Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3253 to 3264 of 5988
TA551 Botnet Manager Sentenced for Ransomware Attacks
In March 2026, Ilya Angelov, a Russian national and co-manager of the cybercriminal group TA551 (also known as Shathak or GOLD CABIN), was sentenced to two years in prison. Angelov's group operated a massive botnet that distributed malware through large-scale phishing campaigns, leading to ransomware attacks on 72 U.S. companies between 2018 and 2019. These attacks resulted in over $14 million in extortion payments. The botnet infected approximately 3,000 computers daily at its peak, facilitating the deployment of ransomware such as BitPaymer. This sentencing underscores the persistent threat posed by sophisticated cybercriminal organizations like TA551, which have been active since at least 2018. Their use of phishing campaigns to distribute malware highlights the critical need for organizations to implement robust email security measures and user awareness training to mitigate such risks.
5 months ago
Kill Chain
Critical Code Injection Vulnerability in Langflow's CSV Agent Node
In February 2026, a critical Remote Code Execution (RCE) vulnerability, identified as CVE-2026-27966, was discovered in Langflow, an open-source platform for building AI-powered agents and workflows. This flaw resides in the CSV Agent node, which, prior to version 1.8.0, hardcoded the parameter `allow_dangerous_code=True`, inadvertently exposing LangChain’s Python REPL tool (`python_repl_ast`). This misconfiguration allows unauthenticated attackers to execute arbitrary Python and OS commands on the server via prompt injection, leading to full system compromise. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-27966/?utm_source=openai)) The rapid exploitation of this vulnerability underscores the critical need for organizations to promptly address security flaws in AI development tools. As AI platforms become integral to business operations, ensuring their security is paramount to prevent potential data breaches and operational disruptions.
5 months ago
Kill Chain
Red Menshen's BPFDoor Malware: A 2026 Telecom Security Wake-Up Call
In early 2026, the Chinese state-sponsored Advanced Persistent Threat (APT) group known as Red Menshen executed a sophisticated cyber-espionage campaign targeting telecommunications providers across multiple regions, including South America and Southeast Asia. Utilizing an advanced variant of their BPFDoor malware, the attackers exploited vulnerabilities in edge network devices to gain initial access. Once inside, they deployed custom Linux-based implants to establish persistent backdoors, enabling them to conduct extensive reconnaissance and exfiltrate sensitive subscriber data over an extended period. The stealthy nature of BPFDoor allowed the attackers to bypass traditional security measures, remaining undetected for months. This breach underscores the evolving tactics of nation-state actors in targeting critical infrastructure sectors, particularly telecommunications, to gather intelligence and potentially disrupt services. The incident highlights the urgent need for enhanced security measures, including robust monitoring of network edge devices and the implementation of advanced threat detection systems to identify and mitigate such sophisticated attacks.
5 months ago
Kill Chain
Nation-State Exploitation of Internet-Connected Cameras: A 2026 Analysis
In early 2026, nation-state actors, notably from Iran and Russia, intensified cyber operations targeting internet-connected surveillance cameras across the Gulf region and Eastern Europe. These actors exploited known vulnerabilities in IP cameras, such as those from Hikvision and Dahua, to gain unauthorized access. This access enabled real-time intelligence gathering, including monitoring military movements and assessing battle damage. The compromised devices were leveraged to support missile targeting and other strategic operations, significantly impacting regional security dynamics. ([asisonline.org](https://www.asisonline.org/security-management-magazine/latest-news/today-in-security/2026/march/camera-compromise-targeting/?utm_source=openai)) This incident underscores a growing trend where nation-states exploit unsecured IoT devices for espionage and military advantage. The proliferation of internet-connected cameras with inadequate security measures presents a substantial risk, highlighting the urgent need for robust cybersecurity practices and regulatory oversight to mitigate such threats.
5 months ago
Kill Chain
Checkmarx 2026 Supply Chain Attack: A Wake-Up Call for CI/CD Security
In March 2026, the threat actor group TeamPCP executed a sophisticated supply chain attack by compromising Checkmarx's GitHub Actions, specifically the 'ast-github-action' repository. The attackers injected credential-stealing malware into all 91 tags of the repository, from v0.1-alpha through v2.3.32, enabling unauthorized access to cloud services, GitHub repositories, and CI/CD pipelines of organizations utilizing these actions. This breach underscores the critical vulnerabilities present in software supply chains and the potential for widespread impact when trusted development tools are compromised. This incident highlights the escalating trend of supply chain attacks targeting development infrastructure, emphasizing the necessity for organizations to implement stringent security measures within their CI/CD pipelines. The event also serves as a reminder of the importance of continuous monitoring and rapid response strategies to mitigate the risks associated with such sophisticated cyber threats.
5 months ago
Kill Chain
Aqua Security Trivy Supply Chain Attack: A 2026 Case Study
In March 2026, a supply chain attack targeted Aqua Security's Trivy, a widely used open-source vulnerability scanner. Unauthorized code was discovered in versions 1.8.12 and 1.8.13 of the Trivy VS Code extension on the OpenVSX registry, uploaded on February 27 and 28, 2026. The malicious code introduced hidden natural-language prompts designed to exploit developers' AI coding tools, turning them into silent data collection instruments. This tampering was not present in the public GitHub repository, making detection challenging. ([cryptika.com](https://www.cryptika.com/threat-actors-exploit-openvsx-aqua-trivy-with-malicious-ai-prompts-to-hijack-local-coding-tools/?utm_source=openai)) This incident underscores the growing trend of supply chain attacks targeting development tools, emphasizing the need for rigorous validation of third-party components. Organizations must enhance their security practices to mitigate risks associated with compromised software dependencies.
5 months ago
Kill Chain
TeamPCP's Supply Chain Attack: Unveiling the Telnyx SDK Compromise and Ransomware Expansion
In March 2026, the threat actor TeamPCP executed a sophisticated supply chain attack by compromising the Telnyx Python SDK on the Python Package Index (PyPI). Malicious versions 4.87.1 and 4.87.2 were published, embedding payloads within WAV audio files—a novel steganography technique. These payloads targeted Windows systems by dropping a persistent binary named 'msbuild.exe' into the Startup folder, while Linux and macOS systems faced credential harvesting similar to previous LiteLLM compromises. Forensic analyses confirmed the use of RSA-4096 encryption and specific exfiltration patterns consistent with TeamPCP's tactics. The compromised versions were promptly quarantined by PyPI. Concurrently, TeamPCP partnered with the Vect ransomware-as-a-service operation and BreachForums, distributing affiliate keys to approximately 300,000 users, potentially enabling one of the largest coordinated ransomware deployments observed. Additionally, the LAPSUS$ group claimed a 3GB data breach of AstraZeneca, allegedly using credentials obtained through TeamPCP's activities. This breach reportedly includes internal code repositories, cloud infrastructure configurations, and employee data. Organizations affected by any phase of the TeamPCP campaign are urged to rotate credentials immediately and monitor for indicators of compromise.
5 months ago
Kill Chain
RedLine Infostealer Administrator Extradited to US in 2026
In March 2026, Armenian national Hambardzum Minasyan was extradited to the United States to face charges for his alleged role in managing the RedLine infostealer malware operation. Minasyan is accused of registering virtual private servers and web domains integral to RedLine's infrastructure, establishing cryptocurrency accounts for affiliate payments, and creating file-sharing repositories used to distribute the malware. RedLine, a malware-as-a-service platform, has been responsible for stealing sensitive data from millions of victims worldwide. Minasyan faces charges including access device fraud, conspiracy to commit computer intrusion, and money laundering, with a potential maximum sentence of 30 years in prison. This extradition underscores the ongoing international efforts to dismantle cybercriminal networks and hold perpetrators accountable. The case highlights the persistent threat posed by infostealer malware and the importance of global cooperation in combating cybercrime.
5 months ago
Kill Chain
CitrixBleed 2: A Critical Vulnerability in NetScaler Appliances
In June 2025, Citrix disclosed a critical vulnerability (CVE-2025-5777), dubbed 'CitrixBleed 2,' affecting NetScaler ADC and Gateway appliances configured as Gateways or AAA virtual servers. This flaw allows unauthenticated attackers to perform out-of-bounds memory reads, potentially leading to session hijacking and bypassing multifactor authentication. Despite the release of patches, over 100 organizations have been compromised, and thousands of instances remain unpatched, exposing sensitive data and critical systems to unauthorized access. The rapid exploitation of CitrixBleed 2 underscores a growing trend of attackers targeting network infrastructure vulnerabilities to gain initial access. This incident highlights the urgent need for organizations to prioritize timely patch management and enhance monitoring of network appliances to mitigate the risk of similar exploits.
5 months ago
Kill Chain
Emerging Threat: The Underground Trade of Paid AI Accounts in 2026
In early 2026, cybersecurity researchers uncovered a burgeoning underground market where cybercriminals are actively trading access to paid AI accounts. These accounts, associated with platforms like ChatGPT, Claude, Microsoft Copilot, and Perplexity, are being sold on dark web forums and encrypted messaging channels. Threat actors obtain these accounts through various means, including credential theft, exploitation of exposed API keys, and abuse of trial programs. The illicit access enables cybercriminals to leverage advanced AI tools for malicious activities such as crafting sophisticated phishing campaigns, automating fraudulent operations, and generating convincing social engineering content. This trend underscores the evolving tactics of cybercriminals who are increasingly integrating AI capabilities into their operations to enhance the scale and effectiveness of their attacks. Organizations must recognize the critical importance of securing AI platform credentials and monitoring for unauthorized access to prevent potential misuse. ([flare.io](https://flare.io/learn/resources/webinars-events/how-the-dark-web-is-reacting-to-the-ai-revolution-2?utm_source=openai))
5 months ago
Kill Chain
Torg Grabber: The Infostealer Targeting Cryptocurrency Wallets
In March 2026, cybersecurity researchers identified 'Torg Grabber,' a sophisticated infostealer malware targeting 728 cryptocurrency wallet browser extensions. The malware gains initial access through the 'ClickFix' technique, hijacking the clipboard to execute malicious PowerShell commands. Once inside, Torg Grabber exfiltrates sensitive data from 25 Chromium-based browsers and 8 Firefox variants, including credentials, cookies, and autofill data. It also targets 103 password managers and two-factor authentication tools, as well as 19 note-taking applications. The malware employs advanced evasion tactics, such as multi-layered obfuscation and reflective loading, to remain undetected. ([asec.ahnlab.com](https://asec.ahnlab.com/en/92902/?utm_source=openai)) The rapid development and deployment of Torg Grabber underscore a growing trend in the cyber threat landscape: the convergence of infostealers and ransomware. This evolution highlights the increasing sophistication of cybercriminals and the urgent need for organizations to enhance their security measures to protect sensitive data and digital assets. ([cyfirma.com](https://www.cyfirma.com/research/the-convergence-of-infostealers-and-ransomware-from-credential-harvesting-to-rapid-extortion-chains/?utm_source=openai))
5 months ago
Kill Chain
PolyShell Attacks Compromise Over Half of Vulnerable Magento Stores
In March 2026, attackers began exploiting the 'PolyShell' vulnerability in Magento Open Source and Adobe Commerce installations, affecting over half of all vulnerable stores. The flaw resides in Magento's REST API, which improperly handles file uploads, allowing attackers to execute remote code or perform account takeovers via stored cross-site scripting (XSS). Adobe released a fix in version 2.4.9-beta1 on March 10, 2026, but it has not yet reached the stable branch. This incident underscores the critical importance of timely patch management and the need for robust security configurations to prevent exploitation of known vulnerabilities. The rapid exploitation following public disclosure highlights the urgency for organizations to stay vigilant and proactive in their cybersecurity practices.
5 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

