The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Defense/Space

Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.

418 threat reports
Page 32 of 35

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Defense/Space Threat Reports

Showing 373–384 / 418 reports
Russian Hackers Evolve Malware via 'I am not a robot' Captchas in 2024
Impact· low

Russian Hackers Evolve Malware via 'I am not a robot' Captchas in 2024

In early 2024, the Russian state-sponsored group Star Blizzard intensified its cyber-espionage operations, leveraging advanced malware strains (NoRobot, MaybeRobot) delivered via deceptive "I am not a robot" CAPTCHA prompts in targeted ClickFix phishing campaigns. Attackers executed multi-stage infection chains, enticing victims to enable malicious browser extensions or download trojanized payloads under the guise of legitimate productivity fixes. These campaigns enabled persistent access to sensitive organizational data, posed risks of lateral movement within networks, and facilitated exfiltration of proprietary intelligence. This incident underscores a concerning trend: the use of dynamic, highly-adaptive social engineering and malware delivery methods by state-backed actors. As similar tactics are increasingly observed across sectors, organizations must harden entry-point protections and improve internal visibility to counter evolving nation-state threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
North Korean APT Combines BeaverTail and OtterCookie in Major 2025 JS Malware Campaign
Impact· low

North Korean APT Combines BeaverTail and OtterCookie in Major 2025 JS Malware Campaign

In October 2025, a North Korean state-sponsored hacking group with ties to the Contagious Interview campaign was observed integrating features from its BeaverTail and OtterCookie malware into a sophisticated new JavaScript-based attack. Security research from Cisco Talos revealed the group’s evolving approach: combining credential theft, evasion, and persistent access in targeted spear-phishing campaigns directed at global enterprises, which enabled stealthy lateral movement and prolonged network compromise. Analysis showed that this fusion malware increased the attackers’ efficiency and resilience, leading to significant data exposure risks and operational disruptions for affected organizations. This incident highlights a broader trend—North Korean APTs are rapidly developing multipurpose malware platforms capable of bypassing traditional defenses. The blending of well-established tools signals a new level of technical maturity, raising the urgency for organizations to shore up east-west traffic security, zero trust segmentation, and advanced threat detection controls.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
NSA’s Multi-Tool Cyber Assault on Beijing’s National Time Service Center: Lessons for Critical Infrastructure
Impact· low

NSA’s Multi-Tool Cyber Assault on Beijing’s National Time Service Center: Lessons for Critical Infrastructure

In October 2025, China's Ministry of State Security (MSS) accused the U.S. National Security Agency (NSA) of orchestrating a sophisticated, multi-stage cyberattack against the National Time Service Center (NTSC) in Beijing. The MSS claims that the NSA deployed at least 42 distinct cyber tools to penetrate critical national infrastructure, leveraging advanced techniques such as encrypted and east-west traffic manipulation, zero trust segmentation circumvention, and covert remote access. The compromise included strategic lateral movement and evasion of detection, reportedly leaving a significant impact on the operational integrity of NTSC, which serves as a reference point for the nation’s official timekeeping and scientific endeavors. This incident marks an escalation in cyber power projection between nation-states and spotlights the increasing use of multi-tool modular attack frameworks by advanced persistent threats (APTs). The breach underscores the urgency for critical infrastructure operators worldwide to reevaluate network segmentation, encrypted communications, and visibility gaps in light of evolving nation-state tactics.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Google Uncovers Rapidly Evolving COLDRIVER Malware Campaigns in 2025
Impact· medium

Google Uncovers Rapidly Evolving COLDRIVER Malware Campaigns in 2025

In May 2025, Google’s Threat Intelligence Group (GTIG) identified a surge in new malware developed by the Russian state-sponsored hacking group COLDRIVER (also known as Callisto or SEABORGIUM). In rapid succession, three new malware families were discovered, each demonstrating increased sophistication and frequent code variations. The attackers leveraged targeted spear-phishing campaigns to compromise government, defense, and policy sector targets across Europe and North America. The swift adaptation and deployment of these malware strains highlight COLDRIVER’s evolving tradecraft and acceleration of offensive cyber operations, posing heightened risks to sensitive data and infrastructure. This campaign signals a broader trend of rapidly evolving Russian cyber-espionage efforts against Western entities. The increased pace, tooling variation, and focus on intelligence collection underline the critical need for organizations to upgrade monitoring, segmentation, and encryption controls across hybrid cloud and on-prem networks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft Windows Smart Card Authentication Breakdowns After 2025 Security Update
Impact· low

Microsoft Windows Smart Card Authentication Breakdowns After 2025 Security Update

In October 2025, Microsoft released security updates to address a cryptographic vulnerability (CVE-2024-30098) in Windows platforms, triggering widespread smart card authentication failures. The update, which altered default behavior from using CSP to KSP for RSA-based smart card certificates, disrupted authentication services across Windows 10, Windows 11, and Windows Server systems. Affected organizations reported issues such as failed logins, inability to sign documents, and critical service interruptions in workflows dependent on certificate-based authentication. The root cause was traced to a registry change designed to mitigate a feature bypass risk, inadvertently impacting legacy compatibility and 32-bit applications. This incident highlights how routine security hardening can introduce substantial operational risk, particularly for enterprises relying on legacy authentication methods. As businesses continue their path to zero trust and increase dependency on certificate-based systems, compatibility breakdowns following security improvements are becoming more prominent, amplifying pressures for comprehensive testing and rapid response strategies.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Startling Satellite Breach: How $600 Unlocked a Global Data Leak in 2025
Impact· high

Startling Satellite Breach: How $600 Unlocked a Global Data Leak in 2025

In early 2025, researchers from the University of Maryland and UC San Diego revealed widespread leakage of sensitive and private data—including military and telecom communications—through unencrypted transmissions sent over geostationary (GEO) satellites. By using only $600 in commercially available equipment, the team passively intercepted vast amounts of plaintext data from major organizations, government entities, and telecom users around the globe. The incident highlighted fundamental lapses in network-layer encryption practices, allowing phone calls, SMS messages, internal application data, and even military vessel information to leak with no authentication or protection. The research further demonstrated that even technically unsophisticated actors could compromise critical satellite backhaul links using minimal resources. This event underscores the urgent need for end-to-end encryption and robust monitoring of satellite communications as reliance on these channels increases and barriers to interception continue to fall. Government and industry must now address the rapidly evolving risk landscape, especially as critical infrastructure becomes more dependent on satellite connectivity.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Flax Typhoon Turns ArcGIS Features Into Espionage Backdoor: 2024 Breach Analysis
Impact· medium

Flax Typhoon Turns ArcGIS Features Into Espionage Backdoor: 2024 Breach Analysis

In early 2024, security researchers revealed that Chinese state-backed group Flax Typhoon covertly infiltrated ArcGIS server environments, maintaining backdoor access for over a year by exploiting legitimate software features. By compromising a backend administrator account, attackers deployed a malicious Server Object Extension (SOE) that blended with normal operations, enabling a persistent webshell and establishing a hidden workspace inaccessible to others. Critically, the attackers embedded their access into system backups, ensuring reinfection even after potential forensics or restoration activities. This sophisticated campaign allowed Flax Typhoon to spy on entities across the U.S., Europe, and Taiwan with minimal use of detectable malware. The incident demonstrates a significant shift towards using trusted enterprise software as an attack vector and reveals how recovery mechanisms like backups become liabilities if not properly verified. Similar living-off-the-land techniques are rising in frequency, challenging traditional security monitoring and incident response strategies.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(medium)
Read Report
AI-Powered PRISONBREAK Influence Operation Targets Iran Amid Heightened Tensions
Impact· high

AI-Powered PRISONBREAK Influence Operation Targets Iran Amid Heightened Tensions

In early 2025, a coordinated AI-enabled information operation named 'PRISONBREAK' targeted Iranian audiences via over 50 inauthentic X (formerly Twitter) profiles. Likely conducted by an Israeli government agency or contracted group, the operation deliberately synchronized its messaging with Israeli military action against Iran in June 2025. These automated profiles aimed to incite unrest and dissent within Iran, leveraging artificial intelligence to amplify and seed anti-government narratives to large public communities, at times with paid promotion. While organic engagement was limited, several posts garnered tens of thousands of views, representing a sophisticated example of nation-state influence using AI and social media. The operation highlights the new scale and efficiency with which AI can power information warfare, especially when paired with state-level coordination. As similar AI-driven campaigns grow globally, organizations and governments must re-examine detection strategies, policy enforcement, and regulatory frameworks for safeguarding against synthetic and manipulative online content.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
RedNovember: Chinese State-Sponsored Espionage Campaign Hits Global Defense and Tech Sectors
Impact· medium

RedNovember: Chinese State-Sponsored Espionage Campaign Hits Global Defense and Tech Sectors

Between June 2024 and July 2025, the Chinese state-sponsored threat group RedNovember (overlapping with Storm-2077 and formerly tagged as TAG-100) orchestrated a far-reaching cyber-espionage campaign targeting government, defense, and technology organizations globally. Leveraging weaponized perimeter device exploits and open-source tools like Pantegana and Cobalt Strike, the group gained initial access via widely used firewalls and VPNs, including SonicWall, Fortinet, Palo Alto, and Ivanti Connect Secure. Victims included ministries, intergovernmental bodies, US defense contractors, European manufacturers, and space organizations. The campaign’s impact highlights persistent perimeter vulnerabilities and demonstrated operational scale and stealth through commodity tooling and strategic timing near geopolitical events. This incident underscores the shift toward exploiting edge devices and open-source frameworks for stealth, scalable compromise by advanced actors. The trend signals urgent challenges for organizations relying on perimeter appliances and highlights the need to strengthen monitoring, zero trust segmentation, and compliance-driven security controls across hybrid and multicloud environments.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Brazilian Military Breach: Zimbra Zero-Day Exploited via Libyan Navy Impersonation
Impact· medium

Brazilian Military Breach: Zimbra Zero-Day Exploited via Libyan Navy Impersonation

In early 2024, cyber attackers posing as representatives of the Libyan Navy’s Office of Protocol targeted the Brazilian military using a sophisticated spear-phishing campaign. By leveraging a previously unknown zero-day vulnerability in Zimbra Collaboration Suite and delivering malicious emails through compromised inter-country secure communications channels (ICS), the threat actors successfully bypassed traditional perimeter defenses. The attackers' advanced persistent techniques enabled them to gain unauthorized access, exploit sensitive data, and risk critical communications infrastructure for the Brazilian defense sector, with potential exposure of mission-critical information. This incident highlights the escalating risks posed by zero-day vulnerabilities and state-linked or impersonation-driven threat actors, particularly against government and defense organizations. The unusual attack vector via ICS demonstrates evolving tactics beyond routine phishing, reinforcing the necessity for layered security, real-time threat detection, and robust segmentation controls.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Red Hat Breach 2025: ShinyHunters Escalate GitLab Data Extortion
Impact· high

Red Hat Breach 2025: ShinyHunters Escalate GitLab Data Extortion

In October 2025, Red Hat suffered a significant data breach after threat actor group Crimson Collective compromised its internal GitLab repositories, exfiltrating nearly 570GB of data including around 800 Customer Engagement Reports (CERs). These reports contained sensitive details about customers’ networks and infrastructure. Following unsuccessful ransom negotiations, Crimson Collective partnered with Scattered Lapsus$ Hunters and ShinyHunters to escalate extortion attempts, publicly posting data samples and demanding payment before a hard deadline. High-profile organizations such as Walmart, HSBC, Bank of Canada, and the US Department of Defense were among affected clients named in the leak. The collaboration between multiple threat actors and the rise of Extortion-as-a-Service operations like ShinyHunters highlight a new era of corporate extortion risk, with increasing pressure on organizations to proactively secure code repositories and sensitive customer communications against rapidly-evolving, multi-actor cyber threats.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
How a Zimbra Zero-Day Breach Exposed the Brazilian Military: Lessons for Secure Collaboration
Impact· low

How a Zimbra Zero-Day Breach Exposed the Brazilian Military: Lessons for Secure Collaboration

In early 2025, a zero-day vulnerability in Zimbra Collaboration (CVE-2025-27915), a widely used email and collaboration platform, was exploited to target the Brazilian military. Attackers used malicious ICS calendar files containing unsanitized HTML and JavaScript to trigger stored cross-site scripting (XSS) within Zimbra's Classic Web Client. This entry vector effectively bypassed standard security controls and provided attackers the ability to execute malicious code in users' browsers, potentially enabling credential theft, session hijacking, and further movement inside the organization before the vulnerability was patched. The campaign underscores how attackers are increasingly leveraging vulnerabilities in collaborative and communication tools to gain a foothold in targeted organizations and critical infrastructure. This breach is particularly relevant today given the ongoing surge in zero-day exploits against widely deployed business applications, especially in sectors such as government and defense. The rapid weaponization of collaboration-tool vulnerabilities highlights the need for timely patch management, robust segmentation, and vigilant threat detection to combat sophisticated phishing and XSS-based initial access.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports