Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3721 to 3732 of 5957
Abu Dhabi Finance Week 2026 Data Breach: A Cloud Misconfiguration Exposes VIP Passport Details
In early February 2026, Abu Dhabi Finance Week (ADFW) experienced a significant data breach due to a misconfigured cloud storage environment managed by a third-party vendor. This misconfiguration exposed scans of over 700 passports and identity cards belonging to high-profile attendees, including former British Prime Minister David Cameron and U.S. investor Anthony Scaramucci. The breach was discovered by cybersecurity researcher Roni Suchowski, who found that the sensitive documents were publicly accessible without password protection. Upon notification, ADFW promptly secured the environment and stated that access activity was limited to the researcher who identified the issue. The incident underscores the critical importance of securing cloud storage configurations to prevent unauthorized access to sensitive information. ([techradar.com](https://www.techradar.com/pro/security/abu-dhabi-finance-summit-exposes-personal-data-passport-info-of-hundreds-of-major-global-figures?utm_source=openai)) This breach highlights the ongoing risks associated with cloud misconfigurations, which continue to be a leading cause of data exposure. As organizations increasingly rely on cloud services, ensuring proper configuration and regular security audits is essential to protect sensitive data and maintain trust with stakeholders.
6 months ago
Kill Chain
Cline 2026 Supply Chain Attack: Lessons Learned
In February 2026, the Cline CLI npm package, a widely used AI coding assistant, was compromised through a supply chain attack. An unauthorized party exploited a stolen npm publish token to release version 2.3.0, which included a postinstall script that silently installed the OpenClaw package globally on users' machines. This malicious version was available for approximately eight hours before being deprecated, during which it was downloaded over 4,000 times. While OpenClaw itself is not malicious, its unauthorized installation raised significant security concerns. This incident underscores the escalating threat of supply chain attacks targeting developer tools and the necessity for robust security measures in software distribution pipelines.
6 months ago
Kill Chain
Starkiller Phishing Kit: A New Era of MFA Bypass Attacks
In February 2026, cybersecurity researchers uncovered 'Starkiller,' a sophisticated phishing-as-a-service (PhaaS) platform that enables cybercriminals to bypass multi-factor authentication (MFA) by proxying live login pages. Unlike traditional phishing kits that use static HTML clones, Starkiller employs a headless Chrome browser within a Docker container to relay real-time authentication sessions, capturing credentials, MFA codes, and session tokens as users interact with legitimate sites. This approach allows attackers to harvest sensitive information without raising user suspicion. The platform is distributed on the dark web with a subscription model, offering updates and customer support, thereby lowering the technical barrier for launching credential-stealing campaigns at scale. ([darkreading.com](https://www.darkreading.com/threat-intelligence/starkiller-phishing-kit-mfa/?utm_source=openai)) The emergence of Starkiller highlights a significant escalation in phishing infrastructure, demonstrating a shift towards real-time, session-aware compromises that render traditional detection methods, such as static page analysis and URL blocklisting, less effective. Organizations are urged to adopt behavioral and identity-aware detection strategies, including monitoring for anomalous sign-ins and session token reuse, to mitigate the risks posed by such advanced phishing platforms. ([darkreading.com](https://www.darkreading.com/threat-intelligence/starkiller-phishing-kit-mfa/?utm_source=openai))
6 months ago
Kill Chain
Critical Vulnerabilities Discovered in Jinan USR IOT's USR-W610 Device
In February 2026, multiple critical vulnerabilities were identified in Jinan USR IOT Technology Limited's USR-W610 serial device server, affecting firmware versions up to and including 3.1.1.0. These vulnerabilities include weak password requirements, cleartext transmission of sensitive information, insufficiently protected credentials, and missing authentication for critical functions. Exploitation could lead to authentication bypass, denial-of-service conditions, or unauthorized access to user credentials, including administrative accounts. ([windowsforum.com](https://windowsforum.com/threads/high-severity-ics-advisory-hits-usr-w610-serial-gateway-cve-2026-25715-to-cve-2026-26048.402628/post-959899?utm_source=openai)) The USR-W610 is widely deployed in industrial environments to bridge legacy serial devices with IP-based networks. Given the device's role in critical manufacturing sectors, these vulnerabilities pose significant risks, including potential unauthorized process changes, production downtime, and safety incidents. ([windowsforum.com](https://windowsforum.com/threads/high-severity-ics-advisory-hits-usr-w610-serial-gateway-cve-2026-25715-to-cve-2026-26048.402628/post-959899?utm_source=openai))
6 months ago
Kill Chain
Critical Vulnerability in Valmet DNA Engineering Web Tools: CVE-2025-15577
In February 2026, a critical vulnerability (CVE-2025-15577) was identified in Valmet DNA Engineering Web Tools versions C2022 and earlier. This flaw allows unauthenticated attackers to manipulate URLs, enabling arbitrary file read access on the affected systems. Exploiting this vulnerability could lead to unauthorized access to sensitive information, posing significant risks to industrial control systems. ([valmet.com](https://www.valmet.com/company/innovation/advisories/CVE-2025-15577/?utm_source=openai)) The discovery of this vulnerability underscores the ongoing challenges in securing industrial control systems against cyber threats. Organizations utilizing Valmet DNA Web Tools are urged to apply the vendor-provided patches promptly and implement recommended security measures to mitigate potential exploitation. ([valmet.com](https://www.valmet.com/company/innovation/advisories/CVE-2025-15577/?utm_source=openai))
6 months ago
Kill Chain
Critical Vulnerabilities in EnOcean SmartServer IoT: Immediate Action Required
In February 2026, critical vulnerabilities were identified in EnOcean's SmartServer IoT versions up to 4.60.009. These flaws, CVE-2026-20761 and CVE-2026-22885, allowed remote attackers to execute arbitrary OS commands and cause memory leaks via specially crafted LON IP-852 management messages. Exploitation could lead to unauthorized control over affected devices and potential data breaches. EnOcean promptly addressed these issues by releasing SmartServer 4.6 Update 2 (v4.60.023) and provided a hardening guide to enhance security measures. Organizations utilizing SmartServer IoT are urged to update to the latest version and implement recommended security practices to mitigate risks associated with these vulnerabilities.
6 months ago
Kill Chain
Critical Vulnerability in Welker OdorEyes EcoSystem Pulse Bypass System (CVE-2026-24790)
In February 2026, a critical vulnerability (CVE-2026-24790) was identified in Welker's OdorEyes EcoSystem Pulse Bypass System with XL4 Controller, widely used in gas odorization processes. This flaw allows remote attackers to manipulate the device's programmable logic controller (PLC) without authentication, potentially leading to over- or under-odorization events. Such incidents can compromise safety, regulatory compliance, and operational integrity. The vendor has not responded to coordinated disclosure attempts, leaving systems exposed to potential exploitation. ([windowsforum.com](https://windowsforum.com/threads/cve-2026-24790-unauthenticated-control-flaw-in-welker-odoreyes-xl4.402623/?utm_source=openai)) This vulnerability underscores the pressing need for robust security measures in industrial control systems, especially those integral to critical infrastructure sectors like energy and chemical processing. The lack of authentication safeguards in such devices highlights a broader issue of security gaps in industrial equipment, necessitating immediate attention and remediation efforts to prevent potential disruptions and safety hazards.
6 months ago
Kill Chain
OpenClaw 2026 Infostealer Malware Attack: A Wake-Up Call for AI Security
In February 2026, OpenClaw, an open-source AI assistant formerly known as Clawdbot and Moltbot, became the target of infostealer malware. Cybersecurity firm Hudson Rock reported that attackers exploited OpenClaw's configuration, which stores sensitive information like API keys and authentication tokens, to extract valuable data. The malware accessed these configurations during standard data-grabbing operations, leading to potential exposure of user credentials and other sensitive information. This incident underscores the growing vulnerability of AI assistant tools as they become more integrated into professional workflows. ([techradar.com](https://www.techradar.com/pro/security/openclaw-ai-agents-targeted-by-infostealer-malware-for-the-first-time?utm_source=openai)) The attack highlights a significant shift in malware trends, with cybercriminals developing specialized modules to target AI agent configurations. As AI assistants like OpenClaw gain popularity, they present new attack surfaces for threat actors, emphasizing the need for robust security measures and vigilant monitoring to protect sensitive data.
