✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 1741 to 1752 of 5134
Critical RCE Vulnerability in Weaver E-cology: CVE-2026-22679
In March 2026, a critical unauthenticated remote code execution (RCE) vulnerability, identified as CVE-2026-22679, was discovered in Weaver (Fanwei) E-cology 10.0 versions prior to 20260312. This flaw resides in the "/papi/esearch/data/devops/dubboApi/debug/method" endpoint, allowing attackers to execute arbitrary commands by exploiting exposed debug functionality without authentication. The vulnerability has a CVSS score of 9.8, indicating its severity. ([thehackernews.com](https://thehackernews.com/2026/05/weaver-e-cology-rce-flaw-cve-2026-22679.html?utm_source=openai)) Active exploitation of this vulnerability was first observed on March 31, 2026, with attackers leveraging it to gain full control over affected systems. The exploitation involves crafting POST requests with malicious parameters to invoke command-execution helpers. Organizations using vulnerable versions are urged to update to version 20260312 or later to mitigate this risk. ([thehackernews.com](https://thehackernews.com/2026/05/weaver-e-cology-rce-flaw-cve-2026-22679.html?utm_source=openai))
3 months ago
Kill Chain
MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks
In April 2026, a critical vulnerability identified as CVE-2026-29014 was discovered in MetInfo CMS versions 7.9, 8.0, and 8.1. This unauthenticated PHP code injection flaw allows remote attackers to execute arbitrary code by sending crafted requests containing malicious PHP code. The vulnerability stems from insufficient input neutralization in the execution path, specifically within the "/app/system/weixin/include/class/weixinreply.class.php" script, leading to potential full control over affected servers. ([thehackernews.com](https://thehackernews.com/2026/05/metinfo-cms-cve-2026-29014-exploited.html?utm_source=openai)) As of May 2026, active exploitation of this vulnerability has been observed, with attackers targeting MetInfo CMS instances, particularly in China and Hong Kong. The ease of exploitation and the critical nature of the flaw underscore the urgency for organizations using affected versions to apply the available patches promptly to mitigate the risk of server compromise. ([thehackernews.com](https://thehackernews.com/2026/05/metinfo-cms-cve-2026-29014-exploited.html?utm_source=openai))
3 months ago
Kill Chain
Persistent OAuth Tokens: The Unseen Backdoor in Enterprise Security
In May 2026, a significant security concern emerged regarding the widespread use of OAuth tokens in enterprise environments. Employees frequently connect AI tools, workflow automations, and productivity applications to platforms like Google and Microsoft, generating persistent OAuth tokens that often lack expiration dates and are not subject to automatic cleanup. This practice creates a substantial security gap, as these tokens can grant attackers unauthorized access without the need for passwords, bypassing traditional security measures such as multi-factor authentication. The inherent design of OAuth, which does not automatically revoke tokens when employees depart or change passwords, exacerbates this vulnerability. The urgency of addressing this issue is underscored by recent incidents where threat actors exploited OAuth tokens to gain unauthorized access to sensitive data. For instance, in August 2025, attackers used compromised OAuth tokens from the Salesloft-Drift integration to access Salesforce environments of over 700 organizations, leading to significant data exfiltration. ([checkred.com](https://checkred.com/resources/blog/when-oauth-tokens-go-rogue-lessons-from-the-salesloft-drift-breach/?utm_source=openai)) These events highlight the critical need for organizations to implement robust monitoring and management of OAuth grants to prevent similar breaches.
3 months ago
Kill Chain
China-Linked UAT-8302 Targets Governments Using Shared APT Malware
Between late 2024 and 2025, the China-nexus advanced persistent threat (APT) group UAT-8302 targeted government entities in South America and southeastern Europe. Post-compromise activities included deploying custom malware families such as NetDraft, CloudSorcerer, and SNOWLIGHT, tools previously associated with other China-aligned threat actors. The group conducted extensive reconnaissance, utilized open-source tools for automated scanning, and established alternative backdoor access using proxy and VPN tools. ([blog.talosintelligence.com](https://blog.talosintelligence.com/uat-8302/?utm_source=openai)) This incident highlights the increasing collaboration among China-aligned APT groups, sharing tools and tactics to enhance their cyber espionage capabilities. The use of shared malware underscores the need for organizations to adopt comprehensive security measures to detect and mitigate such sophisticated threats. ([blog.talosintelligence.com](https://blog.talosintelligence.com/uat-8302/?utm_source=openai))
3 months ago
Kill Chain
DarkSword Malware: A New Threat to iOS Devices
In March 2026, Google's Threat Intelligence Group (GTIG) identified 'DarkSword,' a sophisticated iOS exploit chain targeting devices running iOS versions 18.4 through 18.7. This exploit leverages six vulnerabilities to achieve full device compromise, deploying malware families such as GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER. Initially observed in November 2025, DarkSword has been utilized by multiple threat actors, including state-sponsored groups like UNC6353, to target users in countries such as Saudi Arabia, Turkey, Malaysia, and Ukraine. The exploit is delivered through malicious or compromised websites, enabling attackers to steal sensitive data and execute unauthorized code on affected devices. ([malwarebytes.com](https://www.malwarebytes.com/blog/mobile/2026/03/a-darksword-hangs-over-unpatched-iphones?utm_source=openai)) The widespread adoption of DarkSword by various threat actors underscores a significant shift in the cyber threat landscape, highlighting the increasing accessibility and deployment of advanced mobile exploits. This incident emphasizes the critical importance of timely software updates and robust security practices to mitigate emerging threats. ([labs.cloudsecurityalliance.org](https://labs.cloudsecurityalliance.org/research/csa-research-note-darksword-ios-fullchain-zeroday-multiactor/?utm_source=openai))
3 months ago
Kill Chain
Understanding the 'Copy Fail' Linux Vulnerability (CVE-2026-31431) and Its Implications
In April 2026, Theori disclosed a critical local privilege escalation vulnerability, CVE-2026-31431, dubbed 'Copy Fail,' affecting Linux kernels since 2017. This flaw resides in the 'algif_aead' cryptographic interface, allowing unprivileged users to escalate privileges to root, thereby gaining full system control. Major distributions like Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 10.1, and SUSE 16 are impacted. The vulnerability has been actively exploited in the wild, prompting the Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities catalog. ([tomshardware.com](https://www.tomshardware.com/software/linux/cisa-flags-actively-exploited-copy-fail-linux-kernel-flaw-enabling-root-takeover-across-major-distros-unpatched-systems-may-remain-vulnerable-to-attack?utm_source=openai)) The rapid public disclosure and the availability of a reliable proof-of-concept exploit have heightened concerns, especially in cloud and multi-tenant environments where untrusted code execution is common. Organizations are urged to apply patches promptly and consider temporary mitigations, such as disabling the affected cryptographic modules, to protect against potential exploitation. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/?utm_source=openai))
3 months ago
Kill Chain
CISA Alerts on Active Exploitation of 'Copy Fail' Linux Vulnerability (CVE-2026-31431)
In late April 2026, a critical vulnerability known as 'Copy Fail' (CVE-2026-31431) was disclosed, affecting Linux kernels released since 2017. This flaw resides in the algif_aead cryptographic interface, allowing unprivileged local users to escalate privileges to root by writing controlled bytes to the page cache of any readable file. Theori researchers released a proof-of-concept exploit demonstrating the vulnerability's reliability across major distributions, including Ubuntu, Amazon Linux, RHEL, and SUSE. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, urging immediate patching to mitigate active exploitation risks. The rapid public disclosure and availability of a reliable exploit underscore the urgency for organizations to update their systems promptly. Given the widespread use of affected Linux distributions in enterprise and cloud environments, unpatched systems are at significant risk of compromise, potentially leading to unauthorized access and control over critical infrastructure.
3 months ago
Kill Chain
Critical Authentication Bypass Vulnerability in MOVEit Automation: CVE-2026-4670
In April 2026, Progress Software disclosed a critical authentication bypass vulnerability (CVE-2026-4670) in its MOVEit Automation managed file transfer application. This flaw allows unauthenticated remote attackers to gain unauthorized access to affected systems without user interaction. The vulnerability impacts MOVEit Automation versions prior to 2025.1.5, 2025.0.9, and 2024.1.8. Exploitation could lead to unauthorized access, administrative control, and potential data exposure. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/04/critical-moveit-automation-auth-bypass-vulnerability-fixed-cve-2026-4670/?utm_source=openai)) Given the widespread use of MOVEit Automation in enterprise environments, this vulnerability poses a significant risk. Organizations are urged to upgrade to the latest patched versions immediately to mitigate potential exploitation. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/04/critical-moveit-automation-auth-bypass-vulnerability-fixed-cve-2026-4670/?utm_source=openai))
3 months ago
Kill Chain
PyTorch Lightning Supply Chain Attack: A Wake-Up Call for Developers
In April 2026, versions 2.6.2 and 2.6.3 of the PyTorch Lightning package were compromised and published on the Python Package Index (PyPI). These versions contained malicious code that, upon import, initiated a background process to download and execute an obfuscated JavaScript payload. This payload targeted sensitive information, including environment files, API keys, GitHub tokens, and credentials stored in browsers such as Chrome, Firefox, and Brave. Additionally, it interacted with cloud service APIs (AWS, Azure, GCP) to exfiltrate credentials and had the capability to execute arbitrary system commands. This incident underscores the escalating threat of supply chain attacks in the software development ecosystem. The compromise of widely-used packages like PyTorch Lightning highlights the need for enhanced vigilance and robust security measures in managing software dependencies to prevent unauthorized access and data breaches.
3 months ago
Kill Chain
Fraudsters Exploit Credit Union Verification Processes in 2026
In May 2026, cybersecurity researchers uncovered a sophisticated fraud scheme targeting small to mid-sized credit unions. Threat actors utilized stolen personal data to impersonate legitimate borrowers, navigating through credit checks and identity verification processes without triggering security alerts. This methodical approach exploited perceived weaknesses in the verification systems of smaller financial institutions, leading to unauthorized loan approvals and significant financial losses. This incident underscores a growing trend where cybercriminals focus on process exploitation rather than technical vulnerabilities. The increasing availability of personal data on underground forums, combined with advanced social engineering tactics, poses a heightened risk to financial institutions, especially those with limited fraud prevention resources.
3 months ago
Kill Chain
Weaver E-cology CVE-2026-22679 Exploitation: A Critical Security Alert
In mid-March 2026, attackers began exploiting CVE-2026-22679, a critical unauthenticated remote code execution vulnerability in Weaver E-cology 10.0, an enterprise office automation platform. The flaw resides in an exposed debug API endpoint that allows user-supplied parameters to reach backend Remote Procedure Call (RPC) functionality without authentication or input validation. This enables attackers to execute arbitrary system commands on the server. The attacks commenced five days after the vendor released a security update on March 12, 2026, and two weeks before the vulnerability was publicly disclosed. The exploitation involved multiple phases, including initial reconnaissance through ping commands, attempts to deploy PowerShell-based payloads, and the use of obfuscated, fileless PowerShell scripts to fetch remote scripts. Despite these efforts, the attackers did not establish a persistent session on the targeted hosts.
3 months ago
Kill Chain
Rising Threat: Amazon SES Phishing Abuse in 2026
In May 2026, cybersecurity researchers identified a significant increase in phishing campaigns exploiting Amazon Simple Email Service (SES). Attackers leveraged exposed AWS Identity and Access Management (IAM) access keys, often found in public GitHub repositories, .ENV files, Docker images, and publicly accessible S3 buckets, to send convincing phishing emails that bypass standard security filters. These emails, appearing to originate from trusted sources, included fake document-signing notifications and sophisticated business email compromise (BEC) attacks, leading to unauthorized access and financial losses. This trend underscores the critical need for organizations to implement stringent security measures, such as enforcing least-privilege IAM policies, enabling multi-factor authentication, regularly rotating access keys, and applying IP-based access restrictions. The rise in such attacks highlights the evolving tactics of cybercriminals and the importance of proactive defense strategies to protect sensitive information and maintain trust.
3 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

