Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3481 to 3492 of 5983
BlackSanta Malware: A New Era of Targeted Cyber Threats in HR Workflows
In early 2026, Russian-speaking threat actors initiated the 'BlackSanta' campaign, targeting human resources (HR) workflows to deploy sophisticated malware capable of disabling endpoint detection and response (EDR) systems. The attack begins with resume-themed ISO files delivered through recruitment channels, which, when opened, execute malicious shortcuts that trigger a multi-stage infection chain. This chain includes obfuscated PowerShell commands extracting payloads from steganographic images and sideloading malicious DLLs via legitimate applications. Once executed, the malware performs extensive validation to evade analysis environments before deploying the 'BlackSanta' EDR killer. This component loads legitimate but exploitable kernel drivers to gain low-level system access, subsequently disabling security protections, including antivirus processes, EDR agents, and system logging. This enables attackers to exfiltrate sensitive data over encrypted HTTPS channels with minimal detection risk. The campaign underscores the increasing sophistication of cyber threats targeting operational business workflows, particularly in HR environments. Organizations are advised to apply rigorous security measures to HR systems, including enhanced endpoint protections, monitoring for unusual activity, and increasing security awareness among recruiting teams to mitigate such attacks.
6 months ago
Kill Chain
CISA Adds Three Known Exploited Vulnerabilities to Catalog
On March 9, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. These vulnerabilities include CVE-2021-22054, a Server-Side Request Forgery (SSRF) in VMware Workspace ONE UEM; CVE-2025-26399, an unauthenticated deserialization flaw in SolarWinds Web Help Desk's AjaxProxy component; and CVE-2026-1603, an authentication bypass in Ivanti Endpoint Manager (EPM). Each of these flaws presents significant risks, such as unauthorized access, remote code execution, and credential disclosure, potentially leading to full enterprise compromise. The inclusion of these vulnerabilities in the KEV Catalog underscores the persistent threat posed by unpatched software. Organizations are urged to prioritize remediation efforts to mitigate the risks associated with these actively exploited vulnerabilities.
6 months ago
Kill Chain
Critical Vulnerabilities in AI/ML Platforms: Lessons from the 2025 Security Breach
In mid-2025, a significant security vulnerability was discovered in three widely used open-source Python libraries—NeMo (by NVIDIA), Uni2TS (by Salesforce), and FlexTok (by Apple)—which are integral to various AI and ML platforms. These libraries, collectively downloaded over 10 million times via the HuggingFace platform, were found to execute arbitrary code embedded within model metadata, making them susceptible to remote code execution if exploited by attackers. The vulnerabilities were identified in April 2025 and resolved by July 2025, with corresponding CVEs assigned and severity scores ranging from 7.8 to 9.8 out of 10. As of December 2025, there have been no indications of these flaws being exploited in the wild. ([techradar.com](https://www.techradar.com/pro/security/python-libraries-used-in-top-ai-and-ml-tools-hacked-nvidia-salesforce-and-other-libraries-all-at-risk?utm_source=openai)) This incident underscores the critical importance of securing AI and ML infrastructure, especially as these technologies become increasingly integrated into business operations. The rapid adoption of AI tools without adequate security measures can expose organizations to significant risks, including data breaches and unauthorized access. It highlights the necessity for continuous monitoring, timely patching, and the implementation of robust security protocols to safeguard against emerging threats in the AI landscape.
6 months ago
Kill Chain
Critical SQL Injection Vulnerability in FortiClient EMS 7.4.4
In February 2026, a critical SQL injection vulnerability (CVE-2026-21643) was discovered in Fortinet's FortiClient Endpoint Management Server (EMS) version 7.4.4. This flaw allows unauthenticated attackers to execute arbitrary code or commands via specially crafted HTTP requests, potentially leading to full system compromise. Fortinet promptly released version 7.4.5 to address this issue, urging all users to upgrade immediately. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-21643?utm_source=openai)) This incident underscores the persistent threat posed by SQL injection vulnerabilities, especially in widely used enterprise security solutions. Organizations are reminded of the importance of timely patch management and vigilant monitoring to mitigate such risks.
6 months ago
Kill Chain
AdvJudge-Zero: Unveiling Critical Vulnerabilities in AI Judge Systems
In March 2026, Palo Alto Networks' Unit 42 researchers unveiled a critical vulnerability in AI 'judge' systems, which are large language models (LLMs) employed to enforce security policies and evaluate outputs. Utilizing a tool named AdvJudge-Zero, the researchers demonstrated that these AI judges could be manipulated through stealthy input sequences, a form of prompt injection, to bypass security controls. The attack exploits the models' decision-making processes, allowing unauthorized actions without detection. This vulnerability underscores the need for robust defenses against adversarial manipulations in AI systems. The discovery highlights the growing sophistication of prompt injection attacks, emphasizing the urgency for organizations to reassess and fortify their AI security measures. As AI integration deepens across industries, understanding and mitigating such vulnerabilities becomes paramount to maintaining trust and operational integrity.
6 months ago
Kill Chain
FBI Issues Warning on Phishing Attacks Impersonating Local Government Officials
In March 2026, the FBI issued a warning about a phishing campaign where criminals impersonated U.S. city and county officials to target individuals and businesses applying for land-use permits. The attackers used publicly available information to craft convincing emails, instructing victims to pay fraudulent fees via wire transfer, peer-to-peer payment, or cryptocurrency. This scheme exploited the victims' trust in official communications, leading to financial losses and potential exposure of sensitive information. This incident underscores a growing trend of cybercriminals leveraging publicly accessible data to enhance the credibility of their phishing attacks. The increasing sophistication of such schemes highlights the urgent need for heightened vigilance and robust verification processes in all interactions involving sensitive transactions.
6 months ago
Kill Chain
ShinyHunters' 2026 Exploitation of Salesforce Aura: A Wake-Up Call for Cloud Security
In March 2026, the cybercriminal group ShinyHunters initiated a series of data theft attacks targeting misconfigured Salesforce Experience Cloud instances. By exploiting excessive permissions granted to guest user profiles, the attackers accessed sensitive data without authentication. Utilizing a modified version of the AuraInspector tool, they identified and exploited these vulnerabilities, compromising approximately 300 to 400 organizations, many within the cybersecurity sector. The breaches led to unauthorized access to vast amounts of customer and corporate data, raising significant concerns about data security and privacy. This incident underscores the critical importance of proper configuration and access control in cloud platforms. Organizations are urged to audit guest user permissions, adhere to the principle of least privilege, and monitor for unusual access patterns to mitigate such risks. The event highlights the evolving tactics of threat actors and the necessity for continuous vigilance in cybersecurity practices.
6 months ago
Kill Chain
Google Cloud 2026: Surge in Vulnerability Exploitation
In the latter half of 2025, Google observed a significant shift in cloud attack vectors, with 44.5% of intrusions exploiting newly disclosed vulnerabilities in third-party software, while attacks leveraging weak credentials decreased to 27%. Notably, remote code execution flaws like React2Shell (CVE-2025-55182) and the XWiki vulnerability (CVE-2025-24893) were frequently targeted, with attackers deploying cryptominers within 48 hours of vulnerability disclosure. This trend underscores the urgency for organizations to promptly patch vulnerabilities and enhance their security posture to mitigate rapid exploitation risks. The accelerated exploitation of software vulnerabilities highlights the evolving tactics of threat actors and the necessity for organizations to adopt proactive vulnerability management and robust security measures to safeguard cloud environments against emerging threats.
6 months ago
Kill Chain
Russian Hackers Exploit Phishing to Hijack Signal and WhatsApp Accounts in 2026
In March 2026, Dutch intelligence agencies reported a large-scale cyber campaign by Russian state-sponsored hackers targeting Signal and WhatsApp accounts of government officials, military personnel, and journalists. The attackers employed phishing and social engineering tactics, impersonating support chatbots to deceive users into revealing security verification codes and PINs. This enabled unauthorized access to sensitive communications and group chats. ([english.aivd.nl](https://english.aivd.nl/latest/news/2026/03/09/russia-targets-signal-and-whatsapp-accounts-in-cyber-campaign?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors exploiting human vulnerabilities rather than technical flaws. It highlights the critical need for heightened vigilance and robust security protocols to protect sensitive information in secure messaging platforms.
6 months ago
Kill Chain
Ericsson US Data Breach: Lessons in Third-Party Risk Management
In April 2025, Ericsson Inc., the U.S. subsidiary of the Swedish telecommunications company, experienced a data breach through one of its service providers. Unauthorized access occurred between April 17 and April 22, 2025, compromising sensitive personal information of employees and customers, including names, addresses, Social Security numbers, driver's license numbers, financial data, medical information, and dates of birth. The breach was detected on April 28, 2025, prompting an investigation that concluded on February 23, 2026, confirming the extent of the data exposure. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ericsson-us-discloses-data-breach-after-service-provider-hack/?utm_source=openai)) This incident underscores the critical importance of robust third-party risk management and supply chain security. As organizations increasingly rely on external service providers, ensuring these partners adhere to stringent cybersecurity standards is essential to prevent similar breaches and protect sensitive data.
6 months ago
Kill Chain
Chrome Extensions Compromised Post-Ownership Transfer: A 2026 Case Study
In February 2026, two Google Chrome extensions, QuickLens and ShotBird, were compromised following ownership transfers. The new owners introduced malicious updates that stripped security headers from HTTP responses, enabling code injection and data theft. These updates allowed attackers to execute arbitrary JavaScript, leading to the exfiltration of sensitive user data, including credentials and browsing history. The incident underscores the risks associated with browser extension supply chains and the potential for legitimate tools to become vectors for malware distribution. This event highlights the growing trend of attackers exploiting trusted browser extensions to infiltrate systems, emphasizing the need for vigilant monitoring of software supply chains and the implementation of robust security measures to detect and prevent such compromises.
6 months ago
Kill Chain
Malicious npm Package Poses as OpenClaw Installer, Deploys RAT on macOS
In early March 2026, a malicious npm package named '@openclaw-ai/openclawai' was discovered posing as an installer for OpenClaw. Uploaded on March 3, 2026, by a user named 'openclaw-ai', the package was downloaded 178 times before detection. Upon installation, it executed a postinstall script that deployed a remote access trojan (RAT) capable of stealing sensitive data, including system credentials, browser data, cryptocurrency wallets, SSH keys, Apple Keychain databases, and iMessage history. The malware also established persistence, allowing continuous remote access and data exfiltration. This incident underscores the growing trend of supply chain attacks targeting open-source ecosystems, exploiting the trust developers place in widely-used package managers like npm. The sophistication of the attack, including social engineering tactics and advanced persistence mechanisms, highlights the urgent need for enhanced security measures in software development pipelines.
6 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

