The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Defense/Space

Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.

418 threat reports
Page 11 of 35

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Defense/Space Threat Reports

Showing 121–132 / 418 reports
Critical Vulnerabilities in Ivanti Sentry: CVE-2026-10520 and CVE-2026-10523
Impact· CRITICAL

Critical Vulnerabilities in Ivanti Sentry: CVE-2026-10520 and CVE-2026-10523

In June 2026, Ivanti disclosed two critical vulnerabilities in its Sentry secure mobile gateway: CVE-2026-10520, an OS command injection flaw allowing unauthenticated remote code execution with root privileges, and CVE-2026-10523, an authentication bypass enabling attackers to create administrative accounts. Both vulnerabilities were patched in Sentry versions R10.5.2, R10.6.2, and R10.7.1. These vulnerabilities underscore the persistent targeting of Ivanti products by threat actors, highlighting the necessity for organizations to promptly apply security patches to mitigate potential exploitation risks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
China-Linked JDY Botnet Intensifies Focus on U.S. Military Networks
Impact· CRITICAL

China-Linked JDY Botnet Intensifies Focus on U.S. Military Networks

In June 2026, cybersecurity researchers identified a significant expansion of the JDY botnet, a network linked to Chinese state-sponsored actors such as Volt Typhoon. The botnet, which has grown from approximately 650 active bots in January 2024 to over 1,500 compromised small office/home office (SOHO) and Internet of Things (IoT) devices, primarily targets U.S. military and associated networks. JDY functions as a distributed scanning and fingerprinting network, rapidly identifying vulnerable infrastructure shortly after public vulnerability disclosures, thereby facilitating swift exploitation by advanced persistent threat (APT) actors. This development underscores the escalating sophistication and persistence of state-sponsored cyber threats, particularly those emanating from China. The rapid operationalization of reconnaissance data by APT groups highlights the critical need for organizations, especially within the defense sector, to enhance their cybersecurity posture, promptly apply patches, and implement robust monitoring to detect and mitigate such threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Mandates Immediate Patching of Check Point VPN Vulnerability Exploited by Qilin Ransomware
Impact· CRITICAL

CISA Mandates Immediate Patching of Check Point VPN Vulnerability Exploited by Qilin Ransomware

In early May 2026, a critical vulnerability (CVE-2026-50751) in Check Point's Remote Access VPN and Mobile Access products was exploited by Qilin ransomware affiliates. This flaw allowed unauthenticated remote attackers to bypass authentication and establish VPN connections on systems configured with the deprecated IKEv1 protocol. The attacks led to breaches in several organizations worldwide, prompting Check Point to release security updates on June 8, 2026. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-check-point-flaw-exploited-by-ransomware-gangs/?utm_source=openai)) The exploitation of this vulnerability underscores the persistent threat posed by ransomware groups targeting outdated protocols. Organizations are urged to apply patches promptly and review their VPN configurations to mitigate similar risks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-check-point-flaw-exploited-by-ransomware-gangs/?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Russian Hackers Exploit WinRAR Vulnerability CVE-2025-8088
Impact· HIGH

Russian Hackers Exploit WinRAR Vulnerability CVE-2025-8088

In mid-2025, Russian state-sponsored threat groups, including RomCom (also known as Storm-0978), exploited a critical vulnerability in WinRAR (CVE-2025-8088) to target Ukrainian military and government organizations. The flaw, a path traversal vulnerability, allowed attackers to execute arbitrary code by delivering specially crafted RAR archives via spear-phishing emails. These campaigns led to unauthorized access, data theft, and potential disruption of critical operations within the targeted entities. Despite the release of WinRAR version 7.13 in July 2025, which addressed this vulnerability, many systems remained unpatched due to the software's lack of an automatic update mechanism. This oversight has enabled continued exploitation by various threat actors, underscoring the importance of timely software updates and robust cybersecurity practices to mitigate such risks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Russian-Aligned Groups Exploit WinRAR Vulnerability to Target Ukrainian Organizations
Impact· HIGH

Russian-Aligned Groups Exploit WinRAR Vulnerability to Target Ukrainian Organizations

In June 2026, cybersecurity researchers identified that Russian-aligned groups, Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226), continued exploiting a critical vulnerability in WinRAR (CVE-2025-8088) to target Ukrainian organizations. This path traversal flaw allows attackers to execute arbitrary code by crafting malicious archive files. Despite a patch being released in July 2025, the absence of automatic updates in WinRAR has left many systems vulnerable. The attackers utilized this exploit to deploy information-stealing malware, such as GIFTEDCROOK, which harvests sensitive data from infected systems. The persistent exploitation of CVE-2025-8088 underscores the critical importance of timely software updates and the risks associated with unpatched vulnerabilities. Organizations are urged to manually update WinRAR to version 7.13 or later to mitigate this threat. ([windowscentral.com](https://www.windowscentral.com/software-apps/new-winrar-zero-day-pc-vulnerability-exploited-by-hackers-what-you-need-to-know?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
U.S. Military's Covert Use of GPS for Encrypted Key Distribution Unveiled
Impact· LOW

U.S. Military's Covert Use of GPS for Encrypted Key Distribution Unveiled

In June 2026, security researcher Steven Murdoch uncovered that the U.S. military has been utilizing public GPS signals to broadcast encrypted cryptographic keys for nearly two decades. This method effectively transformed GPS satellites into global 'numbers stations,' enabling the Over-the-Air Distribution (OTAD) and Over-the-Air Rekeying (OTAR) systems to remotely update cryptographic keys for military GPS receivers worldwide. The discovery highlights the military's innovative approach to secure key distribution without relying on physical couriers. ([404media.co](https://www.404media.co/the-u-s-military-quietly-turned-gps-into-a-global-numbers-station-evidence-suggests/?utm_source=openai)) This revelation underscores the critical importance of secure key management in military operations and the potential for leveraging existing infrastructure for covert communications. It also raises questions about the transparency of such methods and their implications for both military and civilian users of GPS technology.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
VerdantBamboo's Prolonged Cyber Espionage via BRICKSTORM Backdoor
Impact· CRITICAL

VerdantBamboo's Prolonged Cyber Espionage via BRICKSTORM Backdoor

In September 2025, cybersecurity firm Volexity identified a prolonged cyber espionage campaign by the Chinese state-sponsored group VerdantBamboo, also known as UNC5221. The attackers exploited a local privilege escalation vulnerability in an Egnyte Storage Sync appliance to deploy a BSD variant of the BRICKSTORM backdoor, maintaining undetected access for at least 18 months. This access facilitated further infiltration into the victim's Microsoft 365 environment and the deployment of additional malware, including PLENET and AGENTPSD, on various network appliances. The campaign underscores the increasing targeting of network appliances and storage systems by sophisticated threat actors, exploiting their lack of endpoint detection capabilities to establish long-term persistence. Organizations are urged to enhance monitoring and security measures for such devices to mitigate similar threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Asin Spyware: A New Threat to Arabic-Speaking Android Users
Impact· MEDIUM

Asin Spyware: A New Threat to Arabic-Speaking Android Users

In early 2025, a sophisticated cyber espionage campaign emerged targeting Arabic-speaking Android users. The threat actor, identified as Arid Viper (also known as APT-C-23, Desert Falcon, or TAG-63), distributed a new spyware variant named Asin through deceptive applications. These malicious apps masqueraded as legitimate utilities, war-related updates, and government news sources, enticing users to download them. Once installed, Asin granted attackers extensive access to victims' devices, enabling the collection of sensitive information such as contacts, messages, and location data. The campaign's strategic use of culturally relevant themes and trusted app appearances significantly increased its effectiveness, leading to widespread data exfiltration and potential national security implications. This incident underscores a growing trend in cyber threats where attackers exploit regional conflicts and cultural contexts to enhance the credibility of their malicious campaigns. The use of sophisticated social engineering tactics, combined with the targeting of specific linguistic and cultural groups, highlights the evolving nature of cyber espionage. Organizations and individuals must remain vigilant, especially in regions experiencing geopolitical tensions, as such environments are increasingly exploited by threat actors to conduct targeted attacks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
TA4922's Global Expansion: A New Cyber Threat Landscape
Impact· HIGH

TA4922's Global Expansion: A New Cyber Threat Landscape

In early 2026, the China-linked cybercrime group TA4922 expanded its operations beyond East Asia, targeting organizations in the U.K., Germany, Italy, and South Africa. The group employed sophisticated phishing campaigns using localized lures related to tax filings, payroll, and compliance to deliver malware such as ValleyRAT (Winos 4.0), Atlas RAT, RomulusLoader, and SilentRunLoader. These attacks aimed to gain unauthorized access for data theft, fraud, and persistent access. ([proofpoint.com](https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global?utm_source=openai)) This incident underscores the evolving threat landscape, where financially motivated cybercriminals are rapidly adapting their tactics and expanding their reach globally. Organizations must remain vigilant against such sophisticated phishing campaigns and enhance their cybersecurity measures to mitigate these risks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Vulnerability in Hitachi Energy's MACH HiDraw: CVE-2026-7310
Impact· MEDIUM

Critical Vulnerability in Hitachi Energy's MACH HiDraw: CVE-2026-7310

In May 2026, a heap-based buffer overflow vulnerability (CVE-2026-7310) was identified in the XML parser functionality of Hitachi Energy's MACH HiDraw versions up to 9.22. An authenticated user with local access could exploit this flaw using a specially crafted XML file, leading to memory corruption and potential arbitrary code execution. Successful exploitation could result in application crashes (denial of service) and compromise the confidentiality and integrity of the affected system. This incident underscores the critical importance of securing industrial control systems against local threats. As cyberattacks targeting infrastructure components become more sophisticated, organizations must prioritize timely vulnerability management and implement robust security measures to protect against potential exploits.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Gamaredon Exploits WinRAR Vulnerability to Deploy Malware in Ukraine
Impact· HIGH

Gamaredon Exploits WinRAR Vulnerability to Deploy Malware in Ukraine

In January 2026, the Russian state-sponsored hacking group Gamaredon exploited a path traversal vulnerability in WinRAR (CVE-2025-8088) to target Ukrainian government entities. The attack began with spear-phishing emails containing malicious RAR archives that, when opened, deployed an HTML Application payload named GammaPhish. This payload downloaded a VBScript downloader called GammaLoad, which subsequently installed malware such as GammaWorm and GammaSteel. GammaWorm established persistence and propagated through network shares and USB drives, while GammaSteel exfiltrated sensitive files to attacker-controlled servers. This incident underscores the persistent threat posed by state-sponsored actors leveraging known vulnerabilities to conduct espionage and data theft. The use of legitimate platforms like Telegram for command-and-control communication highlights the evolving tactics employed to evade detection and maintain long-term access to targeted networks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Iran's MOIS Expands Handala Brand to Physical Threats in 2026
Impact· HIGH

Iran's MOIS Expands Handala Brand to Physical Threats in 2026

In early 2026, Iran's Ministry of Intelligence (MOIS) expanded its 'Handala' brand to include physical threat operations targeting U.S. and Israeli interests. This expansion introduced the Handala Popular Resistance Front (HPRF), a persona soliciting individuals to conduct physical attacks and espionage for financial rewards. Concurrently, three influence operations networks—'VIPEmployment,' 'MOISIRAN,' and 'Brave Israel'—were identified as MOIS personas, amplifying the reach of these operations. ([recordedfuture.com](https://www.recordedfuture.com/research/iran-handala-physical-threats?utm_source=openai)) This development signifies a strategic shift in MOIS's external operations, integrating cyber, physical, and influence tactics under the Handala brand. The coordinated use of these personas likely enhances the effectiveness of MOIS's campaigns, posing increased risks to U.S. and Israeli law enforcement, military, intelligence agencies, and critical infrastructure sectors. ([recordedfuture.com](https://www.recordedfuture.com/research/iran-handala-physical-threats?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports