✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 1201 to 1212 of 5077
Critical Authentication Bypass Vulnerability in Palo Alto Networks PAN-OS (CVE-2026-0257)
In May 2026, Palo Alto Networks disclosed CVE-2026-0257, an authentication bypass vulnerability in its PAN-OS software's GlobalProtect portal and gateway. Initially rated medium severity, the flaw allows remote attackers to forge authentication cookies and establish unauthorized VPN connections. Rapid7 observed active exploitation starting May 17, leading to a reassessment of the vulnerability as critical. The Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities catalog on May 29. ([cyberscoop.com](https://cyberscoop.com/palo-alto-networks-cve-2026-0257-exploited-vulnerability/?utm_source=openai)) This incident underscores the rapid escalation of seemingly moderate vulnerabilities into critical threats, emphasizing the need for organizations to promptly apply patches and follow mitigation strategies to protect their networks from unauthorized access. ([cyberscoop.com](https://cyberscoop.com/palo-alto-networks-cve-2026-0257-exploited-vulnerability/?utm_source=openai))
2 months ago
Kill Chain
Anthropic's Project Glasswing Expands to Strengthen Global Cybersecurity
In April 2026, Anthropic launched Project Glasswing, granting approximately 50 organizations access to its advanced AI model, Claude Mythos Preview, to identify software vulnerabilities. By June 2026, the initiative expanded to include around 150 additional organizations across 15 countries, focusing on critical infrastructure sectors such as power, water, healthcare, communications, and hardware. The model has uncovered over 10,000 high- or critical-severity vulnerabilities, with partners like Cloudflare and Mozilla reporting significant increases in bug discovery rates. The rapid identification of vulnerabilities has shifted the cybersecurity landscape, highlighting challenges in verifying, disclosing, and patching flaws before exploitation. A joint report from the Cloud Security Alliance, the SANS Institute, and OWASP warns that organizations may be overwhelmed by threat actors using AI to exploit vulnerabilities faster than defenders can address them.
2 months ago
Kill Chain
Urgent Alert: Active Exploitation of Critical Windows Netlogon Vulnerability (CVE-2026-41089)
In May 2026, Microsoft disclosed CVE-2026-41089, a critical stack-based buffer overflow vulnerability in the Windows Netlogon service, affecting all supported Windows Server versions, including Windows Server 2025. This flaw allows unauthenticated attackers to execute arbitrary code on domain controllers by sending specially crafted network requests. The Centre for Cybersecurity Belgium (CCB) reported active exploitation of this vulnerability in June 2026, emphasizing the urgency for organizations to apply the available security patches promptly. The exploitation of CVE-2026-41089 underscores a growing trend of attackers rapidly leveraging newly disclosed vulnerabilities to compromise critical infrastructure. This incident highlights the necessity for organizations to maintain vigilant patch management practices and to implement robust monitoring systems to detect and respond to such threats swiftly.
2 months ago
Kill Chain
WordPress Malware Campaign Exploits Steam Profiles - 2026
In July 2025, a sophisticated malware campaign was discovered targeting nearly 2,000 WordPress websites. Attackers exploited vulnerabilities to inject malicious code that fetched encoded payloads from comments on Steam Community profiles. These payloads, concealed using invisible Unicode characters, directed the compromised sites to load external JavaScript from malicious domains, ultimately installing backdoors for remote code execution. The campaign's reliance on Steam's platform allowed it to evade traditional detection methods by blending malicious traffic with legitimate communications. This incident underscores the evolving tactics of cybercriminals who leverage trusted platforms to obfuscate their command-and-control infrastructure. The use of invisible Unicode characters for payload encoding highlights the need for advanced detection mechanisms capable of identifying such covert techniques. Organizations must remain vigilant and implement robust security measures to protect against these sophisticated threats.
2 months ago
Kill Chain
Dashlane Users Experience Account Suspensions Amid Brute-Force Attack Attempts
In late May 2026, Dashlane, a prominent password management service, detected a series of brute-force attacks targeting user accounts. These attacks involved repeated login attempts from unfamiliar locations and devices, prompting Dashlane's automated security protocols to temporarily suspend the affected accounts to prevent unauthorized access. The company confirmed that its internal systems remained uncompromised and that the suspensions were precautionary measures to safeguard user data. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/dashlane-password-manager-users-locked-out-by-brute-force-attacks/?utm_source=openai)) This incident underscores the persistent threat of brute-force attacks in the cybersecurity landscape. It highlights the importance of robust security measures, such as multi-factor authentication and vigilant monitoring, to protect user accounts from unauthorized access attempts.
2 months ago
Kill Chain
Spain Arrests Minor for Leaking Sensitive Government Data
In May 2026, Spanish authorities arrested a minor in Granada for leaking sensitive personal data of members from critical state institutions, including the National Cybersecurity Institute (INCIBE), the State Attorney General's Office, the National Police, the Civil Guard, and the National Security Council. The individual disseminated this information online, posing significant national security risks. The arrest followed an urgent investigation initiated after the mass dissemination of this data was detected, leading to a search of the suspect's residence and the seizure of electronic devices for forensic analysis. This incident underscores the growing threat of doxing, where personal information is maliciously published online, targeting government officials and institutions. The case highlights the need for robust cybersecurity measures and the importance of protecting sensitive data to prevent potential threats to national security.
2 months ago
Kill Chain
Red Hat npm Packages Compromised in 2026 Supply Chain Attack
In June 2026, Red Hat's '@redhat-cloud-services' npm namespace was compromised, leading to the distribution of over 30 backdoored packages containing the 'Miasma' malware. This supply chain attack targeted developer credentials, cloud secrets, SSH keys, and CI/CD tokens. The attackers allegedly gained access through a compromised Red Hat employee's GitHub account, injecting malicious code into multiple repositories. Red Hat promptly removed the affected packages and reported no impact on customer or partner environments. This incident underscores the escalating threat of supply chain attacks in the software development ecosystem. The use of sophisticated malware like 'Miasma' highlights the need for enhanced security measures in CI/CD pipelines and vigilant monitoring of open-source dependencies to prevent unauthorized access and data breaches.
2 months ago
Kill Chain
DriveSurge's Massive Exploitation of Websites via ClickFix and FakeUpdates
In June 2026, the threat actor known as DriveSurge orchestrated large-scale malware distribution campaigns by compromising thousands of legitimate websites. Utilizing techniques such as ClickFix and FakeUpdates, DriveSurge redirected unsuspecting visitors to malicious infrastructure. ClickFix deceives users into executing harmful commands under the guise of resolving technical issues, while FakeUpdates presents fraudulent software update prompts to deliver malware payloads. These attacks were facilitated through the use of zTDS, an open-source Traffic Distribution System, enabling DriveSurge to profile victims and select the most effective lure. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hackers-hijack-thousands-of-sites-for-clickfix-and-fakeupdate-attacks/?utm_source=openai)) This incident underscores the evolving sophistication of social engineering tactics employed by cybercriminals. The widespread nature of the campaign highlights the critical need for organizations to implement robust security measures, including regular website audits and user education, to mitigate the risks associated with such deceptive attacks.
2 months ago
Kill Chain
Miasma Attack: Red Hat npm Packages Compromised in June 2026
In June 2026, a sophisticated supply chain attack, dubbed 'Miasma,' compromised over 30 npm packages under the @redhat-cloud-services scope. The attackers infiltrated Red Hat's GitHub Actions OIDC pipeline, injecting a credential-stealing worm into these packages. Upon installation, the malware executed a preinstall script that harvested sensitive information, including GitHub Actions secrets, npm tokens, cloud credentials, Kubernetes tokens, SSH keys, and Git credentials. The stolen data was exfiltrated to attacker-controlled servers, facilitating further propagation of the malware. This incident underscores the escalating threat of supply chain attacks targeting trusted software repositories. The open-sourcing of the Mini Shai-Hulud malware by the cybercriminal group TeamPCP has lowered the barrier for such attacks, enabling a broader range of threat actors to execute similar campaigns. Organizations must enhance their security measures to protect against these evolving threats.
2 months ago
Kill Chain
Investigating Suspicious AI Workflows in Microsoft Entra Agent ID
In May 2026, a security incident was identified involving a Microsoft Entra Agent ID user account named MrRoboto4@ContosoCorp.onmicrosoft.com. This agent user sent a suspicious Teams message containing a potentially malicious link to https://domoarigato.ai/. The message was reported by a human user, prompting an investigation. Analysis revealed that the agent user had been granted extensive permissions, allowing it to perform actions typically reserved for human users, such as sending messages and emails. The agent's activities were executed via the Graph API from an external IP address, highlighting potential security gaps in monitoring and controlling AI-driven workflows within enterprise environments. This incident underscores the growing security challenges posed by AI agents operating autonomously within organizational systems. As enterprises increasingly integrate AI agents to automate tasks, ensuring proper identity management, access controls, and monitoring mechanisms for these non-human entities becomes critical to prevent unauthorized actions and potential breaches.
2 months ago
Kill Chain
Carnival Corporation's 2026 Data Breach: A ShinyHunters Operation
In April 2026, Carnival Corporation, the world's largest cruise operator, experienced a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers employed social engineering tactics to deceive an employee, gaining unauthorized access to the company's IT systems. This intrusion led to the exfiltration of personal data belonging to nearly 6 million individuals, including names, birthdates, genders, and loyalty program details. The breach was publicly disclosed on May 27, 2026, over a month after the initial compromise. ([prnewswire.com](https://www.prnewswire.com/news-releases/carnival-corporation-notice-of-data-breach-302783524.html?utm_source=openai)) This incident underscores the persistent threat posed by sophisticated cybercriminal groups like ShinyHunters, who have been linked to multiple high-profile data breaches in 2026. The delay in disclosure highlights the challenges organizations face in promptly notifying affected individuals, emphasizing the need for robust cybersecurity measures and transparent communication strategies.
2 months ago
Kill Chain
ShinyHunters' 2026 Data Breaches: A Wake-Up Call for Cybersecurity
In May 2026, the cybercriminal group ShinyHunters executed a series of data breaches targeting multiple organizations, including DentaQuest, a prominent dental benefits administrator in the United States. The attackers employed sophisticated social engineering techniques, such as voice phishing, to compromise employee credentials and gain unauthorized access to sensitive systems. This led to the exfiltration of substantial volumes of personal and proprietary data, which ShinyHunters subsequently threatened to release unless ransom demands were met. The breaches have raised significant concerns regarding data security practices and the effectiveness of current defensive measures against such targeted attacks. The recent surge in ShinyHunters' activities underscores a troubling trend in cybercrime, where threat actors increasingly leverage social engineering to bypass technical defenses. Organizations across various sectors are now facing heightened risks of data breaches, emphasizing the urgent need for enhanced security protocols, employee training, and robust incident response strategies to mitigate the impact of such sophisticated cyber threats.
2 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

