✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3277 to 3288 of 5245
US ATM Jackpotting: Tren de Aragua's Ploutus Malware Heist Exposed
In late 2025 and early 2026, US law enforcement charged 31 additional suspects in a major campaign of ATM jackpotting attacks attributed to the Venezuelan criminal gang Tren de Aragua. The attackers breached numerous ATMs across the United States, installing Ploutus malware by physically accessing internal components and deploying malware to force the machines to dispense large quantities of cash. The sophisticated attacks leveraged swapped hard drives or infected USB devices and allowed the perpetrators to launder stolen funds internationally, inflicting millions of dollars in losses on banks and credit unions. To date, over 87 individuals have been charged in this transnational criminal scheme. This incident highlights the evolving tactics of financially motivated threat groups combining physical access and technical expertise. The designation of Tren de Aragua as a Foreign Terrorist Organization underscores law enforcement’s recognition of cyber-enabled financial crime as a national security threat and signals intensified global scrutiny on such operations.
6 months ago
Kill Chain
HoneyMyte 2025 Cyberespionage Hits: Updated CoolClient and Credential Theft Campaigns
Between 2024 and 2025, the advanced persistent threat group HoneyMyte (aka Mustang Panda, Bronze President) orchestrated advanced espionage campaigns targeting government entities across Southeast Asia, Mongolia, Malaysia, Myanmar, and Europe. Using updated CoolClient backdoors, custom browser credential stealers, and sophisticated prying scripts, HoneyMyte achieved persistent access, broad network infiltration, and the theft of sensitive documents, credentials, and operational intelligence. Attackers exploited signed DLL sideloading, launched post-exploitation scripts, and used public file-sharing services for covert exfiltration, successfully bypassing traditional defense layers and maintaining long-term surveillance on official targets. This incident highlights the evolving techniques of APT campaigns with growing reliance on multi-stage malware, encrypted traffic, and cloud-based exfiltration channels. The sophistication and persistence demonstrated by HoneyMyte reflect a broader rise in state-sponsored cyber espionage, posing continuing challenges for organizations' detection and regulatory compliance efforts in 2025.
6 months ago
Kill Chain
Mustang Panda’s CoolClient Infostealer: 2026 Global Espionage Campaign Unveiled
In January 2026, Chinese state-sponsored group Mustang Panda leveraged an updated version of its CoolClient backdoor to conduct targeted espionage campaigns against government organizations in Myanmar, Mongolia, Malaysia, Russia, and Pakistan. The attackers used legitimate Sangfor software for initial infection and subsequently deployed tailored infostealers that extracted login credentials from major browsers, monitored clipboard data, and profiled compromised systems. The operation featured advanced tactics such as DLL side-loading, remote shell plugins, encrypted multi-stage payloads, and the use of public cloud services (via hardcoded tokens) for stealthy data exfiltration. This breach highlights the rapid advancement and operational innovation among state-backed APT actors, particularly regarding infostealer deployment and C2 evasion using legitimate cloud infrastructure. Organizations in APAC, government, and critical infrastructure sectors remain top targets as attacker toolsets evolve to bypass both endpoint and network security controls.
6 months ago
Kill Chain
2026 Fortinet Zero-Day SSO Breach: How Authentication Bypass Exposed Critical Devices
In January 2026, Fortinet disclosed a critical zero-day vulnerability (CVE-2026-24858) in its FortiCloud SSO authentication mechanism that allowed attackers to bypass security controls and gain unauthorized administrative access to FortiOS, FortiManager, and FortiAnalyzer devices. By leveraging rogue FortiCloud accounts, threat actors exploited an alternate authentication path—even on fully patched systems—to create new local admin and VPN-enabled accounts, exfiltrating firewall configuration data from customer environments within seconds. Fortinet mitigated active attacks by disabling vulnerable FortiCloud SSO connections and initiating global blocks before a patch was available, but over 25,000 devices were at risk during the attack window. This incident is highly relevant due to the growing sophistication and automation of supply chain and SSO-based attacks, with adversaries increasingly targeting trusted cloud management platforms. The event underscores the need for stricter access controls, rapid incident response capabilities, and heightened vigilance around identity infrastructure, especially as SAML and SSO adoption expands in modern enterprises.
6 months ago
Kill Chain
Cellbreak: Critical Grist-Core Vulnerability Enables Remote Code Execution
In January 2026, a critical vulnerability (CVE-2026-24002, codename Cellbreak, CVSS 9.1) was disclosed in Grist-Core, an open-source spreadsheet-database platform. The flaw enabled attackers to leverage malicious spreadsheet formulas for remote code execution (RCE) on self-hosted Grist-Core servers. This vulnerability could grant adversaries full foothold on affected systems, leading to potential data exfiltration, lateral movement, and operational disruption for organizations running vulnerable deployments. Security researchers at Cyera Research Labs made the discovery public after coordinated disclosure and a patch release by Grist developers. The incident is particularly relevant due to the sharp increase in attacks targeting spreadsheet and application logic vulnerabilities—especially in open-source business tools. As attackers pivot toward supply chain and SaaS entry points, control weaknesses involving user-supplied formulas and embedded code in collaborative apps persist as a high-risk vector.
6 months ago
Kill Chain
Microsoft Office 2026 Zero-Day Forces Emergency Patch After Widespread Exploitation
In January 2026, Microsoft urgently released an out-of-band security update to address a high-severity zero-day vulnerability, CVE-2026-21509, in Microsoft Office. This security feature bypass flaw allowed attackers to exploit untrusted inputs, enabling unauthorized code execution through manipulated Office documents. The active exploitation of this vulnerability led to significant exposure for organizations relying on Office, making endpoints susceptible to malware deployment and data compromise. Microsoft’s swift emergency patch was in response to in-the-wild attacks observed by security researchers and incident response teams. This incident underscores the persistent threat of zero-day exploits targeting widely used productivity platforms. Attacker tactics are evolving to bypass conventional controls, driving urgency around proactive patch management and advanced threat detection to mitigate business disruption and data loss.
6 months ago
Kill Chain
Pakistan-Linked APT Launches Gopher Strike & Sheet Attack Against Indian Government in 2025
In September 2025, cybersecurity researchers uncovered coordinated cyber campaigns—dubbed Gopher Strike and Sheet Attack—targeting Indian government entities. Attributed to a Pakistan-linked Advanced Persistent Threat (APT) group, the operations leveraged novel, undocumented tactics involving phishing and multi-stage malware to compromise government networks. Attackers exploited existing security gaps, conducted lateral movement, and exfiltrated sensitive data, threatening the confidentiality and integrity of official communications. The campaigns remained undetected for an extended period, highlighting the advanced tradecraft and persistent nature of the threat actor. These incidents underscore the growing risk posed by state-aligned actors employing increasingly sophisticated tactics to target critical government infrastructure. The discovery of new tools and techniques in these attacks signals an escalation in South Asian regional cyber conflict and emphasizes the need for updated security controls and rapid detection capabilities.
6 months ago
Kill Chain
Sandworm Wiper Campaign Frustrated at Poland Power Grid
In May 2024, cyber researchers reported a high-profile attack attempt targeting Poland’s power grid infrastructure. The operation was attributed to Sandworm, a Russian APT group notorious for wiper malware and sabotage against critical national infrastructure. Attackers leveraged custom malware designed to disrupt grid operations, but strong detection and security controls reportedly thwarted the attempt, preventing widespread outages. The incident highlighted Sandworm’s persistent focus on critical infrastructure in Central Europe and their evolving tactics for sabotaging operational technology environments. This case underscores a larger trend of state-aligned threat actors targeting energy and critical infrastructure in Europe, leveraging specialized wiper tools and lateral movement techniques. It also emphasizes increasing cross-border cyber risk as geopolitical tensions escalate and underscores new regulatory scrutiny for critical sectors.
6 months ago
Kill Chain
CISA Flags Five Actively Exploited Vulnerabilities in 2026 KEV Catalog Update
In January 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added five high-risk vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation. These include flaws in the Linux Kernel, SmarterTools SmarterMail, Microsoft Office, and GNU InetUtils. Threat actors exploited these vulnerabilities through methods such as authentication bypass, unrestricted file upload, security feature bypass, and argument injection, targeting both federal and private sector networks. Rapid exploitation can lead to unauthorized access, data exfiltration, or further compromise of organizational systems if not promptly remediated. This evolving threat landscape highlights an ongoing wave of opportunistic and targeted attacks leveraging widely used enterprise, email, and infrastructure software. The addition of these CVEs to the KEV Catalog underscores regulatory pressure and the increased urgency for organizations of all sizes to prioritize patch management and mitigate exposure to active threats.
6 months ago
Kill Chain
How 2024 Romance Scams Use WhatsApp Social Engineering: An Inside Look
In early 2024, security researchers investigated the initial phases of romance scams conducted over WhatsApp, where attackers use social engineering tactics to engage targets. Scammers made initial contact using 'wrong number' messages, then rapidly built rapport through flattering responses and fabricated personal stories. Over the span of several weeks, operators established credibility by sharing career details, transitioning conversations to new phone numbers, and sharing lifestyle photos to lay groundwork for future financial scams. The observed campaigns were early-stage but designed to emotionally manipulate victims for eventual financial exploitation. This incident spotlights the refined playbooks, multi-operator approaches, and psychological grooming now typical in romance scams. With surges in digital-first communication and persistent threat actor innovation, such social engineering exploits pose a significant and evolving risk to individuals and businesses alike.
6 months ago
Kill Chain
VMware vCenter RCE Flaw Actively Exploited: What Security Teams Need to Know
In January 2026, a critical vulnerability (CVE-2024-37079) in VMware vCenter Server was confirmed as actively exploited in the wild. This heap overflow flaw within the DCERPC protocol implementation enables unauthenticated remote attackers with network access to execute arbitrary code on vulnerable vCenter Server systems. The compromise does not require user interaction or elevated privileges, making attacks relatively low-effort and high-impact. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a directive mandating all federal agencies to remediate the issue within three weeks, underscoring its urgency and operational risk. No temporary mitigations exist, leaving patching as the sole defense for affected environments. This incident highlights a continued trend of attackers targeting management and orchestration layers in hybrid-cloud and virtualized infrastructures. The lack of workarounds, combined with rapid weaponization, points to increasing risks for organizations who delay patching and underlines regulatory pressure on timely remediation for critical zero-day vulnerabilities.
6 months ago
Kill Chain
NPM Supply Chain Bypass: PackageGate and Shai-Hulud Exploits Expose Open-Source Risks in 2026
In January 2026, critical vulnerabilities dubbed "PackageGate" were revealed in NPM and several popular JavaScript package managers, exposing gaps in defenses against supply chain attacks like last year's Shai-Hulud incidents. Despite previous security improvements, attackers could still bypass NPM's safeguard against malicious package scripts by leveraging Git dependencies and malicious .npmrc configuration files, leading to unauthorized code execution—even when script blocking features were enabled. The flaws, discovered by Koi Security researchers, allowed full code compromise and had potential for massive developer credential and secret exfiltration, threatening tens of thousands of projects and their downstream users. These findings highlight the persistent risks in open-source supply chains and the accelerating pace of software supply chain attacks. As threat actors become more adept at exploiting package management tools, organizations face renewed urgency to bolster visibility, enforce granular access controls, and adopt defense-in-depth measures to protect development workflows and critical assets.
6 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

