For MSSPs
Scale threat-led services across your customers
For Internal SOCs
Run threat-led operations in your own environment
Integrations
Connect Sol to your security stack
Blog
Latest articles and insights
About Us
Meet the people and purpose behind Elezar
Account
Login
Create Account
Support
Help Centre
Legal
Terms & Conditions
Privacy Policy
The Americas Government, Public Administration and Defense sector faced a convergence of broad-surface exploitation, event-driven targeting and destructive activity in June 2026. The FIFA World Cup across the United States, Canada and Mexico created a shared attack surface across transport, telecommunications, energy and public services. ShinyHunters exploited Oracle PeopleSoft CVE-2026-35273 against government-deployed systems, while Operation Endgame revealed extensive SocGholish reach into government networks. Iranian-linked Ababil of Minab activity added a destructive wiper dimension against US transportation infrastructure.
Recommendations are calibrated for government identity systems, public-service platforms, defense-adjacent networks, cloud services, remote-access infrastructure and high-impact operational continuity requirements.
EMEA Government, Public Administration and Defense faced a multi-vector espionage environment in June 2026. Operation Dragon Weave directly targeted Czech government personnel with RUSTCLOAK and the Azure-resident AZUREVEIL implant. UNC5221 remained relevant through BRICKSTORM operations against European industry and government-adjacent environments, while a regional infrastructure study identified 3,923 malicious C2 servers across Eastern Europe. The wider reporting corpus rose from 164 to 455 reports, a 177 percent increase from May.
APAC Government, Public Administration and Defense organizations faced sustained espionage activity in June 2026. Reporting identified three concurrent nation-state campaigns: APT32's domestic targeting pivot through the FireAnt MetaKit supply chain, APT37's NarwhalRAT operation against South Korean personnel, and CL-STA-1062's TinyRCT campaign against Southeast Asian government and state-owned networks. Amaranth-Dragon also weaponized CVE-2025-8088 against Indonesian government and law-enforcement targets. Total reporting rose from 164 reports in May to 455 in June, a 177 percent increase across the wider corpus.