The Containment Era is here. →Explore

Industry Category

Defense/Space

Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.

350 threat reports
Page 10 of 30

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Defense/Space Threat Reports

Showing 109120 / 350 reports
Kyber Ransomware's 2026 Attacks: A New Era of Post-Quantum Encryption Threats
Impact· HIGH

Kyber Ransomware's 2026 Attacks: A New Era of Post-Quantum Encryption Threats

In March 2026, the Kyber ransomware group launched attacks targeting Windows systems and VMware ESXi endpoints. The Windows variant, written in Rust, implemented Kyber1024 post-quantum encryption for key protection, while the ESXi variant utilized ChaCha8 for file encryption and RSA-4096 for key wrapping. Both variants shared the same campaign ID and Tor-based ransom infrastructure, indicating coordinated efforts to maximize impact by encrypting all servers simultaneously. The attacks led to significant operational disruptions, particularly affecting a multi-billion-dollar American defense contractor and IT services provider. The adoption of post-quantum cryptographic techniques by ransomware operators marks a significant evolution in cyber threats, highlighting the need for organizations to stay ahead of emerging encryption methods used by adversaries. This incident underscores the importance of robust cybersecurity measures and continuous monitoring to detect and mitigate such sophisticated attacks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Zero Motorcycles Firmware Vulnerability Exposes Riders to Potential Attacks
Impact· MEDIUM

Zero Motorcycles Firmware Vulnerability Exposes Riders to Potential Attacks

In April 2026, a vulnerability identified as CVE-2026-1354 was discovered in Zero Motorcycles' firmware versions 44 and earlier. This flaw allows an attacker in close proximity to forcibly pair a device with the motorcycle via Bluetooth. Once paired, the attacker can exploit the over-the-air firmware update functionality to potentially upload malicious firmware, compromising the motorcycle's integrity. The attack requires the motorcycle to be in Bluetooth pairing mode, and the attacker must maintain proximity throughout the firmware update process. ([securityvulnerability.io](https://securityvulnerability.io/vulnerability/CVE-2026-1354?utm_source=openai)) This incident underscores the growing cybersecurity risks associated with connected vehicles, particularly in the transportation sector. As vehicles become increasingly integrated with wireless technologies, vulnerabilities like this highlight the urgent need for robust security measures to prevent unauthorized access and ensure user safety.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Siemens CVE-2025-40745: Addressing Certificate Validation Vulnerabilities in Industrial Software
Impact· LOW

Siemens CVE-2025-40745: Addressing Certificate Validation Vulnerabilities in Industrial Software

In April 2026, Siemens disclosed a vulnerability (CVE-2025-40745) in multiple applications, including Siemens Software Center, Simcenter 3D, Simcenter Femap, Simcenter STAR-CCM+, Solid Edge SE2025, Solid Edge SE2026, and Tecnomatix Plant Simulation. The flaw involves improper validation of client certificates when connecting to the Analytics Service endpoint, potentially allowing unauthenticated remote attackers to perform man-in-the-middle attacks. Siemens has released updates to address this issue and recommends users upgrade to the latest versions. This incident underscores the critical importance of proper certificate validation in industrial software to prevent unauthorized data interception and manipulation. Organizations using affected Siemens products should promptly apply the recommended updates to mitigate potential security risks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
US Nationals Sentenced for Facilitating North Korean Tech Worker Scheme
Impact· HIGH

US Nationals Sentenced for Facilitating North Korean Tech Worker Scheme

In April 2026, two U.S. nationals, Kejia Wang and Zhenxing Wang, were sentenced to nine years and 92 months in prison, respectively, for facilitating a scheme that enabled North Korean IT workers to pose as American employees. This operation, running from 2021 to 2024, involved the use of stolen identities from over 80 U.S. citizens to secure remote positions at more than 100 U.S. companies, including Fortune 500 firms. The scheme generated over $5 million for the North Korean regime and resulted in U.S. companies incurring damages exceeding $3 million. The perpetrators managed 'laptop farms' within the U.S., allowing North Korean operatives to remotely access company systems, leading to the theft of sensitive data, including export-controlled military technology. This incident underscores the evolving tactics of state-sponsored cyber operations and highlights the critical need for robust identity verification and cybersecurity measures in remote hiring processes. Organizations must remain vigilant against sophisticated insider threats that exploit remote work infrastructures to infiltrate corporate networks and exfiltrate sensitive information.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
U.S. Nationals Sentenced for Facilitating North Korean IT Worker Infiltration
Impact· HIGH

U.S. Nationals Sentenced for Facilitating North Korean IT Worker Infiltration

Between 2021 and October 2024, U.S. nationals Kejia Wang and Zhenxing Wang facilitated a scheme enabling North Korean IT workers to secure remote positions at over 100 U.S. companies, including Fortune 500 firms. By creating fake websites, shell companies, and hosting company-issued laptops in U.S. residences, they masked the workers' true identities, generating over $5 million for the North Korean government and causing approximately $3 million in damages to the affected companies. ([nationaltoday.com](https://nationaltoday.com/us/ma/boston/news/2026/04/16/two-americans-sentenced-for-helping-north-korea-obtain-remote-it-jobs/?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors exploiting remote work infrastructures to infiltrate organizations, emphasizing the need for robust identity verification and cybersecurity measures to protect against such sophisticated schemes.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
AgingFly Malware: A New Threat to Critical Infrastructure
Impact· HIGH

AgingFly Malware: A New Threat to Critical Infrastructure

In March 2026, a sophisticated cyberattack targeted Ukrainian local governments and hospitals, deploying a new malware family named 'AgingFly.' The attack began with phishing emails offering humanitarian aid, leading recipients to compromised or fake websites. These sites delivered malicious files that, once executed, initiated a multi-stage infection process. The final payload, AgingFly, enabled attackers to steal authentication data from Chromium-based browsers and the WhatsApp messenger, and provided remote control capabilities over infected systems. CERT-UA attributed these attacks to the threat actor group UAC-0247. This incident underscores the evolving tactics of cyber adversaries, including the use of AI-generated content and advanced multi-stage malware delivery mechanisms. Organizations, especially those in critical sectors, must remain vigilant against such sophisticated social engineering attacks and enhance their cybersecurity defenses accordingly.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Vulnerability in wolfSSL: CVE-2026-5194 Allows ECDSA Certificate Authentication Bypass
Impact· CRITICAL

Critical Vulnerability in wolfSSL: CVE-2026-5194 Allows ECDSA Certificate Authentication Bypass

In April 2026, a critical vulnerability identified as CVE-2026-5194 was discovered in the wolfSSL library, a widely used SSL/TLS implementation designed for embedded systems and IoT devices. This flaw arises from missing hash/digest size and Object Identifier (OID) checks during the verification of ECDSA certificates, allowing the acceptance of improperly small digests. Consequently, attackers could exploit this weakness to bypass ECDSA certificate-based authentication, potentially leading to unauthorized access and man-in-the-middle attacks. The issue affects configurations where both ECC and EdDSA or ML-DSA are enabled. wolfSSL addressed this vulnerability in version 5.9.1, released on April 8, 2026. The discovery of CVE-2026-5194 underscores the critical importance of rigorous certificate validation processes in cryptographic libraries. As wolfSSL is utilized in over 5 billion devices across various sectors, including industrial control systems, automotive, and aerospace, the potential impact of this vulnerability is extensive. Organizations relying on wolfSSL are urged to promptly update to the patched version to mitigate security risks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
APT37's Facebook Social Engineering Tactics Unveiled
Impact· MEDIUM

APT37's Facebook Social Engineering Tactics Unveiled

In April 2026, the North Korean state-sponsored hacking group APT37 (also known as ScarCruft) initiated a sophisticated social engineering campaign targeting individuals via Facebook. The attackers created fake profiles to befriend targets, eventually moving conversations to Facebook Messenger. They persuaded victims to install a tampered version of Wondershare PDFelement, claiming it was necessary to view encrypted military documents. This malicious software executed embedded shellcode upon launch, establishing a foothold for the attackers. The campaign utilized compromised infrastructure for command-and-control operations, leveraging a legitimate Japanese real estate website to issue malicious commands. Ultimately, the malware was disguised as a harmless JPG image, enabling extensive remote access capabilities while evading detection by security software. This incident underscores the evolving tactics of APT37, highlighting their ability to exploit social media platforms for initial access and their use of legitimate software and infrastructure to evade detection. The campaign's success emphasizes the need for heightened awareness and robust security measures against social engineering attacks, especially those leveraging trusted platforms and applications.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
APT28's PRISMEX Malware Campaign: A Threat to Global Security
Impact· CRITICAL

APT28's PRISMEX Malware Campaign: A Threat to Global Security

In early 2026, the Russian state-sponsored group APT28, also known as Fancy Bear, launched a sophisticated cyber-espionage campaign targeting Ukraine and its NATO allies. The operation, active since at least September 2025 and intensifying in January 2026, involved the deployment of a modular malware suite named PRISMEX. This suite utilized advanced steganography, Component Object Model (COM) hijacking, and exploited newly disclosed vulnerabilities, including CVE-2026-21509 and CVE-2026-21513, to infiltrate defense supply chains and critical infrastructure sectors. The campaign's strategic focus on supply chains and operational planning capabilities underscores a shift toward operational disruption, potentially paving the way for more destructive activities. ([thehackernews.com](https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html?utm_source=openai)) The PRISMEX campaign highlights the persistent and evolving threat posed by APT28, emphasizing the necessity for organizations to adopt proactive cybersecurity measures. The rapid weaponization of vulnerabilities and the use of sophisticated techniques like steganography and cloud service abuse demonstrate the group's advanced capabilities. This incident serves as a critical reminder for entities within targeted sectors to enhance their security postures and remain vigilant against such advanced persistent threats. ([thehackernews.com](https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Iran-Linked Hackers Target U.S. Critical Infrastructure in 2026
Impact· CRITICAL

Iran-Linked Hackers Target U.S. Critical Infrastructure in 2026

In early April 2026, Iran-affiliated cyber actors targeted internet-facing operational technology (OT) devices across U.S. critical infrastructure sectors, including programmable logic controllers (PLCs) manufactured by Rockwell Automation. These attacks led to diminished PLC functionality, manipulation of display data, and, in some cases, operational disruption and financial loss. The Cybersecurity and Infrastructure Security Agency (CISA), along with the FBI and NSA, issued warnings about these threats, emphasizing the need for immediate action to secure vulnerable OT assets. ([nextgov.com](https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/?utm_source=openai)) This incident underscores the escalating cyber threats from nation-state actors targeting critical infrastructure. The exploitation of internet-exposed PLCs highlights the urgent need for organizations to implement robust cybersecurity measures, including network segmentation, regular software updates, and the use of strong, unique passwords to protect against such sophisticated attacks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
APT28's PRISMEX Malware Campaign: A 2026 Cyber-Espionage Threat
Impact· HIGH

APT28's PRISMEX Malware Campaign: A 2026 Cyber-Espionage Threat

In early 2026, the Russian state-sponsored group APT28 (also known as Fancy Bear and Pawn Storm) initiated a sophisticated cyber-espionage campaign targeting Ukraine and its NATO allies. The operation employed a newly developed malware suite named PRISMEX, which utilizes advanced steganography, Component Object Model (COM) hijacking, and the exploitation of legitimate cloud services for command-and-control (C2) communications. The campaign began in September 2025 and intensified in January 2026, focusing on sectors such as defense, emergency services, and logistics across multiple countries, including Poland, Romania, Slovenia, Turkey, Slovakia, and the Czech Republic. ([thehackernews.com](https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html?utm_source=openai)) This campaign underscores the rapid weaponization of newly disclosed vulnerabilities by APT28, notably CVE-2026-21509 and CVE-2026-21513, to infiltrate target systems. The use of PRISMEX highlights a strategic shift towards more covert and resilient attack methodologies, posing significant challenges for detection and mitigation. ([thehackernews.com](https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations
Impact· HIGH

Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations

In March 2026, an Iran-linked threat actor executed a coordinated password-spraying campaign targeting Microsoft 365 environments across Israel and the United Arab Emirates. The attacks occurred in three waves on March 3, 13, and 23, affecting over 300 organizations in Israel and more than 25 in the UAE. Primary targets included municipalities, technology firms, transportation, and healthcare sectors. Attackers utilized rotating Tor exit nodes for scanning and employed VPN services geolocated within Israel to bypass geo-fencing restrictions. Once valid credentials were obtained, they accessed and exfiltrated sensitive data, including personal emails. ([thehackernews.com](https://thehackernews.com/2026/04/iran-linked-password-spraying-campaign.html?utm_source=openai)) This incident underscores the escalating cyber threats in the Middle East, particularly those linked to nation-state actors. The use of password-spraying techniques highlights the critical need for robust authentication measures and vigilant monitoring to detect and mitigate unauthorized access attempts.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports