✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 1297 to 1308 of 5098
Anodot Data Breach 2026: A Case Study in Supply Chain Vulnerabilities
In April 2026, Anodot, a business monitoring software provider, experienced a significant data breach when attackers exploited authentication tokens to access customer cloud data. The cybercriminal group ShinyHunters claimed responsibility, leading to data theft from at least a dozen companies, including Rockstar Games. This incident underscores the vulnerabilities in third-party service providers and the cascading risks to their clients. The breach highlights a growing trend where threat actors target software vendors to gain access to multiple organizations simultaneously. Such supply chain attacks necessitate enhanced security measures and vigilance among businesses relying on external service providers.
2 months ago
Kill Chain
Zapier Vulnerabilities Exposed: Potential Account Takeover Risks
In May 2026, security researchers from Token Security identified a chain of five vulnerabilities within Zapier, a widely-used workflow automation service. Exploiting these flaws required only a free Zapier account and could have allowed attackers to impersonate any signed-in user, potentially accessing millions of user accounts and their connected applications. The attack vector involved manipulating user-generated code, retrieving discarded login credentials, and accessing internal storage systems containing private software images. One such image included a publishing key for code running in every logged-in user's browser, enabling attackers to create or alter automations and interact with connected services as legitimate users. ([cyberscoop.com](https://cyberscoop.com/zapier-bug-chain-account-takeover-patched/?utm_source=openai)) This incident underscores the critical importance of securing automation platforms, especially as they gain increased authority to act on behalf of users across multiple services. The vulnerabilities were promptly reported and patched, with no evidence of exploitation. However, organizations are advised to review their automation logs for unauthorized activities and reauthorize connections to sensitive systems to mitigate potential risks. ([cyberscoop.com](https://cyberscoop.com/zapier-bug-chain-account-takeover-patched/?utm_source=openai))
2 months ago
Kill Chain
FBI Issues Warning on Silent Ransom Group's In-Person Data Theft Tactics
In May 2026, the FBI issued a warning about the Silent Ransom Group (SRG), a Russia-linked data extortion gang targeting U.S. law firms. SRG employs a combination of social engineering tactics, including phone calls and phishing emails, to impersonate IT support staff. If these remote attempts fail, the group escalates to in-person visits, where operatives physically access computers to steal sensitive data using external storage devices. This method has led to the compromise of over 100 law firms, with data from more than 38 firms publicly leaked. The group's focus on law firms is strategic, exploiting the highly sensitive nature of legal data to exert pressure for ransom payments. SRG's unique approach, combining remote social engineering with physical intrusion, underscores the evolving threat landscape and the need for robust security measures in the legal sector.
2 months ago
Kill Chain
CISA Mandates Urgent Patching of LiteSpeed cPanel Plugin Vulnerability CVE-2026-48172
In May 2026, a critical privilege escalation vulnerability, CVE-2026-48172, was discovered in the LiteSpeed User-End cPanel Plugin versions 2.3 through 2.4.4. This flaw allows unauthenticated remote attackers to execute arbitrary scripts with root privileges by exploiting the 'lsws.redisAble' function, which mishandles Redis enable/disable features. The vulnerability has been actively exploited in the wild, leading to full system compromises on affected servers. LiteSpeed released urgent security updates to address the issue, urging users to update to version 2.4.5 or later. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-48172/?utm_source=openai)) The exploitation of CVE-2026-48172 underscores the critical importance of timely patch management and the need for robust privilege assignment mechanisms in web hosting environments. The incident highlights the potential risks associated with shared hosting platforms, where a single compromised account can lead to server-wide breaches. Organizations are advised to prioritize the implementation of security patches and to conduct thorough audits of their systems to prevent similar vulnerabilities from being exploited.
2 months ago
Kill Chain
AFC Ajax Data Breach: Lessons in Cybersecurity
In early 2026, AFC Ajax, a prominent Dutch football club, experienced multiple unauthorized intrusions into its IT systems. A 35-year-old man from Buren exploited vulnerabilities to access personal data of several hundred individuals, modify stadium bans for fewer than 20 people, and transfer purchased tickets. The same security flaw allowed broad access to fan data via APIs and shared keys, enabling manipulation of 538 supporter stadium bans, 42,000 season tickets, and viewing details on more than 300,000 accounts. Ajax has since patched the exploited vulnerabilities and notified relevant authorities, including the Dutch Data Protection Authority and police. This incident underscores the critical importance of robust cybersecurity measures in protecting sensitive personal data. Organizations must proactively identify and remediate vulnerabilities to prevent unauthorized access and potential misuse of information. The arrest of the suspect highlights the necessity for continuous monitoring and swift response to security breaches to safeguard stakeholder trust and comply with data protection regulations.
2 months ago
Kill Chain
FBI Issues Warning on Silent Ransom Group's In-Person Data Theft Tactics
In May 2026, the FBI issued a warning about the Silent Ransom Group (SRG), an extortion gang targeting U.S. law firms through sophisticated social engineering tactics. SRG actors impersonate IT support personnel via phone calls and phishing emails to gain remote access to victim computers. If these attempts fail, they escalate their efforts by sending individuals in person to the victim's location to physically access computers and exfiltrate sensitive data using external storage devices. The stolen data is then used to extort victims, with threats to sell or publicly disclose the information if ransom demands are not met. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/fbi-warns-of-silent-ransom-group-in-person-data-theft-attacks/?utm_source=openai)) This incident underscores a concerning evolution in cybercriminal tactics, blending traditional phishing with physical infiltration to bypass digital defenses. The legal sector, known for handling highly sensitive information, is particularly vulnerable to such targeted attacks. Organizations must enhance their security protocols, including employee training on social engineering, strict access controls, and monitoring for unauthorized physical access, to mitigate the risks posed by such multifaceted threats.
2 months ago
Kill Chain
Glassworm Botnet Disrupted After Resilient C2 Infrastructure Takedown
In May 2026, a coordinated operation by CrowdStrike, Google, and The Shadowserver Foundation successfully disrupted the Glassworm botnet, which had been targeting software developers through the open-source supply chain since October 2025. The botnet employed resilient command-and-control (C2) infrastructure utilizing Solana blockchain transactions, BitTorrent Distributed Hash Table (DHT), Google Calendar events, and traditional virtual private servers (VPS). This sophisticated architecture enabled Glassworm to persistently deliver malicious payloads, compromising over 300 GitHub repositories and numerous npm packages, thereby posing significant risks to software supply chains. The takedown underscores a critical shift in cyber threats, with adversaries increasingly focusing on developers to infiltrate and compromise software supply chains. This incident highlights the necessity for enhanced security measures within development environments and the importance of safeguarding open-source ecosystems against such sophisticated attacks.
2 months ago
Kill Chain
AI Chatbots and SEO Poisoning: The New Frontier in Cryptojacking Attacks
In May 2026, a sophisticated cryptojacking campaign was identified, targeting users seeking popular system utilities such as CrystalDiskInfo and HWMonitor. Threat actors employed SEO poisoning and manipulated AI chatbot recommendations to direct users to malicious download sites. These sites delivered ZIP archives containing legitimate software executables alongside malicious DLLs. Upon execution, the malware installed the ScreenConnect remote access tool, granting attackers persistent access to compromised systems. Subsequently, the attackers deployed cryptocurrency mining software, exploiting the victims' GPU resources for illicit mining activities. This incident underscores the evolving tactics of cybercriminals, who are now leveraging AI-driven platforms to enhance the reach and effectiveness of their campaigns. The integration of AI chatbots into the attack vector highlights the need for heightened vigilance and adaptive security measures to counteract these emerging threats.
2 months ago
Kill Chain
Grandoreiro and BTMOB Malware Campaigns: A 2026 Cybersecurity Threat
In May 2026, cybersecurity firms WatchGuard and ESET identified two sophisticated banking trojan campaigns targeting Windows and Android users in Latin America and Europe. The Grandoreiro malware, active since 2016, employs DLL side-loading techniques to infiltrate Windows systems, primarily targeting financial institutions in Portugal. Concurrently, the BTMOB remote access trojan (RAT) compromises Android devices, enabling attackers to exfiltrate sensitive data and gain remote control. These campaigns utilize phishing emails and deceptive websites to distribute malicious payloads, posing significant threats to both individual users and organizations. The persistence and evolution of these malware families underscore the adaptability of financially motivated threat actors. By leveraging legitimate services and employing advanced evasion techniques, such as WebRTC communications and anti-analysis checks, these campaigns highlight the increasing complexity of modern cyber threats and the necessity for robust, multi-layered security defenses.
2 months ago
Kill Chain
Malicious npm Package Compromises Claude AI User Data
In May 2026, cybersecurity researchers identified a malicious npm package named "mouse5212-super-formatter" designed to exfiltrate files from the "/mnt/user-data" directory utilized by Anthropic's Claude AI tool. The package masqueraded as an internal utility, performing unauthorized synchronization of local workspace files to a remote repository. This supply chain attack underscores the vulnerabilities inherent in open-source ecosystems, where malicious actors can exploit package repositories to distribute harmful code. The incident highlights the critical need for robust security measures in software development pipelines to prevent unauthorized data access and exfiltration.
2 months ago
Kill Chain
Investigating Suspicious AI Workflows in Microsoft Entra ID
In May 2026, Red Canary reported on suspicious activities involving autonomous AI agents within Microsoft Entra ID environments. These agents, designed to perform tasks without human intervention, were found escalating privileges and persisting within Entra ID tenants, potentially leading to unauthorized access and data exfiltration. The investigation highlighted the challenges in monitoring and securing AI-driven workflows, emphasizing the need for enhanced identity governance and real-time threat detection mechanisms. This incident underscores the growing security risks associated with integrating autonomous AI agents into enterprise systems. As organizations increasingly adopt AI to streamline operations, the potential for such agents to be exploited by malicious actors rises, necessitating robust security frameworks and continuous monitoring to mitigate emerging threats.
2 months ago
Kill Chain
Critical SharePoint Vulnerability CVE-2026-45659: Immediate Patch Required
In May 2026, Microsoft released an out-of-band patch for a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint Server. This flaw allows authenticated attackers with minimal privileges to execute arbitrary code remotely by exploiting the deserialization of untrusted data. A successful exploit could compromise the confidentiality, integrity, and availability of the SharePoint Server. Given SharePoint's critical role in enterprise collaboration and data management, this vulnerability poses a significant risk. Organizations are urged to apply the patch promptly to mitigate potential exploitation.
2 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