6 months ago
Kill Chain
Sandworm's DynoWiper Targets Poland's Energy Sector in 2025 Cyberattack
In late December 2025, Poland's energy infrastructure was targeted by a coordinated cyberattack deploying a novel data-wiping malware named DynoWiper. The attack aimed to disrupt operations across multiple renewable energy facilities, including wind and solar farms, as well as a major combined heat and power plant serving approximately 500,000 customers. ESET researchers attributed the attack to the Russian state-sponsored group Sandworm with medium confidence, noting similarities to previous incidents involving wiper malware. Fortunately, the attack was intercepted before causing significant operational disruptions. ([eset.com](https://www.eset.com/us/about/newsroom/research/eset-research-russian-sandwormapt-attacks-energy-company-poland-with-dynowiper/?utm_source=openai)) This incident underscores the evolving threat landscape where state-sponsored actors increasingly target critical infrastructure with destructive malware. The timing, coinciding with the 10th anniversary of Sandworm's 2015 attack on Ukraine's power grid, highlights the symbolic nature of such operations and the persistent risk to energy sectors globally. ([welivesecurity.com](https://www.welivesecurity.com/en/eset-research/eset-research-sandworm-cyberattack-poland-power-grid-late-2025/?utm_source=openai))
6 months ago
Kill Chain
OpenClaw 2026: Critical Supply Chain Vulnerabilities Uncovered
In early 2026, multiple critical vulnerabilities were discovered in OpenClaw, an open-source AI assistant platform. These included CVE-2026-25253, allowing remote code execution via crafted URLs, and CVE-2026-24763, enabling command injection through unsafe handling of environment variables. Exploitation of these flaws could grant attackers unauthorized access to systems, leading to data breaches and system compromises. OpenClaw has since released patches to address these issues. ([smarttech247.com](https://www.smarttech247.com/threat-intel-reports/critical-openclaw-vulnerability-allows-1-click-remote-code-execution?utm_source=openai)) The rapid adoption of AI assistant tools like OpenClaw underscores the importance of securing software supply chains. Organizations must remain vigilant, ensuring timely updates and thorough vetting of third-party extensions to mitigate emerging threats in AI ecosystems.
6 months ago
Kill Chain
BeyondTrust's Critical RCE Vulnerability: A 2026 Cybersecurity Wake-Up Call
In February 2026, BeyondTrust disclosed a critical pre-authentication remote code execution (RCE) vulnerability, CVE-2026-1731, affecting its Remote Support (RS) and Privileged Remote Access (PRA) products. This flaw allows unauthenticated attackers to execute operating system commands remotely, potentially leading to full system compromise, unauthorized access, data exfiltration, and service disruption. The vulnerability impacts Remote Support versions 25.3.1 and prior, and Privileged Remote Access versions 24.3.4 and prior. BeyondTrust applied patches for SaaS customers on February 2, 2026, but self-hosted customers must manually apply updates to mitigate the risk. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/09/beyondtrust-remote-access-vulnerability-cve-2026-1731/?utm_source=openai)) The rapid exploitation of CVE-2026-1731 underscores the increasing speed at which threat actors leverage newly disclosed vulnerabilities. Within 24 hours of a proof-of-concept exploit being released, attackers began targeting vulnerable systems. This incident highlights the critical importance of timely patch management and proactive security measures to defend against emerging threats. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/13/beyondtrust-cve-2026-1731-poc-exploit-activity/?utm_source=openai))
6 months ago
Kill Chain
Salt Typhoon 2024: A Wake-Up Call for Cybersecurity in Telecommunications
In 2024, the Chinese state-sponsored hacking group known as Salt Typhoon orchestrated a comprehensive cyber espionage campaign targeting U.S. telecommunications infrastructure. By exploiting vulnerabilities in network devices, the group infiltrated major telecom networks, gaining persistent access to sensitive data, including call logs and private communications of high-profile individuals. This breach compromised critical infrastructure and posed significant national security risks. ([en.wikipedia.org](https://en.wikipedia.org/wiki/Salt_Typhoon?utm_source=openai)) The incident underscores the evolving sophistication of state-sponsored cyber threats and highlights the urgent need for robust cybersecurity measures. Organizations must prioritize fundamental practices such as zero trust architectures, least-privilege access, and end-to-end encryption to mitigate similar threats. ([en.wikipedia.org](https://en.wikipedia.org/wiki/Salt_Typhoon?utm_source=openai))
6 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

