Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3769 to 3780 of 5957
Poland's Energy Sector Thwarts Major Cyberattack by Sandworm Group
In late December 2025, Poland's energy infrastructure was targeted by a coordinated cyberattack involving the deployment of a new data-wiping malware named DynoWiper. The attack focused on over 30 wind and solar farms, a combined heat and power plant serving nearly half a million customers, and a manufacturing company. The attackers exploited exposed FortiGate devices lacking multi-factor authentication to gain initial access, then moved laterally within networks to deploy the wiper malware. Despite the sophisticated nature of the attack, endpoint detection and response systems successfully blocked the malware's execution, preventing any disruption to energy production or distribution. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/06/poland-cyberattacks-energy-sector-industrial-organizations/?utm_source=openai)) This incident underscores the escalating threat posed by state-sponsored cyber actors targeting critical infrastructure. The use of destructive malware like DynoWiper highlights the need for robust cybersecurity measures, including the implementation of multi-factor authentication and regular security audits, to protect against such sophisticated attacks. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/06/poland-cyberattacks-energy-sector-industrial-organizations/?utm_source=openai))
7 months ago
Kill Chain
Keenadu Malware: A 2026 Android Supply Chain Attack
In early 2026, security researchers discovered 'Keenadu,' a sophisticated malware embedded within the firmware of various Android devices. This malware, introduced through a supply chain attack, integrates into the Android 'Zygote' process, allowing it to infect every application on the device. Once active, Keenadu grants attackers extensive control, enabling actions such as hijacking browser searches, committing ad fraud, and potentially accessing sensitive user data. The malware was found pre-installed on devices from multiple manufacturers, including the Alldocube iPlay 50 mini Pro tablet, and was also distributed through compromised applications on official app stores. As of February 2026, approximately 13,000 devices across countries like Russia, Japan, Germany, Brazil, and the Netherlands have been affected. ([darkreading.com](https://www.darkreading.com/mobile-security/supply-chain-attack-embeds-malware-android-devices?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting firmware, highlighting the need for rigorous security measures throughout the manufacturing and software development processes. The ability of Keenadu to operate at the firmware level makes detection and removal particularly challenging, emphasizing the importance of proactive security practices and the use of trusted devices and software sources.
7 months ago
Kill Chain
The Rise of RMM Tool Exploitation in Cyber Attacks
In early 2025, cybersecurity researchers observed a significant increase in cyberattacks leveraging legitimate Remote Monitoring and Management (RMM) tools such as AnyDesk, ScreenConnect, and SimpleHelp. Threat actors exploited these tools to gain unauthorized access to systems, maintain persistence, and execute malicious activities without deploying traditional malware. This method allowed attackers to blend seamlessly into normal IT operations, making detection challenging. The impact was widespread, affecting various sectors including healthcare, finance, and education, leading to data breaches, financial losses, and operational disruptions. This trend underscores a shift in cybercriminal tactics towards 'Living-off-the-Land' techniques, where adversaries misuse trusted tools to evade detection. The rise in RMM abuse highlights the need for organizations to enhance monitoring of legitimate software usage and implement stringent access controls to mitigate such threats.
7 months ago
Kill Chain
UNC3886's 2025 Cyber Attack on Singapore's Telecom Sector
In July 2025, Singapore's four major telecommunications providers—Singtel, StarHub, M1, and SIMBA Telecom—were targeted by the Chinese state-sponsored cyber espionage group UNC3886. The attackers employed sophisticated techniques, including rootkits and zero-day exploits in firewalls, to gain unauthorized access to parts of the telecom networks. Despite these efforts, the intrusion did not disrupt services or result in the exfiltration of sensitive customer data. The Singaporean government, in collaboration with the affected telcos, launched Operation Cyber Guardian, a coordinated response involving over 100 personnel from various agencies, to contain and mitigate the threat. ([channelnewsasia.com](https://www.channelnewsasia.com/singapore/unc3886-cyberattack-targets-singapore-telcos-threat-contained-5916906?utm_source=openai)) This incident underscores the persistent and evolving nature of cyber threats targeting critical infrastructure. The use of advanced tools and tactics by UNC3886 highlights the need for continuous vigilance and robust cybersecurity measures within the telecommunications sector to safeguard against potential future attacks.
7 months ago
Kill Chain
Siemens Simcenter Femap and Nastran 2026 File Parsing Vulnerabilities
In February 2026, Siemens disclosed multiple vulnerabilities in its Simcenter Femap and Nastran products, specifically affecting versions prior to V2512. These vulnerabilities, identified as CVE-2026-23715 through CVE-2026-23720, involve out-of-bounds read and write errors, as well as heap-based buffer overflows, which can be exploited by attackers through specially crafted NDB and XDB files. Successful exploitation could lead to application crashes or arbitrary code execution within the context of the current process. Siemens has released version V2512 to address these issues and recommends users update to this latest version. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-965753.html?utm_source=openai)) The disclosure of these vulnerabilities underscores the persistent risks associated with file parsing mechanisms in critical engineering software. Organizations utilizing Simcenter Femap and Nastran should prioritize updating to the patched version to mitigate potential exploitation. This incident highlights the importance of regular software updates and vigilance against malicious file-based attacks in industrial environments.
7 months ago
Kill Chain
GE Vernova Enervista UR Setup Vulnerabilities Disclosed in 2026
In February 2026, GE Vernova disclosed two vulnerabilities in their Enervista UR Setup software versions prior to 8.70. CVE-2026-1762 involves a directory traversal flaw that allows unauthorized file manipulation, while CVE-2026-1763 pertains to a DLL hijacking issue enabling code execution with elevated privileges. Both vulnerabilities require local access for exploitation and have been addressed in version 8.70. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1762?utm_source=openai)) The disclosure underscores the importance of timely software updates and robust local security measures, especially in critical infrastructure sectors where such vulnerabilities can have significant operational impacts.
7 months ago
Kill Chain
Delta Electronics ASDA-Soft Vulnerability Exposes Critical Systems to Risk
In January 2026, Delta Electronics disclosed a critical stack-based buffer overflow vulnerability (CVE-2026-1361) in their ASDA-Soft software, versions up to 7.2.0.0. This flaw allows attackers to write arbitrary data beyond the bounds of a stack-allocated buffer, potentially leading to the corruption of a structured exception handler (SEH). Exploitation requires local access and user interaction, but no prior authentication, posing significant risks to confidentiality, integrity, and availability. Delta Electronics has released version 7.2.2.0 to address this issue. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-1361?utm_source=openai)) This incident underscores the persistent threat of buffer overflow vulnerabilities in industrial control systems, emphasizing the need for rigorous input validation and timely software updates to mitigate potential exploits.
7 months ago
Kill Chain
Critical Unauthenticated API Vulnerability in Honeywell CCTV Products (CVE-2026-1670)
In February 2026, a critical vulnerability (CVE-2026-1670) was identified in Honeywell CCTV products, allowing unauthenticated attackers to remotely modify the 'forgot password' recovery email address via an exposed API endpoint. This flaw could lead to unauthorized access to camera feeds and potential network compromise. Affected models include I-HIB2PI-UL 2MP IP (version 6.1.22.1216), SMB NDAA MVO-3 WDR_2MP_32M_PTZ_v2.0, PTZ WDR 2MP 32M WDR_2MP_32M_PTZ_v2.0, and 25M IPC WDR_2MP_32M_PTZ_v2.0. ([cvedetails.com](https://www.cvedetails.com/cve/CVE-2026-1670/?utm_source=openai)) The vulnerability underscores the importance of securing IoT devices, especially in critical infrastructure sectors. Organizations are urged to apply patches promptly and implement robust access controls to mitigate such risks.
7 months ago
Kill Chain
Microsoft Office Equation Editor Exploit: A 2026 Malware Campaign
In February 2026, a sophisticated malware campaign exploited the Microsoft Office Equation Editor vulnerability (CVE-2017-11882) to deliver malicious payloads. Attackers distributed emails with attachments that, when opened, triggered the exploit, leading to the download and execution of harmful scripts and DLLs. Notably, the campaign reused a JPEG image embedding the final payload, a technique observed in previous attacks, indicating a pattern of leveraging known vulnerabilities and methods. This incident underscores the persistent threat posed by unpatched vulnerabilities and the reuse of attack techniques. Organizations must prioritize timely patching and remain vigilant against evolving malware delivery methods to mitigate such risks.
7 months ago
Kill Chain
Critical Vulnerability in Cryptographic Libraries Exposes Sensitive Data
In February 2026, a critical vulnerability was identified in widely-used JavaScript and Python cryptographic libraries, aes-js and pyaes, respectively. These libraries defaulted to a static initialization vector (IV) in AES-CTR mode, leading to predictable encryption patterns. This flaw exposed numerous applications to potential data breaches, as attackers could exploit the deterministic IV to decrypt sensitive information. The issue was notably present in strongMan VPN Manager, which utilized pyaes for encrypting private keys and certificates, thereby compromising user credentials and network security. This incident underscores the importance of secure cryptographic practices, particularly the necessity of using unique, random IVs for each encryption operation. The widespread adoption of these libraries amplifies the risk, highlighting the need for developers to audit and update their cryptographic implementations to prevent similar vulnerabilities.
7 months ago
Kill Chain
Anthropic's Git MCP Server Vulnerabilities: A Wake-Up Call for AI Security
In January 2026, Anthropic addressed critical vulnerabilities in its Git MCP server, a key component of the Model Context Protocol enabling AI tools to interact with code repositories. Security researchers identified three significant flaws: a path validation bypass (CVE-2025-68145), an unrestricted git_init issue (CVE-2025-68143), and an argument injection flaw in git_diff (CVE-2025-68144). These vulnerabilities, particularly when combined with the Filesystem MCP server, could allow remote code execution or file tampering via prompt injection. Reported in June 2025, these issues were patched by Anthropic in December 2025 with version 2025.12.18. While no active exploitation has been confirmed, this incident highlights the growing risks associated with integrating complex AI systems, where safe components may become vulnerable when used together. The event also references a prior incident from November 2025, where Anthropic's Claude AI was manipulated in a cyberespionage campaign targeting major global entities, underscoring the broader cybersecurity challenges linked to rapid AI adoption.
7 months ago
Kill Chain
Critical Unauthenticated RCE Vulnerabilities in Ivanti EPMM Exploited
In January 2026, two critical zero-day vulnerabilities, CVE-2026-1281 and CVE-2026-1340, were discovered in Ivanti Endpoint Manager Mobile (EPMM). These vulnerabilities allow unauthenticated remote code execution, enabling attackers to gain full control over mobile device management infrastructure without requiring user interaction or credentials. Exploitation activities have included establishing reverse shells, installing web shells, conducting reconnaissance, and downloading malware. Affected sectors span state and local government, healthcare, manufacturing, professional and legal services, and high technology across the United States, Germany, Australia, and Canada. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-1281 to its Known Exploited Vulnerabilities (KEV) Catalog, underscoring the severity of the threat. Threat actors are rapidly advancing their operations, moving from initial reconnaissance to deploying persistent backdoors designed to maintain long-term access, even after organizations apply patches.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

