Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3997 to 4008 of 5957
CISA Flags Five Actively Exploited Vulnerabilities in 2026 KEV Catalog Update
In January 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added five high-risk vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation. These include flaws in the Linux Kernel, SmarterTools SmarterMail, Microsoft Office, and GNU InetUtils. Threat actors exploited these vulnerabilities through methods such as authentication bypass, unrestricted file upload, security feature bypass, and argument injection, targeting both federal and private sector networks. Rapid exploitation can lead to unauthorized access, data exfiltration, or further compromise of organizational systems if not promptly remediated. This evolving threat landscape highlights an ongoing wave of opportunistic and targeted attacks leveraging widely used enterprise, email, and infrastructure software. The addition of these CVEs to the KEV Catalog underscores regulatory pressure and the increased urgency for organizations of all sizes to prioritize patch management and mitigate exposure to active threats.
7 months ago
Kill Chain
How 2024 Romance Scams Use WhatsApp Social Engineering: An Inside Look
In early 2024, security researchers investigated the initial phases of romance scams conducted over WhatsApp, where attackers use social engineering tactics to engage targets. Scammers made initial contact using 'wrong number' messages, then rapidly built rapport through flattering responses and fabricated personal stories. Over the span of several weeks, operators established credibility by sharing career details, transitioning conversations to new phone numbers, and sharing lifestyle photos to lay groundwork for future financial scams. The observed campaigns were early-stage but designed to emotionally manipulate victims for eventual financial exploitation. This incident spotlights the refined playbooks, multi-operator approaches, and psychological grooming now typical in romance scams. With surges in digital-first communication and persistent threat actor innovation, such social engineering exploits pose a significant and evolving risk to individuals and businesses alike.
7 months ago
Kill Chain
VMware vCenter RCE Flaw Actively Exploited: What Security Teams Need to Know
In January 2026, a critical vulnerability (CVE-2024-37079) in VMware vCenter Server was confirmed as actively exploited in the wild. This heap overflow flaw within the DCERPC protocol implementation enables unauthenticated remote attackers with network access to execute arbitrary code on vulnerable vCenter Server systems. The compromise does not require user interaction or elevated privileges, making attacks relatively low-effort and high-impact. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a directive mandating all federal agencies to remediate the issue within three weeks, underscoring its urgency and operational risk. No temporary mitigations exist, leaving patching as the sole defense for affected environments. This incident highlights a continued trend of attackers targeting management and orchestration layers in hybrid-cloud and virtualized infrastructures. The lack of workarounds, combined with rapid weaponization, points to increasing risks for organizations who delay patching and underlines regulatory pressure on timely remediation for critical zero-day vulnerabilities.
7 months ago
Kill Chain
NPM Supply Chain Bypass: PackageGate and Shai-Hulud Exploits Expose Open-Source Risks in 2026
In January 2026, critical vulnerabilities dubbed "PackageGate" were revealed in NPM and several popular JavaScript package managers, exposing gaps in defenses against supply chain attacks like last year's Shai-Hulud incidents. Despite previous security improvements, attackers could still bypass NPM's safeguard against malicious package scripts by leveraging Git dependencies and malicious .npmrc configuration files, leading to unauthorized code execution—even when script blocking features were enabled. The flaws, discovered by Koi Security researchers, allowed full code compromise and had potential for massive developer credential and secret exfiltration, threatening tens of thousands of projects and their downstream users. These findings highlight the persistent risks in open-source supply chains and the accelerating pace of software supply chain attacks. As threat actors become more adept at exploiting package management tools, organizations face renewed urgency to bolster visibility, enforce granular access controls, and adopt defense-in-depth measures to protect development workflows and critical assets.
7 months ago
Kill Chain
Microsoft Patches Active Office Zero-Day: What Your Security Team Must Know
In June 2024, Microsoft urgently released security patches addressing a high-severity zero-day vulnerability in Microsoft Office. Threat actors exploited this flaw in-the-wild prior to disclosure, using malicious documents to achieve remote code execution and gain access to targeted systems without user awareness. The vulnerability impacted multiple Office versions, with proof-of-concept exploits circulating even before patch release. Microsoft’s security teams identified active exploitation, prompting swift response to curb potential corporate data exposure, loss of confidentiality, and operational disruption for both private and public sector users worldwide. This incident spotlights the persistent risk of zero-day exploits in mainstream productivity software. It underscores both attackers’ increasing sophistication in rapidly weaponizing new vulnerabilities and the escalating need for organizations to prioritize timely patch application and robust monitoring to mitigate the business impact of emerging threats.
7 months ago
Kill Chain
Konni APT Leverages AI-Generated PowerShell to Breach Blockchain Developers
In January 2026, the North Korean-linked APT group Konni conducted a sophisticated phishing campaign targeting blockchain developers and engineering teams in Japan, Australia, and India. Using AI-generated PowerShell malware, attackers successfully penetrated targeted organizations by delivering malicious payloads through convincing spear-phishing emails. Once inside, the adversaries leveraged lateral movement and exfiltration techniques to access sensitive intellectual property and digital assets, expanding their historical targeting beyond South Korea and parts of Europe. The breach underscores the evolution of attacker tradecraft—adopting AI to evade traditional defenses and efficiently craft malicious code. This incident is highly relevant as it marks a notable surge in both AI-driven malware and the targeting of the blockchain sector. With threat actors broadening their geographic reach and operational sophistication, organizations must urgently re-evaluate their security controls, specifically around code execution, endpoint monitoring, and identity access management, to defend against emerging threats.
7 months ago
Kill Chain
Blackmoon Malware Hits Indian Taxpayers Through Sophisticated Phishing in 2026
In January 2026, Indian users became the focus of a sophisticated cyber espionage campaign involving tax-themed phishing emails masquerading as legitimate communications from the Income Tax Department of India. These emails distributed malicious archive files, which, once opened, executed the infostealer Blackmoon malware. This multi-stage attack enabled threat actors to quietly exfiltrate personal and financial information from compromised systems, potentially exposing sensitive tax details and compromising the victims' digital environments. The attackers applied advanced phishing techniques and evasion tactics to bypass traditional security defenses and maintain persistent access. This incident highlights a broader trend in targeted social engineering attacks leveraging local themes and timely events to increase victim engagement. The resurgence of infostealer malware like Blackmoon underscores the importance of endpoint protection, awareness training, and zero trust controls, particularly in high-risk seasons such as tax filing periods.
7 months ago
Kill Chain
Malicious AI-Powered VS Code Extensions Trigger Global Supply Chain Breach (2026)
In January 2026, cybersecurity researchers uncovered that two widely-distributed AI-powered Microsoft Visual Studio Code extensions, with over 1.5 million combined installs, were covertly exfiltrating developer source code and sensitive project data to servers based in China. The malicious extensions masqueraded as legitimate AI coding tools, enticing developers globally through the official VS Code marketplace. Once installed, these extensions surreptitiously uploaded confidential code and intellectual property, potentially endangering enterprise software assets and customer data. Investigators highlighted the supply chain risk, noting the threat’s scalability via trusted software distribution channels and the delays in detecting such activity. This incident underscores the escalating risks associated with third-party development tools, particularly those leveraging AI branding. The popularity and trust in official marketplaces can allow sophisticated advanced persistent threats (APTs) or criminal groups to exploit developers and organizations, necessitating enhanced scrutiny and continuous security monitoring of supply chain dependencies.
7 months ago
Kill Chain
DPRK's Konni: AI-Generated Backdoor Hits Blockchain Developers in 2024
In early 2024, the North Korean threat group Konni launched a sophisticated supply-chain attack targeting blockchain developers by deploying an AI-generated PowerShell backdoor within compromised development environments. The operation exploited development tools to surreptitiously gain access to cryptocurrency assets, leveraging advanced evasion techniques and encrypted communications to avoid detection. Victims faced risks of cryptocurrency theft, business disruption, and potential regulatory exposure, with the attackers demonstrating a deep understanding of both blockchain technologies and modern security controls. This incident highlights the growing convergence of AI-generated malware and targeted supply-chain attacks, especially against financially lucrative industries like cryptocurrency. As threat actors increasingly leverage custom malware and automated tools, organizations with high-value digital assets face mounting pressure to improve internal visibility, zero-trust enforcement, and incident response capabilities.
7 months ago
Kill Chain
Exposed Environment Files: The $(pwd) Webserver Reconnaissance Surge of Jan 2026
In January 2026, multiple sensors and the SANS Internet Storm Center reported a wave of targeted web application scans probing for exposed environment and configuration files on webservers using the /$(pwd)/ path pattern. Attackers, active since at least January 13th, systematically searched for sensitive files such as .env, docker-compose.yml, and terraform.tfstate, potentially exposing credentials and secrets. Two identified IP addresses (185.177.72.52, 185.177.72.23) led these scans, illustrating an automated approach likely leveraging misconfigured servers. While no confirmed breaches have been disclosed, such activity significantly raises the risk of follow-on exploitation or credential theft if vulnerable files are found. This incident highlights growing attacker sophistication in discovering misconfigurations and automating reconnaissance. The use of predictable directory traversal patterns and attempts to surface hidden files underscore the need for robust web application hardening and monitoring, especially as threat actors increasingly leverage similar tactics to bypass traditional defenses.
7 months ago
Kill Chain
ShinyHunters 2026: SSO Vishing Attacks Trigger Major SaaS Data Breaches
In January 2026, the cybercriminal group ShinyHunters orchestrated a series of sophisticated voice-phishing (vishing) attacks targeting corporate Single Sign-On (SSO) platforms, including Okta, Microsoft Entra, and Google. The attackers posed as IT support staff, manipulated employees into entering their credentials and multi-factor authentication tokens on fake login pages, and subsequently gained unauthorized access to SSO accounts. Leveraging these credentials, ShinyHunters accessed numerous connected SaaS applications such as Salesforce, Microsoft 365, and Slack, harvesting sensitive corporate data that was later used for extortion demands. High-profile organizations like SoundCloud, Betterment, and Crunchbase reported breaches and data losses as a result. This incident underscores a significant evolution in social engineering tactics, with attackers combining real-time phishing kits and vishing to bypass MFA and access a wide swath of corporate resources. As threat actors increasingly exploit identity-driven weaknesses and leverage SSO misconfigurations, organizations face greater risks of multi-system compromise and regulatory fallout.
7 months ago
Kill Chain
Sandworm’s Failed DynoWiper Attack on Poland’s Energy Grid: A 2025 Nation-State Case Study
In late December 2025, Polish energy infrastructure was targeted in a sophisticated cyberattack attributed to Sandworm, a notorious Russian state-sponsored hacking group. The attackers attempted to deploy 'DynoWiper', a destructive data-wiping malware, against two combined heat and power facilities and key management systems for renewable energy assets. Although the wiper aimed to erase files and render systems inoperable, Polish officials confirmed the attack was detected and mitigated before operational disruption occurred. Attribution to Sandworm, linked to Russia’s GRU, underscores continued targeting of critical infrastructure by advanced persistent threats. This incident is highly relevant given the continued escalation of cyber operations against national infrastructure, particularly in Europe. It highlights the evolving use of destructive malware by state-backed actors and signals the necessity for robust cross-sector cyber defenses and detection mechanisms.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

