Topic

Incident Analysis

Post-incident writeups of real breaches and actively exploited vulnerabilities, traced past initial access to the data the attacker could actually read.

23 posts

Incident analysis is the structured review of a real breach or exploited vulnerability to determine which control failed, what the attacker reached, and which architecture would have contained it. It works backward from confirmed facts in vendor advisories, regulatory filings, and exploitation catalogs. The output is an architectural conclusion, not a timeline.

Reviews stop too early. Most writeups end at initial access, name the unpatched appliance or the stolen session, and recommend faster patching, which leaves the more useful question unasked: once the attacker was inside, why was the data readable? Edge devices, federation servers, and endpoint agents keep appearing as entry points precisely because they sit above the data and inherit its trust.

Posts under this hub analyze vulnerabilities listed in the CISA Known Exploited Vulnerabilities catalog across VPN concentrators, file transfer appliances, collaboration platforms, browsers, and network controllers, alongside breach writeups from healthcare, education, and AI platform providers. Each traces the blast radius to the data layer and asks what fail-closed enforcement would have changed. Disclosure obligations get the same treatment.

Frequently asked questions

What is the CISA Known Exploited Vulnerabilities catalog?

The CISA Known Exploited Vulnerabilities catalog is a public list of vulnerabilities with confirmed active exploitation. Federal civilian agencies must remediate entries by assigned due dates under Binding Operational Directive 22-01, and other organizations use it to prioritize ahead of severity scores. Inclusion means exploitation is observed in the wild, a far stronger signal than a CVSS rating alone.

When does the SEC cybersecurity disclosure clock start?

The four business day clock starts when a registrant determines an incident is material, not when it is discovered. The materiality determination itself must be made without unreasonable delay, so a company cannot postpone that decision to delay the filing. The disclosure covers the nature, scope, and timing of the incident plus its material impact on operations and financial condition.

Why do breaches keep succeeding when identity controls hold?

Identity answers who authenticated, not what the data permits. Federation token forgery, session theft, and unauthenticated application flaws all produce sessions the identity layer considers valid, and everything downstream trusts them. When authorization is evaluated once at login and data sits in plaintext behind it, a valid session becomes a full read. Object-level policy re-decides on every access.

What should a post-incident review produce?

A confirmed sequence of events, an evidence-backed blast radius naming which data objects were reachable and readable, the specific control that failed and why, and one architectural change that would have narrowed the outcome. Vague remediation such as improved monitoring signals an incomplete review. Name the enforcement boundary that was missing and where it belongs.

Reading on incident analysis

Lattix branded cover for Ransomware Doesn't Work on Policy-Bound Data. /10 section number, double-extortion failure metadata, IBM Plex Mono on dark grid background, surgical yellow accent.

Ransomware Doesn't Work on Policy-Bound Data

August 19, 2026

Modern ransomware exfiltrates before it encrypts and demands payment under the threat of public release. Neither lever works when the data is already encrypted and policy-bound at the object layer.

Read More →
Lattix branded cover for The Harvest-Now-Decrypt-Later Threat Is Already Here. /12 section number, capture-now decrypt-later timeline metadata, IBM Plex Mono on dark grid background, surgical yellow accent.

The Harvest-Now-Decrypt-Later Threat Is Already Here

July 30, 2026

Adversaries do not need a working quantum computer today to compromise tomorrow's cryptography. They need storage, patience, and a sufficiently long-lived secret. The act that matters has already happened by the time the cryptanalysis is feasible.

Read More →
Lattix branded cover for the SonicWall SMA1000 CVE-2026-15409 and CVE-2026-15410 analysis. Dark grid background, surgical yellow accent, IBM Plex Mono typography, July 14 2026 KEV addition and July 17 2026 federal deadline, CVSS 10.0 and CVSS 7.2 reference box, and a compromise-path strip where the object policy enforcement point is highlighted as the control that survives a gateway takeover.

SonicWall SMA1000 Zero-Days Chain to Root. The Gateway Is Not the Data Boundary.

July 21, 2026

CISA added SonicWall SMA1000 CVE-2026-15409 and CVE-2026-15410 to KEV on July 14, 2026. Chained, an unauthenticated SSRF and a root code injection hand an attacker the remote-access gateway. Object-level enforcement is what still refuses the reach it grants.

Read More →
Lattix branded cover for AD FS CVE-2026-56155 Forges Federation Tokens. Dark grid background, surgical yellow accent, IBM Plex Mono typography, July 14 2026 KEV addition and July 28 2026 federal deadline, CVSS 7.8 and CWE-1220 reference row, and a token-issuance strip where the object policy enforcement point is highlighted as the control that survives forgery.

AD FS CVE-2026-56155 Forges Federation Tokens. Identity Is Not the Data Boundary.

July 20, 2026

CISA added AD FS CVE-2026-56155 to KEV on July 14, 2026 with a July 28 federal deadline. The flaw hands an attacker the token-signing keys, and a forged federation token replays against every connected application. Object-level enforcement is what still refuses it.

Read More →
Lattix branded cover for Check Point VPN CVE-2026-50751. /42 section number, June 2026 KEV disclosure date, CVSS 9.3 authentication-bypass statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the object-level policy enforcement point in a VPN-to-data flow strip.

Check Point VPN CVE-2026-50751 Is in KEV. The Concentrator Is Not the Trust Boundary.

July 6, 2026

Check Point VPN CVE-2026-50751 is an actively exploited IKEv1 authentication bypass that grants an unauthenticated attacker a valid VPN session. CISA added it to KEV with a June 11, 2026 federal deadline. A VPN session is network reachability, not authority over data.

Read More →
Lattix branded cover for PTC Windchill CVE-2026-12569. /43 section number, June 2026 KEV disclosure date, CVSS 9.3 unauthenticated-RCE statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the object-level policy enforcement point in a repository-to-data flow strip.

PTC Windchill CVE-2026-12569 Is in KEV. The PLM Repository Is the Trust Boundary.

July 6, 2026

PTC Windchill CVE-2026-12569 is an actively exploited, unauthenticated RCE that lets attackers drop web shells on the system holding a manufacturer's engineering IP. CISA added it to KEV with a June 28, 2026 deadline. When the repository is the trust boundary, the data has none.

Read More →
Lattix branded cover for HHS HC3 Q2 2026 Threat Brief. /32 section number, Q2 2026 threat brief publish window, healthcare-targeted intrusion count statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the architectural response pillar in a threat actor strip.

HHS HC3 Q2 2026 Threat Brief: Healthcare Data Is the Target. The Response Is Architectural.

July 2, 2026

HHS HC3 quarterly threat briefs catalog the threat actor groups and tactics targeting healthcare data through Q2 2026. The pattern across Medtronic, Change Healthcare aftermath, and recent intrusions is consistent. Healthcare data is high-value and weakly bound to enforcement.

Read More →
Lattix branded cover for the Oracle PeopleSoft CVE-2026-35273 analysis. /41 section number, IBM Plex Mono on a dark grid background, the unauthenticated Environment Management flaw named, a CVSS 9.8 statistic, a 68 percent higher-education victim share, and an exploit-to-data strip with the object-level enforcement point highlighted in surgical yellow.

Oracle PeopleSoft CVE-2026-35273: Unauthenticated Access Reaches Data the Identity Layer Never Sees

July 2, 2026

ShinyHunters exploited an unauthenticated PeopleSoft flaw as a zero-day for two weeks before Oracle's advisory. Universities took 68 percent of the hits. No credential was stolen and none was needed. The data carried no policy of its own.

Read More →
Lattix branded cover for the mid-year 2026 breach pattern analysis. /27 section number, IBM Plex Mono on dark grid background, the identity-to-data pivot named across six 2026 incidents, a 4.67 million dollar credential-breach statistic, and a pivot strip with the data-layer enforcement point highlighted in surgical yellow.

The Mid-Year 2026 Breach Pattern: Identity Holds, Data Does Not

June 30, 2026

Six 2026 breaches, from Mercor to the Canvas and Medtronic disclosures, trace one pattern. Identity and network controls evaluate correctly. The compromised principal reads data the credential is authorized to reach. The data carries no policy of its own.

Read More →
Lattix branded cover for Chromium V8 CVE-2026-11645. /39 section number, June 2026 KEV disclosure date, CVSS 8.8 out-of-bounds renderer statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the object-level PEP in a browser-to-data flow strip.

Chromium V8 CVE-2026-11645 Is in KEV. The Browser Is an Endpoint Data Surface.

June 22, 2026

Chromium V8 CVE-2026-11645 is an actively exploited out-of-bounds flaw giving an attacker read and write access inside the renderer. CISA added it to KEV with a June 23, 2026 federal deadline. The browser is where enterprise data is read, and the renderer holds the cleartext.

Read More →
Lattix branded cover for Arista EOS CVE-2026-7473. /40 section number, June 2026 KEV disclosure date, CVSS 6.9 no-patch statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the object-level PEP in a network-fabric-to-data flow strip.

Arista EOS CVE-2026-7473 Forwards Untrusted Tunnel Traffic. The Fabric Is Not the Boundary.

June 19, 2026

Arista EOS CVE-2026-7473 is an actively exploited tunnel decapsulation flaw that makes a switch forward attacker traffic into isolated segments. CISA added it to KEV with a June 23, 2026 federal deadline, and Arista will not patch it.

Read More →
Lattix branded cover for SolarWinds Serv-U CVE-2026-28318. /38 section number, June 2026 KEV disclosure date, 12,000+ exposed-hosts statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the object-level PEP in a transfer-to-data flow strip.

SolarWinds Serv-U CVE-2026-28318 Is in KEV. The File Transfer Appliance Is the Trust Boundary.

June 13, 2026

SolarWinds Serv-U CVE-2026-28318 is an actively exploited, unauthenticated flaw that crashes the file transfer service. CISA added it to KEV with a June 19, 2026 federal deadline. Managed file transfer keeps proving the appliance is a transport, not a trust boundary.

Read More →
Lattix branded cover for Microsoft Defender CVE-2026-41091 Escalates to SYSTEM. /37 section number, May 2026 zero-day disclosure date, CVSS 7.8 local-to-SYSTEM statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the data-layer PEP in a host-to-data flow strip.

Microsoft Defender CVE-2026-41091 Escalates to SYSTEM. The Endpoint Control Is the Attack Surface.

June 11, 2026

Microsoft Defender CVE-2026-41091 is an actively exploited link-following flaw that elevates a local user to SYSTEM. CISA added it to KEV with a June 3, 2026 federal deadline. When the security tool is the escalation path, object-level enforcement is what survives.

Read More →
Lattix branded cover for Cisco SD-WAN CVE-2026-20182 Bypasses the Network Controller. /24 section number, May 2026 zero-day disclosure date, unauthenticated admin bypass statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the data-layer boundary in a controller-to-data flow strip.

Cisco SD-WAN CVE-2026-20182 Bypasses the Network Controller. The Data Layer Holds.

June 2, 2026

Cisco confirmed CVE-2026-20182 against Catalyst SD-WAN Controller as exploited in the wild in May 2026. Unauthenticated attackers gain admin on affected systems. CISA added the flaw to KEV. SD-WAN is the East-West choke point that perimeter zero trust depends on. Data-level enforcement does not.

Read More →
Lattix branded cover for Langflow CVE-2025-34291 Hands Over the AI Orchestrator's Credential Stash. /25 section number, May 21 2026 KEV addition and June 4 2026 FCEB deadline, CVSS 9.4 statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the policy enforcement point in an LLM provider credential release flow strip.

Langflow CVE-2025-34291 Hands Over the AI Orchestrator's Credential Stash

June 2, 2026

CISA added Langflow CVE-2025-34291 to KEV on May 21, 2026 with a June 4 FCEB deadline. The CVSS 9.4 flaw turns a visit to a malicious page into account takeover plus RCE on a Langflow workspace. The harvested material is the operator's full AI credential stash.

Read More →
Lattix branded cover for The Linux Copy Fail CVE-2026-31431 Reaches Root. /23 section number, May 1 2026 KEV add date, 732-byte exploit statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the data-layer boundary in a kernel-to-data flow strip.

The Linux Copy Fail CVE-2026-31431 Reaches Root. Object-Level Enforcement Reaches the Data.

May 28, 2026

CVE-2026-31431 escalates an unprivileged Linux user to root with a 732-byte Python script. CISA added it to KEV May 1 with a federal remediation deadline of May 15. Patching closes the vector. Object-level cryptographic enforcement closes the consequence.

Read More →
Lattix branded cover for The Nx Console Supply Chain Attack Is a Credentials-as-Data Story. /22 section number, May 18 2026 incident timestamp, 3,800 GitHub internal repositories statistic, IBM Plex Mono on dark grid background, surgical yellow accent on the policy enforcement point in a credential release flow strip.

The Nx Console Supply Chain Attack Is a Credentials-as-Data Story

May 22, 2026

On May 18, 2026, a compromised Nx Console VS Code extension exfiltrated credentials from developer workstations. By May 19, GitHub disclosed that 3,800 internal repositories had been exfiltrated as a result. The pivot was static credentials. The architectural answer is to treat credentials as policy-bound data.

Read More →
Lattix branded cover for The SEC's Four-Day Clock Starts on Materiality, Not Discovery. /17 section number, four business days statistic and Item 1.05 metadata, IBM Plex Mono on dark grid background, surgical yellow accent on the materiality determination node in a decision flow strip.

The SEC's Four-Day Clock Starts on Materiality, Not Discovery

May 15, 2026

Form 8-K Item 1.05 starts the four-business-day clock on the materiality determination, not on incident discovery. The clock is shorter than most response playbooks assume. The architecture that shortens the materiality analysis is data-centric.

Read More →
Lattix branded cover for Vercel + Context.ai: OAuth Is the Quiet Supply Chain. /07 section number, OAuth supply chain metadata, IBM Plex Mono on dark grid background.

Vercel + Context.ai: OAuth Is the Quiet Supply Chain

May 13, 2026

Vercel's April 19, 2026 security bulletin documented an OAuth compromise that exfiltrated environment variables through an authorized AI integration. Identity, network, and device controls all evaluated correctly. The data did not enforce its own policy.

Read More →
Lattix branded cover for The Medtronic Breach Is the Canvas Playbook Run Against a Medical Device Maker. /12 section number, 9M records statistic, ShinyHunters extortion timeline, IBM Plex Mono on dark grid background, surgical yellow accent.

The Medtronic Breach Is the Canvas Playbook Run Against a Medical Device Maker

May 12, 2026

Medtronic confirmed a ShinyHunters extortion event in an SEC 8-K on April 24, 2026. Nine million records claimed, the leak site listing pulled before the deadline. The architectural lesson is the same one the Canvas breach already wrote: containment closes the access path, not the copies that already left.

Read More →
Lattix branded cover for the Canvas breach analysis. /05 section number, IBM Plex Mono on dark grid background, surgical yellow accent, 275M record stat panel and FERPA enforcement gap reference.

The Canvas Breach Is a Data Enforcement Story, Not a Containment Story

May 8, 2026

ShinyHunters claimed 275 million records from Instructure across 9,000 institutions. Containment closed the access path. The records had already crossed the policy boundary. The disclosure surface is what FERPA, schools, and downstream subjects have to deal with now.

Read More →
Diagram showing the disclosure surface around a patched SharePoint instance: the patch closes the network vector while the pre-patch read and write events remain cryptographically unaccounted for without data-layer enforcement.

SharePoint CVE-2026-32201 Is in KEV. The Disclosure Surface Is the Real Issue.

April 22, 2026

CISA added the April SharePoint spoofing zero-day to KEV on April 14 with an FCEB remediation deadline of April 28. Patching closes the vector. It does not answer what an attacker read, modified, or signed before the update landed.

Read More →
Abstract Lattix diagram of a compromised runtime pipeline feeding downstream data stores, with policy-bound data objects remaining sealed.

The Mercor Breach Is a Data-Centric Security Story. Not an Identity One.

April 17, 2026

A malicious LiteLLM package pushed March 27, 2026 cascaded into a four-terabyte exfiltration from an AI training-data vendor whose customer list reads like the frontier lab leaderboard. Identity controls were present. They were not the control that mattered.

Read More →