Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3973 to 3984 of 5957
FBI Takedown of RAMP: Ransomware's Last Open Forum Seized in 2026
In January 2026, the FBI seized control of the notorious Russian-speaking RAMP cybercrime forum, widely used by ransomware gangs to promote operations, recruit affiliates, and trade access to compromised networks. Both its Tor and clearnet domains were confiscated, and a seizure notice was displayed in coordination with U.S. law enforcement agencies. As one of the last prominent ransomware-friendly forums, RAMP had become a hub for multiple groups, facilitated by threat actor Mikhail Matveev (aka Orange/Wazawaka). The FBI now possesses potentially incriminating data on user identities, logins, and private communications, increasing the risk of arrests for those with poor operational security. This takedown reflects a broader law enforcement crackdown on cybercrime infrastructure supporting ransomware attacks. The RAMP seizure is significant amid heightened regulatory and industry focus on disrupting the ransomware ecosystem and demonstrates the ongoing risk of exposure for those operating in or near dark web forums.
7 months ago
Kill Chain
Electrum-Linked Wiper Attack Disables Key Systems in Polish Energy Grid
In late December 2025, a coordinated cyberattack targeted Poland’s distributed energy resource (DER) sites, including combined heat and power, wind, and solar dispatch facilities. The attackers, identified as the Russian-linked Electrum (overlapping with APT44/Sandworm), exploited misconfigurations and exposed operational technology, corrupting or destroying key OT and Windows systems at nearly 30 sites. While no electrical outages were reported and power generation largely continued, remote monitoring and control capabilities were disabled and some equipment rendered inoperable, exposing critical vulnerabilities in Poland’s decentralized energy grid. This incident highlights a significant evolution in threat actor tactics toward industrial systems, specifically targeting the backbone of modern hybrid energy infrastructure. Increased focus on OT security, zero-trust segmentation, and resilient operational controls is crucial as sophisticated groups continue probing for weaknesses in vital infrastructure globally.
7 months ago
Kill Chain
MicroWorld eScan Update Server Breach Exposes Supply Chain Risks
In June 2024, MicroWorld Technologies, developers of eScan antivirus, experienced a breach where attackers compromised one of its update servers. The intruders leveraged this access to push a malicious software update to a limited subset of customers, effectively deploying unauthorized code via the trusted antivirus delivery mechanism. MicroWorld quickly detected the incident, notified impacted users, and began forensic analysis with assistance from cybersecurity experts. The compromised update posed potential risks including malware infection and lateral network movement. This incident is part of a growing trend of supply chain attacks, where adversaries exploit trusted update channels to infiltrate enterprise environments. As organizations increasingly rely on third-party software, vigilance and layered security controls around update infrastructures have become a pressing necessity.
7 months ago
Kill Chain
Fake PyPI Spellchecker Packages Delivered RAT in Supply Chain Attack (2026)
In early 2026, security researchers uncovered a supply chain attack involving two malicious packages—spellcheckerpy and spellcheckpy—distributed on the popular Python Package Index (PyPI). Masquerading as legitimate spellchecking tools, these packages were downloaded over 1,000 times before removal, each covertly containing a remote access trojan (RAT). When unsuspecting developers installed the packages, attackers could gain persistent access to compromised systems, enabling data exfiltration, lateral movement, and remote command execution. No specific organizational victims were named, but the risk extended globally to Python developers and projects that leveraged these components. This incident is emblematic of the growing trend of supply chain attacks targeting open source repositories, exploiting trust in widely used ecosystems like PyPI. As software supply chains become common attack vectors, organizations face heightened pressure to vet dependencies and implement controls to prevent compromise via upstream components.
7 months ago
Kill Chain
Exposed Interfaces & Supply Chain Risks: The 2026 Moltbot AI Assistant Breach
In January 2026, researchers uncovered widespread security vulnerabilities in Moltbot (formerly Clawdbot), an open-source AI assistant that achieved viral adoption among both consumers and employees in the enterprise sector. Due to prevalent misconfigurations—specifically, exposed admin interfaces and reverse proxy errors—hundreds of Moltbot instances were accessible online, allowing unauthenticated attackers to steal API keys, OAuth tokens, credentials, message histories, and even execute commands remotely with system-level permissions. Additional risks arose as malicious skills (modules) could be planted in the official registry, rapidly propagating supply-chain threats to unsuspecting enterprise and developer systems, further compounded by the assistant lacking sandboxing or privilege separation by default. This incident highlights a growing trend where AI/GenAI tools, easily adopted outside corporate IT control, create new vectors for credential theft, data leakage, and lateral movement. As attackers focus on AI-driven endpoints and shadow IT, failure to enforce zero trust, segmentation, and robust monitoring introduces significant business risk and regulatory exposure.
7 months ago
Kill Chain
Fortinet Authentication Bypass: CVE-2026-24858 (2026 Breach & Response)
In January 2026, Fortinet released emergency security patches to address a critical authentication bypass vulnerability (CVE-2026-24858, CVSS 9.4) actively exploited in the wild. Attackers leveraged the flaw in FortiOS's Single Sign-On (SSO) feature, bypassing authentication to gain unauthorized access to sensitive systems including FortiManager and FortiAnalyzer. The incident highlights the risks of unpatched perimeter defenses, with exploitation enabling potential lateral movement, privilege escalation, and access to business-critical data or control systems—potentially at scale for unremediated customers. This event is significant given the continued targeting of network infrastructure through novel bypass techniques. Escalating regulatory scrutiny and threat actor sophistication underscore the need for timely patching, robust segmentation, and ongoing monitoring of privileged identity solutions.
