Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 517 to 528 of 5935
SickKids Hospital Data Breach Exposes Critical Third-Party Security Gaps
In December 2024, Toronto's Hospital for Sick Children (SickKids) disclosed a cybersecurity incident that exposed personal information of current and former employees and job applicants through a vulnerability in third-party software. The breach affected human resources data including names, addresses, phone numbers, and employment details, while clinical systems and patient records remained unaffected. SickKids immediately secured the compromised system, launched an investigation with cybersecurity experts, and began notifying affected individuals while implementing additional security measures. This incident highlights the growing trend of healthcare organizations facing data breaches through third-party vendor vulnerabilities, a critical concern as healthcare becomes increasingly digitized and regulatory scrutiny intensifies under frameworks like HIPAA and emerging privacy legislation.
3 weeks ago
Kill Chain
Novel FTP Banner Attack Delivers E4del and PINHOLE RATs in 2026 Campaign
In July 2026, threat actors developed a novel attack technique using FTP server banners as dead-drop resolvers to deliver two previously undocumented remote access trojans: E4del and PINHOLE. The campaign begins with phishing attacks distributing ZIP archives containing malicious LNK files that connect to compromised FTP servers to retrieve PowerShell commands embedded in server greeting banners. E4del masquerades as Discord using a digitally signed Electron application, while PINHOLE uses sophisticated evasion techniques including shellcode fluctuation and retrieval of C2 configurations from Pinterest and SurveyMonkey. SOCRadar researchers found this technique remained active through August 2026 with new infrastructure continuously deployed. This incident highlights the evolution of living-off-the-land techniques where attackers abuse legitimate protocols and services to evade detection, representing a broader trend toward more sophisticated command and control methods that bypass traditional security controls.
3 weeks ago
Kill Chain
TrueConf Server Supply Chain Attack: How Head Mare Exploited Critical CVE-2026-72529 Vulnerability
In August 2026, CISA ordered federal agencies to patch two critical TrueConf Server vulnerabilities (CVE-2026-72529 and CVE-2026-72530) within two weeks after adding them to the Known Exploited Vulnerabilities catalog. The flaws allow unauthenticated remote code execution and sandbox escape attacks on the self-hosted communications platform. The Head Mare hacktivist group has been actively exploiting these vulnerabilities since July 2026 to replace legitimate client installers with backdoor-laden versions, targeting Russian organizations across transportation, energy, and IT sectors. This incident follows previous TrueConf compromises, including Operation True Chaos linked to Chinese threat actors in April 2026. This attack highlights the growing trend of supply chain compromises targeting enterprise communication platforms, particularly as organizations increasingly rely on self-hosted solutions for secure corporate messaging and video conferencing amid rising cybersecurity concerns about cloud-based alternatives.
3 weeks ago
Kill Chain
Massive AWS Credential Leak Exposes 817 Corporate Accounts to Full Takeover
Between August 2022 and August 2026, Truffle Security discovered over 9,300 Amazon Web Services (AWS) access keys publicly exposed across code repositories, Git history, datasets, Docker images, and CI logs. Of these, 817 keys were linked to corporate accounts, with 526 being AWS root keys granting unrestricted administrative access. Researchers found that 242 keys belonged to IAM users with AdministratorAccess policies, effectively providing full control over corporate AWS environments. Hugging Face emerged as the largest single source with 8,482 exposed keys, many remaining active for years without rotation. This incident highlights the persistent challenge of credential management in cloud environments as organizations increasingly rely on Infrastructure as Code and automated deployment pipelines. With the median age of exposed keys being over five years and only 13.7% showing evidence of rotation, the findings underscore critical gaps in security hygiene that threat actors actively exploit for cryptomining operations, data exfiltration, and persistent access establishment.
3 weeks ago
Kill Chain
Automotive Cybersecurity Alert: First Android Head Unit Malware Targets Connected Vehicles
In June 2026, Kaspersky researchers discovered the first documented case of Android malware specifically targeting automotive head units. The MoYu Group, linked to the BADBOX botnet, exploited legitimate update mechanisms in DoFun head unit firmware to distribute multi-stage malware through the TWCore system application. The attack chain deployed a sophisticated dropper that ultimately created a proxy botnet for ad fraud operations. The malware spread through built-in firmware updaters without user knowledge, establishing command and control infrastructure to recruit infected vehicles into their botnet network. This incident represents a critical expansion of botnet operations into automotive systems, highlighting the growing threat surface as vehicles become increasingly connected. With automotive head units now proven vulnerable to the same malware techniques used against smartphones and IoT devices, the automotive industry faces new cybersecurity challenges requiring immediate attention.
3 weeks ago
Kill Chain
SynkLoader Malware Exploits Microsoft Teams Trust in 2026 Campaign
In July 2026, cybercriminals launched a sophisticated phishing campaign using Microsoft Teams to distribute a new malware family called SynkLoader. Attackers impersonated IT help desk personnel to trick victims into installing a fake 'PowerShell Cleaner' executable hosted on Microsoft Azure. The multi-language malware combines Python, PowerShell, C#, and C++ components to establish persistence, steal credentials through a convincing fake Windows lock screen, and create backdoor access for potential ransomware operations. The campaign demonstrates the growing abuse of trusted collaboration platforms and sophisticated social engineering tactics that bypass traditional email security measures. This incident highlights the evolving threat landscape where attackers increasingly target remote work infrastructure and exploit user trust in corporate communication tools, making traditional perimeter security insufficient against modern attack vectors.
3 weeks ago
Kill Chain
Microsoft Defender's Own Driver Weaponized for Endpoint Security Bypass
In August 2026, Check Point Research disclosed a technique that weaponizes Microsoft Defender's own legitimately signed boot-time remediation driver (BTR.sys) to perform arbitrary kernel-level file and registry operations on Windows systems. The technique, dubbed 'BTR Reforged,' affects all Windows versions from Windows 7 through Windows 11 25H2 and exploits a built-in driver that cannot be blocked without disrupting Defender itself. Researchers demonstrated live deletion of the entire Defender stack on a fully updated Windows 11 system with Tamper Protection active, requiring only administrator privileges with SeLoadDriverPrivilege. Unlike traditional bring-your-own-vulnerable-driver attacks, this technique uses infrastructure present in every Windows installation, making it particularly concerning for endpoint security bypass scenarios. This discovery highlights the evolving sophistication of endpoint security bypass techniques, where attackers increasingly leverage legitimate system components rather than external vulnerable drivers that can be easily blocklisted by security vendors.
3 weeks ago
Kill Chain
First Android Car Malware Campaign Targets Vehicle Head Units Through Update Compromise
In June 2026, Kaspersky discovered the first documented malware specifically targeting Android-based vehicle head units, marking a significant expansion of cybercriminal operations into automotive systems. The malware, attributed to the MoYu Group behind the BADBOX botnet, infected DoFun-powered head units through compromised legitimate update mechanisms. Attackers weaponized the TWCore system app's MQTT-based update channel to deliver JarService dropper malware, enabling ad fraud and proxy botnet creation. The sophisticated attack chain demonstrates how threat actors are adapting traditional mobile malware techniques for automotive platforms, exploiting SIM-enabled connectivity in modern vehicle infotainment systems. This incident highlights the emerging threat landscape as connected vehicles become mainstream targets, with automotive cybersecurity gaps creating new attack vectors for established cybercriminal groups seeking to monetize vehicle connectivity infrastructure.
3 weeks ago
Kill Chain
RedC2 4.0 Supply Chain Attack: AI-Powered Backdoors Target npm Ecosystem
In August 2026, cybersecurity researchers discovered 14 trojanized npm packages masquerading as functional calendar and streak utilities that secretly deployed RedC2 4.0, an AI-powered Linux backdoor. The malicious packages, including streak-metrics-math and kit-map-vim, delivered the RedShell Linux beacon which establishes command and control communications for surveillance, credential theft, and payload delivery operations. The attack leveraged legitimate-seeming functionality to hide malicious binaries that execute automatically upon module import, requiring no installation hooks or explicit function calls to compromise target systems. This incident highlights the growing sophistication of supply chain attacks, particularly the integration of AI-assisted command and control frameworks that lower the barrier to entry for cybercriminals while increasing operational efficiency through natural language command processing.
3 weeks ago
Kill Chain
Paperclip AI Agent Attack Exposes Critical Gaps in Enterprise AI Security
In July 2026, cybercriminals orchestrated a sophisticated supply chain attack targeting the Paperclip agentic AI platform by registering a typosquatted domain and distributing malicious Python packages alongside weaponized AI skills. While automated scanners detected the compromised Python packages within hours, the malicious AI skills evaded detection and accumulated over 300,000 installations each, successfully compromising user machines and exfiltrating credentials and sensitive data. This incident demonstrates the emerging attack surface created by AI agent ecosystems and the inadequacy of current security controls for detecting malicious skills. This attack highlights the critical need for organizations to secure their AI agent deployments as agentic platforms become mainstream business tools, with skill repositories growing by over 30% in recent months and minimal security oversight.
3 weeks ago
Kill Chain
Medusa Ransomware Escalates Attacks on Critical Infrastructure: 500+ Organizations Compromised
The Medusa ransomware syndicate has systematically compromised over 500 critical infrastructure organizations across the United States since June 2021, targeting healthcare, manufacturing, defense, and financial sectors. Operating under a Ransomware-as-a-Service (RaaS) model, the group experienced massive operational growth in 2023 following the launch of their "Medusa Blog" leak site for double extortion tactics. The syndicate actively recruits initial access brokers on dark web forums, offering payments from $100 to $1 million for exclusive system access, demonstrating the industrialization of ransomware operations. This incident highlights the accelerating threat to critical infrastructure as ransomware groups increasingly target essential services through sophisticated affiliate networks. The dramatic increase from 300 to 500 victims in less than a year underscores the urgent need for enhanced security controls across critical sectors.
3 weeks ago
Kill Chain
Delta Flight 591 Wi-Fi Hack: When DEF CON Tools Turn Into In-Flight Threats
In August 2026, a passenger on Delta Air Lines Flight 591 from Las Vegas to Atlanta compromised the aircraft's in-flight Wi-Fi system following the Black Hat and DEF CON conferences. The attacker disabled the legitimate Wi-Fi service and created a rogue access point named "Delta WiFi Fast" that redirected users to a phishing page designed to harvest credentials. Federal authorities launched an investigation into the incident, with suspicion falling on DEF CON attendees who may have used commercially available Wi-Fi Pineapple devices purchased at the conference. This incident highlights the growing risk of in-flight cybersecurity threats as aviation systems become increasingly connected. The ease with which commercially available penetration testing tools can be weaponized in confined, high-security environments demonstrates critical gaps in aviation cybersecurity protocols and passenger device restrictions during flight operations.
3 weeks ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

