✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 2401 to 2412 of 5175
Infinity Stealer: A New Threat to macOS Users
In March 2026, a new macOS-targeted malware named Infinity Stealer emerged, utilizing the ClickFix technique to deceive users into executing malicious code. The malware is delivered through fake CAPTCHA prompts that mimic Cloudflare's human verification, instructing users to paste a base64-obfuscated curl command into the macOS Terminal. This command downloads and executes a Python payload compiled with Nuitka, resulting in a native binary that is more resistant to static analysis. Once executed, Infinity Stealer performs anti-analysis checks and proceeds to exfiltrate sensitive data, including browser credentials, Keychain entries, cryptocurrency wallets, and plaintext secrets from developer files, via HTTP POST requests to a command-and-control server. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/02/02/infostealers-without-borders-macos-python-stealers-and-platform-abuse/?utm_source=openai)) The emergence of Infinity Stealer highlights a growing trend of sophisticated malware targeting macOS systems, leveraging advanced social engineering techniques and cross-platform development tools. This incident underscores the importance of user vigilance and the need for robust security measures to protect against evolving threats.
4 months ago
Kill Chain
Citrix NetScaler 2025 Memory Overread Vulnerability: Immediate Action Required
In June 2025, Citrix disclosed a critical vulnerability (CVE-2025-5777) in NetScaler ADC and NetScaler Gateway, characterized by insufficient input validation leading to memory overread. This flaw allows unauthenticated attackers to remotely access sensitive memory contents, including session tokens and credentials, when the devices are configured as a Gateway or AAA virtual server. The vulnerability affects versions 14.1 before 14.1-43.56 and 13.1 before 13.1-58.32. Citrix released patches on June 17, 2025, urging immediate updates to mitigate potential exploitation. ([support.citrix.com](https://support.citrix.com/external/article/CTX693420/netscaler-adc-and-netscaler-gateway-secu.html?utm_source=openai)) The urgency of addressing this vulnerability is underscored by its active exploitation in the wild, as reported by security agencies and researchers. Organizations are advised to apply the provided patches promptly to prevent unauthorized access and potential data breaches. ([techradar.com](https://www.techradar.com/pro/security/cisa-warns-hackers-are-actively-exploiting-critical-citrixbleed-2?utm_source=openai))
4 months ago
Kill Chain
Iran-Linked Hackers Breach FBI Director's Email and Stryker Systems in 2026
In March 2026, the pro-Iranian hacktivist group Handala Hack Team executed two significant cyberattacks. First, they breached the personal Gmail account of FBI Director Kash Patel, leaking personal photos and documents online. The FBI confirmed the authenticity of the materials but emphasized that no government-related information was compromised. Shortly thereafter, Handala targeted Stryker Corporation, a leading medical technology company, deploying wiper malware that disrupted global operations by wiping over 200,000 systems and exfiltrating 50 terabytes of data. This attack forced Stryker to halt manufacturing and order processing, impacting healthcare supply chains worldwide. ([apnews.com](https://apnews.com/article/9237ca30d1c85f237d7d83e6798d97f0?utm_source=openai)) These incidents underscore the escalating cyber threats posed by state-linked actors targeting both government officials and critical infrastructure. The attacks highlight the vulnerabilities in personal email security and the potential for significant operational disruptions in the healthcare sector due to cyberattacks. Organizations must enhance their cybersecurity measures to protect sensitive information and ensure business continuity in the face of such threats.
4 months ago
Kill Chain
F5 BIG-IP 2025 Remote Code Execution Vulnerability
In October 2025, a critical vulnerability identified as CVE-2025-53521 was discovered in F5 Networks' BIG-IP Access Policy Manager (APM). This flaw allows specific, undisclosed traffic to cause the Traffic Management Microkernel (TMM) to terminate unexpectedly, leading to a denial-of-service (DoS) condition. The vulnerability affects multiple versions of BIG-IP, including 17.5.0, 17.1.0, 16.1.0, and 15.1.0, and has been assigned a CVSS v3.1 score of 7.5, indicating high severity. ([wiz.io](https://www.wiz.io/vulnerability-database/cve/cve-2025-53521?utm_source=openai)) The exploitation of this vulnerability can disrupt critical services relying on BIG-IP systems, posing significant risks to organizations. Given the widespread deployment of BIG-IP devices in enterprise environments, timely remediation is essential to prevent potential service outages and maintain operational continuity.
4 months ago
Kill Chain
Silver Fox Exploits Japan's Tax Season in 2025 Phishing Campaign
In early 2025, the Chinese state-aligned threat actor known as Silver Fox launched a sophisticated phishing campaign targeting Japanese organizations during the tax season. By impersonating official entities such as the National Taxation Bureau, Silver Fox distributed emails containing malicious attachments and links, leading recipients to download trojanized versions of legitimate software. Once installed, these malicious programs deployed remote access trojans (RATs) like ValleyRAT and Winos 4.0, enabling unauthorized access, data exfiltration, and potential financial fraud. The campaign's timing exploited the heightened activity and urgency associated with tax season, increasing the likelihood of successful infiltration. ([trustwave.com](https://www.trustwave.com/en-us/resources/blogs/trustwave-blog/inside-silver-foxs-den-trustwave-spiderlabs-unmasks-a-global-threat-actor/?utm_source=openai)) This incident underscores a growing trend where state-sponsored threat actors blend espionage with financially motivated cybercrime. Silver Fox's operations highlight the evolving landscape of cyber threats, where attackers leverage seasonal events and trusted software to enhance the effectiveness of their campaigns. Organizations must remain vigilant, especially during periods of increased administrative activity, to mitigate the risks posed by such multifaceted threats. ([darkreading.com](https://www.darkreading.com/threat-intelligence/silver-fox-apt-espionage-cybercrime?utm_source=openai))
4 months ago
Kill Chain
Understanding the 2026 TeamPCP Supply Chain Attack
In March 2026, the cybercriminal group TeamPCP executed a sophisticated supply chain attack targeting multiple software packages and cloud services. The campaign began on March 19, 2026, with successive compromises of tools like Trivy, CanisterWorm, Checkmarx, LiteLLM, and Telnyx, occurring every 1-3 days. These attacks involved injecting malicious code into widely used software packages, enabling unauthorized access and data exfiltration from numerous downstream users. The rapid succession of these breaches highlighted the group's aggressive operational tempo and their focus on exploiting trusted software supply chains. As of March 28, 2026, a notable shift in TeamPCP's strategy was observed, with no new compromises reported in the preceding 48 hours. This pause suggests a transition from expanding their foothold to monetizing the vast trove of stolen credentials and data. The group's explicit intent to maintain a prolonged presence indicates that future supply chain attacks remain a significant threat. Organizations are advised to remain vigilant, conduct thorough security assessments, and implement robust monitoring to detect and mitigate potential breaches stemming from this campaign.
4 months ago
Kill Chain
Handala Hackers Breach FBI Director Kash Patel's Personal Email in 2026
In March 2026, the Iranian-linked hacking group Handala claimed responsibility for breaching the personal email account of FBI Director Kash Patel. The group released personal photographs and documents, some dating back over a decade, allegedly obtained from Patel's personal Gmail account. The FBI confirmed awareness of the targeting, emphasizing that the compromised information was historical and did not involve government data. This incident underscores the persistent cyber threats posed by state-sponsored actors targeting high-profile individuals. The breach highlights the importance of securing personal communication channels, especially for individuals in sensitive positions, as adversaries continue to exploit such vulnerabilities for intelligence gathering and propaganda purposes.
4 months ago
Kill Chain
AI-Enhanced Cyber Threats Surge in 2026
In 2026, the cybersecurity landscape witnessed a significant surge in AI-enhanced cyber threats. Malicious actors leveraged artificial intelligence to automate and accelerate attacks, leading to a 72% increase in AI-powered cyber incidents compared to the previous year. These sophisticated attacks utilized generative AI tools to craft convincing phishing emails, deepfakes, and automated exploit development, drastically reducing the time required to breach systems and exfiltrate data. Organizations across various sectors faced unprecedented challenges in defending against these rapidly evolving threats. This escalation underscores the urgent need for organizations to adopt AI-driven defense mechanisms. Traditional security measures are increasingly inadequate against AI-powered attacks, necessitating the integration of advanced AI-based threat detection and response systems to effectively mitigate these emerging risks.
4 months ago
Kill Chain
Dutch Police 2026 Phishing Attack: A Closer Look at the Security Breach
In March 2026, the Dutch National Police experienced a security breach due to a successful phishing attack. The agency's Security Operations Center promptly detected the incident and blocked the attackers' access. Preliminary investigations indicate that the impact was limited, with no exposure of citizens' data or investigative information. A criminal investigation has been initiated to further assess the breach. This incident underscores the persistent threat of phishing attacks targeting governmental institutions. Despite previous breaches and subsequent security enhancements, such as the 2024 data breach linked to a state actor, the recurrence highlights the need for continuous vigilance and adaptive cybersecurity measures.
4 months ago
Kill Chain
European Commission's AWS Account Breach in 2026: A Wake-Up Call for Cloud Security
In March 2026, the European Commission, the executive body of the European Union, experienced a significant security breach when a threat actor gained unauthorized access to its Amazon Web Services (AWS) cloud environment. The attacker claimed to have exfiltrated over 350 GB of data, including multiple databases containing sensitive information about Commission employees and internal communications. The breach was promptly detected, and the Commission's cybersecurity incident response team initiated an investigation to assess the extent of the intrusion and mitigate potential damages. This incident underscores the escalating risks associated with cloud infrastructure security, especially for governmental organizations handling sensitive data. It highlights the necessity for robust cloud security measures, continuous monitoring, and rapid response capabilities to address emerging threats in the digital landscape.
4 months ago
Kill Chain
Telnyx PyPI Supply Chain Attack: A 2026 Case Study
In March 2026, the Telnyx Python package on the Python Package Index (PyPI) was compromised by the threat actor TeamPCP. Malicious versions 4.87.1 and 4.87.2 were uploaded, embedding malware that exfiltrated sensitive data such as SSH keys, cloud tokens, and cryptocurrency wallets. The attack utilized steganography, hiding the payload within WAV audio files, and affected both Linux/macOS and Windows systems. This incident underscores the escalating threat of supply chain attacks targeting widely used open-source packages, emphasizing the need for enhanced security measures in software development pipelines.
4 months ago
Kill Chain
Fake VS Code Alerts on GitHub Distribute Malware to Developers
In March 2026, a large-scale campaign targeted developers on GitHub by posting fake Visual Studio Code (VS Code) security alerts in the Discussions sections of various projects. These deceptive posts, crafted as vulnerability advisories with titles like 'Severe Vulnerability - Immediate Update Required,' included fake CVE IDs and urgent language. Attackers impersonated real code maintainers or researchers to enhance credibility. The posts contained links to purportedly patched versions of VS Code extensions hosted on external services such as Google Drive. Clicking these links led to a redirection chain that executed a JavaScript reconnaissance script, collecting victims' system information and sending it to the attackers' command-and-control server. This campaign highlights the increasing sophistication of social engineering attacks targeting developers through trusted platforms. Similar tactics have been observed in previous incidents, such as the March 2025 phishing campaign that targeted 12,000 GitHub repositories with fake security alerts, leading to unauthorized access to developers' accounts and repositories. The recurrence of such attacks underscores the need for heightened vigilance and robust security practices within the developer community.
4 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

