✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 613 to 624 of 5042
Critical Unpatched Vulnerability in Argo CD Repo-Server Threatens Kubernetes Clusters
In July 2026, a critical vulnerability was disclosed in Argo CD's repo-server component, a widely used tool for deploying software to Kubernetes. The flaw allows unauthenticated attackers to execute arbitrary code by sending crafted requests to the repo-server's internal gRPC service, which lacks authentication. This vulnerability can lead to full cluster takeovers if the repo-server is accessible within the network. Despite being reported to Argo CD's maintainers in January 2025, the issue remains unpatched as of July 2026. This incident underscores the importance of securing internal services and implementing robust network policies. Organizations using Argo CD should immediately apply network isolation measures to prevent unauthorized access to the repo-server component and mitigate potential exploitation.
1 month ago
Kill Chain
19-Year-Old Scattered Spider Member Extradited to U.S. for Hacking Charges
On July 1, 2026, the U.S. Department of Justice announced the extradition of Peter Stokes, a 19-year-old dual U.S. and Estonian citizen, from Finland to the United States. Stokes, identified by the online handle "Bouquet," faces charges of conspiracy, computer intrusion, and fraud for his alleged involvement with the cybercriminal group Scattered Spider. This group has been linked to over 100 network intrusions, resulting in more than $100 million in ransom payments. Stokes appeared in a Chicago federal court on June 30, where he was ordered to remain in custody. The arrest underscores the persistent threat posed by Scattered Spider, known for targeting sectors such as casinos, retailers, and airlines through sophisticated social engineering tactics. Despite recent law enforcement actions, the group's methods continue to evolve, highlighting the need for organizations to bolster their cybersecurity defenses against such adaptive threats.
1 month ago
Kill Chain
Iran-Nexus TAG-182 Deploys MarkiRAT Malware in Surveillance Campaign
In early 2026, the Iranian-linked threat group TAG-182 initiated a cyber espionage campaign deploying MarkiRAT malware via counterfeit Android applications, including fake VPNs and media tools, to surveil Iranian citizens domestically and abroad. This operation aligns with Iran's intensified digital surveillance efforts following the partial restoration of internet access on May 26, 2026, targeting perceived dissidents and foreign collaborators. The MarkiRAT samples exhibit tradecraft overlaps with previous variants used by Ferocious Kitten, suggesting a potential operational connection, though further evidence is required to confirm organizational links. ([staging.hawk-eye.io](https://staging.hawk-eye.io/iran-apt-threat-advisory/?utm_source=openai)) The resurgence of TAG-182's activities underscores the persistent threat posed by Iranian state-sponsored cyber operations, particularly in the realm of surveillance and intelligence gathering. Organizations and individuals, especially those involved in human rights advocacy or opposition activities, should remain vigilant against sophisticated social engineering tactics and ensure robust cybersecurity measures are in place to mitigate the risks associated with such targeted campaigns.
1 month ago
Kill Chain
Persistent Phishing Threats in the Hospitality Industry: A 2026 Case Study
In April 2026, a sophisticated phishing campaign targeted hospitality organizations across Europe and Asia. Attackers impersonated guests, sending emails with malicious ZIP files disguised as photo attachments. These emails exploited trusted services like Calendly and Google redirects to bypass email authentication checks. Upon opening the ZIP files, victims inadvertently executed a PowerShell script that installed a persistent Node.js-based malware implant, granting attackers long-term access to compromised systems. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/phishers-persistence-eu-asia-hospitality-orgs?utm_source=openai)) This incident underscores a growing trend of cybercriminals leveraging social engineering and trusted platforms to infiltrate organizations. The use of advanced techniques, such as 'authentication laundering' and blockchain-based command-and-control mechanisms, highlights the evolving nature of cyber threats in the hospitality sector. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/phishers-persistence-eu-asia-hospitality-orgs?utm_source=openai))
1 month ago
Kill Chain
Securing AI Endpoints: Lessons from Recent Exploits
Between March and May 2026, Zenity researchers identified three distinct campaigns where threat actors exploited exposed AI inference endpoints, such as those of Ollama and LiteLLM, to conduct offensive operations. These attacks did not require full system compromises; attackers merely needed knowledge of the exposed endpoints to leverage them for activities like autonomous penetration testing and web reverse-engineering. The incidents underscore the critical need for securing AI infrastructure against unauthorized access. This trend highlights a growing tactic among cyber adversaries: exploiting misconfigured or exposed AI endpoints to amplify their offensive capabilities. As organizations increasingly integrate AI into their operations, ensuring the security of these systems becomes paramount to prevent their misuse in cyberattacks.
1 month ago
Kill Chain
Agentjacking: The Emerging Threat to AI Coding Agents
In June 2026, Tenet Security unveiled a novel attack method termed 'agentjacking,' wherein attackers exploit AI coding agents by injecting malicious code through fabricated error reports in public bug tracking services. This technique enables unauthorized code execution on developers' machines, potentially leading to the theft of sensitive credentials and compromise of development environments. The attack leverages the AI agents' inability to distinguish between genuine content and embedded instructions, allowing adversaries to manipulate these agents into executing harmful commands. The significance of this discovery lies in the escalating integration of AI coding agents into software development workflows. As these agents become more prevalent, understanding and mitigating their vulnerabilities is crucial to prevent similar exploitation methods. Organizations must reassess their security protocols to address the unique risks posed by AI-driven development tools.
