✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Defense/Space
Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.
Explore Other Sectors
Defense/Space Threat Reports
HollowGraph Malware: Exploiting Microsoft 365 Calendars for Covert C2 Operations
In June 2026, cybersecurity researchers identified a sophisticated malware component named HollowGraph, which exploits Microsoft 365 calendar events to establish covert command-and-control (C2) channels. By leveraging the Microsoft Graph API, the malware communicates through calendar entries dated May 13, 2050, embedding commands and exfiltrated data within event attachments. This technique allows the malware to blend seamlessly with legitimate network traffic, evading traditional detection mechanisms. The campaign primarily targets Israeli organizations, with evidence suggesting links to the Iranian-nexus threat actor Lyceum. The use of trusted cloud services for C2 communications underscores the evolving tactics of state-sponsored cyber espionage groups. ([thehackernews.com](https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html?utm_source=openai)) The discovery of HollowGraph highlights a concerning trend in cyber threats: the abuse of legitimate cloud services to mask malicious activities. As organizations increasingly rely on cloud-based platforms, adversaries are adapting their methods to exploit these trusted environments. This incident serves as a critical reminder for enterprises to enhance monitoring of cloud service activities and implement robust security measures to detect and mitigate such sophisticated threats.
5 days ago
Kill Chain
Russian Hackers Exploit IP Cameras to Monitor NATO Military Logistics
In July 2026, Dutch intelligence agencies AIVD and MIVD disclosed that Russian state-backed hackers systematically compromised internet-connected IP cameras across Europe and Ukraine. By exploiting devices with default passwords and outdated firmware, these actors accessed video feeds to monitor military transport routes and weapons shipments bound for Kyiv. In Ukraine, the compromised cameras were used to identify the locations of Ukrainian military personnel, leading to targeted attacks on troops and equipment. This operation highlights the vulnerability of unsecured IoT devices and their potential exploitation for espionage and military purposes. The incident underscores the critical need for robust cybersecurity measures, especially for devices connected to the internet. Organizations are urged to secure IP cameras by updating firmware, changing default credentials, and restricting public internet access to prevent unauthorized surveillance and data breaches.
5 days ago
Kill Chain
UAC-0145's Use of ClickFix CAPTCHAs: A New Cyber Threat in Ukraine
In July 2026, the Russian state-sponsored hacking group UAC-0145, also known as Sandworm or APT44, launched a campaign targeting Ukrainian organizations. The attackers employed a technique called ClickFix, which involves fake CAPTCHA prompts on compromised websites. These prompts instructed users to execute PowerShell commands, leading to the installation of data-stealing malware such as GHETTOVIBE and SCOUTCURL. The campaign compromised at least ten websites and utilized tools like SMARTAXE to dynamically alter web content, displaying deceptive CAPTCHA checks. Additionally, the attackers distributed malicious Android APK files via messaging apps, deploying the COWARDDUCK backdoor to exfiltrate sensitive information from infected devices. This incident underscores the evolving tactics of state-sponsored threat actors, who are increasingly adopting social engineering techniques traditionally associated with financially motivated cybercriminals. The use of ClickFix by UAC-0145 highlights the need for heightened vigilance and user education to recognize and avoid such deceptive tactics.
6 days ago
Kill Chain
Critical Vulnerability in NASA's cFS Health & Safety Application: CVE-2026-15352
In July 2026, a critical vulnerability (CVE-2026-15352) was identified in NASA's Core Flight System (cFS) Health & Safety (HS) Application. This flaw allows attackers to trigger a segmentation fault by sending a routine Housekeeping Telemetry request, leading to a denial-of-service condition. The vulnerability affects versions of the HS application prior to v7.0.1. NASA has released an update to address this issue and recommends users upgrade to v7.0.1 to mitigate the risk. ([software.nasa.gov](https://software.nasa.gov/software/GSC-18476-1?utm_source=openai)) This incident underscores the importance of timely software updates in mission-critical systems. As space exploration technologies become increasingly reliant on software, ensuring the security and reliability of these systems is paramount to prevent potential disruptions and maintain operational integrity.
1 week ago
Kill Chain
Critical Vulnerabilities in Cursor AI IDE Expose Developers to Remote Code Execution
In early 2026, multiple critical vulnerabilities were discovered in the Cursor AI-integrated development environment (IDE), notably CVE-2026-50548 and CVE-2026-50549. These flaws allowed attackers to escape the IDE's sandbox environment, enabling remote code execution (RCE) on developers' machines. Exploits involved manipulating the working directory parameter and leveraging symbolic link (symlink) manipulation to bypass security controls. The vulnerabilities posed significant risks, including unauthorized access to source code, sensitive data exposure, and potential compromise of development environments. ([csoonline.com](https://www.csoonline.com/article/4191923/sandbox-bypass-flaws-in-cursor-ide-highlight-prompt-injection-as-an-rce-vector.html?utm_source=openai)) The discovery of these vulnerabilities underscores the growing security challenges associated with AI-assisted development tools. As organizations increasingly adopt such tools to enhance productivity, it is imperative to implement robust security measures to mitigate risks associated with prompt injection attacks and sandbox escapes. This incident highlights the need for continuous monitoring and updating of AI development environments to safeguard against emerging threats.
1 week ago
Kill Chain
Critical Cursor Vulnerability Exposes Windows Systems to Malicious Code Execution
In July 2026, a critical vulnerability was discovered in the Cursor development environment, allowing malicious actors to execute arbitrary code on Windows systems. By placing a malicious file named 'git.exe' in the root of a Git repository, attackers could achieve code execution when the repository was opened in Cursor, without any user prompt or warning. This flaw granted attackers access to developers' credentials, including SSH keys and cloud tokens, posing significant security risks. Despite being reported in December 2025, the vulnerability remained unpatched as of July 2026, leaving many systems exposed. This incident underscores the growing threat of supply chain attacks targeting development tools and environments. As developers increasingly rely on third-party repositories and AI-assisted coding tools, the potential for such vulnerabilities to be exploited has risen, emphasizing the need for vigilant security practices and prompt patching of identified flaws.
1 week ago
Kill Chain
EU and UK Sanction Russian GRU Hackers Over Cyberattacks
In July 2026, the European Union and the United Kingdom jointly imposed sanctions on Russian military intelligence officers and associated entities for orchestrating extensive cyberattacks across Europe. These operations, attributed to the GRU and FSB's 16th Centre, targeted government networks and critical infrastructure in countries including France, Germany, Poland, and Finland. Notably, the Turla hacking group, linked to the FSB, attempted to disrupt Poland's energy grid, potentially affecting 500,000 residents during winter. The sanctions encompass asset freezes and travel bans on individuals and entities involved in these cyberespionage activities. This incident underscores the escalating threat of state-sponsored cyberattacks on critical infrastructure, highlighting the need for enhanced cybersecurity measures and international cooperation to deter such activities. The coordinated response by the EU and UK reflects a growing consensus on the importance of addressing cyber threats through unified diplomatic and legal actions.
1 week ago
Kill Chain
CISA Credential Leak May 2026: A Comprehensive Analysis
In May 2026, the Cybersecurity and Infrastructure Security Agency (CISA) discovered that a contractor had inadvertently exposed privileged Amazon AWS GovCloud keys by uploading them to a public GitHub repository. Upon detection, CISA promptly took the repository and its associated development environment offline, revoked the contractor's access, and conducted a thorough analysis. The investigation confirmed that the leaked credentials had not been misused outside of CISA, and no customer or mission-critical data was compromised. This incident underscores the critical importance of stringent access controls and vigilant monitoring of code repositories to prevent unauthorized exposure of sensitive information. The CISA credential leak highlights the growing risks associated with cloud misconfigurations and the inadvertent exposure of sensitive credentials in public repositories. As organizations increasingly rely on cloud services and collaborative development platforms, it is imperative to implement robust security measures, including regular audits, comprehensive logging, and adherence to zero-trust principles, to mitigate potential threats and safeguard critical assets.
2 weeks ago
Kill Chain
Critical Authentication Bypass in Gitea Docker Image (CVE-2026-20896)
In July 2026, a critical authentication bypass vulnerability, CVE-2026-20896, was discovered in Gitea's official Docker image versions up to and including 1.26.2. This flaw allowed unauthenticated attackers to impersonate any user, including administrators, by exploiting a default configuration that trusted reverse-proxy authentication headers from any source IP address. Exploitation began less than two weeks before public disclosure, with approximately 6,200 Gitea instances exposed on the public web. Successful exploitation granted attackers full access to repositories, CI/CD secrets, and administrative functions, posing significant risks to organizations relying on Gitea for source code management. The rapid exploitation of CVE-2026-20896 underscores the critical importance of promptly addressing default configuration vulnerabilities in widely used open-source tools. Organizations must remain vigilant, ensuring that default settings are reviewed and adjusted to align with security best practices to prevent unauthorized access and potential data breaches.
2 weeks ago
Kill Chain
Hackers Exploit Roundcube Flaw to Spy on Academic Researchers
In May 2026, a China-linked threat cluster, identified as UNK_MassTraction, exploited vulnerabilities in Roundcube webmail servers at U.S. and Canadian universities. Targeting physics and engineering departments, the attackers sent malicious emails that, when opened in vulnerable Roundcube clients, triggered the execution of JavaScript code exploiting CVE-2024-42009. This led to the deployment of IceCube malware, harvesting credentials and two-factor authentication data. Further exploitation of CVE-2025-49113 allowed the installation of SquareShell, a PHP webshell, granting remote code execution capabilities. In cases where this failed, the attackers deployed VShell, a Go-based backdoor facilitating interactive shell access and port forwarding. This incident underscores the persistent threat posed by state-sponsored cyber espionage, particularly targeting academic institutions involved in sensitive research areas. The exploitation of known vulnerabilities in widely used software like Roundcube highlights the critical need for timely patching and robust security measures to protect against sophisticated attacks.
2 weeks ago
Kill Chain
Critical Vulnerabilities in Labcenter Proteus 9 Threaten Infrastructure Security
In July 2026, multiple high-severity vulnerabilities were identified in Labcenter Proteus 9.1 SP4 Build 42914, including CVE-2026-42953 (out-of-bounds write), CVE-2026-49033 (stack-based buffer overflow), and CVE-2026-42958 (use-after-free). Exploitation of these vulnerabilities could allow attackers to execute arbitrary code, potentially compromising critical infrastructure sectors such as communications, healthcare, and energy. ([socdefenders.ai](https://www.socdefenders.ai/item/4909df73-d6e4-4d7f-ad22-28b3fb4d7bdc?utm_source=openai)) This incident underscores the persistent risks associated with software vulnerabilities in critical systems. Organizations must prioritize timely patching and robust security measures to mitigate potential threats. ([socdefenders.ai](https://www.socdefenders.ai/item/4909df73-d6e4-4d7f-ad22-28b3fb4d7bdc?utm_source=openai))
2 weeks ago
Kill Chain
China-Aligned Hackers Exploit Roundcube Flaws in University Attacks
In May 2026, a China-aligned threat group, identified as UNK_MassTraction, exploited critical vulnerabilities in Roundcube webmail software to infiltrate physics and engineering departments at U.S. and Canadian universities. By leveraging CVE-2024-42009, the attackers executed arbitrary JavaScript in victims' browsers, leading to credential theft. Subsequently, they exploited CVE-2025-49113 to gain persistent access via web shells or the VShell backdoor, enabling further network penetration. The campaign specifically targeted administrators and professors involved in sensitive research areas, including astrophysics and particle physics. This incident underscores the persistent threat posed by state-sponsored actors targeting academic institutions to access sensitive research data. The exploitation of known vulnerabilities in widely used software like Roundcube highlights the critical need for timely patching and robust cybersecurity measures within the education sector.
2 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports