The Containment Era is here. →Explore

Industry Category

Defense/Space

Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.

350 threat reports
Page 6 of 30

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Defense/Space Threat Reports

Showing 6172 / 350 reports
TA4922's Global Expansion: A New Cyber Threat Landscape
Impact· HIGH

TA4922's Global Expansion: A New Cyber Threat Landscape

In early 2026, the China-linked cybercrime group TA4922 expanded its operations beyond East Asia, targeting organizations in the U.K., Germany, Italy, and South Africa. The group employed sophisticated phishing campaigns using localized lures related to tax filings, payroll, and compliance to deliver malware such as ValleyRAT (Winos 4.0), Atlas RAT, RomulusLoader, and SilentRunLoader. These attacks aimed to gain unauthorized access for data theft, fraud, and persistent access. ([proofpoint.com](https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global?utm_source=openai)) This incident underscores the evolving threat landscape, where financially motivated cybercriminals are rapidly adapting their tactics and expanding their reach globally. Organizations must remain vigilant against such sophisticated phishing campaigns and enhance their cybersecurity measures to mitigate these risks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Vulnerability in Hitachi Energy's MACH HiDraw: CVE-2026-7310
Impact· MEDIUM

Critical Vulnerability in Hitachi Energy's MACH HiDraw: CVE-2026-7310

In May 2026, a heap-based buffer overflow vulnerability (CVE-2026-7310) was identified in the XML parser functionality of Hitachi Energy's MACH HiDraw versions up to 9.22. An authenticated user with local access could exploit this flaw using a specially crafted XML file, leading to memory corruption and potential arbitrary code execution. Successful exploitation could result in application crashes (denial of service) and compromise the confidentiality and integrity of the affected system. This incident underscores the critical importance of securing industrial control systems against local threats. As cyberattacks targeting infrastructure components become more sophisticated, organizations must prioritize timely vulnerability management and implement robust security measures to protect against potential exploits.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Gamaredon Exploits WinRAR Vulnerability to Deploy Malware in Ukraine
Impact· HIGH

Gamaredon Exploits WinRAR Vulnerability to Deploy Malware in Ukraine

In January 2026, the Russian state-sponsored hacking group Gamaredon exploited a path traversal vulnerability in WinRAR (CVE-2025-8088) to target Ukrainian government entities. The attack began with spear-phishing emails containing malicious RAR archives that, when opened, deployed an HTML Application payload named GammaPhish. This payload downloaded a VBScript downloader called GammaLoad, which subsequently installed malware such as GammaWorm and GammaSteel. GammaWorm established persistence and propagated through network shares and USB drives, while GammaSteel exfiltrated sensitive files to attacker-controlled servers. This incident underscores the persistent threat posed by state-sponsored actors leveraging known vulnerabilities to conduct espionage and data theft. The use of legitimate platforms like Telegram for command-and-control communication highlights the evolving tactics employed to evade detection and maintain long-term access to targeted networks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Iran's MOIS Expands Handala Brand to Physical Threats in 2026
Impact· HIGH

Iran's MOIS Expands Handala Brand to Physical Threats in 2026

In early 2026, Iran's Ministry of Intelligence (MOIS) expanded its 'Handala' brand to include physical threat operations targeting U.S. and Israeli interests. This expansion introduced the Handala Popular Resistance Front (HPRF), a persona soliciting individuals to conduct physical attacks and espionage for financial rewards. Concurrently, three influence operations networks—'VIPEmployment,' 'MOISIRAN,' and 'Brave Israel'—were identified as MOIS personas, amplifying the reach of these operations. ([recordedfuture.com](https://www.recordedfuture.com/research/iran-handala-physical-threats?utm_source=openai)) This development signifies a strategic shift in MOIS's external operations, integrating cyber, physical, and influence tactics under the Handala brand. The coordinated use of these personas likely enhances the effectiveness of MOIS's campaigns, posing increased risks to U.S. and Israeli law enforcement, military, intelligence agencies, and critical infrastructure sectors. ([recordedfuture.com](https://www.recordedfuture.com/research/iran-handala-physical-threats?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
SideCopy's Operation XENOFISCAL: A Targeted Cyber Espionage Campaign
Impact· HIGH

SideCopy's Operation XENOFISCAL: A Targeted Cyber Espionage Campaign

In May 2026, the Pakistan-linked threat group SideCopy launched a spear-phishing campaign, dubbed Operation XENOFISCAL, targeting Afghanistan's Ministry of Finance and provincial finance officials. The attackers used ZIP archives containing malicious LNK files with Pashto-language filenames to deliver the open-source remote access trojan Xeno RAT. Once executed, the malware established persistence, enabling the attackers to exfiltrate sensitive data and maintain long-term access to compromised systems. This campaign underscores the persistent cyber threats facing governmental institutions in South Asia, highlighting the need for enhanced cybersecurity measures and vigilance against sophisticated phishing attacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Kimsuky's Advanced Cyber Attacks: A New Era of AI-Driven Threats
Impact· HIGH

Kimsuky's Advanced Cyber Attacks: A New Era of AI-Driven Threats

In March and April 2026, the North Korean state-sponsored threat actor Kimsuky launched sophisticated cyber attacks targeting South Korean military and corporate entities. Utilizing advanced social engineering tactics, they spoofed security software installation pages and crafted fake Webex meeting pages to distribute malware. These campaigns delivered variants of the HTTPSpy remote access trojan, enabling extensive control over compromised systems, including command execution, file manipulation, and data exfiltration. Notably, Kimsuky employed legitimate tools like Visual Studio Code's remote tunneling feature and DWAgent for post-exploitation activities, enhancing their ability to evade detection. The increasing integration of artificial intelligence in cyber attack methodologies, as demonstrated by Kimsuky's use of large language models to develop malware like HelloDoor, signifies a significant evolution in threat actor capabilities. This trend underscores the urgent need for organizations to adopt advanced, behavior-based detection systems and regularly update threat intelligence to effectively counter these sophisticated and rapidly evolving cyber threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
GREYVIBE's AI-Powered Cyberattacks on Ukraine: A 2025 Case Study
Impact· HIGH

GREYVIBE's AI-Powered Cyberattacks on Ukraine: A 2025 Case Study

In August 2025, a previously undocumented threat actor named GREYVIBE initiated a series of cyberattacks targeting Ukrainian military, government, civilian, and business entities. Operating from the Russian time zone and aligning with Kremlin state interests, GREYVIBE employed multiple attack vectors, including spear-phishing emails, fake CAPTCHA pages, and fraudulent websites, to deliver custom-developed malware such as PhantomRelay and LegionRelay. Notably, the group leveraged generative artificial intelligence (GenAI) and large language models (LLMs) to enhance their operations, facilitating rapid development of obfuscators, loaders, and malware. ([thehackernews.com](https://thehackernews.com/2026/05/new-russian-linked-greyvibe-targets.html?utm_source=openai)) The integration of AI technologies in cyberattacks signifies a concerning evolution in threat actor capabilities, enabling even low-to-moderately sophisticated groups to execute complex operations. This trend underscores the urgent need for organizations to adopt advanced cybersecurity measures to detect and mitigate AI-assisted threats. ([t.co](https://t.co/WAHU7GJnZC?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ESET APT Activity Report Q4 2025–Q1 2026: Key Cyber Threats Unveiled
Impact· HIGH

ESET APT Activity Report Q4 2025–Q1 2026: Key Cyber Threats Unveiled

Between October 2025 and March 2026, ESET researchers observed significant activities from various Advanced Persistent Threat (APT) groups. China-aligned actors conducted espionage campaigns targeting maritime, energy, and political sectors, notably in Venezuela and Syria. Iran-aligned groups experienced a decline in activity due to domestic internet restrictions, while proxy and hacktivist actors increased attacks on Israel and the United States. North Korea-aligned groups focused on developers and the cryptocurrency ecosystem, employing social engineering tactics for financial gain and potential supply-chain compromises. Russia-aligned actors intensified operations against Ukraine, deploying new wipers and targeting critical infrastructure, with notable incidents extending to NATO member states like Poland. Lesser-known clusters also emerged, including browser-in-the-browser phishing attacks and Android spyware targeting Arabic-speaking users. This period underscores the evolving tactics of APT groups and the necessity for robust cybersecurity measures to counteract these sophisticated threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
GreyVibe Hackers Leverage AI in 2025 Cyberattacks
Impact· HIGH

