✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 2881 to 2892 of 5196
Diesel Vortex Phishing Attack Targets Freight and Logistics Sector in 2025
In late 2025, a cybercriminal group known as 'Diesel Vortex' orchestrated a sophisticated phishing campaign targeting freight and logistics companies across the United States and Europe. Utilizing 52 deceptive domains, the attackers impersonated legitimate platforms such as DAT Truckstop, TIMOCOM, and Penske Logistics to harvest credentials from industry professionals. The campaign led to the compromise of 1,649 unique accounts, facilitating unauthorized access to critical systems and enabling fraudulent activities, including cargo theft and financial fraud. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/phishing-campaign-targets-freight-and-logistics-orgs-in-the-us-europe/?utm_source=openai)) This incident underscores a growing trend of targeted cyberattacks within the logistics sector, highlighting the urgent need for enhanced security measures and employee training to mitigate the risks associated with phishing and credential theft. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/phishing-campaign-targets-freight-and-logistics-orgs-in-the-us-europe/?utm_source=openai))
5 months ago
Kill Chain
Ex-L3Harris Executive Sentenced for Selling Zero-Day Exploits to Russian Broker
Between 2022 and 2025, Peter Williams, a 39-year-old Australian national and former general manager of Trenchant—a cybersecurity unit of defense contractor L3Harris—stole at least eight sensitive cyber-exploit components intended exclusively for the U.S. government and its allies. Williams sold these zero-day exploits to Operation Zero, a Russian cyber-tools broker that advertises its services to non-NATO buyers, including the Russian government. The theft resulted in $35 million in losses to L3Harris and potentially enabled unauthorized access to millions of devices worldwide. In October 2025, Williams pleaded guilty to two counts of theft of trade secrets and, in February 2026, was sentenced to 87 months in federal prison, forfeiting $1.3 million in cryptocurrency, a house, and luxury items. ([justice.gov](https://www.justice.gov/opa/pr/former-general-manager-us-defense-contractor-sentenced-87-months-selling-stolen-trade?utm_source=openai)) This incident underscores the critical threat posed by insider threats within defense and cybersecurity sectors. The sale of zero-day exploits to adversarial entities highlights the urgent need for robust internal security measures, comprehensive employee vetting, and continuous monitoring to prevent unauthorized access and exfiltration of sensitive information.
5 months ago
Kill Chain
U.S. Sanctions Russian Exploit Broker for Stolen Cyber Tools
In February 2026, the U.S. Department of the Treasury sanctioned Russian exploit broker Operation Zero and its owner, Sergey Zelenyuk, for acquiring and distributing cyber tools harmful to U.S. national security. These tools, including at least eight proprietary cyber exploits stolen from U.S. defense contractor L3Harris by former employee Peter Williams, were sold to unauthorized users. Williams pleaded guilty to theft of trade secrets in October 2025 and was sentenced to over seven years in prison. The sanctions also targeted associated individuals and entities, including UAE-based Special Technology Services LLC FZ, for their roles in the illicit trade of these cyber tools. This incident underscores the persistent threat posed by the illicit trade of zero-day exploits and the involvement of insiders in compromising sensitive information. It highlights the need for robust internal security measures and vigilant monitoring to prevent unauthorized access and distribution of critical cyber tools.
5 months ago
Kill Chain
Critical Zyxel Router Vulnerability (CVE-2025-13942) Exposes Networks to Remote Attacks
In February 2026, Zyxel identified a critical command injection vulnerability (CVE-2025-13942) in the UPnP function of several router models, including 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, and wireless extenders. This flaw allows unauthenticated remote attackers to execute operating system commands on affected devices by sending specially crafted UPnP SOAP requests. While the vulnerability has a CVSS score of 9.8, its exploitation is contingent upon both UPnP and WAN access being enabled, with the latter disabled by default. Zyxel has released security patches to address this issue and strongly advises users to update their firmware promptly. The significance of this vulnerability is underscored by the widespread deployment of Zyxel devices, often provided by internet service providers as default equipment. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is monitoring multiple Zyxel vulnerabilities, highlighting the ongoing risk to network security.
5 months ago
Kill Chain
Marquis Software Solutions Ransomware Attack: A Supply Chain Vulnerability Exposed
In August 2025, Marquis Software Solutions, a Texas-based fintech firm serving over 700 financial institutions, experienced a ransomware attack that compromised sensitive data of more than 780,000 individuals across at least 80 banks and credit unions. The attackers exploited a vulnerability in SonicWall's firewall backup service, gaining unauthorized access to Marquis's network and exfiltrating personal information, including names, addresses, Social Security numbers, and financial account details. This breach underscores the critical importance of securing third-party services and the potential cascading effects of supply chain vulnerabilities. The incident highlights the growing trend of cybercriminals targeting supply chain weaknesses to infiltrate organizations, emphasizing the need for comprehensive security assessments and robust vendor management practices to mitigate such risks.
5 months ago
Kill Chain
OpenClaw Supply Chain Attack 2026: Lessons Learned
In February 2026, the OpenClaw AI assistant platform faced a significant supply chain attack. Malicious actors uploaded over 230 compromised 'skills' to ClawHub, OpenClaw's skill repository, between January 27 and 29. These skills, often disguised as crypto trading tools, were designed to exfiltrate sensitive user data, including cryptocurrency wallets and browser information. The attack exploited OpenClaw's extensive system permissions, allowing unauthorized access to users' local files and networks. Additionally, a vulnerability in the Cline CLI tool led to the unintended installation of OpenClaw on approximately 4,000 developer systems, further expanding the attack's reach. ([cyware.com](https://www.cyware.com/resources/threat-briefings/daily-threat-briefing/cyware-daily-threat-intelligence-february-03-2026?utm_source=openai)) This incident underscores the escalating risks associated with AI-powered automation tools and their plugin ecosystems. The rapid adoption of such platforms, combined with insufficient security vetting of third-party extensions, has created new avenues for supply chain attacks. Organizations must prioritize stringent security measures, including thorough code reviews and robust authentication protocols, to mitigate these emerging threats.
5 months ago
Kill Chain
Critical FileZen Vulnerability Exploited: Immediate Action Required
In February 2026, a critical OS command injection vulnerability (CVE-2026-25108) was identified in Soliton Systems' FileZen, a secure file transfer solution. This flaw allows authenticated users to execute arbitrary commands via specially crafted HTTP requests when the Antivirus Check Option is enabled. Exploitation requires valid user credentials, potentially obtained through phishing or credential stuffing. The vulnerability affects FileZen versions 4.2.1 to 4.2.8 and 5.0.0 to 5.0.10. Soliton Systems has released version 5.0.11 to address this issue. Organizations are urged to update immediately and review logs for unauthorized access. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/25/cve-2026-25108-filezen-vulnerability-exploited/?utm_source=openai)) The active exploitation of this vulnerability underscores the persistent threat posed by command injection flaws, emphasizing the need for robust input validation and timely patch management. The incident highlights the importance of monitoring for unauthorized access and maintaining strict access controls to mitigate potential breaches.
5 months ago
Kill Chain
Chinese Cyberspies Exploit Google Sheets in 2026 Telecom Breach
In February 2026, Google's Threat Intelligence Group, in collaboration with Mandiant and other partners, disrupted a sophisticated cyber-espionage campaign attributed to a Chinese state-sponsored actor known as UNC2814. This campaign, active since at least 2023, targeted 53 organizations across 42 countries, primarily within the telecommunications and government sectors. The attackers deployed a novel backdoor named 'GRIDTIDE,' which exploited the Google Sheets API to facilitate covert command-and-control operations, effectively blending malicious traffic with legitimate network activity. The initial access vector remains unidentified; however, UNC2814 has a history of exploiting vulnerabilities in web servers and edge systems to infiltrate target networks. ([thehackernews.com](https://thehackernews.com/2026/02/google-disrupts-unc2814-gridtide.html?utm_source=openai)) The disruption of this campaign underscores the persistent and evolving nature of cyber threats posed by state-sponsored actors. The use of legitimate services like Google Sheets for command-and-control highlights the increasing sophistication of such attacks, making detection and mitigation more challenging. Organizations, especially those in critical infrastructure sectors, must remain vigilant and adopt comprehensive cybersecurity measures to defend against these advanced persistent threats.
5 months ago
Kill Chain
Cisco SD-WAN Authentication Bypass Vulnerability Exploited by UAT-8616
In February 2026, Cisco disclosed a critical authentication bypass vulnerability (CVE-2026-20127) in its Catalyst SD-WAN Controller and Manager, exploited by the threat actor UAT-8616 since at least 2023. This flaw allowed unauthenticated remote attackers to gain administrative access, manipulate network configurations, and establish persistent control over affected systems. The exploitation involved downgrading software versions to exploit older vulnerabilities, further escalating privileges. The incident underscores the persistent targeting of network infrastructure by sophisticated actors, emphasizing the need for vigilant monitoring and timely patching of critical vulnerabilities.
5 months ago
Kill Chain
Critical Vulnerabilities in SolarWinds Serv-U: Immediate Action Required
In February 2026, SolarWinds addressed four critical vulnerabilities in its Serv-U file transfer software, identified as CVE-2025-40538 through CVE-2025-40541. These flaws, each with a CVSS score of 9.1, could allow attackers with administrative privileges to execute arbitrary code as root. The vulnerabilities include broken access control, type confusion, and insecure direct object reference issues. While no active exploitation has been reported, similar past vulnerabilities have been targeted by threat actors, notably the China-based group Storm-0322. Organizations using Serv-U are urged to update to version 15.5.4 promptly to mitigate potential risks. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/25/solarwinds-serv-u-vulnerabilities-cve-2025-40538-to-cve-2025-40541/?utm_source=openai))
5 months ago
Kill Chain
L3Harris Insider Breach: Zero-Day Exploits Sold to Russian Broker
In October 2025, Peter Williams, a 39-year-old Australian national and former general manager at L3Harris's Trenchant division, pleaded guilty to stealing and selling eight zero-day exploits to a Russian broker, Operation Zero. Over a three-year period, Williams transferred these sensitive cyber-exploit components, originally intended for U.S. government and allied use, in exchange for approximately $1.3 million in cryptocurrency. This unauthorized sale resulted in significant national security concerns and financial losses exceeding $35 million for L3Harris. ([techcrunch.com](https://techcrunch.com/2025/10/29/former-l3harris-trenchant-boss-pleads-guilty-to-selling-zero-day-exploits-to-russian-broker/?utm_source=openai)) This incident underscores the critical need for stringent internal security measures within defense contractors, especially concerning personnel with high-level access to sensitive information. The case highlights the growing threat posed by insider threats and the importance of robust monitoring and compliance frameworks to prevent unauthorized dissemination of national security assets.
5 months ago
Kill Chain
Fake Next.js Job Interview Tests Backdoor Developers' Devices
In February 2026, a coordinated cyberattack targeted software developers through malicious repositories masquerading as legitimate Next.js projects. These repositories were shared during job interviews or technical assessments, leading developers to clone and execute the code. Upon execution, embedded JavaScript scripts initiated remote code execution (RCE), allowing attackers to deploy backdoors, exfiltrate sensitive data, and introduce additional payloads on compromised systems. The attack utilized multiple execution triggers, including VS Code tasks, development server commands, and backend startup scripts, to maximize infection rates. This incident underscores the evolving tactics of threat actors who exploit standard development workflows to infiltrate systems. The use of job-themed lures and the targeting of developers highlight a broader trend of sophisticated social engineering attacks aimed at the tech industry. Organizations must enhance their security protocols, particularly around code repositories and development tools, to mitigate such risks.
5 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

