Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3061 to 3072 of 5988
Storm-1175's Rapid Exploitation of Zero-Days Leads to Medusa Ransomware Attacks
In early April 2026, the China-based cybercriminal group Storm-1175 executed a series of high-velocity attacks targeting vulnerable internet-facing systems across sectors such as healthcare, education, professional services, and finance in Australia, the United Kingdom, and the United States. By exploiting a combination of zero-day and N-day vulnerabilities, including CVE-2025-10035 in Fortra's GoAnywhere MFT and CVE-2026-23760 in SmarterMail, the group rapidly gained initial access. Post-compromise activities involved deploying web shells, creating new user accounts, and utilizing remote monitoring and management tools like SimpleHelp and MeshAgent for persistence and lateral movement. Within as little as 24 hours, Storm-1175 exfiltrated data and deployed Medusa ransomware, leading to significant operational disruptions for the affected organizations. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/?utm_source=openai)) This incident underscores the increasing sophistication and speed of financially motivated threat actors in exploiting newly disclosed vulnerabilities. The rapid transition from initial access to ransomware deployment highlights the critical need for organizations to promptly apply security patches, monitor for unauthorized activities, and implement robust incident response strategies to mitigate such high-tempo cyber threats.
5 months ago
Kill Chain
Iranian Hackers Exploit PLC Vulnerabilities in U.S. Critical Infrastructure
In March 2026, Iranian-affiliated Advanced Persistent Threat (APT) actors initiated cyberattacks targeting internet-exposed Rockwell/Allen-Bradley programmable logic controllers (PLCs) within U.S. critical infrastructure sectors, including Government Services, Water and Wastewater Systems, and Energy. These attacks involved unauthorized access to PLCs, manipulation of project files, and alteration of data displayed on Human-Machine Interface (HMI) and Supervisory Control and Data Acquisition (SCADA) systems, leading to operational disruptions and financial losses. This incident underscores the escalating cyber threat landscape, particularly in the context of geopolitical tensions. Organizations must prioritize securing internet-facing operational technology assets to mitigate risks associated with state-sponsored cyber activities.
5 months ago
Kill Chain
Critical Remote Code Execution Vulnerability in Flowise AI: CVE-2025-59528
In September 2025, a critical remote code execution (RCE) vulnerability, identified as CVE-2025-59528, was discovered in Flowise AI's version 3.0.5. This flaw resided in the CustomMCP node, which improperly executed user-supplied JavaScript code without validation, granting attackers full Node.js runtime privileges. Exploitation of this vulnerability could lead to complete system compromise, unauthorized command execution, and data exfiltration. Flowise addressed this issue by releasing version 3.0.6, which rectified the vulnerability. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-59528?utm_source=openai)) As of April 2026, active exploitation of CVE-2025-59528 has been observed, with over 12,000 Flowise instances exposed to potential attacks. This resurgence underscores the critical need for organizations to ensure their systems are updated to the latest secure versions to mitigate such high-severity threats. ([thehackernews.com](https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html?utm_source=openai))
5 months ago
Kill Chain
Critical Security Flaw in Ninja Forms Plugin Puts WordPress Sites at Risk
In early 2026, a critical vulnerability (CVE-2026-0740) was discovered in the Ninja Forms File Uploads plugin for WordPress, affecting versions up to 3.3.26. This flaw allowed unauthenticated attackers to upload arbitrary files, including malicious PHP scripts, leading to potential remote code execution and complete site takeover. The vulnerability stemmed from inadequate validation of file types and extensions during the file upload process. The issue was reported on January 8, 2026, and a full patch was released on March 19, 2026, with version 3.3.27. Despite the availability of a fix, exploitation attempts surged, with over 3,600 attacks blocked in a single day. This incident underscores the critical importance of timely software updates and robust security practices in mitigating emerging threats.
5 months ago
Kill Chain
FBI's 2025 Cybercrime Report: A 26% Surge to $21 Billion in Losses
In 2025, the FBI's Internet Crime Complaint Center (IC3) reported that Americans lost nearly $21 billion to cyber-enabled crimes, marking a 26% increase from the previous year. The most prevalent incidents included phishing attacks, extortion, and investment scams, with cryptocurrency-related fraud accounting for over $11 billion in losses. Notably, individuals over the age of 60 were disproportionately affected, reporting $7.7 billion in losses, a 37% rise from 2024. Additionally, the FBI highlighted the emergence of AI-driven scams, which resulted in 22,300 complaints and $893 million in losses, involving tactics such as voice cloning and deepfake videos. This surge underscores the evolving sophistication of cybercriminals, who are increasingly leveraging advanced technologies like artificial intelligence to enhance the effectiveness of their schemes. The significant financial impact on older adults highlights the urgent need for targeted education and robust cybersecurity measures to protect vulnerable populations from these emerging threats.
5 months ago
Kill Chain
GPUBreach: Unveiling the 2026 NVIDIA GDDR6 RowHammer Vulnerability
In April 2026, researchers from the University of Toronto unveiled 'GPUBreach,' a sophisticated RowHammer attack targeting NVIDIA GPUs equipped with GDDR6 memory. This attack exploits bit-flips in GPU memory to corrupt page tables, granting an unprivileged process arbitrary read/write access to GPU memory. By leveraging vulnerabilities in the NVIDIA driver, attackers can escalate privileges to gain full control over the host system, even with IOMMU protections enabled. The implications are severe, particularly for cloud AI infrastructures and multi-tenant GPU deployments, as GPUBreach enables attackers to compromise entire systems without physical access. This development underscores the evolving nature of hardware-based attacks and the necessity for robust security measures in GPU environments. ([thehackernews.com](https://thehackernews.com/2026/04/new-gpubreach-attack-enables-full-cpu.html?utm_source=openai))
5 months ago
Kill Chain
Critical Docker Authorization Bypass Vulnerability (CVE-2026-34040) Discovered
In March 2026, a high-severity vulnerability (CVE-2026-34040) was identified in Docker Engine, allowing attackers to bypass authorization plugins (AuthZ) by sending oversized HTTP request bodies. This flaw enables unauthorized users to perform privileged container operations, potentially leading to full host system compromise. The issue affects Docker Engine versions prior to 29.3.1 and is a result of an incomplete fix for a previous vulnerability (CVE-2024-41110) addressed in July 2024. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-34040/?utm_source=openai)) The discovery of this vulnerability underscores the persistent risks associated with authorization bypass flaws in critical infrastructure. Organizations relying on Docker for container management must promptly update to version 29.3.1 or later to mitigate this threat. ([cyera.com](https://www.cyera.com/blog/cyera-research-discovers-docker-authorization-bypass-that-silently-disables-security-policies?utm_source=openai))
5 months ago
Kill Chain
ComfyUI Cryptomining Botnet Attack 2026
In April 2026, over 1,000 internet-exposed instances of ComfyUI, a popular stable diffusion platform, were targeted in a sophisticated cryptomining botnet campaign. Attackers utilized a custom Python scanner to identify vulnerable ComfyUI deployments, exploiting misconfigurations that allowed remote code execution via custom nodes. Upon successful exploitation, compromised hosts were enlisted into a botnet mining Monero and Conflux cryptocurrencies, managed through a Flask-based command-and-control dashboard. The campaign also employed persistence mechanisms to maintain control over infected systems. This incident underscores the critical need for securing internet-facing applications and services, as attackers continue to exploit misconfigurations and vulnerabilities to deploy cryptomining operations. Organizations must prioritize regular security assessments, implement robust authentication mechanisms, and monitor for unauthorized activities to mitigate such threats.
5 months ago
Kill Chain
APT28's 2025 DNS Hijacking Campaign: A Wake-Up Call for Network Security
In 2025, the Russian state-sponsored cyber group APT28, also known as Fancy Bear, exploited vulnerabilities in MikroTik and TP-Link routers to conduct a large-scale DNS hijacking campaign. By compromising these routers, APT28 redirected internet traffic through attacker-controlled servers, enabling adversary-in-the-middle attacks that harvested credentials from web and email services. This operation targeted a broad range of victims, including organizations linked to the UK Ministry of Defence and NATO logistics contractors, posing significant risks of credential theft, data manipulation, and broader network compromise. ([ncsc.gov.uk](https://www.ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dns-hijacking-operations?utm_source=openai)) This incident underscores the critical importance of securing network infrastructure against sophisticated state-sponsored threats. The exploitation of widely used routers highlights the need for organizations to implement robust security measures, including regular firmware updates, strong authentication protocols, and continuous monitoring to detect and mitigate such attacks.
5 months ago
Kill Chain
Russia Hacked Routers to Steal Microsoft Office Tokens
In April 2026, Russian state-sponsored hackers, identified as APT28 (also known as Fancy Bear or Forest Blizzard), exploited vulnerabilities in outdated MikroTik and TP-Link routers to hijack DNS settings. This allowed them to intercept Microsoft Office authentication tokens from users across more than 18,000 networks without deploying malware. The attackers targeted government agencies, law enforcement, and third-party email providers, compromising over 200 organizations and 5,000 consumer devices. ([cyberkendra.com](https://www.cyberkendra.com/2026/04/your-router-is-spying-on-you-and.html?utm_source=openai)) This incident underscores the critical need for organizations to secure network infrastructure, especially as remote work increases reliance on home and small office routers. Ensuring devices are updated and monitoring for unauthorized DNS changes are essential to prevent similar attacks.
5 months ago
Kill Chain
AI-Driven Supply Chain Attack Compromises GitHub Repositories
In March 2026, a threat actor utilized AI-assisted automation to execute over 450 exploit attempts against open-source repositories on GitHub. The campaign, identified as 'prt-scan,' specifically targeted repositories misconfigured with the 'pull_request_target' workflow trigger. While less than 10% of these attempts were successful, the attacker managed to compromise at least two NPM packages, leading to the exposure of ephemeral GitHub credentials. This incident underscores the growing trend of AI-enhanced supply chain attacks, where adversaries leverage automation to scale their operations and exploit common misconfigurations. Organizations are urged to review and secure their CI/CD pipelines to mitigate such risks.
5 months ago
Kill Chain
Fortinet's 2026 Unauthenticated API Access Bypass: A Critical Security Alert
In April 2026, Fortinet disclosed a critical vulnerability (CVE-2026-35616) in its FortiClient Endpoint Management Server (EMS) versions 7.4.5 and 7.4.6. This improper access control flaw allowed unauthenticated attackers to execute unauthorized code or commands via crafted API requests. The vulnerability was actively exploited in the wild, prompting Fortinet to release emergency hotfixes and advise customers to apply them immediately. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/?utm_source=openai)) The incident underscores the persistent targeting of Fortinet products by threat actors, highlighting the importance of timely patch management and vigilant monitoring of security advisories to mitigate risks associated with zero-day vulnerabilities. ([tenable.com](https://www.tenable.com/blog/cve-2026-35616-fortinet-forticlientems-improper-access-control-vulnerability-exploited-in-the?utm_source=openai))
5 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

