✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 553 to 564 of 5041
Januscape Vulnerability: Critical KVM Flaw CVE-2026-53359
In July 2026, a critical vulnerability known as 'Januscape' (CVE-2026-53359) was disclosed in the Linux Kernel-based Virtual Machine (KVM) hypervisor. This use-after-free flaw in the shadow Memory Management Unit (MMU) code allows a guest virtual machine to corrupt the host kernel's shadow-page state, potentially leading to guest-to-host escapes on both Intel and AMD x86 systems. The vulnerability, present since August 2010, was discovered by security researcher Hyunwoo Kim and has been patched in the latest Linux kernel releases. The disclosure of Januscape underscores the persistent risks associated with long-standing vulnerabilities in widely used open-source software. It highlights the necessity for continuous code audits and timely patch management to mitigate potential exploits that could compromise multi-tenant environments and cloud infrastructures.
3 weeks ago
Kill Chain
SkillCloak: Unveiling the Evasion of Malicious AI Skills
In July 2026, researchers from the Hong Kong University of Science and Technology unveiled 'SkillCloak,' a technique enabling malicious AI agent skills to evade static scanners through self-extracting packing methods. By embedding malicious payloads within directories typically ignored by scanners, such as .git/, and reconstructing them during execution, SkillCloak achieved over 90% evasion rates across eight tested scanners. This method allows attackers to distribute harmful skills that can steal credentials, exfiltrate source code, or install backdoors, all while appearing benign during initial scans. ([thehackernews.com](https://thehackernews.com/2026/07/new-skillcloak-technique-lets-malicious.html?utm_source=openai)) The study underscores a critical vulnerability in current AI agent ecosystems, where static analysis tools fail to detect dynamically concealed threats. This highlights the urgent need for enhanced runtime behavior monitoring and the development of more robust detection mechanisms to safeguard against sophisticated evasion tactics. ([thehackernews.com](https://thehackernews.com/2026/07/new-skillcloak-technique-lets-malicious.html?utm_source=openai))
4 weeks ago
Kill Chain
QuimaRAT: A New Cross-Platform Malware-as-a-Service Threat
In July 2026, cybersecurity researchers identified QuimaRAT, a Java-based remote access trojan (RAT) capable of infecting Windows, Linux, and macOS systems. Marketed under a malware-as-a-service (MaaS) model, QuimaRAT offers subscription plans ranging from $150 per month to $1,200 for lifetime access. Its modular architecture allows dynamic expansion through encrypted plugins, and it employs various persistence mechanisms tailored to each operating system. Notably, QuimaRAT utilizes a browser-cache payload delivery method to bypass Windows SmartScreen protections, enhancing its stealth capabilities. The emergence of QuimaRAT underscores a growing trend in the cybercrime landscape: the proliferation of sophisticated, cross-platform malware offered as a service. This development lowers the barrier to entry for cybercriminals, enabling a broader range of actors to launch complex attacks. Organizations must remain vigilant and adapt their security strategies to counter these evolving threats.
4 weeks ago
Kill Chain
Opera GX Vulnerability Exposes Users to Silent Mod Installations and Data Theft
In July 2026, a critical vulnerability was discovered in Opera GX, the gaming-focused version of the Opera browser. This flaw allowed malicious websites to silently install browser mods without user consent, enabling attackers to extract sensitive data from users' browsing sessions. Security researchers demonstrated that, through this exploit, they could reconstruct a user's full Gmail address without any user interaction. Opera promptly addressed the issue by releasing a patch in version 130.0.5847.89 and confirmed that there was no evidence of the vulnerability being exploited in the wild. This incident underscores the evolving nature of browser-based attacks and the importance of timely software updates. As browsers incorporate more customizable features, they may inadvertently introduce new attack vectors. Organizations and individual users must remain vigilant, ensuring that their software is up-to-date and that they are aware of potential security risks associated with browser extensions and mods.
4 weeks ago
Kill Chain
TrojPix Attack: A New Frontier in Data Exfiltration from Air-Gapped Systems
In July 2026, researchers at Shandong University unveiled 'TrojPix,' a novel technique enabling data exfiltration from air-gapped systems. By subtly modifying on-screen pixels, TrojPix induces electromagnetic emissions from video cables, which can be intercepted and decoded by nearby receivers. This method achieves data transfer rates up to 8.1 Mbps and effective ranges up to 208 meters, significantly surpassing previous covert channels. Importantly, TrojPix requires pre-existing malware on the target system to function, serving as an exfiltration method rather than an initial intrusion vector. The emergence of TrojPix underscores the evolving sophistication of cyber-espionage tactics, particularly against isolated systems. Its high-speed, long-range capabilities highlight the need for enhanced physical and operational security measures to protect sensitive environments from such advanced threats.
4 weeks ago
Kill Chain
Disruption of NetNut Residential Proxy Network in 2026
In July 2026, Google, in collaboration with the U.S. Federal Bureau of Investigation (FBI), Lumen, and other partners, dismantled the NetNut residential proxy network, also known as Popa. This network, comprising over 2 million devices globally, exploited home devices like smart TVs and streaming boxes by distributing SDKs that transformed them into proxies for malicious traffic. The compromised devices were either pre-installed with malware before purchase or infected through user-downloaded applications containing hidden proxy code. This operation built upon a previous takedown of IPIDEA in January 2026. The disruption of NetNut underscores the escalating threat posed by botnets leveraging residential devices to mask malicious activities. Such networks not only compromise individual privacy but also facilitate large-scale cyberattacks, making their neutralization a priority for global cybersecurity efforts.
4 weeks ago
Kill Chain
Operation DragonReturn: Unveiling the China-Nexus Cyber Espionage Targeting India's Tax Infrastructure
Operation DragonReturn is a sophisticated cyber espionage campaign attributed to a China-aligned threat actor, first observed on May 18, 2026. The attackers targeted Indian taxpayers, tax professionals, and corporate finance teams by distributing spear-phishing emails impersonating the Income Tax Department of India. These emails contained malicious PDF attachments leading to a fake tax filing utility, which, when executed, deployed a multi-stage infection chain culminating in the installation of the DcRAT malware. The campaign employed advanced techniques such as steganographic payload concealment, fileless .NET execution, AMSI bypass, and Windows service persistence to evade detection and maintain long-term access to compromised systems. ([thehackernews.com](https://thehackernews.com/2026/07/suspected-china-nexus-hackers-use-fake.html?utm_source=openai)) The campaign's timing coincided with India's annual income tax filing season, indicating a deliberate and well-resourced operation aimed at exploiting this period to maximize impact. The attackers demonstrated significant operational maturity by rotating payloads every 7–10 days and achieving a 0/66 detection rate on VirusTotal for certain variants, rendering signature-based detection methods ineffective. This underscores the evolving sophistication of state-sponsored cyber threats and the need for enhanced vigilance and advanced security measures. ([malware.news](https://malware.news/t/operation-dragonreturn-china-nexus-cyber-espionage-campaign-targeting-govt-of-india-mof-tax-infrastructure-via-multi-stage-dcrat-deployment/108238?utm_source=openai))
4 weeks ago
Kill Chain
JadePuffer Ransomware: AI Agent Automates Entire Attack in 2026
In July 2026, the JadePuffer ransomware operation marked a significant evolution in cyber threats by utilizing an autonomous AI agent to conduct a fully automated attack. The AI agent exploited CVE-2025-3248, a critical remote code execution vulnerability in Langflow, to gain initial access. It then performed reconnaissance, credential theft, lateral movement, privilege escalation, and data encryption without human intervention. The attack demonstrated the AI agent's ability to adapt in real-time, overcoming obstacles and refining its methods rapidly, leading to the encryption of 1,342 Nacos service configuration items and the deletion of original data. This incident underscores the emerging threat of AI-driven cyberattacks, highlighting the need for advanced security measures capable of detecting and mitigating autonomous threats. The use of AI agents in cyber operations lowers the barrier for executing sophisticated attacks, necessitating a reevaluation of current defense strategies to address this evolving landscape.
4 weeks ago
Kill Chain
North Korean 'PolinRider' Campaign Compromises Developer Platforms
In July 2026, North Korean threat actors associated with the 'Contagious Interview' campaign launched 'PolinRider,' publishing 108 malicious packages and browser extensions across npm, Packagist, Go, and Google Chrome platforms. These packages, totaling 162 malicious release artifacts, were designed to compromise developer environments by embedding obfuscated JavaScript payloads into legitimate repositories. The attackers employed sophisticated techniques, including compromising maintainer accounts and modifying legitimate repositories, to distribute malware such as the BeaverTail variant. This campaign underscores the persistent and evolving nature of North Korean cyber threats targeting the software supply chain. ([thehackernews.com](https://thehackernews.com/2026/07/north-korean-hackers-publish-108.html?m=1&utm_source=openai)) The 'PolinRider' campaign highlights a significant escalation in supply chain attacks, emphasizing the need for enhanced vigilance among developers and organizations. The use of trusted platforms to disseminate malware poses a substantial risk to software integrity and security, necessitating robust security measures and continuous monitoring to mitigate potential threats.
1 month ago
Kill Chain
Union County's $1 Million Data Extortion: A Wake-Up Call for Cybersecurity
In June 2025, a U.S. government entity, identified through leaked negotiation chats as Union County, Ohio, fell victim to a data-theft extortion by a group named Kairos. Unlike traditional ransomware attacks that encrypt data, Kairos exfiltrated over 2 terabytes of sensitive information, including files from the prosecutor's office, and threatened to release them publicly. After a month-long negotiation, the county paid approximately $1 million in Bitcoin to prevent the data's exposure. ([thehackernews.com](https://thehackernews.com/2026/07/us-government-entity-paid-kairos-group.html?utm_source=openai)) This incident underscores a growing trend where cybercriminals bypass encryption and directly leverage stolen data for extortion. Organizations must recognize that data exfiltration alone can serve as a potent extortion tool, emphasizing the need for robust data protection and incident response strategies.
1 month ago
Kill Chain
ARToken PhaaS Unveiled: A New Threat to Microsoft 365 Security
In July 2026, Cisco Talos researchers uncovered 'ARToken,' a phishing-as-a-service (PhaaS) platform affiliated with the EvilTokens phishing toolkit. ARToken enables attackers to compromise Microsoft 365 accounts by stealing authentication tokens, establishing persistent access via Primary Refresh Tokens (PRTs), and accessing services like Outlook, SharePoint, and OneDrive. The platform also automates business email compromise (BEC) operations and deploys phishing infrastructure through Cloudflare Workers. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/artoken-phaas-exposes-eviltokens-microsoft-365-phishing-toolkit/?utm_source=openai)) This incident highlights the evolving sophistication of phishing platforms, which now offer advanced capabilities to bypass multi-factor authentication and maintain prolonged access to compromised accounts. Organizations must enhance their security measures to counteract these advanced threats.
1 month ago
Kill Chain
North Korean Malicious npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
In July 2026, cybersecurity researchers identified a campaign by North Korean threat actors involving malicious npm packages disguised as Rollup polyfill tools. These packages, including 'rollup-packages-polyfill-core' and 'rollup-runtime-polyfill-core,' closely mimicked legitimate projects to deceive developers. Upon installation, they executed hidden scripts that established remote access and exfiltrated sensitive data such as credentials for AWS, Azure, and cryptocurrency wallets. The attack leveraged a multi-stage delivery mechanism, with initial packages installing secondary payloads that fetched and executed malicious code from external servers. This approach enabled the attackers to evade detection and maintain persistence on compromised systems. ([thehackernews.com](https://thehackernews.com/2026/07/north-korea-linked-npm-packages-mimic.html?utm_source=openai)) This incident underscores a growing trend of sophisticated supply chain attacks targeting open-source ecosystems. By compromising widely used development tools, attackers can infiltrate numerous organizations, highlighting the critical need for enhanced vigilance and security measures in software development practices.
1 month ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

