✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 1573 to 1584 of 5110
Instructure's 2026 Data Breach: A Wake-Up Call for Educational Cybersecurity
In May 2026, Instructure, the company behind the Canvas learning management system, experienced a significant data breach orchestrated by the ShinyHunters extortion group. The attackers exploited vulnerabilities in the Free-for-Teacher environment, gaining access to over 3.6 terabytes of data, including usernames, email addresses, course names, enrollment information, and private messages from nearly 9,000 educational institutions worldwide. Following the initial breach, ShinyHunters defaced Canvas login portals, demanding a ransom to prevent the public release of the stolen data. Instructure reached an agreement with the attackers, who provided evidence of data destruction and assured that no extortion would occur against Instructure's customers. However, the FBI warns that paying ransoms does not guarantee that stolen data won't be sold or used in future attacks. This incident underscores the critical need for robust cybersecurity measures in educational platforms, especially as cybercriminal groups like ShinyHunters continue to target sensitive data for financial gain. Educational institutions must prioritize securing their digital infrastructures to protect against such threats.
2 months ago
Kill Chain
SAP Releases Critical Security Patches for Commerce Cloud and S/4HANA
In May 2026, SAP released security updates addressing 15 vulnerabilities across multiple products, notably two critical flaws in Commerce Cloud and S/4HANA. CVE-2026-34263 in SAP Commerce Cloud allows unauthenticated attackers to execute arbitrary code due to improper Spring Security configuration. CVE-2026-34260 in SAP S/4HANA enables authenticated attackers to perform SQL injection attacks, potentially granting unauthorized access to sensitive data and causing application crashes. These vulnerabilities significantly impact the confidentiality, integrity, and availability of the affected systems. The disclosure of these critical vulnerabilities underscores the ongoing challenges in securing enterprise software platforms. Organizations relying on SAP products must prioritize timely patching and robust security practices to mitigate risks associated with such flaws.
2 months ago
Kill Chain
Shai-Hulud Supply Chain Attack: A Wake-Up Call for CI/CD Security
In May 2026, the 'Shai-Hulud' supply chain attack, attributed to the TeamPCP threat group, compromised hundreds of npm and PyPI packages, including those from TanStack, Mistral AI, UiPath, and OpenSearch. The attackers exploited valid OpenID Connect (OIDC) tokens to publish malicious package versions with verifiable provenance attestation (SLSA Build Level 3), enabling the distribution of credential-stealing malware targeting developers. This sophisticated attack leveraged vulnerabilities in CI/CD pipelines, including risky 'pull_request-target' workflows, GitHub Actions cache poisoning, and OIDC token theft from runner memory, resulting in the unauthorized publication of 84 malicious versions across 42 TanStack packages. The incident underscores the escalating threat of supply chain attacks and the need for robust security measures in software development pipelines. The use of legitimate CI/CD infrastructure to distribute malware highlights the importance of securing development environments against such sophisticated threats.
2 months ago
Kill Chain
Windows 11 May 2026 Patch Tuesday: Critical Security Updates and Exciting New Features
On May 12, 2026, Microsoft released cumulative updates KB5089549 and KB5087420 for Windows 11 versions 25H2/24H2 and 23H2, respectively. These updates addressed 137 security vulnerabilities, including critical flaws in Secure Boot and Remote Desktop Connection. Additionally, the updates introduced new features such as Xbox Mode and expanded archive format support in File Explorer. ([windowsreport.com](https://windowsreport.com/windows-11-may-2026-patch-tuesday-update-kb5089549-out-now/?utm_source=openai)) The release underscores Microsoft's commitment to enhancing system security and user experience. Organizations are advised to promptly apply these updates to mitigate potential threats and benefit from the latest features.
2 months ago
Kill Chain
Škoda Online Shop Data Breach: A Wake-Up Call for E-Commerce Security
In May 2026, Škoda Auto disclosed a data breach affecting its online shop, where attackers exploited a software vulnerability to gain unauthorized access. The compromised data includes customer names, addresses, email addresses, phone numbers, order details, and login credentials. Notably, financial information remained secure as it was processed by external payment service providers. Upon detection, Škoda promptly addressed the vulnerability, reported the incident to authorities, and initiated a forensic investigation. This incident underscores the critical importance of robust cybersecurity measures in e-commerce platforms. With the increasing frequency of such breaches, organizations must prioritize regular security assessments, timely patching of vulnerabilities, and comprehensive incident response plans to protect customer data and maintain trust.
2 months ago
Kill Chain
Microsoft's May 2026 Patch Tuesday: A Comprehensive Security Update
In May 2026, Microsoft released its Patch Tuesday updates addressing 120 security vulnerabilities, including 17 classified as 'Critical.' Notably, this release marked the first in nearly two years without any zero-day vulnerabilities being disclosed or exploited. The critical flaws encompassed remote code execution and elevation of privilege vulnerabilities across various Microsoft products, including Office, Word, and Excel. The absence of zero-day vulnerabilities in this release is a positive development; however, the high number of critical vulnerabilities underscores the ongoing need for organizations to promptly evaluate and deploy these updates to mitigate potential security risks. ([computerweekly.com](https://www.computerweekly.com/news/366642908/Microsoft-releases-rare-zero-day-free-Patch-Tuesday-update?utm_source=openai))
2 months ago
Kill Chain
Critical RCE Vulnerabilities in Fortinet's FortiSandbox and FortiAuthenticator: Immediate Action Required
In May 2026, Fortinet disclosed critical remote code execution (RCE) vulnerabilities in its FortiSandbox and FortiAuthenticator products. These flaws, identified as CVE-2026-44277 and CVE-2026-26083, could allow unauthenticated attackers to execute arbitrary code or commands on unpatched systems via crafted HTTP requests. FortiAuthenticator versions 6.5.7, 6.6.9, and 8.0.3, and FortiSandbox versions 4.4.9 and above, have been patched to address these issues. Organizations using these products are urged to update immediately to mitigate potential exploitation risks. The disclosure underscores the persistent targeting of Fortinet products by threat actors, often leveraging such vulnerabilities in ransomware and cyber-espionage campaigns. This incident highlights the critical importance of timely patch management and continuous monitoring to defend against evolving cyber threats.
2 months ago
Kill Chain
Signal Phishing Attacks 2026: A Wake-Up Call for Cybersecurity
In early 2026, Russian state-sponsored hackers launched a sophisticated phishing campaign targeting high-profile Signal and WhatsApp users, including government officials, military personnel, and journalists. The attackers impersonated official support accounts, deceiving victims into sharing verification codes or scanning QR codes, thereby granting unauthorized access to their accounts and sensitive communications. This campaign exploited social engineering tactics rather than technical vulnerabilities, highlighting the persistent threat posed by human-centric attack vectors. In response, Signal introduced enhanced in-app security features to combat such phishing and social engineering attempts. These measures include displaying 'Name not verified' warnings for new contacts, prompting users to confirm new requests while reminding them that Signal will never ask for registration codes or PINs, and providing enriched safety tips. These proactive steps aim to bolster user awareness and resilience against evolving social engineering threats.
2 months ago
Kill Chain
Instructure Canvas 2026 Cyberattacks: A Wake-Up Call for Educational Cybersecurity
In April and May 2026, Instructure's Canvas learning management system suffered two significant cyberattacks orchestrated by the ShinyHunters extortion group. The initial breach on April 29 led to the theft of personal information—including names, email addresses, student ID numbers, and user communications—from approximately 275 million individuals across nearly 9,000 educational institutions. Shortly after, on May 7, ShinyHunters executed a second attack, defacing Canvas login portals with ransom messages, disrupting access during critical final exams. Instructure responded by revoking compromised credentials, implementing security patches, and engaging forensic experts to investigate the incidents. ([apnews.com](https://apnews.com/article/3d55b9399ae87d49276f354e1c34c180?utm_source=openai)) These breaches underscore the escalating threats faced by educational institutions, particularly during pivotal academic periods. The incidents highlight the necessity for robust cybersecurity measures, proactive threat detection, and comprehensive incident response plans to safeguard sensitive student and staff data against increasingly sophisticated cybercriminal activities. ([apnews.com](https://apnews.com/article/209a51692f043a959459dbe37fb34e4b?utm_source=openai))
2 months ago
Kill Chain
UK Water Supplier Fined $1.3M for Massive Data Breach
In May 2026, the UK's Information Commissioner's Office (ICO) fined South Staffordshire Water Plc and its parent company £963,900 ($1.3 million) following a cyberattack that exposed the personal data of 663,887 customers and employees. The breach originated in September 2020 through a phishing email, allowing attackers to install malware that remained undetected for 20 months. Between May and July 2022, the attackers escalated privileges, gaining domain administrator access. The breach was discovered in July 2022 after IT performance issues prompted an investigation. The compromised data included full names, addresses, email addresses, phone numbers, dates of birth, customer account credentials, bank account details, and employee HR data such as National Insurance numbers. This incident underscores the critical importance of robust cybersecurity measures, especially in essential service sectors. The prolonged undetected presence of malware highlights the need for continuous monitoring and rapid response capabilities to mitigate potential threats effectively.
2 months ago
Kill Chain
Exim BDAT Vulnerability (CVE-2026-45185) Puts GnuTLS Configurations at Risk of Remote Code Execution
In May 2026, a critical vulnerability identified as CVE-2026-45185, also known as Dead.Letter, was discovered in Exim's Mail Transfer Agent (MTA) software. This use-after-free flaw affects versions 4.97 through 4.99.2 when configured with GnuTLS for TLS connections. The vulnerability is triggered during BDAT message body handling when a client sends a TLS close_notify alert before completing the body transfer, followed by a final byte in cleartext on the same TCP connection. This sequence can lead to heap corruption, potentially allowing remote code execution. The issue was reported by Federico Kirschbaum of XBOW on May 1, 2026, and has been addressed in Exim version 4.99.3. Users are strongly advised to upgrade immediately, as no mitigations are available for this vulnerability. This incident underscores the critical importance of timely software updates and vigilant monitoring of open-source components. The exploitation of such vulnerabilities can lead to severe security breaches, emphasizing the need for robust security practices and proactive vulnerability management in IT infrastructures.
2 months ago
Kill Chain
State of Ransomware in 2026: Emerging Trends and Tactics
In 2025, ransomware attacks evolved significantly, with a notable rise in 'encryption-less' extortion tactics where attackers exfiltrate sensitive data and threaten its release without encrypting files. Additionally, some ransomware groups began adopting post-quantum cryptography to secure their operations against future quantum computing threats. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/international-anti-ransomware-day-2026-kaspersky-shares-insights-into-ransomware-trends-and-tactics?utm_source=openai)) These developments underscore the increasing sophistication of ransomware operations, highlighting the need for organizations to enhance their cybersecurity measures to protect against data breaches and ensure compliance with evolving regulatory standards.
2 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

