Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4189 to 4200 of 5957
Apex Legends Live Character Hijack: 2026 Gaming Platform Breach Explained
In January 2026, Apex Legends players experienced a major security incident where an external threat actor gained unauthorized control over live player characters during matches. The attacker remotely hijacked user avatars, disconnected players from servers, and manipulated in-game identities, temporarily disrupting the gaming experience for tens of thousands. Respawn Entertainment, the game's publisher, confirmed the attack but stated there was no evidence of remote code execution or malware. Investigation pointed to exploitation of privileged backend debugging or admin interfaces, rather than a software vulnerability affecting all client machines. This incident underscores escalating threats targeting large-scale gaming platforms, where privilege escalation and endpoint attacks now rival phishing or malware techniques in their sophistication. With gaming ecosystems becoming lucrative and complex, attackers continue to innovate, highlighting the urgent need for improved internal traffic security and continuous monitoring.
8 months ago
Kill Chain
2025 University of Hawaii Cancer Center Ransomware Breach: Research Data Compromised
In August 2025, the University of Hawaii Cancer Center experienced a ransomware incident that resulted in threat actors encrypting systems associated with a specific research project. The intrusion led to the exfiltration and encryption of files, some of which dated back to the 1990s and included research participant data containing Social Security numbers, predating modern de-identification practices. While only research files and not clinical or patient treatment data were affected, the disruption necessitated a comprehensive remediation effort including system replacements, forensic investigations, ransomware payment for decryption, and negotiations for deletion of exfiltrated information. This incident underscores the targeting of higher-education and research organizations by ransomware attackers seeking both data and financial gain. With universities increasingly storing decades-old PII, and ransomware groups escalating both exfiltration and extortion, the breach exemplifies the urgency of robust detection, legacy data management, and compliance disciplines in the education and research sector.
8 months ago
Kill Chain
Browser-in-Browser Phishing Surge: Facebook Credential Thefts Expose New Risks in 2024
In early 2024, cybercriminals dramatically escalated the use of the 'browser-in-browser' (BitB) attack technique to steal Facebook login credentials. This method mimics a legitimate browser popup within the user's real window, tricking individuals into entering their login details on phishing sites that look identical to authentic Facebook authentication dialogs. Attackers lure victims through targeted ads, social engineering, and cleverly crafted phishing emails. The impact includes widespread account compromise, enabling follow-on fraud, spam campaigns, and potential data exfiltration from the compromised users' profiles. Facebook, along with the wider cybersecurity community, is warning users and rolling out alerts in response, but overall threat exposure remains high. The BitB phishing approach reflects a concerning trend of attackers using more advanced visual deceptions to bypass user awareness and established security controls. Its prevalence highlights a widening capability gap in traditional anti-phishing technologies, reinforcing the need for robust anomaly response and continuous education amid shifting adversary tactics.
8 months ago
Kill Chain
CISA Orders Critical Patching After Gogs Zero-Day RCE Attacks Hit Hundreds of Servers
In January 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a directive to all federal agencies to urgently patch a critical remote code execution (RCE) vulnerability (CVE-2025-8110) in Gogs, a popular open-source git service, following multiple waves of active zero-day exploitation. The flaw leveraged a path traversal issue via the PutContents API, allowing authenticated attackers to overwrite files outside repositories—including SSH command configurations—to gain arbitrary code execution. At least 700 internet-facing Gogs servers showed signs of compromise, implicating risks across the federal enterprise. This incident underscores the accelerated threat posed by zero-day exploits targeting software supply chain and collaboration tools exposed to the internet. The increase in attacks against widely used developer platforms, combined with slow patch adoption and the rapid weaponization of vulnerabilities, demands renewed attention to secure configuration, real-time monitoring, and timely security updates.
8 months ago
Kill Chain
GoBruteforcer Botnet Exploits AI-Generated Weak Credentials to Breach Crypto Databases (2026)
In January 2026, the GoBruteforcer botnet orchestrated a campaign targeting cryptocurrency and blockchain project databases. Attackers exploited weak or default credentials on exposed Linux-based services, including FTP, MySQL, PostgreSQL, and phpMyAdmin, to gain unauthorized access and deploy IRC bots and web shells. Many of the compromised credentials were traced to AI-generated server setup examples and outdated web stack configurations. Once inside, the botnet employed brute-force modules to propagate, staged payloads, and established redundant command-and-control channels. One notable tactic involved scanning TRON blockchain addresses for accounts with non-zero balances, signaling a financially motivated focus on blockchain assets. This incident highlights the evolving intersection of automated attack tools, AI-influenced misconfigurations, and crypto-driven targeting. The persistent exploitation of misconfigured infrastructure underscores rising risks to technology firms, especially as low-effort credential attacks increasingly leverage AI-generated default settings.
8 months ago
Kill Chain
Pig Butchering Fraud: Service Providers Power the Next Wave of Industrial-Scale Online Scams
In early 2026, cybersecurity researchers revealed that two specialized service providers are supplying criminal networks with infrastructure and scalable toolkits to support industrial-scale pig butchering fraud, primarily across Southeast Asia. These providers lower the barrier to entry for fraudsters by offering turnkey scam platforms, stolen identity data, and payments solutions designed to evade law enforcement. The so-called PBaaS (Pig-Butchering-as-a-Service) ecosystem enables rapid creation of scam campaigns leveraging advanced CRM platforms, phishing tactics, and laundering tools, impacting individuals and financial institutions globally. This incident underscores the evolution of cyber-enabled fraud into a scalable, service-driven shadow industry, exploiting technology and industrial organization for criminal gain. The widespread adoption of such "fraud-as-a-service" business models reflects a broader trend in cybercrime, making advanced threat tactics more accessible to a wider range of malicious actors.
8 months ago
Kill Chain
How Insider Threats and Malware Breached Rotterdam and Antwerp Ports
Between September 2020 and April 2021, a Dutch national infiltrated IT systems across major European ports, including Rotterdam and Antwerp, by leveraging insider access at a logistics firm. Employees inserted USB sticks laden with malware, providing the hacker with persistent access to sensitive server infrastructure. Through remote access tools, the attacker intercepted data in transit, exfiltrated critical databases, and enabled large-scale smuggling operations—including the undetected import of 210 kg of cocaine—while also attempting extortion and resale of malware. This incident highlights the evolving intersection of cybercrime with organized crime, particularly how threat actors exploit insider vectors to orchestrate large-scale physical and digital breaches. The case underscores urgent regulatory and cyber defense challenges facing port operators and logistics networks globally.
8 months ago
Kill Chain
n8n npm Supply Chain Attack: OAuth Tokens Stolen via Malicious Community Nodes
In early January 2026, threat actors targeted the n8n workflow automation ecosystem by publishing eight malicious npm packages that mimicked legitimate integrations. These packages prompted unsuspecting users to connect OAuth-protected services like Google Ads, Stripe, and Salesforce. Once installed as community nodes, the malware exfiltrated encrypted OAuth tokens from the n8n credential store by decrypting them with n8n's own master key and sending them to attacker-controlled servers. The campaign exploited developer trust in community packages and highlighted a dangerous new avenue for credential theft at scale. This incident reflects the increasing sophistication and frequency of supply chain attacks, particularly against workflow automation tools that centralize sensitive credentials. With open-source ecosystems growing rapidly, businesses face heightened urgency to scrutinize third-party integrations and adopt least-privilege, zero trust security practices.
8 months ago
Kill Chain
Gogs Path Traversal CVE-2025-8110: Active Exploitation Prompts CISA KEV Inclusion
In January 2026, CISA issued an alert adding CVE-2025-8110 to its Known Exploited Vulnerabilities Catalog after confirming active exploitation of a critical path traversal vulnerability in Gogs, a popular self-hosted Git service. Threat actors leveraged this flaw to bypass directory security controls, allowing unauthorized access to sensitive files and potentially facilitating lateral movement, data exfiltration, or the deployment of malicious code in affected federal and private sector organizations. In accordance with Binding Operational Directive 22-01, Federal Civilian Executive Branch agencies were ordered to remediate this vulnerability immediately to stem ongoing exploitation risks and protect government infrastructure. The ongoing exploitation of CVE-2025-8110 highlights a growing trend of attackers targeting unmanaged or overlooked developer infrastructure for initial access. The incident underscores regulatory and operational pressure for timely vulnerability management and demonstrates the criticality of securing east-west application flows.
8 months ago
Kill Chain
Two Major Campaigns Expose AI/LLM Endpoint Security Flaws in 2024
In early 2024, security researchers observed two distinct attack campaigns targeting more than 91,000 public Large Language Model (LLM) endpoints. Threat actors systematically scanned for exposed LLM interfaces left accessible on the public internet, leveraging them to probe for sensitive data leaks and map organizational attack surfaces. Attackers exploited the unprotected AI endpoints primarily through direct web probes and API requests, taking advantage of lax access controls and lack of encryption. The business impact included the risk of sensitive internal data exposure, increased surface area for lateral movement, and potential regulatory non-compliance. The incident highlights the increasing threat to organizations deploying AI/GenAI technologies without robust security controls. As adoption of LLMs surges, attackers are pivoting to exploit these modern interfaces, driving urgency for enterprises to secure AI assets, enforce segmentation, and monitor for unauthorized use of LLM endpoints.
8 months ago
Kill Chain
Researchers Uncover How Subtle Tuning Can Corrupt LLMs via Inductive Backdoors
In January 2026, researchers published a pivotal study revealing new ways that adversaries can corrupt large language models (LLMs) through subtle data poisoning and finetuning techniques that exploit the models’ generalization abilities. The research demonstrated that minimal, targeted finetuning can induce LLMs to adopt outdated or harmful behaviors even outside the initial scope of manipulation. Notably, the study introduced the concept of "inductive backdoors," wherein LLMs generalize a malicious trigger and behavior relationship—resulting in broad, unpredictable misalignments and persona shifts not directly present in the source training data. No direct attacker, but the techniques expose exploitable weaknesses in LLM training pipelines and data supply chain security. This finding is urgent for organizations integrating AI/ML into business operations. It spotlights a new class of supply chain and insider risk: even small, unnoticed changes in model inputs or fine-tuning datasets can profoundly undermine trust, safety, and regulatory compliance in deployed AI systems.
8 months ago
Kill Chain
US Gray Zone Cyber Operations Disrupt Venezuela’s Oil Sector in 2020
In early 2020, cyber-enabled disruptions targeted Venezuela’s state-owned oil sector amidst political upheaval and mounting international pressure. While formal attribution remains disputed, sources suggest that US-affiliated actors leveraged advanced cyber techniques—such as persistent access, supply chain vulnerabilities, and mapped system dependencies—to intermittently degrade operational capabilities and exports. The campaign unfolded as ongoing, reversible disruptions aimed at eroding economic resilience and regime stability without triggering overt conflict. These actions exemplified nation-state 'gray zone' operations, leveraging cyber tools for sustained coercion rather than momentary effect. This incident marked a shift in statecraft, signaling the integration of cyber-enabled economic interference with traditional levers like sanctions and diplomacy. It reflects a broader, rising trend of major powers using deniable, persistent cyber operations to exert pressure on adversarial infrastructure while remaining below the threshold of conventional military escalation.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

