By industry

Government security news

All industries →

Thu, 3 Sept 2026

  1. Government, industry partner to shut down long-running Sality botnet

    A nonprofit group is now working to contact victims.

    Cybersecurity Dive
  2. Government lacks ability to verify AI labs’ claims, experts say

    A new survey of national security practitioners identified a wide range of near- and medium-term AI risks for policymakers to consider.

    Cybersecurity Dive
  3. Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

    Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. "The technique's appeal is that node.exe (the

    The Hacker News
  4. CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows - CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated

    CriticalUsed in attacksThe Hacker NewsSonicWall

Wed, 2 Sept 2026

  1. JFrog security advisory (AV26-867) – Update 1

    Serial number: AV26-867 Date: September 1, 2026 Updated: September 2, 2026 As of August 28, 2026, JFrog is affected by a vulnerability in the following product: Artifactory Prior to 7.111.21 Prior to 7.117.28 Prior to 7.125.20 Prior to 7.133.29 Prior to 7.146.38 Prior to 7.161.20 Open-source reporting indicates that CVE-2026-82329 related to JFrog Artifactory is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Update 1 On September 2, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-82329 to their Known Exploited Vulnerabilities (KEV) Database. Artifactory Self-Managed Releases JFrog Security Advisories CISA KEV: CVE-2026-82329

    CriticalUsed in attacksCanadian Centre for Cyber SecurityJFrog
  2. SonicWall security advisory (AV26-872) – Update 1

    Serial Number: AV26-872 Date: September 2, 2026 As of September 1, 2026, SonicWall is affected by a vulnerability in the following product: SMA1000 - 6210, 7210, 8200v 12.4.3-03453 (platform-hotfix) and older versions 12.5.0-02835 (platform-hotfix) and older versions SonicWall indicates that CVE-2026-83548 and CVE-2026-83549 are being exploited. Update 1 On September 2, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-83548 and CVE-2026-83549 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Advisory SonicWall Security Advisories CISA KEV: CVE-2026-83548 CISA KEV: CVE-2026-83549

    CriticalUsed in attacksCanadian Centre for Cyber SecuritySonicWall
  3. Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

    Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them

    The Hacker NewsGoogle
  4. Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons

    Gambling Goblin compromised Brazilian government sites to drive gambling traffic through SEO fraud

    Infosecurity Magazine
  5. Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

    A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting. Check Point Research said it has tracked the campaign since mid-2025. The modules

    The Hacker NewsApache
  6. Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

    Research by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berberoka, an actor first documented targeting gambling sites across Asia. Once inside a victim, the group deploys a broad Linux toolkit: a custom downloader, several backdoors,

    Check Point ResearchLinux

Latest government briefing

Government Cybersecurity Weekly Intelligence Brief — week ending 2026-09-14

40 stories affecting government tracked in the last seven days, 5 rated critical, 2 vulnerabilities added to the CISA Known Exploited catalogue.

About government news

136
Stories
51
In the last 7 days
5
Critical in the last 7 days