✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3577 to 3588 of 5260
Insider Threat Reality: US Cyber Pros Caught as BlackCat Ransomware Affiliates
In 2023, two U.S.-based cybersecurity professionals—formerly employed by major security firms—pleaded guilty to acting as affiliates for the ALPHV/BlackCat ransomware group. The individuals leveraged their insider knowledge and technical expertise to facilitate the deployment of the ransomware, compromising sensitive systems in targeted organizations. By exploiting weaknesses in internal security protocols and bypassing detection mechanisms, they assisted in the encryption of files and extortion of affected businesses, resulting in operational disruptions and significant reputational damage across multiple sectors. This incident highlights an escalating threat posed by insiders with privileged knowledge and skills, who collaborate with sophisticated ransomware groups like BlackCat. The convergence of advanced ransomware-as-a-service operations and trusted industry insiders signals a dangerous shift, amplifying calls for more robust zero trust strategies, stricter network segmentation, and improved insider threat monitoring.
7 months ago
Kill Chain
Inside the ClickFix Campaign: How Hospitality Firms Were Hit with DCRat Remote Access Attacks
In early 2024, a sophisticated phishing campaign known as 'ClickFix' targeted organizations in the hospitality sector with convincing fake 'Blue Screen of Death' error messages. Attackers leveraged social engineering techniques combined with a legitimate Microsoft utility to trick victims into executing malicious payloads. Once engaged, the attack delivered the DCRat remote access trojan, granting cybercriminals ongoing access and control over affected systems. The campaign demonstrated how legitimate tools and realistic lures can bypass conventional defenses, resulting in compromised credentials, lateral network movement, and potential data exfiltration. This incident reflects a wider trend of threat actors increasingly turning to legitimate software and advanced social engineering to evade detection. Remote access trojans like DCRat continue to be used in targeted attacks, particularly against sectors with complex digital footprints and limited security controls, making it vital for organizations to adapt their threat detection capabilities.
7 months ago
Kill Chain
MongoBleed: Active Exploitation of MongoDB Memory Leak Puts Credentials at Risk in 2024
In June 2024, a critical vulnerability nicknamed "MongoBleed" was discovered in MongoDB, exposing servers to a memory leak flaw that enables unauthenticated attackers to extract sensitive data such as passwords and authentication tokens. Threat actors are actively exploiting the flaw by sending specially crafted requests to exposed MongoDB endpoints, resulting in chunks of memory—including user credentials and potentially session information—being sent in response. Organizations running unpatched MongoDB instances faced increased risk of credential theft, lateral movement, and potential data breaches, with attacks escalating once public proof-of-concept exploits were released. The MongoBleed incident highlights a surge in opportunistic attacks against cloud-managed databases and underscores the crucial need for rapid patch deployment. The attack's simplicity, combined with the prevalence of cloud-exposed databases in hybrid environments, makes this vulnerability especially relevant as organizations transition to zero-trust and improved segmentation to defend against credential harvesting and related threats.
7 months ago
Kill Chain
NordVPN 2026: False Data Breach Claim Traced to Vendor Test Environment
In January 2026, a threat actor claimed to have breached NordVPN's internal Salesforce development servers, alleging access to over ten databases containing sensitive Salesforce API keys and Jira tokens. The attacker purportedly leveraged brute-force tactics against a misconfigured server; however, NordVPN clarified that the data originated from a vendor's temporary test environment used months prior for automated testing. The breached environment contained only non-sensitive, dummy data, was never linked to NordVPN's production infrastructure, and did not expose customer information or production credentials. The company immediately investigated, engaged with the affected vendor, and publicly denied any compromise of its operational assets. This incident highlights how false breach claims—when amplified by threat actors and forums—can impact enterprise reputation, erode trust, and distract security teams. The event also spotlights the importance of robust controls and clear communication regarding third-party environments, even those used only for testing, as threat actors increasingly seek to exploit every operational touchpoint.
7 months ago
Kill Chain
Ledger Customer Data Exposed in 2024 Global-e Third-Party Breach
In June 2024, Ledger, the hardware cryptocurrency wallet provider, disclosed that a third-party service provider, Global-e, suffered a security breach resulting in unauthorized exposure of customer data. Attackers gained access to Global-e’s e-commerce system, compromising customers’ names, addresses, phone numbers, and emails used for Ledger purchases. Financial information and cryptocurrencies remained unaffected, but impacted individuals could be at greater risk for phishing or other targeted attacks leveraging their leaked information. This incident underscores the growing risks organizations face from third-party vendors. As supply chain and partner ecosystems expand, attackers increasingly target less secure partners, leading to significant data exposures even when a primary company’s own systems are uncompromised.
7 months ago
Kill Chain
VSCode IDE Forks Expose Software Supply Chain Risks via Recommended Extensions
In late 2025, researchers at Koi Security identified a vulnerability across several AI-powered IDEs forked from Microsoft Visual Studio Code—including Cursor, Windsurf, Google Antigravity, and Trae—whereby hardcoded lists of "recommended" extensions pointed to namespaces that were unclaimed in the OpenVSX extension registry. Threat actors could exploit this by registering these namespaces and publishing malicious extensions, leveraging user trust in built-in recommendations. The risk affected any developer using these IDE forks, potentially opening the door for supply chain malware. After reporting, project maintainers began removing vulnerable recommendations and placeholder, non-functional extensions were uploaded to block exploitation. No evidence of active malicious abuse was found prior to remediation. This incident underscores the growing risk of software supply chain attacks, particularly via open-source repositories and trusted platform recommendations. As more AI-powered tools automate software development environments, attackers are increasingly targeting overlooked dependency and plugin ecosystems, forcing organizations to enhance extension and third-party controls.
7 months ago
Kill Chain
Corporate Cloud File-Sharing Sites Targeted in Major Zestix Data Theft (2024)
In early 2024, a threat actor identified as Zestix orchestrated a widespread campaign targeting corporate instances of popular cloud file-sharing services, including ShareFile, Nextcloud, and OwnCloud. By exploiting vulnerable configurations and access controls, Zestix infiltrated dozens of organizations, exfiltrating sensitive corporate data and offering it for sale on underground forums. Attackers leveraged cloud-native techniques to blend in with legitimate traffic, complicating detection and response efforts. The incident has resulted in operational disruption for several affected companies and increased scrutiny over cloud data management strategies. This breach highlights the growing sophistication of cybercriminals in targeting SaaS-based collaboration platforms, exploiting the accelerated shift to cloud storage. As data sovereignty and regulatory demands intensify, organizations must urgently address evolving cloud security gaps to counter both traditional and cloud-native threats.
7 months ago
Kill Chain
VVS Stealer: Obfuscated Python Malware Compromises Discord Accounts in 2025
In April 2025, researchers discovered a new information stealer, VVS Stealer, distributed via obfuscated Python code targeting Discord users. The malware, sold on Telegram, leverages Pyarmor obfuscation techniques to evade detection and focuses on harvesting Discord credentials and authentication tokens. Attackers propagated the malware through malicious campaigns that trick users into executing compromised scripts, resulting in unauthorized access to their Discord accounts. The impact was the loss of sensitive credentials, potential identity theft, and exposure of personal communications, with widespread risk for Discord communities and possibly further compromise of cloud-connected services. This incident exemplifies the growing sophistication in malware targeting online communities, particularly through social engineering and advanced obfuscation. There is a notable trend of threat actors exploiting popular platforms and leveraging encryption or evasion techniques to bypass standard security controls — elevating the urgency for endpoint protection, behavioral monitoring, and defense-in-depth controls.
7 months ago
Kill Chain
Bitfinex 2016 Hack: Anatomy of a Record Crypto Heist and Its Aftermath
In 2016, cryptocurrency exchange Bitfinex suffered one of the largest crypto thefts to date when hackers, including Ilya Lichtenstein, exploited security weaknesses to steal nearly 120,000 Bitcoins, worth billions of dollars at the time. Lichtenstein laundered the stolen funds through a sophisticated network of wallets and exchanges to obscure the assets' origin. Following a lengthy investigation, U.S. authorities arrested Lichtenstein in 2022, later convicting and sentencing him for money laundering tied to this high-profile breach. The Bitfinex hack has become a landmark case in cryptocurrency security and digital money laundering tactics. Its legacy persists as the industry faces increased regulatory scrutiny and ongoing threats targeting exchanges via increasingly sophisticated cyber methods.
7 months ago
Kill Chain
Inside the ClickFix Hospitality Attack: How Fake BSOD Screens Delivered Malware in Europe
In early 2024, a social engineering campaign dubbed 'ClickFix' targeted hospitality sector organizations across Europe by deploying convincing fake Windows Blue Screen of Death (BSOD) screens. Threat actors lured hotel staff into believing their systems were compromised, instructing them to download and execute what appeared to be legitimate fixes. Instead, victims manually compiled and ran malware, granting attackers access to sensitive information and operational networks. The campaign highlights how attackers combine psychological manipulation with technical tactics to bypass traditional security and leverage low-privilege endpoints for initial access, risking data loss and downstream attacks on partners. This incident signals a shift toward increasingly sophisticated social engineering and blended attack methods targeting industries with high customer throughput. As phishing tactics evolve, organizations must bolster employee awareness and deploy proactive threat detection to counter these multifaceted threats.
7 months ago
Kill Chain
Brightspeed Hit by Crimson Collective: Major 2026 Data Breach Exposes Customer PII
In January 2026, Brightspeed, one of the largest fiber broadband providers in the United States, launched an investigation after the Crimson Collective extortion gang claimed to have breached the company’s networks and stolen sensitive data. The group asserted they had accessed personal and account-related information of over 1 million customers, including names, addresses, emails, phone numbers, payment histories, and some payment card details. The threat actors reportedly targeted user account systems and exfiltrated personally identifiable information (PII), subsequently pressuring Brightspeed to respond to their extortion demands by threatening to publish samples of the stolen data. This attack underscores the persistent risk posed by targeted data breaches in the telecom sector, where expansive networks and large customer bases make attractive targets for financially motivated threat actors. The incident further highlights a concerning trend: extortion groups are increasingly leveraging cloud misconfigurations, stolen credentials, and lateral movement within corporate environments to maximize data theft and pressure on organizations.
7 months ago
Kill Chain
Kimwolf Botnet Compromises 2 Million+ Android Devices via Exposed ADB in 2026
In early 2026, the Kimwolf botnet orchestrated one of the largest Android targeting campaigns to date, infecting over 2 million devices. Attackers exploited exposed Android Debug Bridge (ADB) interfaces and abused residential proxy networks to establish persistent control and monetize the compromised devices. Synthient researchers revealed that Kimwolf operators maintained access for lateral movement, facilitated app installations, sold network bandwidth, and weaponized infected endpoints for DDoS attacks. The attack chain emphasized exploiting weak or default security configurations on Android devices, allowing broad propagation and quick monetization at scale. The Kimwolf botnet illustrates the evolving risk landscape for mobile endpoints and the increasing use of cloud or residential proxy infrastructure by cybercriminals. Given the speed and scale of infection, this case underscores the urgent need for stronger defense-in-depth strategies and highlights regulatory scrutiny on IoT and mobile security postures.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

