Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 373 to 384 of 5924
PaperCut Zero-Day Exploitation: Securing Enterprise Print Infrastructure
In August 2026, PaperCut disclosed that threat actors were actively exploiting a zero-day vulnerability affecting all versions of PaperCut NG and MF print management software. The company confirmed multiple customer incidents and released emergency patches for versions 25 and 26. Attackers targeted internet-exposed PaperCut Application Servers, with indicators including suspicious post-exploitation activity from pc-app.exe processes and manipulated database logs. The vulnerability allowed unauthorized access to print management systems used across enterprise environments globally. This incident highlights the continued targeting of enterprise infrastructure software, particularly print management systems that often have broad network access and limited security oversight in corporate environments.
2 weeks ago
Kill Chain
Factory Implants in ZBT Routers Expose Global Supply Chain Security Crisis
In August 2026, VulnCheck disclosed two previously undocumented factory implants, SPEAKINGSTONE and DARKLANTERN, found in firmware for routers manufactured by Shenzhen Zhibotong Electronics (ZBT). Both implants, tracked as CVE-2026-74232 and CVE-2026-74233 with CVSS scores of 9.3-9.8, provide unauthenticated remote attackers with root access to affected devices. SPEAKINGSTONE operates as a surveillance implant that beacons to hardcoded command-and-control servers, while DARKLANTERN listens on UDP port 9992 with ineffective authentication. VulnCheck identified over 200 internet-facing DARKLANTERN instances across 22 countries and received beacons from 392 unique devices when they registered the backup C2 domain. This incident highlights the growing threat of supply chain attacks targeting network infrastructure, particularly as organizations increasingly rely on low-cost networking equipment from overseas manufacturers. The discovery comes amid heightened awareness of nation-state activities targeting critical infrastructure and follows similar findings in Chinese-manufactured networking equipment.
2 weeks ago
Kill Chain
Critical Flaws in Ebyte Industrial Gateways Expose Global Infrastructure to Remote Attacks
In August 2026, CISA disclosed thirteen critical vulnerabilities in the Ebyte NA111-M industrial control system device, a Chinese-manufactured gateway used worldwide in critical infrastructure. The vulnerabilities include missing authentication, cleartext transmission of sensitive data, client-side authentication bypass, and weak cryptographic implementations. With CVSS scores up to 9.8, these flaws allow complete device compromise through remote exploitation, enabling attackers to access sensitive configurations, modify device settings, intercept MQTT credentials, and disrupt industrial operations. This disclosure highlights the persistent challenge of securing legacy industrial control systems that lack fundamental security controls, as nation-state actors and cybercriminals increasingly target critical infrastructure through vulnerable ICS devices for espionage and operational disruption.
2 weeks ago
Kill Chain
Critical cPanel Domain Parking Vulnerability Enables Root Privilege Escalation
In August 2026, cPanel disclosed CVE-2026-65643, a critical vulnerability in domain parking and addon domain functionality affecting all supported versions of cPanel and WebHost Manager (WHM). The flaw allows authenticated users with domain management privileges to create arbitrary files on the server, leading to code execution as the root user and complete server compromise. cPanel released patches across multiple version branches (11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7) with automatic updates available for servers configured for daily updates. This incident highlights the growing trend of privilege escalation vulnerabilities in shared hosting control panels, which continue to be high-value targets for attackers seeking to compromise multiple websites simultaneously. The vulnerability's impact on shared hosting environments makes it particularly concerning given the widespread deployment of cPanel across the hosting industry.
2 weeks ago
Kill Chain
CISA Adds Three Actively Exploited Vulnerabilities to KEV Catalog - Immediate Action Required
In August 2026, CISA added three critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation in the wild. The additions include CVE-2023-49105 affecting ownCloud's authentication mechanisms, CVE-2026-53362 targeting Linux kernel systems, and CVE-2026-66384 exploiting JFrog Artifactory's path traversal controls. These vulnerabilities represent significant attack vectors that threat actors are actively leveraging to compromise federal and enterprise systems, with exploitation potentially leading to complete system compromise and unauthorized access to sensitive data repositories. The timing of these KEV additions coincides with increased scrutiny on federal cybersecurity following recent high-profile breaches and the implementation of BOD 26-04, which mandates risk-based vulnerability management for federal agencies. Organizations face mounting pressure to rapidly patch these specific vulnerabilities while implementing comprehensive visibility and control measures to prevent similar exploitation attempts.
2 weeks ago
Kill Chain
ServiceNow AI Platform Hit by Three CVSS 10.0 Vulnerabilities Enabling Unauthenticated Code Execution
In August 2026, ServiceNow disclosed four critical security vulnerabilities in its AI Platform, including three rated 10.0 on the CVSS scale. The flaws include CVE-2026-18885 (GraphQL code injection), CVE-2026-18886 (improper access control), and CVE-2026-74820 (SQL injection), all exploitable by unauthenticated attackers to execute arbitrary code, escalate privileges, and access sensitive data. ServiceNow deployed patches to hosted instances but left self-hosted customers to apply fixes independently, creating potential exposure windows for organizations managing their own deployments. This incident highlights the growing threat landscape surrounding AI platforms and enterprise software-as-a-service solutions. With the increasing adoption of AI-powered business applications and the recent trend of maximum-severity vulnerabilities in cloud platforms, organizations face elevated risks from sophisticated attacks targeting critical infrastructure components that handle sensitive corporate data.
2 weeks ago
Kill Chain
Critical Xiiaozet LK100W Vulnerabilities Expose Industrial Control Systems to Remote Takeover
CISA disclosed three critical vulnerabilities in the Xiiaozet LK100W industrial control device, with CVSS scores up to 9.8. The flaws include OS command injection (CVE-2026-78037), missing authentication for critical functions (CVE-2026-78239), and authentication bypass (CVE-2026-76943). These vulnerabilities allow remote attackers to execute arbitrary commands with elevated privileges, enable unauthorized administrative services, and completely compromise affected devices running firmware versions below 2.1.240. The vulnerabilities were reported by Byron Guernsey of Okachobi, LLC and affect devices deployed worldwide across critical infrastructure sectors. This incident highlights the persistent security challenges in industrial IoT devices and the expanding attack surface of critical infrastructure. With nation-state actors increasingly targeting industrial control systems and the growing convergence of IT and OT networks, these authentication and command injection flaws represent the type of fundamental security weaknesses that enable sophisticated supply chain and infrastructure attacks.
2 weeks ago
Kill Chain
Critical Password Hash Vulnerability Exposes Rockwell Automation Fleet Management Systems
Rockwell Automation's OTTO Fleet Manager versions 2.36.2 and earlier contain a critical vulnerability (CVE-2026-75112) involving insufficient computational effort in bcrypt password hashing implementation. This weakness reduces the computational cost for attackers to perform offline brute-force attacks against stored password hashes if they gain access to unencrypted system backups. The vulnerability affects industrial fleet management systems used worldwide in critical manufacturing and transportation sectors, with Rockwell Automation releasing version 2.36.3 to address the issue. This incident highlights the growing threat to industrial control systems and the critical importance of proper cryptographic implementations in operational technology environments, particularly as threat actors increasingly target industrial infrastructure with sophisticated attack techniques.
2 weeks ago
Kill Chain
Superior Campaign Exploits Browser Extension Supply Chain to Drain Crypto Wallets
Security researchers from Socket discovered a sophisticated supply chain attack targeting browser extension users, involving 19 malicious Chrome and Edge extensions harboring cryptocurrency wallet-draining capabilities. The campaign, tracked as 'Superior,' has been active since February 2024, with threat actors either creating malicious extensions or purchasing legitimate ones before injecting malicious code in subsequent updates. The extensions collectively reached over 80,000 users, with the malware establishing persistent WebSocket connections to command-and-control servers for data exfiltration and executing cryptocurrency theft modules. This incident highlights the growing threat of browser extension supply chain attacks targeting cryptocurrency assets and sensitive user credentials. The Superior campaign demonstrates how threat actors are increasingly exploiting the automatic update mechanisms of browser extensions to deliver malware at scale, representing a significant evolution in supply chain attack methodologies.
2 weeks ago
Kill Chain
Critical Security Flaws Expose Unitree Humanoid Robots to Remote Takeover
Security researcher Olivier Laflamme disclosed two critical root remote code execution vulnerabilities affecting Unitree G1 EDU humanoid robots in August 2026. CVE-2026-76639 exploits a path traversal flaw in the chat_go component to reach bashrunner, while CVE-2026-76640 enables Bluetooth Low Energy attacks that can compromise the robot's Locomotion PC without pairing. The vulnerabilities allowed attackers to gain root access through network-adjacent attacks or proximity-based Bluetooth exploitation, with Unitree partially addressing cloud authorization issues in July 2026 but leaving firmware patches unconfirmed. This incident highlights the growing security risks in autonomous robotics and IoT devices as they become more prevalent in industrial and consumer environments. The combination of wireless attack vectors and critical system access demonstrates the urgent need for robust security frameworks in next-generation robotic platforms.
2 weeks ago
Kill Chain
Inside Malware Development: 2024 Compiler Statistics Reveal Threat Actor Preferences
In August 2024, cybersecurity researcher Xavier Mertens conducted comprehensive analysis of malicious PE (Portable Executable) files using data from Malware Bazaar, processing over 23.5 million files spanning from 2020 to 2024. The research revealed that 32-bit malware remains dominant at 82% of samples, with Microsoft development tools being the most commonly used compiler toolchain at 31.3% of identified samples. The analysis utilized Rich Header examination, .NET CLR metadata parsing, and heuristic string scanning to fingerprint compiler signatures, providing valuable intelligence for threat attribution and malware clustering. This research highlights the continued evolution of malware development practices and the persistent preference for legacy architectures among threat actors, offering crucial insights for security teams developing detection signatures and attribution frameworks.
2 weeks ago
Kill Chain
The AI Revolution in Cyber Reconnaissance: Why Everyone Is Now a Target
Artificial intelligence is fundamentally transforming the cybercrime landscape by democratizing sophisticated Open Source Intelligence (OSINT) reconnaissance capabilities. Previously, comprehensive target profiling required specialized skills and significant time investment, limiting such attacks to high-value targets. AI-powered tools now enable threat actors with minimal technical expertise to rapidly collect, correlate, and weaponize publicly available information from social media, professional networks, and web sources at machine speed, dramatically lowering the barrier to entry for personalized social engineering attacks and fraud schemes. This capability shift represents a critical inflection point in cyber threat evolution, as AI enables scalable personalization of attacks previously reserved for advanced persistent threat groups. The convergence of readily available AI tools with abundant personal data creates unprecedented risk exposure for individuals and organizations alike.
2 weeks ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

