Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3241 to 3252 of 5988
LiteLLM Supply Chain Attack: A Wake-Up Call for Open-Source Security
In March 2026, the widely used Python library LiteLLM was compromised in a supply chain attack. Threat actors, identified as TeamPCP, gained access to the LiteLLM account and released malicious versions 1.82.7 and 1.82.8 on the PyPI repository. These versions contained backdoors that harvested sensitive data, including SSH keys, cloud tokens, Kubernetes secrets, and crypto wallets. The malware also attempted lateral movement across Kubernetes clusters by deploying privileged pods and established persistence via systemd backdoors. ([techradar.com](https://www.techradar.com/pro/security/top-llm-pypl-package-compromised-to-steal-user-details-heres-what-we-know?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting open-source software repositories. The compromise of LiteLLM, a tool integral to AI model management, highlights the critical need for enhanced security measures in software development pipelines to prevent similar breaches.
5 months ago
Kill Chain
Coruna Exploit Kit: A Cautionary Tale of Advanced Hacking Tools in Cybercriminal Hands
In 2025, the Coruna exploit kit emerged as a sophisticated tool targeting iPhones running iOS versions 13.0 through 17.2.1. Initially deployed by a surveillance vendor for government clients, Coruna was later utilized by Russian espionage groups in attacks against Ukrainian users and by financially motivated hackers in China. The kit comprises five exploit chains and 23 vulnerabilities, including CVE-2023-32434 and CVE-2023-38606, previously exploited in Operation Triangulation. These vulnerabilities enable remote code execution and privilege escalation, granting attackers full control over affected devices. ([techcrunch.com](https://techcrunch.com/2026/03/03/a-suite-of-government-hacking-tools-targeting-iphones-is-now-being-used-by-cybercriminals/?utm_source=openai)) The proliferation of Coruna underscores the risks associated with the leakage of government-grade hacking tools into the broader cybercriminal ecosystem. This incident highlights the urgent need for organizations to implement robust security measures, promptly apply software updates, and monitor for emerging threats to protect sensitive data and maintain operational integrity. ([techcrunch.com](https://techcrunch.com/2026/03/03/a-suite-of-government-hacking-tools-targeting-iphones-is-now-being-used-by-cybercriminals/?utm_source=openai))
5 months ago
Kill Chain
Understanding the Coruna iOS Exploit Kit: A 2026 Security Threat
In early 2026, the Coruna iOS exploit kit emerged as a significant threat, targeting iPhones running iOS versions 13.0 through 17.2.1. This sophisticated toolkit comprises 23 exploits, including zero-day vulnerabilities, enabling attackers to execute zero-click attacks via iMessage. Initially developed for government surveillance, Coruna has since been adopted by cybercriminal groups, leading to widespread data breaches and financial losses. The kit's capabilities allow for full device compromise, granting unauthorized access to sensitive information and enabling remote control of infected devices. The proliferation of Coruna underscores the evolving landscape of mobile threats and the critical need for robust security measures to protect against advanced exploit kits. Organizations and individuals must prioritize timely software updates, implement comprehensive security protocols, and remain vigilant against emerging threats to safeguard their digital assets.
5 months ago
Kill Chain
Critical Vulnerability in Anthropic's Claude Chrome Extension Highlights AI Security Risks
In March 2026, a critical vulnerability was discovered in Anthropic's Claude Chrome Extension, allowing malicious actors to inject prompts into the assistant without user interaction. This zero-click cross-site scripting (XSS) flaw enabled attackers to execute arbitrary commands by embedding malicious code into web pages, leading to potential data exfiltration and unauthorized actions. The vulnerability was promptly addressed by Anthropic through an emergency patch, mitigating the risk to users. This incident underscores the growing threat landscape associated with AI-powered browser extensions. As these tools become more integrated into daily workflows, they present new vectors for exploitation. Organizations must remain vigilant, ensuring that such extensions are regularly updated and monitored for security vulnerabilities to prevent similar attacks.
5 months ago
Kill Chain
Unveiling Red Menshen's 2026 BPFDoor Espionage in Telecom Networks
In 2026, the China-linked threat actor Red Menshen, also known as Earth Bluecrow, conducted a prolonged cyber espionage campaign targeting telecommunications networks across the Middle East and Asia. Utilizing the stealthy Linux backdoor BPFDoor, the group infiltrated critical infrastructure, including Home Subscriber Servers (HSS), to exfiltrate sensitive subscriber data. BPFDoor's advanced evasion techniques allowed it to bypass traditional security measures, enabling Red Menshen to maintain persistent access and conduct surveillance undetected for extended periods. This incident underscores the increasing sophistication of nation-state cyber threats targeting telecom infrastructure. The use of kernel-level implants and passive backdoors like BPFDoor highlights the need for enhanced detection capabilities and proactive security measures to protect critical communication networks from such covert operations.
5 months ago
Kill Chain
Unveiling the Scarlet Goldfinch 2025 ClickFix Malware Campaign
In 2025, the Scarlet Goldfinch threat actor launched a sophisticated malware campaign utilizing the ClickFix social engineering technique. This method deceived users into executing malicious commands under the guise of routine system verifications, leading to the installation of NetSupport Manager, a remote access tool. The campaign primarily targeted Windows systems, exploiting compromised websites to display fake browser update prompts, which, when acted upon, initiated the malware download and execution process. ([redcanary.com](https://redcanary.com/threat-detection-report/threats/scarlet-goldfinch/?utm_source=openai)) The significance of this incident lies in the evolution of social engineering tactics, highlighting the increasing sophistication of threat actors in bypassing traditional security measures. The widespread use of ClickFix underscores the necessity for enhanced user education and the implementation of robust security protocols to mitigate such deceptive attack vectors.
5 months ago
Kill Chain
Critical Vulnerabilities in WAGO Industrial Managed Switches Expose Systems to Remote Attacks
In early 2026, multiple critical vulnerabilities were discovered in WAGO GmbH & Co. KG's Industrial Managed Switches, notably models 852-1322 and 852-1328. These flaws, including stack buffer overflows and authentication bypasses, allowed unauthenticated remote attackers to execute arbitrary code, potentially leading to full system compromise. The vulnerabilities stemmed from unsafe input handling in the devices' web-based management interfaces, which utilized modified lighttpd servers and custom CGI binaries. Exploitation could result in denial-of-service conditions and unauthorized access to sensitive configurations. ([certvde.com](https://certvde.com/en/advisories/VDE-2026-004/?utm_source=openai)) This incident underscores the persistent risks associated with industrial control systems (ICS) and the critical need for robust security measures. The vulnerabilities highlight the importance of regular firmware updates, secure coding practices, and comprehensive network segmentation to protect against unauthorized access and potential operational disruptions.
5 months ago
Kill Chain
OpenCode Systems 2026 Access Control Vulnerability Exposes SMS Messages
In March 2026, a significant security vulnerability (CVE-2025-70614) was identified in OpenCode Systems' OC Messaging and USSD Gateway version 6.32.2. This flaw allowed authenticated users with low privileges to access SMS messages beyond their authorized scope by manipulating company or tenant identifier parameters. The vulnerability posed a substantial risk to data confidentiality across multi-tenant environments. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2025-70614/?utm_source=openai)) The incident underscores the critical importance of robust access control mechanisms in multi-tenant systems. Organizations are urged to review and strengthen their access control policies to prevent similar vulnerabilities and protect sensitive information.
5 months ago
Kill Chain
Critical RCE Vulnerability Discovered in PTC Windchill PLM Software
In March 2026, a critical remote code execution (RCE) vulnerability, identified as CVE-2026-4681, was discovered in PTC's Windchill Product Lifecycle Management (PLM) software. This flaw, stemming from improper deserialization of untrusted data, affects multiple versions of Windchill PDMLink and FlexPLM. Exploitation of this vulnerability could allow attackers to execute arbitrary code remotely, potentially compromising sensitive product data and disrupting manufacturing processes. PTC has acknowledged the issue and is actively developing a fix. In the interim, they have provided specific mitigation steps, including updates to Apache and IIS server configurations, to protect affected systems. Organizations utilizing Windchill are urged to implement these workarounds immediately to safeguard their environments. This incident underscores the persistent threat posed by software vulnerabilities in critical infrastructure sectors. The exploitation of deserialization flaws remains a favored technique among cyber adversaries, highlighting the necessity for continuous vigilance, timely patching, and adherence to secure coding practices to mitigate such risks.
5 months ago
Kill Chain
Apple's March 2026 Security Update: Essential Patches for Device Protection
In March 2026, Apple released a comprehensive security update addressing 85 vulnerabilities across its operating systems, including iOS, iPadOS, macOS, tvOS, watchOS, and visionOS. Notably, CVE-2025-43376 allowed remote attackers to view leaked DNS queries with Private Relay enabled, and CVE-2025-43534 permitted physical attackers to bypass Activation Lock on iOS devices. These vulnerabilities, among others, were patched to enhance system security and protect user data. This update underscores the critical importance of timely software updates, as unpatched vulnerabilities can be exploited by attackers to compromise devices and access sensitive information. Organizations and individuals are urged to apply these patches promptly to mitigate potential risks.
5 months ago
Kill Chain
RedLine Infostealer Developer Extradited to US in 2026
In March 2026, international law enforcement agencies successfully extradited Hambardzum Minasyan, an Armenian national, to the United States for his alleged involvement in the development and administration of the RedLine infostealer malware. RedLine, active since 2020, has been one of the most prevalent data-stealing malware variants, responsible for compromising millions of devices worldwide. Minasyan faces charges including conspiracy to commit access device fraud, conspiracy to violate the Computer Fraud and Abuse Act, and conspiracy to commit money laundering. The indictment alleges that he registered virtual private servers to host RedLine, established repositories for distributing the malware, and managed cryptocurrency accounts to receive payments from affiliates. This extradition marks a significant step in the ongoing efforts to dismantle cybercriminal networks operating on a global scale. The arrest and extradition of Minasyan underscore the persistent threat posed by infostealer malware like RedLine. Despite previous takedown operations, such as Operation Magnus in 2024, which targeted RedLine's infrastructure, the malware continues to be a tool for cybercriminals to steal sensitive information, including login credentials, financial data, and cryptocurrency wallets. Organizations must remain vigilant, as the convergence of infostealers and other cyber threats, like ransomware, has led to rapid extortion chains, emphasizing the need for robust cybersecurity measures and international cooperation to combat these evolving threats.
5 months ago
Kill Chain
Critical Authentication Bypass Vulnerability in TP-Link Routers Exposes Networks to Attack
In March 2026, TP-Link disclosed a critical authentication bypass vulnerability (CVE-2026-0834) affecting Archer C20 v6.0 and Archer AX53 v1.0 routers. This flaw resides in the TP-Link Device Debug Protocol (TDDP) module, allowing unauthenticated attackers on the same network to execute administrative commands, such as factory resets and reboots, without credentials. Exploitation of this vulnerability can lead to complete configuration loss and service disruption. This incident underscores the persistent risks associated with network infrastructure vulnerabilities, particularly in consumer-grade routers. The exploitation of such flaws can facilitate broader cyberattacks, including the formation of botnets and unauthorized access to sensitive information. Organizations and individuals must prioritize timely firmware updates and implement robust network security measures to mitigate these risks.
5 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

