Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 1 to 12 of 5908
Ransomware Gangs Exploit Critical VMware vCenter RCE Flaw (CVE-2026-59310)
In July 2026, Broadcom patched CVE-2026-59310, a critical directory traversal vulnerability in VMware vCenter's Syslog server that allows unauthenticated remote code execution. Despite urgent patching guidance, threat actors quickly began exploiting the flaw within weeks, with QUIRSO identifying over 361 compromised IP addresses across 47 countries. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog in August and recently flagged it as actively exploited by ransomware gangs, highlighting the critical risk to enterprise virtualization infrastructure. This incident underscores the accelerating timeline between vulnerability disclosure and ransomware exploitation, particularly targeting VMware environments that serve as high-value infrastructure targets for enterprise data access and lateral movement capabilities.
14 hours ago
Kill Chain
PaperCut Zero-Day Incident Exposes Critical Gaps in Post-Mythos Security Response
In August 2026, PaperCut NG/MF servers faced active zero-day exploitation before any patches were available, exemplifying the new reality of AI-accelerated vulnerability discovery. The incident began on August 27 when PaperCut issued an urgent advisory about active exploitation with no CVE, exploit details, or available patches. The first emergency patch released a day later was immediately bypassed, requiring three separate patch iterations over six days while attackers maintained active exploitation capabilities. This incident highlighted the critical gap between disclosure and effective remediation in the post-Mythos era, where disclosure-to-exploitation windows have compressed from an average of 21.5 days to mere hours. This incident represents the new template for zero-day response in an era where artificial intelligence has fundamentally accelerated both vulnerability discovery and weaponization timelines. Organizations now face scenarios where traditional patch-first security models fail, requiring immediate implementation of compensating controls and technique-based validation before exploits become publicly available.
14 hours ago
Kill Chain
VectraRAT: How a $250 Subscription Makes Enterprise Hacking Accessible
VectraRAT represents a sophisticated malware-as-a-service (MaaS) platform discovered by SOCRadar researchers in June 2026, offering cybercriminals comprehensive enterprise attack capabilities for just $250 per month. The platform provides a full-stack solution including a custom Windows implant, command-and-control infrastructure, and operator panel built entirely from scratch rather than leveraging existing malware frameworks. The RAT incorporates advanced features like User Account Control bypass, proprietary C2 protocols, credential harvesting, and remote desktop access. Analysis revealed 48% of victims were corporate Windows environments including Enterprise editions and Windows Server 2025, with confirmed data exfiltration from compromised systems across the US, Russia, and Germany. This incident highlights the concerning democratization of sophisticated cyberattack capabilities, as professional-grade attack infrastructure becomes increasingly accessible through affordable subscription models, significantly lowering the technical barriers for cybercriminals targeting enterprise networks.
19 hours ago
Kill Chain
Sandworm's Cyclops Blink Evolution: How Russian APT Exploited Cisco Infrastructure
In September 2026, the Russian state-sponsored threat group Sandworm exploited two critical vulnerabilities in Cisco's Firewall Management Center (FMC) software to deploy an upgraded version of the Cyclops Blink malware. The attackers chained CVE-2026-20079 (a maximum severity authentication bypass flaw) with CVE-2026-20316 (a privilege escalation vulnerability) to gain root access and deploy sophisticated backdoors capable of credential harvesting, network scanning, and traffic interception. This campaign represents a significant evolution of Cyclops Blink from its original 2022 variant, now targeting 64-bit Linux systems with enhanced reconnaissance capabilities across network infrastructure devices. This incident highlights the growing trend of state-sponsored actors targeting critical network infrastructure through vulnerability chaining, demonstrating how APT groups are rapidly adapting their malware arsenals to exploit modern enterprise environments and expanding their attack surface beyond traditional endpoints to network management platforms.
21 hours ago
Kill Chain
GitLab's Maximum-Severity Vulnerability: A Supply Chain Security Wake-Up Call
CVE-2026-85706, a maximum-severity path traversal vulnerability in GitLab Community and Enterprise Editions, is being actively exploited by threat actors to compromise software supply chains. The flaw, which received a CVSS score of 10.0, allows unauthenticated attackers to read arbitrary files from GitLab servers, including sensitive credentials and CI/CD secrets. GitLab disclosed and patched the vulnerability on September 10, 2026, but CISA added it to their Known Exploited Vulnerabilities catalog within days due to observed exploitation in the wild. Researchers detected rapid escalation from initial probes to full exploitation, with attackers extracting configuration files and SSH credentials that could enable complete system compromise and lateral movement into development environments. This incident highlights the growing threat to software supply chains as adversaries increasingly target development platforms to gain privileged access to source code, build processes, and deployment pipelines across multiple organizations.
21 hours ago
Kill Chain
CareCam CM2507 IP Cameras: Seven Critical Vulnerabilities Expose Enterprise Networks
The CareCam CM2507 IP camera contains seven critical vulnerabilities (CVE-2026-88259 through CVE-2026-81321) that collectively allow complete device compromise. These flaws include missing authentication for video streaming, empty passwords in ONVIF services, cleartext credential storage, weak password hashing, and unauthorized script execution from removable media. Attackers can exploit these vulnerabilities to access live video feeds, extract stored credentials, execute arbitrary code, and pivot to connected networks. The vendor has not responded to CISA's coordination attempts, leaving deployed devices unpatched. This incident highlights the persistent security challenges in IoT devices deployed across commercial facilities worldwide, particularly as organizations increasingly rely on IP cameras for security monitoring while threat actors actively target poorly secured IoT infrastructure for initial access and lateral movement.
21 hours ago
Kill Chain
Critical Hardcoded Key Vulnerabilities Expose Maritime Infrastructure in Wärtsilä FOS-Onboard Systems
Critical vulnerabilities CVE-2026-78225 and CVE-2026-81855 were discovered in Wärtsilä FOS-Onboard version 5.07.0923.01, affecting maritime transportation systems worldwide. Both vulnerabilities involve hardcoded cryptographic keys - one in the deployer-ng Update Controller component and another in the robot testing framework component. With CVSS scores of 9.0 and 9.1 respectively, successful exploitation could allow attackers to deliver unauthorized updates, execute arbitrary code, or extract credentials to impersonate privileged clients. Wärtsilä has developed security patches and states the vulnerabilities are not exploitable when the product is installed according to recommendations. This incident highlights the growing threat to maritime critical infrastructure as operational technology systems become increasingly connected and targeted by sophisticated adversaries seeking to disrupt global supply chains.
21 hours ago
Kill Chain
Vite Development Servers Under Attack: Mass Campaign Steals Cloud Credentials
In 2024, cybersecurity researchers from F5 Labs disclosed a mass-scanning campaign targeting exposed Vite development servers to extract sensitive cloud credentials and configuration data. The automated attack systematically scanned internet-facing Vite instances, exploiting misconfigurations to steal AWS and Microsoft Azure credentials, infrastructure state files, and other sensitive development artifacts. The campaign demonstrated how exposed development environments can become critical attack vectors for cloud infrastructure compromise, potentially leading to broader cloud account takeovers and data breaches across multiple organizations. This incident highlights the growing threat to cloud-native development workflows as attackers increasingly target DevOps toolchains and CI/CD pipelines. With organizations rapidly adopting cloud-first development practices and infrastructure-as-code approaches, securing development servers and preventing credential exposure has become a critical security imperative for preventing cloud account compromise.
22 hours ago
Kill Chain
Critical Vulnerability in Schneider Electric SCADAPack x70 Systems Exposes Industrial Infrastructure
Schneider Electric disclosed a critical vulnerability (CVE-2026-81861) affecting all versions of its SCADAPack x70 Remote Terminal Units used in critical infrastructure worldwide. The insufficiently protected credentials vulnerability could allow unauthorized access to RTU configuration through the legacy Secure Lock functionality, potentially compromising confidentiality of industrial control systems. The vulnerability affects SCADAPack 47x, 47xi, 47xd, 470R, 57x, 3xx, and 32 products deployed globally in critical manufacturing and energy sectors. Industrial control system vulnerabilities continue to represent a significant threat vector as critical infrastructure increasingly becomes a target for nation-state actors and ransomware groups seeking to disrupt essential services and cause maximum societal impact.
22 hours ago
Kill Chain
Machine-Speed Human Attack: CVE-2026-39987 Marimo Exploit Reaches SSH Bastion in 8 Seconds
In September 2026, skilled threat actors demonstrated machine-speed exploitation of CVE-2026-39987, a critical remote code execution vulnerability in Marimo notebooks with a CVSS score of 9.3. The attackers pivoted from initial compromise to SSH bastion host access in just eight seconds, using hand-crafted Python toolkits without AI assistance. Over a nine-hour session, they executed over 850 interactive commands, harvested AWS credentials from Secrets Manager, and established persistent access to cloud infrastructure, showcasing how human expertise can rival AI-assisted attacks in speed and stealth. This incident highlights the evolving threat landscape where skilled human operators are matching the speed traditionally expected from AI-powered attacks, while demonstrating superior evasion techniques that bypass automated defenses and detection systems designed to catch machine-generated attack patterns.
22 hours ago
Kill Chain
Revolut's 2026 Social Engineering Breach: When Trust Becomes a Vulnerability
In September 2026, fintech giant Revolut disclosed a targeted social engineering attack where threat actors impersonated a government agency to fraudulently obtain sensitive customer data. The attackers used valid domain authentication credentials to request personally identifiable information via email, successfully deceiving Revolut into sharing financial records, passport copies, transaction histories, and account details of high-net-worth customers. The company immediately blocked the fraudulent address and notified relevant authorities upon discovering the deception, though the exact number of affected customers remains undisclosed. This incident highlights the growing sophistication of social engineering attacks targeting financial institutions and the critical need for enhanced verification protocols when handling government data requests, particularly as threat actors increasingly exploit trusted communication channels to bypass security controls.
1 day ago
Kill Chain
Mass Campaign Exploits Vite CVE-2026-39364 to Steal Cloud Credentials
A mass-scanning campaign targeting internet-exposed Vite development servers exploited CVE-2026-39364, a high-severity vulnerability affecting Vite versions 7.1.0 through 7.3.2 and 8.x before 8.0.5. Attackers used query parameter manipulation to bypass file access controls and steal AWS and Azure cloud credentials, configuration files, and environment variables. F5 detected over 800 attacks and 32,000 events within a month, with attackers primarily using Google Cloud IP ranges from the US, Belgium, and Netherlands for evasion. This campaign highlights the growing threat to exposed development environments and the critical need for proper configuration management and credential protection in cloud-native deployments.
1 day ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