GreyVibe Hackers Leverage AI in 2025 Cyberattacks

In August 2025, the Russian-linked threat group GreyVibe initiated a cyberespionage campaign targeting Ukrainian military, government, civilian, and business sectors. Utilizing AI tools like ChatGPT and Google Gemini, they crafted sophisticated lures and developed custom malware, including LegionRelay and PhantomRelay, to infiltrate systems and exfiltrate sensitive data. Their tactics encompassed spear-phishing emails, fake CAPTCHA pages, and counterfeit websites, leading to significant data breaches and operational disruptions. This incident underscores the escalating use of AI in cyberattacks, enabling threat actors to enhance the scale and sophistication of their operations. Organizations must adapt by implementing advanced security measures and continuous monitoring to counteract these evolving threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Iranian Hackers Leverage AI and SEO Poisoning in Advanced Cyber Espionage Campaigns
Impact· HIGH

Iranian Hackers Leverage AI and SEO Poisoning in Advanced Cyber Espionage Campaigns

In early 2026, the Iranian state-sponsored threat actor known as Nimbus Manticore (also referred to as Screening Serpens and UNC1549) launched a series of cyber espionage campaigns targeting the aviation and software sectors across the U.S., Europe, and the Middle East. These operations utilized sophisticated techniques, including career-themed phishing lures and search engine optimization (SEO) poisoning, to distribute newly developed backdoors named MiniFast and an updated version of MiniJunk (MiniJunk V2). The campaigns involved impersonating legitimate organizations to deceive employees into downloading malicious software, leading to unauthorized access and potential data exfiltration. Notably, the MiniFast backdoor exhibited characteristics suggesting it was developed with assistance from artificial intelligence, indicating an evolution in the threat actor's capabilities. ([thehackernews.com](https://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.html?utm_source=openai)) This incident underscores a significant shift in cyber threat tactics, with state-sponsored actors increasingly leveraging AI in malware development and employing SEO poisoning to broaden their attack vectors. Organizations must remain vigilant against such evolving threats by enhancing their cybersecurity measures and educating employees on recognizing sophisticated phishing and social engineering tactics.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Understanding Stack String Obfuscation: A New Challenge in Malware Detection
Impact· LOW

Understanding Stack String Obfuscation: A New Challenge in Malware Detection

In May 2026, cybersecurity researchers highlighted the 'stack string' obfuscation technique, where malware dynamically constructs strings on the stack at runtime, evading detection by static analysis tools. This method involves assembling strings character-by-character directly onto the stack, making them invisible to traditional string extraction utilities. The technique poses significant challenges for malware analysts and underscores the need for advanced detection methods. The resurgence of stack string obfuscation reflects a broader trend of malware authors adopting sophisticated evasion tactics. As traditional detection tools become less effective against such techniques, there is an urgent need for enhanced analysis tools and methodologies to identify and mitigate these evolving threats.

2 months ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Arrest of Kimwolf Botnet Operator Highlights IoT Security Risks
Impact· HIGH

Arrest of Kimwolf Botnet Operator Highlights IoT Security Risks

In May 2026, Canadian authorities arrested Jacob Butler, known online as "Dort," for allegedly creating and operating the Kimwolf botnet. This botnet infected millions of Internet-of-Things (IoT) devices, such as digital photo frames and web cameras, to execute massive distributed denial-of-service (DDoS) attacks. Some of these attacks reached nearly 30 terabits per second, causing financial losses exceeding one million dollars for certain victims. The U.S. Department of Justice has charged Butler with aiding and abetting computer intrusion, and he faces potential extradition to the United States. ([krebsonsecurity.com](https://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canada/?utm_source=openai)) The Kimwolf botnet's unprecedented scale and impact underscore the growing threat posed by IoT-based cyberattacks. This incident highlights the critical need for enhanced security measures in IoT devices and increased international cooperation to combat cybercrime effectively.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports