The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Defense/Space

Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.

418 threat reports
Page 3 of 35

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Defense/Space Threat Reports

Showing 25–36 / 418 reports
Critical Privilege Escalation Vulnerabilities Discovered in Rockwell Automation Industrial Systems
Impact· HIGH

Critical Privilege Escalation Vulnerabilities Discovered in Rockwell Automation Industrial Systems

In September 2026, CISA disclosed two critical privilege escalation vulnerabilities (CVE-2026-9633 and CVE-2026-9634) in Rockwell Automation's Redundancy Module Configuration Tool affecting versions 9.00.00 through 10.00.00. The vulnerabilities stem from incorrect default permissions that allow the tool's executables to search for required DLLs in directories writable by standard users. If exploited, local attackers can place malicious DLLs in these directories, which are then loaded with Administrator/SYSTEM privileges when the tool is run by an administrator. Rockwell Automation has released version 10.01.00 to address these issues, affecting critical manufacturing infrastructure worldwide. This incident highlights the persistent threat of DLL hijacking attacks in industrial control systems, particularly as organizations modernize their operational technology environments. With increasing convergence of IT and OT networks, such privilege escalation vulnerabilities pose significant risks to critical infrastructure security and operational continuity.

3 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
DoD Refrigeration Systems Under Cyber Attack: When Supply Chains Become Attack Vectors
Impact· MEDIUM

DoD Refrigeration Systems Under Cyber Attack: When Supply Chains Become Attack Vectors

In August 2026, multiple U.S. Department of Defense military base commissaries experienced simultaneous refrigeration system failures across at least seven installations, including Fort Irwin, F.E. Warren Air Force Base, Fort Huachuca, Naval Station Newport, Columbus Air Force Base, Travis Air Force Base, and Naval Air Station Lemoore. The coordinated nature and timing of these outages strongly suggests a sophisticated cyber attack targeting critical infrastructure systems within the military supply chain. The Pentagon acknowledged awareness of the disruptions but declined to provide details about the scope or attribution of the incidents. This incident highlights the growing threat to operational technology and IoT devices within critical infrastructure environments. As nation-state actors increasingly target supply chain vulnerabilities and connected systems, the simultaneous failure of refrigeration systems across geographically dispersed military installations demonstrates how cyber threats can disrupt essential services and potentially compromise food safety and operational readiness.

3 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
ownCloud Vulnerability CVE-2023-49105 Exploited in Philippine Nuclear Espionage Campaign
Impact· CRITICAL

ownCloud Vulnerability CVE-2023-49105 Exploited in Philippine Nuclear Espionage Campaign

In August 2026, a Chinese-speaking threat actor exploited CVE-2023-49105, a critical ownCloud WebDAV authentication bypass vulnerability, to steal sensitive nuclear research data from a Philippine research body. The attacker used custom Python scripts to exploit the flaw's pre-signed URL mechanism, downloading 176 files totaling 372 MB including nuclear material records, strategic plans, reactor components, and employee data. The incident also involved a parallel attack on a Philippine marine engineering company serving the Navy, exploiting CVE-2024-28000 in WordPress LiteSpeed Cache plugin, highlighting coordinated cyber espionage targeting Philippine defense and nuclear sectors. This incident underscores the escalating cyber threats targeting critical infrastructure in the Asia-Pacific region amid South China Sea tensions, with state-affiliated actors increasingly focusing on nuclear and defense-related intelligence gathering through unpatched cloud collaboration platforms.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
NovaCookies Phishing Campaign Weaponizes DocuSign to Hijack Microsoft 365 Sessions
Impact· MEDIUM

NovaCookies Phishing Campaign Weaponizes DocuSign to Hijack Microsoft 365 Sessions

NovaCookies, a subscription-based phishing platform advertised on Telegram for $320 monthly, has compromised hundreds of organizations across the U.S., U.K., Germany, and U.A.E. by systematically targeting Microsoft 365 sessions. Operating as an Adversary-in-the-Middle proxy, the platform exploits legitimate DocuSign services to deliver counterfeit document-sharing notifications that bypass standard security filters. The attack uses OAuth error-redirect techniques to guide victims through legitimate Microsoft endpoints before routing them to phishing infrastructure, enabling real-time theft of credentials and multi-factor authentication codes. This incident highlights the evolving sophistication of phishing-as-a-service platforms that leverage trusted cloud services to evade detection, representing a growing trend where threat actors weaponize legitimate business applications to conduct large-scale credential harvesting operations against corporate networks.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Vulnerabilities Expose All-Line Equipment Fuel-Boss Industrial Control Systems to Remote Attacks
Impact· CRITICAL

