✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 1753 to 1764 of 5135
Rising Threat: Amazon SES Phishing Abuse in 2026
In May 2026, cybersecurity researchers identified a significant increase in phishing campaigns exploiting Amazon Simple Email Service (SES). Attackers leveraged exposed AWS Identity and Access Management (IAM) access keys, often found in public GitHub repositories, .ENV files, Docker images, and publicly accessible S3 buckets, to send convincing phishing emails that bypass standard security filters. These emails, appearing to originate from trusted sources, included fake document-signing notifications and sophisticated business email compromise (BEC) attacks, leading to unauthorized access and financial losses. This trend underscores the critical need for organizations to implement stringent security measures, such as enforcing least-privilege IAM policies, enabling multi-factor authentication, regularly rotating access keys, and applying IP-based access restrictions. The rise in such attacks highlights the evolving tactics of cybercriminals and the importance of proactive defense strategies to protect sensitive information and maintain trust.
3 months ago
Kill Chain
Progress Software Patches Critical MOVEit Automation Vulnerabilities
In April 2026, Progress Software identified and patched two critical vulnerabilities in MOVEit Automation, a managed file transfer solution widely used in enterprise environments. The most severe, CVE-2026-4670, is an authentication bypass flaw with a CVSS score of 9.8, allowing unauthenticated remote attackers to gain unauthorized access. The second, CVE-2026-5174, involves improper input validation that could lead to privilege escalation. Exploitation of these vulnerabilities could result in unauthorized access, administrative control, and potential data exposure. ([thehackernews.com](https://thehackernews.com/2026/05/progress-patches-critical-moveit.html?utm_source=openai)) This incident underscores the persistent threat posed by vulnerabilities in widely deployed enterprise software. Organizations are reminded of the importance of timely patch management and vigilant monitoring to mitigate risks associated with such critical flaws.
3 months ago
Kill Chain
VENOMOUS#HELPER Phishing Campaign: A Wake-Up Call for RMM Tool Security
Since April 2025, a sophisticated phishing campaign named VENOMOUS#HELPER has targeted over 80 organizations, primarily in the U.S. Attackers impersonated the U.S. Social Security Administration, sending emails that directed recipients to download malicious executables disguised as official documents. These executables installed legitimate Remote Monitoring and Management (RMM) tools—SimpleHelp and ScreenConnect—on victims' systems, granting attackers persistent remote access. The use of these legitimate tools allowed the attackers to evade detection by standard security measures. ([thehackernews.com](https://thehackernews.com/2026/05/phishing-campaign-hits-80-orgs-using.html?utm_source=openai)) This incident underscores a growing trend where cybercriminals exploit trusted software to maintain undetected access within networks. The dual deployment of RMM tools highlights the need for organizations to scrutinize the use of such software and implement robust monitoring to detect unauthorized installations. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/rmm-tools-stealthy-phishing-campaign?utm_source=openai))
3 months ago
Kill Chain
Exploitation of Amazon SES in Phishing and BEC Attacks: A 2026 Analysis
In early 2026, cybercriminals exploited Amazon Simple Email Service (SES) to conduct sophisticated phishing and Business Email Compromise (BEC) attacks. By leveraging exposed AWS Identity and Access Management (IAM) access keys, attackers sent large volumes of phishing emails that passed standard authentication checks, such as SPF, DKIM, and DMARC. These emails often impersonated trusted services like DocuSign, leading recipients to malicious sites designed to harvest sensitive information. The abuse of Amazon's legitimate infrastructure allowed these phishing campaigns to evade traditional email security measures, resulting in significant data breaches and financial losses for targeted organizations. This incident underscores a growing trend where attackers exploit trusted cloud services to enhance the credibility and effectiveness of their phishing campaigns. The increasing sophistication of such attacks highlights the urgent need for organizations to implement robust security measures, including strict IAM policies, regular key rotation, and comprehensive employee training to recognize and respond to phishing attempts.
3 months ago
Kill Chain
Silver Fox's Tax-Themed Phishing Campaign Unveils New ABCDoor Malware
In December 2025, the China-backed threat group Silver Fox initiated a phishing campaign targeting organizations in India and Russia. The attackers sent emails impersonating tax authorities, prompting recipients to download archives purportedly containing lists of tax violations. These archives contained a modified Rust-based loader that deployed the known ValleyRAT backdoor and a previously undocumented Python-based backdoor named ABCDoor. Between early January and early February 2026, over 1,600 such malicious emails were recorded, affecting sectors including industrial, consulting, retail, and transportation. ([darkreading.com](https://www.darkreading.com/endpoint-security/silver-fox-tax-themed-attacks-india-russia?utm_source=openai)) This incident underscores the evolving tactics of APT groups, particularly their use of sophisticated social engineering techniques and novel malware to infiltrate organizations. The discovery of ABCDoor highlights the continuous development of custom tools by threat actors to evade detection and maintain persistence. ([darkreading.com](https://www.darkreading.com/endpoint-security/silver-fox-tax-themed-attacks-india-russia?utm_source=openai))
3 months ago
Kill Chain
Global Crackdown Dismantles Major Crypto Scam Network
In April 2026, a coordinated international operation led by Dubai Police, in collaboration with the U.S. FBI and the Chinese Ministry of Public Security, resulted in the arrest of at least 276 individuals and the dismantling of nine scam centers involved in cryptocurrency investment fraud targeting American citizens. The operation uncovered that these centers employed 'pig butchering' schemes, where scammers built trust with victims through fake relationships before persuading them to invest in fraudulent cryptocurrency platforms, leading to millions of dollars in losses. Notably, the scams were linked to human trafficking, with individuals coerced into operating the fraudulent schemes under exploitative conditions. ([justice.gov](https://www.justice.gov/opa/pr/coordinated-takedown-scam-centers-leads-least-276-arrests-alleged-managers-and-recruiters?utm_source=openai)) This incident underscores the growing sophistication and international reach of cryptocurrency fraud schemes, highlighting the urgent need for enhanced global cooperation in combating such cybercrimes. The successful operation demonstrates the effectiveness of cross-border law enforcement collaboration in addressing complex financial frauds that exploit emerging technologies.
3 months ago
Kill Chain
Critical cPanel Vulnerability (CVE-2026-41940) Exploited in Government and MSP Networks
In late April 2026, a critical authentication bypass vulnerability (CVE-2026-41940) was discovered in cPanel and WebHost Manager (WHM), widely used web hosting control panels. This flaw allows unauthenticated remote attackers to gain administrative access to servers, potentially compromising all hosted websites and data. ([support.cpanel.net](https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026?utm_source=openai)) By early May, threat actors exploited this vulnerability to target government and military entities in Southeast Asia, as well as managed service providers (MSPs) and hosting providers in multiple countries, including the U.S. ([thehackernews.com](https://thehackernews.com/2026/05/critical-cpanel-vulnerability.html?utm_source=openai)) The attacks have led to server takeovers, website defacements, and data encryption using ransomware. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/04/multiple-threat-actors-actively-exploit-cpanel-vulnerability-cve-2026-41940/?utm_source=openai)) The rapid exploitation of CVE-2026-41940 underscores the critical need for organizations to promptly apply security patches and review their systems for potential breaches. The widespread use of cPanel and WHM amplifies the risk, making it imperative for all users to ensure their installations are updated to the latest secure versions. ([techcrunch.com](https://techcrunch.com/2026/04/30/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites/?utm_source=openai))
3 months ago
Kill Chain
Silver Fox's Tax-Themed Phishing Campaign Unveils New ABCDoor Malware
In December 2025, the China-based cybercrime group Silver Fox initiated a sophisticated phishing campaign targeting organizations in India and Russia. The attackers sent emails impersonating official tax authorities, prompting recipients to download archives purportedly containing lists of tax violations. These archives contained a modified Rust-based loader that deployed the ValleyRAT backdoor, which subsequently installed a new Python-based backdoor named ABCDoor. This malware granted attackers remote access to infected systems, enabling data exfiltration and real-time control over compromised devices. ([thehackernews.com](https://thehackernews.com/2026/05/silver-fox-deploys-abcdoor-malware-via.html?utm_source=openai)) This incident underscores the evolving tactics of cybercriminal groups, particularly their use of tax-themed phishing lures and advanced malware to infiltrate organizations. The deployment of ABCDoor highlights the continuous development of sophisticated tools aimed at evading detection and maintaining persistent access to targeted systems. ([thehackernews.com](https://thehackernews.com/2026/05/silver-fox-deploys-abcdoor-malware-via.html?utm_source=openai))
3 months ago
Kill Chain
Wireshark 4.6.5 Release: Addressing 43 Vulnerabilities Amid AI-Assisted Reports
On May 3, 2026, Wireshark released version 4.6.5, addressing 43 vulnerabilities, including 38 CVEs. This significant update was driven by a surge in AI-assisted vulnerability reports, highlighting the evolving landscape of cybersecurity threats. The vulnerabilities, if exploited, could allow attackers to execute arbitrary code or cause denial-of-service conditions, emphasizing the critical need for timely software updates. The rapid identification and disclosure of these vulnerabilities underscore the dual role of AI in cybersecurity—both as a tool for defenders and a resource for attackers. Organizations must remain vigilant, ensuring that their security practices evolve alongside technological advancements to mitigate emerging threats effectively.
3 months ago
Kill Chain
April 2026 Cybersecurity Threats: AI-Powered Phishing and Linux 'Copy Fail' Vulnerability
In late April 2026, two significant cybersecurity threats emerged. First, a critical vulnerability known as 'Copy Fail' (CVE-2026-31431) was discovered in the Linux kernel, affecting versions released since 2017. This flaw allows unprivileged local users to escalate privileges to root by exploiting the kernel's cryptographic interface. Despite patches being available, many distributions had not yet implemented them, leaving systems vulnerable. Second, researchers identified 'Bluekit,' an advanced phishing kit capable of emulating over 40 global brands and bypassing multi-factor authentication protocols. Bluekit utilizes jailbroken AI models to generate convincing phishing emails and includes features like real-time session hijacking and anti-bot detection, making it a formidable tool for cybercriminals. These incidents underscore the evolving sophistication of cyber threats, particularly the integration of AI in phishing campaigns and the exploitation of longstanding vulnerabilities in widely used systems. Organizations must prioritize timely patch management and enhance their defenses against AI-driven social engineering attacks to mitigate these risks.
3 months ago
Kill Chain
Kaikatsu Club Data Breach 2025: A Wake-Up Call for Cybersecurity in the AI Era
In January 2025, Kaikatsu Club, Japan's largest internet café chain, suffered a significant data breach when a 17-year-old high school student from Osaka exploited vulnerabilities in the company's application server. Utilizing a self-developed program, the attacker illicitly accessed and extracted approximately 7.25 million customer records, including personal information. The breach led to the temporary suspension of certain application functions, disrupting business operations. The individual was arrested in December 2025 under Japan's Unauthorized Access Prohibition Act. This incident underscores the growing accessibility of sophisticated cyberattack tools, even to individuals with limited resources, highlighting the urgent need for robust cybersecurity measures and continuous monitoring to protect sensitive customer data.
3 months ago
Kill Chain
Breaking the Code: Multi-Stage 'Code of Conduct' Phishing Campaign Leads to AiTM Token Compromise
In April 2026, a sophisticated phishing campaign targeted over 35,000 users across 13,000 organizations, primarily in the United States. Attackers employed 'code of conduct' themed emails with polished HTML templates to create a sense of urgency. The multi-stage attack involved CAPTCHA challenges and intermediate pages, culminating in an adversary-in-the-middle (AiTM) phishing site that intercepted authentication tokens, effectively bypassing non-phishing-resistant multifactor authentication (MFA) and granting immediate account access. This incident underscores the evolving sophistication of phishing tactics, highlighting the need for organizations to implement phishing-resistant MFA methods and enhance user awareness training to mitigate such threats.
3 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

