Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3649 to 3660 of 5960
Marquis Software Solutions Ransomware Attack: A Supply Chain Vulnerability Exposed
In August 2025, Marquis Software Solutions, a Texas-based fintech firm serving over 700 financial institutions, experienced a ransomware attack that compromised sensitive data of more than 780,000 individuals across at least 80 banks and credit unions. The attackers exploited a vulnerability in SonicWall's firewall backup service, gaining unauthorized access to Marquis's network and exfiltrating personal information, including names, addresses, Social Security numbers, and financial account details. This breach underscores the critical importance of securing third-party services and the potential cascading effects of supply chain vulnerabilities. The incident highlights the growing trend of cybercriminals targeting supply chain weaknesses to infiltrate organizations, emphasizing the need for comprehensive security assessments and robust vendor management practices to mitigate such risks.
6 months ago
Kill Chain
OpenClaw Supply Chain Attack 2026: Lessons Learned
In February 2026, the OpenClaw AI assistant platform faced a significant supply chain attack. Malicious actors uploaded over 230 compromised 'skills' to ClawHub, OpenClaw's skill repository, between January 27 and 29. These skills, often disguised as crypto trading tools, were designed to exfiltrate sensitive user data, including cryptocurrency wallets and browser information. The attack exploited OpenClaw's extensive system permissions, allowing unauthorized access to users' local files and networks. Additionally, a vulnerability in the Cline CLI tool led to the unintended installation of OpenClaw on approximately 4,000 developer systems, further expanding the attack's reach. ([cyware.com](https://www.cyware.com/resources/threat-briefings/daily-threat-briefing/cyware-daily-threat-intelligence-february-03-2026?utm_source=openai)) This incident underscores the escalating risks associated with AI-powered automation tools and their plugin ecosystems. The rapid adoption of such platforms, combined with insufficient security vetting of third-party extensions, has created new avenues for supply chain attacks. Organizations must prioritize stringent security measures, including thorough code reviews and robust authentication protocols, to mitigate these emerging threats.
6 months ago
Kill Chain
Critical FileZen Vulnerability Exploited: Immediate Action Required
In February 2026, a critical OS command injection vulnerability (CVE-2026-25108) was identified in Soliton Systems' FileZen, a secure file transfer solution. This flaw allows authenticated users to execute arbitrary commands via specially crafted HTTP requests when the Antivirus Check Option is enabled. Exploitation requires valid user credentials, potentially obtained through phishing or credential stuffing. The vulnerability affects FileZen versions 4.2.1 to 4.2.8 and 5.0.0 to 5.0.10. Soliton Systems has released version 5.0.11 to address this issue. Organizations are urged to update immediately and review logs for unauthorized access. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/25/cve-2026-25108-filezen-vulnerability-exploited/?utm_source=openai)) The active exploitation of this vulnerability underscores the persistent threat posed by command injection flaws, emphasizing the need for robust input validation and timely patch management. The incident highlights the importance of monitoring for unauthorized access and maintaining strict access controls to mitigate potential breaches.
6 months ago
Kill Chain
Chinese Cyberspies Exploit Google Sheets in 2026 Telecom Breach
In February 2026, Google's Threat Intelligence Group, in collaboration with Mandiant and other partners, disrupted a sophisticated cyber-espionage campaign attributed to a Chinese state-sponsored actor known as UNC2814. This campaign, active since at least 2023, targeted 53 organizations across 42 countries, primarily within the telecommunications and government sectors. The attackers deployed a novel backdoor named 'GRIDTIDE,' which exploited the Google Sheets API to facilitate covert command-and-control operations, effectively blending malicious traffic with legitimate network activity. The initial access vector remains unidentified; however, UNC2814 has a history of exploiting vulnerabilities in web servers and edge systems to infiltrate target networks. ([thehackernews.com](https://thehackernews.com/2026/02/google-disrupts-unc2814-gridtide.html?utm_source=openai)) The disruption of this campaign underscores the persistent and evolving nature of cyber threats posed by state-sponsored actors. The use of legitimate services like Google Sheets for command-and-control highlights the increasing sophistication of such attacks, making detection and mitigation more challenging. Organizations, especially those in critical infrastructure sectors, must remain vigilant and adopt comprehensive cybersecurity measures to defend against these advanced persistent threats.
6 months ago
Kill Chain
Cisco SD-WAN Authentication Bypass Vulnerability Exploited by UAT-8616
In February 2026, Cisco disclosed a critical authentication bypass vulnerability (CVE-2026-20127) in its Catalyst SD-WAN Controller and Manager, exploited by the threat actor UAT-8616 since at least 2023. This flaw allowed unauthenticated remote attackers to gain administrative access, manipulate network configurations, and establish persistent control over affected systems. The exploitation involved downgrading software versions to exploit older vulnerabilities, further escalating privileges. The incident underscores the persistent targeting of network infrastructure by sophisticated actors, emphasizing the need for vigilant monitoring and timely patching of critical vulnerabilities.
6 months ago
Kill Chain
Critical Vulnerabilities in SolarWinds Serv-U: Immediate Action Required
In February 2026, SolarWinds addressed four critical vulnerabilities in its Serv-U file transfer software, identified as CVE-2025-40538 through CVE-2025-40541. These flaws, each with a CVSS score of 9.1, could allow attackers with administrative privileges to execute arbitrary code as root. The vulnerabilities include broken access control, type confusion, and insecure direct object reference issues. While no active exploitation has been reported, similar past vulnerabilities have been targeted by threat actors, notably the China-based group Storm-0322. Organizations using Serv-U are urged to update to version 15.5.4 promptly to mitigate potential risks. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/25/solarwinds-serv-u-vulnerabilities-cve-2025-40538-to-cve-2025-40541/?utm_source=openai))
6 months ago
Kill Chain
L3Harris Insider Breach: Zero-Day Exploits Sold to Russian Broker
In October 2025, Peter Williams, a 39-year-old Australian national and former general manager at L3Harris's Trenchant division, pleaded guilty to stealing and selling eight zero-day exploits to a Russian broker, Operation Zero. Over a three-year period, Williams transferred these sensitive cyber-exploit components, originally intended for U.S. government and allied use, in exchange for approximately $1.3 million in cryptocurrency. This unauthorized sale resulted in significant national security concerns and financial losses exceeding $35 million for L3Harris. ([techcrunch.com](https://techcrunch.com/2025/10/29/former-l3harris-trenchant-boss-pleads-guilty-to-selling-zero-day-exploits-to-russian-broker/?utm_source=openai)) This incident underscores the critical need for stringent internal security measures within defense contractors, especially concerning personnel with high-level access to sensitive information. The case highlights the growing threat posed by insider threats and the importance of robust monitoring and compliance frameworks to prevent unauthorized dissemination of national security assets.
6 months ago
Kill Chain
Fake Next.js Job Interview Tests Backdoor Developers' Devices
In February 2026, a coordinated cyberattack targeted software developers through malicious repositories masquerading as legitimate Next.js projects. These repositories were shared during job interviews or technical assessments, leading developers to clone and execute the code. Upon execution, embedded JavaScript scripts initiated remote code execution (RCE), allowing attackers to deploy backdoors, exfiltrate sensitive data, and introduce additional payloads on compromised systems. The attack utilized multiple execution triggers, including VS Code tasks, development server commands, and backend startup scripts, to maximize infection rates. This incident underscores the evolving tactics of threat actors who exploit standard development workflows to infiltrate systems. The use of job-themed lures and the targeting of developers highlight a broader trend of sophisticated social engineering attacks aimed at the tech industry. Organizations must enhance their security protocols, particularly around code repositories and development tools, to mitigate such risks.
6 months ago
Kill Chain
UFP Technologies Cyberattack: A 2026 Data Theft Incident
In February 2026, UFP Technologies, a leading medical device manufacturer, detected unauthorized access to its IT systems. The breach, identified on February 14, led to the theft and potential destruction of company data, impacting critical functions such as billing and label creation for customer deliveries. Immediate containment measures were implemented, and external cybersecurity experts were engaged to investigate and remediate the incident. The company has since restored access to the affected information and believes the threat actor has been removed from its systems. This incident underscores the escalating cyber threats targeting the healthcare sector, emphasizing the need for robust cybersecurity measures. Organizations must remain vigilant against sophisticated attacks that can disrupt operations and compromise sensitive data, highlighting the importance of proactive defense strategies and incident response planning.
6 months ago
Kill Chain
SLH's Strategic Shift: Recruiting Women for Targeted Vishing Attacks in 2026
In February 2026, the cybercrime collective Scattered LAPSUS$ Hunters (SLH) initiated a campaign to recruit women for voice phishing (vishing) attacks targeting IT help desks. Offering financial incentives of $500 to $1,000 per call and providing pre-written scripts, SLH aims to enhance the effectiveness of their social engineering tactics by leveraging female voices to impersonate employees. This strategy is designed to manipulate help desk personnel into resetting passwords or installing remote monitoring tools, thereby granting unauthorized access to corporate networks. ([dataminr.com](https://www.dataminr.com/resources/intel-brief/slh-recruiting-women-for-vishing/?utm_source=openai)) This development underscores a significant evolution in cybercriminal methodologies, highlighting the increasing sophistication of social engineering attacks. Organizations must recognize the heightened risk posed by such targeted vishing campaigns and implement robust security measures to mitigate potential breaches.
6 months ago
Kill Chain
Malicious NuGet Packages Target ASP.NET Developers in 2026 Supply Chain Attack
In February 2026, cybersecurity researchers identified a supply chain attack involving four malicious NuGet packages—NCryptYo, DOMOAuth2_, IRAOAuth2.0, and SimpleWriter_—targeting ASP.NET developers. These packages, published between August 12 and 21, 2024, by a user named hamzazaheer, were downloaded over 4,500 times before removal. The attack exfiltrated ASP.NET Identity data, including user accounts and role assignments, and manipulated authorization rules to create persistent backdoors in victim applications. NCryptYo acted as a first-stage dropper, establishing a local proxy for command-and-control communication, while the other packages facilitated data theft and backdoor creation. This incident underscores the escalating threat of supply chain attacks targeting software developers. Similar campaigns have been observed in other ecosystems, such as the npm registry, where malicious packages like ambar-src have been used to deploy cross-platform malware. The increasing frequency and sophistication of these attacks highlight the critical need for developers to exercise caution when incorporating third-party packages and to implement robust security measures to protect their development environments and end-users.
6 months ago
Kill Chain
Google Disrupts UNC2814's Global Cyber Espionage Campaign
In February 2026, Google, in collaboration with industry partners, disrupted a sophisticated cyber espionage campaign orchestrated by the Chinese-linked group UNC2814. Active since at least 2017, UNC2814 infiltrated 53 organizations across 42 countries, primarily targeting telecommunications and government sectors. The group employed a novel backdoor, GRIDTIDE, which exploited the Google Sheets API to disguise command-and-control (C2) communications, enabling the execution of arbitrary shell commands and data exfiltration. The attackers gained initial access by compromising web servers and edge systems, subsequently moving laterally within networks using service accounts and living-off-the-land techniques. ([thehackernews.com](https://thehackernews.com/2026/02/google-disrupts-unc2814-gridtide.html?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors in leveraging legitimate cloud services to evade detection. The global scale and sophistication of UNC2814's operations highlight the critical need for organizations to enhance their cybersecurity measures, particularly in monitoring and securing cloud-based applications and APIs. ([thehackernews.com](https://thehackernews.com/2026/02/google-disrupts-unc2814-gridtide.html?utm_source=openai))
6 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

