Two new incidents on shift — SolarWinds and the MOVEit breach (v0.3.2)
August 11, 2026
Cyber Magen just got two new nights on shift, both drawn straight from real breaches — and the adversary itself got less predictable while nobody was looking.
OPERATION SOLAR STORM — the SolarWinds compromise
Based on the 2020 SolarWinds / SUNBURST supply-chain attack (APT29). The enemy doesn't break in through the front door — they arrive already inside a trusted update your own tools installed. You're not hunting an intruder; you're re-learning which of your own systems to trust. Hold the source repository, watch the monitoring hub, and don't let evidence lose to habit.
OPERATION SILENT TRANSFER — the MOVEit / Cl0p breach
Based on the 2023 Cl0p mass exploitation of MOVEit Transfer (CVE-2023-34362). No ransomware note, no encryption — just a zero-day in a file-transfer appliance, a quiet web shell, and a database getting drained by the thousand. The impact is the theft. Defend forward, or find out how much was already gone before the alert fired.
Both scenarios carry MITRE ATT&CK technique references tied to the real campaigns they're built from, same as the rest of the roster.
Also in this build
- Phase-length jitter — the adversary's kill-chain timing now varies run to run (ordering stays intact, pacing doesn't). Replaying a scenario should feel less like memorizing a script and more like commanding against an opponent.
- Four scenarios now live in the roster: Night Shift, Kill Switch, Solar Storm, Silent Transfer — from hospital ransomware to nation-state supply-chain compromise to mass-exploitation data theft.
What's next
An objective-driven Red that picks its own targets instead of following a fixed script, then an alert-and-triage layer on top of the kill chain. The scenario library keeps growing — if there's a real incident you want to see modeled, join the wishlist and say so when we email.