✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Defense/Space
Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.
Explore Other Sectors
Defense/Space Threat Reports
Google Engineer Convicted of AI Trade Secrets Theft to China
In January 2026, former Google software engineer Linwei Ding was convicted on multiple counts of economic espionage and theft of trade secrets. Between May 2022 and April 2023, Ding illicitly transferred over 2,000 pages of confidential AI-related documents from Google's network to his personal cloud account. These documents detailed Google's proprietary AI supercomputing infrastructure, including custom Tensor Processing Unit (TPU) and Graphics Processing Unit (GPU) technologies, orchestration software for large-scale AI workloads, and SmartNIC networking technology. Concurrently, Ding secretly affiliated with two China-based technology companies, assuming roles such as Chief Technology Officer and CEO, and aimed to replicate Google's AI supercomputing capabilities in China. ([justice.gov](https://www.justice.gov/opa/pr/former-google-engineer-found-guilty-economic-espionage-and-theft-confidential-ai-technology?utm_source=openai)) This incident underscores the persistent threat of insider espionage within the tech industry, particularly concerning advanced AI technologies. It highlights the critical need for robust internal security measures and vigilant monitoring to protect intellectual property from unauthorized access and exfiltration.
5 months ago
Kill Chain
Google Engineer Convicted of AI Trade Secrets Theft for China Startup
In January 2026, former Google engineer Linwei Ding was convicted on seven counts of economic espionage and seven counts of theft of trade secrets. Between May 2022 and April 2023, Ding illicitly transferred over 2,000 confidential documents related to Google's AI technology to his personal Google Cloud account. These documents detailed proprietary information about Google's supercomputing data center infrastructure, including custom Tensor Processing Unit chips, Graphics Processing Unit systems, and the Cluster Management System software. During this period, Ding secretly affiliated with two China-based technology companies, including founding Shanghai Zhisuan Technologies Co., while still employed at Google. He employed deceptive tactics to conceal his activities, such as copying data into the Apple Notes application and converting them to PDFs before uploading them to his personal account. The scheme was uncovered when Google discovered Ding's public presentation in China to potential investors about his startup. This case underscores the persistent threat of insider threats and economic espionage, particularly in the competitive field of artificial intelligence. Organizations must remain vigilant in protecting their intellectual property and sensitive information from both internal and external threats. The incident highlights the importance of robust security measures and monitoring systems to detect and prevent unauthorized access and data exfiltration.
5 months ago
Kill Chain
WinRAR 2025: Nation-State & Cybercrime Groups Exploit Six-Month Software Flaw
In late July 2025, Google Threat Intelligence Group reported that both nation-state actors and financially motivated cybercriminals are actively exploiting a critical WinRAR path traversal vulnerability (CVE-2025-8088) that remained unpatched for over six months. The flaw was widely abused starting two weeks before RARLAB released a fix, allowing attackers to craft specially designed archive files. These malicious files executed code or dropped malware undetected onto victim systems, targeting government, military, and technology sectors—most notably Ukrainian entities—while criminal groups focused campaigns in Latin America, Indonesia, and Brazil. The widespread exploitation continues, leveraging malware and remote access tools for espionage and credential theft. The current landscape highlights accelerated adoption of public exploit tools by both advanced persistent threats and opportunistic criminals. The event underscores urgent industry challenges in rapid patching, software supply chain trust, and the escalating convergence of state and criminal cyber operations sharing technical tradecraft.
5 months ago
Kill Chain
North Korea’s Labyrinth Chollima Splits: New Specialized Threat Groups Emerge in 2024
In early 2024, researchers from CrowdStrike revealed that the long-active North Korean threat group known as Labyrinth Chollima has formally split into three specialized entities: Labyrinth Chollima (espionage), Golden Chollima, and Pressure Chollima (both focused on cryptocurrency theft). This change followed observed divergences in tactics, malware usage, and sector targeting, with Labyrinth Chollima shifting focus to manufacturing, logistics, aerospace, and defense, often leveraging social engineering and sharing infrastructure with its counterparts. Notably, Pressure Chollima was behind the record-breaking $1.46 billion cryptocurrency heist in 2023, illustrating the scale and sophistication of the new operational structure. This realignment signals increasing specialization and growth within North Korea's cyber apparatus, enabling more targeted attacks and efficient monetization strategies. Organizations in critical industries and the crypto sector face heightened risks as these groups adapt rapidly and circumvent international sanctions by fueling cyber operations with illicit gains.
5 months ago
Kill Chain
Mustang Panda’s 2025 Cyber Espionage: Updated COOLCLIENT Backdoor Hits Government
In late 2025, cyber espionage group Mustang Panda (also known as Earth Preta and Twill Typhoon) launched a series of targeted attacks against government entities, deploying an updated version of the COOLCLIENT backdoor. These intrusions leveraged spear-phishing and custom malware to establish persistent access, exfiltrate sensitive government data, and conduct surveillance. The campaign relied on advanced command-and-control infrastructure and encrypted traffic to evade detection, demonstrating the group’s evolving tactics and technical sophistication. The breach resulted in notable data theft and highlighted vulnerabilities in governmental East-West network security and policy enforcement. This incident underscores a rising trend of state-sponsored attackers continuously updating malware toolsets and intensifying operations against government organizations. The sophistication and stealth of these campaigns demand enhanced data protection, visibility, and zero trust network controls to meet regulatory and operational requirements.
5 months ago
Kill Chain
Pakistan-Linked APT Launches Gopher Strike & Sheet Attack Against Indian Government in 2025
In September 2025, cybersecurity researchers uncovered coordinated cyber campaigns—dubbed Gopher Strike and Sheet Attack—targeting Indian government entities. Attributed to a Pakistan-linked Advanced Persistent Threat (APT) group, the operations leveraged novel, undocumented tactics involving phishing and multi-stage malware to compromise government networks. Attackers exploited existing security gaps, conducted lateral movement, and exfiltrated sensitive data, threatening the confidentiality and integrity of official communications. The campaigns remained undetected for an extended period, highlighting the advanced tradecraft and persistent nature of the threat actor. These incidents underscore the growing risk posed by state-aligned actors employing increasingly sophisticated tactics to target critical government infrastructure. The discovery of new tools and techniques in these attacks signals an escalation in South Asian regional cyber conflict and emphasizes the need for updated security controls and rapid detection capabilities.
5 months ago
Kill Chain
Sandworm’s 2025 DynoWiper Attack on Poland’s Power Grid: Lessons in Critical Infrastructure Resilience
In late 2025, a highly targeted cyberattack attributed to the Sandworm group struck Poland's national power grid. Using custom data-wiping malware identified as DynoWiper, the attackers infiltrated critical infrastructure networks, demonstrating sophisticated knowledge of operational technology environments. The initial compromise involved lateral movement through segmented OT/IT networks, facilitated by exploitation of unprotected east-west traffic and weak segmentation controls. The subsequent deployment of DynoWiper caused destructive impacts, including service outages and loss of operational data across several regional substations, with cascading effects on grid stability and dependent sectors. Immediate containment was complicated by attacker persistence and the rapid spread of the wiper. This incident underscores the rising trend of advanced, nation-state wiper malware targeting critical infrastructure, reflecting a shift from espionage to destructive tactics. Organizations face elevated urgency to harden network segmentation, implement robust egress security, and adopt zero trust operational models in light of these evolving threats.
6 months ago
Kill Chain
GitLab Faces Critical 2FA Bypass and DoS Vulnerabilities in 2026
In January 2026, GitLab urgently patched several high-severity vulnerabilities affecting its widely used Community and Enterprise Editions. The most critical issue, tracked as CVE-2026-0723, allowed attackers with knowledge of a user's account ID to bypass two-factor authentication controls by submitting forged device responses, resulting from unchecked return values in authentication services. In addition, GitLab addressed multiple denial-of-service (DoS) vulnerabilities, including CVE-2025-13927 and CVE-2025-13928, which potentially let unauthenticated threat actors trigger service outages through malformed authentication data and improper API endpoint authorization checks. Immediate patches were released to mitigate the risks of account takeover, service disruption, and operational downtime across a user base spanning major enterprises and nearly 6,000 exposed internet-facing instances. This breach stands out in the context of rising attacks exploiting authentication weaknesses and API logic flaws across the software supply chain. As critical open-source DevSecOps platforms like GitLab underpin enterprise workflows, attackers increasingly target authentication and availability gaps, aligning with regulatory scrutiny and the growing demand for robust zero trust controls.
6 months ago
Kill Chain
North Korea Supply Chain Attack Exploits VS Code Projects – 2026 Analysis
In January 2026, cybersecurity researchers uncovered a sophisticated supply chain attack targeting software developers via malicious Visual Studio Code (VS Code) projects. Threat actors linked to North Korea's Contagious Interview campaign distributed weaponized VS Code samples to compromise developer endpoints and install covert backdoors. Once inside victims' systems, the attackers could move laterally, exfiltrate sensitive source code, and access development infrastructure, risking intellectual property, customer data, and supply chain integrity. The campaign represents an evolution of social engineering tactics and demonstrates the attackers’ focus on high-leverage targets within the tech sector. This incident is highly relevant as it underscores the growing trend of software supply chain attacks leveraging development environments and trusted open-source platforms. Organizations must now reassess third-party code risks and developer security, as attackers increasingly exploit toolchains and social-engineering techniques instead of perimeter defenses.
6 months ago
Kill Chain
Google Pixel 9 (2026): Zero-Click BigWave Driver Breach Exposes Kernel Vulnerabilities
In January 2026, Google Pixel 9 devices were found vulnerable to a sophisticated zero-click exploit chain targeting the Android BigWave hardware driver. Attackers combined a remote code execution exploit affecting a Dolby decoder with a privilege escalation flaw in the /dev/bigwave device, accessible from the mediacodec SELinux sandbox. The chain allowed attackers to escape the sandbox, bypass SELinux protections, and achieve kernel-level arbitrary read/write, essentially gaining full device control. This exploit enabled unauthorized access to sensitive data and even allowed remote data exfiltration by attackers, severely compromising device security. This incident highlights the increasing sophistication of exploit chains leveraging hardware-specific drivers and sandbox escape techniques in mobile ecosystems. With the rise in supply chain threats, use of AI to automate exploit engineering, and growing pressure from privacy regulators, organizations face escalating risks from zero-day attacks targeting embedded devices.
6 months ago
Kill Chain
Black Basta Ransomware Boss Named, Placed on Interpol Red Notice in Major 2026 Crackdown
In January 2026, international law enforcement, led by Ukraine and Germany, identified Oleg Evgenievich Nefedov as the leader of the Black Basta ransomware-as-a-service (RaaS) gang. Authorities added Nefedov to Interpol's 'Red Notice' and Europol's 'Most Wanted' lists, following coordinated raids that apprehended affiliates specializing in breaching corporate systems, cracking passwords, and escalating privileges to facilitate attacks. Black Basta has been attributed to over 600 global cyber incidents targeting enterprises in sectors from defense to healthcare, employing ransomware and data extortion to extract payments and exfiltrate sensitive information. This incident is significant as it marks one of the first times a major ransomware operation's leadership was officially unmasked and targeted with international warrants. The Black Basta takedown reflects increasing sophistication and coordination in responses to organized cybercrime, underscoring the persistent threat posed by ransomware groups and their rapid evolution post-Conti.
6 months ago
Kill Chain
Ukraine’s Army Compromised by Void Blizzard in Charity-Themed Malware Campaign
Between October and December 2025, Ukraine's Defense Forces were targeted by a sophisticated malware campaign attributed to the Russian-linked threat group 'Void Blizzard' (also known as 'Laundry Bear'). Attackers leveraged instant messaging apps like Signal and WhatsApp, using compelling charity-themed lures to trick recipients into downloading a password-protected archive. Inside, the PluggyApe backdoor—bundled as disguised executables—provided remote access to compromised hosts, stealing sensitive data and awaiting additional commands. The malware's second-generation included enhanced obfuscation, anti-analysis techniques, and a novel approach to fetching command-and-control addresses from public services like Pastebin. This campaign reflects the escalating use of social engineering, mobile device targeting, and supply chain tactics by state-aligned groups in espionage operations. It highlights the urgent need for stronger endpoint protection, policy enforcement, and continuous monitoring across both traditional and mobile attack surfaces.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports