✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 313 to 324 of 5034
AI-Driven Cyberattacks: Key Insights from Unit 42's 2026 Report
In 2025, Unit 42 responded to over 750 major cyber incidents across various industries and countries. The 2026 Global Incident Response Report highlights that adversaries are leveraging AI to accelerate attack timelines, with data exfiltration occurring up to four times faster than in previous years. Identity weaknesses were exploited in nearly 90% of investigations, and 87% of intrusions involved multiple attack surfaces, including endpoints, networks, cloud services, SaaS platforms, and identity systems. ([paloaltonetworks.com](https://www.paloaltonetworks.com/blog/2026/02/unit-42-global-ir-report/?utm_source=openai)) This trend underscores the urgent need for organizations to enhance their cybersecurity posture by addressing identity vulnerabilities, improving visibility across attack surfaces, and implementing AI-driven defense mechanisms to counteract the speed and complexity of modern cyber threats.
2 weeks ago
Kill Chain
Indictment of Russian Nationals for Bulletproof Hosting Services Facilitating Cyberattacks
In July 2026, U.S. federal prosecutors unsealed an indictment against three Russian nationals—Alexander Alexandrovich Volosovik, Yulia Vladimirovna Pankova, and Kirill Andreevich Zatolokin—accusing them of operating bulletproof hosting services through their companies, Media Land and ML.Cloud. These services allegedly facilitated cyberattacks on critical infrastructure across 21 U.S. states and several countries, resulting in over $62 million in damages. The indictment details how the accused provided infrastructure and technical support to cybercriminals, enabling malware distribution, ransomware attacks, and other illicit activities. ([cyberscoop.com](https://cyberscoop.com/russian-nationals-medialand-mlcloud-indicted-bulletproof-hosting/?utm_source=openai)) This case underscores the persistent threat posed by bulletproof hosting providers, which offer cybercriminals resilient infrastructure to conduct attacks with impunity. The indictment highlights the necessity for international cooperation in dismantling such networks and protecting critical infrastructure from cyber threats. ([cyberscoop.com](https://cyberscoop.com/russian-nationals-medialand-mlcloud-indicted-bulletproof-hosting/?utm_source=openai))
2 weeks ago
Kill Chain
Scattered Spider's 2024 Cyberattack on Transport for London: A Case Study
Between August 31 and September 3, 2024, the cybercriminal group Scattered Spider executed a sophisticated cyberattack on Transport for London (TfL). Utilizing social engineering techniques, they infiltrated TfL's network, leading to significant disruptions in technical services, including the Oyster payment system and third-party APIs. The attack necessitated a mass password reset for all 28,000 TfL employees and resulted in financial losses estimated at £29 million. ([nationalcrimeagency.gov.uk](https://www.nationalcrimeagency.gov.uk/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted?utm_source=openai)) This incident underscores the escalating threat posed by cybercriminal groups employing advanced social engineering tactics to target critical infrastructure. Organizations must enhance their cybersecurity measures, particularly in employee training and network security protocols, to mitigate such risks.
2 weeks ago
Kill Chain
Spirals Ransomware Attack on South Asian IT Firm in June 2026
In June 2026, an IT services firm in South Asia fell victim to a rapid and sophisticated ransomware attack orchestrated by a previously unknown group deploying the 'Spirals' ransomware. The attackers gained initial access through a publicly exposed Internet Information Services (IIS) server, where they uploaded an ASP.NET web shell. Within a three-hour window, they established persistent access, disabled security software, extracted credentials, and moved laterally across the network. Less than 24 hours after the initial breach, the Spirals ransomware was deployed, encrypting files and exfiltrating sensitive data. The attackers threatened to publish the stolen data within six days unless a ransom was paid. This incident underscores the evolving threat landscape, where cybercriminals are executing attacks with unprecedented speed and efficiency. Organizations must reassess their security postures, particularly concerning publicly accessible services and rapid response capabilities, to mitigate such swift and damaging intrusions.
2 weeks ago
Kill Chain
Russian Hackers Exploit WebEx and Zoom Installers to Deploy Starland RAT
In June 2025, the Russian threat actor UAT-11795 initiated a campaign targeting users primarily in the United States, with additional victims in Germany, Romania, and Venezuela. The attackers distributed trojanized installers of legitimate software, including WebEx and Zoom, to deploy the Starland RAT malware. This backdoor enabled the exfiltration of browser data, cryptocurrency wallet assets, system details, and Active Directory information. The malware also facilitated remote command execution, screenshot capture, and the deployment of additional payloads such as CastleStealer and Remcos RAT. This incident underscores the increasing sophistication of supply chain attacks, where trusted software is weaponized to infiltrate systems. The use of trojanized installers highlights the critical need for organizations to enforce strict software sourcing policies and to educate users on the risks of downloading software from unofficial sources.
2 weeks ago
Kill Chain
Urgent: CISA Mandates Patching of Critical Oracle EBS Vulnerability Amid Active Exploitation
In May 2026, Oracle disclosed a critical vulnerability (CVE-2026-46817) in the File Transmission component of its E-Business Suite's Oracle Payments module, affecting versions 12.2.3 through 12.2.15. This flaw allows unauthenticated attackers with HTTP network access to fully compromise the Oracle Payments system. Despite the release of a security patch, by late June 2026, threat intelligence firm Defused observed active exploitation of this vulnerability in the wild. Consequently, on July 15, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-46817 to its Known Exploited Vulnerabilities Catalog and mandated federal agencies to apply the patch by July 18, 2026. This incident underscores the critical importance of timely patch management, especially for vulnerabilities with high CVSS scores and active exploitation. Organizations are urged to assess their exposure to CVE-2026-46817 and ensure that all affected systems are promptly updated to mitigate potential risks.
2 weeks ago
Kill Chain
Scattered Spider's 2024 Cyberattack on Transport for London: A Case Study
In August 2024, Transport for London (TfL) suffered a significant cyberattack orchestrated by the Scattered Spider hacking group. The breach disrupted internal systems and online services, including Dial-a-Ride, concessionary travel cards, digital payments, and contactless ticketing. Approximately 148 systems were rendered inoperable, and all 27,000 TfL employees were required to reset their passwords in person. The attack resulted in £29 million in losses and recovery costs, with potential economic damages estimated at up to £56 billion had the transport network been fully compromised. This incident underscores the escalating threat posed by cybercriminal groups like Scattered Spider, known for their sophisticated social engineering tactics and targeting of critical infrastructure. The successful prosecution of the perpetrators highlights the importance of early cooperation between organizations and law enforcement in mitigating cyber threats and bringing offenders to justice.
2 weeks ago
Kill Chain
23andMe Data Breach: A Wake-Up Call for Credential Security
In October 2023, genetic testing company 23andMe disclosed a significant data breach resulting from credential-stuffing attacks that went undetected for five months, from April to September 2023. Attackers exploited reused passwords to access approximately 14,000 user accounts, subsequently exposing sensitive genetic and personal information of 6.9 million customers. This data was later found for sale on the dark web, raising serious privacy concerns. The incident underscores the critical importance of robust cybersecurity measures, including the implementation of multi-factor authentication and proactive monitoring systems. Organizations handling sensitive data must prioritize these defenses to prevent similar breaches and protect consumer trust.
2 weeks ago
Kill Chain
OkoBot Malware: A New Threat to Cryptocurrency Security
In July 2026, cybersecurity researchers identified OkoBot, a sophisticated malware framework comprising over 20 modules designed to steal cryptocurrency wallet seed phrases, credentials, and other sensitive data. OkoBot infiltrates systems through deceptive ClickFix attacks and malicious GitHub repositories masquerading as legitimate software tools. Once installed, it deploys various payloads, including browser injectors and keyloggers, to harvest user information and monitor activities. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-okobot-framework-deploys-20-payloads-to-steal-data-crypto/?utm_source=openai)) The emergence of OkoBot underscores a growing trend of targeted attacks on cryptocurrency users, highlighting the need for enhanced vigilance and robust security measures within the crypto community. As the malware continues to evolve, staying informed about such threats is crucial for safeguarding digital assets.
2 weeks ago
Kill Chain
Critical Vulnerability in Claude Chrome Extension Exposes User Data
In July 2026, a critical vulnerability was discovered in Anthropic's Claude for Chrome browser extension. This flaw allowed malicious extensions to simulate user interactions, triggering predefined AI actions without user consent. Exploiting this, attackers could access connected services such as Gmail, Google Docs, Google Calendar, and Salesforce, leading to unauthorized data access and potential data exfiltration. The vulnerability stemmed from the extension's failure to verify the origin of click events, accepting synthetic events generated by other extensions as legitimate user actions. This incident underscores the growing risks associated with browser extensions and their integration with AI-powered services. As organizations increasingly adopt such tools to enhance productivity, ensuring robust security measures and thorough validation of user interactions becomes imperative to prevent unauthorized access and data breaches.
2 weeks ago
Kill Chain
ClickLock: The New macOS Malware Exploiting User Trust
In July 2026, cybersecurity researchers identified a new macOS malware named ClickLock, which employs social engineering tactics to deceive users into revealing their system login passwords. The malware initiates by presenting a fake Cloudflare 'human verification' prompt, leading users to execute a command in the Terminal. This action triggers the download of malicious modules that disable keyboard interrupts and suppress system notifications. Subsequently, ClickLock displays a counterfeit macOS password dialog, coercing users into entering their credentials. Upon obtaining the password, the malware exfiltrates sensitive data, including login credentials, cryptocurrency assets, and browser information, to the attackers via Telegram. Additionally, it installs a persistent backdoor, granting ongoing remote access to the compromised systems. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-clicklock-macos-malware-traps-users-into-revealing-login-password/?utm_source=openai)) The emergence of ClickLock underscores a growing trend in macOS-targeted malware leveraging sophisticated social engineering techniques. This incident highlights the necessity for heightened user awareness and the implementation of robust security measures to counteract such deceptive attacks.
2 weeks ago
Kill Chain
Coca-Cola's Fairlife Ransomware Attack Disrupts U.S. Production
In July 2026, The Coca-Cola Company's subsidiary, Fairlife, experienced a ransomware attack that led to unauthorized access to its production-related systems. This breach resulted in the temporary suspension of Fairlife's U.S. production operations. Upon detection, Coca-Cola promptly activated its incident response and business continuity protocols, engaged external cybersecurity experts, and notified law enforcement. The company confirmed that product quality and safety remained unaffected, and Canadian production facilities continued operations without disruption. This incident underscores the escalating threat of ransomware attacks targeting critical infrastructure and supply chains. Organizations must enhance their cybersecurity measures to protect against such disruptions, which can have significant operational and financial repercussions.
2 weeks ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

