Skip to main content
All Sectors

Government

ireland

Irish government departments and agencies

NIS2 Essential Entity

Compliance tags are AI-generated and should not be cited as regulatory evidence without independent review.

Total (30d)

41

Critical

3

High

18

Medium

14

41 threats in last 30 days( 42% vs prior period)
Top ATT&CK Techniques
T1190Exploit Public-Facing Application23x

Deploy WAF rules, patch public-facing apps within 48h of CVE disclosure, segment DMZ from internal networks, and run authenticated vulnerability scans weekly.

T1071Application Layer Protocol16x

Inspect TLS traffic at the proxy (break-and-inspect), deploy network IDS/IPS signatures for known C2 frameworks, and baseline normal DNS/HTTP patterns.

T1078Valid Accounts12x

Enforce MFA on all accounts, implement conditional access policies, audit privileged accounts quarterly, and monitor for impossible-travel logins.

T1566.001Spearphishing Attachment8x

Block macros in Office docs from the internet (ASR rules), detonate attachments in a sandbox before delivery, and strip active content from inbound email.

T1486Data Encrypted for Impact7x

Maintain offline/immutable backups tested monthly, enable ASR rules against ransomware, and deploy behavioural detection for mass file encryption patterns.

T1204User Execution6x

Block execution of downloaded files via Mark-of-the-Web + SmartScreen, train users on social engineering, and sandbox browser downloads.

T1059Command and Scripting Interpreter5x

Disable unused scripting interpreters, enforce PowerShell Constrained Language Mode, log all script block execution via ScriptBlockLogging.

T1566.003Phishing5x

Enforce DMARC (p=reject), SPF, and DKIM on all domains; block executable attachments at the mail gateway; conduct quarterly phishing simulations.

T1547Boot or Logon Autostart Execution5x

Monitor Run/RunOnce registry keys and startup folders for changes, restrict registry write permissions, and use application whitelisting to block unsigned autostart entries.

T1055Process Injection3x

Enable EDR memory-injection detection, enforce Credential Guard, restrict debug privileges (SeDebugPrivilege) to admin accounts only.

Compliance Exposure
NIS2-Art21-2b(69)NIS2-Art21-2e(30)DORA-Art17-23(23)NIS2-Art23(4)NIS2-Art21-2i(3)GDPR-Breach(2)NIS2-Art21-2k(2)NIS2-Art21-2g(2)NIS2-Art21-2c(2)DORA-Art5-16(1)
Technologies
SAPOracleMicrosoft 365SharePoint

Recent Intelligence

Untitled Security Alert

Multiple cybersecurity incidents have been reported, including the use of commercially available location data to track US troop locations and a phishing campaign targeting Signal message backups. Users are advised to exercise caution and implement robust security measures. Microsoft's response to zero-day disclosures has also been criticized.

3/6/2026Medium

Philippines Gov Joins HIBP

The Philippine government has partnered

3/6/2026Info

Anthropic Expands AI Model Access

Anthropic is expanding access to its Mythos-class AI models, including to governments, while

25/5/2026Medium

FBI Director's Site Hacked

The merchandise website of FBI director Kash Patel was taken offline after reports of a malware compromise. Users who visited the site may have been tricked into installing malware via a fake Cloudflare page. It is recommended that users who visited the

25/5/2026Medium

Ghostwriter A

The Ghostwriter APT group has launched a phishing campaign targeting Ukrainian government agencies, using a legitimate online learning platform as bait to deliver malware and Cobalt Strike payloads. Government employees who use the Prometheus learning platform are at risk. Users should exercise caution when receiving emails related to the platform.

23/5/2026High

Cybercrime VPN Shutdown

European authorities have dismantled

22/5/2026Info

CISA Data Leak Exposed

A CISA contractor has leaked sensitive agency data, including AWS GovCloud keys, on a public GitHub account. Lawmakers are demanding answers as CISA works to contain the breach and invalidate the leaked

22/5/2026High

Ukraine Gov Targets by Ghostwriter

Ghostwriter, a Belarus-aligned threat actor, has been targeting Ukrainian government entities with phishing emails using lures related to the Prometheus online learning platform. The emails aim to deliver malware to compromise government systems. Affected organizations should be cautious of suspicious emails and verify sender authenticity.

22/5/2026Medium

CISA Contractor Security Incident

A CISA contractor exposed credentials, potentially compromising security. The incident highlights the need for robust security measures to protect sensitive information. Users are advised to monitor for suspicious activity and update their security protocols.

22/5/2026Medium

CISA Leaks AWS GovCloud Keys

A contractor for the Cybersecurity and Infrastructure Security Agency (CISA) exposed credentials to highly privileged AWS GovCloud accounts and internal CISA systems on a public GitHub repository. The leak affects CISA's internal systems and potentially compromises national security. Users should monitor for potential malicious activity and update their security protocols.

22/5/2026Critical

EU Govts Hacked by China's Webworm

An advanced persistent threat group, known as China's Webworm, has been using Discord and Microsoft Graphs to hack into EU government systems. The attack affects multiple European government agencies, compromising sensitive information. Users are advised to monitor their systems for suspicious activity and update their security software.

22/5/2026High

US Cybersecurity Funding Criticized

The US Democratic Party has criticized the Trump administration for allocating insufficient funds to cybersecurity initiatives, while increasing spending on other areas. This underfunding may impact the security of government systems and citizens' data. Affected parties should monitor budget developments and advocate for increased cybersecurity funding.

21/5/2026Medium

Microsoft Patches Zero-Days

Microsoft has released patches for two zero-day vulnerabilities, UnDefend and RedSun Defender, which could be exploited to elevate privileges or create a denial-of-service condition. Users of affected systems are advised to apply the patches as soon as possible. The vulnerabilities could impact any Windows system that has not been updated.

21/5/2026High

AI-Powered App Attacks Rise

A recent report by Digital.ai warns that AI-powered attacks on mobile apps are becoming faster, more frequent, and harder to stop, affecting all industries. These attacks can occur within hours of an app's release, erasing the distinction between emerging and primary targets. Users and developers should be vigilant and take proactive measures to secure their apps.

20/5/2026High

Webworm APT Targets Europe

The Webworm APT group, also known as Space Pirates and UAT-8302, has expanded its operations to target government organizations in Europe, including those in Belgium, Italy, Poland, Serbia, and Spain. Organizations in these regions should be aware of the potential threat and take necessary precautions to protect themselves. The group's

20/5/2026Medium

Vulnerability Exploitation Tops DBIR

According to the 2026 Verizon Data Breach Investigations Report, vulnerability exploitation has become the most common initial access vector, surpassing stolen credentials. This shift affects organizations of all sizes and industries, emphasizing the need for robust vulnerability management. To mitigate this risk, prioritize vulnerability patching and implement a comprehensive security strategy.

20/5/2026High

Windows, Windows Server Vulnerabilities

Multiple vulnerabilities have been discovered in Microsoft Windows and Windows Server, allowing attackers to elevate privileges, execute arbitrary code, and conduct Denial of Service attacks. Users of these operating systems are advised

20/5/2026High

Windows BitLocker Bypass

A vulnerability in Windows BitLocker has been discovered, allowing attackers to bypass its security features. Users of Windows systems that utilize BitLocker for encryption are potentially affected. It is recommended to monitor for updates from

19/5/2026Medium

Untitled Security Alert

The 2026 Data Breach Investigations Report reveals that exploits are increasingly used in initial access for breaches, with patching efforts lagging behind. This trend affects enterprises, highlighting the need for timely vulnerability management. To mitigate risks, organizations should prioritize patching and vulnerability remediation.

19/5/2026High

US Cyber Agency Exposes Credentials

The US Cybersecurity and Infrastructure Security Agency (CISA) has inadvertently exposed sensitive credentials, including passwords and tokens, through an open GitHub repository. This incident affects CISA and potentially other organizations that may have accessed or used the exposed credentials. Users are advised to review their own security practices and ensure that sensitive information is properly secured.

19/5/2026Medium