The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Defense/Space

Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.

418 threat reports
Page 30 of 35

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Defense/Space Threat Reports

Showing 349–360 / 418 reports
North Korean Operatives Pose as IT Job Seekers to Infiltrate Western Companies
Impact· medium

North Korean Operatives Pose as IT Job Seekers to Infiltrate Western Companies

In 2023, multiple Western technology firms fell victim to a sophisticated insider threat campaign involving North Korean operatives posing as freelance IT job seekers. These actors used false identities and forged CVs to secure remote employment and gain access to sensitive corporate environments. Once inside, they leveraged their positions to siphon proprietary information, commit financial fraud, and, in some cases, facilitate broader cyber-espionage activities by collecting credentials and mapping internal systems. The impact spanned financial loss, reputation damage, and increased exposure to supply chain attacks. This incident highlights the growing trend of well-resourced nation-state actors exploiting remote work arrangements and third-party talent networks. As companies aggressively scale digital transformation and outsourcing, vigilance against social engineering and identity fraud is critical to mitigate the risk of covert infiltration and regulatory non-compliance.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Pixel KASLR Bypass: Linear Map Non-Randomization Threatens Android Kernel Security
Impact· low

Pixel KASLR Bypass: Linear Map Non-Randomization Threatens Android Kernel Security

In November 2025, security researchers from Google Project Zero disclosed a significant design flaw in the Linux kernel’s implementation of Kernel Address Space Layout Randomization (KASLR) on modern Android devices, specifically Google Pixel phones. The weakness stems from the lack of randomization in both the linear kernel mapping and the physical memory loading address of the kernel itself. As a result, attackers with an arbitrary read/write primitive could derive static kernel virtual addresses, bypassing KASLR protections without leaks—thereby making exploitation significantly easier and increasing the risk of privilege escalation and persistence. This incident underscores a broader industry challenge where operating system mitigations lag behind evolving attacker techniques. The exposure of predictable kernel virtual addresses on widely deployed Android devices highlights the urgency for stronger kernel randomization and renewed attention to memory safety for mobile platforms.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
UNC6384 Strikes: Diplomatic Espionage Campaign Hits Europe via Windows Exploits
Impact· low

UNC6384 Strikes: Diplomatic Espionage Campaign Hits Europe via Windows Exploits

In early 2024, advanced persistent threat group UNC6384 targeted multiple European diplomatic entities in a sophisticated cyber-espionage campaign. By leveraging highly convincing spear-phishing emails themed around the European Commission and NATO, attackers tricked foreign affairs officials into clicking malicious links crafted to exploit Windows vulnerabilities. Once compromised, victims' systems allowed for persistent access, resulting in unauthorized data exfiltration and significant risks to sensitive diplomatic communications. The attack underscores the vulnerability of trusted organizations to nation-state tactics and the dangers posed by zero-day Windows exploits in high-value targets. The incident highlights a growing trend of targeted attacks against governmental organizations, coinciding with increased geopolitical tension in Europe. As cyber threat actors continue to exploit social engineering and sophisticated malware, organizations must prioritize endpoint security, staff awareness, and aggressive detection measures to thwart emerging espionage campaigns.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(low)
Read Report
Insider at L3Harris Sells Cyber Exploits to Russian Broker in 2024 Breach
Impact· high

Insider at L3Harris Sells Cyber Exploits to Russian Broker in 2024 Breach

In early 2024, Peter Williams, a former executive at L3Harris Trenchant, a U.S. defense contractor, pleaded guilty to stealing and illicitly selling confidential cyber exploit information to a Russian broker. The insider utilized privileged access to exfiltrate sensitive data on cybersecurity vulnerabilities and offensive research, subsequently marketing this intelligence to foreign entities, including actors associated with the Russian cyber underground. The breach exposed L3Harris Trenchant's internal detection gaps, ultimately triggering a federal investigation and leading to Williams' prosecution in U.S. District Court. This incident underscores the growing threat posed by insider actors within critical infrastructure and defense sectors. It highlights the need for advanced detection, segmentation, and strict policy enforcement to counter the insider risk—especially as nation-state and organized crime demand for zero-day vulnerabilities and advanced cyber tools continues to escalate.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Siemens 2025: Type Confusion RCE Threatens HyperLynx & Industrial Edge Security
Impact· medium

Siemens 2025: Type Confusion RCE Threatens HyperLynx & Industrial Edge Security

In October 2025, Siemens disclosed a critical vulnerability (CVE-2025-6554) affecting HyperLynx and Industrial Edge App Publisher products. The flaw, rooted in type confusion within the V8 JavaScript engine (Google Chrome), enables remote attackers to execute arbitrary code via malicious HTML, particularly impacting vulnerable product versions used in worldwide critical manufacturing environments. For HyperLynx, exploitation requires local access, while Industrial Edge App Publisher is exploitable remotely with low complexity, posing a substantial risk to integrity and confidentiality. Siemens and CISA jointly advised immediate updates and best-practice mitigations. This incident highlights a growing trend of supply chain and third-party component vulnerabilities impacting industrial control systems, particularly as attackers increasingly target embedded web technologies. The Siemens disclosure underlines ongoing regulatory and operational pressure to address software dependencies and enforce proactive patch management in critical infrastructure.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Flags DELMIA Apriso Vulnerabilities: Urgent Action for Manufacturers
Impact· low

CISA Flags DELMIA Apriso Vulnerabilities: Urgent Action for Manufacturers

In October 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities affecting Dassault Systèmes DELMIA Apriso (CVE-2025-6204 and CVE-2025-6205) to its Known Exploited Vulnerabilities (KEV) Catalog following confirmed evidence of active exploitation in the wild. The code injection and missing authorization flaws present serious security bypass opportunities, allowing malicious actors to achieve unauthorized access and potentially execute arbitrary code. These weaknesses have become high-value targets for cyber attackers, potentially threatening sensitive enterprise manufacturing and operational data integrity across organizations that have yet to apply available patches. This incident underscores the growing trend of rapid exploitation of industrial software vulnerabilities by sophisticated threat actors. With regulatory frameworks such as BOD 22-01 placing increasing responsibility on federal agencies to remediate such vulnerabilities quickly, all organizations must adapt their patch management and risk processes to respond to elevated attacker velocity.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Iranian Hacker Training School Hit by Major Data Leak in 2024
Impact· high

Iranian Hacker Training School Hit by Major Data Leak in 2024

In June 2024, a significant data breach struck Ravin Academy, an institution linked to training operatives for Iran’s Ministry of Intelligence and Security (MOIS). Unknown attackers infiltrated Ravin Academy’s infrastructure and exfiltrated sensitive personal information on students, instructors, and internal operations. The breach exposed emails, full names, contact info, assignment details, and evidence of the academy’s ties to cyberespionage. Responsibility was claimed by hacktivists aiming to publicly reveal Iranian cyber capabilities. The school is believed to have failed in securing internal East-West traffic, and evidence suggests lack of robust threat detection or network segmentation allowed attackers to maintain persistence long enough to extract substantial records. The breach is under investigation, but sensitive intelligence operations may have been compromised. This incident draws renewed focus on “learning supply chain” vulnerabilities: attacker interest in targeting not just state actors, but their feeder institutions and ecosystems. Such breaches underscore mounting regulatory concern over insider risk, inadequate segmentation, and the risks of unencrypted internal communications in institutions developing offensive cyber capabilities.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
L3Harris Insider Breach: Zero-Day Exploits Sold to Russian Broker in 2024
Impact· high

L3Harris Insider Breach: Zero-Day Exploits Sold to Russian Broker in 2024

In 2024, a former executive at defense contractor L3Harris, Peter Williams, pleaded guilty to stealing and selling eight zero-day cyber exploits to a Russian broker linked to Operation Zero. Williams exploited privileged access at Trenchant, an L3Harris subsidiary, to covertly extract software developed for the U.S. government. He sold these sensitive trade secrets between 2022 and 2024 for several million dollars in cryptocurrency, hiding the transactions through encrypted communications. The sale of these advanced cyber capabilities to an entity catering to Russian state clients exposed L3Harris to estimated damages of $35 million and raised concerns about offensive tools in adversarial hands. This case highlights the increasing risks posed by insider threats exploiting specialized knowledge in the cyber-arms marketplace. Recent trends show threat actors—often with national ties—actively pursuing zero-day exploits via brokers, making supply chain trust and internal controls critical concerns for organizations managing sensitive cyber assets.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Alert: Active Exploits Target Dassault DELMIA Apriso and XWiki in 2025
Impact· low

CISA Alert: Active Exploits Target Dassault DELMIA Apriso and XWiki in 2025

In October 2025, cybersecurity authorities including CISA confirmed active exploitation of critical vulnerabilities in Dassault Systèmes DELMIA Apriso and XWiki platforms. Threat actors leveraged flaws such as CVE-2025-6204—an 8.0 CVSS code injection bug—to gain unauthorized access and potential code execution on affected systems. The attackers exploited unpatched systems to facilitate lateral movement, data exfiltration, and possible disruption of manufacturing and enterprise workflows. Affected organizations faced immediate operational risk and the prospect of sensitive information compromise. This incident highlights a growing trend in rapid exploitation of recently disclosed enterprise software vulnerabilities. With increased attacker focus on supply chain and collaborative platforms, organizations must respond swiftly to new advisories and prioritize vulnerability management programs to reduce exposure to high-severity threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
TEE.Fail: New Side-Channel Flaw Exposes Intel and AMD DDR5 Secure Enclaves
Impact· low

TEE.Fail: New Side-Channel Flaw Exposes Intel and AMD DDR5 Secure Enclaves

In October 2025, a collaborative group of researchers from Georgia Tech, Purdue University, and Synkhronix unveiled a significant hardware vulnerability named TEE.Fail, targeting processor trusted execution environments (TEEs) such as Intel SGX and TDX and AMD SEV-SNP on DDR5 systems. By using a novel side-channel attack, the team demonstrated the ability to extract cryptographic secrets and sensitive data from isolated enclaves, undermining critical security guarantees of TEEs. The vulnerability leverages intermediate memory leakage patterns not previously considered exploitable, impacting cloud, enterprise, and virtualization environments relying on hardware-backed isolation for confidentiality. This disclosure underscores escalating risks posed by advanced hardware attacks. With the ongoing shift toward enclave-based computing and the rapid adoption of DDR5, the emergence of such sophisticated exploits highlights urgent needs for architectural mitigations, renewed auditing, and cloud provider vigilance.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
APT36 Exploits Golang-Based Malware to Compromise Indian Government in 2025
Impact· low

APT36 Exploits Golang-Based Malware to Compromise Indian Government in 2025

In August and September 2025, the state-sponsored hacking group APT36 (also known as Transparent Tribe) launched a spear-phishing campaign targeting Indian government entities. The campaign delivered a new variant of a Golang-based remote access trojan, DeskRAT, which allowed attackers to gain persistent access, conduct reconnaissance, and exfiltrate sensitive information. The phishing emails, likely crafted to impersonate trusted sources, succeeded in infecting victim networks, enabling APT36 to conduct espionage activities against high-profile targets, further compromising Indian national security interests. This incident underscores the persistent risk posed by well-resourced, nation-state threat actors using continuously evolving malware families and novel programming languages like Golang. The rise of such campaigns highlights an urgent need for improved east-west traffic monitoring, zero trust network segmentation, and advanced user awareness against targeted phishing techniques.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Former L3Harris Executive Charged with Selling Cyber Trade Secrets to Russia
Impact· medium

Former L3Harris Executive Charged with Selling Cyber Trade Secrets to Russia

In August 2025, U.S. federal prosecutors charged Peter Williams, a former executive at L3Harris Technologies’ cyber division, with stealing and selling sensitive trade secrets to an undisclosed Russian buyer. Williams, the former general manager of specialized hacking group Trenchant, allegedly misappropriated eight proprietary technologies from two companies between April 2022 and August 2025, totaling $1.3 million in illicit gains. The Department of Justice seeks forfeiture of assets derived from the scheme. Neither L3Harris nor Trenchant is accused of direct wrongdoing. This incident underscores the growing threat posed by insiders with privileged access to highly sensitive cyber capabilities. As governments and critical industries bolster defenses, advanced techniques to detect, monitor, and mitigate insider risk are essential to prevent breaches that could have national security consequences.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports