✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 2221 to 2232 of 5175
New macOS Malware Campaign Exploits Script Editor in ClickFix Attack
In April 2026, a new macOS malware campaign emerged, leveraging the Script Editor application to deliver the Atomic Stealer (AMOS) malware. Attackers employed a variation of the ClickFix technique, directing users to malicious websites that prompted them to open Script Editor via the 'applescript://' URL scheme. This method executed obfuscated commands to download and run AMOS, which exfiltrated sensitive data including Keychain information, browser credentials, and cryptocurrency wallets. This incident underscores the evolving tactics of threat actors targeting macOS systems, particularly through trusted applications like Script Editor. The shift from Terminal-based to Script Editor-based ClickFix attacks highlights the need for continuous vigilance and user education to recognize and avoid such sophisticated social engineering schemes.
4 months ago
Kill Chain
Iran-Linked Hackers Target U.S. Critical Infrastructure in 2026
In early April 2026, Iran-affiliated cyber actors targeted internet-facing operational technology (OT) devices across U.S. critical infrastructure sectors, including programmable logic controllers (PLCs) manufactured by Rockwell Automation. These attacks led to diminished PLC functionality, manipulation of display data, and, in some cases, operational disruption and financial loss. The Cybersecurity and Infrastructure Security Agency (CISA), along with the FBI and NSA, issued warnings about these threats, emphasizing the need for immediate action to secure vulnerable OT assets. ([nextgov.com](https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/?utm_source=openai)) This incident underscores the escalating cyber threats from nation-state actors targeting critical infrastructure. The exploitation of internet-exposed PLCs highlights the urgent need for organizations to implement robust cybersecurity measures, including network segmentation, regular software updates, and the use of strong, unique passwords to protect against such sophisticated attacks.
4 months ago
Kill Chain
Magento 2026: PolyShell Vulnerability Exploited in Credit Card Skimming Attacks
In April 2026, a significant cybersecurity incident targeted nearly 100 online stores utilizing the Magento e-commerce platform. Attackers exploited the 'PolyShell' vulnerability, a critical flaw in Magento's REST API, allowing unauthenticated remote code execution. By injecting malicious code into a 1x1-pixel SVG image within the websites' HTML, they deployed a sophisticated credit card skimmer. This skimmer intercepted checkout processes, presenting a fake 'Secure Checkout' overlay to customers, capturing their payment information, and exfiltrating it through encrypted channels. The campaign's stealthy nature and the widespread use of Magento made this attack particularly impactful. This incident underscores a growing trend of attackers leveraging zero-day vulnerabilities in widely used platforms to conduct large-scale data theft. The use of obfuscated code within seemingly benign elements like SVG images highlights the evolving sophistication of threat actors. Organizations must remain vigilant, ensuring timely patching and employing advanced detection mechanisms to mitigate such risks.
4 months ago
Kill Chain
Hims & Hers Data Breach: Lessons in Third-Party Security
In early February 2026, telehealth company Hims & Hers Health experienced a data breach when unauthorized individuals accessed support tickets through their third-party customer service platform, Zendesk. The breach, occurring between February 4 and February 7, exposed personal information such as names and contact details of customers. Importantly, no medical records or doctor communications were compromised. The company promptly secured the platform and initiated an investigation upon discovering the suspicious activity on February 5. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hims-and-hers-warns-of-data-breach-after-zendesk-support-ticket-breach/?utm_source=openai)) This incident underscores the vulnerabilities associated with third-party service providers and the critical need for robust security measures. As cyber threats targeting support systems increase, organizations must enhance their security protocols to protect sensitive customer data and maintain trust.
4 months ago
Kill Chain
Navigating Financial Cyberthreats: Insights from 2025 and Projections for 2026
In 2025, the financial sector faced a rapidly evolving cyber landscape characterized by the proliferation of infostealers, AI-assisted attacks, and supply chain compromises. Notably, there was a significant increase in mobile financial threats, with a 102% rise in users affected globally compared to 2023. Additionally, 12.8% of B2B finance sector companies encountered ransomware attacks, marking a 35.7% increase from the previous year. These developments underscore the growing sophistication and diversification of cyber threats targeting financial institutions. ([me-en.kaspersky.com](https://me-en.kaspersky.com/about/press-releases/financial-sector-faced-ai-blockchain-and-organized-crime-threats-in-2025-kaspersky-reports?utm_source=openai)) Looking ahead to 2026, the financial sector is expected to confront even more complex challenges, including the emergence of quantum-proof ransomware and the continued advancement of mobile financial cyberthreats. Organizations must proactively adapt their cybersecurity strategies to address these evolving threats, emphasizing the importance of real-time monitoring, cross-channel threat intelligence, and robust identity protection measures. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/kaspersky-predicts-quantum-proof-ransomware-and-advancements-in-mobile-financial-cyberthreats-in-2025?utm_source=openai))
4 months ago
Kill Chain
North Korean Hackers Deploy 1,700 Malicious Packages in Unprecedented Supply Chain Attack
In early April 2026, North Korean state-sponsored hackers, identified as the Contagious Interview group, executed a sophisticated supply chain attack by publishing over 1,700 malicious packages across multiple open-source ecosystems, including npm, PyPI, Go, Rust, and PHP. These packages impersonated legitimate developer tools but functioned as malware loaders, deploying platform-specific payloads capable of data theft and remote access. The attack underscores the persistent threat to software supply chains and the need for vigilant security practices among developers and organizations. ([thehackernews.com](https://thehackernews.com/2026/04/n-korean-hackers-spread-1700-malicious.html?utm_source=openai)) This incident highlights a concerning trend of state-sponsored actors targeting open-source ecosystems to infiltrate developer environments. The scale and coordination of this attack demonstrate the evolving tactics of threat actors and the critical importance of securing software supply chains to prevent widespread compromise.
4 months ago
Kill Chain
APT28's PRISMEX Malware Campaign: A 2026 Cyber-Espionage Threat
In early 2026, the Russian state-sponsored group APT28 (also known as Fancy Bear and Pawn Storm) initiated a sophisticated cyber-espionage campaign targeting Ukraine and its NATO allies. The operation employed a newly developed malware suite named PRISMEX, which utilizes advanced steganography, Component Object Model (COM) hijacking, and the exploitation of legitimate cloud services for command-and-control (C2) communications. The campaign began in September 2025 and intensified in January 2026, focusing on sectors such as defense, emergency services, and logistics across multiple countries, including Poland, Romania, Slovenia, Turkey, Slovakia, and the Czech Republic. ([thehackernews.com](https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html?utm_source=openai)) This campaign underscores the rapid weaponization of newly disclosed vulnerabilities by APT28, notably CVE-2026-21509 and CVE-2026-21513, to infiltrate target systems. The use of PRISMEX highlights a strategic shift towards more covert and resilient attack methodologies, posing significant challenges for detection and mitigation. ([thehackernews.com](https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html?utm_source=openai))
4 months ago
Kill Chain
Anthropic's Claude Mythos AI Model Uncovers Critical Software Vulnerabilities
In April 2026, Anthropic unveiled its advanced AI model, Claude Mythos, which autonomously identified thousands of high-severity vulnerabilities across major operating systems and web browsers. This unprecedented capability led to the launch of Project Glasswing, a collaborative initiative with tech giants like Amazon, Apple, and Microsoft, aiming to address these security flaws before potential exploitation. The discovery of such extensive vulnerabilities underscores the critical need for proactive cybersecurity measures in the face of rapidly advancing AI technologies. As AI models become more sophisticated, they present both opportunities for enhancing security and risks of being weaponized by malicious actors. Organizations must stay vigilant and adapt their defenses to counteract these evolving threats.
4 months ago
Kill Chain
Masjesu Botnet: A New Era of DDoS-for-Hire Targeting IoT Devices
In April 2026, cybersecurity researchers identified 'Masjesu,' a sophisticated botnet operating as a DDoS-for-hire service. Masjesu has been active since 2023, primarily targeting a wide array of IoT devices, including routers and gateways, across multiple architectures. The botnet employs advanced evasion techniques, such as randomizing packet headers and payloads, to mimic legitimate traffic and avoid detection. It propagates by exploiting known vulnerabilities in devices from manufacturers like D-Link, GPON, and Netgear, and by brute-forcing weak or default passwords. Masjesu's operators advertise their services via Telegram, offering clients the ability to launch large-scale DDoS attacks on demand. ([trellix.com](https://www.trellix.com/blogs/research/masjesu-rising-stealth-iot-botnet-ddos-evasion/?utm_source=openai)) The emergence of Masjesu underscores the escalating threat posed by IoT-based botnets. With the proliferation of unsecured IoT devices, attackers can easily amass vast networks capable of launching devastating DDoS attacks. This trend highlights the urgent need for enhanced security measures, including regular firmware updates, strong password policies, and network monitoring, to protect against such evolving threats.
4 months ago
Kill Chain
Chaos Malware's New Variant Exploits Cloud Misconfigurations in 2026
In March 2026, cybersecurity researchers identified a new variant of the Chaos malware targeting misconfigured cloud deployments, particularly 64-bit Linux servers. Previously known for compromising routers and edge devices, this evolution signifies a strategic shift by attackers to exploit cloud infrastructure vulnerabilities. The malware gains access through misconfigurations, establishes persistence via systemd services, and introduces a SOCKS5 proxy feature, enabling attackers to route malicious traffic through compromised servers. This development underscores the critical need for organizations to secure cloud environments against evolving threats. The inclusion of proxy capabilities in Chaos malware reflects a broader trend of botnets expanding functionalities beyond traditional DDoS attacks, facilitating more complex cybercriminal activities. This shift highlights the importance of robust security configurations and continuous monitoring in cloud deployments to mitigate emerging risks.
4 months ago
Kill Chain
AI-Assisted Cyberattack Compromises 600+ FortiGate Firewalls Globally
In early 2026, a sophisticated cyberattack leveraging artificial intelligence (AI) tools compromised over 600 FortiGate firewalls across 55 countries. The attackers utilized AI to automate reconnaissance, vulnerability scanning, and exploitation processes, significantly accelerating the attack timeline and reducing the need for human intervention. By exploiting weak security configurations and exposed management interfaces, the threat actors gained unauthorized access to critical network infrastructure, leading to potential data breaches and operational disruptions. This incident underscores the escalating threat posed by AI-enhanced cyberattacks, which enable adversaries to conduct large-scale operations with unprecedented speed and efficiency. Organizations must recognize the evolving capabilities of AI in the cyber threat landscape and implement robust security measures to defend against such advanced attacks.
4 months ago
Kill Chain
Storm-1175's High-Velocity Medusa Ransomware Attacks in 2026
In April 2026, the financially motivated cybercriminal group Storm-1175 launched rapid ransomware attacks targeting healthcare, education, professional services, and finance sectors across Australia, the UK, and the US. Exploiting both zero-day and recently disclosed vulnerabilities, the group moved swiftly from initial access to data exfiltration and deployment of Medusa ransomware, often within 24 hours. Their tactics included creating new user accounts, deploying remote monitoring tools, stealing credentials, and disabling security software to facilitate their operations. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/?utm_source=openai)) This incident underscores the critical need for organizations to promptly patch vulnerabilities and enhance monitoring of web-facing assets. The speed and efficiency of Storm-1175's attacks highlight a growing trend among threat actors to exploit the narrow window between vulnerability disclosure and patch deployment, emphasizing the importance of proactive cybersecurity measures. ([darkreading.com](https://www.darkreading.com/threat-intelligence/storm-1175-medusa-ransomware-high-velocity/?utm_source=openai))
4 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

