Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4105 to 4116 of 5957
Malicious Chrome Extensions Target Workday and NetSuite Users in Coordinated Attack
In January 2026, cybersecurity researchers uncovered a campaign involving five malicious Google Chrome extensions that impersonated enterprise platforms such as Workday, NetSuite, and SuccessFactors. These extensions worked in unison to steal authentication tokens, disrupt incident response procedures, and seize control of victim user accounts. Attackers leveraged the trust users place in HR and ERP browser tools, exploiting their position to achieve data exfiltration and persistent account takeover across corporate environments. The attack’s main impact included unauthorized access to sensitive business systems and increased potential for widespread lateral movement within organizations. This incident underscores the growing sophistication of browser-based threats as attackers increasingly mimic legitimate business tools to infiltrate organizations. With a rise in social engineering and token theft techniques targeting identity and SaaS workflows, enterprises face heightened risk to cloud and hybrid environments, necessitating additional focus on endpoint, browser, and application-layer defenses.
8 months ago
Kill Chain
China-Linked APT Leverages Sitecore Zero-Day to Target Critical Infrastructure (2025)
In late 2025, a China-nexus advanced persistent threat group tracked as UAT-8837 exploited a critical Sitecore zero-day vulnerability (CVE-2025-53690, CVSS 9.0) to compromise multiple critical infrastructure organizations in North America. Following initial access through vulnerable servers or compromised credentials, the threat actor leveraged open-source post-exploitation tools to steal sensitive credentials, manipulate Active Directory, and establish multiple persistent access channels. Attackers disabled security features like RestrictedAdmin for RDP and exfiltrated confidential assets, including proprietary DLL libraries, potentially setting the stage for future supply chain attacks or further reverse engineering efforts. This incident reflects a broader trend of sophisticated, state-linked attackers increasingly targeting operational technology environments and critical infrastructure, exploiting unpatched vulnerabilities and adopting living-off-the-land techniques. The ongoing relevance is underscored by heightened governmental warnings and the urgent need for robust vulnerability management, segmentation, and monitoring in high-value environments.
8 months ago
Kill Chain
Predator Spyware: Inside Intellexa’s Vendor-Controlled C2 Attack Tactics (2024)
In early 2024, cybersecurity researchers uncovered evidence of Predator, a commercial spyware platform developed by Intellexa, leveraging a vendor-controlled command-and-control (C2) infrastructure to improve attack precision. Failed and thwarted infection attempts were systematically analyzed by the vendor to refine future attack methods, highlighting a professionalized feedback loop in commercial spyware campaigns. The attack vectors included advanced mobile device exploits, with malicious payloads deployed on targeted mobile devices through phishing or exploit links. The incident underscores how commercial spyware vendors adapt rapidly by learning from failed compromises, posing significant operational risk to both individuals and organizations globally. The exposure of Predator's vendor-controlled C2 approach signals a broader industry shift toward more dynamic, resilient spyware operations, complicating detection and defense for enterprises. This incident exemplifies the rise of highly adaptive, commercially-driven attack infrastructure, intensifying regulatory, technical, and reputational challenges for security leaders and organizations handling sensitive data.
8 months ago
Kill Chain
Microsoft Dismantles RedVDS: Takedown of a Major Cybercrime Infrastructure in 2026
In January 2026, Microsoft, in collaboration with Europol and German authorities, disrupted RedVDS, a global cybercrime-as-a-service platform responsible for at least $40 million in fraud losses since March 2025. RedVDS provided criminals with affordable, disposable virtual Windows servers and administrator-level access, enabling mass phishing, business email compromise (BEC) scams, credential theft, and sophisticated social engineering—including attacks leveraging AI technologies. The takedown involved legal action, seizure of RedVDS infrastructure, and removal of its marketplace and customer portal, significantly impacting cybercriminal campaigns that leveraged these services to attack organizations and individuals worldwide. This incident underscores the increasing threat posed by cybercrime-as-a-service models, which drastically lower barriers for criminals to launch high-volume, geographically-targeted attacks leveraging cloud infrastructure. The rise of AI-generated phishing, deepfakes, and anonymized payment methods heightens risk, challenging both organizational defenses and global law enforcement.
8 months ago
Kill Chain
DoS Flaw in Palo Alto Networks PAN-OS 2026: Firewall Shutdowns Expose New Risks
In January 2026, Palo Alto Networks disclosed and patched a high-severity Denial of Service (DoS) vulnerability—CVE-2026-0227—in its next-generation firewalls running PAN-OS 10.1 or later, as well as in Prisma Access configurations with the GlobalProtect gateway or portal enabled. The flaw allowed unauthenticated attackers to remotely disable firewall services, causing the devices to enter maintenance mode and disrupt protections. While there was no evidence of active exploitation at disclosure, the vulnerability posed significant risks to business continuity and network security, particularly for organizations relying on always-on perimeter defense. This incident is of particular concern given the recent uptick in attacks targeting network security and VPN appliances, regulatory focus on rapid patching, and the extensive use of Palo Alto hardware by Fortune 10 enterprises, critical infrastructure, and government agencies. The evolving threat landscape underscores the urgent need for timely vulnerability management and layered security controls.
8 months ago
Kill Chain
Critical Google Fast Pair Bluetooth Flaw Lets Hackers Track & Eavesdrop (2024)
In early June 2024, a critical vulnerability was disclosed in Google's Fast Pair Bluetooth protocol, used widely in Android devices, headphones, and earbuds. Security researchers revealed that attackers could exploit this flaw to hijack Bluetooth audio accessories, track device owners' physical movements, and potentially eavesdrop on private conversations—all without user interaction. The Fast Pair protocol failed to adequately authenticate and encrypt initial device pairing traffic, allowing threat actors within radio range to intercept or manipulate connections. The business impact extends to privacy exposures and reputational risk for both individuals and organizations relying on wireless audio devices for sensitive conversations. This incident is particularly relevant as Bluetooth and wireless accessories proliferate in enterprises, with remote and on-the-go professionals depending on them daily. The flaw highlights an urgent need for stronger encryption and authentication in edge protocols, especially as threat actors shift to exploiting overlooked supply chain and device-layer risks.
8 months ago
Kill Chain
Gootloader’s Stealth Upgrade: 1,000-Part ZIP Exploit Bypasses Detection in 2026
In January 2026, the Gootloader malware loader resurfaced with advanced evasion techniques, deploying highly obfuscated, malformed ZIP archives containing JScript payloads. By concatenating up to 1,000 archive parts and leveraging ZIP format irregularities, attackers successfully bypassed many security tools, causing them to crash or miss the threat. These ZIPs are unpackable by Windows' default utility but break common tools like 7-Zip and WinRAR. Once delivered via a decoded, XOR-encoded blob, the JScript establishes persistence through .LNK shortcuts and triggers PowerShell-based execution chains, facilitating initial access for ransomware and other malware campaigns. This incident highlights a shift toward highly customized, anti-analysis delivery methods and demonstrates how common file formats can be manipulated to evade detection. With Gootloader back in circulation, organizations face renewed threats from sophisticated malware loaders that exploit endpoint tool weaknesses and static signature limitations.
8 months ago
Kill Chain
Grubhub 2024 Data Breach: Hackers Steal Sensitive Customer Information
In June 2024, Grubhub, a major food delivery platform, experienced a significant data breach after hackers gained unauthorized access to its internal systems. According to official statements and media reports, the attackers stole sensitive customer data, including contact details and potentially account credentials. The incident led to extortion demands from the threat actors, prompting Grubhub to initiate incident response protocols and notify affected users. The breach highlighted the attackers’ ability to navigate network defenses, exfiltrate data, and potentially disrupt business operations with ransom threats. This incident is particularly relevant amid a surge in data breaches targeting large consumer platforms and the continued evolution of extortion-based attacks. With regulatory scrutiny increasing and attackers using sophisticated lateral movement tactics, organizations must reassess data protection, segmentation, and threat detection strategies.
8 months ago
Kill Chain
Modular DS WordPress Plugin Flaw Grants Attackers Admin Access in Widespread 2026 Breach
In January 2026, a critical authentication bypass vulnerability (CVE-2026-23550) was discovered and exploited in the Modular DS WordPress plugin. With over 40,000 installations, the plugin allowed central management of multiple WordPress sites. The flaw enabled unauthenticated attackers to remotely access admin-level privileges by exploiting flawed logic in the plugin’s direct request mode, resulting in privileged access without cryptographic checks. Attackers were able to select or auto-enroll themselves as site administrators, exposing affected sites to full compromise and potential downstream attacks. A patch was quickly released in version 2.5.2, closing the immediate vulnerability. This incident stands out as attackers increasingly target plugin ecosystems in widely-used CMS platforms, exploiting software supply chain vectors for rapid, broad impact. The case illustrates the urgency for continuous code review and rapid patch management in response to emergent threats.
8 months ago
Kill Chain
Palo Alto Networks GlobalProtect DoS Flaw in 2026: What CISOs Need to Know
In January 2026, Palo Alto Networks disclosed a high-severity vulnerability (CVE-2026-0227, CVSS 7.7) in its GlobalProtect Gateway and Portal services for PAN-OS, exposing organizations to unauthenticated denial-of-service (DoS) attacks. The flaw, an improper handling of exceptional conditions, enables remote attackers to crash affected firewalls and force them into maintenance mode, disrupting business-critical network operations. Vulnerable PAN-OS versions include 12.1, 11.2, 11.1, 10.2, and 10.1, as well as Prisma Access 10.2/11.2 with GlobalProtect enabled. No workarounds are available, and Palo Alto released urgent patches following responsible disclosure by an external researcher. While exploitation in the wild wasn't confirmed at disclosure, ongoing threat actor scanning against GlobalProtect instances was reported in prior months. This vulnerability reinforces the ongoing risk to critical network infrastructure posed by service exposure and unauthenticated access paths. The incident follows a trend of increased attacks targeting VPN and remote access solutions as part of broader DoS and ransomware campaigns, placing heightened pressure on organizations to patch exposed perimeter devices rapidly.
8 months ago
Kill Chain
Microsoft & Law Enforcement Dismantle RedVDS Cybercrime Platform in 2026
In January 2026, Microsoft, in collaboration with U.S. and U.K. law enforcement, disrupted the RedVDS cybercrime infrastructure, dismantling a crimeware-as-a-service network that fueled millions in global fraud losses. Managed by the threat actor Storm-2470, RedVDS offered inexpensive, disposable Windows-based RDP servers with no logging, enabling cybercriminals to conduct mass phishing, business email compromise (BEC) schemes, account takeovers, and other online fraud at scale. RedVDS’s infrastructure was critical in facilitating over $40 million in reported fraud losses in the U.S. since March 2025, impacting at least 191,000 organizations across sectors like healthcare, legal, finance, manufacturing, and real estate. The incident underscores the rapidly growing risk posed by cybercrime subscription models that democratize access to sophisticated attack tools. As CaaS platforms pair with generative AI, threat actors are increasingly able to automate and scale targeted campaigns, elevating both regulatory risk and enterprise exposure across all industries.
8 months ago
Kill Chain
Reprompt Attack on Microsoft Copilot Unlocks Single-Click Data Exfiltration
In January 2026, cybersecurity researchers discovered a novel attack technique, dubbed 'Reprompt,' targeting Microsoft Copilot and similar enterprise AI chatbots. This method leverages legitimate Microsoft links requiring only a single user click to trigger silent, one-click exfiltration of sensitive corporate data – all while circumventing standard enterprise security controls. The attack exploits weaknesses in how Copilot processes prompts and allows threat actors to quickly access confidential information without needing additional malware or user authentication bypasses. This incident highlights the increasing risk posed by attacks on generative AI systems within enterprise environments. As the adoption of LLM-powered assistants accelerates, organizations must remain vigilant against rapidly evolving prompt-injection threats, and are under new regulatory, compliance, and reputational pressures to secure data in AI workflows.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