7 months ago
Kill Chain
Google Flags Ongoing Exploitation of WinRAR CVE-2025-8088 by Elite Threat Actors
In July 2025, a critical vulnerability (CVE-2025-8088) in RARLAB WinRAR was identified and subsequently patched, but not before multiple threat actors, including government-backed groups from Russia and China as well as financially motivated cybercriminals, actively exploited it. Attackers leveraged the flaw as an initial access vector, distributing diverse malicious payloads to compromise targeted systems. The exploitation campaign enabled unauthorized access to sensitive environments and facilitated follow-on activities such as lateral movement and data exfiltration, raising serious concerns for organizations and individuals relying on WinRAR for file management. This incident is significant as it highlights the speed and sophistication with which both nation-state and financially driven attackers weaponize zero-day vulnerabilities. The continued exploitation of unpatched systems following disclosure underscores the persistent risks organizations face from lagging patch cycles and evolving adversary tactics.
7 months ago
Kill Chain
Mustang Panda’s 2025 Cyber Espionage: Updated COOLCLIENT Backdoor Hits Government
In late 2025, cyber espionage group Mustang Panda (also known as Earth Preta and Twill Typhoon) launched a series of targeted attacks against government entities, deploying an updated version of the COOLCLIENT backdoor. These intrusions leveraged spear-phishing and custom malware to establish persistent access, exfiltrate sensitive government data, and conduct surveillance. The campaign relied on advanced command-and-control infrastructure and encrypted traffic to evade detection, demonstrating the group’s evolving tactics and technical sophistication. The breach resulted in notable data theft and highlighted vulnerabilities in governmental East-West network security and policy enforcement. This incident underscores a rising trend of state-sponsored attackers continuously updating malware toolsets and intensifying operations against government organizations. The sophistication and stealth of these campaigns demand enhanced data protection, visibility, and zero trust network controls to meet regulatory and operational requirements.
7 months ago
Kill Chain
Critical vm2 Node.js Flaw Enables Sandbox Escape and Supply-Chain Exploit
In January 2026, a critical vulnerability (CVE-2026-22709, CVSS 9.8) was disclosed in the popular Node.js library vm2, enabling attackers to escape its JavaScript sandbox and execute arbitrary code on affected systems. The flaw, present in version 3.10.0, allowed exploitation via manipulation of Promise.prototype.then and Promise.prototype.catch, providing a direct path to remote code execution. Organizations relying on vm2 for untrusted code execution and sandboxing were at significant risk, with the vulnerability exposing underlying infrastructure to privilege escalation, data exfiltration, or supply-chain compromise. This incident highlights increased supply-chain risk in NPM ecosystems, where critical open-source dependencies like vm2 are often trusted by default. There is growing urgency as attackers increasingly target widely-used libraries to compromise downstream applications at scale, underscoring the need for stronger package vetting, runtime segmentation, and elastic incident response.
7 months ago
Kill Chain
Critical n8n Vulnerabilities Allow Authenticated Remote Code Execution (2026)
In January 2026, cybersecurity researchers uncovered two critical vulnerabilities in the n8n workflow automation platform, including a CVE-2026-1470 flaw (CVSS 9.9) which enables authenticated users to achieve remote code execution via eval injection. Discovered by the JFrog Security Research team, attackers exploiting these weaknesses could bypass the Expression system and execute arbitrary commands on affected servers. Successful exploitation could allow lateral movement and data exfiltration by leveraging internal automation integrations, putting sensitive business processes and connected services at significant risk. This incident underscores a rising trend of attackers targeting automation and orchestration platforms as high-value footholds in enterprise environments. With the increased adoption of low-code automation, vulnerabilities in such platforms can propagate risk across multiple systems, driving urgent need for software vendors and organizations to prioritize security reviews, patch management, and robust segmentation controls.
7 months ago
Kill Chain
Fake AI Coding Assistant Delivers Malware via VS Code Marketplace in 2026 Supply-Chain Attack
In January 2026, cybersecurity researchers discovered a malicious Visual Studio Code extension masquerading as "ClawdBot Agent - AI Coding Assistant" in the official VS Code Marketplace. The extension claimed to offer AI-assisted coding functionality but instead delivered a concealed malware payload to users who installed it. The attack leveraged the supply chain vector—abusing trust in a popular development marketplace—and could compromise the local development environment, providing the threat actor with unauthorized access and control over the affected system. This incident highlights the expanding risk of supply-chain attacks in developer ecosystems and raises concerns about the integrity of widely used software distribution platforms. This case underscores a rising trend of threat actors exploiting trusted software repositories to launch targeted malware campaigns. As AI coding assistants and marketplace extensions surge in popularity, organizations face mounting pressure to implement rigorous vetting and monitoring to protect software supply chains from increasingly sophisticated threats.
7 months ago
Kill Chain
Russian ELECTRUM APT Strikes Polish Power Grid with Coordinated December 2025 Attack
In December 2025, a coordinated cyber attack disrupted multiple sites within Poland's national power grid, marking the first significant compromise of distributed energy operational technology in the region. The campaign, attributed with medium confidence to Russian state-sponsored APT group ELECTRUM, leveraged supply chain vulnerabilities and advanced lateral movement techniques to infiltrate the grid's OT networks. Attackers exploited unencrypted east-west traffic and segmentation gaps, enabling persistent access and operational disruption that triggered brief power outages and forced manual intervention by Polish operators. The incident showcased a notable escalation in critical infrastructure targeting methods by highly skilled actors. This incident highlights the increasing risk of state-sponsored attacks on energy infrastructure, especially in the context of rising geopolitical tensions and adversarial use of sophisticated supply chain compromise and network segmentation evasion. Organizations should reassess their visibility and controls for east-west and encrypted traffic to mitigate similar risks.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

