LIVE · cybersecurity feed
Live wire
security

Military device manufacturer discloses cyber incident to SEC

IEH Corporation — which produces specialized products used in military satellites, missiles and fighter jets — said it discovered a cyberattack on Tuesday and immediately tried to contain it.

zeroday.news ·

IEH Corporation, a manufacturer of specialized electronic components for military applications, has disclosed a cyber incident to the U.S. Securities and Exchange Commission (SEC) after an employee's email inbox was compromised. The company, which produces connectors used in military satellites, missiles, and fighter jets, stated that it discovered the cyberattack on Tuesday, August 4, 2026, and promptly initiated containment measures.

According to the 8-K filing with the SEC, the incident stemmed from a phishing attack that granted unauthorized parties access to an employee's mailbox. The compromised inbox contained various types of information, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information.

While IEH Corporation confirmed that sensitive information was accessible to the unauthorized party during the compromise period, as of Friday, August 7, 2026, there is no evidence that emails or other data were exfiltrated from the account. The company is currently undertaking corrective actions to secure the mailbox and preserve evidence related to the incident.

The investigation into the breach is ongoing. IEH Corporation has indicated that, as of the latest update, there is no evidence to suggest the incident will impact its business operations.

IEH Corporation's products are critical components in various defense systems, including precision-guided missile programs such as THAAD and Patriot Missiles. Their connectors are also utilized in fighter jets, airborne radars, rotary-winged aircraft, ground radars, radios, and torpedoes. The company's customer base includes European countries and the government of India. For the 2026 fiscal year, IEH Corporation reported revenues approaching $30 million.

ShareXLinkedInWhatsAppFacebook

More News

view all →
malwarehigh

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.

security

New Mexico judge orders Meta to pay $567 million in kids online safety case

The money will be used to create a fund to mitigate social media harms, including by carving out $420 million for treatment for New Mexico youth who have been hurt on the platforms.

vulnerability

WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover

WordPress XSS2Shell flaw enables admin takeover and remote code execution. Users should update to patched versions. Researchers at Pwn just published a report on a vulnerability chain they’re calling XSS2Shell, and the entry point is quite simple: type a username that doesn’t exist, and WordPress echoes it back with a tiny formatting flaw baked into […]

breach

Hackers Impersonate IT Support to Breach Leading Financial Companies

Hackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies. A hacking campaign operating under names including Redact, Pink, Falcon, and Helix has built credential-stealing websites targeting employees at Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s, among

security

Levi Strauss & Co. says hackers stole corporate data in cyberattack

Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. [...]

vulnerability

N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands

Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again