The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Defense/Space

Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.

418 threat reports
Page 4 of 35

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Defense/Space Threat Reports

Showing 37–48 / 418 reports
U.S. Treasury Launches 'Economic D-Day' Against Iranian Cyber Operations Targeting Critical Infrastructure
Impact· HIGH

U.S. Treasury Launches 'Economic D-Day' Against Iranian Cyber Operations Targeting Critical Infrastructure

In January 2025, the U.S. Treasury Department sanctioned four Iranian hackers as part of an 'economic D-Day' campaign against Iran's cyber operations. The sanctioned individuals - Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda'i, and Mojtaba Ghal'eh-Kuhi - conducted sophisticated attacks against U.S. critical infrastructure since late 2023, successfully compromising and exfiltrating data from energy companies, defense contractors, healthcare institutions, IT companies, and financial institutions. These attacks were directed by Iran's Ministry of Intelligence and Security (MOIS), with hackers motivated by both state objectives and personal financial gain, leading some to also target Iranian domestic companies. This incident highlights the escalating cyber warfare between nation-states and the U.S. government's increasingly aggressive economic response to state-sponsored cyberthreats. The sanctions represent a significant shift toward treating cyber operations as acts of war requiring comprehensive economic retaliation rather than just cybersecurity countermeasures.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Supply-Chain Attack: Hackers Poison Popular Rust Crate arrayref
Impact· HIGH

Critical Supply-Chain Attack: Hackers Poison Popular Rust Crate arrayref

On August 20, 2026, attackers compromised the maintainer account of the widely-used Rust crate arrayref, injecting malware that executed during compilation on developers' systems. Within a 23-minute window, the attackers also poisoned two additional crates (append-only-vec and internment) in this sophisticated supply-chain attack. The malicious code introduced a dependency on proc-macro1, a typosquat of the legitimate proc-macro2 crate, which deployed cross-platform infostealer malware targeting credentials from Chrome, Brave, and Edge browsers. With arrayref having over 245 million lifetime downloads and being used in critical blockchain and cryptography projects, the potential impact was substantial before the malicious packages were removed within 1.5 hours. This incident highlights the growing sophistication of supply-chain attacks targeting developer ecosystems, with security researchers noting infrastructure overlaps with recent North Korean state-sponsored campaigns. As organizations increasingly rely on open-source dependencies and automated build processes, these attacks represent a critical threat vector that can bypass traditional perimeter defenses.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Russian APT29 Clusters Weaponize OAuth and WhatsApp in Sophisticated 2026 Espionage Campaign
Impact· HIGH

Russian APT29 Clusters Weaponize OAuth and WhatsApp in Sophisticated 2026 Espionage Campaign

Between March and August 2026, three suspected Russian cyber espionage clusters (UNC6293, UNC7005, and UNC5976) conducted sophisticated authentication-focused attacks targeting academics, diplomats, defense personnel, and think tank researchers across Europe and the United States. The threat actors, linked to APT29/Ice Relic operations, exploited legitimate OAuth flows, WhatsApp device linking, and captive Wi-Fi portals to compromise personal accounts through highly targeted phishing campaigns. Their operations included the CaptiveCrunch campaign that hijacked hotel and airport Wi-Fi networks, deployed CornFlake RAT and ChocoShell infostealers, and potentially compromised managed service providers in supply chain attacks affecting approximately 70 victim locations globally. These incidents highlight the evolving threat landscape where state-sponsored actors increasingly abuse legitimate authentication mechanisms and trusted infrastructure to bypass traditional security controls, making detection significantly more challenging for organizations.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
How Pakistan's Transparent Tribe Exploited Cybersecurity Gaps in Afghan Infrastructure
Impact· HIGH

How Pakistan's Transparent Tribe Exploited Cybersecurity Gaps in Afghan Infrastructure

Pakistan's Transparent Tribe (APT36) conducted an active cyber espionage campaign against Afghan government and telecommunications organizations from December 2025 through August 2026, deploying new malware variants including Patchcord and Sheetcord backdoors. The threat actor successfully compromised an Afghan Telecom IT officer and an international company's Afghan subsidiary, stealing sensitive data and WhatsApp communications for further social engineering attacks. While attacks against Indian government agencies including the Ministries of Defense and Foreign Affairs were attempted, these were unsuccessful due to India's superior cybersecurity defenses and proactive blocking by CERT-In. This incident highlights the growing sophistication of regional APT groups targeting countries with immature cybersecurity infrastructures, particularly in the context of heightened geopolitical tensions in South Asia and the Taliban's governance challenges in Afghanistan.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
NASA Spacecraft Control Vulnerability Highlights Critical Infrastructure Security Gaps
Impact· CRITICAL

NASA Spacecraft Control Vulnerability Highlights Critical Infrastructure Security Gaps

In August 2026, Cycode security researchers disclosed critical vulnerabilities in NASA's AIT-GUI spacecraft control software that allowed unauthenticated attackers to issue arbitrary commands to spacecraft and instruments. The flaw chain, rated 9.4 CVSS, affected AIT-GUI versions 2.5.1 and earlier, exposing command endpoints without authentication, authorization, or CSRF protection. Attackers could execute server-side scripts, run command sequences, and issue spacecraft commands via simple HTTP POST requests to the web interface that bound to all network interfaces by default. This incident highlights the growing risk of AI-assisted vulnerability research and the critical need for secure-by-default configurations in operational technology environments. As space infrastructure becomes increasingly digitized and interconnected, authentication gaps in command and control systems represent existential risks to mission-critical operations.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
SilkParasite APT's Advanced RATs Target Central Asian Governments
Impact· HIGH

SilkParasite APT's Advanced RATs Target Central Asian Governments

In late 2025, the Chinese-nexus advanced persistent threat (APT) group known as SilkParasite initiated a cyber-espionage campaign targeting government organizations across Central Asia, including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. Utilizing spear-phishing emails with regionally tailored Office documents, often within password-protected RAR archives, the attackers deployed a suite of seven remote access Trojans (RATs), five of which were previously undocumented. These RATs enabled long-term access to sensitive governmental systems, facilitating intelligence gathering and potential disruption of critical operations. This incident underscores the evolving sophistication of state-sponsored cyber threats, particularly the use of modular and AI-assisted malware designed to evade detection. The strategic focus on Central Asian governments highlights a shift in geopolitical cyber-espionage activities, emphasizing the need for enhanced cybersecurity measures and international cooperation to mitigate such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Clop Ransomware's Targeted Attack on PTC Windchill via CVE-2026-12569
Impact· CRITICAL

Clop Ransomware's Targeted Attack on PTC Windchill via CVE-2026-12569

In August 2026, the Clop ransomware group exploited a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM servers, deploying a custom JavaServer Pages (JSP) web shell. This sophisticated implant enabled attackers to decrypt stored credentials, map sensitive engineering data, and execute arbitrary code, facilitating remote access, data exfiltration, and potential ransomware deployment. The attack underscores the evolving tactics of threat actors in targeting enterprise Product Lifecycle Management (PLM) software to access proprietary information and credentials. Organizations utilizing such platforms must prioritize timely patching and robust security measures to mitigate the risk of similar exploits.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Vulnerability in Siemens Simcenter Nastran: CVE-2026-59086
Impact· HIGH

Critical Vulnerability in Siemens Simcenter Nastran: CVE-2026-59086

In August 2026, Siemens disclosed a critical stack overflow vulnerability (CVE-2026-59086) in Simcenter Nastran versions prior to V2606. This flaw allows attackers to execute arbitrary code by exploiting the application's argument parsing mechanism. If a user is tricked into running the affected application with a malicious string, the vulnerability can be leveraged to perform remote code execution within the current process context. Siemens has released updated versions to address this issue and recommends users upgrade to V2606 or later. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-965753.html?utm_source=openai)) This incident underscores the persistent risk of stack overflow vulnerabilities in critical engineering software, highlighting the importance of timely software updates and vigilant security practices to prevent potential exploitation.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Clop Ransomware's Targeted Attack on PTC Windchill: A Wake-Up Call for PLM Security
Impact· CRITICAL

Clop Ransomware's Targeted Attack on PTC Windchill: A Wake-Up Call for PLM Security

In July 2026, the Clop ransomware gang exploited a critical vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM platforms, enabling unauthenticated remote code execution. This allowed attackers to deploy custom JavaServer Pages (JSP) web shells, granting them access to sensitive product lifecycle data. The breach led to significant data exfiltration, impacting numerous organizations reliant on these platforms for product design and management. This incident underscores the evolving tactics of ransomware groups, shifting from traditional encryption-based attacks to data theft and extortion. Organizations must prioritize timely patching of known vulnerabilities and enhance monitoring of enterprise applications to mitigate such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
CopyCop's Disinformation Campaigns Against Armenia's Firebird AI Data Center in 2026
Impact· LOW

CopyCop's Disinformation Campaigns Against Armenia's Firebird AI Data Center in 2026

Between June 24 and July 13, 2026, the Russian influence network known as CopyCop (Storm-1516) orchestrated a series of disinformation campaigns targeting the Firebird AI data center in Hrazdan, Armenia. These campaigns disseminated false narratives, including fabricated earthquake threats, doubts about the facility's economic viability, and claims that the data center was a legitimate military target. The reach of these narratives expanded significantly, culminating in over 1.6 million combined views by the third instance, indicating a growing audience engagement as the campaign progressed. This incident underscores the increasing use of coordinated disinformation campaigns by state-affiliated actors to undermine strategic infrastructure projects. The targeting of a major AI initiative highlights the vulnerability of emerging technologies to such operations, emphasizing the need for robust information security measures and public awareness to counteract misinformation.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Cavern C2 Framework's Evolution: Leveraging DNS and Google Apps Script for Stealth
Impact· HIGH

Cavern C2 Framework's Evolution: Leveraging DNS and Google Apps Script for Stealth

In August 2026, cybersecurity researchers identified advancements in the Cavern (aka Cav3rn) command-and-control (C2) framework, utilized by Iranian nation-state hackers targeting Israeli entities. The updated framework incorporates a complex C2 module that leverages DNS A-record responses to dynamically select between direct HTTPS communication and a Google Apps Script relay for each transaction. This evolution enhances the framework's ability to blend malicious traffic with legitimate network activity, complicating detection efforts. The Cavern framework, first documented in July 2026, is associated with the Cavern Manticore group, linked to Iran's Ministry of Intelligence and Security (MOIS), and shares overlaps with other Iranian threat actors such as MuddyWater and Lyceum. The modular architecture of Cavern facilitates various post-exploitation activities, including file operations, database enumeration, Active Directory reconnaissance, and network tunneling. The integration of legitimate services like Google Apps Script and Microsoft 365 calendars into its C2 channels underscores a strategic shift towards more covert and resilient communication methods. This development highlights the increasing sophistication of nation-state cyber operations and the challenges in detecting and mitigating such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in AVEVA Enterprise SCADA: CVE-2025-7639
Impact· HIGH

Critical Vulnerability in AVEVA Enterprise SCADA: CVE-2025-7639

In August 2026, AVEVA disclosed a critical vulnerability (CVE-2025-7639) in its Enterprise SCADA software, affecting versions up to 2025. This flaw allows authenticated users with 'DNA Authority - Operator' privileges to tamper with serialized data, potentially leading to code execution during deserialization under the 'DNA Apps' security group. Exploitation could result in unauthorized control over SCADA systems, posing significant risks to industrial operations. The vulnerability underscores the persistent threat of deserialization flaws in industrial control systems. Organizations are urged to assess their SCADA deployments, apply the recommended patches, and implement robust access controls to mitigate potential exploitation.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports