Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4153 to 4164 of 5957
Critical Node.js async_hooks Vulnerability Puts Production Apps at Risk of DoS Attacks
In January 2026, Node.js disclosed a critical vulnerability (CVE-2025-59466) affecting all production environments using the async_hooks module, which underpins popular frameworks and monitoring tools such as React Server Components, Next.js, and major APM platforms. The flaw allowed an attacker to cause a denial-of-service (DoS) condition by forcing stack space exhaustion via unsanitized user input, leading the Node.js process to crash unexpectedly without a catchable error. All supported Node.js Long Term Support (LTS) versions were patched, while older, unsupported releases remain exposed, impacting a broad portion of the JavaScript ecosystem. This incident highlights not only the risks inherent in reliance on low-level APIs, but also the speed at which vulnerabilities impacting critical supply chain components can disrupt software availability. Organizations reliant on Node.js for cloud, SaaS, and modern web solutions face renewed pressure to update dependencies proactively and establish robust exception handling and segmentation practices.
8 months ago
Kill Chain
Malicious Chrome Extension Breach Drains MEXC Crypto Accounts via API Key Theft
In January 2026, cybersecurity researchers uncovered a malicious Chrome extension called "MEXC API Automator" targeting users of the MEXC cryptocurrency exchange. Deployed via the Chrome Web Store, the extension masqueraded as a legitimate trading tool to covertly generate new API keys on behalf of users, surreptitiously enabling withdrawal permissions. It then exfiltrated these sensitive credentials to a Telegram bot controlled by the attacker, granting potential full access to victims' MEXC accounts, including the ability to automate trades and drain balances. The campaign leveraged authenticated browser sessions, evading traditional credential protections, and tampered with the user interface to conceal its malicious activity. This incident highlights a sophisticated shift in attack vectors targeting API workflows and browser sessions, rather than direct password theft. It underscores urgent risks inherent in trusted browser extensions, particularly as infostealers increasingly exploit the digital supply chain and cryptographic asset platforms.
8 months ago
Kill Chain
Magecart Web Skimming Campaign Exposes Payment Providers and Customers
Between January 2022 and January 2026, cybersecurity researchers uncovered an advanced web skimming campaign attributed to Magecart-related actors, compromising numerous e-commerce and payment websites linked to major providers including American Express, Mastercard, and others. The attackers injected heavily obfuscated JavaScript skimmers via domains controlled by sanctioned bulletproof hosts, notably Stark Industries and THE.Hosting, enabling the theft of sensitive credit card and personal data from unsuspecting users during checkout. The malicious code leveraged techniques to evade administrator detection and selectively harvested data before exfiltrating it through external servers, ultimately exposing customers and enterprises to widespread data theft risks. The discovery highlights a sustained increase in sophisticated client-side web skimming attacks leveraging supply chain weak points and exploiting trust in major payment platforms. The evolving tactics, regulatory expectations for PCI and consumer protection, and the broadening scope of victim organizations make ongoing vigilance and technical controls imperative for all businesses accepting online payments.
8 months ago
Kill Chain
2026 Web Research: Unjustified Third-Party App Data Access Exposes Massive Risk
In January 2026, new research exposed that 64% of third-party applications integrated by over 4,700 prominent websites were accessing sensitive user and business data without valid justification. The study found alarming trends, notably a surge in malicious activity targeting the government sector (rising from 2% to 12.9%) and a concerning rate of active compromise in education sites, with one in seven showing evidence of ongoing breaches. Key offenders included Google Tag Manager, Shopify, and Facebook Pixel, which collectively accounted for a significant proportion of data exposure violations. The study reveals ongoing systemic weaknesses in the vetting and oversight of embedded web applications, risking confidential data and regulatory non-compliance for organizations. This report is especially pertinent amidst increased regulatory scrutiny and as supply chain attacks become more prevalent. Attackers are exploiting trust relationships with third-party services, while organizations face rising pressure to demonstrate rigorous controls over data sharing and vendor integrations. The findings underscore a shift in attacker focus and highlight the operational risks of unchecked third-party access.
8 months ago
Kill Chain
Microsoft’s January 2026 Patch Tuesday: 114 Flaws Fixed, Zero-Day Exploited
In January 2026, Microsoft released its first Patch Tuesday update of the year, addressing 114 security vulnerabilities affecting Windows, with one actively exploited zero-day vulnerability. Of the total, eight were rated Critical and the rest Important, with the majority comprising privilege escalation, information disclosure, and remote code execution flaws. The exploited vulnerability, discovered in the wild, could allow threat actors to gain unauthorized access or escalate privileges on affected systems, posing a risk to both organizations and individuals relying on unpatched Windows environments. Microsoft issued immediate guidance to mitigate ongoing risks. This incident underscores the persistent risks from unpatched systems and highlights the continued targeting of widely deployed platforms like Windows. Organizations face heightened pressure to prioritize vulnerability management and timely patching as adversaries quickly weaponize newly disclosed flaws.
8 months ago
Kill Chain
AI Agents: The New Privilege Escalation Path in Enterprise Security (2026)
In January 2026, organizations leveraging AI agents across core business processes were found to face significant privilege escalation risks. AI-powered workflow and support agents—granted broad permissions for automation—enabled users to trigger actions and access resources far beyond their direct entitlements. Because these agents operate under shared service accounts or long-lived credentials, traditional identity-based access controls and audit trails attributed activities to the agent, obscuring the true initiator. This design gap quietly allowed users to bypass policy boundaries, escalating privileges and risking unauthorized changes or exposure of sensitive data. The incident highlights a crucial shift: as enterprises rapidly adopt organizational AI agents, attackers and insiders can exploit the mismatch between agent and user permissions. With AI-mediated workflows, the failure to tie actions to originating users undermines zero trust, least privilege, and core compliance mandates, increasing urgency for new visibility and access governance solutions.
8 months ago
Kill Chain
Attackers Bypass Security Using c-ares DLL Side-Loading: Commodity Malware Delivered in Active Campaign
In January 2026, security researchers reported an active malware campaign leveraging DLL side-loading via the open-source c-ares library. Attackers paired a malicious 'libcares-2.dll' with the legitimate signed 'ahost.exe' to evade security controls and deploy multiple trojans and info-stealer malwares. This method exploited trust in legitimate software to bypass endpoint defenses, leading to widespread compromise across targeted organizations and enabling the theft of sensitive data and credentials. Initial access was facilitated by distributing rogue DLLs alongside trusted binaries, primarily impacting organizations with inadequate application whitelisting and file integrity controls. This incident is particularly relevant as DLL side-loading attacks remain a favored technique for cybercriminals to circumvent detection, especially as organizations continue to migrate to cloud and hybrid environments. The campaign highlights a growing trend in software supply chain exploitation and the need for stronger endpoint and lateral movement protections.
8 months ago
Kill Chain
Unpacking the Kimwolf & AISURU Botnet: How 2 Million Android Devices Became a DDoS Army
In late 2025, security researchers at Lumen’s Black Lotus Labs null-routed traffic to over 550 command-and-control (C2) servers associated with the rapidly expanding Kimwolf and AISURU botnets. These botnets primarily targeted Android TV streaming devices—especially those with exposed ADB services—and used a malicious SDK (ByteConnect) to conscript over two million devices into a powerful residential proxy network. Threat actors leveraged this massive bot army to launch distributed denial-of-service (DDoS) attacks and facilitate malicious relay of internet traffic, further monetizing access via underground proxy services marketed on Discord and other platforms. The botnets exhibited rapid growth, exploiting security flaws in both consumer hardware and third-party proxy services for propagation. This incident highlights a shift in cybercriminal tactics toward wielding residential IP addresses for nefarious activity, circumventing traditional detection and blocking mechanisms. The scale and sophistication of these campaigns underscore escalating risks to organizations relying on residential endpoints and underscore the urgency for improved segmentation, anomaly detection, and real-time response.
8 months ago
Kill Chain
Fortinet FortiSIEM 2026: Critical Unauthenticated Remote Code Execution Vulnerability Exposed
In January 2026, Fortinet disclosed and patched a critical vulnerability (CVE-2025-64155) affecting FortiSIEM, its security information and event management platform. The flaw is an OS command injection bug with a CVSS score of 9.4, which allows unauthenticated remote attackers to execute arbitrary code with system privileges. This exposes organizations to potential full compromise of their FortiSIEM instances, enabling adversaries to gain visibility into security infrastructure, manipulate logs, or pivot into internal environments. Immediate updates were recommended to prevent exploitation, as vulnerable versions were actively at risk. This incident underscores the persistent risk posed by pre-authentication remote code execution vulnerabilities in widely-deployed security appliances. The growing reliance on SIEM and orchestration tools makes them attractive targets, amplifying the urgency for rapid patching and robust network segmentation to minimize blast radius amid evolving attacker techniques.
8 months ago
Kill Chain
WhiteDate 2026 Data Breach: Privacy, Doxing, and Sensitive Data Handling
In January 2026, a sensitive data breach occurred involving WhiteDate, a controversial dating platform, exposing the personal information of its user base. The breach involved the unauthorized disclosure of email addresses and other private attributes, potentially linking individuals to a site associated with significant social stigma and white supremacist ideologies. Cybersecurity experts flagged this incident as highly sensitive due to the risk of outing individuals based solely on their presence in the dataset, which could result in reputational, professional, and even physical harm. The case reignited debates on the ethics of breach data handling and the obligations for responsible disclosure, especially where the data intersects with legally defined sensitive categories. This breach is particularly relevant as privacy frameworks and legal standards, such as GDPR and CCPA, impose stricter requirements for classifying and handling sensitive data. The rise of doxing and moral-driven disclosures increases the urgency for robust zero trust governance and nuanced incident response.
8 months ago
Kill Chain
VoidLink Malware: Advanced Intrusions Against Linux & Cloud in 2024
In early 2024, security researchers uncovered a highly advanced Linux threat dubbed 'VoidLink,' a modular and cloud-first malware framework engineered for persistent, stealthy access on enterprise Linux systems. The attackers leveraged sophisticated obfuscation and privilege escalation techniques to deploy VoidLink in cloud environments, allowing them to bypass traditional detection controls. With capabilities to maintain long-term access, communicate over encrypted channels, and employ lateral movement, the group behind VoidLink targeted organizations seeking to exploit gaps in east-west traffic security and cloud visibility. The resulting impact included potential unauthorized access, data exfiltration, and operational risk to critical workloads. The VoidLink discovery underscores a broader industry trend toward sophisticated Linux and cloud-targeting malware, reflecting both attacker innovation and increasing value of Linux workloads. Security and compliance leaders should consider this incident a warning—defending Linux-based environments now requires cloud-native controls, enhanced visibility, and integrated anomaly detection as attackers shift beyond legacy perimeter defenses.
8 months ago
Kill Chain
Microsoft Patch Tuesday January 2026: Actively Exploited Zero-Day and Critical Vulnerabilities
In January 2026, Microsoft released updates addressing 113 vulnerabilities across its Windows operating systems and supported software, including eight critical flaws and an actively exploited zero-day, CVE-2026-20805, in Desktop Window Manager (DWM). Despite a moderate CVSS of 5.5, this bug exposes address layout information, enabling attackers to chain it with other vulnerabilities for reliable compromise. Additionally, two critical Microsoft Office remote code execution flaws allowed attacks via specially crafted emails, and legacy modem driver vulnerabilities posed new elevation-of-privilege risks. Failure to patch exposes organizations to memory exploit chains, lateral movement, and potential system-level compromise affecting even fully updated environments. This incident highlights the ongoing threat of exploited zero-day vulnerabilities and the importance of timely patching amidst evolving attacker tactics. The rise of attacks leveraging old device drivers and exploitation chains underscores the need for risk-based vulnerability management and proactive security control validation.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

