✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 2689 to 2700 of 5177
Chinese Cyber Threat Targets Asian Critical Infrastructure
Since at least 2020, a Chinese-speaking threat actor identified as CL-UNK-1068 has been conducting cyber-espionage campaigns targeting critical infrastructure sectors across South, Southeast, and East Asia. The sectors affected include aviation, energy, government, law enforcement, pharmaceuticals, technology, and telecommunications. The attackers exploit vulnerabilities in public-facing web servers to gain initial access, deploying web shells like GodZilla and AntSword to maintain control. They employ tools such as Mimikatz and LsaRecorder for credential theft, and utilize custom malware alongside open-source utilities to facilitate lateral movement and data exfiltration. ([darkreading.com](https://www.darkreading.com/threat-intelligence/chinese-cyber-threat-critical-asian-sectors?utm_source=openai))This incident underscores the persistent and evolving nature of cyber threats from state-sponsored actors, particularly those linked to China. The use of sophisticated tools and techniques highlights the need for organizations to enhance their cybersecurity measures to detect and mitigate such threats effectively. ([darkreading.com](https://www.darkreading.com/threat-intelligence/chinese-cyber-threat-critical-asian-sectors?utm_source=openai))
5 months ago
Kill Chain
AirSnitch: Unveiling the 2026 Wi-Fi Vulnerability
In February 2026, researchers from the University of California, Riverside, and KU Leuven's DistriNet lab unveiled 'AirSnitch,' a novel attack that exploits fundamental flaws in Wi-Fi client isolation mechanisms. By leveraging cross-layer identity desynchronization, AirSnitch enables attackers to perform full bidirectional man-in-the-middle (MitM) attacks, allowing them to intercept and modify data between clients on the same network. This vulnerability affects a wide range of devices, including consumer routers from Netgear, Tenda, D-Link, TP-Link, and Asus, as well as enterprise hardware from Ubiquiti and Cisco. The attack is particularly concerning as it bypasses existing Wi-Fi encryption protocols without the need to crack them, posing significant risks to both home and enterprise networks. ([arstechnica.com](https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/?utm_source=openai)) The discovery of AirSnitch underscores the urgent need for standardized and robust client isolation implementations in Wi-Fi networks. As the attack exploits architectural weaknesses rather than specific software flaws, addressing this vulnerability requires coordinated efforts from hardware manufacturers, software developers, and standards organizations to enhance the security of wireless communications. ([cyberkendra.com](https://www.cyberkendra.com/2026/02/new-airsnitch-attack-bypasses-wpa2-and.html?utm_source=openai))
5 months ago
Kill Chain
Cybercriminals Exploit .arpa Domains and IPv6 to Bypass Phishing Defenses
In March 2026, cybersecurity researchers identified a sophisticated phishing campaign exploiting the .arpa top-level domain (TLD) and IPv6 reverse DNS to bypass traditional security measures. Attackers acquired IPv6 address blocks and manipulated reverse DNS zones to create deceptive subdomains under the ip6.arpa domain. These subdomains hosted phishing sites that impersonated legitimate brands, luring victims through emails promising rewards or account notifications. The use of .arpa domains, typically reserved for internet infrastructure, allowed these malicious sites to evade detection by standard domain reputation checks and email security gateways. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hackers-abuse-arpa-dns-and-ipv6-to-evade-phishing-defenses/?utm_source=openai)) This incident underscores a growing trend where threat actors exploit lesser-known internet protocols and infrastructure to conduct attacks. The abuse of reserved domains like .arpa highlights the need for enhanced monitoring and security measures that encompass all facets of the DNS ecosystem. Organizations must adapt to these evolving tactics to protect against increasingly sophisticated phishing schemes. ([infoblox.com](https://www.infoblox.com/blog/threat-intelligence/abusing-arpa-the-tld-that-isnt-supposed-to-host-anything/?utm_source=openai))
5 months ago
Kill Chain
Velvet Tempest's Use of 'ClickFix' in Recent Cyber Intrusion
Between February 3 and 16, 2026, the threat group Velvet Tempest (also known as DEV-0504) conducted a sophisticated cyber intrusion targeting a U.S. non-profit organization with over 3,000 endpoints and 2,500 users. Utilizing a malvertising campaign, they employed the 'ClickFix' technique, deceiving victims into executing obfuscated commands via the Windows Run dialog. This led to the deployment of DonutLoader and the CastleRAT backdoor, facilitating credential harvesting and extensive reconnaissance. Notably, while Velvet Tempest is known for deploying various ransomware strains, including Ryuk, REvil, and Conti, the Termite ransomware was not executed in this particular incident. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/termite-ransomware-breaches-linked-to-clickfix-castlerat-attacks/?utm_source=openai)) This incident underscores the evolving tactics of ransomware affiliates, highlighting the use of social engineering techniques like 'ClickFix' to gain initial access. The absence of immediate ransomware deployment suggests a strategic shift towards prolonged network infiltration and data exfiltration, posing significant challenges for detection and mitigation.
5 months ago
Kill Chain
Microsoft Reports Surge in AI-Powered Cyberattacks in 2026
In March 2026, Microsoft reported a significant increase in cyberattacks leveraging artificial intelligence (AI) across all stages of the attack lifecycle. Threat actors utilized generative AI tools for tasks such as reconnaissance, phishing, infrastructure development, malware creation, and post-compromise activities. Notably, North Korean groups like Jasper Sleet (Storm-0287) and Coral Sleet (Storm-1877) employed AI to craft realistic digital personas, enabling them to infiltrate Western organizations under the guise of remote IT workers. This strategic use of AI allowed attackers to accelerate operations, scale malicious activities, and lower technical barriers, resulting in more sophisticated and efficient cyberattacks. The current relevance of this incident lies in the escalating trend of AI-powered cyber threats. As AI technologies become more accessible, both state-sponsored and financially motivated actors are increasingly integrating AI into their operations. This evolution necessitates that organizations enhance their cybersecurity measures to detect and mitigate AI-driven attacks effectively.
5 months ago
Kill Chain
OpenAI Codex Security: Revolutionizing Vulnerability Detection with AI
In March 2026, OpenAI introduced Codex Security, an AI-powered security agent designed to identify, validate, and propose fixes for software vulnerabilities. During its beta phase, Codex Security scanned over 1.2 million commits across various repositories, uncovering 792 critical and 10,561 high-severity issues in open-source projects such as OpenSSH, GnuTLS, GOGS, Thorium, libssh, PHP, and Chromium. The tool leverages advanced AI models to build deep context about projects, enabling it to detect complex vulnerabilities that traditional tools might miss, thereby improving the security posture of software systems. The release of Codex Security underscores a growing trend in the cybersecurity landscape: the integration of artificial intelligence to enhance vulnerability detection and remediation processes. As software development accelerates and systems become more complex, AI-driven tools like Codex Security are becoming essential in proactively identifying and addressing security flaws, thereby reducing the risk of exploitation and enhancing overall system resilience.
5 months ago
Kill Chain
Anthropic's AI Model Enhances Firefox Security by Identifying 22 Vulnerabilities
In January 2026, Anthropic's AI model, Claude Opus 4.6, identified 22 security vulnerabilities in Mozilla's Firefox browser during a two-week collaboration. Of these, 14 were classified as high-severity, seven as moderate, and one as low. The vulnerabilities were promptly addressed in Firefox version 148, released in February 2026. This effort involved scanning nearly 6,000 C++ files and submitting 112 unique reports, highlighting the efficiency of AI in enhancing software security. ([thehackernews.com](https://thehackernews.com/2026/03/anthropic-finds-22-firefox.html?utm_source=openai)) This incident underscores the growing role of AI in cybersecurity, demonstrating its capability to uncover significant vulnerabilities in well-established software. The collaboration between Anthropic and Mozilla exemplifies how AI can augment traditional security measures, leading to more robust and secure applications. ([blog.mozilla.org](https://blog.mozilla.org/en/firefox/hardening-firefox-anthropic-red-team/?utm_source=openai))
5 months ago
Kill Chain
North Korean AI-Enhanced Fake Worker Schemes: A 2026 Cybersecurity Threat
In early 2026, Microsoft reported that North Korean state-sponsored groups, notably Jasper Sleet and Coral Sleet, have been leveraging artificial intelligence to enhance their longstanding schemes of infiltrating Western companies by posing as remote IT workers. These operatives utilize AI tools to generate realistic fake identities, including culturally appropriate names and professional headshots, and employ voice-changing software during interviews to mask their accents. Once hired, they use AI to craft professional communications and generate code, aiming to maintain employment and funnel earnings back to the North Korean regime. This sophisticated use of AI has significantly increased the scale and effectiveness of their operations, posing substantial risks to targeted organizations. ([theguardian.com](https://www.theguardian.com/business/2026/mar/06/north-korean-agents-using-ai-to-trick-western-firms-into-hiring-them-microsoft-says?utm_source=openai)) The urgency of this threat is underscored by the rapid advancement and accessibility of AI technologies, which lower the barrier for executing complex social engineering attacks. Organizations must enhance their hiring and security protocols to detect and prevent such infiltrations, as the potential for data breaches and financial losses continues to escalate.
5 months ago
Kill Chain
FBI's Surveillance Systems Breached in 2026 by Salt Typhoon
In March 2026, the FBI confirmed a breach affecting systems used to manage surveillance and wiretap warrants. The agency identified and addressed suspicious activities on its networks, leveraging all technical capabilities to respond. While the FBI did not disclose the full scope or impact, the incident underscores the vulnerability of critical law enforcement infrastructure to cyber threats. This breach is part of a broader pattern of cyber espionage activities attributed to state-sponsored actors, notably the Chinese group known as Salt Typhoon. In 2024, Salt Typhoon compromised U.S. federal government systems used for court-authorized network wiretapping requests, highlighting the persistent and evolving nature of cyber threats targeting sensitive government operations.
5 months ago
Kill Chain
Beware: Fake Claude Code Install Guides Spreading Infostealer Malware
In March 2026, threat actors launched a campaign utilizing a new social engineering technique called InstallFix to distribute the Amatera Stealer malware. By cloning legitimate installation pages for popular command-line interface (CLI) tools like Anthropic's Claude Code, attackers inserted malicious commands into the installation instructions. These fake pages were promoted through malvertising campaigns on Google Ads, leading unsuspecting users to execute harmful commands that installed the infostealer on their systems. The Amatera Stealer is designed to exfiltrate sensitive data, including credentials and cryptocurrency wallets, from compromised devices. This incident underscores the evolving nature of social engineering attacks, particularly those exploiting the trust users place in official-looking domains and installation guides. As developers and non-technical users increasingly rely on online resources for software installation, the risk of such deceptive tactics grows, highlighting the need for heightened vigilance and verification of sources before executing installation commands.
5 months ago
Kill Chain
Critical Vulnerabilities in Hikvision and Rockwell Automation Devices Added to CISA KEV Catalog
In March 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2017-7921 affecting Hikvision products and CVE-2021-22681 impacting Rockwell Automation devices. CVE-2017-7921 is an improper authentication flaw that allows attackers to escalate privileges and access sensitive information in Hikvision cameras. CVE-2021-22681 involves insufficiently protected credentials in Rockwell Automation's Studio 5000 Logix Designer and related controllers, enabling unauthorized users to bypass verification mechanisms and alter device configurations. Both vulnerabilities have a CVSS score of 9.8, indicating their severity and the potential risk to critical infrastructure. The inclusion of these vulnerabilities in the KEV catalog underscores the ongoing threat posed by unpatched security flaws in widely used industrial and surveillance equipment. Organizations are urged to prioritize remediation efforts to mitigate the risk of exploitation, especially given the active targeting of such vulnerabilities by malicious actors.
5 months ago
Kill Chain
React2Shell: Understanding and Mitigating the Critical React Server Components Vulnerability
In December 2025, a critical vulnerability known as React2Shell (CVE-2025-55182) was discovered in React Server Components, affecting versions 19.0 through 19.2.0. This flaw allows unauthenticated remote code execution via a single malicious HTTP request, enabling attackers to execute arbitrary code on vulnerable servers. Exploitation was observed within hours of disclosure, with state-sponsored groups from China and North Korea actively targeting affected systems. The rapid exploitation underscores the vulnerability's severity and the need for immediate remediation. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2025/12/15/defending-against-the-cve-2025-55182-react2shell-vulnerability-in-react-server-components/?msockid=3159dd8396d16eca0085cb7697616f99&utm_source=openai)) The widespread use of React in web applications amplifies the risk, as many organizations may unknowingly be exposed. This incident highlights the critical importance of prompt patching and vigilant monitoring to defend against rapidly evolving cyber threats. ([aws.amazon.com](https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/?utm_source=openai))
5 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

