✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 2977 to 2988 of 5196
Texas Sues TP-Link Over Chinese Hacking Risks
In February 2026, the Texas Attorney General filed a lawsuit against TP-Link Systems Inc., alleging deceptive marketing practices and security vulnerabilities in their networking devices. The suit claims that TP-Link misled consumers by labeling products as 'Made in Vietnam' while sourcing components from China, potentially exposing users to Chinese state-sponsored cyberattacks. The lawsuit highlights instances where TP-Link routers were exploited by Chinese hacking groups, such as the Quad7 botnet, to conduct credential-theft operations targeting U.S. entities. This legal action underscores the growing concern over supply chain security and the integrity of networking equipment used by consumers and businesses. As cyber threats evolve, ensuring transparency in product sourcing and robust security measures in networking devices becomes increasingly critical to protect against state-sponsored cyber espionage and attacks.
5 months ago
Kill Chain
Nigerian Hacker Sentenced for Tax Firm Breach Using Warzone RAT
Between June 2016 and June 2021, Nigerian national Matthew Abiodun Akande orchestrated a sophisticated cyber intrusion targeting multiple tax preparation firms in Massachusetts. Utilizing phishing emails that impersonated a CEO, Akande deployed the Warzone remote-access trojan (RAT) to infiltrate the firms' networks. This allowed him to steal clients' personal information, leading to the filing of over 1,000 fraudulent tax returns and the illicit collection of more than $1.3 million in refunds. Akande was arrested in October 2024 at London's Heathrow Airport, extradited to the United States in March 2025, and sentenced to eight years in prison in February 2026. ([justice.gov](https://www.justice.gov/usao-ma/pr/nigerian-man-sentenced-eight-years-prison-computer-intrusion-and-theft?utm_source=openai)) This incident underscores the persistent threat posed by sophisticated phishing campaigns and the use of advanced malware like RATs in financial fraud schemes. It highlights the critical need for organizations, especially those handling sensitive client data, to implement robust cybersecurity measures and employee training to prevent such breaches.
5 months ago
Kill Chain
Infostealer Credential Theft Surges 800% in 2025
In 2025, cybercriminals escalated their use of infostealer malware, leading to the theft of 1.8 billion credentials—a staggering 800% increase compared to the previous year. These infostealers infiltrated 5.8 million devices, extracting sensitive data such as login credentials, cookies, and financial information. The stolen credentials were subsequently sold on dark web marketplaces, facilitating further cyberattacks including ransomware and data breaches. Notably, major organizations like Deloitte, KPMG, and Samsung fell victim to these attacks due to inadequate enforcement of multi-factor authentication (MFA), underscoring the critical need for robust security measures. ([infosecurity-magazine.com](https://www.infosecurity-magazine.com/news/staggering-800-rise-infostealer/?utm_source=openai)) This surge in credential theft highlights a significant shift in cybercriminal tactics, emphasizing the exploitation of identity-based vulnerabilities. The convergence of infostealers and ransomware has created rapid extortion chains, where stolen credentials are quickly leveraged to deploy ransomware within organizations. This trend underscores the urgency for businesses to implement comprehensive security strategies, including the enforcement of MFA, regular credential monitoring, and employee education on phishing and malware threats. ([cyfirma.com](https://www.cyfirma.com/research/the-convergence-of-infostealers-and-ransomware-from-credential-harvesting-to-rapid-extortion-chains/?utm_source=openai))
5 months ago
Kill Chain
CRESCENTHARVEST Malware Campaign Exploits Iran Protests to Target Supporters
In early January 2026, a cyberespionage campaign named CRESCENTHARVEST emerged, targeting individuals supporting Iran's anti-government protests. Attackers distributed malicious archive files containing authentic protest media and Farsi-language reports, alongside disguised Windows shortcut (.LNK) files. When executed, these shortcuts deployed a remote access trojan (RAT) capable of executing commands, logging keystrokes, and exfiltrating sensitive data. The campaign's sophistication suggests alignment with Iranian state interests, aiming for long-term surveillance and information theft. This incident underscores the increasing use of geopolitical events as lures in cyberattacks, highlighting the need for heightened vigilance among activists, journalists, and dissidents. The campaign's reliance on social engineering and legitimate-looking media emphasizes the importance of verifying the authenticity of received files, especially those related to sensitive political contexts.
5 months ago
Kill Chain
Massiv Android Trojan Exploits IPTV Apps for Device Takeover Attacks in 2026
In early 2026, cybersecurity researchers identified a new Android trojan named Massiv, which masquerades as IPTV applications to infiltrate devices. Once installed, Massiv enables attackers to remotely control infected devices, facilitating device takeover attacks that lead to unauthorized financial transactions from victims' banking accounts. The malware employs techniques such as screen streaming, keylogging, SMS interception, and fake overlays to steal sensitive information. Notably, it has targeted applications like Portugal's gov.pt, exploiting digital identity systems to bypass Know Your Customer (KYC) verifications and open fraudulent accounts in victims' names. This incident underscores the evolving tactics of cybercriminals who exploit popular app themes to distribute malware, highlighting the need for heightened vigilance among mobile banking users. The use of IPTV app disguises reflects a broader trend of leveraging entertainment-related applications to deceive users, emphasizing the importance of downloading apps only from trusted sources and maintaining robust security practices.
5 months ago
Kill Chain
Microsoft Patches Critical Privilege Escalation Vulnerability in Windows Admin Center
In February 2026, Microsoft disclosed a critical security vulnerability (CVE-2026-26119) in Windows Admin Center, a browser-based management tool for Windows environments. This flaw, rated with a CVSS score of 8.8, stemmed from improper authentication mechanisms, allowing authorized attackers to escalate their privileges over a network. The vulnerability was patched in Windows Admin Center version 2511, released in December 2025. While no active exploitation was reported at the time, Microsoft assessed the likelihood of exploitation as high. This incident underscores the importance of timely software updates and robust authentication protocols. Organizations relying on Windows Admin Center should ensure they have applied the latest patches to mitigate potential risks associated with privilege escalation vulnerabilities.
5 months ago
Kill Chain
AI-Powered Cyberattacks Surge in 2026: A New Era of Cyber Threats
In 2026, the cybersecurity landscape witnessed a significant escalation in AI-powered cyberattacks. Threat actors, including state-sponsored groups from Russia, China, Iran, and North Korea, increasingly leveraged artificial intelligence to automate and enhance their cyber operations. This resulted in a dramatic surge in attack frequency and sophistication, with automated scans reaching 36,000 per second globally. Notably, the ShinyHunters group orchestrated a series of social engineering campaigns targeting enterprise single sign-on (SSO) environments, leading to data breaches at major organizations. Additionally, the first known AI-orchestrated cyberattack was reported by Anthropic, involving a Chinese state-sponsored group using a jailbroken AI tool to conduct a sophisticated cyber-espionage campaign targeting multiple institutions. ([apnews.com](https://apnews.com/article/ad678e5192dd747834edf4de03ac84ee?utm_source=openai)) The current relevance of these incidents is underscored by the rapid evolution of AI-driven cyber threats. The integration of AI into cyberattack methodologies has not only increased the speed and scale of attacks but also introduced new attack vectors, such as AI-generated deepfakes and autonomous agent-driven attacks. This trend highlights the urgent need for organizations to adopt AI-enhanced defensive strategies and continuous threat exposure management to effectively counter these emerging threats. ([apnews.com](https://apnews.com/article/846847536f6feb2bbb423943fd96e1f1?utm_source=openai))
5 months ago
Kill Chain
INTERPOL's Operation Red Card 2.0: A Major Blow to African Cybercrime Networks
Between December 8, 2025, and January 30, 2026, INTERPOL coordinated Operation Red Card 2.0, a collaborative effort involving law enforcement agencies from 16 African countries. This operation targeted transnational cybercriminal networks engaged in high-yield investment scams, mobile money fraud, and fraudulent mobile loan applications. The concerted efforts led to the arrest of 651 individuals, the recovery of over $4.3 million, and the dismantling of 1,442 malicious infrastructures, including IPs, domains, and servers. Investigations revealed that these scams were responsible for financial losses exceeding $45 million, affecting 1,247 victims across Africa and beyond. ([interpol.int](https://www.interpol.int/News-and-Events/News/2026/Major-operation-in-Africa-targeting-online-scams-nets-651-arrests-recovers-USD-4.3-million?utm_source=openai)) The success of Operation Red Card 2.0 underscores the escalating threat posed by organized cybercrime syndicates and highlights the critical importance of international collaboration in combating these pervasive threats. The operation also emphasizes the need for continuous vigilance and proactive measures to protect individuals and businesses from evolving cyber fraud schemes.
5 months ago
Kill Chain
PromptSpy: AI-Enhanced Android Malware Redefines Mobile Threats
In February 2026, cybersecurity researchers identified PromptSpy, the first known Android malware to exploit Google's Gemini AI for persistence. Disguised as a banking app targeting users in Argentina, PromptSpy uses Gemini to analyze on-screen elements and execute gestures that keep it active in the device's recent apps list, preventing easy termination. Beyond persistence, it deploys a VNC module granting attackers remote access to the device, enabling actions like capturing lockscreen data, taking screenshots, and recording screen activity. The malware also employs Android's accessibility services to block uninstallation attempts by overlaying invisible elements on critical buttons. Distribution occurred through dedicated phishing websites impersonating JPMorgan Chase Bank, with evidence suggesting development in a Chinese-speaking environment. ([eset.com](https://www.eset.com/us/about/newsroom/research/eset-research-discovers-promptspy-first-android-threat-using-genai/?utm_source=openai)) This incident underscores the evolving threat landscape where adversaries integrate generative AI into malware, enhancing adaptability across various devices and operating system versions. The use of AI in malware execution flows signifies a shift towards more dynamic and resilient attack methods, posing challenges for traditional detection and mitigation strategies. ([computerweekly.com](https://www.computerweekly.com/news/366639201/PromptSpy-Android-malware-may-exploit-Gemini-AI?utm_source=openai))
5 months ago
Kill Chain
SonicWall's 2025 Cloud Backup Data Breach: A Wake-Up Call for Cloud Security
In September 2025, SonicWall, a prominent cybersecurity firm, experienced a significant data breach affecting all customers utilizing its MySonicWall cloud backup service. Initially, the company reported that fewer than 5% of users were impacted; however, it was later confirmed that every customer using the cloud backup feature was affected. The breach exposed encrypted firewall configuration files containing sensitive data such as network rules, VPN settings, administrative credentials, and service authentication details. Although the files remained encrypted, their exposure heightened the risk of targeted cyberattacks due to the critical nature of the information. SonicWall promptly advised customers to delete existing cloud backups, reset credentials, rotate shared secrets, and transition to local backups to mitigate potential threats. This incident underscores the vulnerabilities inherent in cloud-based services and the importance of robust security measures to protect sensitive data. The breach also highlights the necessity for organizations to maintain vigilance and implement comprehensive security protocols to safeguard against evolving cyber threats.
5 months ago
Kill Chain
Salt Typhoon 2026 Telecom Breach: A Wake-Up Call for Cybersecurity
In early 2026, the Chinese state-sponsored hacking group known as Salt Typhoon executed a sophisticated cyber espionage campaign targeting major telecommunications providers, including AT&T and Verizon. The attackers exploited vulnerabilities in network devices to gain unauthorized access, allowing them to intercept private communications and exfiltrate sensitive data over an extended period. This breach compromised the personal information of millions of users and raised significant concerns about the security of critical infrastructure. The incident underscores the escalating threat posed by nation-state actors to global telecommunications networks. Despite previous sanctions and heightened security measures, Salt Typhoon's continued success highlights the need for more robust defenses and international cooperation to protect against such advanced persistent threats.
5 months ago
Kill Chain
Chinese APT Exploits Dell RecoverPoint Zero-Day Since 2024
In mid-2024, a Chinese state-sponsored threat group, identified as UNC6201, began exploiting a critical zero-day vulnerability (CVE-2026-22769) in Dell's RecoverPoint for Virtual Machines. This flaw, stemming from hardcoded credentials, allowed unauthenticated remote attackers to gain root-level access to affected systems. The attackers utilized this access to deploy backdoors such as BRICKSTORM and later GRIMBOLT, facilitating persistent access and lateral movement within compromised networks. Dell released a patch for this vulnerability in February 2026, urging immediate remediation to prevent further exploitation. ([securityweek.com](https://www.securityweek.com/dell-recoverpoint-zero-day-exploited-by-chinese-cyberespionage-group/?utm_source=openai)) This incident underscores the persistent threat posed by nation-state actors targeting critical infrastructure through zero-day vulnerabilities. The prolonged undetected exploitation highlights the necessity for robust monitoring and rapid response mechanisms to mitigate such sophisticated cyber threats. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/chinese-hackers-exploiting-dell-zero-day-flaw-since-mid-2024/?utm_source=openai))
5 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