Critical Vulnerabilities Expose All-Line Equipment Fuel-Boss Industrial Control Systems to Remote Attacks

All-Line Equipment Company's Fuel-Boss industrial control systems across multiple variants (Standard, Portal, Master/Slave, and Backflush Systems) contain critical vulnerabilities CVE-2018-19518 and CVE-2019-11043 affecting PHP 7.1.5 implementations. These vulnerabilities enable remote code execution through argument injection and buffer overflow attacks, with CVSS scores reaching 8.7-9.4. The systems are deployed worldwide across critical infrastructure sectors including manufacturing, defense, emergency services, and transportation. While fixes are available for Standard and Portal variants, Master/Slave systems remain unpatched and Backflush Systems will not receive updates, leaving significant exposure in operational technology environments. This incident highlights the growing convergence of IT and OT security risks as legacy industrial systems with outdated software components become increasingly connected to enterprise networks and the internet, creating new attack vectors for threat actors targeting critical infrastructure.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical Security Flaws Expose Unitree Humanoid Robots to Remote Takeover
Impact· HIGH

Critical Security Flaws Expose Unitree Humanoid Robots to Remote Takeover

Security researcher Olivier Laflamme disclosed two critical root remote code execution vulnerabilities affecting Unitree G1 EDU humanoid robots in August 2026. CVE-2026-76639 exploits a path traversal flaw in the chat_go component to reach bashrunner, while CVE-2026-76640 enables Bluetooth Low Energy attacks that can compromise the robot's Locomotion PC without pairing. The vulnerabilities allowed attackers to gain root access through network-adjacent attacks or proximity-based Bluetooth exploitation, with Unitree partially addressing cloud authorization issues in July 2026 but leaving firmware patches unconfirmed. This incident highlights the growing security risks in autonomous robotics and IoT devices as they become more prevalent in industrial and consumer environments. The combination of wireless attack vectors and critical system access demonstrates the urgent need for robust security frameworks in next-generation robotic platforms.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
BlueDelta's HOOKEDGE Campaign: How Russian APT28 Evolved Diplomatic Espionage Tactics
Impact· HIGH

BlueDelta's HOOKEDGE Campaign: How Russian APT28 Evolved Diplomatic Espionage Tactics

Between September 2025 and April 2026, Russian state-sponsored threat group BlueDelta (APT28, Fancy Bear) conducted sophisticated espionage campaigns targeting government and diplomatic organizations in Romania, Spain, and Turkey. The group deployed HOOKEDGE, a lightweight batch-script backdoor delivered through macro-enabled Microsoft Word documents using diplomatic-themed lures, including materials impersonating Spain's Ministry of the Presidency. HOOKEDGE represents an evolution of BlueDelta's earlier HEADLACE malware, utilizing legitimate webhook services for command-and-control operations to blend malicious traffic with normal network activity while targeting European diplomatic entities for intelligence collection. This campaign demonstrates the continuing evolution of state-sponsored espionage tactics, particularly the refinement of lightweight malware tools that can evade detection while maintaining operational effectiveness. As geopolitical tensions escalate and diplomatic intelligence becomes increasingly valuable, threat actors are adapting their methods to exploit legitimate cloud services and social engineering techniques.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
FBI Disrupts Chinese QTFY Espionage Network: How Advanced Proxy Infrastructure Threatens Critical Systems
Impact· HIGH

FBI Disrupts Chinese QTFY Espionage Network: How Advanced Proxy Infrastructure Threatens Critical Systems

In August 2026, the FBI disrupted a sophisticated Chinese state-sponsored cyber espionage operation run by threat actor QTFY/QT/QTCYBER, which provided reconnaissance, proxy management, and operational routing capabilities for attacks on U.S. critical infrastructure. The group, connected to China's Ministry of State Security and employing former People's Liberation Army members, operated QScan reconnaissance platforms and QTRouter obfuscation networks to target NASA, the Federal Reserve, Departments of Energy and Justice, NIH, and the U.S. Senate. Their infrastructure utilized compromised IoT devices and commercial proxy services to create an evasive Operational Relay Box (ORB) network that blended espionage traffic with legitimate consumer proxy traffic. This incident highlights the evolving sophistication of state-sponsored espionage operations that increasingly leverage commercial proxy infrastructure and compromised IoT devices to evade detection, representing a significant escalation in cyber warfare tactics targeting critical national infrastructure.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
GPUThor Rowhammer Attack Defeats NVIDIA ECC Protection in AI Infrastructure
Impact· HIGH

GPUThor Rowhammer Attack Defeats NVIDIA ECC Protection in AI Infrastructure

University of Toronto researchers disclosed GPUThor, a sophisticated Rowhammer attack that bypasses NVIDIA's Error-Correcting Code (ECC) protections on Ampere-class workstation GPUs including RTX A4000, A4500, A5000, and A6000 models. The attack exploits undocumented GPU behaviors to avoid Target Row Refresh mitigations, achieving bit-flip rates up to 377,000 flips per GB and enabling denial-of-service conditions and root-level privilege escalation within 1.1 minutes. GPUThor demonstrates 4,548 to 23,597 times higher effectiveness than previous GPU Rowhammer attacks, posing significant risks to AI infrastructure and cloud environments relying on these widely deployed GPU models for machine learning workloads. This vulnerability highlights the growing sophistication of hardware-level attacks targeting AI infrastructure as organizations increasingly depend on GPU-accelerated computing for critical business operations and model training.

4 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Iranian APT Nimbus Manticore Deploys Advanced SSH Tunneling and Backdoor Tools
Impact· HIGH

Iranian APT Nimbus Manticore Deploys Advanced SSH Tunneling and Backdoor Tools

In August 2026, cybersecurity researchers discovered new infrastructure and previously undocumented malware tools used by Nimbus Manticore, an Iranian state-sponsored hacking group linked to the Islamic Revolutionary Guard Corps (IRGC). The threat actor has expanded their arsenal with a TWOSTROKE-like C++ backdoor and an SSH tunneling utility that masquerades as Windows Terminal Server SDK components. Group-IB's analysis revealed extensive infrastructure spanning Europe and the Middle East, indicating an expanded targeting profile beyond their traditional focus on defense, aerospace, and military organizations in the Middle East and United States. This incident highlights the continued evolution of Iranian APT capabilities and their persistent focus on establishing long-term access to critical infrastructure. As nation-state actors increasingly develop sophisticated toolsets and expand their geographic reach, organizations must prioritize comprehensive network visibility and east-west traffic monitoring to detect lateral movement and command-and-control activities.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical Maritime Security Alert: FURUNO FA-50 AIS Transponder Vulnerabilities Expose Global Fleet
Impact· CRITICAL

Critical Maritime Security Alert: FURUNO FA-50 AIS Transponder Vulnerabilities Expose Global Fleet

Critical vulnerabilities CVE-2026-59769 and CVE-2026-67578 were discovered in FURUNO FA-50 Class B AIS Transponder devices used worldwide in maritime transportation systems. The flaws include hardcoded credentials and missing authentication for critical functions, allowing attackers with network access to alter device settings and configurations. With CVSS scores of 9.1 and 7.5 respectively, these vulnerabilities affect all versions of the discontinued product, leaving thousands of vessels potentially exposed to navigation system manipulation. FURUNO ended production in October 2020 and will not provide security updates, recommending only physical security measures and network isolation as mitigations. This incident highlights the growing risks of legacy IoT/OT devices in critical infrastructure, where end-of-life products continue operating without security support, creating persistent attack vectors that threaten maritime safety and operational integrity.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Zimbra's Critical RCE Flaw Highlights the New Reality of Emergency Patching
Impact· CRITICAL

Zimbra's Critical RCE Flaw Highlights the New Reality of Emergency Patching

In August 2026, CISA issued a three-day emergency patching directive for CVE-2026-73570, a critical remote code execution vulnerability in Zimbra Collaboration Suite. The flaw allows unauthenticated attackers to execute arbitrary commands on servers with SNMP notifications enabled through specially crafted SMTP requests. Active exploitation was reported by Poland's CERT Polska, prompting the accelerated response timeline. Successful attacks provide access to email communications, calendars, contacts, and organizational intelligence that can facilitate follow-on attacks. This incident exemplifies the shrinking window between vulnerability disclosure and active exploitation, driven by AI-enabled exploit development that reduces the time from patch analysis to working exploits from weeks to mere days.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports