The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Defense/Space
Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.
Explore Other Sectors
Defense/Space Threat Reports
Critical Vulnerabilities in SolarWinds Serv-U Require Immediate Attention
In February 2026, SolarWinds disclosed four critical vulnerabilities in its Serv-U file transfer software, including CVE-2025-40538, a broken access control flaw allowing attackers with administrative privileges to create system admin users and execute arbitrary code as root. These vulnerabilities, each assigned a CVSS score of 9.1, could lead to full system compromise if exploited. SolarWinds released version 15.5.4 to address these issues. The disclosure underscores the persistent targeting of file transfer solutions by threat actors due to their access to sensitive data. Organizations are urged to promptly apply patches and review access controls to mitigate potential exploitation risks.
7 months ago
Kill Chain
Anthropic Uncovers Unauthorized Distillation Attacks by Chinese AI Firms in 2026
In February 2026, Anthropic, a U.S.-based AI company, reported that three Chinese AI firms—DeepSeek, Moonshot AI, and MiniMax—conducted large-scale distillation attacks to extract capabilities from its Claude AI model. These companies generated over 16 million interactions using approximately 24,000 fraudulent accounts, violating Anthropic's terms of service and regional access restrictions. The attacks focused on Claude's advanced features, including reasoning, coding, and tool use, aiming to enhance their own AI models without proper authorization. This incident underscores the escalating risks of intellectual property theft in the AI sector, particularly through distillation techniques. Such activities not only compromise proprietary technologies but also pose significant national security concerns, as models developed through illicit means may lack essential safety measures, potentially facilitating malicious applications.
7 months ago
Kill Chain
Anthropic's Claude Model Targeted in Large-Scale AI Distillation Attack by Chinese Labs
In February 2026, Anthropic, a U.S.-based AI startup, reported that three Chinese AI laboratories—DeepSeek, Moonshot, and MiniMax—conducted large-scale 'distillation' attacks to extract capabilities from Anthropic's Claude model. These labs utilized 24,000 fraudulent accounts to send approximately 16 million requests to Claude, aiming to enhance their own AI models. This unauthorized extraction of intellectual property not only violated Anthropic's terms of service but also posed significant national security risks by potentially enabling offensive cyber operations and mass surveillance. ([cyberscoop.com](https://cyberscoop.com/anthropic-accuses-chinese-labs-ai-distillation-cyber-risk/?utm_source=openai)) This incident underscores the growing threat of AI model distillation as a method for intellectual property theft. The scale and sophistication of these attacks highlight the urgent need for robust security measures and regulatory frameworks to protect proprietary AI technologies from unauthorized exploitation.
7 months ago
Kill Chain
APT28's Operation MacroMaze: A New Wave of Cyber Espionage
Between September 2025 and January 2026, the Russian state-sponsored threat actor APT28 conducted Operation MacroMaze, targeting entities in Western and Central Europe. The campaign utilized spear-phishing emails containing malicious Word documents with embedded macros. These macros exploited legitimate services like webhook[.]site for command-and-control and data exfiltration, employing techniques such as headless browser execution and keyboard simulation to evade detection. ([thehackernews.com](https://thehackernews.com/2026/02/apt28-targeted-european-entities-using.html?utm_source=openai)) This incident underscores the evolving tactics of APT28, highlighting their ability to adapt and leverage basic tools in sophisticated ways. The use of legitimate services for malicious purposes poses significant challenges for detection and mitigation, emphasizing the need for robust cybersecurity measures and continuous monitoring.
7 months ago
Kill Chain
North Korean IT Workers Exploit Remote Work to Infiltrate U.S. Companies in 2025
In 2025, U.S. authorities uncovered a sophisticated scheme where North Korean IT workers, using stolen or fabricated identities, secured remote positions within over 300 U.S. companies. These operatives, often based in China and Russia, infiltrated organizations by posing as legitimate American employees, thereby accessing sensitive corporate data and systems. The illicit earnings, estimated at over $88 million, were funneled back to North Korea to support its weapons programs. ([forbes.com](https://www.forbes.com/sites/alonzomartinez/2025/04/25/north-korean-hackers-pose-as-remote-workers-to-infiltrate-us-firms/?utm_source=openai)) This incident underscores the escalating threat of nation-state actors exploiting remote work vulnerabilities to bypass traditional security measures. The use of advanced tactics, including AI-generated profiles and deepfake technologies, highlights the need for enhanced identity verification processes and continuous monitoring of remote access points to safeguard organizational assets. ([fortune.com](https://fortune.com/2025/08/04/north-korean-it-worker-infiltrations-exploded/?utm_source=openai))
7 months ago
Kill Chain
Google Engineers Indicted for Trade Secret Theft to Iran
In February 2026, three Silicon Valley engineers—Samaneh Ghandali, her sister Soroor Ghandali, and her husband Mohammadjavad Khosravi—were indicted for allegedly stealing trade secrets from Google and other technology companies and transferring them to unauthorized locations, including Iran. The trio exploited their positions to access sensitive data related to processor security and cryptography, transferring hundreds of confidential files to personal devices and third-party platforms. Their actions were detected by Google's internal security systems in August 2023, leading to an internal investigation and subsequent legal action. This incident underscores the persistent threat of insider attacks in the tech industry, highlighting the need for robust internal security measures and vigilant monitoring to protect intellectual property. The case also reflects broader concerns about the exfiltration of sensitive technologies to foreign entities, emphasizing the importance of safeguarding national security interests in the face of evolving cyber threats.
7 months ago
Kill Chain
Ukrainian National Sentenced for Facilitating North Korean IT Worker Fraud
In February 2026, Ukrainian national Oleksandr Didenko was sentenced to five years in U.S. federal prison for orchestrating a scheme that enabled North Korean IT workers to fraudulently secure employment at 40 U.S. companies. Didenko operated the website Upworksell.com, facilitating the sale of stolen U.S. citizen identities to these workers, who then funneled their earnings back to North Korea to support its weapons programs. He also managed multiple 'laptop farms' in the U.S. to create the illusion of domestic employment locations. This case underscores the persistent threat of nation-state actors exploiting identity theft to infiltrate and financially exploit U.S. businesses. The incident highlights the evolving tactics of North Korean operatives, who now leverage authentic LinkedIn profiles to enhance the credibility of their fraudulent job applications, posing ongoing risks to corporate security and compliance.
7 months ago
Kill Chain
Ukrainian National Sentenced for Facilitating North Korean IT Worker Scheme
In February 2026, Ukrainian national Oleksandr Didenko was sentenced to five years in U.S. federal prison for orchestrating a scheme that enabled North Korean IT workers to fraudulently secure employment at 40 American companies. Didenko operated the website upworksell.com, through which he sold stolen U.S. citizens' identities, facilitating the creation of over 2,500 fraudulent accounts on various platforms. These actions allowed North Korean operatives to infiltrate U.S. businesses, diverting hundreds of thousands of dollars to the North Korean regime, thereby supporting its munitions programs. This case underscores the persistent threat posed by state-sponsored cyber operations and the exploitation of identity theft to circumvent international sanctions. The incident highlights the critical need for robust identity verification processes and vigilant monitoring of remote workforces to prevent unauthorized access and protect national security interests.
7 months ago
Kill Chain
Chinese APT Exploits Dell RecoverPoint Zero-Day Since 2024
In mid-2024, a Chinese state-sponsored threat group, identified as UNC6201, began exploiting a critical zero-day vulnerability (CVE-2026-22769) in Dell's RecoverPoint for Virtual Machines. This flaw, stemming from hardcoded credentials, allowed unauthenticated remote attackers to gain root-level access to affected systems. The attackers utilized this access to deploy backdoors such as BRICKSTORM and later GRIMBOLT, facilitating persistent access and lateral movement within compromised networks. Dell released a patch for this vulnerability in February 2026, urging immediate remediation to prevent further exploitation. ([securityweek.com](https://www.securityweek.com/dell-recoverpoint-zero-day-exploited-by-chinese-cyberespionage-group/?utm_source=openai)) This incident underscores the persistent threat posed by nation-state actors targeting critical infrastructure through zero-day vulnerabilities. The prolonged undetected exploitation highlights the necessity for robust monitoring and rapid response mechanisms to mitigate such sophisticated cyber threats. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/chinese-hackers-exploiting-dell-zero-day-flaw-since-mid-2024/?utm_source=openai))
7 months ago
Kill Chain
Operation Absolute Resolve: Cyber-Physical Tactics in Modern Warfare
On January 3, 2026, during Operation Absolute Resolve, U.S. forces executed a mission to capture Venezuelan President Nicolás Maduro. The operation involved over 150 aircraft conducting airstrikes on key military installations in Caracas, including Fuerte Tiuna and La Carlota Air Base. Concurrently, cyber capabilities were deployed to disrupt Venezuela's power grid, resulting in widespread blackouts across the capital. This multi-domain approach combined kinetic strikes with cyber operations to disable critical infrastructure and facilitate the extraction of Maduro. The operation led to significant physical damage to military facilities and substations, causing prolonged power outages in several districts. The integration of cyber and kinetic tactics underscores the evolving nature of modern military engagements, highlighting the strategic use of cyber operations to achieve tactical objectives. This incident serves as a case study in the application of cyber-physical strategies in contemporary warfare, emphasizing the need for robust cybersecurity measures to protect national infrastructure.
7 months ago
Kill Chain
Poland's Energy Sector Thwarts Major Cyberattack by Sandworm Group
In late December 2025, Poland's energy infrastructure was targeted by a coordinated cyberattack involving the deployment of a new data-wiping malware named DynoWiper. The attack focused on over 30 wind and solar farms, a combined heat and power plant serving nearly half a million customers, and a manufacturing company. The attackers exploited exposed FortiGate devices lacking multi-factor authentication to gain initial access, then moved laterally within networks to deploy the wiper malware. Despite the sophisticated nature of the attack, endpoint detection and response systems successfully blocked the malware's execution, preventing any disruption to energy production or distribution. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/06/poland-cyberattacks-energy-sector-industrial-organizations/?utm_source=openai)) This incident underscores the escalating threat posed by state-sponsored cyber actors targeting critical infrastructure. The use of destructive malware like DynoWiper highlights the need for robust cybersecurity measures, including the implementation of multi-factor authentication and regular security audits, to protect against such sophisticated attacks. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/06/poland-cyberattacks-energy-sector-industrial-organizations/?utm_source=openai))
7 months ago
Kill Chain
Siemens Simcenter Femap and Nastran 2026 File Parsing Vulnerabilities
In February 2026, Siemens disclosed multiple vulnerabilities in its Simcenter Femap and Nastran products, specifically affecting versions prior to V2512. These vulnerabilities, identified as CVE-2026-23715 through CVE-2026-23720, involve out-of-bounds read and write errors, as well as heap-based buffer overflows, which can be exploited by attackers through specially crafted NDB and XDB files. Successful exploitation could lead to application crashes or arbitrary code execution within the context of the current process. Siemens has released version V2512 to address these issues and recommends users update to this latest version. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-965753.html?utm_source=openai)) The disclosure of these vulnerabilities underscores the persistent risks associated with file parsing mechanisms in critical engineering software. Organizations utilizing Simcenter Femap and Nastran should prioritize updating to the patched version to mitigate potential exploitation. This incident highlights the importance of regular software updates and vigilance against malicious file-based attacks in industrial environments.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports