✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 505 to 516 of 5035
Critical Vulnerabilities Discovered in Digi International's PortServer TS and Digi One SP IA Devices
In July 2026, Digi International disclosed two significant vulnerabilities affecting their PortServer TS and Digi One SP IA devices. The first, CVE-2026-12352, allows unauthenticated attackers to bypass authentication mechanisms, granting unauthorized access to restricted resources. The second, CVE-2026-12948, is a stored cross-site scripting (XSS) vulnerability that enables authenticated administrators to inject malicious scripts into system configuration fields, which execute in the browsers of users viewing the affected pages. These vulnerabilities pose risks of unauthorized access, credential theft, and potential system compromise. The disclosure of these vulnerabilities underscores the critical importance of securing networked devices, especially those integral to industrial control systems. Organizations must prioritize timely firmware updates and implement robust network segmentation to mitigate such risks. This incident highlights the ongoing challenges in maintaining the security of legacy systems and the necessity for continuous monitoring and proactive defense strategies.
3 weeks ago
Kill Chain
GitHub's 'Verified' Commits Vulnerable to Hash Malleability
In July 2026, researcher Jacob Ginesin identified a vulnerability in GitHub's commit verification process, revealing that signed Git commits can be altered to produce new hashes without invalidating their signatures. This flaw allows attackers to replicate commits with identical content, authorship, and timestamps, yet different hashes, while still displaying a 'Verified' status on GitHub. Consequently, systems relying on commit hashes for security measures, such as blocklists and provenance logs, are susceptible to evasion tactics. ([thehackernews.com](https://thehackernews.com/2026/07/github-verified-commits-can-be.html?utm_source=openai)) This discovery underscores the critical need for robust verification mechanisms in software development platforms. As supply chain attacks become more sophisticated, ensuring the integrity and authenticity of code commits is paramount to maintaining trust and security in open-source ecosystems.
3 weeks ago
Kill Chain
Critical Vulnerabilities in Labcenter Proteus 9 Threaten Infrastructure Security
In July 2026, multiple high-severity vulnerabilities were identified in Labcenter Proteus 9.1 SP4 Build 42914, including CVE-2026-42953 (out-of-bounds write), CVE-2026-49033 (stack-based buffer overflow), and CVE-2026-42958 (use-after-free). Exploitation of these vulnerabilities could allow attackers to execute arbitrary code, potentially compromising critical infrastructure sectors such as communications, healthcare, and energy. ([socdefenders.ai](https://www.socdefenders.ai/item/4909df73-d6e4-4d7f-ad22-28b3fb4d7bdc?utm_source=openai)) This incident underscores the persistent risks associated with software vulnerabilities in critical systems. Organizations must prioritize timely patching and robust security measures to mitigate potential threats. ([socdefenders.ai](https://www.socdefenders.ai/item/4909df73-d6e4-4d7f-ad22-28b3fb4d7bdc?utm_source=openai))
3 weeks ago
Kill Chain
Critical Vulnerability in Hitachi Energy's PROMOD V: CVE-2026-10763
In June 2026, Hitachi Energy disclosed a vulnerability (CVE-2026-10763) in its PROMOD V software, which utilized unencrypted HTTP communication due to the lack of HTTPS support from a third-party Digipede server. This flaw exposed sensitive data to potential interception and manipulation, posing risks such as credential theft and unauthorized access. The affected versions include PROMOD V up to 1.0.10. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-10763?utm_source=openai)) This incident underscores the critical importance of secure communication protocols in industrial control systems. Organizations are urged to review their software dependencies and ensure that all components support encrypted communications to mitigate similar vulnerabilities.
3 weeks ago
Kill Chain
SCMBANKER Malware Targets Mexican Banks Using ClickFix Lures
In July 2026, a sophisticated cybercriminal operation targeted customers of Mexican financial institutions, including banks, fintech companies, payment processors, and cryptocurrency exchanges. The attackers employed a social engineering technique known as ClickFix, presenting victims with fake CAPTCHA verification pages that instructed them to execute a malicious command. This command installed a PowerShell-based toolkit named SCMBANKER, enabling the threat actors to monitor banking sessions, capture screenshots, manipulate clipboards, and deploy remote access tools for full system control. The campaign, identified by Elastic Security Labs as REF6045, demonstrated a high level of automation and adaptability, with evidence suggesting the use of large language models to develop the malware components. ([thehackernews.com](https://thehackernews.com/2026/07/scmbanker-malware-uses-clickfix-lures.html?utm_source=openai)) This incident underscores the evolving nature of cyber threats targeting the financial sector, particularly in Mexico. The use of AI-assisted malware development and advanced social engineering tactics like ClickFix highlights the need for continuous vigilance and adaptive security measures to protect sensitive financial data and maintain customer trust.
3 weeks ago
Kill Chain
EvilTokens Phishing Campaign: A 2026 Cybersecurity Wake-Up Call
In early 2026, the EvilTokens phishing-as-a-service (PhaaS) platform emerged, exploiting the OAuth 2.0 Device Authorization Grant to compromise Microsoft 365 accounts. This sophisticated campaign utilized AI to generate personalized phishing lures, leading to a 1,380% increase in device code phishing attacks between July–December 2025 and January–April 2026. Attackers bypassed multi-factor authentication (MFA) by redirecting legitimate authentication flows, granting them persistent access to corporate email, SharePoint, and OneDrive services. The campaign targeted hundreds of organizations daily, affecting sectors globally. ([huntress.com](https://www.huntress.com/resources/eviltokens-ai-powered-phishing-report?utm_source=openai)) The EvilTokens operation underscores a significant evolution in phishing tactics, leveraging AI to automate and personalize attacks at scale. This trend highlights the urgent need for organizations to reassess and strengthen their security postures, particularly concerning identity and access management, to mitigate the risks posed by increasingly sophisticated phishing campaigns. ([securityboulevard.com](https://securityboulevard.com/2026/07/eviltokens-campaign-reveals-device-code-phishing-ticks-up-1380-powered-by-ai/?utm_source=openai))
3 weeks ago
Kill Chain
CISA Highlights Three Actively Exploited Vulnerabilities in Latest KEV Catalog Update
On July 7, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. These vulnerabilities include CVE-2026-48908, an unrestricted file upload flaw in JoomShaper's SP Page Builder; CVE-2026-55255, an authorization bypass in Langflow; and CVE-2026-56290, an improper access control issue in Joomlack's Page Builder. Such vulnerabilities are commonly exploited by malicious actors, posing significant risks to federal enterprises. The inclusion of these vulnerabilities underscores the critical need for organizations to prioritize remediation efforts. CISA's Binding Operational Directive (BOD) 26-04 mandates federal agencies to address high-risk vulnerabilities promptly, emphasizing the importance of proactive vulnerability management to safeguard against active threats.
3 weeks ago
Kill Chain
Critical Vulnerability in Hitachi Energy e-mesh EMS: CVE-2026-42945
In July 2026, Hitachi Energy disclosed a critical vulnerability (CVE-2026-42945) in its e-mesh EMS versions 4.1.6, 4.4.2, and 4.7.0. This heap-based buffer overflow in the NGINX component's ngx_http_rewrite_module allows unauthenticated attackers to send crafted HTTP requests, potentially leading to application crashes and arbitrary code execution. The vulnerability arises when specific rewrite directives are used with unnamed PCRE captures and replacement strings containing a question mark. ([windowsforum.com](https://windowsforum.com/threads/cve-2026-42945-nginx-heap-overflow-hits-hitachi-energy-e-mesh-ems.435597/?utm_source=openai)) This incident underscores the risks of integrating widely-used web components like NGINX into critical infrastructure systems. Organizations must prioritize patching affected systems and reviewing configurations to mitigate potential exploitation, especially in environments where operational technology intersects with standard web technologies.
3 weeks ago
Kill Chain
HalluSquatting: Exploiting AI Coding Assistants to Deploy Botnet Malware
In July 2026, researchers identified a novel cyberattack technique termed 'HalluSquatting,' which exploits AI coding assistants' tendency to generate plausible but non-existent resource names. Attackers predict these hallucinated names, register them, and embed malicious code. When users prompt their AI assistants to fetch these resources, the assistants inadvertently execute the malicious code, potentially installing botnet malware on the user's machine. This method leverages AI hallucinations and prompt injections to compromise systems without direct user interaction. The emergence of HalluSquatting underscores the evolving threat landscape in AI-integrated development environments. As AI tools become more prevalent, attackers are increasingly targeting their inherent vulnerabilities. This incident highlights the urgent need for enhanced security measures in AI-driven tools to prevent exploitation through such sophisticated techniques.
3 weeks ago
Kill Chain
Expansion of Deepfake CSAM Lawsuit Targets xAI and Stability AI
In July 2026, a class-action lawsuit against xAI, the developer of the AI tool Grok, was expanded to include two additional plaintiffs. These individuals allege that Grok was used by acquaintances to generate nonconsensual deepfake child sexual abuse material (CSAM) based on their real photos. The lawsuit also names Stability AI as a defendant, claiming that its Stable Diffusion model facilitated the creation of such illicit content. The plaintiffs report significant emotional distress and a loss of control over the dissemination of these images. This incident underscores the urgent need for robust safeguards in AI technologies to prevent misuse, particularly in generating harmful content. It highlights the growing legal and ethical challenges companies face in ensuring their AI models are not exploited for creating nonconsensual and illegal material.
3 weeks ago
Kill Chain
Spain Arrests Alleged Member of Pro-Russian Hacktivist Group in 2026
In March 2026, Spanish authorities arrested an alleged member of the pro-Russian hacktivist group Cyber Army of Russia Reborn (CARR) in Palencia, Spain. The arrest followed an investigation initiated by an FBI tip in August 2025. The individual is accused of providing logistical support to a Ukrainian hacker associated with CARR, facilitating their escape to Russia, and participating in cyber activities attributed to the pro-Russian hacktivist group NoName057(16). Authorities seized computers and cryptocurrency storage devices from the suspect's residence and froze a cryptocurrency wallet allegedly used for illicit payments. The suspect faces accusations of collaborating with a terrorist organization, glorifying terrorism, and damaging computers. ([cyberscoop.com](https://cyberscoop.com/spain-arrests-alleged-cyber-army-of-russia-reborn-member/?utm_source=openai)) This arrest underscores the ongoing international efforts to combat cyber threats posed by state-sponsored hacktivist groups targeting critical infrastructure. The collaboration between Spanish authorities and the FBI highlights the importance of cross-border cooperation in addressing cybercrime. Organizations are advised to remain vigilant against such threats and implement robust cybersecurity measures to protect their systems.
3 weeks ago
Kill Chain
Critical Authentication Bypass Vulnerabilities in BeyondTrust Remote Support
In July 2026, BeyondTrust disclosed critical vulnerabilities in its Remote Support (RS) and Privileged Remote Access (PRA) software, notably CVE-2026-40138 and CVE-2026-40139. These flaws, stemming from improper authentication handling, could allow unauthenticated attackers to bypass access controls and gain elevated privileges. Exploitation requires specific authentication configurations to be enabled. BeyondTrust has released patches to address these issues. The disclosure underscores the persistent risks associated with remote access solutions, especially as organizations increasingly rely on them for remote work. Ensuring timely application of security patches and reviewing authentication configurations are crucial to mitigate potential exploitation.
3 weeks ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

