✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 1657 to 1668 of 5129
Karakurt Ransomware Negotiator Sentenced to 102 Months in Prison
In May 2026, Latvian national Deniss Zolotarjovs was sentenced to 102 months in U.S. federal prison for his role as a negotiator in the Karakurt ransomware group. Operating between June 2021 and August 2023, Zolotarjovs was instrumental in extorting over 54 companies, leading to more than $56 million in losses. He employed aggressive tactics, including leveraging sensitive data such as children's health records, to pressure victims into paying ransoms. This sentencing marks a significant milestone in the fight against international cybercrime, highlighting the global reach of law enforcement agencies in apprehending and prosecuting cybercriminals. The case underscores the persistent threat posed by ransomware groups and the importance of robust cybersecurity measures to protect sensitive information.
2 months ago
Kill Chain
PCPJack Malware: A New Threat to Cloud Security
In May 2026, cybersecurity researchers identified a sophisticated malware named PCPJack, designed to infiltrate cloud environments by exploiting exposed services and harvesting sensitive credentials. The malware initiates its attack through a 'bootstrap' module that establishes persistence and downloads additional components. It then employs a 'monitor' script to collect system metrics and exfiltrate configuration files, cloud service credentials, and cryptocurrency wallets. Notably, PCPJack targets services such as AWS, GitHub, Slack, and popular email platforms, posing significant risks to organizations' cloud infrastructures. PCPJack's unique approach includes utilizing parquet files from Common Crawl for stealthy, pre-validated target discovery, allowing it to efficiently identify and exploit vulnerable cloud services. This method underscores the evolving tactics of threat actors in leveraging open-source data for malicious purposes. The incident highlights the critical need for organizations to implement robust cloud security measures, including the use of credential vaults and multifactor authentication, to safeguard against such advanced threats.
3 months ago
Kill Chain
Critical 'Dirty Frag' Vulnerability in Linux Kernel Grants Root Access
A critical local privilege escalation (LPE) vulnerability, dubbed 'Dirty Frag,' has been identified in the Linux kernel, affecting major distributions such as Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 10.1, and SUSE 16. This flaw allows unprivileged local users to gain root access by exploiting a logic error in the kernel's cryptographic module. The vulnerability has been actively exploited in the wild, with a publicly available proof-of-concept demonstrating its reliability across affected systems. Immediate patching is essential to mitigate the risk of unauthorized system control. The disclosure of 'Dirty Frag' underscores the persistent challenges in securing widely used open-source software. Organizations must prioritize timely updates and consider implementing additional security measures, such as disabling vulnerable modules or restricting access, to protect against potential exploits targeting this and similar vulnerabilities.
3 months ago
Kill Chain
PamDOORa: A New Threat to Linux Authentication Security
In May 2026, cybersecurity researchers uncovered a new Linux backdoor named PamDOORa, advertised on the Rehub Russian cybercrime forum for $1,600 by a threat actor known as "darkworm." PamDOORa is a Pluggable Authentication Module (PAM)-based post-exploitation toolkit that enables persistent SSH access through a magic password and specific TCP port combination. Additionally, it can harvest credentials from all legitimate users who authenticate through the compromised system. The backdoor also incorporates anti-forensic capabilities to tamper with authentication logs, effectively erasing traces of malicious activity. The emergence of PamDOORa highlights a growing trend of sophisticated Linux-based malware targeting authentication mechanisms to establish persistent access and exfiltrate sensitive credentials. This development underscores the need for organizations to implement robust monitoring and auditing of authentication processes to detect and mitigate such threats.
3 months ago
Kill Chain
Critical Vulnerability in MAXHUB Pivot Client Application: CVE-2025-53704
In December 2025, a critical vulnerability (CVE-2025-53704) was identified in the MAXHUB Pivot client application versions prior to v1.36.2. This flaw involved a weak password recovery mechanism, allowing remote attackers to request password resets and gain unauthorized access to user accounts without prior authentication. The vulnerability posed significant risks, including potential data breaches and unauthorized control over affected systems. The incident underscores the importance of robust authentication mechanisms and timely software updates. Organizations are advised to upgrade to version 1.36.2 or newer to mitigate this risk. This case highlights the ongoing need for vigilance against authentication vulnerabilities in widely used applications.
3 months ago
Kill Chain
Quasar Linux RAT: A New Threat to Developer Environments
In May 2026, security researchers uncovered Quasar Linux RAT (QLNX), a sophisticated Linux-based remote access trojan targeting developer systems. QLNX operates stealthily, executing filelessly from memory and employing multiple persistence mechanisms, including systemd, crontab, and .bashrc shell injection. It masquerades as kernel threads to evade detection and utilizes both userland and kernel-level rootkits to conceal its presence. The malware's primary objective is to harvest credentials from high-value files such as .npmrc, .pypirc, .git-credentials, and cloud service configurations, enabling attackers to infiltrate software supply chains and cloud infrastructures. ([roguevault.news](https://www.roguevault.news/quasar-linux-rat-supply-chain-threat/?utm_source=openai)) The emergence of QLNX underscores a growing trend of targeted attacks on developer environments, aiming to exploit the trust within software supply chains. This incident highlights the critical need for enhanced security measures in development pipelines, as the compromise of a single developer's credentials can lead to widespread distribution of malicious code, affecting numerous downstream users and systems. ([socprime.com](https://socprime.com/active-threats/qlnx-linux-rat-uses-rootkit-and-pam-backdoor/?utm_source=openai))
3 months ago
Kill Chain
CISA Adds CVE-2026-6973 to Known Exploited Vulnerabilities Catalog
On May 7, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-6973 to its Known Exploited Vulnerabilities (KEV) catalog. This high-severity vulnerability affects Ivanti Endpoint Manager Mobile (EPMM) versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1, allowing authenticated users with administrative privileges to execute arbitrary code remotely. Ivanti has released patches to address this issue and urges organizations to update their systems promptly. ([redpacketsecurity.com](https://www.redpacketsecurity.com/cve-alert-cve-2026-6973-ivanti-endpoint-manager-mobile/?utm_source=openai)) The inclusion of CVE-2026-6973 in the KEV catalog underscores the ongoing threat posed by vulnerabilities in widely used enterprise management tools. Organizations are advised to prioritize the remediation of such vulnerabilities to mitigate potential risks to their networks and data. ([cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=openai))
3 months ago
Kill Chain
Critical RCE Vulnerabilities in Microsoft's Semantic Kernel SDK
In May 2026, Microsoft disclosed critical vulnerabilities in its Semantic Kernel SDK, specifically CVE-2026-26030 and CVE-2026-25592. These flaws allowed remote code execution and arbitrary file writes through AI agent frameworks, posing significant security risks. Attackers could exploit these vulnerabilities to execute unauthorized code and manipulate file systems, potentially leading to full system compromise. The vulnerabilities were promptly addressed in subsequent updates, with Microsoft releasing patches to mitigate the risks. Organizations utilizing the Semantic Kernel SDK were urged to update to the latest versions to protect their systems from potential exploitation. This incident underscores the evolving threat landscape in AI and machine learning applications, highlighting the need for continuous vigilance and proactive security measures in the development and deployment of AI agents. As AI technologies become more integrated into critical systems, ensuring their security is paramount to prevent potential breaches and maintain trust in these advanced solutions.
3 months ago
Kill Chain
Dirty Frag: Unpatched Linux Vulnerability Grants Root Access
On May 7, 2026, a critical Linux kernel vulnerability known as 'Dirty Frag' was publicly disclosed. This flaw allows unprivileged local users to escalate their privileges to root across major Linux distributions, including Ubuntu, RHEL, Fedora, and others. Discovered by security researcher Hyunwoo Kim, Dirty Frag exploits two distinct vulnerabilities within the IPsec ESP and RxRPC modules, enabling attackers to modify read-only files in the page cache, leading to full system compromise. The premature disclosure occurred before patches were available, leaving systems vulnerable without immediate remediation options. The urgency of addressing Dirty Frag is heightened by its similarity to the recently disclosed 'Copy Fail' vulnerability (CVE-2026-31431), which also facilitates local privilege escalation. The public availability of exploit code for both vulnerabilities increases the risk of widespread exploitation. Organizations must prioritize mitigating these vulnerabilities to prevent potential system compromises and data breaches.
3 months ago
Kill Chain
CallPhantom Scam: Deceptive Android Apps Exploit User Curiosity
In November 2025, ESET researchers identified a series of fraudulent Android applications, collectively named 'CallPhantom,' on the Google Play Store. These 28 apps falsely claimed to provide access to call logs, SMS records, and WhatsApp call histories for any phone number. Users were prompted to pay for these services but received only randomly generated, fabricated data. The apps amassed over 7.3 million downloads before being reported to Google and subsequently removed from the store. This incident underscores the persistent threat of deceptive applications exploiting user curiosity and trust. The CallPhantom scam highlights the need for continuous vigilance against fraudulent apps, especially as cybercriminals increasingly target mobile platforms. Users should be cautious of apps requesting payments for services that seem too good to be true and verify the legitimacy of applications before installation.
3 months ago
Kill Chain
Understanding the Impact of Recent SSRF Vulnerabilities in MCP Servers
In early 2026, critical vulnerabilities were discovered in MCP servers, notably in Atlassian's mcp-atlassian and Microsoft's MarkItDown. These vulnerabilities, including CVE-2026-27826, allowed unauthenticated attackers to exploit Server-Side Request Forgery (SSRF) flaws, potentially leading to remote code execution and unauthorized access to internal resources. The mcp-atlassian vulnerability stemmed from unvalidated custom HTTP headers, while MarkItDown's flaw involved improper URL validation, enabling access to cloud metadata services. ([pluto.security](https://pluto.security/blog/mcpwnfluence-cve-2026-27825-critical/?utm_source=openai)) These incidents underscore the persistent threat posed by SSRF vulnerabilities in widely used platforms. As organizations increasingly integrate MCP servers into their infrastructure, ensuring robust input validation and implementing strict access controls are imperative to prevent similar exploits and safeguard sensitive data.
3 months ago
Kill Chain
Critical Ivanti EPMM Zero-Day CVE-2026-6973 Exploited in the Wild
In May 2026, Ivanti disclosed a critical zero-day vulnerability, CVE-2026-6973, in its Endpoint Manager Mobile (EPMM) software. This flaw allows authenticated users with administrative privileges to execute remote code, potentially compromising the entire mobile device management infrastructure. The vulnerability has been actively exploited in the wild, with Ivanti confirming limited instances of exploitation. To mitigate this risk, Ivanti released patches for EPMM versions 12.6.1.1, 12.7.0.1, and 12.8.0.1, urging all on-premises EPMM customers to apply these updates immediately. ([thehackernews.com](https://thehackernews.com/2026/05/ivanti-epmm-cve-2026-6973-rce-under.html?utm_source=openai)) This incident underscores the persistent targeting of mobile device management systems by threat actors, highlighting the critical need for organizations to maintain up-to-date security measures and promptly apply vendor-released patches to protect sensitive data and infrastructure.
3 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

