The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Defense/Space
Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.
Explore Other Sectors
Defense/Space Threat Reports
PCIe Encryption Vulnerabilities Disclosed: 2025 Hardware Security Risks
In December 2025, three critical hardware vulnerabilities were disclosed in the Peripheral Component Interconnect Express (PCIe) Integrity and Data Encryption (IDE) protocol, impacting PCIe Base Specification Revision 5.0 and newer systems. These vulnerabilities—CVE-2025-9612, CVE-2025-9613, and CVE-2025-9614—enable local attackers with physical or low-level access to manipulate encrypted traffic, cause information disclosure, escalate privileges, or disrupt services. Affected products include select Intel Xeon and AMD EPYC processor lines. The flaws are notable for potentially undermining the core security objectives of IDE, especially in environments relying on trusted execution and encrypted data flows. This disclosure is particularly relevant as hardware-level vulnerabilities are increasingly leveraged by attackers seeking to evade conventional endpoint and network security controls. The need for integrity in encrypted data pathways is surging amid rising adoption of zero trust and compliance mandates, underscoring the urgency of prompt firmware patches and adherence to updated PCIe standards.
8 months ago
Kill Chain
Russian State-Backed Cyberattack Hits US Critical Infrastructure: Lessons from 2024
In 2024, U.S. authorities charged Ukrainian national Victoria Dubranova for her alleged involvement in Russian state-sponsored cyberattacks targeting critical infrastructure across the U.S. and allied nations. Dubranova is accused of collaborating with CyberArmyofRussia_Reborn (CARR) and NoName057(16), groups funded by Russian entities, to launch coordinated distributed denial of service (DDoS) and destructive intrusions. The attacks compromised water systems, food processing facilities, government bodies, and nuclear regulatory sites, resulting in water system sabotage, meat contamination, and emergency evacuations. Investigations revealed evolving tactics and recruitment methods, including custom malware (DDoSia) and incentivized hacktivist participation. This case underscores the escalating threat from state-backed cybercriminals targeting operational technology and essential services. As hacktivists innovate with new tools and social engineering, the risk to public utilities remains severe, prompting a regulatory and industry emphasis on network segmentation, reduced internet exposure, and proactive cyber defense.
8 months ago
Kill Chain
U-Boot Bootloader Flaw Threatens Global Manufacturing and Critical Infrastructure
In December 2025, a critical vulnerability (CVE-2025-24857) was disclosed in U-Boot, a widely-used bootloader for embedded systems, impacting all versions prior to 2017.11 and several Qualcomm chipsets. The flaw—improper access control for volatile memory containing boot code—allowed an attacker with local access to execute arbitrary code at boot, posing significant risk to devices across essential sectors including energy, communications, manufacturing, healthcare, and more. No active exploitation has been reported, but the vulnerability could undermine device integrity and operational security in globally deployed critical infrastructure systems. Mitigations include upgrading to the latest U-Boot version and implementing strict physical and network isolation measures. This incident underlines the persistent risk posed by supply chain and firmware vulnerabilities in critical infrastructure. With IoT and embedded device ubiquity rising, attackers are increasingly targeting low-level firmware to achieve persistence or bypass security, heightening regulatory scrutiny and emphasizing the need for proactive vulnerability management and secure device lifecycle practices.
8 months ago
Kill Chain
Poland Arrests Ukrainians in 2024 Espionage Cyber Incident
In June 2024, Polish authorities arrested three Ukrainian nationals accused of using sophisticated hacking equipment to carry out cyberattacks targeting Polish IT systems, with particular emphasis on the theft of 'computer data of particular importance to national defense.' The suspects were apprehended while allegedly attempting to damage government information technology infrastructure, utilizing encrypted communications and advanced attack tools likely designed to evade monitoring and facilitate data exfiltration. The incident underscores heightened tensions in the region and reveals vulnerabilities within national networks, with Polish law enforcement quickly intervening to mitigate further impact. This breach is emblematic of a broader escalation in nation-state cyber operations across Europe, featuring cross-border actors relying on advanced techniques to infiltrate sensitive targets. The event highlights the urgent need for robust east-west traffic security, encrypted communications, and real-time anomaly detection controls to guard national interests and critical IT environments.
8 months ago
Kill Chain
Iranian APT 'MuddyWater' Launches UDPGangster Backdoor in Multi-Nation Espionage Campaign
In late 2025, the Iranian cyber espionage group MuddyWater launched a targeted campaign against organizations in Turkey, Israel, and Azerbaijan using a novel backdoor dubbed UDPGangster. The malware leveraged UDP-based command-and-control channels to enable remote management of infected systems while evading traditional network detection techniques. Attacks typically began via spear-phishing emails containing malicious attachments or links, granting the attackers a foothold in victim environments and facilitating lateral movement and data exfiltration. Fortinet FortiGuard Labs was among the first to document the malware and its unique communication characteristics. The campaign highlighted substantial risks to critical sectors and national security in the affected countries. This incident exemplifies rising threat actor sophistication—specifically, abuse of obscure protocols like UDP for covert C2—and underscores the strategic evolution of Iranian groups. Its tactics reflect broader cyber espionage trends across the Middle East and signal urgent needs for advanced lateral movement detection and zero trust controls.
8 months ago
Kill Chain
CISA Issues Stark Warning on Ongoing Brickstorm Backdoor Attacks
In early 2024, the Cybersecurity and Infrastructure Security Agency (CISA) issued a warning regarding sustained state-sponsored attacks targeting VMware vSphere environments, attributed to China-linked advanced persistent threat (APT) groups. These actors deployed the 'Brickstorm' backdoor to compromise government and technology sector organizations, exploiting vulnerabilities to achieve persistence and lateral movement within affected networks. The intrusion enabled attackers to bypass security controls, maintain privileged access, and exfiltrate sensitive information, highlighting a persistent threat targeting virtualization infrastructure. This incident is notable as it reflects a concerning evolution in attacker tactics, specifically the abuse of virtualization platforms as an entry vector for espionage. The ongoing campaign underscores the urgent need for enhanced detection, segmentation, and defense against stealthy operations in hybrid and cloud environments.
8 months ago
Kill Chain
Major Insider Attack Wipes 96 US Government Databases: Lessons for 2024
In June 2024, two Virginia-based former federal contractors were accused of orchestrating a significant insider attack after being terminated from their government roles. Prosecutors allege the brothers conspired to steal sensitive information and deliberately wiped 96 critical government databases, severely disrupting several agencies' operations. The attack exploited their privileged access, allowing them to bypass existing controls and inflict lasting operational and data loss consequences. This incident highlights how trusted insiders with sufficient technical skills and unresolved grievances can weaponize their access against public-sector organizations, exposing gaps in monitoring and segmentation. Insider-powered destructive attacks are on the rise globally, targeting both public and private sectors with increasing sophistication. In a climate of heightened regulatory expectations and increasing adoption of zero trust models, this incident demonstrates the urgency to strengthen monitoring, privileged access controls, and anomaly detection to detect and prevent similar threats.
8 months ago
Kill Chain
How MuddyWater Used a Snake Game to Breach Israeli Networks in 2024
In early 2024, Iranian state-sponsored APT MuddyWater launched a series of cyberattacks against Israeli organizations using a novel evasion method involving a modified version of the classic Snake mobile game. Attackers embedded malicious code within the game to establish a covert communication channel and facilitate lateral movement within compromised networks. Initial access was likely achieved through phishing emails, followed by deployment of specially crafted files to disguise data exfiltration activities. The campaign resulted in unauthorized access to sensitive data and disruption of critical business operations for targeted Israeli entities. This incident highlights a growing trend of threat actors leveraging benign-looking applications and creative techniques to bypass traditional security controls. The use of retro games as a decoy demonstrates that sophisticated attackers are continually adapting, raising the bar for detection and forensic analysis across industries.
8 months ago
Kill Chain
How Iran's MuddyWater APT Used Memory-Only Malware for Stealthy Espionage in 2024
In early 2024, the Iranian state-backed actor MuddyWater significantly evolved its tradecraft by deploying a new memory-only loader, codenamed Fooder, and the stealthy 'MuddyViper' backdoor in espionage campaigns. The group, previously known for noisy operations, shifted to fileless malware and in-memory tactics targeting government and critical infrastructure networks in the Middle East and beyond. These attacks enabled extended persistence, facilitated lateral movement, and were effective at evading traditional endpoint detection and response solutions. As a result, targeted organizations faced serious risk of data theft and operational compromise before the campaign was exposed by security researchers. This incident marks a growing trend of threat actors adopting advanced memory-only and fileless TTPs to avoid detection. The operational upgrade by MuddyWater highlights increased sophistication among nation-state adversaries and reinforces the urgent need for advanced threat detection and stronger east-west network controls.
8 months ago
Kill Chain
Lazarus APT’s Remote-Worker Ruse: How North Korean Hackers Infiltrated via Trusted IT Contractors
In late 2025, cybersecurity researchers from BCA LTD, NorthScan, and ANY.RUN captured an active infiltration by North Korea’s Lazarus Group (specifically the Famous Chollima division) leveraging remote IT workers implanted in Western organizations. This highly coordinated campaign used the appearance of legitimate remote workers—often hired via freelance and IT staffing platforms—to discreetly gain access to internal systems, exfiltrate sensitive data, and facilitate the deployment of malware directly through trusted accounts. The operation showcased sophisticated methods for circumventing east-west traffic controls and exploiting trusted relationships, posing a direct risk to organizations’ hybrid and cloud environments. This breach exemplifies the quick evolution of nation-state threat actors exploiting global remote work and cloud-native architectures. As the use of remote staff and contractors surges, organizations face mounting pressure to implement zero trust controls and granular segmentation to prevent well-resourced APTs from leveraging trusted credentials for deep access and stealthy lateral movement.
8 months ago
Kill Chain
How Iran Blended Cyber and Kinetic Strikes: The 2024 Critical Infrastructure Attack
In early 2024, Iranian state-sponsored threat actors coordinated sophisticated cyber-attacks in parallel with kinetic strikes targeting maritime and land-based assets in the Middle East. Leveraging advanced reconnaissance and lateral movement within targeted networks, attackers exploited encrypted and unencrypted traffic flows to identify critical systems and facilitate precision missile and drone attacks. These operations, often timed to coincide with physical assaults, compromised internal infrastructure, leading to service disruption, operational delays, and data exfiltration impacting both regional governments and commercial enterprises. This incident highlights a rapidly evolving threat landscape where nation-state adversaries integrate cyber intrusions with physical warfare. The tactical use of data from east-west traffic, paired with real-time targeting for kinetic operations, signals the urgent need for organizations to elevate network segmentation, encryption standards, and visibility to meet new regulatory and threat actor challenges.
8 months ago
Kill Chain
Rockwell Automation Arena Simulation Buffer Overflow (2025): Risks to Industrial Control Systems
In November 2025, Rockwell Automation disclosed a stack-based buffer overflow vulnerability (CVE-2025-11918) in its Arena Simulation software (versions 16.20.10 and earlier). The flaw, reported by security researcher Michael Heinzl, enables local attackers to execute arbitrary code by tricking users into opening a malicious DOE file. While the vulnerability is not exploitable remotely, it presents a significant risk to organizations leveraging Arena for critical manufacturing automation, especially when adequate segmentation and endpoint security controls are lacking. No public exploitation has been reported to date, and the vendor has released a security update to address the issue. This incident is a reminder of the persistence of file parsing vulnerabilities in industrial software, which continue to enable initial compromise via local vectors like engineered files or insider threats. The increase in similar vulnerabilities and the possibility of operational technology (OT) system breaches intensify the call for zero-trust and defense-in-depth strategies within the manufacturing sector.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports