The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Defense/Space
Breach intelligence, attack campaigns, and threat reports targeting the Defense/Space sector.
Explore Other Sectors
Defense/Space Threat Reports
Critical Vulnerabilities in Cursor AI IDE Expose Developers to Remote Code Execution
In early 2026, multiple critical vulnerabilities were discovered in the Cursor AI-integrated development environment (IDE), notably CVE-2026-50548 and CVE-2026-50549. These flaws allowed attackers to escape the IDE's sandbox environment, enabling remote code execution (RCE) on developers' machines. Exploits involved manipulating the working directory parameter and leveraging symbolic link (symlink) manipulation to bypass security controls. The vulnerabilities posed significant risks, including unauthorized access to source code, sensitive data exposure, and potential compromise of development environments. ([csoonline.com](https://www.csoonline.com/article/4191923/sandbox-bypass-flaws-in-cursor-ide-highlight-prompt-injection-as-an-rce-vector.html?utm_source=openai)) The discovery of these vulnerabilities underscores the growing security challenges associated with AI-assisted development tools. As organizations increasingly adopt such tools to enhance productivity, it is imperative to implement robust security measures to mitigate risks associated with prompt injection attacks and sandbox escapes. This incident highlights the need for continuous monitoring and updating of AI development environments to safeguard against emerging threats.
2 months ago
Kill Chain
Critical Cursor Vulnerability Exposes Windows Systems to Malicious Code Execution
In July 2026, a critical vulnerability was discovered in the Cursor development environment, allowing malicious actors to execute arbitrary code on Windows systems. By placing a malicious file named 'git.exe' in the root of a Git repository, attackers could achieve code execution when the repository was opened in Cursor, without any user prompt or warning. This flaw granted attackers access to developers' credentials, including SSH keys and cloud tokens, posing significant security risks. Despite being reported in December 2025, the vulnerability remained unpatched as of July 2026, leaving many systems exposed. This incident underscores the growing threat of supply chain attacks targeting development tools and environments. As developers increasingly rely on third-party repositories and AI-assisted coding tools, the potential for such vulnerabilities to be exploited has risen, emphasizing the need for vigilant security practices and prompt patching of identified flaws.
2 months ago
Kill Chain
EU and UK Sanction Russian GRU Hackers Over Cyberattacks
In July 2026, the European Union and the United Kingdom jointly imposed sanctions on Russian military intelligence officers and associated entities for orchestrating extensive cyberattacks across Europe. These operations, attributed to the GRU and FSB's 16th Centre, targeted government networks and critical infrastructure in countries including France, Germany, Poland, and Finland. Notably, the Turla hacking group, linked to the FSB, attempted to disrupt Poland's energy grid, potentially affecting 500,000 residents during winter. The sanctions encompass asset freezes and travel bans on individuals and entities involved in these cyberespionage activities. This incident underscores the escalating threat of state-sponsored cyberattacks on critical infrastructure, highlighting the need for enhanced cybersecurity measures and international cooperation to deter such activities. The coordinated response by the EU and UK reflects a growing consensus on the importance of addressing cyber threats through unified diplomatic and legal actions.
2 months ago
Kill Chain
CISA Credential Leak May 2026: A Comprehensive Analysis
In May 2026, the Cybersecurity and Infrastructure Security Agency (CISA) discovered that a contractor had inadvertently exposed privileged Amazon AWS GovCloud keys by uploading them to a public GitHub repository. Upon detection, CISA promptly took the repository and its associated development environment offline, revoked the contractor's access, and conducted a thorough analysis. The investigation confirmed that the leaked credentials had not been misused outside of CISA, and no customer or mission-critical data was compromised. This incident underscores the critical importance of stringent access controls and vigilant monitoring of code repositories to prevent unauthorized exposure of sensitive information. The CISA credential leak highlights the growing risks associated with cloud misconfigurations and the inadvertent exposure of sensitive credentials in public repositories. As organizations increasingly rely on cloud services and collaborative development platforms, it is imperative to implement robust security measures, including regular audits, comprehensive logging, and adherence to zero-trust principles, to mitigate potential threats and safeguard critical assets.
2 months ago
Kill Chain
Critical Authentication Bypass in Gitea Docker Image (CVE-2026-20896)
In July 2026, a critical authentication bypass vulnerability, CVE-2026-20896, was discovered in Gitea's official Docker image versions up to and including 1.26.2. This flaw allowed unauthenticated attackers to impersonate any user, including administrators, by exploiting a default configuration that trusted reverse-proxy authentication headers from any source IP address. Exploitation began less than two weeks before public disclosure, with approximately 6,200 Gitea instances exposed on the public web. Successful exploitation granted attackers full access to repositories, CI/CD secrets, and administrative functions, posing significant risks to organizations relying on Gitea for source code management. The rapid exploitation of CVE-2026-20896 underscores the critical importance of promptly addressing default configuration vulnerabilities in widely used open-source tools. Organizations must remain vigilant, ensuring that default settings are reviewed and adjusted to align with security best practices to prevent unauthorized access and potential data breaches.
2 months ago
Kill Chain
Hackers Exploit Roundcube Flaw to Spy on Academic Researchers
In May 2026, a China-linked threat cluster, identified as UNK_MassTraction, exploited vulnerabilities in Roundcube webmail servers at U.S. and Canadian universities. Targeting physics and engineering departments, the attackers sent malicious emails that, when opened in vulnerable Roundcube clients, triggered the execution of JavaScript code exploiting CVE-2024-42009. This led to the deployment of IceCube malware, harvesting credentials and two-factor authentication data. Further exploitation of CVE-2025-49113 allowed the installation of SquareShell, a PHP webshell, granting remote code execution capabilities. In cases where this failed, the attackers deployed VShell, a Go-based backdoor facilitating interactive shell access and port forwarding. This incident underscores the persistent threat posed by state-sponsored cyber espionage, particularly targeting academic institutions involved in sensitive research areas. The exploitation of known vulnerabilities in widely used software like Roundcube highlights the critical need for timely patching and robust security measures to protect against sophisticated attacks.
2 months ago
Kill Chain
Critical Vulnerabilities in Labcenter Proteus 9 Threaten Infrastructure Security
In July 2026, multiple high-severity vulnerabilities were identified in Labcenter Proteus 9.1 SP4 Build 42914, including CVE-2026-42953 (out-of-bounds write), CVE-2026-49033 (stack-based buffer overflow), and CVE-2026-42958 (use-after-free). Exploitation of these vulnerabilities could allow attackers to execute arbitrary code, potentially compromising critical infrastructure sectors such as communications, healthcare, and energy. ([socdefenders.ai](https://www.socdefenders.ai/item/4909df73-d6e4-4d7f-ad22-28b3fb4d7bdc?utm_source=openai)) This incident underscores the persistent risks associated with software vulnerabilities in critical systems. Organizations must prioritize timely patching and robust security measures to mitigate potential threats. ([socdefenders.ai](https://www.socdefenders.ai/item/4909df73-d6e4-4d7f-ad22-28b3fb4d7bdc?utm_source=openai))
2 months ago
Kill Chain
China-Aligned Hackers Exploit Roundcube Flaws in University Attacks
In May 2026, a China-aligned threat group, identified as UNK_MassTraction, exploited critical vulnerabilities in Roundcube webmail software to infiltrate physics and engineering departments at U.S. and Canadian universities. By leveraging CVE-2024-42009, the attackers executed arbitrary JavaScript in victims' browsers, leading to credential theft. Subsequently, they exploited CVE-2025-49113 to gain persistent access via web shells or the VShell backdoor, enabling further network penetration. The campaign specifically targeted administrators and professors involved in sensitive research areas, including astrophysics and particle physics. This incident underscores the persistent threat posed by state-sponsored actors targeting academic institutions to access sensitive research data. The exploitation of known vulnerabilities in widely used software like Roundcube highlights the critical need for timely patching and robust cybersecurity measures within the education sector.
2 months ago
Kill Chain
Understanding the 'GitLost' Vulnerability in GitHub's Agentic Workflows
In July 2026, researchers at Noma Security identified a critical vulnerability, dubbed 'GitLost,' in GitHub's Agentic Workflows. This flaw allows unauthenticated attackers to craft issues in public repositories that, when processed by AI-powered automation, can access and leak data from an organization's private repositories. The attack exploits prompt injection techniques, manipulating the AI agent into executing unintended actions, thereby exposing sensitive information without requiring stolen credentials or direct access to the organization. This incident underscores the growing risks associated with integrating AI agents into development workflows. As organizations increasingly adopt AI-driven automation, the potential for such vulnerabilities rises, emphasizing the need for robust security measures and continuous monitoring to prevent unauthorized data access and leakage.
2 months ago
Kill Chain
Chinese Espionage Group Exploits Roundcube Vulnerabilities to Infiltrate Universities
In May 2026, Proofpoint researchers identified a cyber-espionage campaign targeting physics and engineering departments at U.S. and Canadian universities. The attackers, attributed to a China-aligned group known as UNK_MassTraction, exploited two critical vulnerabilities in the Roundcube email client—CVE-2024-42009 and CVE-2025-49113—to gain unauthorized access. By sending crafted emails, they executed malicious JavaScript and achieved remote code execution, leading to the installation of webshells and backdoors for persistent access. The campaign is ongoing, with several universities potentially affected. This incident underscores the evolving tactics of state-sponsored threat actors, who are increasingly targeting academic institutions to access sensitive research data. The use of email-based exploit chains to compromise mail servers highlights the need for robust email security measures and prompt patching of known vulnerabilities to mitigate such threats.
2 months ago
Kill Chain
US Army Websites Defaced via 404 Hijacking with Pro-Kurdish Messages
In July 2026, multiple U.S. Army subdomains, including oil.army.mil and ai2c.army.mil, were defaced through a 404 hijacking attack. The attackers exploited vulnerabilities in the websites' error-handling systems to display messages denigrating President Donald Trump and U.S. Ambassador to Türkiye Tom Barrack, alongside pro-Kurdish sentiments. The affected sites, running on WordPress and Microsoft cloud infrastructure, were promptly taken offline for investigation. ([cyberscoop.com](https://cyberscoop.com/us-army-websites-defaced-404-hijacking-kurdistan/?utm_source=openai)) This incident underscores the persistent threat of website defacements targeting government entities, highlighting the need for robust security measures and vigilant monitoring to prevent unauthorized access and content manipulation.
2 months ago
Kill Chain
TrojPix Attack: A New Frontier in Data Exfiltration from Air-Gapped Systems
In July 2026, researchers at Shandong University unveiled 'TrojPix,' a novel technique enabling data exfiltration from air-gapped systems. By subtly modifying on-screen pixels, TrojPix induces electromagnetic emissions from video cables, which can be intercepted and decoded by nearby receivers. This method achieves data transfer rates up to 8.1 Mbps and effective ranges up to 208 meters, significantly surpassing previous covert channels. Importantly, TrojPix requires pre-existing malware on the target system to function, serving as an exfiltration method rather than an initial intrusion vector. The emergence of TrojPix underscores the evolving sophistication of cyber-espionage tactics, particularly against isolated systems. Its high-speed, long-range capabilities highlight the need for enhanced physical and operational security measures to protect sensitive environments from such advanced threats.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports