The Containment Era is here. →Explore

Industry Category

Defense/Space

Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.

350 threat reports
Page 28 of 30

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Defense/Space Threat Reports

Showing 325336 / 350 reports
Phantom Taurus: Stealth China-Linked APT Breaches Global Governments in 2025
Impact· low

Phantom Taurus: Stealth China-Linked APT Breaches Global Governments in 2025

Between early 2023 and mid-2025, government and telecommunications agencies spanning Africa, the Middle East, and Asia became the targets of a previously undocumented China-linked nation-state threat group, dubbed Phantom Taurus. The group leveraged stealthy, custom malware and encrypted command-and-control channels to infiltrate ministries of foreign affairs, embassies, and military operations, maintaining persistent access to sensitive networks for extended periods. Attackers employed advanced lateral movement and living-off-the-land techniques, hindering detection and enabling covert intelligence collection. Exfiltrated data included diplomatic communications and potentially classified material, posing severe geopolitical and operational risks to the affected organizations. This incident underscores a rising trend of sophisticated China-aligned APT campaigns exploiting stealth malware, encrypted traffic, and advanced cloud evasion to breach strategic targets. As state-sponsored espionage continues to escalate, organizations must strengthen zero trust controls, real-time traffic inspection, and segmented multicloud defenses to counter evolving nation-state tactics.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Phantom Taurus: Inside the 2025 Chinese APT NET-STAR Espionage Breach
Impact· medium

Phantom Taurus: Inside the 2025 Chinese APT NET-STAR Espionage Breach

In early 2025, security researchers uncovered a sophisticated espionage campaign attributed to a newly recognized Chinese nation-state actor, Phantom Taurus. Operating since at least late 2022, the group prioritized stealth and advanced tactics, primarily targeting government and telecommunications entities across Africa, the Middle East, and Asia. Attackers leveraged a novel, highly covert malware suite—NET-STAR—capable of remaining fileless within IIS web servers and facilitating persistent, encrypted exfiltration of sensitive diplomatic, military, and geopolitical data. The operation exploited custom-developed tools to move from email theft to direct database compromise, employing in-memory web backdoors and evasion techniques like timestomping and security mechanism bypasses to avoid detection and maintain long-term access. The exposure of Phantom Taurus and the NET-STAR suite highlights an escalating trend of targeted, stealthy cyber espionage campaigns against critical infrastructure by advanced persistent threat (APT) actors. This incident underscores the urgent need for organizations to strengthen east-west security visibility, enforce zero trust principles, and regularly review controls against constantly evolving attacker tradecraft.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Threat Insights: Nation-State Exploitation of Cisco ASA Zero-Days (ArcaneDoor 2025)
Impact· medium

Threat Insights: Nation-State Exploitation of Cisco ASA Zero-Days (ArcaneDoor 2025)

In September 2025, Cisco disclosed that a sophisticated nation-state threat actor, linked to the ArcaneDoor campaign, exploited multiple zero-day vulnerabilities in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. These attackers targeted government networks and critical infrastructure globally, leveraging CVE-2025-20333 and CVE-2025-20362, which enabled remote code execution, persistent malware installation, and data exfiltration. Advanced evasion tactics allowed the attackers to disrupt device logging and remain undetected for extended periods, while the deployment of custom malware such as RayInitiator and LINE VIPER provided long-term backdoor access to compromised environments. This case highlights growing trends in state-sponsored exploitation of perimeter devices and demonstrates how quickly nation-state TTPs can proliferate to broader criminal groups. The campaign triggered urgent mandates from CISA and NCSC for organizations—especially in the public sector—to patch and monitor edge infrastructure, emphasizing the escalating risk from zero-day vulnerabilities and the increasing sophistication of attacker methods.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Nation-State Zero-Day Attacks Breach Cisco Firewalls in 2024
Impact· medium

Nation-State Zero-Day Attacks Breach Cisco Firewalls in 2024

In mid-2024, an advanced nation-state threat group—tracked as UAT4356 (Talos) and Storm-1849 (Microsoft)—launched a widespread espionage campaign exploiting newly discovered zero-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) in Cisco Adaptive Security Appliance (ASA) firewalls. These attackers gained persistent, full-device control by chaining zero-days, disabling logging, evading defenses, and implanting custom malware on federal networks, achieving potential data exfiltration and establishing long-term persistence beyond standard remediation steps. The Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive mandating immediate federal agency response, including mandatory patching or device disconnection. This attack underscores the evolving sophistication and urgency of supply chain and perimeter device threats. As zero-day exploitation targeting network infrastructure escalates and aligns with global power competition, organizations must prioritize detection, segmented defense, and rapid vulnerability management to safeguard high-value assets and comply with emerging federal cyber mandates.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Cisco Zero-Day Exploitation: Federal Agencies Targeted in Prolonged Nation-State Attack
Impact· medium

Cisco Zero-Day Exploitation: Federal Agencies Targeted in Prolonged Nation-State Attack

In 2024, a series of sophisticated attacks leveraging zero-day vulnerabilities in Cisco firewalls targeted U.S. federal agencies and critical infrastructure. Initial reconnaissance began in November 2023, with attackers exploiting unknown flaws at the network edge to gain persistent, low-profile access—including read-only memory modifications. The breach remained undetected for months as Cisco and federal authorities investigated, coordinated patches, and ultimately prompted an emergency CISA directive. Despite working closely with vendors on remediation, the scope required urgent government intervention, with potential exposure impacting hundreds of Cisco firewalls across key sectors. These attacks underscore growing nation-state interest in exploiting core network devices for stealthy espionage. With similar tactics on the rise, the breach brings renewed urgency for rapid threat detection, zero-trust policy enforcement, and timely vulnerability disclosures across government and industry.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
RedNovember: Chinese APT Weaponizes Public PoCs for Rapid Government Espionage in 2024
Impact· medium

RedNovember: Chinese APT Weaponizes Public PoCs for Rapid Government Espionage in 2024

In 2024, a state-aligned Chinese advanced persistent threat (APT) group known as RedNovember, or Storm-2077, conducted an extensive cyber espionage campaign targeting high-profile organizations, especially government agencies and technology firms across Asia and Europe. Rather than developing custom exploits or zero-days, RedNovember systematically monitored security researcher disclosures and quickly weaponized publicly released proof-of-concept (PoC) vulnerability exploits to compromise edge devices such as VPN gateways, firewalls, and remote access platforms. Notable targets included Taiwan’s technology sector and Fijian government entities, coinciding with periods of heightened geopolitical activity. The group's attacks enabled deep network intrusion and intelligence exfiltration in line with Chinese state interests. This campaign exemplifies a fast-growing threat: sophisticated threat actors operationalize public vulnerability disclosures before organizations can patch, increasing the risk of high-impact breaches. The reliance on open-source PoCs reduces barriers to entry, accelerates attacks, and puts pressure on organizations to shorten vulnerability patch cycles.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Federal Agency Breach: GeoServer Zero-Day Exposes Gaps in 2024 Cyber Defense
Impact· medium

Federal Agency Breach: GeoServer Zero-Day Exposes Gaps in 2024 Cyber Defense

In July 2024, attackers exploited CVE-2024-36401—a critical remote code execution vulnerability in the open source GeoServer mapping server—less than two weeks after public disclosure, to breach a US federal civilian executive branch (FCEB) agency. The adversaries gained initial access to public-facing GeoServer instances, subsequently moving laterally through the network using living-off-the-land techniques, dropping web shells (including China Chopper), leveraging brute force and privilege escalation attacks, and establishing command-and-control with open-source tools. Due to delayed patching and inadequate incident response, attackers remained undetected for three weeks, compromising additional servers and extracting sensitive information related to geospatial data and internal credentials. This incident exemplifies the growing risk posed by rapid, post-disclosure exploitation of critical vulnerabilities, particularly those affecting widely deployed open source software. The breach also highlights persistent gaps in vulnerability management, security operations, and incident response readiness at major organizations, driving new urgency around patch timeliness and comprehensive monitoring.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
RTX Ransomware Attack Disrupts Major European Airports in 2025
Impact· high

RTX Ransomware Attack Disrupts Major European Airports in 2025

In September 2025, RTX Corporation (formerly Raytheon Technologies) experienced a significant ransomware attack targeting its Collins Aerospace Multi-User System Environment (MUSE) passenger processing platform. The ransomware—suspected to be from the Hardbit or Loki ransomware families—caused widespread operational disruptions, leading to flight cancellations and delays at major European airports including London Heathrow, Brussels, Cork, Dublin, and Berlin. The attack was detected on September 19th, prompting RTX to initiate a full incident response, notify authorities, and deploy technical mitigations across affected customer networks. Law enforcement arrested a UK-based suspect linked to the attack, underscoring the event’s criminal intent and sophistication. This incident highlights a rising trend of ransomware groups targeting critical infrastructure and supply chain applications, often by leveraging commodity Ransomware-as-a-Service (RaaS) tools. It also signals a shift in attacker behavior towards less sophisticated malware, which can still yield significant operational disruption due to integrated, shared technology platforms in aviation and other sectors.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
RedNovember: 2025 Chinese State Cyber Espionage Campaign Hits Global Governments
Impact· low

RedNovember: 2025 Chinese State Cyber Espionage Campaign Hits Global Governments

In mid-2025, a Chinese state-sponsored threat group known as RedNovember (previously tracked as TAG-100) orchestrated a widespread cyber espionage campaign targeting government and private sector organizations across Africa, Asia, North America, South America, and Oceania. The attackers leveraged sophisticated tools including the Pantegana backdoor and Cobalt Strike to establish persistence, perform lateral movement, and exfiltrate sensitive data. Entry vectors included spear-phishing emails and exploitation of known network vulnerabilities, allowing RedNovember to stealthily compromise high-value systems and harvest intelligence for extended periods before discovery. The impact included unauthorized access to confidential government documents and disruption of critical data workloads. This incident underscores the persistent evolution of state-sponsored attack tactics, with RedNovember employing advanced, evasive techniques and custom malware. The growing use of encrypted command-and-control traffic and living-off-the-land strategies sets a concerning precedent, especially for government agencies and regulated enterprises facing a surge in sophisticated espionage operations.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
How North Korean IT Workers Exposed the Next Insider Threat: Lessons from the 2025 Breach
Impact· high

How North Korean IT Workers Exposed the Next Insider Threat: Lessons from the 2025 Breach

In 2025, organizations across multiple industries discovered they had inadvertently hired North Korean IT workers—an emerging form of insider threat tied to sophisticated fraud and sanctions evasion tactics. These workers, embedded via remote roles and often identified through HR anomalies, funneled their earnings back to the North Korean regime, potentially exposing companies and their payment processors to strict sanctions liability. Initial detections stemmed from mismatched credentials or suspicious onboarding behaviors, with security and legal teams realizing the scope only after covert employment periods. Business impact included urgent compliance, forensic device recovery, and reputational risk, with legal exposure for both inadvertent payments and regulatory reporting lapses. This incident highlights an evolving threat landscape: state-sponsored employment fraud now overlaps with insider threat and compliance failures. Increased scrutiny from regulators, combined with ongoing geopolitical and cyber risk, is driving rapid change in how companies monitor, vet, and respond to workforce-related security incidents.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Iranian APT Extends Reach: 2024 Nimbus Manticore Malware Hits Europe
Impact· medium

Iranian APT Extends Reach: 2024 Nimbus Manticore Malware Hits Europe

In early 2024, a sophisticated Iran-backed threat group known as “Nimbus Manticore” launched targeted cyberattacks against several European organizations using enhanced variants of its custom malware. The attackers leveraged spear-phishing emails embedding malicious attachments as their initial access vector, resulting in the deployment of advanced payloads that enabled persistent access and lateral movement within affected networks. Once inside, the group utilized encrypted communication channels and east-west movement to exfiltrate sensitive data and evade common detection mechanisms. The incident has caused operational disruptions and triggered regulatory notifications in multiple EU member states. This breach illustrates a strategic expansion of Iran-linked APT operations beyond their traditional region, pointing to escalating risks for European enterprises. The exposed techniques underscore the necessity for advanced detection, robust internal segmentation, and regulatory alignment as attackers increasingly shift tactics to bypass perimeter controls.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Gamaredon & Turla: Joint APT Campaign Strikes Ukraine in 2025
Impact· medium

Gamaredon & Turla: Joint APT Campaign Strikes Ukraine in 2025

In early 2025, a previously unseen collaboration between advanced persistent threat groups Gamaredon and Turla was discovered in Ukraine. Utilizing ESET telemetry, researchers identified co-compromises in which Gamaredon provided initial access using spearphishing and malicious PowerShell-based tools (such as PteroGraphin and PteroOdd), allowing Turla to deploy its exclusive Kazuar backdoor on select high-value targets. The attacks, attributed to Russian FSB-linked groups, targeted governmental entities and leveraged encrypted channels, PowerShell scripting, and multi-stage malware delivery via compromised web services and cloud platforms. Impact was mainly concentrated on the potential exfiltration of sensitive national intelligence. This incident underscores a growing trend of threat actor collaboration within nation-state cyber operations, blurring lines between operational roles and increasing attack efficiency. The overlapping TTPs and use of novel access and persistence mechanisms signal heightened complexity in the Eastern European threat landscape, demanding urgent operational and strategic defensive improvements.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports