Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4201 to 4212 of 5957
Instagram 2026: Data Scraping Leak Exposes 17 Million Accounts
In January 2026, security researchers and several hacking forums circulated claims that data for over 17 million Instagram accounts was leaked online. The incident is believed to stem from large-scale data scraping leveraging a password reset email bug, combined potentially with prior years' API vulnerabilities. The leaked dataset included a variety of personal information such as usernames, phone numbers, email addresses, and physical addresses. No passwords were exposed, and Meta (Instagram's parent company) denies that a system breach or new API compromise occurred, noting existing issues were promptly addressed and account security remains uncompromised. This case underscores the ongoing threat of data scraping and API abuse, where publicly accessible or insufficiently protected endpoints are targeted by cybercriminals. With the proliferation of social engineering attacks using scraped personal data and the repeated emergence of similar incidents across major platforms, the need for robust API security and user vigilance has never been greater.
8 months ago
Kill Chain
Spain’s 2026 Black Axe Bust Exposes BEC Cybercrime Risks
In January 2026, Spanish authorities arrested 34 individuals connected to the Black Axe cybercrime syndicate after dismantling a sophisticated cyber fraud ring operating across several European countries. The group, led by Nigerian nationals, specialized in Business Email Compromise (BEC) attacks and man-in-the-middle scams, intercepting legitimate corporate communications to modify payment details and siphon funds. Law enforcement seized cash, vehicles, electronics, and froze bank accounts, with total damages from the group estimated at over $6 million—$3.5 million of which is tied directly to this operation. The offenders face serious criminal charges including fraud, money laundering, and membership in a criminal organization. This case highlights both the growing scale and ongoing evolution of international BEC cybercrime, where criminal syndicates exploit business processes, global money mules, and increasingly sophisticated digital tactics. Regulatory, financial, and reputational risks remain high for organizations that fail to secure communications channels and business workflows from targeted attacks.
8 months ago
Kill Chain
BreachForums 2025 Breach: 324,000 Accounts and PGP Keys Leaked in Cybercrime Forum Incident
In August 2025, BreachForums—the notorious hacking forum—suffered a major data leak when an unsecured backup of its user database was exposed online during site restoration activities. Threat actors, including a site impersonating the ShinyHunters gang, published the database containing nearly 324,000 account records. Most member IP addresses were obfuscated, but over 70,000 exposed real public IPs, along with usernames, emails, registration dates, and other metadata. Also leaked was a PGP private key used by forum admins, which later became accessible after the passphrase was posted online. This breach occurred shortly after law enforcement actions against the forum and the shutdown of its .hn domain following the arrest of its operators. This incident underscores the persistent risk of sensitive data exposure even among cybercriminal communities and highlights evolving law enforcement tactics. The leak fuels ongoing debate over forum honeypots, operational security failures, and the volatility of underground forums, while serving as a timely reminder of the dangers of unprotected data backups and shifting threat actor TTPs.
8 months ago
Kill Chain
MuddyWater Deploys RustyWater RAT: 2026 State-Sponsored Espionage Hits Middle East
In January 2026, the Iranian state-aligned threat actor MuddyWater (also known as Mango Sandstorm and TA450) executed a targeted spear-phishing campaign against diplomatic, maritime, financial, and telecom organizations in the Middle East. Attackers used icon-spoofed phishing emails with malicious Microsoft Word documents, luring victims to enable macros which deployed the RustyWater remote access trojan—a Rust-based modular implant offering asynchronous command-and-control, anti-analysis techniques, registry persistence, and capability to expand post-compromise operations. The campaign reflects MuddyWater’s ongoing evolution from using commercial RATs to custom malware, with RustyWater providing high stealth and operational flexibility. This incident highlights the growing sophistication of state-affiliated threat actors leveraging new malware frameworks and advanced phishing tradecraft. MuddyWater’s rapid shift to Rust-based tooling demonstrates a broader attacker trend toward custom, evasive, and cross-platform implants targeting critical infrastructure and sensitive sectors.
8 months ago
Kill Chain
Europol Arrests 34 Black Axe Members in Massive 2026 Organized Cyber-Fraud Takedown
In January 2026, Europol and Spanish authorities arrested 34 suspected members of the Black Axe organized crime syndicate in Spain, dismantling a major transnational cyber-fraud operation. The group, originating from Nigeria but operating internationally, orchestrated a series of sophisticated cyber-enabled crimes, including business email compromise, romance and inheritance scams, credit card and tax fraud, and extensive money laundering. Law enforcement seized over €185,000 ($216,000) in assets and disrupted fraud estimated at more than €5.9 million ($6.9M), highlighting Black Axe's role in global financial crime and cyber-enabled offenses. This incident underscores the growing intersection of traditional organized crime with advanced cyber-fraud tactics, as law enforcement faces increasingly complex, multi-jurisdictional threats. The reliance on cyber-enabled fraud techniques by such syndicates reflects an urgent need for organizations to adapt their security posture to address sophisticated, persistent, and highly organized threats.
8 months ago
Kill Chain
CISA Closes Era of Emergency Directives — Centralizes Federal Vulnerability Management in 2026
In January 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) retired ten Emergency Directives (EDs) that had been issued between 2019 and 2024 to mitigate high-risk vulnerabilities including DNS tampering, Microsoft Exchange flaws, Print Spooler vulnerabilities, SolarWinds compromise, and other widely exploited threats. CISA's review determined that remediation was complete and these urgent directives are now covered under Binding Operational Directive 22-01—which requires agencies to rapidly patch known exploited vulnerabilities (KEVs) in accordance with stricter deadlines. This mass retirement signals a shift from fragmented, incident-driven orders to centralized, ongoing vulnerability management via the KEV catalog. This move is especially relevant as threat actors continue to exploit unpatched vulnerabilities with increasing speed and sophistication. CISA’s new guidance streamlines federal agencies’ response, setting an industry precedent for proactive vulnerability management and rapid patch cycles aligned with emerging regulatory pressure and rising adversary activity.
8 months ago
Kill Chain
China-Nexus Hackers Breach Telecoms via Edge Device Exploitation
In January 2026, a sophisticated cyber-espionage campaign attributed to China-linked group UAT-7290 targeted telecommunications providers across South Asia and Southeastern Europe. The threat actors exploited known vulnerabilities in edge network devices using one-day exploits and targeted SSH brute-forcing for initial access, quickly escalating privileges and deploying Linux-based malware such as RushDrop, DriveSwitch, SilentRaid, and Bulbature. Their activities included extensive reconnaissance, persistent backdoor deployment, and converting compromised servers into operational relay boxes for further attacks, causing significant risk to sensitive communications infrastructure. This incident highlights escalating threats to critical telecom sectors, as state-affiliated actors increasingly leverage public exploits and shared toolkits for multi-layered attacks. Such breaches underscore urgent needs for proactive edge device security and improved lateral movement detection strategies amid rising geopolitical cyber operations.
8 months ago
Kill Chain
Critical RCE Flaw in Trend Micro Apex Central Revealed and Patched
In January 2026, Trend Micro disclosed a critical remote code execution (RCE) vulnerability (CVE-2025-69258) in its Apex Central on-premises management console. The flaw allowed unauthenticated, remote attackers to achieve SYSTEM-level code execution by sending crafted messages to the MsgReceiver.exe process via TCP port 20001. Exploitation required no user interaction and leveraged a DLL injection via a LoadLibraryEx vulnerability. Successful exploits could give attackers control over endpoint security management, posing risks to network-wide defenses and compliance. This incident underscores the urgent need for rapid patching, especially for Internet-facing management consoles. Such remote code execution vulnerabilities are increasingly targeted by threat actors due to their high-impact potential, and regulatory scrutiny over software vulnerabilities in critical security products has intensified.
8 months ago
Kill Chain
Illinois Man Phishes 570 Snapchat Accounts in Major 2026 Breach
In early 2026, U.S. authorities charged Illinois resident Kyle Svara for orchestrating a large-scale phishing and account takeover operation targeting Snapchat users. Between May 2020 and February 2021, Svara used social engineering tactics, including impersonating Snap representatives, to solicit access codes from over 4,500 individuals. He successfully compromised credentials for approximately 570 victims and accessed at least 59 accounts without permission, stealing private images and selling his hacking services online via forums like Reddit and encrypted channels such as Kik. Affected organizations included Northeastern University and Colby College, with the breach exposing significant privacy and security risks for hundreds of women. This breach highlights the escalating threat of identity-driven attacks leveraging social engineering and phishing to gain unauthorized access to sensitive accounts. The incident underscores increased regulatory and public scrutiny of platforms' ability to safeguard user credentials, as well as the evolving risks posed by credential harvesting and account takeover methods.
8 months ago
Kill Chain
Hackers Exploit Misconfigured Proxies to Access Paid LLM Services in 2026
In late 2025 and early 2026, threat actors launched coordinated campaigns to identify and exploit misconfigured proxy servers providing unauthorized access to commercial large language model (LLM) services. Using enumeration techniques and server-side request forgery (SSRF) vulnerabilities, attackers probed over 73 LLM endpoints—like OpenAI, Anthropic, and Google Gemini—producing more than 80,000 sessions. Their tactics included low-noise queries to bypass security alerts, the injection of malicious registry URLs, and Twilio SMS webhooks. While the activity appeared research-oriented at times, the scale and automated reconnaissance efforts were indicative of broader malicious reconnaissance likely intended for future exploitation or abuse of these valuable AI assets. This incident underscores a broader rise in cloud misconfiguration attacks and highlights escalating threats targeting AI infrastructure. As reliance on LLM APIs grows, so too does the risk of credential abuse and exploitation, placing new urgency on proactive cloud security, real-time monitoring, and zero trust principles across managed AI services.
8 months ago
Kill Chain
Illinois DHS Exposes 700,000+ Residents in Years-long Data Misconfiguration
In September 2025, the Illinois Department of Human Services (IDHS) discovered a data exposure incident affecting nearly 700,000 residents, when maps containing sensitive information were found to be publicly accessible due to misconfigured privacy settings on a mapping website. The breach, which lasted for several years, involved the exposure of addresses, case numbers, demographic details, and medical assistance plan information for Medicaid and Medicare recipients (without names), as well as additional data including names for a smaller group of rehabilitation services clients. Upon discovery, IDHS promptly secured the exposed maps, reviewed affected materials, and implemented safeguards to prevent recurrence. This incident highlights the persistent risk of misconfiguration-based data exposures in public sector organizations, especially with increasing reliance on digital tools for data visualization and resource management. As regulatory scrutiny and public concern over privacy intensify, organizations must prioritize robust controls over platforms managing sensitive information.
8 months ago
Kill Chain
FBI: North Korean 'Quishing' Campaign Exploits QR Codes to Breach US Organizations (2025)
In May and June 2025, North Korean state-backed group Kimsuky (also known as APT43) launched a wave of spear-phishing attacks leveraging malicious QR codes—known as "quishing"—against U.S. and foreign think tanks, academic institutions, and government entities. Attackers embedded QR codes in spoofed emails designed to bypass enterprise security controls by luring recipients into scanning codes with unmanaged mobile devices. These malicious codes redirected victims to attacker-controlled infrastructure for credential harvesting, cloud account takeover, and the deployment of Android malware such as DocSwap. The campaign enabled threat actors to steal session tokens, circumvent multi-factor authentication, and maintain persistence in organizational environments via compromised identities and secondary phishing from breached mailboxes. This incident underscores a significant shift toward MFA-resilient, mobile-driven spear-phishing tactics that exploit overlooked security gaps at the intersection of email and mobile authentication. The campaign represents a new wave of targeted attacks exploiting trust in QR codes and mobile workflows as adversaries adapt to improved enterprise email defenses.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

