✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 373 to 384 of 5035
U.S. Treasury Sanctions 1VPNS for Facilitating Ransomware Attacks
In July 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) sanctioned First VPN Service (1VPNS) and its administrator, Ukrainian national Dmytro Rashevskyi, for providing services to ransomware operators. 1VPNS, operational since 2014, advertised its refusal to cooperate with law enforcement and offered anonymity services that were exploited by cybercriminals to conceal attack origins, deploy malware, and manage exfiltrated data. Victims included U.S. businesses, financial services companies, hospitals, and municipal governments. Additionally, Belarusian national Yegeniy Vladimirovich Silayev was sanctioned for selling 'cryptors'—tools designed to disguise ransomware and other malware as harmless files—to ransomware operators. These actions underscore the critical role that infrastructure providers play in facilitating cybercriminal activities and the necessity of targeting such enablers to disrupt the ransomware ecosystem. The sanctions highlight the ongoing efforts by international law enforcement to dismantle networks that support ransomware operations, emphasizing the importance of vigilance and proactive measures in cybersecurity.
2 weeks ago
Kill Chain
US Sanctions 1VPNS and Affiliates for Enabling Ransomware Attacks
In July 2026, the U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and Belarusian national Yegeniy Vladimirovich Silayev for facilitating ransomware attacks against U.S. organizations. 1VPNS provided anonymizing services to cybercriminals, while Silayev sold cryptors that helped malware evade detection. These services enabled ransomware groups to conduct attacks resulting in billions of dollars in losses to U.S. businesses and critical infrastructure. The sanctions followed a May 2026 law enforcement operation that dismantled 1VPNS's infrastructure and arrested Rashevskyi. This incident underscores the critical role that service providers play in the cybercriminal ecosystem. By targeting these enablers, authorities aim to disrupt the infrastructure supporting ransomware operations. Organizations should be aware of the evolving threat landscape and the importance of securing their networks against such indirect threats.
2 weeks ago
Kill Chain
SAP's July 2026 Security Updates: Addressing Critical Vulnerabilities in NetWeaver and Commerce Cloud
In July 2026, SAP released security updates addressing 16 vulnerabilities across multiple products, including three critical flaws in NetWeaver, Commerce Cloud, and Approuter. The most severe, CVE-2026-44747, is a memory corruption issue in NetWeaver Application Server ABAP, potentially leading to unauthorized data access and system unavailability. CVE-2026-27690, an HTTP request smuggling vulnerability in SAP Approuter, could allow unauthenticated attackers to access user responses and trigger denial-of-service attacks. CVE-2026-44761 in SAP Commerce Cloud involves default credentials that enable attackers to obtain valid access tokens and manipulate data via certain APIs. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/sap-warns-of-critical-flaws-in-netweaver-and-commerce-cloud/?utm_source=openai)) These vulnerabilities underscore the critical need for organizations to promptly apply security patches to prevent potential exploitation. The increasing complexity and integration of enterprise software systems make timely updates essential to maintain system integrity and protect sensitive data.
2 weeks ago
Kill Chain
Nightmare-Eclipse: A Deep Dive into the 2026 Windows Zero-Day Exploits
Between April and June 2026, a security researcher known as 'Nightmare-Eclipse' publicly disclosed eight zero-day vulnerabilities targeting core Windows components, including Microsoft Defender and BitLocker. These exploits, such as BlueHammer, RedSun, and UnDefend, allowed attackers to escalate privileges to SYSTEM level and disable security features. Microsoft addressed some of these vulnerabilities through patches released in April and June 2026, but others remained unpatched for extended periods, leading to active exploitation in the wild. The disclosures were timed immediately after Patch Tuesday releases, leaving systems vulnerable for weeks. This incident underscores the critical need for organizations to implement robust vulnerability management and rapid patching processes to mitigate the risks associated with zero-day exploits. The rapid disclosure and exploitation of these vulnerabilities highlight the evolving threat landscape and the importance of proactive security measures.
2 weeks ago
Kill Chain
Emerging Phishing Kits Bypass MFA to Compromise Microsoft 365 Accounts
In July 2026, cybersecurity researchers identified two sophisticated phishing kits, Jalisco and OmegaLord, targeting Microsoft 365 accounts. Jalisco employs device-code phishing by generating real-time OAuth device codes, tricking users into authorizing attacker-controlled devices. OmegaLord masquerades as a PDF reader to harvest login credentials and phone numbers, potentially intercepting MFA codes. Both methods effectively bypass multi-factor authentication, granting attackers unauthorized access to sensitive data stored in services like SharePoint and other SaaS platforms. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-phishing-kits-target-microsoft-365-accounts-evade-mfa/?utm_source=openai)) This incident underscores the evolving nature of phishing attacks, highlighting the need for organizations to reassess and strengthen their authentication mechanisms. The emergence of such advanced phishing kits indicates a trend towards more sophisticated social engineering tactics capable of circumventing traditional security measures.
2 weeks ago
Kill Chain
Phishing Alert: LastPass and Bitwarden Users Targeted in July 2026
In July 2026, a sophisticated phishing campaign targeted users of LastPass and Bitwarden, two prominent password management services. Attackers sent emails from addresses like 'hello@lastpassnewsletter.com' and 'hello@bitwardennewsletter.com', falsely notifying recipients of updated security policies. These emails directed users to fraudulent websites impersonating DocuSign, prompting them to download malicious files purportedly compatible with both Windows and macOS systems. The domains used, such as 'lastpasscompliance[.]com' and 'bitwardencompliance[.]com', were flagged as malicious by security services. LastPass confirmed that its systems remained uncompromised and that the phishing emails did not originate from its infrastructure. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/lastpass-bitwarden-users-targeted-with-fake-security-alerts/?utm_source=openai)) This incident underscores a growing trend of cybercriminals targeting password manager users through sophisticated phishing tactics. The use of legitimate-looking emails and websites to deceive users highlights the need for heightened vigilance and robust security measures. Organizations and individuals must remain alert to such evolving threats to safeguard sensitive information.
2 weeks ago
Kill Chain
Uncovering the BoryptGrab Infostealer: Nearly 300 Fake GitHub Repositories Distribute Malware
In July 2026, a sophisticated cyber campaign was uncovered involving nearly 300 fraudulent GitHub repositories that impersonated legitimate software projects to distribute the BoryptGrab infostealer malware. These repositories targeted users searching for security tools, cryptocurrency services, financial applications, developer utilities, secure email providers, macOS utilities, and gaming software. The malware was capable of harvesting data from over 19 web browsers, extracting information from 32 cryptocurrency wallets, and exfiltrating sensitive details from messaging and social media applications. The campaign utilized deceptive landing pages with trust-inducing elements to lure victims into downloading malicious ZIP archives containing trojanized DLL files and legitimate executables, which, when executed, loaded the infostealer into memory. This incident underscores a growing trend where threat actors exploit trusted platforms like GitHub to disseminate malware, leveraging search engine optimization (SEO) techniques to enhance the visibility of malicious repositories. The use of legitimate-looking repositories and sophisticated social engineering tactics highlights the evolving nature of cyber threats and the need for heightened vigilance when downloading software from online sources.
2 weeks ago
Kill Chain
Critical Zero-Day Vulnerability in Progress ShareFile: A Wake-Up Call for Cybersecurity
In July 2026, Progress Software identified a high-severity zero-day vulnerability in its ShareFile Storage Zone Controllers, affecting versions 5.x and 6.x. This path traversal flaw allowed authenticated administrative users to read arbitrary files, write malicious content to directories, and enumerate the server's filesystem layout. Upon discovery, Progress promptly released patched versions 5.12.5 and 6.0.2 to mitigate the issue. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/?utm_source=openai)) This incident underscores the critical importance of timely patch management and proactive vulnerability assessments. Organizations are reminded to regularly update their systems and monitor for emerging threats to safeguard sensitive data and maintain operational integrity.
2 weeks ago
Kill Chain
Windows 11 July 2026 Patch Tuesday: Critical Updates and New Features
On July 14, 2026, Microsoft released cumulative updates KB5101650 and KB5099414 for Windows 11 versions 25H2/24H2 and 23H2, respectively. These mandatory updates addressed 571 security vulnerabilities, including three zero-day exploits, and introduced new features such as improved Bluetooth reliability, enhanced Widgets experience, and Point-in-Time restore functionality. The updates also included various performance and reliability improvements across system components, including File Explorer, networking, printing, and accessibility. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5101650-and-kb5099414-cumulative-updates-released/amp/?utm_source=openai)) The release of these updates underscores the ongoing need for organizations to prioritize timely patch management. With the increasing complexity and volume of vulnerabilities, staying current with security updates is essential to protect systems against potential exploits and maintain operational integrity.
2 weeks ago
Kill Chain
Microsoft's KB5099539 Update: A Critical Security Release for Windows 10
On July 14, 2026, Microsoft released the Windows 10 KB5099539 extended security update, addressing 570 vulnerabilities, including two zero-day flaws actively exploited in the wild. This update is part of Microsoft's Extended Security Updates (ESU) program, which was recently extended to provide free security updates until October 12, 2027. The update includes fixes for issues such as OLE Automation compatibility, File Explorer's OneDrive shortcut malfunction, and Recycle Bin confirmation dialog errors. Additionally, it introduces security hardening changes like enforcing TDI transport registration requirements and enhancing Secure Boot certificate management. The release of KB5099539 underscores the critical importance of timely patch management, especially in light of the record-breaking number of vulnerabilities addressed. Organizations must prioritize the deployment of this update to mitigate potential security risks and ensure compliance with industry standards. The extension of the ESU program provides additional time for organizations to transition to newer operating systems while maintaining security posture.
2 weeks ago
Kill Chain
LabubaRAT: A New Rust-Based RAT Disguised as NVIDIA Software
In July 2026, cybersecurity researchers identified LabubaRAT, a previously undocumented Rust-based remote access trojan (RAT) that masquerades as NVIDIA software to infiltrate Windows systems. The malware establishes a persistent foothold, enabling attackers to profile the host, identify security tools, execute commands, transfer files, capture screenshots, and proxy traffic through the compromised system. LabubaRAT employs multiple communication methods, including HTTPS, WebView2, and DNS tunneling, to maintain access even if one pathway is detected and blocked. The attack initiates with an executable named "nvidia-sysruntime.exe," which impersonates NVIDIA's container runtime toolkit. Instead of hard-coding its command-and-control (C2) information, the malware accepts runtime configurations via command-line arguments, allowing operators to define parameters such as server details and polling intervals. This flexibility enables the reuse of the same binary across different infrastructures and campaigns without modification. Once deployed, LabubaRAT conducts discovery operations to inventory installed web browsers and security products, gathering information on the host's environment to tailor its functionality accordingly. The malware's capabilities include command execution, PowerShell and JavaScript execution, screenshot capture, file upload and download, archive handling, and SOCKS5 proxy support. These features provide attackers with comprehensive control over the infected host, facilitating data exfiltration and further malicious activities. The emergence of LabubaRAT underscores the evolving sophistication of malware designed to evade detection by masquerading as legitimate software. Its use of Rust, a language known for its performance and safety features, highlights a trend among threat actors to adopt modern programming languages to develop more robust and stealthy malware. Organizations must remain vigilant and implement robust security measures to detect and mitigate such threats.
2 weeks ago
Kill Chain
SonicWall SMA1000 Zero-Day Vulnerabilities: Immediate Action Required
In July 2026, SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances: CVE-2026-15409, a server-side request forgery flaw, and CVE-2026-15410, a post-authentication code injection vulnerability. These flaws allowed unauthenticated attackers to make unauthorized requests and authenticated administrators to execute arbitrary OS commands, respectively. Both vulnerabilities were actively exploited in zero-day attacks, prompting SonicWall to release urgent security patches. Organizations utilizing affected SMA1000 models were advised to upgrade to the latest firmware versions immediately and to inspect their systems for indicators of compromise. This incident underscores the persistent targeting of remote access solutions by threat actors, highlighting the necessity for continuous monitoring, timely patching, and comprehensive security measures to protect against evolving cyber threats.
2 weeks ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

