✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3589 to 3600 of 5263
Inside the ClickFix Hospitality Attack: How Fake BSOD Screens Delivered Malware in Europe
In early 2024, a social engineering campaign dubbed 'ClickFix' targeted hospitality sector organizations across Europe by deploying convincing fake Windows Blue Screen of Death (BSOD) screens. Threat actors lured hotel staff into believing their systems were compromised, instructing them to download and execute what appeared to be legitimate fixes. Instead, victims manually compiled and ran malware, granting attackers access to sensitive information and operational networks. The campaign highlights how attackers combine psychological manipulation with technical tactics to bypass traditional security and leverage low-privilege endpoints for initial access, risking data loss and downstream attacks on partners. This incident signals a shift toward increasingly sophisticated social engineering and blended attack methods targeting industries with high customer throughput. As phishing tactics evolve, organizations must bolster employee awareness and deploy proactive threat detection to counter these multifaceted threats.
7 months ago
Kill Chain
Brightspeed Hit by Crimson Collective: Major 2026 Data Breach Exposes Customer PII
In January 2026, Brightspeed, one of the largest fiber broadband providers in the United States, launched an investigation after the Crimson Collective extortion gang claimed to have breached the company’s networks and stolen sensitive data. The group asserted they had accessed personal and account-related information of over 1 million customers, including names, addresses, emails, phone numbers, payment histories, and some payment card details. The threat actors reportedly targeted user account systems and exfiltrated personally identifiable information (PII), subsequently pressuring Brightspeed to respond to their extortion demands by threatening to publish samples of the stolen data. This attack underscores the persistent risk posed by targeted data breaches in the telecom sector, where expansive networks and large customer bases make attractive targets for financially motivated threat actors. The incident further highlights a concerning trend: extortion groups are increasingly leveraging cloud misconfigurations, stolen credentials, and lateral movement within corporate environments to maximize data theft and pressure on organizations.
7 months ago
Kill Chain
Kimwolf Botnet Compromises 2 Million+ Android Devices via Exposed ADB in 2026
In early 2026, the Kimwolf botnet orchestrated one of the largest Android targeting campaigns to date, infecting over 2 million devices. Attackers exploited exposed Android Debug Bridge (ADB) interfaces and abused residential proxy networks to establish persistent control and monetize the compromised devices. Synthient researchers revealed that Kimwolf operators maintained access for lateral movement, facilitated app installations, sold network bandwidth, and weaponized infected endpoints for DDoS attacks. The attack chain emphasized exploiting weak or default security configurations on Android devices, allowing broad propagation and quick monetization at scale. The Kimwolf botnet illustrates the evolving risk landscape for mobile endpoints and the increasing use of cloud or residential proxy infrastructure by cybercriminals. Given the speed and scale of infection, this case underscores the urgent need for stronger defense-in-depth strategies and highlights regulatory scrutiny on IoT and mobile security postures.
7 months ago
Kill Chain
Russia-Aligned Group UAC-0184 Breaches Ukrainian Government via Viber Attack
In early 2025, the Russia-aligned cyber-espionage group UAC-0184 undertook a targeted campaign against Ukrainian military and government organizations. Leveraging the popular Viber messaging platform, the threat actors distributed malicious ZIP archives to infiltrate sensitive networks. Security researchers from the 360 Threat Intelligence Center noted that these operations demonstrated continued intelligence-gathering efforts, employing social engineering tactics and the abuse of trusted communication channels. The attack resulted in the unauthorized access and potential exposure of confidential government and defense information, further escalating the cyber hostilities related to the conflict in Ukraine. This incident highlights a growing trend in the weaponization of encrypted messaging apps for cyber-espionage, as nation-state actors increasingly exploit trusted consumer platforms to bypass traditional enterprise security controls. The breach underscores the urgency for robust east-west traffic monitoring, zero trust segmentation, and advanced detection capabilities across critical sectors.
7 months ago
Kill Chain
RondoDox Botnet Leverages React2Shell to Breach Next.js Servers
In early 2024, the RondoDox botnet launched widespread attacks targeting exposed Next.js servers by exploiting a vulnerability known as React2Shell. The threat actors leveraged this exploit to install cryptomining malware, enroll compromised enterprise and IoT devices into their botnet, and facilitate lateral movement across affected networks. The campaign demonstrates advanced threat sophistication, including rapid deployment of botnet payloads and persistent communication over encrypted channels, resulting in operational disruption and the risk of sensitive data exposure for impacted organizations. This incident underscores an uptick in supply chain and application-layer attacks, particularly on modern frameworks like Next.js. With attackers automating exploitation of recently disclosed vulnerabilities, organizations must prioritize patch management and adopt Zero Trust controls to defend against evolving botnet campaigns.
7 months ago
Kill Chain
How Telegram Became the World's Largest Darknet Market Platform in 2026
In early 2026, major Chinese-speaking darknet markets known as Tudou Guarantee and Xinbi Guarantee emerged on the encrypted messaging platform Telegram, quickly becoming the world’s largest such entities. Following enforcement action and the banning of two prior networks, these new markets enabled an illicit ecosystem reportedly handling nearly $2 billion each month in laundering, sale of scamware, stolen data, deepfake technologies, and a disturbing array of black-market services. Their operations fuel high-volume crypto investment and romance scams, including the so-called 'pig butchering' schemes, which exploit trafficked labor and result in billions in global losses—with US victims alone losing around $10 billion a year. This incident illustrates the adaptability of cybercriminal infrastructure, highlighting Telegram’s evolving role as a trusted communications and trading platform for serious organized cyber threats. The surge in Telegram-based darknet activity coincides with increased regulatory scrutiny, growing law enforcement action, and a shift toward encrypted, resilient, and cross-border cybercrime tactics.
7 months ago
Kill Chain
Resecurity 2025: How a Cybersecurity Firm Turned an Alleged Breach Into a Threat Intelligence Win
In December 2025, threat actors identifying as the 'Scattered Lapsus$ Hunters' claimed they had breached systems belonging to cybersecurity firm Resecurity, stealing employee data, internal communications, threat intelligence reports, and client information. The attackers published screenshots to support their claims, including evidence of access to collaboration platforms. However, Resecurity quickly countered the claims, explaining that the compromised environment was actually a carefully monitored honeypot populated with synthetic datasets and fake credentials, intentionally designed to attract cybercriminals for research purposes. The company monitored and logged the attackers’ behaviors, collected valuable intelligence—including reconnaissance, OPSEC failures, and the use of residential proxy infrastructure—and shared key data with law enforcement. No real customer data or production systems were at risk during the incident, according to Resecurity. This case highlights the growing trend of cyber attackers targeting security firms as retaliation for investigations, as well as the strategic use of deceptive honeypots to gather adversary intelligence. The incident underlines the importance of controlled cyber deception, advanced detection, and proactive threat intelligence amid an escalating environment of data theft claims and public leak extortion tactics.
7 months ago
Kill Chain
RondoDox Botnet: React2Shell Flaw Drives Massive Next.js Server Breaches
In December 2025, the RondoDox botnet exploited the critical React2Shell vulnerability (CVE-2025-55182) to breach hundreds of Next.js servers worldwide. Researchers observed the botnet initiating mass scans and automated remote code execution attacks against exposed servers, deploying malware, persistent botnet loaders, and cryptominers. RondoDox leveraged the unpatched flaw in the widely used React Server Components protocol, enrolling compromised systems and IoT devices into its botnet and wiping out competing malware. The attack impacted both consumer and enterprise networks, risking data exfiltration, service outages, and broader supply chain compromise. This campaign underscores the increased urgency around patching application-layer vulnerabilities at scale, as attackers rapidly weaponize zero-day and n-day exploits across popular frameworks. The prevalence of automated exploitation and lateral expansion tactics reflects a shifting threat landscape that challenges traditional perimeter security and requires robust detection, segmentation, and rapid response capabilities.
7 months ago
Kill Chain
Crypto Phishing 2026: How Chatbots and Telegra.ph Power Modern Scams
Between October 2025 and early 2026, a persistent cryptocurrency phishing campaign leveraged fake chatbot websites and phishing emails to target users, primarily using minimalist publishing platforms such as telegra.ph and Google Forms. The attackers distributed scam emails promising recipients substantial payouts in Bitcoin, directing them to malicious pages purporting to automate cryptocurrency mining profits. Victims were eventually asked to pay a fraudulent conversion fee to claim their non-existent funds, with payments funneled into wallets controlled by the attackers. The campaign’s simplicity and abuse of free digital services allowed it to evade basic filtering and reach a wide audience repeatedly. This incident highlights an ongoing rise in abuse of cloud-based publishing and forms services for elaborate phishing scams. Attackers are increasingly automating social engineering techniques, combining chatbots and “cash out” lures that have proven cost-effective and resilient even as major platforms improve traditional anti-phishing measures.
- Banking/Mortgage
- Capital Markets/Hedge Fund/Private Equity
- Investment Management/Hedge Fund/Private Equity
7 months ago
Kill Chain
GlassWorm Malware Hits macOS: Supply Chain Attack via Malicious VSCode Extensions (2026)
In late 2025 and into January 2026, a new wave of the "GlassWorm" malware campaign targeted macOS developers by infiltrating Visual Studio Code and OpenVSX extension marketplaces. Malicious extensions, embedding AES-256-CBC–encrypted JavaScript payloads, were uploaded using covert techniques. Once installed, the malware stole sensitive credentials, including GitHub, NPM, and crypto wallet data, and established persistence via AppleScript and LaunchAgents. The campaign also attempted to replace popular hardware cryptocurrency wallet apps like Ledger Live and Trezor Suite, although this payload failed due to incomplete attacker infrastructure. Over 33,000 installs were recorded, potentially impacting individual developers and organizations reliant on secure software supply chains. GlassWorm’s evolution targets not only Windows but also macOS ecosystems, signaling a rising trend in sophisticated supply chain attacks against developer tooling. This incident is a cautionary reminder for organizations and developers to tightly scrutinize third-party plugins, raising urgency to implement stronger extension vetting, threat detection, and least-privilege controls.
7 months ago
Kill Chain
AI Supply Chain: Ultralytics, Nx, and ChatGPT Breaches Expose Massive Secrets Leakage
Between late 2024 and mid-2025, a series of major AI supply chain security breaches exposed severe vulnerabilities in widely used machine learning and development platforms. In December 2024, the Ultralytics AI library was compromised and distributed malicious code that hijacked victims’ systems for illicit cryptocurrency mining. By August 2025, attackers published malicious Nx packages that leaked over 2,300 GitHub, cloud, and AI credentials, enabling unauthorized access to sensitive resources. Throughout 2024, vulnerabilities in ChatGPT enabled cross-user data extractions via memory leakage, resulting in the exposure of personal and proprietary information. In total, an alarming 23.77 million secrets were leaked through AI-centric software and supply chain vectors within this period. This string of incidents impacted a wide spectrum of organizations, undermining trust in AI-based workflows and amplifying compliance and regulatory risk. These attacks underscore the rapidly escalating risk of supply chain compromise in AI-centric infrastructure. As organizations increasingly rely on open-source ML libraries and cloud-native platforms, threats targeting code dependencies, API memory, and package repositories are proliferating, outpacing traditional security controls. The incident highlights the urgent need for AI-aware, zero-trust frameworks, advanced east-west traffic monitoring, and routine credential hygiene to prevent similar future exposures.
7 months ago
Kill Chain
27 Malicious npm Packages Turn Dev Ecosystem Into Phishing Playground in 2025
In late 2025, security researchers uncovered a sophisticated supply chain attack leveraging the npm package ecosystem to execute a targeted spear-phishing campaign. Over a five-month period, attackers published 27 malicious npm packages via six aliases, using content delivery networks to host and serve browser-based phishing lures. These lures mimicked document-sharing and Microsoft sign-in portals to trick targeted sales and commercial staff at 25 organizations across manufacturing, industrial automation, healthcare, and allied sectors in the US and Europe. The campaign incorporated advanced anti-analysis checks, obfuscated JavaScript, and honeypot detection to evade security tooling, with hardcoded targets likely sourced from trade show and open-sourced company data. This incident exemplifies the growing abuse of public developer ecosystems and infrastructure in credential theft operations, highlighting an urgent need for organizations to monitor software supply chains and enforce modern, phishing-resistant controls. Attackers' use of legitimate distribution services as resilient hosting and focus on regional, non-IT staff illustrate shifting tactics in supply chain and social engineering threats.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

