The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Defense/Space
Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.
Explore Other Sectors
Defense/Space Threat Reports
APT28's Exploitation of MSHTML Zero-Day Vulnerability in February 2026
In early 2026, the Russian state-sponsored threat actor APT28 exploited a zero-day vulnerability, CVE-2026-21513, in the MSHTML Framework. This high-severity flaw allowed attackers to bypass security features by convincing users to open malicious HTML or shortcut files, leading to potential code execution. The exploitation occurred before Microsoft's February 2026 Patch Tuesday, which subsequently addressed the vulnerability. ([thehackernews.com](https://thehackernews.com/2026/03/apt28-tied-to-cve-2026-21513-mshtml-0.html?utm_source=openai)) The incident underscores the persistent threat posed by state-sponsored actors leveraging zero-day vulnerabilities. Organizations are reminded of the critical importance of timely patch management and user education to mitigate risks associated with such sophisticated attacks.
6 months ago
Kill Chain
Escalation of Iranian Cyber Attacks Post-2026 Military Strikes
In response to the joint U.S.-Israeli military strikes on February 28, 2026, Iranian-affiliated cyber actors have intensified their operations targeting U.S. critical infrastructure. Utilizing tactics such as brute force attacks, password spraying, and exploitation of unpatched vulnerabilities, these actors aim to disrupt services and exfiltrate sensitive data. Notably, sectors including energy, defense, and public health have reported increased intrusion attempts, with some incidents leading to operational disruptions and data breaches. This escalation underscores the persistent cyber threat posed by Iranian state-sponsored and aligned groups, even amidst kinetic military engagements. Organizations are urged to bolster their cybersecurity postures, as the likelihood of retaliatory cyber operations remains high, potentially leading to significant operational and reputational impacts.
6 months ago
Kill Chain
Understanding the RESURGE Malware: A 2025 Cybersecurity Threat
In early 2025, the Cybersecurity and Infrastructure Security Agency (CISA) identified a sophisticated malware variant named RESURGE, which exploited the critical vulnerability CVE-2025-0282 in Ivanti Connect Secure appliances. This vulnerability allowed unauthenticated remote code execution, enabling attackers to deploy RESURGE to establish persistent access, create web shells, harvest credentials, and escalate privileges. The malware's advanced evasion techniques, including network-level stealth and boot-level persistence, posed significant challenges for detection and remediation. The emergence of RESURGE underscores a growing trend of advanced persistent threats targeting critical infrastructure through zero-day vulnerabilities. Organizations must prioritize timely patching, implement robust monitoring systems, and adopt a zero-trust security model to mitigate such sophisticated attacks.
6 months ago
Kill Chain
APT37's Ruby Jumper Campaign: A New Threat to Air-Gapped Networks
In December 2025, the North Korean state-sponsored group APT37, also known as ScarCruft, launched the 'Ruby Jumper' campaign targeting air-gapped networks. The attack began with victims opening malicious Windows shortcut (LNK) files, which executed PowerShell scripts to deploy a series of malware tools: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, and FOOTWINE. These tools facilitated initial infection, established command-and-control via Zoho WorkDrive, and enabled lateral movement through removable media, ultimately compromising isolated systems. The campaign underscores the evolving tactics of APT37 in breaching highly secure environments. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/apt37-hackers-use-new-malware-to-breach-air-gapped-networks/?utm_source=openai)) This incident highlights a significant advancement in cyber-espionage techniques, demonstrating the capability to infiltrate air-gapped systems. Organizations with critical infrastructure should reassess their security protocols to mitigate such sophisticated threats.
6 months ago
Kill Chain
ScarCruft's 'Ruby Jumper' Campaign: A New Era in Air-Gapped Network Breaches
In December 2025, the North Korean state-sponsored group ScarCruft (APT37) launched the 'Ruby Jumper' campaign, deploying sophisticated malware to infiltrate air-gapped networks. The attack began with malicious LNK files that, when executed, initiated a multi-stage infection chain. This chain utilized Zoho WorkDrive for command-and-control communications and leveraged removable media to bridge air-gapped systems, enabling data exfiltration and command execution. The campaign introduced new malware tools, including RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, and FOOTWINE, each designed to facilitate various stages of the attack, from initial compromise to surveillance and data theft. ([thehackernews.com](https://thehackernews.com/2026/02/scarcruft-uses-zoho-workdrive-and-usb.html?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors in targeting isolated networks, highlighting the need for enhanced security measures to protect sensitive environments. The use of legitimate cloud services for C2 communications and the exploitation of removable media to breach air-gapped systems represent significant advancements in cyber-espionage techniques, posing increased risks to critical infrastructure and sensitive data repositories. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/apt37-hackers-use-new-malware-to-breach-air-gapped-networks/?utm_source=openai))
6 months ago
Kill Chain
Critical Vulnerability in Pelco Sarix Pro 3 Series IP Cameras: Immediate Action Required
In February 2026, a critical authentication bypass vulnerability (CVE-2026-1241) was identified in Pelco, Inc.'s Sarix Pro 3 Series IP Cameras, affecting firmware versions up to 02.52. This flaw allows unauthorized access to the cameras' web management interface, enabling attackers to view live video streams and potentially manipulate device settings without proper authentication. The vulnerability poses significant privacy risks and operational challenges for organizations utilizing these surveillance systems. The incident underscores the growing threat landscape targeting IoT devices, particularly in critical infrastructure sectors such as commercial facilities, defense, energy, healthcare, and transportation. As cyber adversaries increasingly exploit vulnerabilities in connected devices, it is imperative for organizations to prioritize regular firmware updates, implement robust access controls, and conduct comprehensive security assessments to mitigate potential risks.
6 months ago
Kill Chain
Harvest Now, Decrypt Later: The Quantum Computing Threat
The 'Harvest Now, Decrypt Later' (HNDL) strategy involves adversaries collecting encrypted data today with the intention of decrypting it in the future when quantum computers become capable of breaking current cryptographic algorithms. This approach poses a significant threat to sensitive information with long-term confidentiality requirements, such as financial records, healthcare data, and intellectual property. Organizations must proactively transition to post-quantum cryptographic (PQC) algorithms to safeguard their data against future quantum-enabled decryption attacks. ([prnewswire.com](https://www.prnewswire.com/news-releases/harvest-now-decrypt-later-attacks-pose-a-security-concern-as-organizations-consider-implications-of-quantum-computing-301628445.html?utm_source=openai)) The urgency to address HNDL threats is underscored by the rapid advancements in quantum computing. Experts predict that cryptographically relevant quantum computers could emerge within the next decade, rendering existing encryption methods obsolete. ([docs.paloaltonetworks.com](https://docs.paloaltonetworks.com/network-security/quantum-security/administration/quantum-security-concepts/the-quantum-computing-threat?utm_source=openai))
7 months ago
Kill Chain
Ex-L3Harris Executive Sentenced for Selling Zero-Day Exploits to Russian Broker
Between 2022 and 2025, Peter Williams, a 39-year-old Australian national and former general manager of Trenchant—a cybersecurity unit of defense contractor L3Harris—stole at least eight sensitive cyber-exploit components intended exclusively for the U.S. government and its allies. Williams sold these zero-day exploits to Operation Zero, a Russian cyber-tools broker that advertises its services to non-NATO buyers, including the Russian government. The theft resulted in $35 million in losses to L3Harris and potentially enabled unauthorized access to millions of devices worldwide. In October 2025, Williams pleaded guilty to two counts of theft of trade secrets and, in February 2026, was sentenced to 87 months in federal prison, forfeiting $1.3 million in cryptocurrency, a house, and luxury items. ([justice.gov](https://www.justice.gov/opa/pr/former-general-manager-us-defense-contractor-sentenced-87-months-selling-stolen-trade?utm_source=openai)) This incident underscores the critical threat posed by insider threats within defense and cybersecurity sectors. The sale of zero-day exploits to adversarial entities highlights the urgent need for robust internal security measures, comprehensive employee vetting, and continuous monitoring to prevent unauthorized access and exfiltration of sensitive information.
7 months ago
Kill Chain
U.S. Sanctions Russian Exploit Broker for Stolen Cyber Tools
In February 2026, the U.S. Department of the Treasury sanctioned Russian exploit broker Operation Zero and its owner, Sergey Zelenyuk, for acquiring and distributing cyber tools harmful to U.S. national security. These tools, including at least eight proprietary cyber exploits stolen from U.S. defense contractor L3Harris by former employee Peter Williams, were sold to unauthorized users. Williams pleaded guilty to theft of trade secrets in October 2025 and was sentenced to over seven years in prison. The sanctions also targeted associated individuals and entities, including UAE-based Special Technology Services LLC FZ, for their roles in the illicit trade of these cyber tools. This incident underscores the persistent threat posed by the illicit trade of zero-day exploits and the involvement of insiders in compromising sensitive information. It highlights the need for robust internal security measures and vigilant monitoring to prevent unauthorized access and distribution of critical cyber tools.
7 months ago
Kill Chain
L3Harris Insider Breach: Zero-Day Exploits Sold to Russian Broker
In October 2025, Peter Williams, a 39-year-old Australian national and former general manager at L3Harris's Trenchant division, pleaded guilty to stealing and selling eight zero-day exploits to a Russian broker, Operation Zero. Over a three-year period, Williams transferred these sensitive cyber-exploit components, originally intended for U.S. government and allied use, in exchange for approximately $1.3 million in cryptocurrency. This unauthorized sale resulted in significant national security concerns and financial losses exceeding $35 million for L3Harris. ([techcrunch.com](https://techcrunch.com/2025/10/29/former-l3harris-trenchant-boss-pleads-guilty-to-selling-zero-day-exploits-to-russian-broker/?utm_source=openai)) This incident underscores the critical need for stringent internal security measures within defense contractors, especially concerning personnel with high-level access to sensitive information. The case highlights the growing threat posed by insider threats and the importance of robust monitoring and compliance frameworks to prevent unauthorized dissemination of national security assets.
7 months ago
Kill Chain
L3Harris Executive Sentenced for Selling Zero-Day Exploits to Russian Broker
In February 2026, Peter Williams, a former executive at L3Harris's cyber division Trenchant, was sentenced to 87 months in prison for selling eight zero-day exploits to a Russian broker, Operation Zero. Over a three-year period, Williams stole proprietary cyber tools intended for exclusive use by the U.S. government and its allies, causing an estimated $35 million in losses to L3Harris. He received approximately $1.3 million in cryptocurrency for the stolen exploits, which he used to purchase luxury items. This case underscores the severe risks posed by insider threats within defense contracting firms, especially concerning sensitive cybersecurity tools. The incident highlights the critical need for robust internal security measures and monitoring to prevent unauthorized access and exfiltration of proprietary information. Additionally, the U.S. Department of the Treasury sanctioned Operation Zero and its founder, Sergey Zelenyuk, for their role in acquiring and distributing cyber tools harmful to U.S. national security.
7 months ago
Kill Chain
Lazarus Group's Medusa Ransomware Attacks on Healthcare in 2026
In early 2026, the North Korean state-sponsored Lazarus Group initiated a series of cyberattacks targeting healthcare organizations in the United States and the Middle East using Medusa ransomware. These attacks involved deploying the ransomware to encrypt critical data, followed by ransom demands averaging $260,000. Notably, the group targeted a mental health nonprofit and an educational facility for autistic children in the U.S. ([theregister.com](https://www.theregister.com/2026/02/24/north_koreas_lazarus_group_healthcare_medusa_ransomware/?utm_source=openai)). The attackers utilized a suite of tools, including the Comebacker backdoor and Blindingcan remote access trojan, to infiltrate and compromise systems. ([scworld.com](https://www.scworld.com/news/north-koreas-lazarus-group-targets-us-middle-east-healthcare-sectors?utm_source=openai)) This incident underscores the Lazarus Group's continued evolution and adaptability in cyber warfare, highlighting the persistent threat posed by state-sponsored actors to critical infrastructure sectors. The healthcare industry's vulnerability to such attacks emphasizes the urgent need for enhanced cybersecurity measures and international cooperation to mitigate the risks associated with sophisticated ransomware campaigns.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports