Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 2989 to 3000 of 5988
Hims & Hers Data Breach: A Wake-Up Call for Third-Party Service Security
In early February 2026, telehealth company Hims & Hers experienced a data breach when unauthorized actors accessed its third-party customer service platform between February 4 and February 7. The attackers obtained customer support tickets containing personal information, including names and contact details. The company detected the intrusion on February 5 and promptly secured the affected system. While medical records and provider communications remained unaffected, the breach exposed sensitive customer data. ([techcrunch.com](https://techcrunch.com/2026/04/02/telehealth-giant-hims-hers-says-its-customer-support-system-was-hacked/?utm_source=openai)) This incident underscores the growing trend of cyberattacks targeting third-party service providers, exploiting their access to sensitive data. Organizations must reassess and strengthen their vendor risk management and cybersecurity measures to prevent similar breaches.
5 months ago
Kill Chain
Understanding the 2026 Surge in AI-Driven Credential Theft
In 2026, the cybersecurity landscape witnessed a significant surge in AI-driven credential theft, with attackers leveraging artificial intelligence to automate and scale their operations. This escalation led to a 160% increase in credential-based attacks, resulting in the theft of 1.8 billion login credentials from 5.8 million compromised endpoints. The use of AI enabled threat actors to conduct sophisticated phishing campaigns, exploit vulnerabilities rapidly, and bypass traditional security measures, posing substantial risks to organizations worldwide. The current relevance of this incident is underscored by the continued evolution of AI technologies, which have lowered the barrier to entry for cybercriminals and increased the speed and efficiency of attacks. Organizations must adapt their security strategies to address these advanced threats, emphasizing continuous identity assessment, behavioral anomaly detection, and the implementation of phishing-resistant authentication methods to mitigate the risks associated with AI-driven credential theft.
5 months ago
Kill Chain
Safeguarding AI Systems: Addressing Indirect Prompt Injection Vulnerabilities
In April 2026, security researchers identified a critical vulnerability in AI-integrated customer service solutions utilizing Large Language Models (LLMs). The attack, termed 'indirect prompt injection,' involves embedding malicious instructions within user profile fields or external data sources that the LLM processes as context. This method allows attackers to bypass supervisor agents designed to monitor direct user inputs, leading to unauthorized actions by the AI system. The exploitation of this vulnerability underscores the need for comprehensive security measures that encompass all data sources influencing LLM behavior. As AI systems become more integrated into critical workflows, the prevalence of such sophisticated attacks is expected to rise, highlighting the urgency for organizations to reassess and fortify their AI security protocols.
5 months ago
Kill Chain
CPUID's 2026 Supply Chain Breach: A Wake-Up Call for Software Security
In April 2026, CPUID's website was compromised through a secondary API, leading to the distribution of trojanized versions of CPU-Z and HWMonitor. For approximately six hours between April 9 and April 10, attackers altered download links to serve malicious executables, exposing millions of users to potential malware infections. The malicious files, notably named HWiNFO_Monitor_Setup.exe, utilized advanced evasion techniques, including multi-stage, in-memory execution and NTDLL proxying from a .NET assembly, to bypass detection by endpoint detection and response (EDR) systems and antivirus software. CPUID has since identified and rectified the breach, confirming that their original signed binaries remained uncompromised. This incident underscores the escalating threat of supply chain attacks targeting widely used utilities. The attackers' sophisticated methods highlight the need for enhanced vigilance and robust security measures in software distribution channels. Organizations must prioritize the integrity of their software supply chains to prevent similar breaches and protect end-users from malicious software distribution.
5 months ago
Kill Chain
Microsoft 2026: Storm-2755's Payroll Pirate Attack Exposes MFA Vulnerabilities
In April 2026, Microsoft identified a financially motivated threat actor, Storm-2755, targeting Canadian employees through sophisticated 'payroll pirate' attacks. The attackers employed adversary-in-the-middle (AiTM) techniques, using malicious Microsoft 365 sign-in pages to intercept authentication tokens and session cookies. This method allowed them to bypass traditional multi-factor authentication (MFA) and gain unauthorized access to employee accounts. Once inside, they created inbox rules to conceal communications from human resources and manipulated payroll systems, such as Workday, to redirect salary payments to accounts under their control. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/09/investigating-storm-2755-payroll-pirate-attacks-targeting-canadian-employees/?utm_source=openai)) This incident underscores the evolving nature of business email compromise (BEC) schemes, highlighting the need for organizations to implement phishing-resistant MFA solutions and monitor for anomalous activities within their systems. The use of AiTM tactics to circumvent standard security measures signifies a shift in cybercriminal strategies, emphasizing the importance of continuous vigilance and adaptive security protocols. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/09/investigating-storm-2755-payroll-pirate-attacks-targeting-canadian-employees/?utm_source=openai))
5 months ago
Kill Chain
Iranian Cyberattack on U.S. Industrial Devices in 2026
In March 2026, Iranian state-sponsored hackers targeted U.S. critical infrastructure by exploiting internet-exposed Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs). These attacks led to operational disruptions and financial losses across sectors including government services, water and wastewater systems, and energy. The attackers extracted device project files and manipulated human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, compromising industrial processes. ([techcrunch.com](https://techcrunch.com/2026/04/07/iranian-hackers-are-targeting-american-critical-infrastructure-u-s-agencies-warn/?utm_source=openai)) This incident underscores the escalating cyber threats from nation-state actors targeting critical infrastructure. The exploitation of industrial control systems highlights the urgent need for enhanced cybersecurity measures, including network segmentation, regular patching, and the implementation of multifactor authentication to protect against such sophisticated attacks.
5 months ago
Kill Chain
Qualys 2026 Report Highlights Urgent Need for Automated Vulnerability Management
In March 2026, Qualys released a comprehensive analysis of over one billion remediation records from the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, spanning 10,000 organizations over four years. The study revealed that despite a 6.5-fold increase in remediation efforts since 2022, 63% of critical vulnerabilities remained unpatched after seven days, up from 56% in previous years. Alarmingly, 88% of 52 high-profile weaponized vulnerabilities were patched slower than they were exploited, with half being weaponized before any patch was available. This indicates a systemic failure in current vulnerability management practices to keep pace with the rapid exploitation timelines of threat actors. The findings underscore the urgent need for organizations to adopt autonomous, closed-loop risk operations to effectively mitigate vulnerabilities in real-time. The traditional manual remediation processes are proving inadequate against the accelerating threat landscape, necessitating a paradigm shift towards automated and proactive security measures.
5 months ago
Kill Chain
Smart Slider 3 Pro Supply Chain Attack: A 2026 Case Study
In April 2026, unknown threat actors compromised Nextend's update infrastructure to distribute a malicious version (3.5.1.35) of the Smart Slider 3 Pro plugin for WordPress and Joomla. This backdoored update, available for approximately six hours on April 7, allowed attackers to create hidden administrator accounts, execute remote commands, and establish multiple persistence mechanisms, leading to unauthorized access and potential data exfiltration on affected websites. The incident underscores the critical risks associated with supply chain attacks, where trusted software distribution channels are exploited to deliver malware. Such attacks bypass traditional security measures, emphasizing the need for enhanced vigilance and monitoring of software update processes to detect and mitigate unauthorized modifications promptly.
5 months ago
Kill Chain
Marimo 2026 Pre-Auth RCE Exploit: A Wake-Up Call for Rapid Patch Management
In April 2026, a critical pre-authentication remote code execution (RCE) vulnerability, CVE-2026-39987, was identified in Marimo, an open-source Python notebook platform. This flaw allowed unauthenticated attackers to gain full shell access via the /terminal/ws WebSocket endpoint, bypassing authentication mechanisms. Exploitation was observed within 10 hours of public disclosure, with attackers conducting credential theft and reconnaissance activities. The vulnerability affected all Marimo versions up to 0.20.4 and was patched in version 0.23.0. This incident underscores the rapid weaponization of disclosed vulnerabilities, highlighting the necessity for organizations to promptly apply security patches and review authentication controls, especially in platforms exposed to the internet. The swift exploitation also emphasizes the importance of continuous monitoring and threat intelligence to detect and mitigate emerging threats effectively.
5 months ago
Kill Chain
GlassWorm Campaign 2026: Unveiling the Zig Dropper Threat to Developer IDEs
In April 2026, the GlassWorm campaign introduced a new attack vector targeting developers by distributing a malicious Visual Studio Code (VS Code) extension named "specstudio.code-wakatime-activity-tracker." This extension, masquerading as the legitimate WakaTime tool, included a Zig-compiled native binary designed to stealthily infect all integrated development environments (IDEs) on a developer's machine. Once installed, the binary identified and compromised various IDEs, including VS Code, VSCodium, Positron, and AI-powered coding tools like Cursor and Windsurf. The attack involved downloading a second-stage malicious extension from an attacker-controlled GitHub account, which exfiltrated sensitive data and deployed a remote access trojan (RAT) that installed an information-stealing Google Chrome extension. ([thehackernews.com](https://thehackernews.com/2026/04/glassworm-campaign-uses-zig-dropper-to.html?utm_source=openai)) This incident underscores the evolving sophistication of supply chain attacks targeting developer environments. The use of native binaries compiled in Zig to propagate malware across multiple IDEs highlights the need for enhanced vigilance and security measures within the software development community. Developers are advised to scrutinize extensions before installation and monitor their systems for unauthorized changes to prevent similar compromises.
5 months ago
Kill Chain
APT28's PRISMEX Malware Campaign: A Threat to Global Security
In early 2026, the Russian state-sponsored group APT28, also known as Fancy Bear, launched a sophisticated cyber-espionage campaign targeting Ukraine and its NATO allies. The operation, active since at least September 2025 and intensifying in January 2026, involved the deployment of a modular malware suite named PRISMEX. This suite utilized advanced steganography, Component Object Model (COM) hijacking, and exploited newly disclosed vulnerabilities, including CVE-2026-21509 and CVE-2026-21513, to infiltrate defense supply chains and critical infrastructure sectors. The campaign's strategic focus on supply chains and operational planning capabilities underscores a shift toward operational disruption, potentially paving the way for more destructive activities. ([thehackernews.com](https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html?utm_source=openai)) The PRISMEX campaign highlights the persistent and evolving threat posed by APT28, emphasizing the necessity for organizations to adopt proactive cybersecurity measures. The rapid weaponization of vulnerabilities and the use of sophisticated techniques like steganography and cloud service abuse demonstrate the group's advanced capabilities. This incident serves as a critical reminder for entities within targeted sectors to enhance their security postures and remain vigilant against such advanced persistent threats. ([thehackernews.com](https://thehackernews.com/2026/04/apt28-deploys-prismex-malware-in.html?utm_source=openai))
5 months ago
Kill Chain
Anthropic's Claude Mythos AI Model: A Double-Edged Sword in Cybersecurity
In April 2026, Anthropic unveiled Claude Mythos Preview, an advanced AI model capable of autonomously identifying and exploiting zero-day vulnerabilities across major operating systems and web browsers. This model discovered thousands of critical security flaws, including a 27-year-old bug in OpenBSD, raising significant concerns about its potential misuse. To mitigate risks, Anthropic restricted access to select organizations through Project Glasswing, collaborating with tech giants like Apple, Microsoft, and Google to enhance cybersecurity defenses. The emergence of AI models like Claude Mythos underscores the urgent need for robust security measures and regulatory frameworks to prevent malicious exploitation. As AI capabilities advance, organizations must proactively adapt their cybersecurity strategies to address these evolving threats.
5 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

