Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3445 to 3456 of 5983
Microsoft's March 2026 Patch Tuesday: Addressing 83 Vulnerabilities, Including Two Publicly Disclosed Zero-Days
In March 2026, Microsoft released security updates addressing 83 vulnerabilities across its product suite, including Windows, Office, SQL Server, Azure, and .NET. Among these, two zero-day vulnerabilities were publicly disclosed prior to patch release: CVE-2026-21262, an elevation of privilege flaw in SQL Server, and CVE-2026-26127, a denial-of-service vulnerability in .NET. Notably, none of these vulnerabilities were reported as actively exploited in the wild at the time of release. The update also included eight critical vulnerabilities, such as CVE-2026-21536, a remote code execution flaw in the Microsoft Devices Pricing Program, which Microsoft mitigated server-side without requiring user action. This Patch Tuesday marks the first in six months without any actively exploited zero-day vulnerabilities, indicating a positive trend in Microsoft's proactive security measures. However, the presence of publicly disclosed vulnerabilities underscores the importance of timely patch application to mitigate potential risks.
6 months ago
Kill Chain
Stryker's 2026 Cyberattack: A Wake-Up Call for Healthcare Cybersecurity
In March 2026, Stryker Corporation, a leading U.S. medical technology company, experienced a significant cyberattack attributed to the pro-Palestinian hacktivist group Handala. The attackers reportedly utilized wiper malware to erase data from over 200,000 systems, including servers and mobile devices, leading to widespread operational disruptions across Stryker's global network. Employees in multiple countries, notably Ireland, were sent home as the company worked to contain the incident. Handala claimed the attack was retaliation for a missile strike that resulted in civilian casualties in Iran. This incident underscores the escalating trend of state-sponsored hacktivism targeting critical infrastructure and healthcare sectors. Organizations must enhance their cybersecurity measures to defend against sophisticated threats that aim not only to steal data but also to cause operational paralysis. The use of wiper malware highlights the need for robust data backup and recovery strategies to mitigate the impact of such destructive attacks.
6 months ago
Kill Chain
APT28's 2026 Espionage Campaign: Exploiting Office Vulnerabilities with Advanced Malware
In early 2026, the Russian state-sponsored threat actor APT28, also known as Fancy Bear, launched a sophisticated cyber-espionage campaign targeting Ukrainian military personnel. The attackers utilized spear-phishing emails containing malicious Microsoft Office documents to exploit the CVE-2026-21509 vulnerability, allowing them to execute code via OLE objects without macros or warnings. This method facilitated the deployment of two advanced malware implants: BeardShell, a custom C++ backdoor leveraging the Icedrive cloud service for command-and-control communications, and Covenant, a heavily modified open-source .NET post-exploitation framework. These tools enabled APT28 to conduct long-term surveillance, data exfiltration, and maintain persistent access to compromised systems. ([cyberpress.org](https://cyberpress.org/apt28-exploits-office-vulnerability/?utm_source=openai)) This incident underscores a significant evolution in APT28's tactics, techniques, and procedures (TTPs), highlighting their ability to rapidly weaponize newly disclosed vulnerabilities and integrate legitimate cloud services into their command-and-control infrastructure. The campaign's success emphasizes the urgent need for organizations to promptly apply security patches, enhance phishing defenses, and monitor for abuse of legitimate services in cyber operations. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/03/10/sednit-espionage-toolkit-stealing-data/?utm_source=openai))
6 months ago
Kill Chain
Microsoft's March 2026 Patch Tuesday: Key Vulnerabilities and Updates
In March 2026, Microsoft released security updates addressing 83 vulnerabilities across its product suite, including Windows, Office, SQL Server, Azure, and .NET. Notably, two zero-day vulnerabilities were publicly disclosed prior to patch release: CVE-2026-21262, an elevation of privilege flaw in SQL Server, and CVE-2026-26127, a denial-of-service vulnerability in .NET. Additionally, a critical remote code execution vulnerability, CVE-2026-21536, affecting the Microsoft Devices Pricing Program, was mitigated server-side without requiring user action. While none of these vulnerabilities were reported as actively exploited in the wild, organizations are advised to apply the patches promptly to mitigate potential risks. ([anonhaven.com](https://anonhaven.com/en/news/microsoft-march-2026-patch-tuesday-83-cves/?utm_source=openai)) The absence of actively exploited zero-day vulnerabilities in this release marks a positive shift from previous months. However, the public disclosure of certain flaws prior to patch availability underscores the importance of timely updates. Organizations should remain vigilant, as threat actors may exploit unpatched systems, emphasizing the need for robust patch management practices. ([cyberscoop.com](https://cyberscoop.com/microsoft-patch-tuesday-march-2026/?utm_source=openai))
6 months ago
Kill Chain
Salesforce Experience Cloud Guest User Misconfiguration Breach 2026
In March 2026, the cybercriminal group ShinyHunters exploited misconfigured guest user profiles in Salesforce's Experience Cloud, leading to unauthorized access to sensitive customer data. By utilizing a modified version of the open-source tool AuraInspector, the attackers scanned public-facing Experience Cloud sites and extracted data without authentication. This breach impacted approximately 400 organizations, including high-profile companies such as Snowflake, Okta, LastPass, Sony, AMD, and Salesforce itself. The compromised data included names, phone numbers, and other CRM information, which were subsequently used for social engineering and voice phishing campaigns. Salesforce confirmed that the issue stemmed from customer-configured settings rather than a vulnerability in its platform. ([techradar.com](https://www.techradar.com/pro/security/shinyhunters-claims-its-behind-ongoing-salesforce-aura-data-theft-assault-warns-more-attacks-to-come?utm_source=openai)) This incident underscores the critical importance of proper configuration and regular auditing of cloud-based services. Misconfigurations, especially in widely used platforms like Salesforce, can lead to significant data breaches, emphasizing the need for organizations to adhere to security best practices and continuously monitor their systems for potential vulnerabilities.
6 months ago
Kill Chain
Chinese APT Group Exploits Middle East Tensions to Target Qatar with PlugX Malware
In early March 2026, the Chinese-linked Advanced Persistent Threat (APT) group known as Camaro Dragon launched a cyber-espionage campaign targeting entities in Qatar. Within 24 hours of the escalation of Middle East tensions, the group deployed PlugX malware using war-themed lure documents that mimicked legitimate communications related to the regional conflict. The infection chain involved malicious LNK files leading to DLL hijacking of a legitimate Baidu NetDisk binary, ultimately installing the PlugX backdoor. This malware enables remote command execution, keystroke logging, screen capture, and data exfiltration. The rapid deployment and contextually relevant lures highlight the group's ability to swiftly adapt to geopolitical events for intelligence gathering purposes. This incident underscores the increasing trend of state-sponsored cyber actors exploiting current geopolitical crises to enhance the effectiveness of their campaigns. Organizations, especially those in geopolitically sensitive regions, must remain vigilant against such rapidly evolving threats and ensure robust cybersecurity measures are in place to detect and mitigate sophisticated intrusion attempts.
6 months ago
Kill Chain
AWS Data Centers in Middle East Targeted by Drone Strikes in 2026
In early March 2026, Iranian drone strikes targeted Amazon Web Services (AWS) data centers in the United Arab Emirates (UAE) and Bahrain, causing significant structural damage and service disruptions. Two facilities in the UAE were directly hit, while a third in Bahrain sustained damage from a nearby strike. These attacks led to outages across multiple AWS services, including EC2, S3, and RDS, affecting businesses, financial institutions, and government entities in the region. AWS reported that recovery efforts would be prolonged due to the extent of the physical damage. ([thenationalnews.com](https://www.thenationalnews.com/business/2026/03/03/drone-strikes-damage-amazon-data-centres-in-uae-and-bahrain-disrupting-services/?utm_source=openai)) This incident underscores the vulnerability of cloud infrastructure to physical attacks, especially in geopolitically volatile regions. Organizations relying on cloud services must reassess their disaster recovery and data sovereignty strategies to ensure resilience against both cyber and kinetic threats. ([apnews.com](https://apnews.com/article/71066b0a822c4cfd88b61e3fe79af917?utm_source=openai))
6 months ago
Kill Chain
Critical Vulnerabilities in Lantronix EDS3000PS and EDS5000 Devices Threaten Infrastructure Security
In March 2026, multiple critical vulnerabilities were identified in Lantronix EDS3000PS and EDS5000 devices, including OS command injection and authentication bypass issues. Exploitation of these vulnerabilities could allow attackers to execute code with root-level privileges, potentially compromising critical infrastructure sectors such as Communications, Information Technology, and Critical Manufacturing. ([cisa.gov](https://www.cisa.gov/news-events/bulletins/sb22-108?utm_source=openai)) This incident underscores the ongoing risks associated with unpatched vulnerabilities in network devices, highlighting the necessity for organizations to implement robust vulnerability management and regular system updates to mitigate potential threats.
6 months ago
Kill Chain
Critical Security Flaws in Apeman Cameras: A 2025 Analysis
In late 2025, multiple critical vulnerabilities were identified in Apeman ID71 cameras, including hard-coded credentials (CVE-2025-11126), cross-site scripting (CVE-2025-11851), and missing authentication for critical functions (CVE-2025-11852). These flaws could allow remote attackers to gain unauthorized access, manipulate device settings, or intercept camera feeds. Despite early notifications, Apeman did not respond to these disclosures, leaving devices exposed to potential exploitation. The prevalence of IoT devices with unpatched vulnerabilities underscores the urgent need for manufacturers to implement robust security measures and for users to apply timely updates. This incident highlights the critical importance of proactive vulnerability management in safeguarding connected devices against emerging threats.
6 months ago
Kill Chain
Microsoft's March 2026 Patch Tuesday: Addressing 83 Vulnerabilities, Including Two Zero-Days
In March 2026, Microsoft released security updates addressing 83 vulnerabilities across its product suite, including Windows, Office, SQL Server, Azure, and .NET. Among these, eight were rated as critical, and two vulnerabilities—CVE-2026-26127 and CVE-2026-21262—were publicly disclosed prior to patch release, though neither had been exploited in the wild. CVE-2026-21536, a remote code execution flaw in Microsoft's Devices Pricing Program, received the highest severity rating with a CVSS score of 9.8. Microsoft has proactively mitigated this issue within its cloud infrastructure, requiring no customer action. ([anonhaven.com](https://anonhaven.com/en/news/microsoft-march-2026-patch-tuesday-83-cves/?utm_source=openai)) This update marks the first Patch Tuesday in six months without any actively exploited zero-day vulnerabilities. The absence of active exploitation provides organizations a crucial window to apply patches without the immediate pressure of ongoing attacks. However, the disclosure of vulnerabilities like CVE-2026-26127 and CVE-2026-21262 underscores the importance of timely patch management to preempt potential exploitation. ([cyberscoop.com](https://cyberscoop.com/microsoft-patch-tuesday-march-2026/?utm_source=openai))
6 months ago
Kill Chain
Critical Unauthenticated Access Vulnerability in Honeywell IQ4x BMS Controllers (2026)
In March 2026, a critical vulnerability (CVE-2026-3611) was identified in Honeywell's IQ4x Building Management System (BMS) controllers. The flaw allows unauthenticated access to the web-based Human-Machine Interface (HMI) in factory-default configurations, enabling remote attackers to create administrative accounts, manipulate building controls, and potentially lock out legitimate operators. This vulnerability affects multiple models, including IQ4E, IQ412, IQ422, IQ4NC, IQ41x, IQ3, and IQECO, across firmware versions from v3.50_3.44 to v4.36_build_4.3.7.9. ([community.itbible.org](https://community.itbible.org/t/honeywell-iq4x-bms-controller/2685?utm_source=openai)) The discovery underscores the critical need for secure default configurations in industrial control systems. With thousands of these controllers potentially exposed online, the risk of unauthorized access to critical infrastructure is heightened, emphasizing the importance of immediate remediation and robust security practices in operational technology environments. ([cybersecuritynews.com](https://cybersecuritynews.com/thousand-of-honeywell-controllers-exposed/?utm_source=openai))
6 months ago
Kill Chain
Critical Vulnerability in Ceragon and Siklu's EtherHaul and MultiHaul Devices (CVE-2025-57176)
In September 2025, a critical vulnerability (CVE-2025-57176) was identified in Ceragon Networks and Siklu Communication's EtherHaul and MultiHaul series devices. The 'rfpiped' service on TCP port 555 allowed unauthenticated file uploads to any writable location on the device. This flaw, present in firmware versions 7.4.0 through 10.7.3, utilized weak encryption for metadata and transmitted file contents in cleartext, lacking authentication and path validation. Exploitation could lead to unauthorized access and control over affected devices. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-57176?utm_source=openai)) This incident underscores the persistent risks associated with inadequate authentication mechanisms in network devices. Organizations must prioritize regular firmware updates and implement robust access controls to mitigate such vulnerabilities.
6 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

