Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 2353 to 2364 of 5982
Mamont Banking Trojan: A Rising Threat in Q1 2026
In Q1 2026, the Mamont banking Trojan emerged as a significant threat to Android users, accounting for 73.5% of banking Trojan detections. This malware family, including variants like Mamont.jo and Mamont.jx, primarily targets users' financial credentials by masquerading as legitimate applications. The surge in Mamont-related incidents underscores the evolving tactics of cybercriminals in exploiting mobile platforms for financial gain. The proliferation of Mamont banking Trojans highlights the critical need for enhanced mobile security measures. As cyber threats become more sophisticated, users and organizations must adopt proactive strategies to safeguard sensitive financial information from such pervasive malware.
4 months ago
Kill Chain
Red-Teaming Reveals Critical Vulnerabilities in Government Education AI Assistant
In early 2026, a government-deployed AI assistant designed to handle education-related inquiries was subjected to a comprehensive red-teaming assessment. The evaluation revealed that, despite robust defenses against direct prompt injections and social engineering tactics, the AI system was vulnerable to structural manipulation techniques. Specifically, attackers successfully bypassed semantic filters by embedding malicious commands within JSON structures and utilizing Base64 encoding, leading the AI to generate unauthorized outputs, including phishing payloads and the disclosure of its own system prompts. These findings underscore the critical need for AI systems to implement multi-layered security measures that address both semantic and structural vulnerabilities to prevent exploitation through prompt injection attacks. The incident highlights the evolving nature of AI security threats, particularly the sophistication of prompt injection techniques that can circumvent traditional safeguards. As AI systems become increasingly integrated into sensitive sectors like education, it is imperative for organizations to adopt comprehensive security frameworks that encompass regular red-teaming exercises, advanced input validation, and continuous monitoring to detect and mitigate emerging threats effectively.
4 months ago
Kill Chain
SHub Reaper: A New macOS Threat Exploiting Trusted Brands
In May 2026, a sophisticated macOS malware variant named SHub Reaper emerged, employing a multi-stage attack chain that impersonates trusted brands such as Apple, Google, and Microsoft. The malware is distributed through fake installers for applications like WeChat and Miro, hosted on typo-squatted domains resembling legitimate Microsoft sites. Upon execution, it masquerades as an Apple security update and establishes persistence via a fake Google Software Update directory. SHub Reaper is designed to steal sensitive information, including passwords, cryptocurrency wallets, and documents, while maintaining a backdoor for ongoing access. This incident underscores a growing trend of malware leveraging brand impersonation and social engineering to bypass traditional security measures. The use of legitimate-looking applications and trusted system processes highlights the need for enhanced vigilance and advanced detection mechanisms to protect against such evolving threats.
4 months ago
Kill Chain
Iranian Hackers Compromise U.S. Fuel Monitoring Systems in 2026
In May 2026, Iranian hackers reportedly breached automatic tank gauge (ATG) systems monitoring fuel levels at gas stations across multiple U.S. states. These systems, exposed online without password protection, allowed attackers to alter display readings without affecting actual fuel levels. While no physical damage occurred, the incident underscores vulnerabilities in critical infrastructure. ([abc17news.com](https://abc17news.com/politics/national-politics/cnn-us-politics/2026/05/15/exclusive-hackers-have-breached-tank-readers-at-us-gas-stations-officials-suspect-iran-is-responsible/?utm_source=openai)) This breach highlights the evolving nature of cyber warfare, where nation-state actors target essential services. The incident serves as a stark reminder for organizations to secure internet-facing operational technology systems to prevent potential disruptions and safety hazards.
4 months ago
Kill Chain
Unveiling Fast16: The Pre-Stuxnet Cyber Sabotage Tool
In May 2026, cybersecurity researchers uncovered 'fast16,' a sophisticated Lua-based malware designed to sabotage nuclear weapons testing simulations. Developed as early as 2005, predating Stuxnet by two years, fast16 targeted engineering applications like LS-DYNA and AUTODYN to corrupt uranium-compression simulations essential for nuclear weapon design. The malware selectively tampered with high-explosive simulations, activating only when material density exceeded 30 g/cm³, a threshold indicative of uranium under implosion conditions. This strategic interference aimed to produce flawed simulation results, potentially derailing nuclear weapons development programs. The discovery of fast16 highlights the longstanding use of cyber tools for industrial sabotage by nation-state actors. Its sophisticated design and targeted approach underscore the critical need for robust cybersecurity measures in protecting sensitive research and development activities, especially those related to national security.
4 months ago
Kill Chain
Malicious npm Packages Deliver Infostealers and DDoS Malware
In May 2026, cybersecurity researchers identified four malicious npm packages—chalk-tempalte, @deadcode09284814/axios-util, axois-utils, and color-style-utils—containing infostealer malware and DDoS botnet functionality. These packages, published by the user deadcode09284814, were designed to steal sensitive information and facilitate distributed denial-of-service attacks. Notably, one package was a clone of the Shai-Hulud worm, previously leaked by TeamPCP. This incident underscores the escalating threat of supply chain attacks targeting developers through trusted repositories like npm. The discovery highlights the critical need for developers to exercise caution when integrating third-party packages, as attackers increasingly exploit public repositories to distribute malware. Implementing robust security measures, such as verifying package authenticity and monitoring for suspicious activity, is essential to mitigate the risks associated with supply chain compromises.
4 months ago
Kill Chain
MiniPlasma Zero-Day: A Critical Threat to Windows 11 Security
In May 2026, security researcher Chaotic Eclipse disclosed a critical zero-day vulnerability in Microsoft Windows, codenamed MiniPlasma. This flaw affects the Windows Cloud Files Mini Filter Driver (cldflt.sys) and allows attackers to escalate privileges to SYSTEM level on fully patched Windows 11 systems. The vulnerability was initially reported to Microsoft in September 2020 and was believed to have been patched in December 2020 as CVE-2020-17103. However, recent findings indicate that the issue remains unpatched, posing significant security risks. The public release of the MiniPlasma exploit underscores ongoing challenges in Windows security, particularly concerning privilege escalation vulnerabilities. Organizations must reassess their security postures and implement additional measures to mitigate the risks associated with this unpatched flaw.
4 months ago
Kill Chain
Critical Vulnerability in Ivanti Xtraction (CVE-2026-8043) Poses Severe Risks
In May 2026, Ivanti disclosed a critical vulnerability (CVE-2026-8043) in its Xtraction platform, which allows authenticated remote attackers to bypass directory restrictions. This flaw enables unauthorized access to sensitive internal system files and permits writing arbitrary HTML files to web directories, potentially transforming trusted servers into malicious hosts for client-side attacks. The vulnerability carries a CVSS score of 9.6, indicating its severity. The healthcare sector is particularly at risk due to the sensitive nature of Protected Health Information (PHI) managed by Xtraction. Organizations are urged to upgrade to version 2026.2 immediately to mitigate potential data exposure and client-side attacks.
4 months ago
Kill Chain
Critical Cybersecurity Incidents: Exchange 0-Day, npm Worm, and Cisco Exploit
In May 2026, a series of significant cybersecurity incidents underscored the vulnerabilities in widely used systems and software. A zero-day vulnerability (CVE-2026-42897) in Microsoft Exchange Server was actively exploited, allowing attackers to execute arbitrary JavaScript via crafted emails, affecting on-premises deployments. Concurrently, the 'Mini Shai-Hulud' campaign compromised multiple npm packages, including those from TanStack and Mistral AI, embedding malicious code to steal credentials and potentially execute destructive actions. Additionally, a critical authentication bypass flaw (CVE-2026-20182) in Cisco Catalyst SD-WAN Controllers was exploited by threat actor UAT-8616 to gain unauthorized access and escalate privileges. These incidents highlight the escalating sophistication of supply chain attacks and the critical need for robust security measures across all software dependencies. Organizations must prioritize patching known vulnerabilities, implement stringent access controls, and continuously monitor for anomalous activities to mitigate the risks posed by such multifaceted threats.
4 months ago
Kill Chain
Mini Shai-Hulud Attack: A Wake-Up Call for Developer Ecosystem Security
Between April 29 and May 1, 2026, a coordinated supply chain attack known as "Mini Shai-Hulud" targeted multiple developer ecosystems, including npm, PyPI, and Docker Hub. The threat actor group TeamPCP injected malicious code into widely used packages such as SAP's Cloud Application Programming Model, PyTorch Lightning, and Intercom's npm package. This malware harvested sensitive credentials from developer environments and CI/CD pipelines, including GitHub tokens, cloud API keys, and SSH keys, by exfiltrating them to attacker-controlled repositories. The attack compromised over 170 packages, affecting millions of developers and organizations worldwide. ([labs.cloudsecurityalliance.org](https://labs.cloudsecurityalliance.org/research/csa-research-note-mini-shai-hulud-supply-chain-20260503-csa/?utm_source=openai)) This incident underscores the evolving nature of supply chain attacks, which now focus on developer workstations as entry points. The integration of malicious code into trusted packages highlights the need for enhanced security measures in the software development lifecycle, particularly in dependency management and CI/CD processes. Organizations must adopt comprehensive strategies to protect against such sophisticated threats.
4 months ago
Kill Chain
YellowKey Exploit: A Critical Threat to BitLocker Encryption on Windows 11
In May 2026, a security researcher known as Nightmare-Eclipse disclosed a critical vulnerability named YellowKey, which allows attackers with physical access to bypass BitLocker encryption on Windows 11 systems. By exploiting the Windows Recovery Environment (WinRE), an attacker can use a specially crafted USB stick to gain full access to encrypted drives without requiring the user's password. This vulnerability affects default deployments of BitLocker, posing significant risks to data security. The disclosure of YellowKey underscores the ongoing challenges in securing physical access points and highlights the need for robust encryption practices. Organizations relying on BitLocker for data protection must reassess their security measures to mitigate potential exploitation of this vulnerability.
4 months ago
Kill Chain
Instructure Canvas Breach 2026: A Wake-Up Call for SaaS Security
In early May 2026, Instructure's Canvas learning management system suffered two significant breaches within a week, orchestrated by the cybercriminal group ShinyHunters. The attackers exploited vulnerabilities in the 'Free-For-Teacher' accounts to gain unauthorized access, leading to the exfiltration of 3.65 terabytes of data from approximately 275 million users across nearly 9,000 institutions. The compromised data included names, email addresses, student ID numbers, and private messages. Following the breaches, ShinyHunters defaced Canvas login pages and demanded a ransom, which Instructure paid in exchange for assurances that the stolen data would be destroyed and not used for further extortion. ([techcrunch.com](https://techcrunch.com/2026/05/12/instructure-strikes-deal-with-hackers-who-breached-it-twice/?utm_source=openai)) This incident underscores the escalating threat landscape targeting educational platforms and the critical need for robust identity governance and data protection measures. The breaches highlight the vulnerabilities inherent in widely adopted SaaS platforms and the potential for significant operational disruptions and data privacy concerns when such systems are compromised.
4 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

