✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviation/Aerospace
Breach intelligence, attack campaigns, and threat reports targeting the Aviation/Aerospace sector.
Explore Other Sectors
Aviation/Aerospace Threat Reports
Citrix NetScaler CVE-2025-7775: Critical Vulnerability Exploited in the Wild
On August 26, 2025, Citrix disclosed a critical vulnerability (CVE-2025-7775) in NetScaler ADC and NetScaler Gateway products, which was actively exploited in the wild. This memory overflow flaw allows unauthenticated remote code execution and denial of service attacks on unpatched devices. The vulnerability affects versions 14.1 before 14.1-47.48, 13.1 before 13.1-59.22, 13.1-FIPS/NDcPP before 13.1-37.241-FIPS/NDcPP, and 12.1-FIPS/NDcPP up to 12.1-55.330-FIPS/NDcPP. Citrix released security updates to address this issue and urged immediate patching due to the lack of available mitigations. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/citrix-fixes-critical-netscaler-rce-flaw-exploited-in-zero-day-attacks/amp/?utm_source=openai)) The active exploitation of CVE-2025-7775 underscores the persistent targeting of critical infrastructure by threat actors. Organizations relying on NetScaler products must prioritize patching to mitigate potential risks. This incident highlights the importance of timely vulnerability management and the need for robust security practices to defend against evolving cyber threats.
2 days ago
Kill Chain
Critical Vulnerability in NASA's cFS Health & Safety Application: CVE-2026-18064
In July 2026, a critical vulnerability (CVE-2026-18064) was identified in NASA's Core Flight System (cFS) Health & Safety (HS) Application versions up to 7.0.1. This flaw, stemming from an incomplete fix for a previous issue (CVE-2026-15352), allows attackers to trigger a NULL pointer dereference, leading to application crashes and potential denial-of-service conditions. The vulnerability affects systems worldwide, given cFS's deployment across various space missions. ([vulners.com](https://vulners.com/ics/ICSA-26-197-03?utm_source=openai)) This incident underscores the challenges in fully remediating software vulnerabilities and highlights the importance of thorough testing and validation processes. Organizations relying on cFS should prioritize updating to the latest software versions and implement robust monitoring to detect and mitigate potential exploitation attempts.
1 week ago
Kill Chain
Russian Hackers Exploit Exchange OWA Zero-Day (CVE-2026-42897)
In May 2026, the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, exploited a zero-day vulnerability (CVE-2026-42897) in Microsoft Exchange's Outlook Web Access (OWA). This cross-site scripting (XSS) flaw allowed attackers to execute arbitrary JavaScript in users' browsers by sending specially crafted emails. Upon opening these emails in OWA, the embedded malicious code executed, leading to the deployment of a sophisticated backdoor named OWAReaper. This malware enabled long-term access to victims' mailboxes, even after system restorations or credential changes. The campaign targeted various organizations, including government entities in the U.S. and Europe, as well as companies in the telecommunications, financial, hospitality, and aerospace sectors. The incident underscores the evolving tactics of state-sponsored threat actors and the critical need for organizations to promptly apply security patches and enhance email security measures. The exploitation of webmail platforms through XSS vulnerabilities highlights the importance of comprehensive security strategies to protect against sophisticated cyber espionage campaigns.
1 week ago
Kill Chain
Russian Hackers Exploit Microsoft OWA Vulnerability CVE-2026-42897
In July 2026, Russian state-sponsored threat actors, identified as Laundry Bear (also known as TA488 or Void Blizzard), exploited a cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA), designated as CVE-2026-42897. This flaw allowed attackers to execute arbitrary JavaScript code when a user opened a specially crafted email in OWA, leading to unauthorized access and data exfiltration. The campaign targeted U.S. and European government entities, as well as sectors including telecommunications, financial services, hospitality, and aerospace. This incident underscores a concerning trend of sophisticated, state-sponsored cyber attacks leveraging zero-day vulnerabilities to gain persistent access to critical systems. The rapid exploitation of such flaws highlights the urgent need for organizations to implement robust patch management processes and enhance their cybersecurity defenses to mitigate evolving threats.
1 week ago
Kill Chain
Mirage Kitten's New Malware Targets Middle East and Africa
In July 2026, the advanced persistent threat group Mirage Kitten, also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, launched a cyber-espionage campaign targeting aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa. Utilizing highly targeted spear-phishing campaigns and fake recruitment portals, they deployed a previously undocumented malware set, including the NightLedger backdoor and two WebSocket-based tunnelers, ArcBridge and BridgeHead, to gain persistent access and exfiltrate sensitive data. ([securelist.com](https://securelist.com/mirage-kitten-new-tools/120811/?utm_source=openai)) This incident underscores the evolving sophistication of APT groups in developing custom malware to infiltrate critical sectors. Organizations must enhance their cybersecurity measures to detect and mitigate such advanced threats, emphasizing the importance of proactive defense strategies in the face of persistent cyber-espionage activities.
1 week ago
Kill Chain
CubePilot's DNS Hijacking Incident: A Wake-Up Call for Cybersecurity
In July 2026, CubePilot, an Australian drone software developer, experienced a significant operational disruption due to a DNS hijacking attack. On July 24, attackers gained control over the DNS settings of cubepilot.org, redirecting user traffic to malicious servers. They also obtained TLS certificates for all subdomains, enabling them to intercept sensitive data, including user credentials entered on CubePilot's services. The company promptly regained control, revoked the fraudulent certificates, and initiated an investigation, advising users to change passwords if reused elsewhere. This incident underscores the escalating threat of DNS hijacking attacks targeting critical infrastructure and technology providers. Organizations must enhance their DNS security measures and monitor for unauthorized changes to prevent similar breaches.
