Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 1753 to 1764 of 5957
Kali365: The Emerging Threat Bypassing MFA in Microsoft 365
In April 2026, a new Phishing-as-a-Service (PhaaS) platform named Kali365 emerged, enabling cybercriminals to hijack Microsoft 365 accounts by exploiting the OAuth device code flow. This method allows attackers to bypass multi-factor authentication (MFA) by tricking users into entering device codes on legitimate Microsoft verification pages, thereby granting unauthorized access to services like Outlook, OneDrive, and Teams. The FBI issued a public service announcement in May 2026, highlighting the widespread distribution of Kali365 via Telegram and its use in numerous attacks across various sectors, including manufacturing, education, government, financial services, and healthcare. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260521?utm_source=openai)) The significance of this incident lies in its demonstration of how attackers can circumvent traditional security measures, such as MFA, by exploiting legitimate authentication processes. The accessibility of Kali365 through subscription services lowers the barrier for less-skilled attackers to conduct sophisticated phishing campaigns, posing a substantial threat to organizations relying on Microsoft 365. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260521?utm_source=openai))
3 months ago
Kill Chain
Unveiling the 2025 AWS Cryptomining Security Breach
In November 2025, Amazon Web Services (AWS) identified a sophisticated cryptocurrency mining campaign targeting Amazon EC2 and Amazon ECS services. Threat actors utilized compromised AWS Identity and Access Management (IAM) credentials to deploy mining operations rapidly, often within minutes of gaining access. They employed advanced persistence techniques, such as modifying instance attributes to disable termination, complicating incident response efforts. This campaign underscores the critical importance of securing IAM credentials and monitoring for unauthorized activities within cloud environments. The incident highlights a growing trend of attackers leveraging legitimate credentials to exploit cloud resources for illicit purposes. Organizations must prioritize robust access controls, implement multi-factor authentication, and continuously monitor for anomalous behaviors to mitigate such threats effectively.
3 months ago
Kill Chain
FIFA 2026 World Cup Broadcast Vulnerability Exposed
In June 2026, an ethical hacker known as "BobDaHacker" identified a critical access control vulnerability within FIFA's Microsoft Entra environment. By registering as a football agent, the hacker gained unauthorized access to FIFA's internal systems, including the live production hub for World Cup broadcasts. This flaw allowed potential manipulation of global television streams, match management systems, and other critical platforms. The vulnerability was promptly reported and subsequently addressed by FIFA. This incident underscores the pressing need for robust server-side authorization mechanisms, especially in high-profile events like the FIFA World Cup. The exposure of such critical systems highlights the importance of comprehensive security measures to prevent unauthorized access and potential disruptions on a global scale.
3 months ago
Kill Chain
Salesforce Data Breach via Klue App Compromise
In June 2026, threat actors exploited OAuth tokens from Klue's Battlecards app to access Salesforce instances, leading to unauthorized data exfiltration. This incident mirrors previous breaches involving third-party integrations like Salesloft's Drift and Gainsight, highlighting the persistent risks associated with SaaS application connections. The attackers authenticated through a compromised Klue integration service account, generating OAuth tokens that granted access to customers' integrated Salesforce environments. The exfiltration process involved automated scripts querying the Salesforce REST API over a 24-hour period, with some instances experiencing concentrated bursts of nearly a thousand queries in 15 minutes. This breach underscores the critical need for organizations to scrutinize third-party integrations and enforce stringent security measures to protect sensitive data. The recurrence of such attacks emphasizes the importance of continuous monitoring and the implementation of robust security protocols to mitigate risks associated with third-party applications.
3 months ago
Kill Chain
Unveiling the Popa Botnet: A Threat Hidden in Plain Sight
In June 2026, cybersecurity researchers uncovered that the 'Popa' botnet, active for four years, had compromised millions of Android-based TV boxes, turning them into nodes for a residential proxy network. This network facilitated activities such as advertising fraud, account takeovers, and mass data scraping. Investigations linked the botnet to NetNut, a residential proxy provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd. The compromised devices, often marketed as offering free access to subscription services, were found to have pre-installed software that enrolled users' home internet connections into the proxy network without explicit consent. This incident highlights the growing threat posed by malicious software embedded in consumer devices, particularly those offering 'free' services. The use of residential proxy networks for illicit activities underscores the need for consumers to exercise caution when purchasing and installing such devices. It also emphasizes the importance of regulatory scrutiny over companies providing proxy services to ensure they are not facilitating cybercriminal activities.
3 months ago
Kill Chain
INC Ransomware's 2026 Surge: A Growing Threat to Sensitive Sectors
In early 2026, the INC ransomware group, a ransomware-as-a-service (RaaS) operation active since mid-2023, intensified its attacks across various sectors, notably healthcare, education, and government entities. Utilizing double extortion tactics, INC affiliates gained initial access through spear-phishing campaigns and exploitation of vulnerabilities in external services. Once inside, they conducted internal reconnaissance using tools like NETSCAN.EXE and AnyDesk.exe, exfiltrated sensitive data, and deployed ransomware to encrypt systems, pressuring victims into paying ransoms to prevent data leaks. ([explore.ontolocy.com](https://explore.ontolocy.com/intel/intrusion-sets/inc-ransomware-group/?utm_source=openai)) This surge in INC's activities underscores the evolving ransomware landscape, where groups leverage RaaS models to scale operations rapidly. The focus on sectors with sensitive data highlights the critical need for organizations to bolster defenses against such multifaceted threats.
3 months ago
Kill Chain
INC Ransomware: A Rising Threat with Over 830 Victims Since 2023
Since August 2023, the INC ransomware group has rapidly evolved into a significant ransomware-as-a-service (RaaS) operation, claiming over 830 victims by June 2026. The group's attacks are characterized by the use of Rust-based encryptors for cross-platform compatibility and resistance to reverse engineering. They employ a diverse range of tools and techniques, including exploiting vulnerabilities in public-facing applications, credential dumping from Veeam backup servers, and utilizing living-off-the-land binaries (LOLBins) for lateral movement. Notably, INC has targeted unpatched edge devices for initial access and used commercial remote monitoring and management (RMM) tools for command-and-control operations. The rise of INC ransomware underscores the adaptability of cybercriminals in leveraging existing vulnerabilities and tools to execute widespread attacks. Their success highlights the critical need for organizations to maintain up-to-date security measures, conduct regular vulnerability assessments, and implement robust incident response plans to mitigate the risks posed by such sophisticated ransomware operations.
3 months ago
Kill Chain
DragonForce Ransomware's Stealthy Exploitation of Microsoft Teams
In December 2025, the DragonForce ransomware group infiltrated a major U.S. services firm by exploiting an SQL-related vulnerability. They deployed a custom Go-based remote access trojan (RAT) named Backdoor.Turn, which concealed command-and-control (C2) traffic within Microsoft Teams' TURN relay infrastructure. This method allowed the attackers to remain undetected for one to two months, as the malicious traffic appeared as legitimate Teams communication. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/06/16/dragonforce-microsoft-teams-malware-backdoor-turn/?utm_source=openai)) This incident underscores a significant evolution in cyberattack methodologies, highlighting the increasing sophistication of threat actors in leveraging trusted communication platforms to evade detection. Organizations must reassess their security postures to address such advanced persistent threats.
3 months ago
Kill Chain
Microsoft Uncovers Sophisticated Windows Clipper Malware Campaign
In June 2026, Microsoft disclosed a sophisticated malware campaign targeting Windows users through USB drives containing malicious LNK files. Once executed, these shortcuts leveraged Windows Script Host and ActiveX to initiate a Tor proxy, establishing a connection to a hidden command-and-control (C2) server. The primary objective of this campaign was to deploy a cryptocurrency clipper, designed to intercept and alter clipboard contents, thereby redirecting cryptocurrency transactions to attacker-controlled wallets. This incident underscores the persistent threat posed by USB-based malware and the evolving tactics of cybercriminals who exploit legitimate Windows functionalities to evade detection. The use of Tor for C2 communication highlights the increasing adoption of anonymization techniques by threat actors, complicating traditional network defense strategies.
3 months ago
Kill Chain
Red Hat npm Supply Chain Attack: A Wake-Up Call for Software Security
In June 2026, Red Hat's npm packages were compromised in a significant supply chain attack. Threat actors infiltrated the @redhat-cloud-services namespace, injecting a credential-stealing worm into 32 packages, affecting 96 versions. These malicious packages, downloaded over 116,000 times weekly, exploited GitHub Actions' OpenID Connect to publish the compromised code, indicating a breach in the CI/CD pipeline. The attack led to unauthorized access to sensitive credentials, posing substantial risks to downstream users. ([aikido.dev](https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting trusted software ecosystems. Organizations must enhance their security measures, particularly in CI/CD pipelines, to prevent similar breaches. The event highlights the necessity for continuous monitoring and rapid response strategies to mitigate the impact of such sophisticated attacks.
3 months ago
Kill Chain
Surge in SSH Brute Force Attacks Correlates with Global Events in 2026
Between February and May 2026, a DShield honeypot recorded over 20 million SSH brute-force attempts, revealing a significant correlation between attack volumes and external events such as geopolitical tensions and cybersecurity advisories. Notably, a 2100% surge in attacks coincided with CISA's Emergency Directive 26-03 addressing Cisco SD-WAN vulnerabilities, and peaks in activity aligned with escalating conflicts involving Iran, Israel, and the United States. These findings underscore the adaptability of threat actors who exploit global events to intensify their malicious activities. The study highlights the persistent threat posed by coordinated SSH brute-force attacks and the necessity for organizations to implement robust security measures. As attackers continue to leverage global events to orchestrate large-scale attacks, it is imperative for entities to enhance their defenses, monitor for unusual activity, and stay informed about emerging threats to mitigate potential breaches.
3 months ago
Kill Chain
Crypto Clipper Malware: A New Threat Leveraging Tor and Worm-Like Propagation
In February 2026, Microsoft identified a Windows-based cryptocurrency clipper malware that propagates via malicious shortcut (.lnk) files. This malware comprises a worm component for self-propagation and a stealer component that harvests and exfiltrates cryptocurrency wallet information. Notably, it utilizes Windows Script Host and ActiveX to launch a bundled Tor proxy, enabling communication with a hidden-service command-and-control (C2) server. The malware performs high-frequency clipboard monitoring, screenshot exfiltration, and wallet-address substitution, effectively turning a financially motivated stealer into a lightweight backdoor. The incident underscores the evolving sophistication of malware leveraging anonymized communication channels like Tor and worm-like propagation methods. Organizations should be vigilant about script-based threats and implement behavioral detection mechanisms to identify suspicious activities such as script interpreters spawning unexpected child processes, localhost proxy usage, and clipboard inspection behaviors.
3 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

