Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 1225 to 1236 of 5948
North Korean Hackers Exploit Fake Coding Tests to Deploy OtterCookie Malware via Steganography
In July 2026, North Korean state-sponsored hackers initiated a sophisticated campaign targeting software developers through fake job postings and coding assessments. These assessments contained repositories with malicious code concealed within SVG image files, employing steganography to evade detection. Upon execution, the code deployed a multi-stage payload associated with the OtterCookie malware, capable of stealing browser credentials, cryptocurrency wallets, and sensitive files, as well as establishing remote access via a Socket.IO-based trojan. This operation underscores the persistent threat posed by North Korean cyber actors to the software development community, aiming to exfiltrate valuable data and financial assets. The use of steganography in SVG files highlights the evolving tactics employed by these adversaries to bypass traditional security measures, emphasizing the need for heightened vigilance and advanced detection capabilities within the industry.
2 months ago
Kill Chain
ACR Stealer 2026: Unveiling the ClickFix Intrusion Chains
Between late April and mid-June 2026, Microsoft Defender Experts observed a surge in ACR Stealer activity targeting enterprise environments. Attackers employed 'ClickFix' social engineering tactics to deceive users into executing malicious commands, leading to the theft of browser credentials, authentication tokens, and sensitive documents. The campaigns utilized two primary intrusion chains: one leveraging WebDAV for payload delivery with Python-based loaders and blockchain-backed command-and-control mechanisms, and another employing MSHTA-initiated PowerShell scripts with steganographic techniques for in-memory payload execution. These sophisticated methods enabled attackers to evade detection and maintain persistence within compromised systems. The significance of this incident lies in the advanced techniques used to bypass traditional security measures, highlighting the evolving nature of cyber threats. Organizations must remain vigilant against such deceptive tactics and enhance their security protocols to detect and mitigate similar attacks effectively.
2 months ago
Kill Chain
AI-Driven Cyberattacks: Key Insights from Unit 42's 2026 Report
In 2025, Unit 42 responded to over 750 major cyber incidents across various industries and countries. The 2026 Global Incident Response Report highlights that adversaries are leveraging AI to accelerate attack timelines, with data exfiltration occurring up to four times faster than in previous years. Identity weaknesses were exploited in nearly 90% of investigations, and 87% of intrusions involved multiple attack surfaces, including endpoints, networks, cloud services, SaaS platforms, and identity systems. ([paloaltonetworks.com](https://www.paloaltonetworks.com/blog/2026/02/unit-42-global-ir-report/?utm_source=openai)) This trend underscores the urgent need for organizations to enhance their cybersecurity posture by addressing identity vulnerabilities, improving visibility across attack surfaces, and implementing AI-driven defense mechanisms to counteract the speed and complexity of modern cyber threats.
2 months ago
Kill Chain
Indictment of Russian Nationals for Bulletproof Hosting Services Facilitating Cyberattacks
In July 2026, U.S. federal prosecutors unsealed an indictment against three Russian nationals—Alexander Alexandrovich Volosovik, Yulia Vladimirovna Pankova, and Kirill Andreevich Zatolokin—accusing them of operating bulletproof hosting services through their companies, Media Land and ML.Cloud. These services allegedly facilitated cyberattacks on critical infrastructure across 21 U.S. states and several countries, resulting in over $62 million in damages. The indictment details how the accused provided infrastructure and technical support to cybercriminals, enabling malware distribution, ransomware attacks, and other illicit activities. ([cyberscoop.com](https://cyberscoop.com/russian-nationals-medialand-mlcloud-indicted-bulletproof-hosting/?utm_source=openai)) This case underscores the persistent threat posed by bulletproof hosting providers, which offer cybercriminals resilient infrastructure to conduct attacks with impunity. The indictment highlights the necessity for international cooperation in dismantling such networks and protecting critical infrastructure from cyber threats. ([cyberscoop.com](https://cyberscoop.com/russian-nationals-medialand-mlcloud-indicted-bulletproof-hosting/?utm_source=openai))
2 months ago
Kill Chain
Scattered Spider's 2024 Cyberattack on Transport for London: A Case Study
Between August 31 and September 3, 2024, the cybercriminal group Scattered Spider executed a sophisticated cyberattack on Transport for London (TfL). Utilizing social engineering techniques, they infiltrated TfL's network, leading to significant disruptions in technical services, including the Oyster payment system and third-party APIs. The attack necessitated a mass password reset for all 28,000 TfL employees and resulted in financial losses estimated at £29 million. ([nationalcrimeagency.gov.uk](https://www.nationalcrimeagency.gov.uk/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted?utm_source=openai)) This incident underscores the escalating threat posed by cybercriminal groups employing advanced social engineering tactics to target critical infrastructure. Organizations must enhance their cybersecurity measures, particularly in employee training and network security protocols, to mitigate such risks.
2 months ago
Kill Chain
Spirals Ransomware Attack on South Asian IT Firm in June 2026
In June 2026, an IT services firm in South Asia fell victim to a rapid and sophisticated ransomware attack orchestrated by a previously unknown group deploying the 'Spirals' ransomware. The attackers gained initial access through a publicly exposed Internet Information Services (IIS) server, where they uploaded an ASP.NET web shell. Within a three-hour window, they established persistent access, disabled security software, extracted credentials, and moved laterally across the network. Less than 24 hours after the initial breach, the Spirals ransomware was deployed, encrypting files and exfiltrating sensitive data. The attackers threatened to publish the stolen data within six days unless a ransom was paid. This incident underscores the evolving threat landscape, where cybercriminals are executing attacks with unprecedented speed and efficiency. Organizations must reassess their security postures, particularly concerning publicly accessible services and rapid response capabilities, to mitigate such swift and damaging intrusions.
2 months ago
Kill Chain
Russian Hackers Exploit WebEx and Zoom Installers to Deploy Starland RAT
In June 2025, the Russian threat actor UAT-11795 initiated a campaign targeting users primarily in the United States, with additional victims in Germany, Romania, and Venezuela. The attackers distributed trojanized installers of legitimate software, including WebEx and Zoom, to deploy the Starland RAT malware. This backdoor enabled the exfiltration of browser data, cryptocurrency wallet assets, system details, and Active Directory information. The malware also facilitated remote command execution, screenshot capture, and the deployment of additional payloads such as CastleStealer and Remcos RAT. This incident underscores the increasing sophistication of supply chain attacks, where trusted software is weaponized to infiltrate systems. The use of trojanized installers highlights the critical need for organizations to enforce strict software sourcing policies and to educate users on the risks of downloading software from unofficial sources.
2 months ago
Kill Chain
Urgent: CISA Mandates Patching of Critical Oracle EBS Vulnerability Amid Active Exploitation
In May 2026, Oracle disclosed a critical vulnerability (CVE-2026-46817) in the File Transmission component of its E-Business Suite's Oracle Payments module, affecting versions 12.2.3 through 12.2.15. This flaw allows unauthenticated attackers with HTTP network access to fully compromise the Oracle Payments system. Despite the release of a security patch, by late June 2026, threat intelligence firm Defused observed active exploitation of this vulnerability in the wild. Consequently, on July 15, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-46817 to its Known Exploited Vulnerabilities Catalog and mandated federal agencies to apply the patch by July 18, 2026. This incident underscores the critical importance of timely patch management, especially for vulnerabilities with high CVSS scores and active exploitation. Organizations are urged to assess their exposure to CVE-2026-46817 and ensure that all affected systems are promptly updated to mitigate potential risks.
2 months ago
Kill Chain
Scattered Spider's 2024 Cyberattack on Transport for London: A Case Study
In August 2024, Transport for London (TfL) suffered a significant cyberattack orchestrated by the Scattered Spider hacking group. The breach disrupted internal systems and online services, including Dial-a-Ride, concessionary travel cards, digital payments, and contactless ticketing. Approximately 148 systems were rendered inoperable, and all 27,000 TfL employees were required to reset their passwords in person. The attack resulted in £29 million in losses and recovery costs, with potential economic damages estimated at up to £56 billion had the transport network been fully compromised. This incident underscores the escalating threat posed by cybercriminal groups like Scattered Spider, known for their sophisticated social engineering tactics and targeting of critical infrastructure. The successful prosecution of the perpetrators highlights the importance of early cooperation between organizations and law enforcement in mitigating cyber threats and bringing offenders to justice.
2 months ago
Kill Chain
23andMe Data Breach: A Wake-Up Call for Credential Security
In October 2023, genetic testing company 23andMe disclosed a significant data breach resulting from credential-stuffing attacks that went undetected for five months, from April to September 2023. Attackers exploited reused passwords to access approximately 14,000 user accounts, subsequently exposing sensitive genetic and personal information of 6.9 million customers. This data was later found for sale on the dark web, raising serious privacy concerns. The incident underscores the critical importance of robust cybersecurity measures, including the implementation of multi-factor authentication and proactive monitoring systems. Organizations handling sensitive data must prioritize these defenses to prevent similar breaches and protect consumer trust.
2 months ago
Kill Chain
OkoBot Malware: A New Threat to Cryptocurrency Security
In July 2026, cybersecurity researchers identified OkoBot, a sophisticated malware framework comprising over 20 modules designed to steal cryptocurrency wallet seed phrases, credentials, and other sensitive data. OkoBot infiltrates systems through deceptive ClickFix attacks and malicious GitHub repositories masquerading as legitimate software tools. Once installed, it deploys various payloads, including browser injectors and keyloggers, to harvest user information and monitor activities. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-okobot-framework-deploys-20-payloads-to-steal-data-crypto/?utm_source=openai)) The emergence of OkoBot underscores a growing trend of targeted attacks on cryptocurrency users, highlighting the need for enhanced vigilance and robust security measures within the crypto community. As the malware continues to evolve, staying informed about such threats is crucial for safeguarding digital assets.
2 months ago
Kill Chain
Critical Vulnerability in Claude Chrome Extension Exposes User Data
In July 2026, a critical vulnerability was discovered in Anthropic's Claude for Chrome browser extension. This flaw allowed malicious extensions to simulate user interactions, triggering predefined AI actions without user consent. Exploiting this, attackers could access connected services such as Gmail, Google Docs, Google Calendar, and Salesforce, leading to unauthorized data access and potential data exfiltration. The vulnerability stemmed from the extension's failure to verify the origin of click events, accepting synthetic events generated by other extensions as legitimate user actions. This incident underscores the growing risks associated with browser extensions and their integration with AI-powered services. As organizations increasingly adopt such tools to enhance productivity, ensuring robust security measures and thorough validation of user interactions becomes imperative to prevent unauthorized access and data breaches.
2 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