1 week ago
Kill Chain
Clop Ransomware Exploits Critical Vulnerability in PTC Windchill and FlexPLM
In July 2026, the Clop ransomware group exploited a critical vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM systems, leading to unauthorized remote code execution. This flaw allowed attackers to deploy JSP webshells, facilitating the exfiltration of sensitive product data from compromised organizations. The exploitation of this vulnerability underscores the persistent threat posed by ransomware groups targeting critical infrastructure and intellectual property. Organizations utilizing PTC's Windchill and FlexPLM platforms are urged to apply the latest security patches and implement robust monitoring to detect and prevent such intrusions.
2 weeks ago
Kill Chain
Clop Ransomware's Exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM
In July 2026, the Clop ransomware group exploited a critical vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM systems, leading to unauthorized access and data exfiltration. This vulnerability, stemming from improper input validation, allowed attackers to execute arbitrary code remotely, compromising sensitive product lifecycle management data. The exploitation involved deploying JSP webshells to facilitate data theft, significantly impacting organizations relying on these platforms for managing product data and processes. This incident underscores the escalating trend of ransomware groups targeting enterprise applications with known vulnerabilities. The active exploitation of CVE-2026-12569 highlights the urgent need for organizations to promptly apply security patches and implement robust monitoring to detect unauthorized access, as threat actors continue to evolve their tactics to exploit critical infrastructure vulnerabilities.
2 weeks ago
Kill Chain
Critical Vulnerability in NASA's cFS Health & Safety Application: CVE-2026-15352
In July 2026, a critical vulnerability (CVE-2026-15352) was identified in NASA's Core Flight System (cFS) Health & Safety (HS) Application. This flaw allows attackers to trigger a segmentation fault by sending a routine Housekeeping Telemetry request, leading to a denial-of-service condition. The vulnerability affects versions of the HS application prior to v7.0.1. NASA has released an update to address this issue and recommends users upgrade to v7.0.1 to mitigate the risk. ([software.nasa.gov](https://software.nasa.gov/software/GSC-18476-1?utm_source=openai)) This incident underscores the importance of timely software updates in mission-critical systems. As space exploration technologies become increasingly reliant on software, ensuring the security and reliability of these systems is paramount to prevent potential disruptions and maintain operational integrity.
3 weeks ago
Kill Chain
Critical Vulnerabilities in 6 GHz Wi-Fi AFC Systems Uncovered
In July 2026, researchers from Pennsylvania State University and Idaho National Laboratory identified significant security vulnerabilities in Automated Frequency Coordination (AFC) systems, which manage the 6 GHz Wi-Fi spectrum to prevent interference with critical infrastructure. The study revealed that AFC systems inherently trust client-side data, such as GPS coordinates and time synchronization inputs, without adequate verification. This trust model exposes the systems to potential attacks where adversaries could spoof location data or manipulate time synchronization, leading to unauthorized spectrum access, harmful interference with incumbent services, or denial-of-service conditions for legitimate 6 GHz Wi-Fi users. ([darkreading.com](https://www.darkreading.com/perimeter/6-ghz-wi-fi-flaws-disrupt-critical-systems?utm_source=openai)) The findings underscore the urgent need for enhanced security measures in AFC systems, especially as the adoption of 6 GHz Wi-Fi expands. Without addressing these vulnerabilities, critical communication infrastructures remain at risk of disruption, highlighting the importance of implementing robust authentication and validation mechanisms within AFC architectures to safeguard against potential exploits.
3 weeks ago
Kill Chain
Critical Vulnerabilities in Labcenter Proteus 9 Threaten Infrastructure Security
In July 2026, multiple high-severity vulnerabilities were identified in Labcenter Proteus 9.1 SP4 Build 42914, including CVE-2026-42953 (out-of-bounds write), CVE-2026-49033 (stack-based buffer overflow), and CVE-2026-42958 (use-after-free). Exploitation of these vulnerabilities could allow attackers to execute arbitrary code, potentially compromising critical infrastructure sectors such as communications, healthcare, and energy. ([socdefenders.ai](https://www.socdefenders.ai/item/4909df73-d6e4-4d7f-ad22-28b3fb4d7bdc?utm_source=openai)) This incident underscores the persistent risks associated with software vulnerabilities in critical systems. Organizations must prioritize timely patching and robust security measures to mitigate potential threats. ([socdefenders.ai](https://www.socdefenders.ai/item/4909df73-d6e4-4d7f-ad22-28b3fb4d7bdc?utm_source=openai))
1 month ago
Kill Chain
Critical Vulnerability in CubeSpace CW0057 Reaction Wheel Firmware
In July 2026, CubeSpace disclosed a vulnerability (CVE-2026-13743) in its CW0057 Reaction Wheel firmware versions prior to 5.0.20. This flaw allows attackers with physical access to upload malicious firmware without authentication, potentially compromising satellite operations. The issue stems from the device's reliance on CRC-32 integrity checks, which verify data integrity but not the authenticity of the firmware source. CubeSpace has released firmware version 5.0.20, introducing cryptographically verified secure boot, though this feature is not enabled by default and requires user activation. This incident underscores the critical importance of robust firmware authentication mechanisms in aerospace components. As satellites become increasingly integral to global communications and defense, ensuring the integrity of onboard systems is paramount. Organizations must proactively implement and enable security features to mitigate risks associated with unauthorized firmware modifications.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports