✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3289 to 3300 of 5245
Microsoft Patches Active Office Zero-Day: What Your Security Team Must Know
In June 2024, Microsoft urgently released security patches addressing a high-severity zero-day vulnerability in Microsoft Office. Threat actors exploited this flaw in-the-wild prior to disclosure, using malicious documents to achieve remote code execution and gain access to targeted systems without user awareness. The vulnerability impacted multiple Office versions, with proof-of-concept exploits circulating even before patch release. Microsoft’s security teams identified active exploitation, prompting swift response to curb potential corporate data exposure, loss of confidentiality, and operational disruption for both private and public sector users worldwide. This incident spotlights the persistent risk of zero-day exploits in mainstream productivity software. It underscores both attackers’ increasing sophistication in rapidly weaponizing new vulnerabilities and the escalating need for organizations to prioritize timely patch application and robust monitoring to mitigate the business impact of emerging threats.
6 months ago
Kill Chain
Konni APT Leverages AI-Generated PowerShell to Breach Blockchain Developers
In January 2026, the North Korean-linked APT group Konni conducted a sophisticated phishing campaign targeting blockchain developers and engineering teams in Japan, Australia, and India. Using AI-generated PowerShell malware, attackers successfully penetrated targeted organizations by delivering malicious payloads through convincing spear-phishing emails. Once inside, the adversaries leveraged lateral movement and exfiltration techniques to access sensitive intellectual property and digital assets, expanding their historical targeting beyond South Korea and parts of Europe. The breach underscores the evolution of attacker tradecraft—adopting AI to evade traditional defenses and efficiently craft malicious code. This incident is highly relevant as it marks a notable surge in both AI-driven malware and the targeting of the blockchain sector. With threat actors broadening their geographic reach and operational sophistication, organizations must urgently re-evaluate their security controls, specifically around code execution, endpoint monitoring, and identity access management, to defend against emerging threats.
6 months ago
Kill Chain
Blackmoon Malware Hits Indian Taxpayers Through Sophisticated Phishing in 2026
In January 2026, Indian users became the focus of a sophisticated cyber espionage campaign involving tax-themed phishing emails masquerading as legitimate communications from the Income Tax Department of India. These emails distributed malicious archive files, which, once opened, executed the infostealer Blackmoon malware. This multi-stage attack enabled threat actors to quietly exfiltrate personal and financial information from compromised systems, potentially exposing sensitive tax details and compromising the victims' digital environments. The attackers applied advanced phishing techniques and evasion tactics to bypass traditional security defenses and maintain persistent access. This incident highlights a broader trend in targeted social engineering attacks leveraging local themes and timely events to increase victim engagement. The resurgence of infostealer malware like Blackmoon underscores the importance of endpoint protection, awareness training, and zero trust controls, particularly in high-risk seasons such as tax filing periods.
6 months ago
Kill Chain
Malicious AI-Powered VS Code Extensions Trigger Global Supply Chain Breach (2026)
In January 2026, cybersecurity researchers uncovered that two widely-distributed AI-powered Microsoft Visual Studio Code extensions, with over 1.5 million combined installs, were covertly exfiltrating developer source code and sensitive project data to servers based in China. The malicious extensions masqueraded as legitimate AI coding tools, enticing developers globally through the official VS Code marketplace. Once installed, these extensions surreptitiously uploaded confidential code and intellectual property, potentially endangering enterprise software assets and customer data. Investigators highlighted the supply chain risk, noting the threat’s scalability via trusted software distribution channels and the delays in detecting such activity. This incident underscores the escalating risks associated with third-party development tools, particularly those leveraging AI branding. The popularity and trust in official marketplaces can allow sophisticated advanced persistent threats (APTs) or criminal groups to exploit developers and organizations, necessitating enhanced scrutiny and continuous security monitoring of supply chain dependencies.
6 months ago
Kill Chain
DPRK's Konni: AI-Generated Backdoor Hits Blockchain Developers in 2024
In early 2024, the North Korean threat group Konni launched a sophisticated supply-chain attack targeting blockchain developers by deploying an AI-generated PowerShell backdoor within compromised development environments. The operation exploited development tools to surreptitiously gain access to cryptocurrency assets, leveraging advanced evasion techniques and encrypted communications to avoid detection. Victims faced risks of cryptocurrency theft, business disruption, and potential regulatory exposure, with the attackers demonstrating a deep understanding of both blockchain technologies and modern security controls. This incident highlights the growing convergence of AI-generated malware and targeted supply-chain attacks, especially against financially lucrative industries like cryptocurrency. As threat actors increasingly leverage custom malware and automated tools, organizations with high-value digital assets face mounting pressure to improve internal visibility, zero-trust enforcement, and incident response capabilities.
6 months ago
Kill Chain
Exposed Environment Files: The $(pwd) Webserver Reconnaissance Surge of Jan 2026
In January 2026, multiple sensors and the SANS Internet Storm Center reported a wave of targeted web application scans probing for exposed environment and configuration files on webservers using the /$(pwd)/ path pattern. Attackers, active since at least January 13th, systematically searched for sensitive files such as .env, docker-compose.yml, and terraform.tfstate, potentially exposing credentials and secrets. Two identified IP addresses (185.177.72.52, 185.177.72.23) led these scans, illustrating an automated approach likely leveraging misconfigured servers. While no confirmed breaches have been disclosed, such activity significantly raises the risk of follow-on exploitation or credential theft if vulnerable files are found. This incident highlights growing attacker sophistication in discovering misconfigurations and automating reconnaissance. The use of predictable directory traversal patterns and attempts to surface hidden files underscore the need for robust web application hardening and monitoring, especially as threat actors increasingly leverage similar tactics to bypass traditional defenses.
6 months ago
Kill Chain
ShinyHunters 2026: SSO Vishing Attacks Trigger Major SaaS Data Breaches
In January 2026, the cybercriminal group ShinyHunters orchestrated a series of sophisticated voice-phishing (vishing) attacks targeting corporate Single Sign-On (SSO) platforms, including Okta, Microsoft Entra, and Google. The attackers posed as IT support staff, manipulated employees into entering their credentials and multi-factor authentication tokens on fake login pages, and subsequently gained unauthorized access to SSO accounts. Leveraging these credentials, ShinyHunters accessed numerous connected SaaS applications such as Salesforce, Microsoft 365, and Slack, harvesting sensitive corporate data that was later used for extortion demands. High-profile organizations like SoundCloud, Betterment, and Crunchbase reported breaches and data losses as a result. This incident underscores a significant evolution in social engineering tactics, with attackers combining real-time phishing kits and vishing to bypass MFA and access a wide swath of corporate resources. As threat actors increasingly exploit identity-driven weaknesses and leverage SSO misconfigurations, organizations face greater risks of multi-system compromise and regulatory fallout.
6 months ago
Kill Chain
Sandworm’s Failed DynoWiper Attack on Poland’s Energy Grid: A 2025 Nation-State Case Study
In late December 2025, Polish energy infrastructure was targeted in a sophisticated cyberattack attributed to Sandworm, a notorious Russian state-sponsored hacking group. The attackers attempted to deploy 'DynoWiper', a destructive data-wiping malware, against two combined heat and power facilities and key management systems for renewable energy assets. Although the wiper aimed to erase files and render systems inoperable, Polish officials confirmed the attack was detected and mitigated before operational disruption occurred. Attribution to Sandworm, linked to Russia’s GRU, underscores continued targeting of critical infrastructure by advanced persistent threats. This incident is highly relevant given the continued escalation of cyber operations against national infrastructure, particularly in Europe. It highlights the evolving use of destructive malware by state-backed actors and signals the necessity for robust cross-sector cyber defenses and detection mechanisms.
6 months ago
Kill Chain
Sandworm’s DynoWiper Attack on Poland’s Power Grid: How Cyberdefenders Stopped a Nation-State Threat
In late December 2025, Poland’s power sector faced the largest cyberattack in its history, attributed to the notorious Russian state-backed Sandworm group. The attackers deployed a new destructive malware strain dubbed DynoWiper, attempting to disrupt critical energy operations by wiping systems within operational networks. Polish cyber defense teams identified the attack early through advanced threat monitoring and contained the threat before any operational damage occurred. No loss of service or data was reported, and authorities confirmed that core infrastructure remained uncompromised. The incident has intensified scrutiny of nation-state threats to Europe’s energy grid, reinforcing calls for resilient cybersecurity postures across all critical infrastructure assets. Sandworm’s use of a novel wiper malware and focus on lateral movement echo a sharp uptick in high-impact, geopolitically motivated attacks targeting EU utilities. This case highlights the growing sophistication and persistence of nation-state cyber operations, raising fresh challenges for defenders in the energy sector and beyond.
6 months ago
Kill Chain
Russian Organizations Hit by Advanced Multi-Stage Phishing with Amnesia RAT and Ransomware
In January 2026, a sophisticated multi-stage phishing campaign targeted Russian organizations, leveraging social engineering emails that contained tampered business documents. These lures delivered a remote access trojan (Amnesia RAT) alongside ransomware, allowing attackers to establish stealthy persistence and ultimately encrypt sensitive data for extortion. The threat actors employed layered infection chains, executed lateral movement within infected environments, and exfiltrated critical information before deploying ransomware. The attack resulted in operational disruptions and financial risk for affected businesses. This incident reflects an escalating trend of multi-vector threats where initial phishing access rapidly pivots to advanced malware implants and ransomware. Security leaders must recognize the evolving sophistication and automation in phishing and malware delivery, and reinforce layered defenses, monitoring, and incident response to counter multi-stage cyber attacks.
6 months ago
Kill Chain
Konni Deploys AI-Built Malware Against Blockchain Engineers in 2026 Cyber Campaign
In January 2026, the North Korean-linked Konni APT (also known as Opal Sleet or TA406) launched a targeted cyber campaign against blockchain developers and engineers in the Asia-Pacific region, deploying bespoke PowerShell malware suspected of being generated using AI tools. Attackers lured victims with Discord-hosted ZIP files containing malicious shortcut links that, when launched, initiated a multi-stage infection chain. This included staged extraction of obfuscated PowerShell backdoors, privilege detection, scheduled task creation for persistence, and hourly beaconing to a remote command-and-control server. The malware focused on extracting sensitive development environment credentials, API keys, and potentially cryptocurrency wallet access, posing significant risks to both individuals and organizations handling blockchain assets. This incident exemplifies a sharp escalation in attacker sophistication, particularly the operational use of AI-powered malware, accelerating the pace at which advanced persistent threats can scale, adapt, and evade detection. As malicious actors increasingly leverage generative AI to develop modular, well-commented, and evasive code, organizations in crypto and other high-value sectors face a heightened need for adaptive security controls and rapid incident detection to keep defenses aligned with evolving attack techniques.
6 months ago
Kill Chain
CISA Urgently Flags Critical VMware vCenter Vulnerability (CVE-2024-37079) Amid Active Exploitation
In June 2024, a critical heap overflow vulnerability (CVE-2024-37079) affecting Broadcom VMware vCenter Server was identified and patched, but active exploitation was confirmed shortly thereafter. On January 10, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog after evidence surfaced of attackers leveraging the bug to execute unauthorized code remotely. Malicious actors could use this exploit to gain privileged access, conduct lateral movement, and potentially exfiltrate sensitive data or disrupt operations in environments utilizing unpatched vCenter servers. The incident underscores the continued targeting of core virtualization infrastructure by sophisticated threat actors and ransomware groups. With threat actors rapidly exploiting newly disclosed vulnerabilities, unpatched critical systems are at heightened risk, prompting urgency for patch management and layered security controls across enterprise environments.
6 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

