The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Defense/Space

Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.

418 threat reports
Page 28 of 35

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Defense/Space Threat Reports

Showing 325–336 / 418 reports
SiRcom Vulnerability Exposes Critical Siren Systems to Hijack (2025)
Impact· high

SiRcom Vulnerability Exposes Critical Siren Systems to Hijack (2025)

In November 2025, a critical vulnerability (CVE-2025-13483) was disclosed in SiRcom SMART Alert (SiSA), a central emergency alert management system used globally in emergency services, government, and defense sectors. The flaw, due to missing authentication for critical API functions, enabled unauthenticated attackers to access restricted backend operations. Successful exploitation could allow remote manipulation and activation of emergency sirens, posing wide-reaching operational and safety risks to affected communities. The vulnerability, assigned a CVSS v4 score of 8.8, was initially reported by Microsec researcher Souvik Kandar. This incident highlights the persistent risks posed by missing authentication in critical infrastructure applications. With remote exploitation possible and attackers’ interest in manipulating physical environments on the rise, it underscores the urgent need for robust authentication, especially amid compliance and regulatory tightening in the critical infrastructure sector.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Google Uncovers BadAudio Malware in Chinese APT24 Espionage Campaign
Impact· low

Google Uncovers BadAudio Malware in Chinese APT24 Espionage Campaign

In early 2024, Google’s Threat Analysis Group uncovered a sophisticated, years-long cyber espionage campaign orchestrated by the China-linked APT24 threat group. The attackers leveraged a newly discovered malware dubbed BadAudio to infiltrate government agencies, research institutions, and select private organizations. Initial access was obtained via spear-phishing campaigns, progressing to persistent lateral movement within compromised environments. BadAudio’s deployment enabled covert data exfiltration over encrypted channels, evading standard security controls and providing unmatched visibility and persistence for the attackers. The incident highlights the advanced tradecraft and evolving toolsets in use by nation-state threat actors, with business impacts centered on the loss of sensitive data and the undermining of critical organizational trust. The exposure of BadAudio signals a notable escalation in cyber espionage tactics, utilizing bespoke malware and encrypted traffic to circumvent modern defenses. Organizations across sectors are at risk as threat groups adopt similar methods, prompting increased scrutiny from regulators and heightened awareness around securing east-west traffic and anomaly detection.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Iran-Linked Hackers Fuse Cyber Espionage and Kinetic Strikes with Ship AIS Breach
Impact· high

Iran-Linked Hackers Fuse Cyber Espionage and Kinetic Strikes with Ship AIS Breach

In November 2025, state-sponsored hackers tied to Iran conducted a sophisticated cyber operation targeting maritime assets by mapping Automatic Identification System (AIS) data of commercial ships transiting a volatile region. Advanced reconnaissance and cyber infiltration enabled the attackers to gather real-time ship movement and metadata, informing a coordinated missile strike days later. The breach demonstrated tight integration between cyber-enabled intelligence collection and traditional kinetic attacks, raising alarm within global shipping, defense, and infrastructure sectors. The incident highlights a dangerous evolution in the use of cyber capabilities to directly amplify physical-world conflict and disruption. The rapid fusion of cyber warfare with real-world military operations signals a new era of threats that transcend digital boundaries. As geopolitical tensions escalate and critical infrastructure remains vulnerable, robust cyber and operational defenses are imperative for organizations at risk of becoming targets in hybrid war campaigns.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
China-Backed PlushDaemon APT Leverages Network Devices for Advanced MitM Attacks (2024)
Impact· medium

China-Backed PlushDaemon APT Leverages Network Devices for Advanced MitM Attacks (2024)

In 2024, ESET researchers uncovered a sustained campaign by the China-linked PlushDaemon APT that targeted edge and network devices in government, telecommunications, and technology sectors, enabling advanced adversary-in-the-middle (AitM) attacks. PlushDaemon deployed a sophisticated network implant capable of intercepting, modifying, and redirecting encrypted and unencrypted traffic, allowing the threat actor to facilitate credential theft and covert surveillance. The operation exploited weak segmentation and insufficient east-west controls, compromising business operations and exposing sensitive communications to persistent espionage. This incident is particularly relevant as APTs increasingly leverage traffic interception at the network device layer, bypassing traditional endpoint security and highlighting urgent gaps in zero trust, segmentation, and encrypted traffic monitoring solutions.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Amazon Warns: MuddyWater Cyberattack Bridges Digital and Kinetic Warfare
Impact· medium

Amazon Warns: MuddyWater Cyberattack Bridges Digital and Kinetic Warfare

In June 2024, Amazon Threat Intelligence reported a sophisticated, nation-state cyberattack demonstrating the merging of cyber and kinetic warfare. The Iranian-backed MuddyWater group leveraged compromised CCTV infrastructure in Jerusalem to obtain real-time intelligence, directly enabling more precise missile strikes against physical targets. Attackers provisioned infrastructure and infiltrated CCTV feeds a month in advance, highlighting a deliberate and strategic approach to combining digital reconnaissance with physical attack vectors. Israeli authorities confirmed that this real-time data was used to adjust targeting during the incident, leading to heightened operational impact and escalating concerns for critical infrastructure operators. This incident underscores an alarming trend: cyber-espionage operations now increasingly serve as force multipliers for military actions. The blurred line between cyber and physical domains exemplifies an evolution in threat tactics, with nation-state actors exploiting enterprise networks as entry points for real-world impact. Security leaders must recognize this convergence and adapt defense and intelligence sharing accordingly.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Forces Rapid Patch of Fortinet Zero-Day Exploited in Real Attacks
Impact· low

CISA Forces Rapid Patch of Fortinet Zero-Day Exploited in Real Attacks

In June 2024, U.S. government agencies were urgently ordered by CISA to patch a critical vulnerability in Fortinet's FortiWeb web application firewall after it was discovered being exploited as a zero-day. Threat actors leveraged this flaw to bypass security controls, potentially gaining unauthorized access to sensitive government systems. The incident underscores the persistent targeting of network edge devices and highlights the risks associated with unpatched security infrastructure. The rapid CISA directive required agencies to address the exploit within seven days, reflecting the severe operational risk and potential for further compromise. This event demonstrates a rising focus on web application and perimeter device vulnerabilities by sophisticated adversaries, especially those exploiting zero-days. The urgency of the directive and the exploitation method signal a larger industry trend: attackers increasingly prioritize zero-day vulnerabilities in widely deployed security products to maximize impact and evade detection.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Iran-Nexus UNC1549 Targets Aerospace: 2024 Cyberattack Details
Impact· low

Iran-Nexus UNC1549 Targets Aerospace: 2024 Cyberattack Details

In early 2024, the Iranian-aligned threat actor group identified as UNC1549 orchestrated targeted cyberattacks against aerospace and defense organizations across the US, Israel, UAE, Qatar, Spain, and Saudi Arabia. Researchers discovered that the group leveraged sophisticated spear-phishing campaigns and custom malware implants to infiltrate sensitive networks, focusing primarily on exfiltrating confidential intellectual property and operational data. The campaign showcased advanced persistence techniques and bypassed standard security controls, leading to operational disruption and heightened espionage risk for impacted organizations. These attacks highlight a broader trend of nation-state threat actors increasingly focusing on strategic sectors with evolving tools and tactics. The targeting of multiple geographies underscores the global nature of aerospace security risks and pressing regulatory and compliance expectations.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Iranian Espionage Campaign Uses DEEPROOT & TWOSTROKE in Aerospace and Defense Breach (2025)
Impact· medium

Iranian Espionage Campaign Uses DEEPROOT & TWOSTROKE in Aerospace and Defense Breach (2025)

In late 2025, an Iranian-linked threat group known as UNC1549 targeted aerospace and defense organizations in the Middle East, deploying custom backdoors named TWOSTROKE and DEEPROOT. The attackers gained access through spear-phishing and strategic web compromises, establishing persistent footholds and enabling sustained espionage operations. Google-owned Mandiant attributed the campaign to advanced initial access and lateral movement techniques, allowing the threat actors to blend into legitimate network activity while exfiltrating sensitive intellectual property and operational data. The campaign underscored weaknesses in internal segmentation, encrypted traffic oversight, and anomaly detection within high-value verticals. This incident highlights an uptick in sophisticated espionage attacks on critical infrastructure using tailored malware and stealthy, post-compromise tactics. The use of novel backdoors and multi-stage intrusion campaigns demonstrates an evolving threat landscape, emphasizing the need for deeper defense in depth and zero trust approaches among organizations handling sensitive data.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Chinese State Hackers Weaponize Anthropic AI in Automated 2025 Espionage Campaign
Impact· medium

Chinese State Hackers Weaponize Anthropic AI in Automated 2025 Espionage Campaign

In September 2025, state-sponsored Chinese cyber actors launched a highly automated espionage campaign leveraging artificial intelligence technology developed by Anthropic. The attackers exploited the 'agentic' capabilities of advanced AI systems, automating reconnaissance, payload development, and intrusion execution at a scale not previously observed. Attack vectors included automating phishing, adaptive malware payloads, and real-time east-west movement within compromised enterprise networks. The campaign resulted in significant data exfiltration from several multinational organizations, exposing sensitive proprietary information and triggering high-level security responses. This incident marks a turning point in offensive cyber operations, as AI-driven, autonomous attacks blur the line between traditional human-led tactics and machine-accelerated campaigns. Organizations face urgent pressure to redesign controls that address rapidly evolving AI-based threats that often outpace traditional detections and response frameworks.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
APT42’s ‘SpearSpecter’: Iranian State Hackers Breach Defense & Government Targets in 2025
Impact· low

APT42’s ‘SpearSpecter’: Iranian State Hackers Breach Defense & Government Targets in 2025

In September 2025, the Iranian state-sponsored threat group APT42 launched a targeted cyber-espionage campaign, codenamed 'SpearSpecter', against global defense and government organizations with ties or relevance to the Iranian Islamic Revolutionary Guard Corps (IRGC). Attackers employed spear-phishing and advanced malware to infiltrate internal systems, establish encrypted backdoors, and move laterally, aiming to gather intelligence and monitor sensitive communications. The operation has compromised multiple agencies, with impacts including loss of classified data and exposure of critical government operations. This incident underscores the intensifying sophistication of state-sponsored actors leveraging advanced persistence techniques and custom tooling to evade detection. These campaigns highlight the persistent threat posed by geopolitically motivated attacks and the urgent need for robust intrusion detection and segmenting sensitive assets.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
US Citizens Busted for Aiding North Korean IT Worker Supply-Chain Fraud in 2024
Impact· low

US Citizens Busted for Aiding North Korean IT Worker Supply-Chain Fraud in 2024

In 2024, four United States citizens pleaded guilty to helping North Korean nationals surreptitiously secure IT positions at American companies by misrepresenting the workers’ identities and providing remote access to corporate assets. This insider-assisted scheme enabled foreign IT professionals to bypass typical background checks and compliance controls, giving them potential access to sensitive information and intellectual property. The activities ran over a sustained period and leveraged supply-chain weaknesses in remote workforce onboarding and equipment provisioning, ultimately exposing numerous U.S. firms to regulatory and operational risk. This incident underscores a worrying trend in which threat actors exploit remote work arrangements, weak identity verification protocols, and gaps in third-party management—highlighting increased regulatory scrutiny on supply-chain and insider vulnerabilities, especially amid ongoing geopolitical tensions involving North Korea.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CISA Alert: Active Exploitation of Cisco ASA & Firepower Devices in 2024
Impact· medium

CISA Alert: Active Exploitation of Cisco ASA & Firepower Devices in 2024

In June 2024, CISA issued an urgent alert to federal agencies following the discovery of active exploitation of two critical vulnerabilities (CVE-2024-20353 and CVE-2024-20359) in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices. Threat actors leveraged these flaws to bypass authentication and remotely execute code, potentially enabling lateral movement and unauthorized network access. Several government and enterprise environments were left exposed due to unpatched systems, raising significant risk to sensitive operations and regulated data. This incident underscores the growing sophistication of cybercriminals targeting network infrastructure, particularly edge devices, and highlights the urgent need for rapid patch management and network segmentation as threat vectors continually evolve.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports