Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3001 to 3012 of 5988
Cirro Cloud Security Breach 2026: Lessons Learned and Future Precautions
In 2026, Cirro, a cloud security tool, experienced a significant security incident where attackers exploited vulnerabilities in its platform, leading to unauthorized access to sensitive client data. The breach was initiated through a compromised administrative account, allowing threat actors to navigate internal systems undetected for several days. This intrusion resulted in the exfiltration of confidential information, affecting numerous organizations relying on Cirro for cloud security solutions. The incident underscores the critical importance of robust access controls and continuous monitoring in cloud environments. As cloud adoption accelerates, the frequency and sophistication of such breaches have increased, highlighting the need for organizations to implement comprehensive security measures and stay vigilant against evolving cyber threats.
5 months ago
Kill Chain
Obfuscated JavaScript Phishing Attack Delivers FormBook Malware - April 2026
In April 2026, a sophisticated phishing campaign was identified, distributing the FormBook infostealer malware through obfuscated JavaScript files. The attack began with phishing emails containing RAR archives that, when extracted, revealed large, obfuscated JavaScript files. These scripts utilized Windows-specific ActiveXObjects to establish persistence via scheduled tasks and dropped multiple files, including AES-encrypted data and .NET DLLs. The payloads were decrypted and executed using PowerShell scripts, ultimately injecting the FormBook malware into legitimate processes like MSBuild.exe. This multi-stage attack chain effectively evaded traditional detection mechanisms by leveraging obfuscation, encryption, and living-off-the-land techniques. The resurgence of such sophisticated phishing campaigns underscores the evolving tactics of threat actors and the necessity for organizations to enhance their email security measures and endpoint detection capabilities to mitigate the risks associated with advanced malware delivery methods.
5 months ago
Kill Chain
FBI Dismantles APT28's Global Router-Based Espionage Network
In April 2026, the FBI, in collaboration with international partners, executed Operation Masquerade to dismantle a sophisticated cyberespionage campaign orchestrated by APT28, also known as Fancy Bear or Forest Blizzard. This Russian state-sponsored group had compromised over 18,000 TP-Link routers across more than 120 countries, infiltrating over 200 organizations. By exploiting vulnerabilities in these routers, APT28 altered DNS settings to redirect internet traffic through attacker-controlled servers, enabling the interception of sensitive data, including credentials for Microsoft Outlook and Office 365 services. The operation involved sending commands to reset the compromised routers' DNS settings, effectively severing the attackers' access and mitigating further data exfiltration. ([justice.gov](https://www.justice.gov/opa/pr/justice-department-conducts-court-authorized-disruption-dns-hijacking-network-controlled?utm_source=openai)) This incident underscores the escalating threat posed by nation-state actors targeting network infrastructure to conduct large-scale espionage. The use of DNS hijacking to perform adversary-in-the-middle attacks highlights the need for organizations to secure all network devices, including SOHO routers, and to implement robust monitoring and response strategies to detect and mitigate such sophisticated threats. ([ncsc.gov.uk](https://www.ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dns-hijacking-operations?utm_source=openai))
5 months ago
Kill Chain
Iranian Cyberattacks on U.S. Critical Infrastructure: A 2026 Analysis
In March 2026, Iranian-affiliated cyber actors initiated a series of attacks targeting U.S. critical infrastructure sectors, including energy, water, and government services. These attackers exploited vulnerabilities in internet-exposed Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs), leading to operational disruptions and financial losses. The Cybersecurity and Infrastructure Security Agency (CISA), along with other federal agencies, issued a joint advisory warning of these ongoing threats and provided mitigation strategies to affected organizations. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/us-warns-of-iranian-hackers-targeting-critical-infrastructure/?utm_source=openai)) This incident underscores the escalating cyber threat landscape, particularly from nation-state actors targeting industrial control systems. Organizations must prioritize securing operational technology environments to prevent similar disruptions and safeguard critical services.
5 months ago
Kill Chain
Google's 2026 Announcement: Accelerating the Shift to Post-Quantum Cryptography by 2029
In March 2026, Google announced an accelerated timeline to migrate its systems to post-quantum cryptography (PQC) by 2029, moving up from the previously anticipated mid-2030s. This decision was driven by rapid advancements in quantum computing, particularly in hardware development, error correction, and factoring resource estimates, which suggest that quantum computers capable of breaking current encryption methods could emerge sooner than expected. Google's proactive approach aims to safeguard its systems, devices, and data against potential quantum threats. ([blog.google](https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/?utm_source=openai)) This move underscores the urgency for organizations to assess and enhance their cryptographic resilience. The looming possibility of quantum computers rendering existing encryption obsolete necessitates immediate action to transition to quantum-resistant algorithms, ensuring the continued security of sensitive information in the near future.
5 months ago
Kill Chain
Adobe Reader Zero-Day Exploit Uncovered in December 2025
In December 2025, attackers began exploiting a zero-day vulnerability in Adobe Reader by distributing maliciously crafted PDF documents. These documents, often containing Russian-language lures related to the Russian oil and gas industry, leveraged an unpatched flaw in Adobe Reader to steal data from compromised systems and potentially execute remote code, granting attackers full control over affected machines. This incident underscores the persistent threat posed by zero-day vulnerabilities and the importance of timely software updates. The use of industry-specific lures highlights the evolving tactics of threat actors targeting specific sectors.
5 months ago
Kill Chain
Bitcoin Depot's 2026 Security Breach: A Wake-Up Call for Cryptocurrency Security
In March 2026, Bitcoin Depot, a leading Bitcoin ATM operator, experienced a significant security breach when attackers infiltrated its IT systems and obtained credentials for digital asset settlement accounts. This unauthorized access enabled the transfer of approximately 50.9 Bitcoin, valued at $3.665 million at the time, from company-controlled wallets. The breach was detected on March 23, prompting Bitcoin Depot to activate incident response protocols, engage external cybersecurity experts, and notify law enforcement. Importantly, the company reported that customer platforms and data remained unaffected by this incident. This breach underscores the persistent vulnerabilities within the cryptocurrency sector, particularly concerning the security of internal corporate systems. The incident highlights the critical need for robust credential management and comprehensive security measures to protect digital assets. As the cryptocurrency market continues to expand, organizations must prioritize the implementation of stringent security protocols to mitigate the risk of such attacks.
5 months ago
Kill Chain
Eurail 2025 Data Breach: A Wake-Up Call for Travel Industry Cybersecurity
In late December 2025, Eurail B.V., a Netherlands-based travel company, experienced a significant data breach when unauthorized actors accessed its network and exfiltrated files containing sensitive customer information. The breach, which occurred on December 26, 2025, was discovered on January 5, 2026, and confirmed on February 25, 2026. Approximately 308,777 individuals were affected, with compromised data including names, passport numbers, dates of birth, email addresses, postal addresses, phone numbers, bank account references (IBANs), and health-related information. ([claimdepot.com](https://www.claimdepot.com/data-breach/eurail-2026?utm_source=openai)) This incident underscores the escalating threat landscape targeting the travel industry, where personal data is highly valuable. The breach highlights the critical need for robust cybersecurity measures, including regular system audits, employee training, and comprehensive incident response plans to mitigate potential risks and protect customer information.
5 months ago
Kill Chain
Supply Chain Attack on Smart Slider 3 Pro Compromises Websites in 2026
In April 2026, attackers compromised the update system of the Smart Slider 3 Pro plugin, affecting version 3.5.1.35 for both WordPress and Joomla platforms. This malicious update introduced multiple backdoors, created hidden administrator accounts, and exfiltrated sensitive data from affected websites. The incident underscores the critical importance of securing software supply chains to prevent unauthorized code distribution and maintain the integrity of widely used web applications. This event highlights a growing trend of supply chain attacks targeting popular web plugins, emphasizing the need for vigilant monitoring of software updates and the implementation of robust security measures to detect and prevent unauthorized modifications.
5 months ago
Kill Chain
Figure Technology Solutions Data Breach: A Wake-Up Call for Fintech Security
In February 2026, Figure Technology Solutions, a leading fintech company specializing in blockchain-enabled lending services, experienced a significant data breach. The incident began when an employee was deceived by a sophisticated voice phishing (vishing) attack, leading to unauthorized access to the company's systems. The cybercriminal group ShinyHunters claimed responsibility, exfiltrating approximately 2.5 gigabytes of sensitive customer data, including full names, addresses, dates of birth, phone numbers, Social Security numbers, and loan information. This breach affected nearly one million customers, exposing them to potential identity theft and financial fraud. ([crowdfundinsider.com](https://www.crowdfundinsider.com/2026/02/262975-figure-technology-faces-major-data-breach-impacting-nearly-one-million-customers/?utm_source=openai)) This incident underscores the escalating threat of social engineering attacks targeting financial institutions. Despite advancements in cybersecurity measures, human factors remain a critical vulnerability. The breach highlights the necessity for comprehensive security protocols, including robust employee training and advanced authentication mechanisms, to mitigate the risks associated with sophisticated phishing campaigns.
5 months ago
Kill Chain
ChipSoft Ransomware Attack: A Wake-Up Call for Healthcare Cybersecurity
In April 2026, ChipSoft, a leading Dutch healthcare software provider serving approximately 70% of the country's hospitals, suffered a ransomware attack. The incident led to the company's website going offline and raised concerns about potential unauthorized access to patient records. In response, several hospitals disconnected their systems as a precautionary measure. The full extent of the data breach remains under investigation. This attack underscores the escalating threat of ransomware targeting critical healthcare infrastructure. The incident highlights the urgent need for robust cybersecurity measures and comprehensive incident response plans to protect sensitive patient data and ensure the continuity of healthcare services.
5 months ago
Kill Chain
Google Chrome 2026: Device Bound Session Credentials Enhance Security Against Infostealer Threats
In April 2026, Google introduced Device Bound Session Credentials (DBSC) in Chrome 146 for Windows, aiming to combat the escalating threat of session cookie theft by infostealer malware. DBSC cryptographically binds authentication sessions to a user's specific device using hardware-backed security modules like the Trusted Platform Module (TPM). This binding ensures that even if session cookies are exfiltrated, they cannot be utilized on unauthorized devices, thereby mitigating unauthorized access to user accounts. ([security.googleblog.com](https://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html?utm_source=openai)) The deployment of DBSC is particularly timely given the rise of sophisticated infostealer malware, such as LummaC2, which harvests session cookies to bypass traditional authentication mechanisms, including multi-factor authentication (MFA). By rendering stolen session cookies ineffective on unauthorized devices, DBSC addresses a critical vulnerability in current web authentication practices. ([security.googleblog.com](https://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html?utm_source=openai))
5 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

