The Containment Era is here. →Explore

Industry Category

Defense/Space

Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.

350 threat reports
Page 21 of 30

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Defense/Space Threat Reports

Showing 241252 / 350 reports
NANOREMOTE: Google Drive-Enabled APT Breach Targets Global Sectors in 2025
Impact· medium

NANOREMOTE: Google Drive-Enabled APT Breach Targets Global Sectors in 2025

In late 2025, security researchers discovered a sophisticated cyber-espionage campaign leveraging a new Windows backdoor known as NANOREMOTE. This malware, attributed to the Chinese-linked threat cluster REF7707 (also called Jewelbug), exploited the Google Drive API for covert command-and-control and data exfiltration. Driven by a loader mimicking legitimate security software, the attack targeted government, defense, telecommunications, education, and aviation organizations across Southeast Asia and South America. NANOREMOTE's powerful features supported reconnaissance, file operations, and encrypted communications, enabling stealthy operations and persistent access for attackers. The initial infection vector remains unknown, but the malware's modular task management and file transfer facilities allowed efficient data theft and staged payload delivery undetected by many security controls. This incident exemplifies emerging threat trends where advanced persistent threat actors abuse benign, widely trusted cloud APIs to hide their operations. As similar tradecraft spreads, organizations face heightened risks of deep lateral movement, multifaceted data breaches, and regulatory scrutiny. Continuous improvements in east-west security and traffic visibility are critical as attackers innovate with cloud-native exfiltration channels.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CISA Adds OSGeo GeoServer CVE-2025-58360 to Known Exploited Vulnerabilities List
Impact· low

CISA Adds OSGeo GeoServer CVE-2025-58360 to Known Exploited Vulnerabilities List

In December 2025, CISA added CVE-2025-58360, an Improper Restriction of XML External Entity Reference vulnerability in OSGeo GeoServer, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation in the wild. The vulnerability allows remote attackers to exploit XML parsing weaknesses to access sensitive data or execute arbitrary code by submitting malicious crafted XML to the GeoServer platform, which is widely used for geospatial data services. Malicious actors leveraging this flaw can bypass security controls, potentially leading to significant data breaches or operational disruption across organizations dependent on GeoServer. This incident highlights the increasing urgency of remediating software supply chain and core infrastructure vulnerabilities exploited in real-world attacks. The active exploitation of such high-impact flaws is driving regulatory entities and private organizations to re-examine patch management, incident response, and zero trust controls for critical applications.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical Siemens 2025 IAM Client TLS Flaw Exposes Industrial Environments
Impact· low

Critical Siemens 2025 IAM Client TLS Flaw Exposes Industrial Environments

In December 2025, Siemens disclosed a critical vulnerability (CVE-2025-40800) in the IAM Client component used across key products such as COMOS, NX, Simcenter, and Solid Edge. The flaw stemmed from improper validation of server certificates during TLS sessions, exposing organizations to potential Man-in-the-Middle (MitM) attacks by unauthenticated remote attackers. Impacting deployments globally within the critical manufacturing sector, the vulnerability received a CVSS v4 base score of 9.1, reflecting its high risk. While patches are available for most products, a fix for COMOS V10.6 was unavailable at disclosure. This incident highlights ongoing risks from certificate handling errors, which remain common initial access vectors. As industrial networks become more interconnected, failures in basic cryptographic hygiene, especially in authentication mechanisms, are increasingly targeted by sophisticated attackers leveraging supply chain or network-layer attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Multi-APT Exploitation of WinRAR CVE-2025-6218: A Recurring Supply Chain Risk
Impact· medium

Multi-APT Exploitation of WinRAR CVE-2025-6218: A Recurring Supply Chain Risk

In mid to late 2025, a critical vulnerability in WinRAR (CVE-2025-6218), enabling path traversal and arbitrary code execution on Windows systems, was exploited by multiple sophisticated threat groups. Notably, GOFFEE, Bitter APT (APT-C-08), and the Russian state-linked Gamaredon leveraged spear-phishing emails with booby-trapped RAR archives to compromise targets, including Ukrainian government, South Asian organizations, and others. Attackers used malicious archives to persistently install remote access malware, capable of keylogging, data exfiltration, and credential theft, while some incidents involved destructive attacks deploying wiper malware. The vulnerability was patched in June 2025, but active exploitation continued through the year, forcing urgent defensive measures across critical sectors. This incident highlights the rapid weaponization of newly disclosed vulnerabilities by nation-state and criminal groups, as well as the challenges organizations face in managing unstructured file transfer risks. The coordinated exploitation across regions and APTs underscores an upward trend in supply chain and endpoint software attacks, increasing regulatory and operational urgency to close patching and phishing resilience gaps.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
PCIe Encryption Vulnerabilities Disclosed: 2025 Hardware Security Risks
Impact· high

PCIe Encryption Vulnerabilities Disclosed: 2025 Hardware Security Risks

In December 2025, three critical hardware vulnerabilities were disclosed in the Peripheral Component Interconnect Express (PCIe) Integrity and Data Encryption (IDE) protocol, impacting PCIe Base Specification Revision 5.0 and newer systems. These vulnerabilities—CVE-2025-9612, CVE-2025-9613, and CVE-2025-9614—enable local attackers with physical or low-level access to manipulate encrypted traffic, cause information disclosure, escalate privileges, or disrupt services. Affected products include select Intel Xeon and AMD EPYC processor lines. The flaws are notable for potentially undermining the core security objectives of IDE, especially in environments relying on trusted execution and encrypted data flows. This disclosure is particularly relevant as hardware-level vulnerabilities are increasingly leveraged by attackers seeking to evade conventional endpoint and network security controls. The need for integrity in encrypted data pathways is surging amid rising adoption of zero trust and compliance mandates, underscoring the urgency of prompt firmware patches and adherence to updated PCIe standards.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Russian State-Backed Cyberattack Hits US Critical Infrastructure: Lessons from 2024
Impact· high

Russian State-Backed Cyberattack Hits US Critical Infrastructure: Lessons from 2024

In 2024, U.S. authorities charged Ukrainian national Victoria Dubranova for her alleged involvement in Russian state-sponsored cyberattacks targeting critical infrastructure across the U.S. and allied nations. Dubranova is accused of collaborating with CyberArmyofRussia_Reborn (CARR) and NoName057(16), groups funded by Russian entities, to launch coordinated distributed denial of service (DDoS) and destructive intrusions. The attacks compromised water systems, food processing facilities, government bodies, and nuclear regulatory sites, resulting in water system sabotage, meat contamination, and emergency evacuations. Investigations revealed evolving tactics and recruitment methods, including custom malware (DDoSia) and incentivized hacktivist participation. This case underscores the escalating threat from state-backed cybercriminals targeting operational technology and essential services. As hacktivists innovate with new tools and social engineering, the risk to public utilities remains severe, prompting a regulatory and industry emphasis on network segmentation, reduced internet exposure, and proactive cyber defense.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
U-Boot Bootloader Flaw Threatens Global Manufacturing and Critical Infrastructure
Impact· low

U-Boot Bootloader Flaw Threatens Global Manufacturing and Critical Infrastructure

In December 2025, a critical vulnerability (CVE-2025-24857) was disclosed in U-Boot, a widely-used bootloader for embedded systems, impacting all versions prior to 2017.11 and several Qualcomm chipsets. The flaw—improper access control for volatile memory containing boot code—allowed an attacker with local access to execute arbitrary code at boot, posing significant risk to devices across essential sectors including energy, communications, manufacturing, healthcare, and more. No active exploitation has been reported, but the vulnerability could undermine device integrity and operational security in globally deployed critical infrastructure systems. Mitigations include upgrading to the latest U-Boot version and implementing strict physical and network isolation measures. This incident underlines the persistent risk posed by supply chain and firmware vulnerabilities in critical infrastructure. With IoT and embedded device ubiquity rising, attackers are increasingly targeting low-level firmware to achieve persistence or bypass security, heightening regulatory scrutiny and emphasizing the need for proactive vulnerability management and secure device lifecycle practices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Poland Arrests Ukrainians in 2024 Espionage Cyber Incident
Impact· low

Poland Arrests Ukrainians in 2024 Espionage Cyber Incident

In June 2024, Polish authorities arrested three Ukrainian nationals accused of using sophisticated hacking equipment to carry out cyberattacks targeting Polish IT systems, with particular emphasis on the theft of 'computer data of particular importance to national defense.' The suspects were apprehended while allegedly attempting to damage government information technology infrastructure, utilizing encrypted communications and advanced attack tools likely designed to evade monitoring and facilitate data exfiltration. The incident underscores heightened tensions in the region and reveals vulnerabilities within national networks, with Polish law enforcement quickly intervening to mitigate further impact. This breach is emblematic of a broader escalation in nation-state cyber operations across Europe, featuring cross-border actors relying on advanced techniques to infiltrate sensitive targets. The event highlights the urgent need for robust east-west traffic security, encrypted communications, and real-time anomaly detection controls to guard national interests and critical IT environments.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(low)
Read Report
Iranian APT 'MuddyWater' Launches UDPGangster Backdoor in Multi-Nation Espionage Campaign
Impact· low

Iranian APT 'MuddyWater' Launches UDPGangster Backdoor in Multi-Nation Espionage Campaign

In late 2025, the Iranian cyber espionage group MuddyWater launched a targeted campaign against organizations in Turkey, Israel, and Azerbaijan using a novel backdoor dubbed UDPGangster. The malware leveraged UDP-based command-and-control channels to enable remote management of infected systems while evading traditional network detection techniques. Attacks typically began via spear-phishing emails containing malicious attachments or links, granting the attackers a foothold in victim environments and facilitating lateral movement and data exfiltration. Fortinet FortiGuard Labs was among the first to document the malware and its unique communication characteristics. The campaign highlighted substantial risks to critical sectors and national security in the affected countries. This incident exemplifies rising threat actor sophistication—specifically, abuse of obscure protocols like UDP for covert C2—and underscores the strategic evolution of Iranian groups. Its tactics reflect broader cyber espionage trends across the Middle East and signal urgent needs for advanced lateral movement detection and zero trust controls.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CISA Issues Stark Warning on Ongoing Brickstorm Backdoor Attacks
Impact· medium

CISA Issues Stark Warning on Ongoing Brickstorm Backdoor Attacks

In early 2024, the Cybersecurity and Infrastructure Security Agency (CISA) issued a warning regarding sustained state-sponsored attacks targeting VMware vSphere environments, attributed to China-linked advanced persistent threat (APT) groups. These actors deployed the 'Brickstorm' backdoor to compromise government and technology sector organizations, exploiting vulnerabilities to achieve persistence and lateral movement within affected networks. The intrusion enabled attackers to bypass security controls, maintain privileged access, and exfiltrate sensitive information, highlighting a persistent threat targeting virtualization infrastructure. This incident is notable as it reflects a concerning evolution in attacker tactics, specifically the abuse of virtualization platforms as an entry vector for espionage. The ongoing campaign underscores the urgent need for enhanced detection, segmentation, and defense against stealthy operations in hybrid and cloud environments.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Major Insider Attack Wipes 96 US Government Databases: Lessons for 2024
Impact· high

Major Insider Attack Wipes 96 US Government Databases: Lessons for 2024

In June 2024, two Virginia-based former federal contractors were accused of orchestrating a significant insider attack after being terminated from their government roles. Prosecutors allege the brothers conspired to steal sensitive information and deliberately wiped 96 critical government databases, severely disrupting several agencies' operations. The attack exploited their privileged access, allowing them to bypass existing controls and inflict lasting operational and data loss consequences. This incident highlights how trusted insiders with sufficient technical skills and unresolved grievances can weaponize their access against public-sector organizations, exposing gaps in monitoring and segmentation. Insider-powered destructive attacks are on the rise globally, targeting both public and private sectors with increasing sophistication. In a climate of heightened regulatory expectations and increasing adoption of zero trust models, this incident demonstrates the urgency to strengthen monitoring, privileged access controls, and anomaly detection to detect and prevent similar threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
How MuddyWater Used a Snake Game to Breach Israeli Networks in 2024
Impact· medium

How MuddyWater Used a Snake Game to Breach Israeli Networks in 2024

In early 2024, Iranian state-sponsored APT MuddyWater launched a series of cyberattacks against Israeli organizations using a novel evasion method involving a modified version of the classic Snake mobile game. Attackers embedded malicious code within the game to establish a covert communication channel and facilitate lateral movement within compromised networks. Initial access was likely achieved through phishing emails, followed by deployment of specially crafted files to disguise data exfiltration activities. The campaign resulted in unauthorized access to sensitive data and disruption of critical business operations for targeted Israeli entities. This incident highlights a growing trend of threat actors leveraging benign-looking applications and creative techniques to bypass traditional security controls. The use of retro games as a decoy demonstrates that sophisticated attackers are continually adapting, raising the bar for detection and forensic analysis across industries.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports