The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Defense/Space
Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.
Explore Other Sectors
Defense/Space Threat Reports
GitLab Token Exposure Enables Supply Chain Attacks on Open Source Projects
In September 2026, security researchers at Aikido discovered that private GitLab email addresses containing long-lived authentication tokens were being deliberately exposed in public documentation by project maintainers. These addresses, part of GitLab's "Email work item to this project" feature, allow attackers to push code to protected branches, access private repositories, steal CI/CD secrets, and compromise developer accounts without proper authentication validation. The vulnerability affects popular open-source projects, creating significant supply chain risks as attackers can modify email suffixes to escalate from creating issues to opening merge requests. This incident highlights the growing trend of misunderstood security features in DevOps platforms leading to supply chain compromises, as organizations increasingly rely on automated development workflows without fully comprehending the associated security implications.
6 minutes ago
Kill Chain
Russian Hybrid Warfare Escalates Across Europe: The New Generation Warfare Threat
Since February 2022, Russia has significantly escalated hybrid warfare operations across Europe as part of its New Generation Warfare (NGW) strategy, extending far beyond traditional Soviet territories. Russian state-sponsored groups have conducted coordinated cyber and physical sabotage campaigns targeting critical infrastructure, government entities, and private sector organizations throughout European nations. These operations have resulted in widespread disruption of services, data breaches, and potential threats to personnel safety across multiple sectors including energy, telecommunications, and transportation. This escalation represents a critical shift in modern threat landscapes as nation-state actors increasingly blur the lines between cyber warfare and physical attacks, making hybrid threats one of the most pressing security challenges facing organizations today.
1 hour ago
Kill Chain
GitLab Email Addresses Weaponized in 2026 Supply Chain Attacks
In September 2026, Aikido Security researchers discovered that GitLab's incoming email addresses contain non-expiring access tokens that grant broad privileges across an organization's public and private projects. These automatically assigned email addresses, designed for creating issues via email, can be weaponized by attackers who obtain them to push malicious code, bypass IP restrictions, and execute CI/CD jobs without direct account access. The vulnerability affects the entire GitLab ecosystem, with researchers finding exposed addresses for popular open-source projects during a brief internet scan. This incident highlights the growing sophistication of supply chain attacks targeting developer platforms and the hidden security implications of seemingly benign productivity features. As organizations increasingly rely on DevOps platforms for critical infrastructure, attackers are exploiting overlooked authentication mechanisms to compromise software supply chains at scale.
6 hours ago
Kill Chain
First-Ever Terraform Registry Supply Chain Attack: North Korean Hackers Deploy Sophisticated Go Malware
In September 2026, cybersecurity researchers discovered North Korean threat actors using HashiCorp's Terraform Registry to distribute Go-based malware for the first time. The attackers published four malicious packages across Terraform providers and Go modules, accumulating over 1,600 downloads before detection. The malware employed sophisticated dual command-and-control channels using blockchain dead drops and Slack APIs, with execution triggered only during specific cryptographic operations to avoid detection. This campaign represents an expansion of the previously identified Graphalgo operation, demonstrating DPRK actors' continued evolution of supply chain attack vectors beyond traditional npm and PyPI repositories. This incident highlights the growing sophistication of state-sponsored supply chain attacks as threat actors diversify their distribution channels to target infrastructure-as-code and cloud-native development workflows, making detection and prevention increasingly challenging for organizations.
1 day ago
Kill Chain
SideCopy APT Expands to Target Indian Academic Institutions with Advanced ReverseRAT Campaign
The Pakistan-linked APT group SideCopy has expanded its targeting beyond Indian government entities to include academic institutions through sophisticated spear-phishing campaigns in 2026. The threat actors utilize weaponized ZIP archives containing malicious LNK files that abuse mshta.exe to execute obfuscated HTML applications, ultimately deploying the ReverseRAT malware for data exfiltration and remote access. The attack chain employs multi-stage obfuscation, anti-forensic self-deletion routines, and encrypted command-and-control communications to evade detection while harvesting system metadata, credentials, and sensitive documents from compromised networks. This incident highlights the evolving threat landscape where state-sponsored groups are diversifying their target profiles to include educational institutions, recognizing their value as repositories of intellectual property and research data. The sophistication of SideCopy's techniques demonstrates the growing challenge organizations face in defending against adaptive APT groups that continuously refine their tradecraft.
1 day ago
Kill Chain
Critical Siemens Siveillance Control Vulnerability Exposes Industrial Infrastructure to Root-Level Compromise
A critical vulnerability (CVE-2026-50093) with CVSS score 9.0 was discovered in Siemens Siveillance Control and Siveillance Control Pro systems, affecting the Open Interface Services (OIS) web module. The vulnerability allows attackers to upload arbitrary files to the server, potentially leading to unauthorized root-level access and complete system compromise. Multiple versions of Siveillance Control V3.0, V4.0, and Pro editions are affected, with patches now available from Siemens. The vulnerability impacts critical infrastructure sectors including critical manufacturing, communications, and commercial facilities worldwide. This incident highlights the growing threat to industrial control systems and critical infrastructure, particularly as nation-state actors increasingly target OT environments. With the rise of hybrid IT/OT networks and remote access requirements, vulnerabilities in surveillance and control systems present expanded attack surfaces for sophisticated threat actors seeking to disrupt industrial operations.
2 days ago
Kill Chain
CVE-2025-6625: Critical FTP Vulnerability in Schneider Electric Industrial Controllers
Schneider Electric disclosed CVE-2025-6625, a high-severity improper input validation vulnerability affecting Modicon M340 controllers and communication modules used across critical infrastructure sectors including energy, chemical, and water systems. The vulnerability allows attackers to send crafted FTP commands to cause denial of service attacks, potentially disrupting industrial control systems. Multiple product versions are affected, with firmware updates available for some modules while others await remediation. The vulnerability carries a CVSS score of 7.5 and impacts globally deployed industrial automation systems. This incident highlights the ongoing security challenges facing industrial control systems as threat actors increasingly target operational technology environments. With critical infrastructure under heightened scrutiny following recent nation-state campaigns, vulnerabilities in widely-deployed industrial controllers represent significant risk amplification across interconnected systems.
6 days ago
Kill Chain
APT36 Evolves Tactics with Rust Malware and GitHub Infrastructure in Operation RapidRust
In September 2026, the Pakistan-aligned threat group Transparent Tribe (APT36) launched Operation RapidRust, targeting government and defense entities in India and Afghanistan with four new malware families: RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The campaign utilized innovative command-and-control infrastructure through private GitHub repositories and typosquatted domains mimicking Indian news organizations. The sophisticated attack chain involved a Rust-based backdoor for encrypted communications, USB propagation tools, and cross-platform file stealers capable of exfiltrating up to 5GB of sensitive data per execution. This incident highlights the evolving threat landscape where nation-state actors increasingly leverage legitimate cloud services for malicious infrastructure while expanding their technical capabilities across multiple operating systems and attack vectors.
6 days ago
Kill Chain
How Iranian Cyber Operations Target the Hidden Infrastructure Behind U.S. Military Power
Iranian cyber operations are increasingly targeting the interconnected civilian infrastructure that supports U.S. military operations, including commercial railroads, ports, utilities, and defense contractors. Rather than pursuing catastrophic single attacks, Iranian threat groups are conducting persistent, volume-based campaigns across multiple smaller targets to strain response capabilities and disrupt military logistics chains. Recent attacks on water utilities across 12 states and a four-day power plant outage in the UK demonstrate this strategy of imposing cumulative operational strain rather than seeking headline-grabbing breaches. This threat model reflects Iran's adaptation to prolonged conflict scenarios, where creating sustained disruption across military-supporting infrastructure becomes more strategically valuable than traditional espionage or single-point failures.
1 week ago
Kill Chain
Critical XSS Vulnerability in Siemens Teamcenter Exposes Manufacturing Systems to Web-Based Attacks
A reflected cross-site scripting (XSS) vulnerability (CVE-2026-58113) was discovered in Siemens Teamcenter's authentication redirect flow, affecting multiple versions across V2412, V2506, V2512, and V2606 product lines. The vulnerability allows unauthenticated remote attackers to inject malicious JavaScript into authenticated user sessions through crafted URLs, potentially enabling data theft and unauthorized actions within victims' Teamcenter sessions. Siemens has released patches for all affected versions and recommends immediate updates to mitigate the CVSS 6.1 rated vulnerability. This incident highlights the persistent threat of web application vulnerabilities in critical manufacturing systems, particularly as organizations increasingly rely on web-based PLM platforms for sensitive industrial operations and intellectual property management.
1 week ago
Kill Chain
Yemen Threat Actors Exploit Claude AI for Advanced Weapons Development
In September 2026, Anthropic disclosed that threat actors based in northern Yemen exploited their Claude AI models to develop guidance, navigation, and control software for advanced weapons systems, including guided rockets, ballistic missiles with 2,000+ km range, and hypersonic glide vehicles. The actors used multiple Claude instances simultaneously, assigning specialized roles to each AI system while employing evasion techniques to bypass safety guardrails. Although Anthropic's safeguards blocked many requests, the actors successfully developed software and conducted field tests of a guided rocket, though initial tests failed. This incident represents a concerning escalation in AI-enabled weapons proliferation, demonstrating how generative AI can democratize sophisticated military engineering capabilities previously limited to nation-states and well-funded organizations.
1 week ago
Kill Chain
Red Heron's Rapid Gitea Exploitation Exposes Critical Zero Trust Gaps
In July 2026, the Chinese threat actor Red Heron rapidly weaponized CVE-2026-60004, a critical Gitea remote code execution vulnerability, to compromise 13 organizations across six countries including Canada, Taiwan, the U.S., Qatar, Argentina, and Sri Lanka. The campaign targeted defense, election, energy, aerospace, telecommunications, government, and research sectors, progressing from source code theft to persistent access through deployment of the JITTERLY backdoor and SIXZUT rootkit. Red Heron's automated exploitation framework enabled systematic credential collection, lateral movement, and root-level access to critical infrastructure including a three-node Proxmox cluster. This incident demonstrates the accelerating threat landscape where nation-state actors can transform public proof-of-concept exploits into sophisticated automated frameworks within days of vulnerability disclosure, highlighting the critical window between patch availability and mass exploitation.
1 week ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports