✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Aviation/Aerospace
Breach intelligence, attack campaigns, and threat reports targeting the Aviation/Aerospace sector.
Explore Other Sectors
Aviation/Aerospace Threat Reports
Critical Buffer Overflow Flaws in Ashlar-Vellum Software Threaten Industrial Security
In November 2025, Ashlar-Vellum disclosed two critical software vulnerabilities—an Out-of-Bounds Write (CVE-2025-65084) and a Heap-based Buffer Overflow (CVE-2025-65085)—impacting its Cobalt, Xenon, Argon, Lithium, and Cobalt Share products (version 12.6.1204.207 and prior). Identified by security researcher Michael Heinzl and published via CISA, these flaws could allow local attackers to gain information disclosure or execute arbitrary code on affected engineering systems, primarily used in the Critical Manufacturing sector worldwide. The vulnerabilities are rated high (CVSS v4 score 8.4), but no exploitation has been reported to date. This incident reinforces the urgent need for robust vulnerability management and regular software patching within industrial control environments. Manufacturers and operators face increasing regulatory and operational pressure to proactively address new threats in their digital supply chains and critical OT infrastructure.
6 months ago
Kill Chain
Rockwell Automation Arena Simulation Buffer Overflow (2025): Risks to Industrial Control Systems
In November 2025, Rockwell Automation disclosed a stack-based buffer overflow vulnerability (CVE-2025-11918) in its Arena Simulation software (versions 16.20.10 and earlier). The flaw, reported by security researcher Michael Heinzl, enables local attackers to execute arbitrary code by tricking users into opening a malicious DOE file. While the vulnerability is not exploitable remotely, it presents a significant risk to organizations leveraging Arena for critical manufacturing automation, especially when adequate segmentation and endpoint security controls are lacking. No public exploitation has been reported to date, and the vendor has released a security update to address the issue. This incident is a reminder of the persistence of file parsing vulnerabilities in industrial software, which continue to enable initial compromise via local vectors like engineered files or insider threats. The increase in similar vulnerabilities and the possibility of operational technology (OT) system breaches intensify the call for zero-trust and defense-in-depth strategies within the manufacturing sector.
6 months ago
Kill Chain
Iran-Nexus UNC1549 Targets Aerospace: 2024 Cyberattack Details
In early 2024, the Iranian-aligned threat actor group identified as UNC1549 orchestrated targeted cyberattacks against aerospace and defense organizations across the US, Israel, UAE, Qatar, Spain, and Saudi Arabia. Researchers discovered that the group leveraged sophisticated spear-phishing campaigns and custom malware implants to infiltrate sensitive networks, focusing primarily on exfiltrating confidential intellectual property and operational data. The campaign showcased advanced persistence techniques and bypassed standard security controls, leading to operational disruption and heightened espionage risk for impacted organizations. These attacks highlight a broader trend of nation-state threat actors increasingly focusing on strategic sectors with evolving tools and tactics. The targeting of multiple geographies underscores the global nature of aerospace security risks and pressing regulatory and compliance expectations.
6 months ago
Kill Chain
Iranian Espionage Campaign Uses DEEPROOT & TWOSTROKE in Aerospace and Defense Breach (2025)
In late 2025, an Iranian-linked threat group known as UNC1549 targeted aerospace and defense organizations in the Middle East, deploying custom backdoors named TWOSTROKE and DEEPROOT. The attackers gained access through spear-phishing and strategic web compromises, establishing persistent footholds and enabling sustained espionage operations. Google-owned Mandiant attributed the campaign to advanced initial access and lateral movement techniques, allowing the threat actors to blend into legitimate network activity while exfiltrating sensitive intellectual property and operational data. The campaign underscored weaknesses in internal segmentation, encrypted traffic oversight, and anomaly detection within high-value verticals. This incident highlights an uptick in sophisticated espionage attacks on critical infrastructure using tailored malware and stealthy, post-compromise tactics. The use of novel backdoors and multi-stage intrusion campaigns demonstrates an evolving threat landscape, emphasizing the need for deeper defense in depth and zero trust approaches among organizations handling sensitive data.
6 months ago
Kill Chain
Siemens Solid Edge 2025: Improper Certificate Validation Exposes Critical Manufacturing to MITM Attacks
In November 2025, Siemens disclosed a critical vulnerability in its Solid Edge SE2025 product, identified as CVE-2025-40744. This software flaw, stemming from improper certificate validation in the License Service endpoint, allows unauthenticated remote attackers to perform man-in-the-middle (MITM) attacks by intercepting or manipulating encrypted traffic. The issue, rated 8.7 (CVSS v4), affects all versions of Solid Edge SE2025 prior to V225.0 Update 11, putting global critical manufacturing environments at risk of credential interception and data exposure. This incident reflects increasing attacker focus on exploiting certificate validation weaknesses in supply chain and industrial environments. With industrial control systems often at the core of large enterprises' operations, such vulnerabilities demand swift patching and ongoing vigilance in authentication and encrypted traffic controls.
6 months ago
Kill Chain
Siemens 2025: Critical DLL Hijacking Flaw Exposes Manufacturing Software
In November 2025, Siemens disclosed a vulnerability (CVE-2025-40827) in its Software Center and Solid Edge products, affecting versions prior to 3.5 and V225.0 Update 10, respectively. The flaw, rooted in uncontrolled search path element (CWE-427), allows local attackers to execute arbitrary code via DLL hijacking—placing crafted DLLs on vulnerable systems. Although exploitation requires local access and some user interaction, compromise could lead to full system takeover in manufacturing environments globally. Siemens responded by advising immediate updates and enhanced network protections. This incident underscores the ongoing risks posed by software supply chain vulnerabilities and underscores the importance of timely patching in industrial environments. It highlights how attackers continue targeting widely deployed engineering software with low-complexity, high-impact exploits, especially as operational technology environments see increased convergence with IT infrastructures.
6 months ago
Kill Chain
Global Airports at Risk: Radiometrics VizAir 2025 Unauthenticated Access Exposes Critical Infrastructure
In November 2025, critical vulnerabilities were publicly disclosed in Radiometrics VizAir, a system widely deployed in global airport transportation infrastructure. The flaws (CVE-2025-61945, CVE-2025-54863, CVE-2025-61956) permit unauthenticated remote attackers to manipulate weather parameters, runway settings, and extract sensitive meteorological data via missing authentication controls and exposed credentials. Exploitation could disrupt airport operations, mislead air traffic control and pilots, and create hazardous flight conditions by disabling vital alerts or injecting false data. The vulnerabilities were reported by a security researcher and were assigned the highest CVSS score of 10.0, reflecting severe risk to operational safety. This incident highlights the escalating risk facing critical infrastructure as attackers increasingly target operational technology systems with low-complexity, high-impact exploits. Given the global reliance on secure flight operations, the breach underscores the urgency for robust authentication, segmentation, and credential management controls across transportation-critical systems.
6 months ago
Kill Chain
Lazarus Breaches UAV Sector: 2024 Cyberespionage Attack Analysis
In early 2024, ESET researchers uncovered a targeted cyberespionage campaign orchestrated by the North Korea-aligned Lazarus Group against a prominent company in the Unmanned Aerial Vehicle (UAV) sector. The attackers leveraged the Operation DreamJob social engineering scheme, luring victims with fake job offers and delivering custom malware through malicious attachments. Once inside, Lazarus gained remote access, exfiltrated sensitive data, and attempted to move laterally across the compromised network, emphasizing the group's advanced targeting of critical aerospace technologies. This incursion exposed operational blueprints, intellectual property, and potentially sensitive communications, raising industry-wide alarm about advanced persistent threats targeting high-value sectors. This incident is especially relevant today due to increased targeting of defense and aerospace industries by state-sponsored actors using sophisticated social engineering paired with malware. The techniques seen in Operation DreamJob reflect a broader trend of highly-customized attacks utilizing credible lures and persistent denial detection tactics.
6 months ago
Kill Chain
Siemens 2025: Type Confusion RCE Threatens HyperLynx & Industrial Edge Security
In October 2025, Siemens disclosed a critical vulnerability (CVE-2025-6554) affecting HyperLynx and Industrial Edge App Publisher products. The flaw, rooted in type confusion within the V8 JavaScript engine (Google Chrome), enables remote attackers to execute arbitrary code via malicious HTML, particularly impacting vulnerable product versions used in worldwide critical manufacturing environments. For HyperLynx, exploitation requires local access, while Industrial Edge App Publisher is exploitable remotely with low complexity, posing a substantial risk to integrity and confidentiality. Siemens and CISA jointly advised immediate updates and best-practice mitigations. This incident highlights a growing trend of supply chain and third-party component vulnerabilities impacting industrial control systems, particularly as attackers increasingly target embedded web technologies. The Siemens disclosure underlines ongoing regulatory and operational pressure to address software dependencies and enforce proactive patch management in critical infrastructure.
6 months ago
Kill Chain
CISA Flags DELMIA Apriso Vulnerabilities: Urgent Action for Manufacturers
In October 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities affecting Dassault Systèmes DELMIA Apriso (CVE-2025-6204 and CVE-2025-6205) to its Known Exploited Vulnerabilities (KEV) Catalog following confirmed evidence of active exploitation in the wild. The code injection and missing authorization flaws present serious security bypass opportunities, allowing malicious actors to achieve unauthorized access and potentially execute arbitrary code. These weaknesses have become high-value targets for cyber attackers, potentially threatening sensitive enterprise manufacturing and operational data integrity across organizations that have yet to apply available patches. This incident underscores the growing trend of rapid exploitation of industrial software vulnerabilities by sophisticated threat actors. With regulatory frameworks such as BOD 22-01 placing increasing responsibility on federal agencies to remediate such vulnerabilities quickly, all organizations must adapt their patch management and risk processes to respond to elevated attacker velocity.
6 months ago
Kill Chain
CISA Alert: Active Exploits Target Dassault DELMIA Apriso and XWiki in 2025
In October 2025, cybersecurity authorities including CISA confirmed active exploitation of critical vulnerabilities in Dassault Systèmes DELMIA Apriso and XWiki platforms. Threat actors leveraged flaws such as CVE-2025-6204—an 8.0 CVSS code injection bug—to gain unauthorized access and potential code execution on affected systems. The attackers exploited unpatched systems to facilitate lateral movement, data exfiltration, and possible disruption of manufacturing and enterprise workflows. Affected organizations faced immediate operational risk and the prospect of sensitive information compromise. This incident highlights a growing trend in rapid exploitation of recently disclosed enterprise software vulnerabilities. With increased attacker focus on supply chain and collaborative platforms, organizations must respond swiftly to new advisories and prioritize vulnerability management programs to reduce exposure to high-severity threats.
6 months ago
Kill Chain
Active Exploitation of Dassault DELMIA Apriso Vulnerabilities Impacts Manufacturing Sector
In June 2024, CISA issued an alert highlighting active exploitation of two vulnerabilities (CVE-2024-22120 and CVE-2024-22121) within Dassault Systèmes’ DELMIA Apriso platform, a widely used manufacturing operations management solution. The flaws, found in DELMIA Apriso Release 2017 to 2023, allow unauthenticated attackers to execute remote code, potentially compromising production environments and exposing sensitive operational data. Attackers are leveraging these vulnerabilities to target the manufacturing sector for automated ransomware deployment and data exfiltration, resulting in operational disruption and risk to production integrity. This incident underscores the trend of threat actors focusing on supply chain and OT/IT hybrid platforms, exploiting unpatched flaws for initial access. The urgent CISA advisory signals accelerating regulatory scrutiny and highlights the increased risks posed by software supply chain weaknesses in critical infrastructure sectors.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports