Sunday , August 2 2026
.gov

.Gov Domains Weaponized in Phishing Surge

A recent report from Cofense Intelligence highlights a concerning trend: threat actors are increasingly misusing .gov top-level domains (TLDs) to execute phishing campaigns. Between November 2022 and November 2024, attackers have leveraged vulnerabilities in government websites from various countries to host malicious content, act as command-and-control (C2) servers, and funnel users to credential phishing sites.

Source: cofense.com

Attackers are exploiting trust in .gov domains by using open redirect vulnerabilities, especially through CVE-2024-25608 in the Liferay digital experience platform. This allows them to evade secure email gateways and lure victims into clicking malicious links.

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
CISA alerts to cyberattacks affecting U.S. water utilities

“CyberStrike” AI-Driven Security Platform for Automated Testing

A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
“CyberStrike” AI-Driven Security Platform for Automated Testing

AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

Attackers often exploit open redirect vulnerabilities, where a web application allows users to input a URL for redirecting them to an external site. The Cofense report states: “Threat actors regularly take advantage of open redirects such as Google AMP and TikTok to bypass secure email gateways (SEGs), and .gov domains are similarly abused.”

Source: cofense.com

Threat actors use .gov URLs in phishing emails to exploit trust in government domains, tricking users into clicking links that lead to fake Microsoft login pages for credential theft.

“The campaigns abusing United States-based .gov domains for open redirects were all Microsoft-themed with the credential phishing page typically including Microsoft logos and indicators.”

U.S. government .gov domains made up only 9% of abused domains but were still the third most exploited globally. All instances of abuse involved open redirects. The report notes that: “Over 77% of the open redirects used made use of ‘noSuchEntryRedirect,’ making it likely that the United States-based government websites also fell prey to CVE-2024-25608.”

Source: cofense.com

Brazil’s .gov.br domains were the most targeted globally, exceeding the combined totals of the next three countries. However, the report indicates this may be due to a few specific domains being targeted repeatedly, rather than all Brazilian government websites facing widespread attack.

The ability of .gov domains to bypass security email gateways is concerning. Major email security solutions like Microsoft ATP, Proofpoint, Cisco IronPort, Symantec MessageLabs, and Mimecast failed to filter phishing emails that misuse government open redirects.. “This is a good indicator of how successful .gov domains are at bypassing SEGs.”

Attackers often create phishing emails that appear to be about document signing or legitimate business requests. Many users trust government websites and fail to check the full URL, making them easy victims of redirection-based phishing.

Cofense Intelligence found that, in addition to phishing, some .gov domains were abused by cybercriminals using compromised government email addresses as command and control servers for malware. In mid-2023 and early 2024, these emails were used for Agent Tesla Keylogger and StormKitty malware.

The report indicates that only two government email addresses were exploited, showing that while email security in government is generally strong, it is not completely safe from attacks.

Emerging Phishing Threat in Bangladesh’s Cyber Space

Check Also

Windows LegacyHive 0, AWS, Fortinet, TP-LINK multiple flaws got hackers attention

A Windows security flaw called LegacyHive (MSNightmare) misuses the User Profile Service. This allows local …