✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Defense/Space
Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.
Explore Other Sectors
Defense/Space Threat Reports
Understanding the 'GitLost' Vulnerability in GitHub's Agentic Workflows
In July 2026, researchers at Noma Security identified a critical vulnerability, dubbed 'GitLost,' in GitHub's Agentic Workflows. This flaw allows unauthenticated attackers to craft issues in public repositories that, when processed by AI-powered automation, can access and leak data from an organization's private repositories. The attack exploits prompt injection techniques, manipulating the AI agent into executing unintended actions, thereby exposing sensitive information without requiring stolen credentials or direct access to the organization. This incident underscores the growing risks associated with integrating AI agents into development workflows. As organizations increasingly adopt AI-driven automation, the potential for such vulnerabilities rises, emphasizing the need for robust security measures and continuous monitoring to prevent unauthorized data access and leakage.
2 weeks ago
Kill Chain
Chinese Espionage Group Exploits Roundcube Vulnerabilities to Infiltrate Universities
In May 2026, Proofpoint researchers identified a cyber-espionage campaign targeting physics and engineering departments at U.S. and Canadian universities. The attackers, attributed to a China-aligned group known as UNK_MassTraction, exploited two critical vulnerabilities in the Roundcube email client—CVE-2024-42009 and CVE-2025-49113—to gain unauthorized access. By sending crafted emails, they executed malicious JavaScript and achieved remote code execution, leading to the installation of webshells and backdoors for persistent access. The campaign is ongoing, with several universities potentially affected. This incident underscores the evolving tactics of state-sponsored threat actors, who are increasingly targeting academic institutions to access sensitive research data. The use of email-based exploit chains to compromise mail servers highlights the need for robust email security measures and prompt patching of known vulnerabilities to mitigate such threats.
2 weeks ago
Kill Chain
US Army Websites Defaced via 404 Hijacking with Pro-Kurdish Messages
In July 2026, multiple U.S. Army subdomains, including oil.army.mil and ai2c.army.mil, were defaced through a 404 hijacking attack. The attackers exploited vulnerabilities in the websites' error-handling systems to display messages denigrating President Donald Trump and U.S. Ambassador to Türkiye Tom Barrack, alongside pro-Kurdish sentiments. The affected sites, running on WordPress and Microsoft cloud infrastructure, were promptly taken offline for investigation. ([cyberscoop.com](https://cyberscoop.com/us-army-websites-defaced-404-hijacking-kurdistan/?utm_source=openai)) This incident underscores the persistent threat of website defacements targeting government entities, highlighting the need for robust security measures and vigilant monitoring to prevent unauthorized access and content manipulation.
2 weeks ago
Kill Chain
TrojPix Attack: A New Frontier in Data Exfiltration from Air-Gapped Systems
In July 2026, researchers at Shandong University unveiled 'TrojPix,' a novel technique enabling data exfiltration from air-gapped systems. By subtly modifying on-screen pixels, TrojPix induces electromagnetic emissions from video cables, which can be intercepted and decoded by nearby receivers. This method achieves data transfer rates up to 8.1 Mbps and effective ranges up to 208 meters, significantly surpassing previous covert channels. Importantly, TrojPix requires pre-existing malware on the target system to function, serving as an exfiltration method rather than an initial intrusion vector. The emergence of TrojPix underscores the evolving sophistication of cyber-espionage tactics, particularly against isolated systems. Its high-speed, long-range capabilities highlight the need for enhanced physical and operational security measures to protect sensitive environments from such advanced threats.
2 weeks ago
Kill Chain
Union County's $1 Million Data Extortion: A Wake-Up Call for Cybersecurity
In June 2025, a U.S. government entity, identified through leaked negotiation chats as Union County, Ohio, fell victim to a data-theft extortion by a group named Kairos. Unlike traditional ransomware attacks that encrypt data, Kairos exfiltrated over 2 terabytes of sensitive information, including files from the prosecutor's office, and threatened to release them publicly. After a month-long negotiation, the county paid approximately $1 million in Bitcoin to prevent the data's exposure. ([thehackernews.com](https://thehackernews.com/2026/07/us-government-entity-paid-kairos-group.html?utm_source=openai)) This incident underscores a growing trend where cybercriminals bypass encryption and directly leverage stolen data for extortion. Organizations must recognize that data exfiltration alone can serve as a potent extortion tool, emphasizing the need for robust data protection and incident response strategies.
3 weeks ago
Kill Chain
Critical Vulnerabilities in FatFs Expose Millions of Embedded Devices
In July 2026, security firm runZero disclosed seven vulnerabilities in FatFs, a widely used filesystem library for FAT and exFAT formats. These flaws, present in devices like security cameras, drones, and industrial controllers, allow attackers to exploit crafted storage media to corrupt memory and execute arbitrary code. The vulnerabilities, rated Medium to High severity, include issues like integer overflows and buffer overflows, leading to potential device crashes or unauthorized code execution. Notably, CVE-2026-6682 involves an integer overflow during FAT32 volume mounting, which can result in memory corruption and code execution. ([thehackernews.com](https://thehackernews.com/2026/07/unpatched-flaws-disclosed-in-filesystem.html?utm_source=openai)) The widespread use of FatFs in embedded systems, combined with the lack of upstream fixes and the absence of a responsive maintainer, poses significant security risks. Devices relying on FatFs remain vulnerable, and the exploitation of these flaws could lead to persistent operational denial of service or device bricking. Organizations must assess their exposure and implement mitigations to protect against potential attacks. ([thehackernews.com](https://thehackernews.com/2026/07/unpatched-flaws-disclosed-in-filesystem.html?utm_source=openai))
3 weeks ago
Kill Chain
Critical Vulnerabilities Discovered in ST Engineering iDirect iQ-Series Terminals
In July 2026, vulnerabilities were identified in ST Engineering iDirect's iQ-Series Terminals, specifically CVE-2026-38059 and CVE-2026-38057. These flaws allowed unauthenticated attackers to access sensitive device information and execute unauthorized device reboots, potentially leading to denial-of-service conditions. The affected products included Evolution iQ-Series terminals, 3315-Series terminals, and 9-Series terminals, all running firmware versions up to 4.5.2.1. The discovery of these vulnerabilities underscores the critical importance of securing networked devices in sectors such as Communications, Defense Industrial Base, Energy, Government Services, and Transportation Systems. Organizations are urged to update their devices to firmware version 4.5.2.2 or newer and implement recommended security practices to mitigate potential exploitation.
3 weeks ago
Kill Chain
Critical Vulnerability in CubeSpace CW0057 Reaction Wheel Firmware
In July 2026, CubeSpace disclosed a vulnerability (CVE-2026-13743) in its CW0057 Reaction Wheel firmware versions prior to 5.0.20. This flaw allows attackers with physical access to upload malicious firmware without authentication, potentially compromising satellite operations. The issue stems from the device's reliance on CRC-32 integrity checks, which verify data integrity but not the authenticity of the firmware source. CubeSpace has released firmware version 5.0.20, introducing cryptographically verified secure boot, though this feature is not enabled by default and requires user activation. This incident underscores the critical importance of robust firmware authentication mechanisms in aerospace components. As satellites become increasingly integral to global communications and defense, ensuring the integrity of onboard systems is paramount. Organizations must proactively implement and enable security features to mitigate risks associated with unauthorized firmware modifications.
3 weeks ago
Kill Chain
China-Linked Group Targets Southeast Asia Critical Systems
In mid-2025, the Chinese-speaking advanced persistent threat (APT) group CL-STA-1062 initiated a cyber espionage campaign targeting government entities and critical infrastructure in Southeast Asia. The group compromised at least 10 organizations, including state-owned enterprises in the energy and government sectors, deploying a custom backdoor named TinyRCT. This backdoor facilitated unauthorized access, data exfiltration, and system control, posing significant risks to national security and operational stability. ([thehackernews.com](https://thehackernews.com/2026/06/chinese-speaking-apt-deploys-new.html?utm_source=openai)) The emergence of TinyRCT underscores the evolving sophistication of state-sponsored cyber threats in the region. Organizations must enhance their cybersecurity measures to detect and mitigate such advanced persistent threats, ensuring the resilience of critical infrastructure against future attacks. ([thehackernews.com](https://thehackernews.com/2026/06/chinese-speaking-apt-deploys-new.html?utm_source=openai))
3 weeks ago
Kill Chain
U.S. Offers $10 Million Reward for Information on Russian Hackers Targeting Encrypted Messaging Apps
In June 2026, the U.S. Department of State announced a reward of up to $10 million for information leading to the identification or location of members of the Russian-linked cyber groups UNC5792 and UNC4221. These groups have been implicated in extensive phishing campaigns targeting Signal and WhatsApp accounts of U.S. government officials, military leaders, and allied personnel. The attackers employed social engineering tactics, impersonating support agents to deceive users into revealing their backup recovery keys, thereby gaining access to their encrypted communications. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/us-offers-10-million-for-hackers-targeting-whatsapp-signal-users/?utm_source=openai)) This incident underscores the evolving nature of cyber threats, particularly the sophisticated use of social engineering to bypass encryption safeguards. It highlights the critical need for heightened vigilance and robust security protocols to protect sensitive communications, especially for individuals in positions of authority or influence.
3 weeks ago
Kill Chain
Gamaredon's 2025 Cyber Offensive: Unveiling New Malware and Tactics
In 2025, the Russian-aligned APT group Gamaredon intensified its cyber operations against Ukrainian governmental and military institutions. ESET observed 35 distinct spear-phishing campaigns, primarily in the latter half of the year, utilizing archive attachments and XHTML files with HTML smuggling to deploy malicious HTA downloaders. These campaigns aimed to exfiltrate sensitive information to support Russian interests in the ongoing conflict. Gamaredon also exploited a WinRAR vulnerability (CVE-2025-8088) to achieve persistence by placing malicious files in the Windows Startup folder. Additionally, the group introduced six new PowerShell tools, including PteroDee and PteroCache, to enhance their malware arsenal. ([thehackernews.com](https://thehackernews.com/2026/06/gamaredon-expands-ukraine-attacks-with.html?utm_source=openai)) The group's reliance on third-party services grew significantly, employing tunnel services and serverless platforms to conceal their infrastructure. This evolution underscores the increasing sophistication of state-sponsored cyber threats and the necessity for robust cybersecurity measures to protect sensitive governmental data. ([thehackernews.com](https://thehackernews.com/2026/06/gamaredon-expands-ukraine-attacks-with.html?utm_source=openai))
3 weeks ago
Kill Chain
FBI Issues Alert on Russian Hackers Targeting Signal Backup Recovery Keys
In June 2026, the FBI and CISA issued a warning about a sophisticated phishing campaign by Russian intelligence services targeting Signal users. The attackers impersonated Signal support teams, sending messages that prompted users to enable backups and share their 64-character recovery keys. With these keys, the attackers could decrypt victims' entire message histories, compromising sensitive communications. The campaign primarily targeted individuals of high intelligence value, including government officials, military personnel, political figures, journalists, and key officials in Ukraine. This incident underscores the evolving tactics of state-sponsored cyber actors and highlights the critical importance of user vigilance against social engineering attacks. The exploitation of backup recovery keys represents a significant escalation in phishing techniques, emphasizing the need for robust security practices and user education to prevent unauthorized access to encrypted communications.
4 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports