✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 181 to 192 of 5033
Russian Espionage Group Exploits Zimbra Zero-Day Vulnerability
In July 2025, the Russian state-sponsored threat group known as Laundry Bear initiated a sophisticated cyber-espionage campaign targeting Western government and commercial organizations. By exploiting a zero-day vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite's webmail client, the attackers deployed a 'view-based exploit' that activated upon merely viewing a malicious email. This allowed them to exfiltrate sensitive data, including recent emails, entire email directories, browser-saved passwords, and two-factor authentication recovery codes. The vulnerability was patched in November 2025, but unpatched systems remain at risk. ([nsa.gov](https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4553352/nsa-and-partners-alert-zimbra-collaboration-suite-users-of-a-russian-state-supp/?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors exploiting zero-day vulnerabilities. The use of 'zero-click' exploits, which require no user interaction beyond viewing an email, highlights the evolving sophistication of cyber threats and the critical need for timely patch management and robust cybersecurity measures. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/russian-hackers-zimbra-zero-day-us-ukraine-targets?utm_source=openai))
1 week ago
Kill Chain
Origin Energy Data Breach: A Wake-Up Call for Critical Infrastructure Security
In July 2026, Origin Energy, Australia's largest energy retailer, confirmed a data breach involving unauthorized access to customer information. The compromised data includes names, addresses, dates of birth, contact numbers, account details, and partial financial information (last four digits of credit cards or last three digits of bank accounts). The company is working to determine the total number of affected customers and has engaged with the Australian Cyber Security Centre, the Australian Federal Police, and the Office of the Australian Information Commissioner to investigate the incident. ([originenergy.com.au](https://www.originenergy.com.au/about/investors-media/update-on-data-security-incident/?utm_source=openai)) This breach underscores the escalating threat of cyberattacks targeting critical infrastructure sectors. The exposure of personal information increases the risk of identity theft and sophisticated phishing scams, particularly with the rise of AI-driven cybercrime. Organizations must enhance their cybersecurity measures to protect sensitive customer data and maintain public trust. ([abc.net.au](https://www.abc.net.au/news/2026-07-24/origin-breach-could-fuel-wave-of-ai-powered-scams/106951588?utm_source=openai))
1 week ago
Kill Chain
TAG-195's Modular Malware: A New Era in Cyber Threats
In July 2026, Insikt Group identified four new malware families—TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and ChromEggscalator—developed by TAG-195, also known as "Golden Chickens" or "Venom Spider." These developments signify a strategic shift towards modular, operator-driven tools within the TAG-195 malware-as-a-service (MaaS) ecosystem. The modularized ChonkyChicken variant employs a controller-and-plugin architecture, allowing the base implant to dynamically load specific capability modules from attacker-controlled infrastructure, thereby reducing its static detection footprint. All four malware families exhibit consistent command-and-control mechanisms, shared persistence methods, string obfuscation, and execution via legitimate Windows binaries. This evolution underscores TAG-195's commitment to enhancing the adaptability and stealth of its offerings, catering to a diverse range of operational requirements. The emergence of these advanced, modular malware families highlights the ongoing sophistication of MaaS providers and the necessity for organizations to bolster their detection and response strategies against such evolving threats.
1 week ago
Kill Chain
LummaStealer's 2026 Resurgence: The Role of CastleLoader and ClickFix Techniques
Between December 2025 and January 2026, cybersecurity researchers observed a significant resurgence of LummaStealer infections, facilitated by the deployment of CastleLoader malware through sophisticated ClickFix social engineering techniques. Attackers lured victims to malicious websites mimicking legitimate services, where fake CAPTCHA verifications tricked users into executing malicious PowerShell commands. These commands installed CastleLoader, which subsequently delivered LummaStealer, an infostealer targeting sensitive data such as credentials, cryptocurrency wallets, and session cookies. This campaign marked a notable evolution in malware delivery methods, combining advanced loaders with deceptive social engineering tactics to bypass traditional security measures. The resurgence of LummaStealer, despite previous law enforcement disruptions, underscores the adaptability and persistence of cybercriminals. The use of CastleLoader and ClickFix techniques highlights a trend towards more sophisticated and deceptive attack vectors, emphasizing the need for continuous vigilance and advanced security protocols to protect sensitive information.
1 week ago
Kill Chain
Fake Bahrain Alert App Exploits Crisis to Deploy Android Spyware
In July 2026, a malicious Android application named "BH Alert" emerged, masquerading as Bahrain's official civil-defense emergency alert app. Distributed through counterfeit Google Play Store and Bahraini government websites, the app exploited heightened public concern during Iranian missile strikes. Once installed, it deployed a sophisticated four-stage surveillance platform capable of harvesting lockscreen credentials, SMS messages, contacts, and screenshots, running banking-app overlays, and granting attackers full remote control over the device. This campaign underscores the increasing trend of threat actors leveraging trusted government applications during crises to disseminate advanced spyware. Organizations should be vigilant about such tactics, as similar methods have been observed in previous incidents, including a Trojanized version of Israel's "Red Alert" app distributed via phishing campaigns earlier this year.
1 week ago
Kill Chain
SANDWORM_MODE: Unveiling the npm Supply Chain Attack on AI Development Tools
In February 2026, the SANDWORM_MODE malware campaign targeted the npm ecosystem by distributing 19 typosquatted packages under aliases 'official334' and 'javaorg'. Upon installation, these packages executed a multi-stage attack: initially harvesting developer credentials and environment variables, followed by deploying a malicious MCP server to compromise AI coding assistants. The malware propagated by injecting itself into GitHub repositories and CI/CD pipelines, exfiltrating sensitive data, and, if thwarted, activating a destructive fallback to erase user files. ([crowdstrike.com](https://www.crowdstrike.com/en-us/blog/denying-the-worm-sandworm-mode-and-ai-toolchain-supply-chain-attacks/?utm_source=openai)) This incident underscores the escalating sophistication of supply chain attacks, particularly those exploiting AI development tools. Organizations must enhance their security measures to detect and prevent such multi-faceted threats that blend into legitimate development workflows.
1 week ago
Kill Chain
Critical Flaws in Microsoft's Passkey Implementation Uncovered
In July 2026, security researchers identified critical vulnerabilities in Microsoft's passkey implementation within Windows 11 and Microsoft Entra ID. These flaws allowed attackers to exploit weaknesses reminiscent of traditional password attacks, enabling them to impersonate privileged users and bypass phishing-resistant multifactor authentication. The vulnerabilities were disclosed to Microsoft, which subsequently released patches to address the issues. This incident underscores the importance of thorough implementation and validation of security protocols, even when adopting advanced authentication methods like passkeys. Organizations must remain vigilant, ensuring that new technologies are deployed securely to prevent exploitation by threat actors.
1 week ago
Kill Chain
Lampion Banking Trojan Resurfaces in Portugal: A 2026 Threat Analysis
In July 2026, the Brazilian banking Trojan known as Lampion was identified in an active campaign targeting Portuguese users. The malware is disseminated through phishing emails that masquerade as financial and administrative communications, leading recipients to download malicious ZIP files. Once executed, Lampion establishes persistence, connects to a remote command-and-control server, and can inject overlays into banking websites to steal credentials. This campaign has resulted in significant data breaches and financial losses for affected individuals and organizations. The resurgence of Lampion underscores the persistent threat posed by banking Trojans, especially those leveraging social engineering tactics. Organizations must remain vigilant, as attackers continue to exploit language and cultural similarities to enhance the effectiveness of their campaigns.
1 week ago
Kill Chain
Nichirei Cyberattack: A Wake-Up Call for Supply Chain Security
In July 2026, Nichirei Corporation, a leading Japanese frozen food and logistics company, experienced a significant cyberattack attributed to the RansomHouse group. The attack disrupted operations across approximately 140 distribution centers, affecting major clients like Kentucky Fried Chicken Japan, which faced ingredient shortages and operational challenges. The breach led to system failures, particularly in refrigerated warehouse and frozen food shipping services, causing widespread supply chain disruptions. Nichirei collaborated with external cybersecurity firms and authorities to investigate and mitigate the incident, aiming to fully resume operations by the end of the week. This incident underscores the escalating threat of ransomware attacks targeting critical supply chains, highlighting the need for robust cybersecurity measures and incident response strategies. Organizations must prioritize securing their digital infrastructures to prevent similar disruptions and protect sensitive data from malicious actors.
1 week ago
Kill Chain
RefluXFS (CVE-2026-64600): Critical Linux Kernel XFS Vulnerability
On July 22, 2026, a critical vulnerability known as RefluXFS (CVE-2026-64600) was disclosed, affecting the Linux kernel's XFS filesystem. This flaw allows unprivileged local users to overwrite root-owned files, such as `/etc/passwd` or setuid-root binaries, by exploiting a race condition in the copy-on-write (CoW) mechanism. The exploit enables attackers to gain persistent root access without leaving traces in kernel logs, and the changes persist across reboots. Systems running Linux kernel version 4.11 or later with XFS filesystems created with `reflink=1` are vulnerable. Default installations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux are particularly at risk. ([blog.qualys.com](https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600?utm_source=openai)) The RefluXFS vulnerability underscores the importance of timely patch management and system monitoring. With over 16.4 million systems potentially affected, organizations must prioritize updating their Linux distributions and implementing security measures to prevent unauthorized access and potential data breaches. ([secnews.gr](https://www.secnews.gr/en/723207/refluxfs-cve-2026-64600-linux-xfs-16m-systems/?utm_source=openai))
1 week ago
Kill Chain
Critical Authentication Bypass in Check Point SmartConsole (CVE-2026-16232) Exploited
In July 2026, Check Point identified a critical authentication bypass vulnerability (CVE-2026-16232) in its SmartConsole login process, allowing unauthenticated remote attackers to gain full administrative privileges. Exploitation requires internet access to the Management Server IP address and a configuration without Trusted Clients restrictions. Successful attacks enable modification of security policies and configurations. Check Point confirmed active exploitation affecting a limited number of customers. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-16232?utm_source=openai)) This incident underscores the escalating risks associated with exposed management interfaces and the necessity for stringent access controls. Organizations must prioritize timely patching and restrict management access to trusted IP addresses to mitigate such vulnerabilities.
1 week ago
Kill Chain
GitHub Actions Exploited in Large-Scale cPanel and WHM Server Attacks
In July 2026, a large-scale cyberattack exploited compromised GitHub repositories to target cPanel and WebHost Manager (WHM) servers. Attackers inserted malicious GitHub Actions workflows into repositories associated with a legitimate PHP developer, leading to the deployment of GitHub-hosted runners that scanned for vulnerable cPanel and WHM instances susceptible to CVE-2026-41940, an authentication bypass vulnerability. Upon successful exploitation, the attackers harvested sensitive data, including credentials and configuration files, from the compromised servers. This incident underscores the evolving nature of supply chain attacks, where trusted development tools and platforms are weaponized to facilitate widespread exploitation. Organizations must remain vigilant and implement robust security measures to protect against such sophisticated threats.
1 week ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

