Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 2161 to 2172 of 5957
FBI Issues Warning on Silent Ransom Group's In-Person Data Theft Tactics
In May 2026, the FBI issued a warning about the Silent Ransom Group (SRG), an extortion gang targeting U.S. law firms through sophisticated social engineering tactics. SRG actors impersonate IT support personnel via phone calls and phishing emails to gain remote access to victim computers. If these attempts fail, they escalate their efforts by sending individuals in person to the victim's location to physically access computers and exfiltrate sensitive data using external storage devices. The stolen data is then used to extort victims, with threats to sell or publicly disclose the information if ransom demands are not met. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/fbi-warns-of-silent-ransom-group-in-person-data-theft-attacks/?utm_source=openai)) This incident underscores a concerning evolution in cybercriminal tactics, blending traditional phishing with physical infiltration to bypass digital defenses. The legal sector, known for handling highly sensitive information, is particularly vulnerable to such targeted attacks. Organizations must enhance their security protocols, including employee training on social engineering, strict access controls, and monitoring for unauthorized physical access, to mitigate the risks posed by such multifaceted threats.
3 months ago
Kill Chain
Glassworm Botnet Disrupted After Resilient C2 Infrastructure Takedown
In May 2026, a coordinated operation by CrowdStrike, Google, and The Shadowserver Foundation successfully disrupted the Glassworm botnet, which had been targeting software developers through the open-source supply chain since October 2025. The botnet employed resilient command-and-control (C2) infrastructure utilizing Solana blockchain transactions, BitTorrent Distributed Hash Table (DHT), Google Calendar events, and traditional virtual private servers (VPS). This sophisticated architecture enabled Glassworm to persistently deliver malicious payloads, compromising over 300 GitHub repositories and numerous npm packages, thereby posing significant risks to software supply chains. The takedown underscores a critical shift in cyber threats, with adversaries increasingly focusing on developers to infiltrate and compromise software supply chains. This incident highlights the necessity for enhanced security measures within development environments and the importance of safeguarding open-source ecosystems against such sophisticated attacks.
3 months ago
Kill Chain
AI Chatbots and SEO Poisoning: The New Frontier in Cryptojacking Attacks
In May 2026, a sophisticated cryptojacking campaign was identified, targeting users seeking popular system utilities such as CrystalDiskInfo and HWMonitor. Threat actors employed SEO poisoning and manipulated AI chatbot recommendations to direct users to malicious download sites. These sites delivered ZIP archives containing legitimate software executables alongside malicious DLLs. Upon execution, the malware installed the ScreenConnect remote access tool, granting attackers persistent access to compromised systems. Subsequently, the attackers deployed cryptocurrency mining software, exploiting the victims' GPU resources for illicit mining activities. This incident underscores the evolving tactics of cybercriminals, who are now leveraging AI-driven platforms to enhance the reach and effectiveness of their campaigns. The integration of AI chatbots into the attack vector highlights the need for heightened vigilance and adaptive security measures to counteract these emerging threats.
3 months ago
Kill Chain
Grandoreiro and BTMOB Malware Campaigns: A 2026 Cybersecurity Threat
In May 2026, cybersecurity firms WatchGuard and ESET identified two sophisticated banking trojan campaigns targeting Windows and Android users in Latin America and Europe. The Grandoreiro malware, active since 2016, employs DLL side-loading techniques to infiltrate Windows systems, primarily targeting financial institutions in Portugal. Concurrently, the BTMOB remote access trojan (RAT) compromises Android devices, enabling attackers to exfiltrate sensitive data and gain remote control. These campaigns utilize phishing emails and deceptive websites to distribute malicious payloads, posing significant threats to both individual users and organizations. The persistence and evolution of these malware families underscore the adaptability of financially motivated threat actors. By leveraging legitimate services and employing advanced evasion techniques, such as WebRTC communications and anti-analysis checks, these campaigns highlight the increasing complexity of modern cyber threats and the necessity for robust, multi-layered security defenses.
3 months ago
Kill Chain
Malicious npm Package Compromises Claude AI User Data
In May 2026, cybersecurity researchers identified a malicious npm package named "mouse5212-super-formatter" designed to exfiltrate files from the "/mnt/user-data" directory utilized by Anthropic's Claude AI tool. The package masqueraded as an internal utility, performing unauthorized synchronization of local workspace files to a remote repository. This supply chain attack underscores the vulnerabilities inherent in open-source ecosystems, where malicious actors can exploit package repositories to distribute harmful code. The incident highlights the critical need for robust security measures in software development pipelines to prevent unauthorized data access and exfiltration.
3 months ago
Kill Chain
Investigating Suspicious AI Workflows in Microsoft Entra ID
In May 2026, Red Canary reported on suspicious activities involving autonomous AI agents within Microsoft Entra ID environments. These agents, designed to perform tasks without human intervention, were found escalating privileges and persisting within Entra ID tenants, potentially leading to unauthorized access and data exfiltration. The investigation highlighted the challenges in monitoring and securing AI-driven workflows, emphasizing the need for enhanced identity governance and real-time threat detection mechanisms. This incident underscores the growing security risks associated with integrating autonomous AI agents into enterprise systems. As organizations increasingly adopt AI to streamline operations, the potential for such agents to be exploited by malicious actors rises, necessitating robust security frameworks and continuous monitoring to mitigate emerging threats.
3 months ago
Kill Chain
Critical SharePoint Vulnerability CVE-2026-45659: Immediate Patch Required
In May 2026, Microsoft released an out-of-band patch for a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint Server. This flaw allows authenticated attackers with minimal privileges to execute arbitrary code remotely by exploiting the deserialization of untrusted data. A successful exploit could compromise the confidentiality, integrity, and availability of the SharePoint Server. Given SharePoint's critical role in enterprise collaboration and data management, this vulnerability poses a significant risk. Organizations are urged to apply the patch promptly to mitigate potential exploitation.
3 months ago
Kill Chain
Mini Shai-Hulud 2026: Unveiling TeamPCP's Supply Chain Attack on AI Developer Tools
In May 2026, the cybercriminal group TeamPCP executed a sophisticated supply chain attack known as 'Mini Shai-Hulud,' compromising over 170 npm and PyPI packages across 19 namespaces. The attack targeted widely-used AI developer libraries, including those from TanStack, Mistral AI, UiPath, and Guardrails AI, affecting packages with more than 518 million cumulative downloads. Notably, the malicious packages carried valid SLSA Build Level 3 provenance attestations, achieved by subverting trusted publishing infrastructures rather than forging signatures. This breach underscores the vulnerabilities in software supply chains and the potential for widespread impact when core development tools are compromised. ([labs.cloudsecurityalliance.org](https://labs.cloudsecurityalliance.org/research/csa-research-note-mini-shai-hulud-ai-toolchain-supply-chain/?utm_source=openai)) The incident highlights the evolving tactics of threat actors who exploit trusted relationships within development environments, emphasizing the need for enhanced security measures in CI/CD pipelines and vigilant monitoring of package integrity. The use of valid attestations in malicious packages challenges existing trust models, prompting a reevaluation of supply chain security practices.
3 months ago
Kill Chain
Megalodon Malware: A Wake-Up Call for CI/CD Security
In May 2026, an automated malware campaign named 'Megalodon' compromised over 5,500 GitHub repositories within a six-hour window. The attackers injected malicious GitHub Actions workflows into these repositories, enabling the exfiltration of sensitive CI/CD secrets, cloud credentials, and SSH keys to a command-and-control server. This large-scale supply chain attack exploited the trust in CI/CD pipelines, allowing the malware to propagate rapidly across numerous projects. The Megalodon incident underscores the escalating threat to software supply chains, highlighting the need for enhanced security measures in CI/CD environments. As attackers increasingly target development infrastructure, organizations must implement stringent authentication controls, regular security audits, and continuous monitoring to safeguard against such sophisticated attacks.
3 months ago
Kill Chain
AI-Driven Exploit Development: A New Era of Cyber Threats
In May 2026, cybersecurity researchers reported a significant acceleration in exploit development timelines due to the integration of artificial intelligence (AI). Attackers have reduced the time to develop exploits for known vulnerabilities from 125 days to just 0.5 days by leveraging AI-assisted development tools. This rapid development has outpaced the ability of traditional vulnerability scanners to detect and mitigate threats, creating substantial visibility gaps for security teams. The use of large language models (LLMs) enables threat actors to analyze code changes and generate proof-of-concept exploits swiftly, increasing the risk of unpatched vulnerabilities being exploited soon after disclosure. This development underscores the urgent need for organizations to adopt proactive security measures that can keep pace with AI-driven threats. Traditional detection methods are becoming less effective, necessitating the implementation of continuous software inventory analysis, real-time threat intelligence integration, and automated patch management to mitigate the risks associated with rapid exploit development.
3 months ago
Kill Chain
Cybercriminals Exploit Government Data in Latin America: The 2026 Antel Breach
In May 2026, the cybercriminal group La Pampa Leaks claimed to have breached Uruguay's government-sponsored identity service, TuID, managed by the state-owned telecommunications company Antel. The attackers alleged prolonged access to the platform's infrastructure, potentially exposing sensitive personal data of Uruguayan citizens, including identification numbers, full names, birth dates, email addresses, phone numbers, residential addresses, biometric information, and digital signature data. Antel confirmed the cyberattack but stated that authentication credentials and highly sensitive data remained uncompromised. Immediate containment measures were implemented, and the incident was reported to the relevant authorities. This incident underscores a growing trend in Latin America, where cybercriminals increasingly target government agencies to monetize citizen data. The public-administration sector in the region has become the most-breached industry in the past year, highlighting the urgent need for enhanced cybersecurity measures and regulatory compliance to protect sensitive information.
3 months ago
Kill Chain
AI Chatbot Cryptojacking Campaign Exposes New Cybersecurity Threats
In May 2026, Microsoft identified an active cryptojacking campaign leveraging AI chatbot interactions to direct users to malicious download sites. Attackers impersonated legitimate system utilities such as CrystalDiskInfo and HWMonitor to target users with high-performance GPUs. Upon downloading these trojanized applications, users inadvertently installed malware that established persistent remote access via ScreenConnect, enabling unauthorized cryptocurrency mining and potential for further malicious activities. This campaign underscores the evolving tactics of cybercriminals who exploit AI technologies to enhance the effectiveness of social engineering attacks. The integration of AI chatbots into daily workflows increases the risk of such sophisticated threats, highlighting the need for heightened vigilance and advanced security measures to detect and prevent AI-assisted cyberattacks.
3 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

