Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3685 to 3696 of 5958
CEO Deepfake Scam 2019: A Wake-Up Call for Corporate Security
In March 2019, a UK-based energy firm's CEO was deceived by a deepfake audio impersonation of his German parent company's chief executive. The fraudster, using AI-generated voice technology, instructed the CEO to transfer €220,000 (approximately $243,000) to a Hungarian supplier's account. Believing the request was legitimate, the CEO complied. Subsequent attempts for additional transfers raised suspicions, leading to the discovery of the scam. The initial funds were moved from Hungary to Mexico and then dispersed to other locations, making recovery challenging. ([forbes.com](https://www.forbes.com/sites/jessedamiani/2019/09/03/a-voice-deepfake-was-used-to-scam-a-ceo-out-of-243000/?utm_source=openai)) This incident underscores the escalating threat of AI-driven deepfake technologies in corporate fraud. As these tools become more sophisticated and accessible, organizations face increased risks of impersonation attacks targeting financial transactions and sensitive information. The event highlights the urgent need for enhanced security measures and employee training to detect and prevent such advanced social engineering tactics.
6 months ago
Kill Chain
CrowdStrike 2025 Global Threat Report: Attackers Moving Through Networks in Under 30 Minutes
In 2025, cyberattacks accelerated significantly, with the average breakout time—the duration for attackers to move from initial intrusion to other network systems—dropping to 29 minutes, a 65% increase in speed from the previous year. Notably, the fastest recorded breakout time was 27 seconds. This rapid progression was facilitated by attackers refining their techniques, leveraging social engineering to access high-privilege systems swiftly, and exploiting gaps across cloud, identity, enterprise, and unmanaged network devices. Consequently, defenders faced increased challenges, including burnout and stress, leading to potential mistakes. Additionally, CrowdStrike identified 281 threat groups by the end of 2025, including 24 new threats named throughout the year, highlighting the expanding and evolving threat landscape. The urgency of this issue is underscored by the 37% year-over-year increase in cloud-focused attacks, with a staggering 266% surge in such activities from nation-state threat groups. Furthermore, 82% of attacks detected in 2025 were malware-free, indicating a shift towards hands-on-keyboard operations and the abuse of legitimate tools and credentials. This trend emphasizes the need for organizations to enhance their security measures, focusing on rapid detection and response capabilities to mitigate the risks posed by increasingly sophisticated and swift cyber adversaries.
6 months ago
Kill Chain
Anthropic's Claude Model Targeted in Large-Scale AI Distillation Attack by Chinese Labs
In February 2026, Anthropic, a U.S.-based AI startup, reported that three Chinese AI laboratories—DeepSeek, Moonshot, and MiniMax—conducted large-scale 'distillation' attacks to extract capabilities from Anthropic's Claude model. These labs utilized 24,000 fraudulent accounts to send approximately 16 million requests to Claude, aiming to enhance their own AI models. This unauthorized extraction of intellectual property not only violated Anthropic's terms of service but also posed significant national security risks by potentially enabling offensive cyber operations and mass surveillance. ([cyberscoop.com](https://cyberscoop.com/anthropic-accuses-chinese-labs-ai-distillation-cyber-risk/?utm_source=openai)) This incident underscores the growing threat of AI model distillation as a method for intellectual property theft. The scale and sophistication of these attacks highlight the urgent need for robust security measures and regulatory frameworks to protect proprietary AI technologies from unauthorized exploitation.
6 months ago
Kill Chain
Roundcube Webmail Vulnerabilities: Immediate Action Required
In June and December 2025, two critical vulnerabilities were identified in Roundcube Webmail: CVE-2025-49113, a remote code execution flaw, and CVE-2025-68461, a cross-site scripting vulnerability. These flaws allowed attackers to execute arbitrary code and inject malicious scripts, respectively, compromising the security of affected systems. Despite patches being released promptly, threat actors rapidly developed exploits, leading to active exploitation of these vulnerabilities. The exploitation of these vulnerabilities underscores the persistent threat posed by unpatched software in widely used applications. Organizations must prioritize timely updates and robust security measures to mitigate such risks. ([securityweek.com](https://www.securityweek.com/recent-roundcube-webmail-vulnerability-exploited-in-attacks/?utm_source=openai))
6 months ago
Kill Chain
Optimizely's 2026 Data Breach: A Case Study in Vishing Attacks
In February 2026, Optimizely, a New York-based ad tech company, experienced a data breach initiated through a sophisticated voice phishing (vishing) attack. The attackers, identified as the ShinyHunters group, impersonated internal IT staff to deceive employees into divulging single sign-on (SSO) credentials and multi-factor authentication (MFA) codes. This social engineering tactic granted unauthorized access to Optimizely's systems, leading to the exfiltration of basic business contact information. The breach was confined to certain internal business systems, records in the customer relationship management (CRM) platform, and a limited set of internal documents used for back-office operations. There is no evidence that sensitive customer data or personal information beyond basic business contact information was accessed. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/?utm_source=openai)) This incident underscores a significant escalation in the operations of the ShinyHunters group, which has been actively targeting organizations through vishing attacks to compromise SSO credentials. The group's tactics have evolved to include harassment of victim personnel and other aggressive measures. ([itpro.com](https://www.itpro.com/security/google-issues-warning-over-shinyhunters-branded-vishing-campaigns?utm_source=openai))
6 months ago
Kill Chain
Security Flaws in Android Mental Health Apps Put Millions at Risk
In February 2026, security researchers identified significant vulnerabilities in several Android mental health applications, collectively downloaded over 14.7 million times from Google Play. These apps, designed to assist users with conditions such as depression and anxiety, were found to contain a total of 1,575 security flaws, including 54 high-severity and 538 medium-severity issues. Exploiting these vulnerabilities could allow attackers to intercept sensitive user data, including therapy session transcripts and personal health information, thereby compromising user privacy and confidentiality. This incident underscores the critical need for rigorous security measures in applications handling sensitive health data. The discovery highlights the potential risks associated with inadequate app security, emphasizing the importance of regular security assessments and compliance with data protection regulations to safeguard user information.
6 months ago
Kill Chain
Spain Arrests Anonymous Fénix Hacktivists for DDoS Attacks
In February 2026, Spanish authorities arrested four members of the hacktivist group 'Anonymous Fénix' for orchestrating distributed denial-of-service (DDoS) attacks against government ministries, political parties, and public institutions. The group initiated its activities in April 2023, intensifying efforts after the October 2024 DANA storm in Valencia, which resulted in significant casualties and damage. They utilized social media platforms like X and Telegram to disseminate anti-government messages and recruit participants for their cyber campaigns. The arrests, conducted in May 2025 and February 2026 across various Spanish cities, led to the judicial seizure of the group's online accounts and the closure of their communication channels. ([web.guardiacivil.es](https://web.guardiacivil.es/en/destacados/noticias/Detenidos-los-cuatro-principales-integrantes-del-grupo-hacktivista-Anonymous-Fenix-por-ciberataques-contra-organismos-publicos/?utm_source=openai)) This incident underscores the persistent threat posed by hacktivist groups leveraging socio-political events to justify cyberattacks. The use of DDoS tactics to disrupt critical government services highlights the need for robust cybersecurity measures and proactive monitoring of online platforms for recruitment and coordination activities.
6 months ago
Kill Chain
MuddyWater's Operation Olalampo: A New Era of Cyber Threats in MENA
In early 2026, the Iranian state-sponsored APT group MuddyWater launched 'Operation Olalampo,' targeting organizations across the Middle East and North Africa (MENA) region. The campaign utilized sophisticated spear-phishing emails with malicious Microsoft Office documents to deploy new malware families, including GhostFetch, HTTP_VIP, CHAR, and GhostBackDoor. These tools enabled the attackers to perform system reconnaissance, execute remote commands, and exfiltrate sensitive data, compromising entities in sectors such as telecommunications, government, and energy. This incident underscores a significant evolution in MuddyWater's tactics, notably their adoption of Rust-based malware and AI-assisted development processes. The group's enhanced capabilities and persistent targeting of critical infrastructure highlight the escalating cyber threat landscape in the MENA region, emphasizing the need for robust cybersecurity measures and vigilance against advanced persistent threats.
6 months ago
Kill Chain
PromptSpy AI Malware: Unveiling the Future of Android Cyber Threats
In February 2026, cybersecurity researchers identified 'PromptSpy,' the first known Android malware leveraging generative AI at runtime. This sophisticated malware utilizes Google's Gemini model to adapt its persistence mechanisms across various devices, enhancing its ability to evade detection. PromptSpy's discovery marks a significant evolution in mobile threats, demonstrating the integration of AI to dynamically modify malicious behavior during execution. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/promptspy-is-the-first-android-malware-to-use-generative-ai-at-runtime/?utm_source=openai)) The emergence of AI-driven malware like PromptSpy underscores a critical shift in cyber threats, where adversaries harness advanced technologies to create more resilient and adaptive attack vectors. This development necessitates a reevaluation of current security measures to effectively counteract AI-enhanced malicious activities.
6 months ago
Kill Chain
SANDWORM_MODE: A New Era of Supply Chain Attacks Targeting Developers
In February 2026, a sophisticated supply chain attack, dubbed SANDWORM_MODE, targeted the npm ecosystem by distributing at least 19 malicious packages. These packages were designed to harvest sensitive information, including system data, access tokens, environment secrets, and API keys from developer environments. The malware propagated by exploiting compromised npm and GitHub accounts, enabling widespread credential theft and unauthorized access to development infrastructures. Notably, the attack introduced a module that infiltrated AI coding assistants, extracting API keys from nine large language model providers and injecting malicious servers into tool configurations. This incident underscores the escalating complexity and reach of supply chain attacks, particularly those leveraging trusted open-source repositories. The integration of AI toolchain manipulation highlights a concerning evolution in attacker tactics, emphasizing the need for enhanced vigilance and security measures within development environments.
6 months ago
Kill Chain
Unveiling the Wormable XMRig Campaign: A Deep Dive into BYOVD Exploits and Time-Based Logic Bombs
In February 2026, cybersecurity researchers uncovered a sophisticated cryptojacking campaign that utilized pirated software bundles to deploy a customized XMRig miner on compromised systems. The malware exhibited worm-like capabilities, spreading via external storage devices, and employed a 'Bring Your Own Vulnerable Driver' (BYOVD) technique to escalate privileges. Additionally, it incorporated a time-based logic bomb set to deactivate the malware after December 23, 2025, indicating a planned operational timeframe. This campaign underscores the evolving tactics of cybercriminals, combining social engineering, legitimate software exploitation, and advanced persistence mechanisms to maximize cryptocurrency mining output. The use of BYOVD exploits and logic bombs highlights the need for robust security measures to detect and mitigate such multifaceted threats.
6 months ago
Kill Chain
APT28's Operation MacroMaze: A New Wave of Cyber Espionage
Between September 2025 and January 2026, the Russian state-sponsored threat actor APT28 conducted Operation MacroMaze, targeting entities in Western and Central Europe. The campaign utilized spear-phishing emails containing malicious Word documents with embedded macros. These macros exploited legitimate services like webhook[.]site for command-and-control and data exfiltration, employing techniques such as headless browser execution and keyboard simulation to evade detection. ([thehackernews.com](https://thehackernews.com/2026/02/apt28-targeted-european-entities-using.html?utm_source=openai)) This incident underscores the evolving tactics of APT28, highlighting their ability to adapt and leverage basic tools in sophisticated ways. The use of legitimate services for malicious purposes poses significant challenges for detection and mitigation, emphasizing the need for robust cybersecurity measures and continuous monitoring.
6 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

