The Containment Era is here. →Explore

Industry Category

Defense/Space

Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.

350 threat reports
Page 24 of 30

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Defense/Space Threat Reports

Showing 277288 / 350 reports
Kimsuky Unleashes HTTPTroy Backdoor in Targeted Attack on South Korea
Impact· low

Kimsuky Unleashes HTTPTroy Backdoor in Targeted Attack on South Korea

In early 2024, the North Korean state-sponsored group Kimsuky launched a targeted cyberespionage campaign using a new backdoor called HTTPTroy, aimed at South Korean users. Leveraging sophisticated obfuscation and advanced anti-analysis features, Kimsuky distributed the malware primarily via phishing emails containing malicious attachments. Once installed, HTTPTroy enabled the attackers to execute commands remotely and exfiltrate sensitive data while evading detection. The campaign underscores the increasing technical capabilities of North Korean APT groups and their persistent focus on South Korean government, critical infrastructure, and research sectors. This incident highlights an accelerating trend of advanced persistent threats deploying stealthy, resilient malware to bypass traditional defenses. As attackers evolve their toolchains, organizations—especially in frequently targeted regions—face heightened risk from espionage operations that blend social engineering, evasion tactics, and custom malware.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
F5’s 2023 Supply Chain Breach: When Nation-State Attacks Undermine U.S. Cyber Readiness
Impact· medium

F5’s 2023 Supply Chain Breach: When Nation-State Attacks Undermine U.S. Cyber Readiness

In October 2023, a significant nation-state supply chain attack targeted F5, a leading provider of network and application security solutions. Threat actors believed to be linked to China successfully gained unauthorized access to F5's source code and undisclosed vulnerabilities, providing them with intimate knowledge required to craft advanced exploits capable of bypassing traditional security defenses. BIG-IP, F5's flagship product, is widely deployed by major enterprises, federal agencies, healthcare institutions, and utilities, making the impact of this breach exceptionally far-reaching. In response, CISA issued an emergency directive urging federal agencies to promptly patch vulnerable systems, citing the potential for cascading impacts across critical infrastructure. This incident is particularly relevant as it underscores the growing sophistication of supply chain attacks, where adversaries target foundational software providers instead of individual end-users. The breach comes amidst rising threats from nation-state actors and highlights the urgent need for proactive security controls, rapid patching, and improved cross-sector collaboration to strengthen cyber resilience.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Operation SkyCloak: Tor-Enabled OpenSSH Backdoor Infiltrates Defense Networks
Impact· low

Operation SkyCloak: Tor-Enabled OpenSSH Backdoor Infiltrates Defense Networks

In November 2025, a sophisticated cyber campaign dubbed 'Operation SkyCloak' was uncovered, targeting Russian and Belarusian defense sectors. Attackers distributed weaponized attachments via phishing emails, successfully implanting a persistent OpenSSH-based backdoor on compromised hosts. To conceal its activity, the malware leverages a customized Tor hidden service with obfs4 protocol, facilitating covert command-and-control and persistent unauthorized access. This campaign demonstrates advanced threat actor operational security, targeting high-value government and defense assets to enable espionage and data exfiltration. The use of Tor-enabled backdoors in defense-related attacks is surging, marking a shift towards more covert, untraceable threat tactics. This incident exemplifies the growing adoption of anonymized infrastructure by attackers to evade detection, highlighting urgent requirements for east-west traffic inspection, advanced threat detection, and zero trust segmentation for critical sectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(low)
Read Report
Lazarus Breaches UAV Sector: 2024 Cyberespionage Attack Analysis
Impact· low

Lazarus Breaches UAV Sector: 2024 Cyberespionage Attack Analysis

In early 2024, ESET researchers uncovered a targeted cyberespionage campaign orchestrated by the North Korea-aligned Lazarus Group against a prominent company in the Unmanned Aerial Vehicle (UAV) sector. The attackers leveraged the Operation DreamJob social engineering scheme, luring victims with fake job offers and delivering custom malware through malicious attachments. Once inside, Lazarus gained remote access, exfiltrated sensitive data, and attempted to move laterally across the compromised network, emphasizing the group's advanced targeting of critical aerospace technologies. This incursion exposed operational blueprints, intellectual property, and potentially sensitive communications, raising industry-wide alarm about advanced persistent threats targeting high-value sectors. This incident is especially relevant today due to increased targeting of defense and aerospace industries by state-sponsored actors using sophisticated social engineering paired with malware. The techniques seen in Operation DreamJob reflect a broader trend of highly-customized attacks utilizing credible lures and persistent denial detection tactics.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(low)
Read Report
North Korean Operatives Pose as IT Job Seekers to Infiltrate Western Companies
Impact· medium

North Korean Operatives Pose as IT Job Seekers to Infiltrate Western Companies

In 2023, multiple Western technology firms fell victim to a sophisticated insider threat campaign involving North Korean operatives posing as freelance IT job seekers. These actors used false identities and forged CVs to secure remote employment and gain access to sensitive corporate environments. Once inside, they leveraged their positions to siphon proprietary information, commit financial fraud, and, in some cases, facilitate broader cyber-espionage activities by collecting credentials and mapping internal systems. The impact spanned financial loss, reputation damage, and increased exposure to supply chain attacks. This incident highlights the growing trend of well-resourced nation-state actors exploiting remote work arrangements and third-party talent networks. As companies aggressively scale digital transformation and outsourcing, vigilance against social engineering and identity fraud is critical to mitigate the risk of covert infiltration and regulatory non-compliance.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Pixel KASLR Bypass: Linear Map Non-Randomization Threatens Android Kernel Security
Impact· low

Pixel KASLR Bypass: Linear Map Non-Randomization Threatens Android Kernel Security

In November 2025, security researchers from Google Project Zero disclosed a significant design flaw in the Linux kernel’s implementation of Kernel Address Space Layout Randomization (KASLR) on modern Android devices, specifically Google Pixel phones. The weakness stems from the lack of randomization in both the linear kernel mapping and the physical memory loading address of the kernel itself. As a result, attackers with an arbitrary read/write primitive could derive static kernel virtual addresses, bypassing KASLR protections without leaks—thereby making exploitation significantly easier and increasing the risk of privilege escalation and persistence. This incident underscores a broader industry challenge where operating system mitigations lag behind evolving attacker techniques. The exposure of predictable kernel virtual addresses on widely deployed Android devices highlights the urgency for stronger kernel randomization and renewed attention to memory safety for mobile platforms.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
UNC6384 Strikes: Diplomatic Espionage Campaign Hits Europe via Windows Exploits
Impact· low

UNC6384 Strikes: Diplomatic Espionage Campaign Hits Europe via Windows Exploits

In early 2024, advanced persistent threat group UNC6384 targeted multiple European diplomatic entities in a sophisticated cyber-espionage campaign. By leveraging highly convincing spear-phishing emails themed around the European Commission and NATO, attackers tricked foreign affairs officials into clicking malicious links crafted to exploit Windows vulnerabilities. Once compromised, victims' systems allowed for persistent access, resulting in unauthorized data exfiltration and significant risks to sensitive diplomatic communications. The attack underscores the vulnerability of trusted organizations to nation-state tactics and the dangers posed by zero-day Windows exploits in high-value targets. The incident highlights a growing trend of targeted attacks against governmental organizations, coinciding with increased geopolitical tension in Europe. As cyber threat actors continue to exploit social engineering and sophisticated malware, organizations must prioritize endpoint security, staff awareness, and aggressive detection measures to thwart emerging espionage campaigns.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(low)
Read Report
Insider at L3Harris Sells Cyber Exploits to Russian Broker in 2024 Breach
Impact· high

Insider at L3Harris Sells Cyber Exploits to Russian Broker in 2024 Breach

In early 2024, Peter Williams, a former executive at L3Harris Trenchant, a U.S. defense contractor, pleaded guilty to stealing and illicitly selling confidential cyber exploit information to a Russian broker. The insider utilized privileged access to exfiltrate sensitive data on cybersecurity vulnerabilities and offensive research, subsequently marketing this intelligence to foreign entities, including actors associated with the Russian cyber underground. The breach exposed L3Harris Trenchant's internal detection gaps, ultimately triggering a federal investigation and leading to Williams' prosecution in U.S. District Court. This incident underscores the growing threat posed by insider actors within critical infrastructure and defense sectors. It highlights the need for advanced detection, segmentation, and strict policy enforcement to counter the insider risk—especially as nation-state and organized crime demand for zero-day vulnerabilities and advanced cyber tools continues to escalate.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Siemens 2025: Type Confusion RCE Threatens HyperLynx & Industrial Edge Security
Impact· medium

Siemens 2025: Type Confusion RCE Threatens HyperLynx & Industrial Edge Security

In October 2025, Siemens disclosed a critical vulnerability (CVE-2025-6554) affecting HyperLynx and Industrial Edge App Publisher products. The flaw, rooted in type confusion within the V8 JavaScript engine (Google Chrome), enables remote attackers to execute arbitrary code via malicious HTML, particularly impacting vulnerable product versions used in worldwide critical manufacturing environments. For HyperLynx, exploitation requires local access, while Industrial Edge App Publisher is exploitable remotely with low complexity, posing a substantial risk to integrity and confidentiality. Siemens and CISA jointly advised immediate updates and best-practice mitigations. This incident highlights a growing trend of supply chain and third-party component vulnerabilities impacting industrial control systems, particularly as attackers increasingly target embedded web technologies. The Siemens disclosure underlines ongoing regulatory and operational pressure to address software dependencies and enforce proactive patch management in critical infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Flags DELMIA Apriso Vulnerabilities: Urgent Action for Manufacturers
Impact· low

CISA Flags DELMIA Apriso Vulnerabilities: Urgent Action for Manufacturers

In October 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities affecting Dassault Systèmes DELMIA Apriso (CVE-2025-6204 and CVE-2025-6205) to its Known Exploited Vulnerabilities (KEV) Catalog following confirmed evidence of active exploitation in the wild. The code injection and missing authorization flaws present serious security bypass opportunities, allowing malicious actors to achieve unauthorized access and potentially execute arbitrary code. These weaknesses have become high-value targets for cyber attackers, potentially threatening sensitive enterprise manufacturing and operational data integrity across organizations that have yet to apply available patches. This incident underscores the growing trend of rapid exploitation of industrial software vulnerabilities by sophisticated threat actors. With regulatory frameworks such as BOD 22-01 placing increasing responsibility on federal agencies to remediate such vulnerabilities quickly, all organizations must adapt their patch management and risk processes to respond to elevated attacker velocity.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Iranian Hacker Training School Hit by Major Data Leak in 2024
Impact· high

Iranian Hacker Training School Hit by Major Data Leak in 2024

In June 2024, a significant data breach struck Ravin Academy, an institution linked to training operatives for Iran’s Ministry of Intelligence and Security (MOIS). Unknown attackers infiltrated Ravin Academy’s infrastructure and exfiltrated sensitive personal information on students, instructors, and internal operations. The breach exposed emails, full names, contact info, assignment details, and evidence of the academy’s ties to cyberespionage. Responsibility was claimed by hacktivists aiming to publicly reveal Iranian cyber capabilities. The school is believed to have failed in securing internal East-West traffic, and evidence suggests lack of robust threat detection or network segmentation allowed attackers to maintain persistence long enough to extract substantial records. The breach is under investigation, but sensitive intelligence operations may have been compromised. This incident draws renewed focus on “learning supply chain” vulnerabilities: attacker interest in targeting not just state actors, but their feeder institutions and ecosystems. Such breaches underscore mounting regulatory concern over insider risk, inadequate segmentation, and the risks of unencrypted internal communications in institutions developing offensive cyber capabilities.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
L3Harris Insider Breach: Zero-Day Exploits Sold to Russian Broker in 2024
Impact· high

L3Harris Insider Breach: Zero-Day Exploits Sold to Russian Broker in 2024

In 2024, a former executive at defense contractor L3Harris, Peter Williams, pleaded guilty to stealing and selling eight zero-day cyber exploits to a Russian broker linked to Operation Zero. Williams exploited privileged access at Trenchant, an L3Harris subsidiary, to covertly extract software developed for the U.S. government. He sold these sensitive trade secrets between 2022 and 2024 for several million dollars in cryptocurrency, hiding the transactions through encrypted communications. The sale of these advanced cyber capabilities to an entity catering to Russian state clients exposed L3Harris to estimated damages of $35 million and raised concerns about offensive tools in adversarial hands. This case highlights the increasing risks posed by insider threats exploiting specialized knowledge in the cyber-arms marketplace. Recent trends show threat actors—often with national ties—actively pursuing zero-day exploits via brokers, making supply chain trust and internal controls critical concerns for organizations managing sensitive cyber assets.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports