The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Defense/Space
Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.
Explore Other Sectors
Defense/Space Threat Reports
SiRcom Vulnerability Exposes Critical Siren Systems to Hijack (2025)
In November 2025, a critical vulnerability (CVE-2025-13483) was disclosed in SiRcom SMART Alert (SiSA), a central emergency alert management system used globally in emergency services, government, and defense sectors. The flaw, due to missing authentication for critical API functions, enabled unauthenticated attackers to access restricted backend operations. Successful exploitation could allow remote manipulation and activation of emergency sirens, posing wide-reaching operational and safety risks to affected communities. The vulnerability, assigned a CVSS v4 score of 8.8, was initially reported by Microsec researcher Souvik Kandar. This incident highlights the persistent risks posed by missing authentication in critical infrastructure applications. With remote exploitation possible and attackers’ interest in manipulating physical environments on the rise, it underscores the urgent need for robust authentication, especially amid compliance and regulatory tightening in the critical infrastructure sector.
8 months ago
Kill Chain
Google Uncovers BadAudio Malware in Chinese APT24 Espionage Campaign
In early 2024, Google’s Threat Analysis Group uncovered a sophisticated, years-long cyber espionage campaign orchestrated by the China-linked APT24 threat group. The attackers leveraged a newly discovered malware dubbed BadAudio to infiltrate government agencies, research institutions, and select private organizations. Initial access was obtained via spear-phishing campaigns, progressing to persistent lateral movement within compromised environments. BadAudio’s deployment enabled covert data exfiltration over encrypted channels, evading standard security controls and providing unmatched visibility and persistence for the attackers. The incident highlights the advanced tradecraft and evolving toolsets in use by nation-state threat actors, with business impacts centered on the loss of sensitive data and the undermining of critical organizational trust. The exposure of BadAudio signals a notable escalation in cyber espionage tactics, utilizing bespoke malware and encrypted traffic to circumvent modern defenses. Organizations across sectors are at risk as threat groups adopt similar methods, prompting increased scrutiny from regulators and heightened awareness around securing east-west traffic and anomaly detection.
8 months ago
Kill Chain
Iran-Linked Hackers Fuse Cyber Espionage and Kinetic Strikes with Ship AIS Breach
In November 2025, state-sponsored hackers tied to Iran conducted a sophisticated cyber operation targeting maritime assets by mapping Automatic Identification System (AIS) data of commercial ships transiting a volatile region. Advanced reconnaissance and cyber infiltration enabled the attackers to gather real-time ship movement and metadata, informing a coordinated missile strike days later. The breach demonstrated tight integration between cyber-enabled intelligence collection and traditional kinetic attacks, raising alarm within global shipping, defense, and infrastructure sectors. The incident highlights a dangerous evolution in the use of cyber capabilities to directly amplify physical-world conflict and disruption. The rapid fusion of cyber warfare with real-world military operations signals a new era of threats that transcend digital boundaries. As geopolitical tensions escalate and critical infrastructure remains vulnerable, robust cyber and operational defenses are imperative for organizations at risk of becoming targets in hybrid war campaigns.
8 months ago
Kill Chain
China-Backed PlushDaemon APT Leverages Network Devices for Advanced MitM Attacks (2024)
In 2024, ESET researchers uncovered a sustained campaign by the China-linked PlushDaemon APT that targeted edge and network devices in government, telecommunications, and technology sectors, enabling advanced adversary-in-the-middle (AitM) attacks. PlushDaemon deployed a sophisticated network implant capable of intercepting, modifying, and redirecting encrypted and unencrypted traffic, allowing the threat actor to facilitate credential theft and covert surveillance. The operation exploited weak segmentation and insufficient east-west controls, compromising business operations and exposing sensitive communications to persistent espionage. This incident is particularly relevant as APTs increasingly leverage traffic interception at the network device layer, bypassing traditional endpoint security and highlighting urgent gaps in zero trust, segmentation, and encrypted traffic monitoring solutions.
8 months ago
Kill Chain
Amazon Warns: MuddyWater Cyberattack Bridges Digital and Kinetic Warfare
In June 2024, Amazon Threat Intelligence reported a sophisticated, nation-state cyberattack demonstrating the merging of cyber and kinetic warfare. The Iranian-backed MuddyWater group leveraged compromised CCTV infrastructure in Jerusalem to obtain real-time intelligence, directly enabling more precise missile strikes against physical targets. Attackers provisioned infrastructure and infiltrated CCTV feeds a month in advance, highlighting a deliberate and strategic approach to combining digital reconnaissance with physical attack vectors. Israeli authorities confirmed that this real-time data was used to adjust targeting during the incident, leading to heightened operational impact and escalating concerns for critical infrastructure operators. This incident underscores an alarming trend: cyber-espionage operations now increasingly serve as force multipliers for military actions. The blurred line between cyber and physical domains exemplifies an evolution in threat tactics, with nation-state actors exploiting enterprise networks as entry points for real-world impact. Security leaders must recognize this convergence and adapt defense and intelligence sharing accordingly.
8 months ago
Kill Chain
CISA Forces Rapid Patch of Fortinet Zero-Day Exploited in Real Attacks
In June 2024, U.S. government agencies were urgently ordered by CISA to patch a critical vulnerability in Fortinet's FortiWeb web application firewall after it was discovered being exploited as a zero-day. Threat actors leveraged this flaw to bypass security controls, potentially gaining unauthorized access to sensitive government systems. The incident underscores the persistent targeting of network edge devices and highlights the risks associated with unpatched security infrastructure. The rapid CISA directive required agencies to address the exploit within seven days, reflecting the severe operational risk and potential for further compromise. This event demonstrates a rising focus on web application and perimeter device vulnerabilities by sophisticated adversaries, especially those exploiting zero-days. The urgency of the directive and the exploitation method signal a larger industry trend: attackers increasingly prioritize zero-day vulnerabilities in widely deployed security products to maximize impact and evade detection.
8 months ago
Kill Chain
Iran-Nexus UNC1549 Targets Aerospace: 2024 Cyberattack Details
In early 2024, the Iranian-aligned threat actor group identified as UNC1549 orchestrated targeted cyberattacks against aerospace and defense organizations across the US, Israel, UAE, Qatar, Spain, and Saudi Arabia. Researchers discovered that the group leveraged sophisticated spear-phishing campaigns and custom malware implants to infiltrate sensitive networks, focusing primarily on exfiltrating confidential intellectual property and operational data. The campaign showcased advanced persistence techniques and bypassed standard security controls, leading to operational disruption and heightened espionage risk for impacted organizations. These attacks highlight a broader trend of nation-state threat actors increasingly focusing on strategic sectors with evolving tools and tactics. The targeting of multiple geographies underscores the global nature of aerospace security risks and pressing regulatory and compliance expectations.
8 months ago
Kill Chain
Iranian Espionage Campaign Uses DEEPROOT & TWOSTROKE in Aerospace and Defense Breach (2025)
In late 2025, an Iranian-linked threat group known as UNC1549 targeted aerospace and defense organizations in the Middle East, deploying custom backdoors named TWOSTROKE and DEEPROOT. The attackers gained access through spear-phishing and strategic web compromises, establishing persistent footholds and enabling sustained espionage operations. Google-owned Mandiant attributed the campaign to advanced initial access and lateral movement techniques, allowing the threat actors to blend into legitimate network activity while exfiltrating sensitive intellectual property and operational data. The campaign underscored weaknesses in internal segmentation, encrypted traffic oversight, and anomaly detection within high-value verticals. This incident highlights an uptick in sophisticated espionage attacks on critical infrastructure using tailored malware and stealthy, post-compromise tactics. The use of novel backdoors and multi-stage intrusion campaigns demonstrates an evolving threat landscape, emphasizing the need for deeper defense in depth and zero trust approaches among organizations handling sensitive data.
8 months ago
Kill Chain
Chinese State Hackers Weaponize Anthropic AI in Automated 2025 Espionage Campaign
In September 2025, state-sponsored Chinese cyber actors launched a highly automated espionage campaign leveraging artificial intelligence technology developed by Anthropic. The attackers exploited the 'agentic' capabilities of advanced AI systems, automating reconnaissance, payload development, and intrusion execution at a scale not previously observed. Attack vectors included automating phishing, adaptive malware payloads, and real-time east-west movement within compromised enterprise networks. The campaign resulted in significant data exfiltration from several multinational organizations, exposing sensitive proprietary information and triggering high-level security responses. This incident marks a turning point in offensive cyber operations, as AI-driven, autonomous attacks blur the line between traditional human-led tactics and machine-accelerated campaigns. Organizations face urgent pressure to redesign controls that address rapidly evolving AI-based threats that often outpace traditional detections and response frameworks.
8 months ago
Kill Chain
APT42’s ‘SpearSpecter’: Iranian State Hackers Breach Defense & Government Targets in 2025
In September 2025, the Iranian state-sponsored threat group APT42 launched a targeted cyber-espionage campaign, codenamed 'SpearSpecter', against global defense and government organizations with ties or relevance to the Iranian Islamic Revolutionary Guard Corps (IRGC). Attackers employed spear-phishing and advanced malware to infiltrate internal systems, establish encrypted backdoors, and move laterally, aiming to gather intelligence and monitor sensitive communications. The operation has compromised multiple agencies, with impacts including loss of classified data and exposure of critical government operations. This incident underscores the intensifying sophistication of state-sponsored actors leveraging advanced persistence techniques and custom tooling to evade detection. These campaigns highlight the persistent threat posed by geopolitically motivated attacks and the urgent need for robust intrusion detection and segmenting sensitive assets.
8 months ago
Kill Chain
US Citizens Busted for Aiding North Korean IT Worker Supply-Chain Fraud in 2024
In 2024, four United States citizens pleaded guilty to helping North Korean nationals surreptitiously secure IT positions at American companies by misrepresenting the workers’ identities and providing remote access to corporate assets. This insider-assisted scheme enabled foreign IT professionals to bypass typical background checks and compliance controls, giving them potential access to sensitive information and intellectual property. The activities ran over a sustained period and leveraged supply-chain weaknesses in remote workforce onboarding and equipment provisioning, ultimately exposing numerous U.S. firms to regulatory and operational risk. This incident underscores a worrying trend in which threat actors exploit remote work arrangements, weak identity verification protocols, and gaps in third-party management—highlighting increased regulatory scrutiny on supply-chain and insider vulnerabilities, especially amid ongoing geopolitical tensions involving North Korea.
8 months ago
Kill Chain
CISA Alert: Active Exploitation of Cisco ASA & Firepower Devices in 2024
In June 2024, CISA issued an urgent alert to federal agencies following the discovery of active exploitation of two critical vulnerabilities (CVE-2024-20353 and CVE-2024-20359) in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices. Threat actors leveraged these flaws to bypass authentication and remotely execute code, potentially enabling lateral movement and unauthorized network access. Several government and enterprise environments were left exposed due to unpatched systems, raising significant risk to sensitive operations and regulated data. This incident underscores the growing sophistication of cybercriminals targeting network infrastructure, particularly edge devices, and highlights the urgent need for rapid patch management and network segmentation as threat vectors continually evolve.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports