Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3361 to 3372 of 5987
Konni's 2026 Phishing Attack Deploys AI-Generated EndRAT via KakaoTalk
In early 2026, the North Korean state-sponsored hacking group Konni launched a sophisticated phishing campaign targeting blockchain developers in Japan, Australia, and India. The attackers utilized AI-generated PowerShell malware, delivered through malicious emails disguised as financial notices. These emails contained ZIP files with Windows shortcuts that executed embedded PowerShell loaders, leading to the deployment of the EndRAT backdoor. This malware enabled the attackers to establish persistence, evade detection, and gain unauthorized access to development environments, potentially compromising sensitive blockchain-related resources and infrastructure. This incident underscores a significant evolution in cyber threat tactics, highlighting the increasing use of artificial intelligence by threat actors to enhance the sophistication and effectiveness of their attacks. The targeting of blockchain developers indicates a strategic shift towards compromising emerging financial technologies, emphasizing the need for heightened vigilance and advanced security measures within the industry.
6 months ago
Kill Chain
Amazon Bedrock AgentCore 2026 DNS Exfiltration Vulnerability
In March 2026, cybersecurity researchers identified a vulnerability in Amazon Bedrock AgentCore's Code Interpreter, allowing attackers to exfiltrate sensitive data via DNS queries. The flaw permitted outbound DNS requests from the sandbox environment, enabling unauthorized data transmission. This vulnerability underscores the critical need for robust security measures in AI code execution platforms to prevent data breaches. Organizations utilizing AI agents must implement stringent controls to mitigate such risks.
6 months ago
Kill Chain
LeakNet Ransomware's 2026 Campaign: Exploiting ClickFix and Deno Runtime for Stealthy Attacks
In March 2026, the LeakNet ransomware group initiated a sophisticated campaign leveraging the ClickFix social engineering technique to gain initial access to target systems. By compromising legitimate websites, they presented users with deceptive prompts instructing them to execute malicious PowerShell commands under the guise of resolving non-existent errors. This method effectively bypassed traditional security measures, leading to the deployment of an in-memory loader utilizing the Deno JavaScript runtime. This loader facilitated the execution of the CastleRAT malware directly in memory, thereby evading detection by conventional endpoint security solutions. The campaign resulted in significant data breaches and operational disruptions across multiple sectors. This incident underscores a concerning evolution in ransomware tactics, highlighting the increasing sophistication of social engineering methods and the exploitation of novel technologies like the Deno runtime for stealthy malware deployment. The use of in-memory execution techniques poses a substantial challenge to traditional security defenses, emphasizing the need for advanced detection mechanisms and comprehensive user education to mitigate such threats.
6 months ago
Kill Chain
Warlock Ransomware Group's 2025 Exploitation of SharePoint Vulnerabilities
In mid-2025, the Warlock ransomware group exploited unpatched Microsoft SharePoint servers to gain initial access to various organizations across North America, Europe, Asia, and Africa. Utilizing known vulnerabilities (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771), they deployed web shells via HTTP POST requests, enabling reconnaissance, credential theft, and lateral movement. The attack culminated in the deployment of ransomware, encrypting files with the .x2anylock extension and exfiltrating data using RClone. ([clearphish.ai](https://www.clearphish.ai/news/warlock-ransomware-sharepoint-attacks-2025?utm_source=openai)) This incident underscores the critical importance of timely patch management, especially for widely used enterprise applications like SharePoint. The Warlock group's rapid escalation from forum discussions to impactful campaigns highlights the evolving threat landscape and the need for organizations to bolster their cybersecurity defenses against sophisticated ransomware operations.
6 months ago
Kill Chain
Unveiling the Stealth: China's Prolonged Cyber Espionage in Southeast Asia
In March 2026, Palo Alto Networks' Unit 42 uncovered a prolonged cyber espionage campaign attributed to Chinese state-sponsored actors, targeting military organizations in Southeast Asia since at least 2020. The attackers employed novel backdoors, including 'AppleChris' and 'MemFun,' and utilized dead-drop resolvers on platforms like Pastebin and Dropbox to maintain covert command-and-control channels. Their operations focused on exfiltrating sensitive military data, such as information on capabilities, organizational structures, and collaborations with Western forces. The campaign demonstrated strategic patience, with attackers maintaining undetected access for extended periods and employing advanced evasion techniques like delayed execution and timestomping to avoid detection. This incident underscores the evolving sophistication of state-sponsored cyber threats, highlighting the need for organizations to enhance their cybersecurity measures. The use of legitimate web services for malicious activities and the deployment of custom malware with advanced evasion tactics reflect a broader trend in cyber espionage, emphasizing the importance of proactive threat intelligence and robust security protocols.
6 months ago
Kill Chain
GlassWorm Malware: A 2026 Supply Chain Attack on Developer Ecosystems
In early 2026, the GlassWorm malware resurfaced, compromising the Open VSX Registry by infiltrating trusted developer accounts. Attackers published malicious updates to widely used VS Code extensions, embedding loaders that executed encrypted payloads to steal sensitive information, including developer credentials and cryptocurrency wallets. The malware employed advanced evasion techniques, such as using invisible Unicode characters and leveraging the Solana blockchain for command-and-control communication, making detection and mitigation challenging. This incident underscores the escalating sophistication of supply chain attacks targeting developer ecosystems. The use of decentralized infrastructures and obfuscation methods highlights the need for enhanced vigilance and security measures within software development communities to prevent similar breaches.
6 months ago
Kill Chain
Wing FTP Server 2025 Information Disclosure Vulnerability: What You Need to Know
In July 2025, a medium-severity information disclosure vulnerability, identified as CVE-2025-47813, was discovered in Wing FTP Server versions 7.4.3 and earlier. This flaw allowed unauthenticated attackers to obtain sensitive information about the server's local file system by exploiting the 'loginok.html' page with a specially crafted UID cookie. The vulnerability was addressed in version 7.4.4, released on May 14, 2025. Despite the availability of a patch, many systems remained unpatched, leaving them susceptible to potential exploitation. The incident underscores the critical importance of timely software updates and robust vulnerability management practices. Organizations are urged to prioritize the remediation of known vulnerabilities to mitigate the risk of unauthorized access and data breaches.
6 months ago
Kill Chain
Iranian Cyber Threat Evolution: Exploiting MDM Platforms in 2026
In March 2026, Iranian state-sponsored cyber actors executed a large-scale attack by compromising privileged identities within cloud-based Mobile Device Management (MDM) platforms. This allowed them to issue legitimate remote-wipe commands, resulting in the simultaneous erasure of data from over 200,000 devices globally. The attack exploited administrative tools to bypass traditional endpoint detection systems, leading to significant operational disruptions across multiple organizations. This incident underscores a strategic shift in Iranian cyber operations from deploying custom malware to leveraging existing administrative infrastructures for destructive purposes. The use of legitimate management tools for widescale data destruction highlights the evolving threat landscape and the need for organizations to enhance identity and access management protocols to mitigate such risks.
6 months ago
Kill Chain
Introducing Augustus: Praetorian's Open-Source LLM Vulnerability Scanner
In February 2026, Praetorian released Augustus, an open-source vulnerability scanner designed to test Large Language Models (LLMs) against a comprehensive suite of adversarial attacks. Augustus automates over 210 distinct attack vectors, including prompt injections and jailbreaks, across 28 LLM providers. This tool addresses the growing need for robust security testing as enterprises rapidly integrate generative AI into their products. By providing a portable, single-binary solution, Augustus facilitates seamless integration into continuous integration/continuous deployment (CI/CD) pipelines, enabling security teams to identify and mitigate vulnerabilities efficiently. The release of Augustus underscores the escalating threats targeting LLMs, as adversaries increasingly exploit these models for malicious purposes. The tool's comprehensive testing capabilities highlight the necessity for organizations to proactively assess and fortify their AI systems against evolving attack methodologies.
6 months ago
Kill Chain
South Korea's NTS Security Lapse Results in $4.8M Crypto Theft
In February 2026, South Korea's National Tax Service (NTS) conducted raids on 124 high-value tax evaders, seizing digital assets worth approximately $5.6 million. During a press release showcasing the operation, the NTS inadvertently published images displaying a Ledger hardware wallet alongside a handwritten note containing the wallet's mnemonic recovery phrase. This exposure allowed an unauthorized individual to access and transfer 4 million Pre-Retogeum (PRTG) tokens, valued at about $4.8 million, from the confiscated wallet. The NTS has since apologized for the oversight and initiated measures to prevent similar incidents in the future. ([koreajoongangdaily.joins.com](https://koreajoongangdaily.joins.com/news/2026-03-01/national/socialAffairs/Police-probing-unauthorized-crypto-transfer-after-NTS-inadvertently-shared-wallet-recovery-phrase/2534349?utm_source=openai)) This incident underscores the critical importance of secure handling and storage of digital assets, especially by governmental agencies. As cryptocurrency adoption grows, ensuring robust security protocols and staff training is essential to prevent such costly errors and maintain public trust.
6 months ago
Kill Chain
Kwamaine Jerell Ford's 2026 Phishing Scheme Targets Professional Athletes
In March 2026, Kwamaine Jerell Ford, a 34-year-old from Georgia, was indicted for orchestrating a sophisticated phishing scheme targeting professional NBA and NFL athletes. While incarcerated for a similar offense, Ford allegedly impersonated an adult film star to deceive athletes into providing their iCloud credentials and multifactor authentication codes. This access enabled him to steal sensitive personal and financial information, leading to unauthorized transactions exceeding 2,000 instances between November 2020 and September 2024. The scheme also involved coercing an OnlyFans model into recording commercial sex acts with athletes without their consent, further complicating the legal ramifications. This incident underscores the persistent threat of social engineering attacks, even from individuals previously convicted of similar crimes. It highlights the critical need for continuous vigilance, robust cybersecurity measures, and comprehensive education on recognizing and mitigating phishing attempts, especially for high-profile individuals who are frequent targets.
6 months ago
Kill Chain
UK's Companies House Security Flaw Exposes Business Data - 2026
In March 2026, the UK's Companies House disclosed a significant security vulnerability in its WebFiling service, which had been present since October 2025. This flaw allowed authenticated users to access and potentially modify sensitive information of any registered company by exploiting a back-navigation loophole. The exposed data included directors' residential addresses, email addresses, and dates of birth. The agency has since rectified the issue, notified affected parties, and reported the incident to the Information Commissioner's Office (ICO) and the National Cyber Security Centre (NCSC). This incident underscores the critical importance of rigorous security testing and prompt response to vulnerabilities in public sector digital services. The exposure of personal data over an extended period raises concerns about potential misuse and the necessity for enhanced monitoring and compliance measures to protect sensitive information.
6 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

