The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Defense/Space

Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.

418 threat reports
Page 25 of 35

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Defense/Space Threat Reports

Showing 289–300 / 418 reports
How the 2020 Venezuelan Power Grid Cyberattack Set a New Precedent for Nation-State Warfare
Impact· medium

How the 2020 Venezuelan Power Grid Cyberattack Set a New Precedent for Nation-State Warfare

In May 2020, Venezuela experienced a significant power grid disruption that coincided with an alleged US-backed military incursion. Intelligence sources and public statements, including hints from President Trump, suggested that nation-state cyber actors played a role in disabling critical infrastructure, likely by targeting unencrypted or poorly segmented network traffic in Caracas. The incident demonstrated the attackers’ use of advanced cyber capabilities to disrupt the nation's power supply, contributing to confusion and vulnerability during a period of political unrest. While the precise techniques remain classified, the attack highlighted significant weaknesses in Venezuela’s critical industrial control systems and network segmentation. The relevance of this event endures as cyber operations against power grids and critical infrastructure grow more sophisticated and frequent globally. Recent years have seen a surge in state-sponsored attacks leveraging both advanced persistent threats and rapid lateral movement, making robust east-west security, zero trust practices, and encrypted traffic defenses urgent imperatives for organizations.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
State-Sponsored Cyberattack: US Targets Venezuelan Power Grid (2019)
Impact· medium

State-Sponsored Cyberattack: US Targets Venezuelan Power Grid (2019)

In March 2019, a significant power outage crippled Venezuela’s capital, Caracas, and other major cities, reportedly as part of a broader campaign by the United States involving offensive cyber operations. Although official attribution remains classified, senior U.S. officials and President Trump openly hinted at the use of advanced cyberattacks to disrupt Venezuela’s electrical grid during a period of heightened political instability and efforts to capture President Nicolás Maduro. This unprecedented event marked a rare instance of publicized state-sponsored cyber warfare, raising concerns about the direct targeting of national critical infrastructure and its immediate social, political, and economic impact. This incident highlights a growing trend of nations turning to cyber operations as a tool for geopolitical leverage, targeting vital systems with the intent to destabilize adversaries. The weaponization of cyber capabilities against critical infrastructure sets a precedent for both escalation and regulatory scrutiny worldwide.

8 months ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Russia-Aligned Group UAC-0184 Breaches Ukrainian Government via Viber Attack
Impact· low

Russia-Aligned Group UAC-0184 Breaches Ukrainian Government via Viber Attack

In early 2025, the Russia-aligned cyber-espionage group UAC-0184 undertook a targeted campaign against Ukrainian military and government organizations. Leveraging the popular Viber messaging platform, the threat actors distributed malicious ZIP archives to infiltrate sensitive networks. Security researchers from the 360 Threat Intelligence Center noted that these operations demonstrated continued intelligence-gathering efforts, employing social engineering tactics and the abuse of trusted communication channels. The attack resulted in the unauthorized access and potential exposure of confidential government and defense information, further escalating the cyber hostilities related to the conflict in Ukraine. This incident highlights a growing trend in the weaponization of encrypted messaging apps for cyber-espionage, as nation-state actors increasingly exploit trusted consumer platforms to bypass traditional enterprise security controls. The breach underscores the urgency for robust east-west traffic monitoring, zero trust segmentation, and advanced detection capabilities across critical sectors.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Mustang Panda’s 2025 Kernel Rootkit: How a Signed Driver Enabled Stealth Espionage in Asia
Impact· high

Mustang Panda’s 2025 Kernel Rootkit: How a Signed Driver Enabled Stealth Espionage in Asia

In mid-2025, the Chinese cyber espionage group Mustang Panda deployed a previously undocumented, signed kernel-mode rootkit to secretly load a TONESHELL backdoor variant during targeted attacks against government organizations in Southeast and East Asia—mainly Myanmar and Thailand. Leveraging a stolen legacy digital certificate, the attackers installed a Windows minifilter driver to inject TONESHELL into system processes, evade security controls, and shield their malware and associated files from detection. The backdoor enabled ongoing remote control, data exfiltration, and further malware deployments via encrypted channels, establishing persistent clandestine access. This incident is notable for its innovative use of signed kernel drivers to enhance stealth, resilience, and anti-forensic measures. It reflects a broader trend among sophisticated threat actors who increasingly leverage advanced rootkit technology and certificate abuse to bypass endpoint protections and remain undetected for extended periods.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Over 10,000 Fortinet Firewalls Still Exposed to 2FA Bypass Attack in 2026
Impact· medium

Over 10,000 Fortinet Firewalls Still Exposed to 2FA Bypass Attack in 2026

In early January 2026, it was revealed that over 10,000 Fortinet FortiGate firewalls remain exposed to a critical authentication bypass vulnerability (CVE-2020-12812) first patched by Fortinet in July 2020. Attackers exploit this flaw by manipulating username case sensitivity to bypass two-factor authentication (2FA) on SSL VPNs—allowing unauthorized access to devices with unpatched software and certain LDAP configurations. Despite years of vendor and government warnings, more than 1,300 vulnerable systems in the United States alone are still online, placing organizations at ongoing risk of compromise. The persistence of this five-year-old flaw’s exploitation highlights chronic issues in vulnerability management and patch adoption within network infrastructure. Active targeting by both cybercriminal and state-backed actors, combined with evidence of ransomware deployment, underscores the need for continuous configuration hardening, zero trust adoption, and rapid remediation of exposed security controls.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How Transparent Tribe’s 2026 RAT Offensive Breached Indian Government & Academia
Impact· medium

How Transparent Tribe’s 2026 RAT Offensive Breached Indian Government & Academia

In early 2026, the advanced persistent threat group Transparent Tribe (APT36) launched a sophisticated cyber espionage campaign targeting Indian governmental and academic institutions. Attackers distributed spear-phishing emails containing ZIP archives with malicious Windows shortcut (LNK) files, disguised as legitimate PDFs. Upon execution, these files deployed remote access trojans (RATs) by loading encrypted payloads in-memory and displaying decoy documents to evade suspicion. The malware adapted its persistence techniques based on detected antivirus solutions and enabled functions such as file management, system reconnaissance, data exfiltration, and command execution via a dynamic command-and-control infrastructure. This incident highlights the persistent evolution of state-linked cyber threats and the rising use of multi-stage spear-phishing, evasive loaders, and context-aware persistence. As state-sponsored attacks become more adaptive and target the public sector, organizations face increased regulatory and operational pressure to fortify internal security controls and monitor lateral movement.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Thousands Breached: The 2024 Ivanti EPMM Zero-Day APT Campaign
Impact· low

Thousands Breached: The 2024 Ivanti EPMM Zero-Day APT Campaign

In April and May 2024, thousands of organizations worldwide were compromised after a Chinese state-sponsored advanced persistent threat (APT) group exploited multiple previously unknown zero-day vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) platform. The attackers used these flaws as entry points to gain administrative control, move laterally, and deploy persistent malware, leading to widespread data exfiltration and operational disruption. The campaign targeted government, critical infrastructure, and private sector entities, exploiting unpatched systems at scale before public disclosure, prompting rapid security advisories and emergency patching. This Ivanti EPMM incident underscores the growing sophistication of nation-state campaigns leveraging zero-day vulnerabilities for large-scale compromise. It highlights the urgent industry need for rigorous vulnerability management, zero trust architectures, and rapid detection in light of escalating APT tactics.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
ESA 2024 External Server Breach: Lessons on Third-Party and Perimeter Security
Impact· medium

ESA 2024 External Server Breach: Lessons on Third-Party and Perimeter Security

In June 2024, the European Space Agency (ESA) confirmed a cybersecurity incident involving unauthorized access to external servers outside its core corporate IT network. These servers contained 'unclassified' information tied to ESA's collaborative engineering activities. The breach was detected and announced on June 24, with the agency rapidly taking down the compromised servers to contain the incident and beginning an internal investigation. No critical or classified ESA infrastructure was reportedly affected, and mission operations remained unaffected. This breach underscores persistent risks facing organizations collaborating with external partners and utilizing externally accessible infrastructure. Similar methodologies targeting non-core systems and lateral movements are increasing, highlighting the importance of robust segmentation, external system monitoring, and continuous risk assessment for third-party assets.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
2025's Stealth Loader and AI Exploit Wave: How Multi-Vector Attacks Redefined Cybersecurity
Impact· medium

2025's Stealth Loader and AI Exploit Wave: How Multi-Vector Attacks Redefined Cybersecurity

In late 2025, a coordinated wave of global cyber attacks leveraged stealthy multi-vector campaigns with commodity loaders, AI-powered exploits, and social engineering. Attackers weaponized legitimate tools like Nezha for post-exploitation, orchestrated large-scale phishing using fake updates and PoC exploits, and targeted both enterprise and consumer platforms. These campaigns saw loaders like Caminho deliver diverse malware such as XWorm, PureLogs, and RATs into manufacturing, government, and IT networks across several regions. Simultaneously, attackers abused vulnerabilities in AI assistants and exploited weaknesses in NFC-enabled Android malware, achieving persistent access, privilege escalation, data exfiltration, and lateral movement—all while skillfully blending malicious traffic with normal system behaviors. This incident highlights a sharp evolution in attack methods as threat actors increasingly favor low-noise, blended tradecraft over traditional smash-and-grab approaches. With the convergence of signature evasion, AI system manipulation, and commodity loader sharing, defenders must shift toward integrated, threat-aware security architectures. These incidents mark a critical inflection point, signaling a persistent rise in invisible, multi-layered threats fueled by automation and attacker collaboration.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fortinet SSO Bypass: 25,000 Devices at Risk from Critical CVE-2025-59718 Exploit
Impact· medium

Fortinet SSO Bypass: 25,000 Devices at Risk from Critical CVE-2025-59718 Exploit

In December 2025, over 25,000 internet-exposed Fortinet devices with FortiCloud Single Sign-On (SSO) enabled were found vulnerable to an actively exploited authentication bypass flaw (CVE-2025-59718/CVE-2025-59719). Threat actors leveraged a malicious SAML message to compromise admin accounts via the SSO interface, gaining unauthorized access to system configuration files that revealed credentials, service details, network layouts, and firewall policies. The wide exposure was confirmed by independent scans, while U.S. government agencies were urgently mandated by CISA to patch within a week due to mounting exploitation. This incident highlights the persistent risk posed by poorly secured administrative interfaces, unpatched vulnerabilities, and credential-access techniques. Escalating regulatory pressure and attacker focus on identity-driven infrastructure demonstrate the need for robust segmentation and detection across all exposed assets.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
China-backed APT 'LongNosedGoblin' Penetrates Asian Governments via Group Policy Abuse
Impact· high

China-backed APT 'LongNosedGoblin' Penetrates Asian Governments via Group Policy Abuse

In late 2025, cybersecurity researchers uncovered a sophisticated cyber-espionage campaign targeting multiple Southeast Asian and Japanese government entities, attributed to a new China-backed advanced persistent threat (APT) group known as LongNosedGoblin. Active since at least 2023, the group leveraged privileged access to Windows environments—specifically abusing legitimate Group Policy mechanisms to deploy malicious payloads, conduct lateral movement, and gain deep persistence within victim networks. Once entrenched, the attackers deployed a range of custom C#/.NET tools, including keyloggers, data exfiltration malware, and backdoor implants (NosyDoor), often using cloud services for command and control communications. The campaign highlights the risk of domain administrator credential compromise, allowing broad control across entire agency infrastructures. Fewer than a dozen victims were confirmed, but the attacks signify a moderate level of operator sophistication. This incident signals a shift in APT tactics toward leveraging built-in administrative utilities for stealthy malware distribution and lateral escalation, reducing detection risk. Use of cloud-based C2 and tailored tooling further complicate response and attribution, illustrating the urgency for proactive identity management and defense-in-depth protections across government and enterprise networks.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Issues 2025 Update: New Detection for BRICKSTORM Backdoor Malware
Impact· low

CISA Issues 2025 Update: New Detection for BRICKSTORM Backdoor Malware

In December 2025, CISA, the NSA, and the Canadian Centre for Cyber Security released an updated malware analysis report on the BRICKSTORM backdoor. The update detailed new Rust-based variants featuring advanced persistence, evasive execution as background services, and robust command and control via encrypted WebSocket connections. Organizations were provided with new YARA detection signatures and IOCs to bolster defenses and urged to scan for, report, and contain potential infections. This surge in sophisticated malware highlights evolving attacker tactics aimed at stealthy, persistent network infiltration. The growing adoption of advanced persistent threats such as BRICKSTORM underlines the critical need for proactive threat detection, zero trust segmentation, and cyber hygiene. Security teams must stay vigilant as attackers refine malware with encrypted communications and evasion strategies, while regulatory bodies continue to emphasize robust incident response.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports