✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 2317 to 2328 of 5175
Anthropic's 2026 Claude Code Source Code Leak Exploited to Distribute Infostealer Malware
In March 2026, Anthropic inadvertently exposed over 500,000 lines of Claude Code's source code due to a packaging error, leading to its rapid dissemination on platforms like GitHub. Threat actors exploited this leak by creating malicious GitHub repositories that masqueraded as the leaked code, enticing users to download files that deployed Vidar infostealer malware upon execution. This incident underscores the critical need for robust internal security measures and vigilance against opportunistic cyber threats that capitalize on such exposures. The exploitation of this leak highlights a growing trend where cybercriminals swiftly leverage publicly disclosed vulnerabilities to distribute malware, emphasizing the importance of prompt incident response and comprehensive security protocols to mitigate potential damages.
4 months ago
Kill Chain
Drift Protocol's $280 Million Admin Takeover Exploit in 2026
In April 2026, Drift Protocol, a Solana-based decentralized finance (DeFi) platform, suffered a significant security breach resulting in the loss of approximately $280 million. The attacker employed a sophisticated strategy involving durable nonce accounts and pre-signed transactions to gain unauthorized administrative control over Drift's Security Council. This method allowed the execution of malicious transactions at a predetermined time, leading to the rapid transfer of administrative powers and subsequent draining of funds. Notably, the breach did not exploit any vulnerabilities in Drift's smart contracts or programs, and there was no compromise of seed phrases. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/drift-loses-280-million-as-hackers-seize-security-council-powers/?utm_source=openai)) This incident underscores the evolving nature of cyber threats targeting DeFi platforms, highlighting the need for enhanced security measures beyond traditional smart contract audits. The use of advanced techniques such as durable nonces and social engineering to manipulate governance structures presents a new challenge for the industry, emphasizing the importance of robust administrative controls and vigilant monitoring to prevent similar exploits.
4 months ago
Kill Chain
WhatsApp 2026: Italian Surveillance Firm's Fake iOS App Distributes Spyware
In April 2026, WhatsApp identified approximately 200 users, primarily in Italy, who were deceived into installing a counterfeit version of the app containing spyware. The malicious application was developed by ASIGINT, a subsidiary of the Italian surveillance firm SIO, and was distributed through unofficial channels. Upon discovery, WhatsApp logged affected users out of their accounts, alerted them to the security risks, and advised them to reinstall the official app from trusted sources. This incident underscores the persistent threat posed by social engineering tactics and the importance of downloading applications exclusively from official app stores. The proliferation of sophisticated spyware tools like those developed by ASIGINT highlights the evolving landscape of cyber threats targeting mobile devices. Organizations and individuals must remain vigilant against such deceptive practices to safeguard their privacy and security.
4 months ago
Kill Chain
REF1695's 2023 Campaign: Unveiling the Threat of Fake Installers
In November 2023, a financially motivated threat actor, codenamed REF1695, initiated a campaign leveraging fake software installers to deploy remote access trojans (RATs) and cryptocurrency miners. The attackers utilized ISO files containing a .NET Reactor-protected loader and instructions guiding users to bypass Microsoft Defender SmartScreen protections. This method facilitated the installation of a previously undocumented .NET implant known as CNB Bot, enabling unauthorized access and resource exploitation on compromised systems. Beyond cryptomining, REF1695 monetized infections through Cost Per Action (CPA) fraud, directing victims to content locker pages under the guise of software registration. This multifaceted approach not only compromised system integrity but also led to financial losses for affected organizations. The incident underscores the evolving tactics of cybercriminals who combine traditional malware deployment with social engineering techniques to maximize their illicit gains. Organizations are urged to enhance their cybersecurity measures, including user education on recognizing phishing attempts and the importance of verifying software sources, to mitigate such threats.
4 months ago
Kill Chain
Urgent: Patch Critical RCE Vulnerabilities in Progress ShareFile
In March 2026, security researchers identified two critical vulnerabilities in Progress ShareFile, designated as CVE-2026-2699 and CVE-2026-2701. These flaws, when exploited in tandem, allow unauthenticated attackers to execute remote code by bypassing authentication mechanisms and uploading malicious web shells. Progress promptly addressed these issues by releasing Storage Zone Controller version 5.12.4 on March 10, 2026. Given the approximately 30,000 internet-facing instances of ShareFile, immediate patching is imperative to prevent potential exploitation. This incident underscores the persistent threat posed by chaining multiple vulnerabilities to achieve significant security breaches. Organizations must remain vigilant, ensuring timely updates and comprehensive security assessments to mitigate such risks.
4 months ago
Kill Chain
React2Shell Exploitation Leads to Massive Credential Harvesting in 2026
In early 2026, a large-scale credential harvesting operation exploited the React2Shell vulnerability (CVE-2025-55182) to compromise 766 Next.js hosts. Attackers leveraged this critical remote code execution flaw in React Server Components to gain unauthorized access to sensitive data, including database credentials, SSH private keys, AWS secrets, shell command history, Stripe API keys, and GitHub tokens. The breach underscores the severe risks associated with unpatched vulnerabilities in widely used web frameworks. The React2Shell vulnerability, disclosed in December 2025, has been actively exploited by threat actors, leading to significant data breaches and system compromises. This incident highlights the urgent need for organizations to promptly apply security patches and implement robust monitoring to detect and mitigate exploitation attempts.
4 months ago
Kill Chain
Cisco IMC Vulnerabilities: Authentication Bypass and Command Injection Risks in 2026
In April 2026, Cisco disclosed two critical vulnerabilities in its Integrated Management Controller (IMC): CVE-2026-20093 and CVE-2026-20094. CVE-2026-20093 is an authentication bypass flaw that allows unauthenticated, remote attackers to gain admin access by exploiting improper handling of password change requests. CVE-2026-20094 is a command injection vulnerability enabling authenticated users with read-only privileges to execute arbitrary commands as the root user due to inadequate input validation. Exploitation of these vulnerabilities could lead to full system compromise, including unauthorized access, data manipulation, and potential service disruptions. ([cisco.com](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-cimc-auth-bypass-AgG2BxTn.html?utm_source=openai)) The disclosure of these vulnerabilities underscores the ongoing risks associated with out-of-band management interfaces. As organizations increasingly rely on such systems for remote administration, ensuring their security becomes paramount. This incident highlights the necessity for regular security assessments, prompt application of patches, and vigilant monitoring to mitigate potential threats.
4 months ago
Kill Chain
AZ Monica Hospital Cyberattack: A Stark Reminder for Healthcare Security
In January 2026, AZ Monica Hospital in Antwerp, Belgium, experienced a significant cyberattack that disrupted its computer systems, leading to the cancellation of at least 70 surgeries and the transfer of seven critical patients to other facilities. The attack also affected patient registration processes and emergency services, compelling the hospital to advise patients to seek care elsewhere. This incident underscores the escalating threat of cyberattacks on healthcare institutions, highlighting the critical need for robust cybersecurity measures to protect patient safety and maintain operational continuity.
4 months ago
Kill Chain
Casbaneiro Banking Trojan's 2026 Campaign: A Wake-Up Call for Financial Cybersecurity
In early 2026, the Brazilian cybercrime group known as Augmented Marauder launched a sophisticated phishing campaign targeting Spanish-speaking users across Latin America and Europe. Utilizing the Horabot malware, they distributed the Casbaneiro banking trojan through deceptive emails containing password-protected PDFs. Once executed, Casbaneiro monitored victims' online banking activities, capturing credentials and facilitating unauthorized financial transactions. The campaign's worm-like propagation via compromised email accounts significantly amplified its reach and impact. This incident underscores the evolving tactics of cybercriminals in deploying banking trojans, highlighting the need for enhanced email security measures and user awareness. The use of dynamic PDF lures and self-propagating malware reflects a broader trend of increasingly sophisticated phishing techniques aimed at financial institutions and their customers.
4 months ago
Kill Chain
Understanding Cookie-Controlled PHP Web Shells in Linux Hosting
In early 2026, threat actors increasingly exploited PHP web shells on Linux servers, utilizing HTTP cookies as control channels. This method allowed malicious code to remain dormant during normal operations, activating only when specific cookie values were present, thereby evading traditional detection mechanisms. The attackers employed various obfuscation techniques, including layered encoding and dynamic function reconstruction, to conceal their activities. This approach enabled persistent access, often through scheduled tasks that reinstated the web shell if removed, complicating remediation efforts. The incidents underscored the need for enhanced monitoring of web server processes and stricter controls over scheduled tasks to prevent unauthorized access and maintain system integrity. The rise of cookie-controlled PHP web shells highlights a significant shift in attacker tactics, emphasizing stealth and persistence. Organizations must adapt by implementing advanced detection strategies, such as behavior-based monitoring and anomaly detection, to identify and mitigate these sophisticated threats effectively.
4 months ago
Kill Chain
Critical Security Alert: CVE-2026-5281 in Google Chrome's Dawn Component
In April 2026, a critical use-after-free vulnerability, identified as CVE-2026-5281, was discovered in Google Chrome's Dawn component, which handles WebGPU operations. This flaw allows remote attackers who have compromised the renderer process to execute arbitrary code via crafted HTML pages. The vulnerability affects Chrome versions prior to 146.0.7680.178. Google has released a patch to address this issue, and users are strongly advised to update their browsers immediately to mitigate potential risks. ([leakycreds.com](https://www.leakycreds.com/vulnerability/CVE-2026-5281?utm_source=openai)) The inclusion of CVE-2026-5281 in CISA's Known Exploited Vulnerabilities catalog underscores the severity of the threat, as it has been actively exploited in the wild. This incident highlights the ongoing challenges in securing widely used software components and the importance of timely updates to protect against emerging threats. ([thecyberthrone.in](https://thecyberthrone.in/2026/04/02/cve-2026-5281-google-chrome-dawn-use-after-free-under-active-exploitation/?utm_source=openai))
4 months ago
Kill Chain
Axios Supply Chain Attack: A Wake-Up Call for Software Security
In late March 2026, attackers compromised the npm account of a primary maintainer of Axios, a widely-used JavaScript HTTP client library with over 100 million weekly downloads. They published two malicious versions, axios@1.14.1 and axios@0.30.4, which included a hidden dependency named 'plain-crypto-js'. This dependency executed a post-install script that deployed a cross-platform Remote Access Trojan (RAT) targeting Windows, macOS, and Linux systems. The RAT connected to a command-and-control server to retrieve platform-specific payloads, performed reconnaissance, and established persistence, with self-deletion capabilities to evade detection. The malicious versions were available for approximately three hours before removal, but the widespread use of Axios means the impact could be significant. ([sans.org](https://www.sans.org/blog/axios-npm-supply-chain-compromise-malicious-packages-remote-access-trojan?utm_source=openai)) This incident underscores the growing threat of supply chain attacks, where trusted software components are exploited to distribute malware. The sophistication of this attack, including the use of a legitimate maintainer's credentials and the deployment of a cross-platform RAT, highlights the need for enhanced security measures in software development and distribution processes. Organizations must remain vigilant and implement robust monitoring and response strategies to mitigate such risks. ([sans.org](https://www.sans.org/blog/axios-npm-supply-chain-compromise-malicious-packages-remote-access-trojan?utm_source=openai))
4 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

