The Containment Era is here. →Explore

Industry Category

Defense/Space

Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.

350 threat reports
Page 22 of 30

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Defense/Space Threat Reports

Showing 253264 / 350 reports
How Iran's MuddyWater APT Used Memory-Only Malware for Stealthy Espionage in 2024
Impact· medium

How Iran's MuddyWater APT Used Memory-Only Malware for Stealthy Espionage in 2024

In early 2024, the Iranian state-backed actor MuddyWater significantly evolved its tradecraft by deploying a new memory-only loader, codenamed Fooder, and the stealthy 'MuddyViper' backdoor in espionage campaigns. The group, previously known for noisy operations, shifted to fileless malware and in-memory tactics targeting government and critical infrastructure networks in the Middle East and beyond. These attacks enabled extended persistence, facilitated lateral movement, and were effective at evading traditional endpoint detection and response solutions. As a result, targeted organizations faced serious risk of data theft and operational compromise before the campaign was exposed by security researchers. This incident marks a growing trend of threat actors adopting advanced memory-only and fileless TTPs to avoid detection. The operational upgrade by MuddyWater highlights increased sophistication among nation-state adversaries and reinforces the urgent need for advanced threat detection and stronger east-west network controls.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Lazarus APT’s Remote-Worker Ruse: How North Korean Hackers Infiltrated via Trusted IT Contractors
Impact· low

Lazarus APT’s Remote-Worker Ruse: How North Korean Hackers Infiltrated via Trusted IT Contractors

In late 2025, cybersecurity researchers from BCA LTD, NorthScan, and ANY.RUN captured an active infiltration by North Korea’s Lazarus Group (specifically the Famous Chollima division) leveraging remote IT workers implanted in Western organizations. This highly coordinated campaign used the appearance of legitimate remote workers—often hired via freelance and IT staffing platforms—to discreetly gain access to internal systems, exfiltrate sensitive data, and facilitate the deployment of malware directly through trusted accounts. The operation showcased sophisticated methods for circumventing east-west traffic controls and exploiting trusted relationships, posing a direct risk to organizations’ hybrid and cloud environments. This breach exemplifies the quick evolution of nation-state threat actors exploiting global remote work and cloud-native architectures. As the use of remote staff and contractors surges, organizations face mounting pressure to implement zero trust controls and granular segmentation to prevent well-resourced APTs from leveraging trusted credentials for deep access and stealthy lateral movement.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
How Iran Blended Cyber and Kinetic Strikes: The 2024 Critical Infrastructure Attack
Impact· medium

How Iran Blended Cyber and Kinetic Strikes: The 2024 Critical Infrastructure Attack

In early 2024, Iranian state-sponsored threat actors coordinated sophisticated cyber-attacks in parallel with kinetic strikes targeting maritime and land-based assets in the Middle East. Leveraging advanced reconnaissance and lateral movement within targeted networks, attackers exploited encrypted and unencrypted traffic flows to identify critical systems and facilitate precision missile and drone attacks. These operations, often timed to coincide with physical assaults, compromised internal infrastructure, leading to service disruption, operational delays, and data exfiltration impacting both regional governments and commercial enterprises. This incident highlights a rapidly evolving threat landscape where nation-state adversaries integrate cyber intrusions with physical warfare. The tactical use of data from east-west traffic, paired with real-time targeting for kinetic operations, signals the urgent need for organizations to elevate network segmentation, encryption standards, and visibility to meet new regulatory and threat actor challenges.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Rockwell Automation Arena Simulation Buffer Overflow (2025): Risks to Industrial Control Systems
Impact· medium

Rockwell Automation Arena Simulation Buffer Overflow (2025): Risks to Industrial Control Systems

In November 2025, Rockwell Automation disclosed a stack-based buffer overflow vulnerability (CVE-2025-11918) in its Arena Simulation software (versions 16.20.10 and earlier). The flaw, reported by security researcher Michael Heinzl, enables local attackers to execute arbitrary code by tricking users into opening a malicious DOE file. While the vulnerability is not exploitable remotely, it presents a significant risk to organizations leveraging Arena for critical manufacturing automation, especially when adequate segmentation and endpoint security controls are lacking. No public exploitation has been reported to date, and the vendor has released a security update to address the issue. This incident is a reminder of the persistence of file parsing vulnerabilities in industrial software, which continue to enable initial compromise via local vectors like engineered files or insider threats. The increase in similar vulnerabilities and the possibility of operational technology (OT) system breaches intensify the call for zero-trust and defense-in-depth strategies within the manufacturing sector.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SiRcom Vulnerability Exposes Critical Siren Systems to Hijack (2025)
Impact· high

SiRcom Vulnerability Exposes Critical Siren Systems to Hijack (2025)

In November 2025, a critical vulnerability (CVE-2025-13483) was disclosed in SiRcom SMART Alert (SiSA), a central emergency alert management system used globally in emergency services, government, and defense sectors. The flaw, due to missing authentication for critical API functions, enabled unauthenticated attackers to access restricted backend operations. Successful exploitation could allow remote manipulation and activation of emergency sirens, posing wide-reaching operational and safety risks to affected communities. The vulnerability, assigned a CVSS v4 score of 8.8, was initially reported by Microsec researcher Souvik Kandar. This incident highlights the persistent risks posed by missing authentication in critical infrastructure applications. With remote exploitation possible and attackers’ interest in manipulating physical environments on the rise, it underscores the urgent need for robust authentication, especially amid compliance and regulatory tightening in the critical infrastructure sector.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Google Uncovers BadAudio Malware in Chinese APT24 Espionage Campaign
Impact· low

Google Uncovers BadAudio Malware in Chinese APT24 Espionage Campaign

In early 2024, Google’s Threat Analysis Group uncovered a sophisticated, years-long cyber espionage campaign orchestrated by the China-linked APT24 threat group. The attackers leveraged a newly discovered malware dubbed BadAudio to infiltrate government agencies, research institutions, and select private organizations. Initial access was obtained via spear-phishing campaigns, progressing to persistent lateral movement within compromised environments. BadAudio’s deployment enabled covert data exfiltration over encrypted channels, evading standard security controls and providing unmatched visibility and persistence for the attackers. The incident highlights the advanced tradecraft and evolving toolsets in use by nation-state threat actors, with business impacts centered on the loss of sensitive data and the undermining of critical organizational trust. The exposure of BadAudio signals a notable escalation in cyber espionage tactics, utilizing bespoke malware and encrypted traffic to circumvent modern defenses. Organizations across sectors are at risk as threat groups adopt similar methods, prompting increased scrutiny from regulators and heightened awareness around securing east-west traffic and anomaly detection.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Iran-Linked Hackers Fuse Cyber Espionage and Kinetic Strikes with Ship AIS Breach
Impact· high

Iran-Linked Hackers Fuse Cyber Espionage and Kinetic Strikes with Ship AIS Breach

In November 2025, state-sponsored hackers tied to Iran conducted a sophisticated cyber operation targeting maritime assets by mapping Automatic Identification System (AIS) data of commercial ships transiting a volatile region. Advanced reconnaissance and cyber infiltration enabled the attackers to gather real-time ship movement and metadata, informing a coordinated missile strike days later. The breach demonstrated tight integration between cyber-enabled intelligence collection and traditional kinetic attacks, raising alarm within global shipping, defense, and infrastructure sectors. The incident highlights a dangerous evolution in the use of cyber capabilities to directly amplify physical-world conflict and disruption. The rapid fusion of cyber warfare with real-world military operations signals a new era of threats that transcend digital boundaries. As geopolitical tensions escalate and critical infrastructure remains vulnerable, robust cyber and operational defenses are imperative for organizations at risk of becoming targets in hybrid war campaigns.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
China-Backed PlushDaemon APT Leverages Network Devices for Advanced MitM Attacks (2024)
Impact· medium

China-Backed PlushDaemon APT Leverages Network Devices for Advanced MitM Attacks (2024)

In 2024, ESET researchers uncovered a sustained campaign by the China-linked PlushDaemon APT that targeted edge and network devices in government, telecommunications, and technology sectors, enabling advanced adversary-in-the-middle (AitM) attacks. PlushDaemon deployed a sophisticated network implant capable of intercepting, modifying, and redirecting encrypted and unencrypted traffic, allowing the threat actor to facilitate credential theft and covert surveillance. The operation exploited weak segmentation and insufficient east-west controls, compromising business operations and exposing sensitive communications to persistent espionage. This incident is particularly relevant as APTs increasingly leverage traffic interception at the network device layer, bypassing traditional endpoint security and highlighting urgent gaps in zero trust, segmentation, and encrypted traffic monitoring solutions.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Amazon Warns: MuddyWater Cyberattack Bridges Digital and Kinetic Warfare
Impact· medium

Amazon Warns: MuddyWater Cyberattack Bridges Digital and Kinetic Warfare

In June 2024, Amazon Threat Intelligence reported a sophisticated, nation-state cyberattack demonstrating the merging of cyber and kinetic warfare. The Iranian-backed MuddyWater group leveraged compromised CCTV infrastructure in Jerusalem to obtain real-time intelligence, directly enabling more precise missile strikes against physical targets. Attackers provisioned infrastructure and infiltrated CCTV feeds a month in advance, highlighting a deliberate and strategic approach to combining digital reconnaissance with physical attack vectors. Israeli authorities confirmed that this real-time data was used to adjust targeting during the incident, leading to heightened operational impact and escalating concerns for critical infrastructure operators. This incident underscores an alarming trend: cyber-espionage operations now increasingly serve as force multipliers for military actions. The blurred line between cyber and physical domains exemplifies an evolution in threat tactics, with nation-state actors exploiting enterprise networks as entry points for real-world impact. Security leaders must recognize this convergence and adapt defense and intelligence sharing accordingly.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Forces Rapid Patch of Fortinet Zero-Day Exploited in Real Attacks
Impact· low

CISA Forces Rapid Patch of Fortinet Zero-Day Exploited in Real Attacks

In June 2024, U.S. government agencies were urgently ordered by CISA to patch a critical vulnerability in Fortinet's FortiWeb web application firewall after it was discovered being exploited as a zero-day. Threat actors leveraged this flaw to bypass security controls, potentially gaining unauthorized access to sensitive government systems. The incident underscores the persistent targeting of network edge devices and highlights the risks associated with unpatched security infrastructure. The rapid CISA directive required agencies to address the exploit within seven days, reflecting the severe operational risk and potential for further compromise. This event demonstrates a rising focus on web application and perimeter device vulnerabilities by sophisticated adversaries, especially those exploiting zero-days. The urgency of the directive and the exploitation method signal a larger industry trend: attackers increasingly prioritize zero-day vulnerabilities in widely deployed security products to maximize impact and evade detection.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Iran-Nexus UNC1549 Targets Aerospace: 2024 Cyberattack Details
Impact· low

Iran-Nexus UNC1549 Targets Aerospace: 2024 Cyberattack Details

In early 2024, the Iranian-aligned threat actor group identified as UNC1549 orchestrated targeted cyberattacks against aerospace and defense organizations across the US, Israel, UAE, Qatar, Spain, and Saudi Arabia. Researchers discovered that the group leveraged sophisticated spear-phishing campaigns and custom malware implants to infiltrate sensitive networks, focusing primarily on exfiltrating confidential intellectual property and operational data. The campaign showcased advanced persistence techniques and bypassed standard security controls, leading to operational disruption and heightened espionage risk for impacted organizations. These attacks highlight a broader trend of nation-state threat actors increasingly focusing on strategic sectors with evolving tools and tactics. The targeting of multiple geographies underscores the global nature of aerospace security risks and pressing regulatory and compliance expectations.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Iranian Espionage Campaign Uses DEEPROOT & TWOSTROKE in Aerospace and Defense Breach (2025)
Impact· medium

Iranian Espionage Campaign Uses DEEPROOT & TWOSTROKE in Aerospace and Defense Breach (2025)

In late 2025, an Iranian-linked threat group known as UNC1549 targeted aerospace and defense organizations in the Middle East, deploying custom backdoors named TWOSTROKE and DEEPROOT. The attackers gained access through spear-phishing and strategic web compromises, establishing persistent footholds and enabling sustained espionage operations. Google-owned Mandiant attributed the campaign to advanced initial access and lateral movement techniques, allowing the threat actors to blend into legitimate network activity while exfiltrating sensitive intellectual property and operational data. The campaign underscored weaknesses in internal segmentation, encrypted traffic oversight, and anomaly detection within high-value verticals. This incident highlights an uptick in sophisticated espionage attacks on critical infrastructure using tailored malware and stealthy, post-compromise tactics. The use of novel backdoors and multi-stage intrusion campaigns demonstrates an evolving threat landscape, emphasizing the need for deeper defense in depth and zero trust approaches among organizations handling sensitive data.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports