✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 2185 to 2196 of 5166
Bitcoin Depot's 2026 Security Breach: A Wake-Up Call for Cryptocurrency Security
In March 2026, Bitcoin Depot, a leading Bitcoin ATM operator, experienced a significant security breach when attackers infiltrated its IT systems and obtained credentials for digital asset settlement accounts. This unauthorized access enabled the transfer of approximately 50.9 Bitcoin, valued at $3.665 million at the time, from company-controlled wallets. The breach was detected on March 23, prompting Bitcoin Depot to activate incident response protocols, engage external cybersecurity experts, and notify law enforcement. Importantly, the company reported that customer platforms and data remained unaffected by this incident. This breach underscores the persistent vulnerabilities within the cryptocurrency sector, particularly concerning the security of internal corporate systems. The incident highlights the critical need for robust credential management and comprehensive security measures to protect digital assets. As the cryptocurrency market continues to expand, organizations must prioritize the implementation of stringent security protocols to mitigate the risk of such attacks.
4 months ago
Kill Chain
Eurail 2025 Data Breach: A Wake-Up Call for Travel Industry Cybersecurity
In late December 2025, Eurail B.V., a Netherlands-based travel company, experienced a significant data breach when unauthorized actors accessed its network and exfiltrated files containing sensitive customer information. The breach, which occurred on December 26, 2025, was discovered on January 5, 2026, and confirmed on February 25, 2026. Approximately 308,777 individuals were affected, with compromised data including names, passport numbers, dates of birth, email addresses, postal addresses, phone numbers, bank account references (IBANs), and health-related information. ([claimdepot.com](https://www.claimdepot.com/data-breach/eurail-2026?utm_source=openai)) This incident underscores the escalating threat landscape targeting the travel industry, where personal data is highly valuable. The breach highlights the critical need for robust cybersecurity measures, including regular system audits, employee training, and comprehensive incident response plans to mitigate potential risks and protect customer information.
4 months ago
Kill Chain
Supply Chain Attack on Smart Slider 3 Pro Compromises Websites in 2026
In April 2026, attackers compromised the update system of the Smart Slider 3 Pro plugin, affecting version 3.5.1.35 for both WordPress and Joomla platforms. This malicious update introduced multiple backdoors, created hidden administrator accounts, and exfiltrated sensitive data from affected websites. The incident underscores the critical importance of securing software supply chains to prevent unauthorized code distribution and maintain the integrity of widely used web applications. This event highlights a growing trend of supply chain attacks targeting popular web plugins, emphasizing the need for vigilant monitoring of software updates and the implementation of robust security measures to detect and prevent unauthorized modifications.
4 months ago
Kill Chain
Figure Technology Solutions Data Breach: A Wake-Up Call for Fintech Security
In February 2026, Figure Technology Solutions, a leading fintech company specializing in blockchain-enabled lending services, experienced a significant data breach. The incident began when an employee was deceived by a sophisticated voice phishing (vishing) attack, leading to unauthorized access to the company's systems. The cybercriminal group ShinyHunters claimed responsibility, exfiltrating approximately 2.5 gigabytes of sensitive customer data, including full names, addresses, dates of birth, phone numbers, Social Security numbers, and loan information. This breach affected nearly one million customers, exposing them to potential identity theft and financial fraud. ([crowdfundinsider.com](https://www.crowdfundinsider.com/2026/02/262975-figure-technology-faces-major-data-breach-impacting-nearly-one-million-customers/?utm_source=openai)) This incident underscores the escalating threat of social engineering attacks targeting financial institutions. Despite advancements in cybersecurity measures, human factors remain a critical vulnerability. The breach highlights the necessity for comprehensive security protocols, including robust employee training and advanced authentication mechanisms, to mitigate the risks associated with sophisticated phishing campaigns.
4 months ago
Kill Chain
ChipSoft Ransomware Attack: A Wake-Up Call for Healthcare Cybersecurity
In April 2026, ChipSoft, a leading Dutch healthcare software provider serving approximately 70% of the country's hospitals, suffered a ransomware attack. The incident led to the company's website going offline and raised concerns about potential unauthorized access to patient records. In response, several hospitals disconnected their systems as a precautionary measure. The full extent of the data breach remains under investigation. This attack underscores the escalating threat of ransomware targeting critical healthcare infrastructure. The incident highlights the urgent need for robust cybersecurity measures and comprehensive incident response plans to protect sensitive patient data and ensure the continuity of healthcare services.
4 months ago
Kill Chain
Google Chrome 2026: Device Bound Session Credentials Enhance Security Against Infostealer Threats
In April 2026, Google introduced Device Bound Session Credentials (DBSC) in Chrome 146 for Windows, aiming to combat the escalating threat of session cookie theft by infostealer malware. DBSC cryptographically binds authentication sessions to a user's specific device using hardware-backed security modules like the Trusted Platform Module (TPM). This binding ensures that even if session cookies are exfiltrated, they cannot be utilized on unauthorized devices, thereby mitigating unauthorized access to user accounts. ([security.googleblog.com](https://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html?utm_source=openai)) The deployment of DBSC is particularly timely given the rise of sophisticated infostealer malware, such as LummaC2, which harvests session cookies to bypass traditional authentication mechanisms, including multi-factor authentication (MFA). By rendering stolen session cookies ineffective on unauthorized devices, DBSC addresses a critical vulnerability in current web authentication practices. ([security.googleblog.com](https://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html?utm_source=openai))
4 months ago
Kill Chain
LucidRook Malware Targets Taiwanese NGOs and Universities in 2025
In October 2025, the threat actor group UAT-10362 launched spear-phishing campaigns targeting non-governmental organizations (NGOs) and universities in Taiwan. These attacks utilized a newly identified Lua-based malware named 'LucidRook,' which was delivered through malicious LNK and EXE files disguised as legitimate software. Once executed, LucidRook embedded a Lua interpreter within a dynamic-link library (DLL) to download and execute staged Lua bytecode payloads, enabling the attackers to update functionality without modifying the core malware. The malware performed system reconnaissance, collecting information such as user and computer names, installed applications, and running processes, which was then encrypted and exfiltrated via FTP to attacker-controlled infrastructure. ([blog.talosintelligence.com](https://blog.talosintelligence.com/new-lua-based-malware-lucidrook/?utm_source=openai)) This incident underscores the evolving sophistication of cyber threats, particularly those targeting educational and non-governmental sectors. The use of modular malware like LucidRook, capable of dynamic updates and extensive obfuscation, highlights the need for organizations to enhance their cybersecurity measures, including employee training on phishing tactics and the implementation of advanced threat detection systems.
4 months ago
Kill Chain
VENOM Phishing Campaign: A Wake-Up Call for Executive Security
Between November 2025 and March 2026, a sophisticated phishing campaign utilizing the previously undocumented VENOM phishing-as-a-service (PhaaS) platform targeted C-suite executives across over 20 industries. Attackers impersonated Microsoft SharePoint notifications, embedding QR codes to lure victims into credential theft schemes. The campaign employed advanced evasion techniques, including adversary-in-the-middle (AiTM) attacks and device code abuse, effectively bypassing multi-factor authentication (MFA) and establishing persistent access to compromised accounts. ([abnormal.ai](https://abnormal.ai/resources/venom-phaas-c-suite-microsoft-credential-theft-report?utm_source=openai)) This incident underscores a growing trend of highly targeted phishing attacks against high-level executives, highlighting the need for organizations to reassess their security postures. The emergence of sophisticated PhaaS platforms like VENOM indicates an evolution in cybercriminal tactics, emphasizing the urgency for enhanced defenses against such advanced threats. ([abnormal.ai](https://abnormal.ai/resources/venom-phaas-c-suite-microsoft-credential-theft-report?utm_source=openai))
4 months ago
Kill Chain
Bitter APT's Hack-for-Hire Campaign Targets MENA Journalists
In a series of cyber espionage activities from 2023 to 2024, the Bitter APT group, suspected to have ties to the Indian government, orchestrated a hack-for-hire campaign targeting journalists, activists, and government officials across the Middle East and North Africa (MENA) region. Notably, Egyptian journalists Mostafa Al-A'sar and Ahmed Eltantawy were subjected to spear-phishing attacks aimed at compromising their Apple and Google accounts. These attacks involved deceptive emails leading to counterfeit login pages designed to harvest credentials and two-factor authentication codes. ([thehackernews.com](https://thehackernews.com/2026/04/bitter-linked-hack-for-hire-campaign.html?utm_source=openai)) This incident underscores a concerning trend of state-affiliated threat actors employing sophisticated social engineering tactics to infiltrate the accounts of individuals critical of governmental policies. The Bitter APT group's activities highlight the persistent and evolving nature of cyber threats targeting civil society in the MENA region. ([accessnow.org](https://www.accessnow.org/press-release/hack-for-hire-new-report-egyptian-journalists/?utm_source=openai))
4 months ago
Kill Chain
ClipBanker Malware 2025: Trojanized Proxifier Leads to Crypto Theft
In early 2025, cybersecurity researchers identified a sophisticated malware campaign involving the ClipBanker Trojan, which was distributed through a trojanized version of the Proxifier software. Users searching for Proxifier were led to a GitHub repository hosting a malicious installer. Upon execution, this installer initiated a complex infection chain, ultimately deploying ClipBanker—a malware designed to monitor clipboard activity and replace cryptocurrency wallet addresses with those controlled by attackers, leading to unauthorized fund transfers. ([securelist.com](https://securelist.com/clipbanker-malware-distributed-via-trojanized-proxifier/119341/?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals who exploit trusted platforms and software to distribute malware. The use of trojanized legitimate applications highlights the need for heightened vigilance and the importance of downloading software exclusively from official sources to mitigate such risks.
4 months ago
Kill Chain
Critical RCE Vulnerability Discovered in Apache ActiveMQ Classic
In April 2026, a critical remote code execution (RCE) vulnerability, identified as CVE-2026-34197, was discovered in Apache ActiveMQ Classic's Jolokia JMX-HTTP bridge. This flaw allows authenticated attackers to execute arbitrary code on the server by exploiting improper input validation within the Jolokia endpoint. The vulnerability affects all versions of Apache ActiveMQ Classic and has remained undetected for over 13 years. ([cryptika.com](https://www.cryptika.com/claude-uncovers-13-year-old-rce-flaw-in-apache-activemq-in-just-10-minutes/?utm_source=openai)) The discovery of this longstanding vulnerability underscores the persistent risks associated with legacy software components and the importance of regular security assessments. Organizations utilizing Apache ActiveMQ Classic are urged to apply the latest patches promptly to mitigate potential exploitation.
4 months ago
Kill Chain
Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025
In December 2025, a critical zero-day vulnerability in Adobe Reader was exploited through maliciously crafted PDF documents. The exploit, identified by researcher Haifei Li, allowed attackers to execute arbitrary code on affected systems, leading to potential data breaches and system compromises. The malicious PDFs, some of which were uploaded to VirusTotal as early as November 28, 2025, indicate that the vulnerability had been actively exploited for several months before detection. ([securityweek.com](https://www.securityweek.com/adobe-reader-zero-day-exploited-for-months-researcher/?utm_source=openai)) This incident underscores the persistent threat posed by zero-day vulnerabilities and the importance of timely detection and patching. The exploitation of widely used software like Adobe Reader highlights the need for organizations to maintain robust cybersecurity measures and stay vigilant against emerging threats.
4 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

