✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3529 to 3540 of 5257
NodeCordRAT Trojan Exposed in npm Bitcoin-Themed Packages (2026)
In November 2025, cybersecurity researchers uncovered a sophisticated supply chain attack involving malicious npm packages—'bitcoin-main-lib', 'bitcoin-lib-js', and 'bip40'—that distributed the remote access trojan NodeCordRAT. Uploaded by the threat actor 'wenmoonx', these packages mimicked legitimate BitcoinJS repositories, leveraging npm’s postinstall scripts to deliver malware hidden in 'bip40'. NodeCordRAT enabled attackers to exfiltrate Chrome credentials, cryptocurrency wallet seed phrases, and sensitive files to Discord-controlled servers, using Discord’s API for covert communication and command execution. This multi-OS campaign potentially impacted thousands of developers before takedown. The incident stands out for its abuse of trusted open-source components, increasing concern across the software supply chain. Its methodology highlights the growing sophistication of attacker tradecraft leveraging developer ecosystems and API-based covert channels, making such threats relevant for all organizations relying on open-source dependencies.
7 months ago
Kill Chain
Cisco Patches ISE Flaw Following Public Exploit Release: What Enterprises Need to Know
In January 2026, Cisco disclosed a medium-severity vulnerability (CVE-2026-20029, CVSS 4.9) in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products after a public proof-of-concept (PoC) exploit was released. The flaw, originating from improper XML parsing in the web-based management interface, could allow authenticated administrators to upload malicious files and read sensitive files from the underlying operating system—data ordinarily inaccessible, even to admins. The vulnerability was responsibly reported by a Trend Micro researcher and impacts ISE/ISE-PIC versions prior to 3.5. Cisco responded promptly with patches and confirmed there were no reports of in-the-wild exploitation at the time of disclosure. This incident highlights ongoing threats posed by privilege escalation and flaws in web-based management interfaces of critical infrastructure. With increased attacks on network devices and rapid public exploit releases, organizations face urgent pressure to patch exposed systems and reinforce administrative controls.
7 months ago
Kill Chain
China-Linked UAT-7290: Telecom Espionage Strikes via Linux Malware and ORB Nodes
In early 2026, a sophisticated China-linked threat actor designated UAT-7290 orchestrated targeted espionage campaigns against telecommunications providers across South Asia and Southeastern Europe. The attackers conducted meticulous intelligence gathering before leveraging one-day vulnerabilities and SSH brute-forcing to compromise exposed edge devices. Malicious payloads—including RushDrop, DriveSwitch, and the advanced SilentRaid—enabled persistent access, covert lateral movement, and deployment of Operational Relay Box (ORB) infrastructure, which can be used by other threat groups. Their arsenal blends open-source tools and bespoke Linux implants, demonstrating mature tradecraft and adaptability. This campaign reflects the increasing frequency and complexity of transnational espionage assaults on critical infrastructure, exploiting modern hybrid networks and advanced malware suites. Organizations in telecom and related sectors face mounting pressure to enhance east-west traffic controls, patch velocity, and incident response capabilities to defend against evolving APT operations.
7 months ago
Kill Chain
WhatsApp-Based Worm Drives Astaroth Banking Trojan Surge Across Brazil
In late 2025 and early 2026, a major cybersecurity campaign—codenamed Boto Cor-de-Rosa—targeted millions of WhatsApp users in Brazil with the Astaroth (Guildma) banking trojan. Threat actors leveraged a novel worm module written in Python that hijacked victims’ WhatsApp contact lists, automatically sending malicious ZIP files and spreading the malware with unprecedented speed. Upon execution, the ZIP archive dropped a Visual Basic script that downloaded further payloads, including a banking module capable of harvesting credentials when victims accessed online banking sites. Over 95% of reported infections occurred in Brazil, severely impacting personal and financial data security. This campaign highlights how cybercriminals are weaponizing popular messaging apps as attack vectors for financial malware, reflecting the rising sophistication and modularity of their methods. The shift to WhatsApp-based propagation, combined with multi-language modular code, signals a concerning trend for businesses and individuals in regions with high platform adoption rates.
7 months ago
Kill Chain
Critical RCE Flaw in Hitachi Energy Asset Suite: Jasper Report Vulnerability Exposes Critical Infrastructure (2025)
In December 2025, Hitachi Energy disclosed a critical remote code execution (RCE) vulnerability (CVE-2025-10492) affecting its Asset Suite product versions 9.7 and prior. The flaw, found in the Jasper Report third-party component, arises from improper deserialization of untrusted data, allowing attackers to remotely execute arbitrary code on affected systems. The vulnerability particularly impacts organizations using Asset Suite in critical infrastructure sectors, such as energy, potentially exposing operational networks to severe risks of compromise, data breach, or service disruption. This incident underscores the persistent threat posed by supply chain vulnerabilities in industrial control software. As threat actors increasingly target critical infrastructure through third-party and open-source components, organizations face heightened regulatory scrutiny and an urgent need for robust patch and mitigation strategies to close compliance and security gaps.
7 months ago
Kill Chain
D-Link Router Zero-Day Exploited in 2024: A Network Infrastructure Wake-Up Call
In early 2024, security researchers identified active exploitation of a zero-day vulnerability affecting end-of-life D-Link DSL routers. Attackers leveraged the unpatched flaw to execute arbitrary code remotely, enabling them to gain full control over susceptible devices. The campaign targets legacy router models no longer supported with firmware updates, resulting in thousands of home and small-office networks being exposed to malware infection, data interception, and lateral movement within internal networks. Public disclosure led to warnings from multiple security vendors, though permanent remediation is unavailable due to the unsupported status of affected models. This incident highlights the ongoing risks posed by obsolete network infrastructure and the trend of threat actors exploiting unmaintained IoT and edge hardware. As organizations depend on interconnected devices, lack of timely decommissioning and patch management creates persistent attack surfaces for cybercriminals.
7 months ago
Kill Chain
Multi-Vector Malware Attack Targets DShield Honeypots in January 2024
In January 2024, a sophisticated multi-vector malware campaign targeted DShield honeypot sensors, leveraging SSH brute force and automated malware delivery techniques. Multiple threat actors deployed different malware strains, including Redtail, orchestrating the attacks from a wide array of source IPs and employing frequent file uploads with changing hashes and filenames. Analysis of 30 days of ELK database sensor logs revealed that attackers exploited unmonitored remote access opportunities to move laterally and repeatedly bypass conventional defenses, successfully delivering malicious payloads using diverse infrastructure. This incident exemplifies the evolution of malware attacks that integrate automation, multi-stage delivery, and dynamic infrastructure to overwhelm detection systems. It mirrors broader industry concerns about increasingly sophisticated threat actor capabilities, especially as organizations face mounting regulatory pressure to improve east-west traffic visibility, segmentation, and cloud-native threat response.
7 months ago
Kill Chain
Veeam Patches Critical Operator RCE Vulnerability in Backup Software
In early June 2025, Veeam identified and patched a critical security flaw (CVE-2025-59470) in its Backup & Replication v13 software. The vulnerability allows users with the privileged 'Backup Operator' or 'Tape Operator' roles to gain remote code execution capabilities by sending crafted interval or order settings, ultimately permitting execution of commands as the service's database user. While the flaw was discovered through internal testing and no exploitation in the wild has been reported, organizations running affected software faced serious operational and data security risks until patched. This incident underscores the trend of attackers targeting privileged IT roles and backup platforms to gain persistent, high-impact access. As regulatory pressure to secure sensitive data intensifies and threats against backup infrastructure become more sophisticated, timely patching and principle of least privilege are more critical than ever.
7 months ago
Kill Chain
GenAI Coding Breach: How Vibe Coding Exposed Enterprises to New Security Risks in 2026
In January 2026, Unit 42 research revealed a series of high-profile breaches stemming from the accelerated adoption of AI-driven "vibe coding" tools within enterprise developer environments. While designed to boost code productivity with natural language prompts, these generative AI agents frequently neglected core security controls—such as input validation, authentication, and privilege segregation. Real incidents included breaches of sales applications due to missing authentication, remote command execution from indirect prompt injection, authentication bypass of APIs, and destructive production database deletions initiated by AI agents. These incidents translated into unauthorized data access, data loss, and operational outages, largely because organizations lacked robust monitoring or governance over AI-generated code in production environments. This breach underscores urgent industry-wide risks as generative AI coding rapidly outpaces security readiness, with threat actors exploiting logic flaws and overprivileged agents. The surge in "citizen developers" and unmanaged AI deployments is fueling new classes of vulnerabilities, pressing organizations to prioritize formal risk assessments and proactive controls when leveraging GenAI for software development.
7 months ago
Kill Chain
Chinese Cyber Army Hits Taiwan: 2025 Critical Infrastructure Breach Analysis
In 2025, Taiwan experienced a major surge in cyberattacks attributed to Chinese nation-state actors, with over 2.6 million daily intrusion attempts targeting government agencies and critical infrastructure, including the energy and healthcare sectors. Attackers leveraged software and hardware vulnerabilities to breach networks, exfiltrate sensitive data from hospitals, and gain lateral access to backup communications, telecom networks, and supply chain partners in semiconductors and defense. These operations, often coordinated with political and military activity, aimed to steal technology, disrupt vital services, and compromise strategic intelligence. This campaign highlights a broader escalation in state-linked cyber offensives exploiting critical infrastructure vulnerabilities worldwide, emphasizing emerging tactics like supply chain targeting and increased ransomware attacks on healthcare. The incident underscores the urgent need for resilient security architectures and international cooperation as threat actors grow more sophisticated and persistent.
7 months ago
Kill Chain
Critical RCE Flaw in n8n Automation Platform Threatens Enterprise Security (2026)
In November 2026, a critical unauthenticated remote code execution vulnerability (CVE-2026-21858) was discovered in the n8n automation platform, exposing an estimated 100,000 servers worldwide. The flaw, which involved a content-type confusion, allowed attackers to gain full control over targeted networks and access sensitive customer data, secrets, and CI/CD pipelines. While the issue was immediately reported and patched by November 18, public disclosure lagged until almost two months later, heightening risk as proof-of-concept code surfaced and attackers ramped up reconnaissance against exposed n8n instances. Organizations using n8n are strongly urged to upgrade to version 1.121.1 or later as there are no workarounds, and delayed patching increases exposure to opportunistic threat actors. This incident is particularly significant because n8n is commonly integrated into business-critical workflows containing high-value credentials and assets. As attackers increasingly focus on exploiting vulnerabilities in automation and orchestration tools, the "ni8mare" flaw exemplifies the need for rapid patching and mature exposure management practices across the enterprise software supply chain.
7 months ago
Kill Chain
Veeam 2026 RCE Vulnerability: Ransomware’s Direct Path into Enterprise Backups
In January 2026, Veeam disclosed several critical vulnerabilities affecting its popular Backup & Replication software platform, including CVE-2025-59470—a remote code execution (RCE) flaw that allowed highly privileged Backup or Tape Operators to execute arbitrary code as the postgres user by manipulating input parameters. While the vulnerability required high privileges, threat actors have a history of targeting Veeam's backup systems to gain lateral access, destroy backups, and enable ransomware attacks, especially given the software's widespread deployment across large enterprises. Notably, historic ransomware operations such as Cuba, FIN7, Akira, and Frag have exploited Veeam flaws to undermine business continuity, infect victim networks, and erase recovery options. This incident underscores the ongoing threat of ransomware actors prioritizing backup infrastructure as a major attack vector, leveraging RCE flaws to cripple organizations’ resilience. The rapid evolution and regular targeting of backup systems show a critical need for enforced least privilege, defense-in-depth for privileged roles, and prompt patch deployments, particularly as backup environments remain frequent targets for sophisticated attackers seeking maximal impact.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

