By industry
Government security news
Tue, 11 Aug 2026
- Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.
SecurelistGoogle
Fri, 7 Aug 2026
- Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
Overview On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077 , a critical unsafe deserialization vulnerability affecting JetBrains TeamCity . An attacker who can reach a TeamCity server over HTTP or HTTPS can exploit the agent polling protocol without credentials and execute operating system commands with the privileges of the TeamCity server process. JetBrains reported no known active exploitation when it disclosed the vulnerability. However, on August 5, 2026, CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities (KEV) catalog, confirming exploitation in the wild. Our analysis finds that a vulnerable TeamCity server creates a permissive XStream allowlist. This allowlist is intended to restrict which Java classes can be deserialized when servicing unauthenticated agent requests. However, this allowlist incorrectly adds TeamCity protocol classes without removing XStream's existing default permissions. This introduces an unsafe deserialization issue. A patched TeamCity server remediates this by adding NoTypePermission.NONE before the TeamCity allowlist, which removes the default permissions and makes the allowlist exclusive. Rapid7 Labs has verifi
CriticalUsed in attacksRapid7 BlogJetBrains
Thu, 30 Jul 2026
- NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Devices
The UK’s National Cyber Security Centre wants network device makers to improve forensic observability
Infosecurity Magazine
Wed, 29 Jul 2026
- NCSC Publishes Guidance to Aid Incident Response and Recovery
The National Cyber Security Centre has released a detailed framework to assist with incident response and recovery
Infosecurity Magazine
Thu, 23 Jul 2026
- Iranian Hackers Target Siemens and Schneider Industrial Systems, CISA Warns
US government agencies have warned that Iranian cyber actors are targeting US-based Siemens and Schneider industrial equipment
Infosecurity Magazine
Wed, 22 Jul 2026
Fri, 17 Jul 2026
- Government Agencies Falling Victim to Ransomware Daily, Warns Study
Government organizations are targeted by attackers who know agencies cannot afford disruption to public services
Infosecurity Magazine - CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities
US government agencies have until July 19 to patch two critical Fortinet vulnerabilities
Infosecurity MagazineFortinet
Wed, 15 Jul 2026
- Government Updates UK’s National Risk Register with Cyber Warnings
The UK government is warning of the potential impact of catastrophic cyber-attacks
Infosecurity Magazine
Tue, 14 Jul 2026
- US: Pentagon Suspends CMMC Phase II Requirements for Defense Contractors
The US Department of Defense announced the immediate suspension of the CMMC Phase II requirements until further review
Infosecurity Magazine
Latest government briefing
Government Cybersecurity Weekly Intelligence Brief — week ending 2026-09-14 →40 stories affecting government tracked in the last seven days, 5 rated critical, 2 vulnerabilities added to the CISA Known Exploited catalogue.
Named most often, last 90 days
About government news
- 135
- Stories
- 57
- In the last 7 days
- 7
- Critical in the last 7 days