

Tue, 11 Aug 2026

  1. Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection

    Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.

    SecurelistGoogle

Fri, 7 Aug 2026

  1. Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)

    Overview On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077 , a critical unsafe deserialization vulnerability affecting JetBrains TeamCity . An attacker who can reach a TeamCity server over HTTP or HTTPS can exploit the agent polling protocol without credentials and execute operating system commands with the privileges of the TeamCity server process. JetBrains reported no known active exploitation when it disclosed the vulnerability. However, on August 5, 2026, CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities (KEV) catalog, confirming exploitation in the wild. Our analysis finds that a vulnerable TeamCity server creates a permissive XStream allowlist. This allowlist is intended to restrict which Java classes can be deserialized when servicing unauthenticated agent requests. However, this allowlist incorrectly adds TeamCity protocol classes without removing XStream's existing default permissions. This introduces an unsafe deserialization issue. A patched TeamCity server remediates this by adding NoTypePermission.NONE before the TeamCity allowlist, which removes the default permissions and makes the allowlist exclusive. Rapid7 Labs has verifi

    CriticalUsed in attacksRapid7 BlogJetBrains

Thu, 30 Jul 2026

  1. NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Devices

    The UK’s National Cyber Security Centre wants network device makers to improve forensic observability

    Infosecurity Magazine

Wed, 29 Jul 2026

  1. NCSC Publishes Guidance to Aid Incident Response and Recovery

    The National Cyber Security Centre has released a detailed framework to assist with incident response and recovery

    Infosecurity Magazine

Thu, 23 Jul 2026

  1. Iranian Hackers Target Siemens and Schneider Industrial Systems, CISA Warns

    US government agencies have warned that Iranian cyber actors are targeting US-based Siemens and Schneider industrial equipment

    Infosecurity Magazine

Wed, 22 Jul 2026

Fri, 17 Jul 2026

  1. Government Agencies Falling Victim to Ransomware Daily, Warns Study

    Government organizations are targeted by attackers who know agencies cannot afford disruption to public services

    Infosecurity Magazine
  2. CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities

    US government agencies have until July 19 to patch two critical Fortinet vulnerabilities

    Infosecurity MagazineFortinet

Wed, 15 Jul 2026

  1. Government Updates UK’s National Risk Register with Cyber Warnings

    The UK government is warning of the potential impact of catastrophic cyber-attacks

    Infosecurity Magazine

Tue, 14 Jul 2026

  1. US: Pentagon Suspends CMMC Phase II Requirements for Defense Contractors

    The US Department of Defense announced the immediate suspension of the CMMC Phase II requirements until further review

    Infosecurity Magazine

Latest government briefing

Government Cybersecurity Weekly Intelligence Brief — week ending 2026-09-14

40 stories affecting government tracked in the last seven days, 5 rated critical, 2 vulnerabilities added to the CISA Known Exploited catalogue.

About government news

135
Stories
57
In the last 7 days
7
Critical in the last 7 days