1 month ago
Kill Chain
China-Linked Group Targets Southeast Asia Critical Systems
In mid-2025, the Chinese-speaking advanced persistent threat (APT) group CL-STA-1062 initiated a cyber espionage campaign targeting government entities and critical infrastructure in Southeast Asia. The group compromised at least 10 organizations, including state-owned enterprises in the energy and government sectors, deploying a custom backdoor named TinyRCT. This backdoor facilitated unauthorized access, data exfiltration, and system control, posing significant risks to national security and operational stability. ([thehackernews.com](https://thehackernews.com/2026/06/chinese-speaking-apt-deploys-new.html?utm_source=openai)) The emergence of TinyRCT underscores the evolving sophistication of state-sponsored cyber threats in the region. Organizations must enhance their cybersecurity measures to detect and mitigate such advanced persistent threats, ensuring the resilience of critical infrastructure against future attacks. ([thehackernews.com](https://thehackernews.com/2026/06/chinese-speaking-apt-deploys-new.html?utm_source=openai))
1 month ago
Kill Chain
Phantom Squatting: Unveiling the New AI-Driven Cyber Threat
In July 2026, cybersecurity researchers identified a new threat vector termed 'phantom squatting,' where attackers exploit AI-generated, non-existent domains associated with legitimate brands. By registering these hallucinated domains, cybercriminals can intercept traffic directed by AI systems, leading to phishing attacks and malware distribution. This method leverages the tendency of large language models (LLMs) to generate plausible yet fictitious web addresses, creating a novel supply chain vulnerability. The emergence of phantom squatting underscores the evolving landscape of AI-driven cyber threats. As organizations increasingly integrate AI assistants into their operations, the risk of such AI-induced vulnerabilities grows, necessitating proactive measures to monitor and secure potential phantom domains before they are weaponized by adversaries.
1 month ago
Kill Chain
Critical Vulnerabilities in Delta Electronics DVP12SE PLCs: CVE-2026-12819 and CVE-2026-12818
In June 2026, critical vulnerabilities were identified in Delta Electronics DVP12SE Programmable Logic Controllers (PLCs), specifically CVE-2026-12819 and CVE-2026-12818. These flaws allow remote attackers to issue commands, modify operational values, and interfere with control logic without authentication. The vulnerabilities affect all versions of the DVP12SE PLC, potentially enabling unauthorized access to sensitive control functions and causing resource exhaustion through flooding attacks. The discovery of these vulnerabilities underscores the increasing risks associated with industrial control systems (ICS) and the necessity for robust security measures. Organizations utilizing Delta Electronics DVP12SE PLCs should implement recommended mitigations, such as enabling IP filtering, setting up password protection, and ensuring network isolation, to safeguard against potential exploitation.
1 month ago
Kill Chain
Unveiling the Evolution of ClickFix: API-Driven Malware Delivery Exposed
In July 2026, security researcher Bert-Jan Pals analyzed approximately 3,000 live ClickFix payloads, uncovering a significant evolution in the malware delivery mechanism. ClickFix, a social engineering technique that deceives users into executing malicious commands, has transitioned to using API-driven servers. These servers dynamically generate unique, obfuscated commands for each visitor, effectively disguising the same underlying malware. Additionally, a new delivery method was identified that bypasses Windows' script scanning by downloading a file to the user's system and executing it through a seemingly innocuous command, thereby evading traditional detection mechanisms. This development underscores the increasing sophistication of social engineering attacks and the continuous adaptation of threat actors to circumvent security measures. Organizations must remain vigilant, updating their security protocols and educating users about emerging threats to mitigate the risks associated with such advanced attack vectors.
1 month ago
Kill Chain
Critical XZ Utils Vulnerability Affects B&R Products (CVE-2025-31115)
In June 2026, B&R Industrial Automation GmbH disclosed a critical vulnerability (CVE-2025-31115) in their products due to a flaw in XZ Utils versions 5.3.3alpha to 5.8.0. This race condition within the multithreaded .xz decoder in liblzma could allow attackers to crash the system or corrupt memory data. Affected products include PPC3100, C50, C80, FT50, MT50, T30, T80, and T50, with specific versions listed in the advisory. The vulnerability has a CVSS v3 base score of 7.5, indicating high severity. ([cisa.gov](https://www.cisa.gov/sites/default/files/publications/web-metrics/CISA.gov-Apr-2024-Web-Metrics-508.pdf?utm_source=openai)) This incident underscores the importance of promptly addressing vulnerabilities in widely used open-source libraries. Organizations are advised to update to XZ Utils version 5.8.1 or apply the provided patches to mitigate potential risks. ([cisa.gov](https://www.cisa.gov/sites/default/files/publications/web-metrics/CISA.gov-Apr-2024-Web-Metrics-508.pdf?utm_source=openai))
1 month ago
Kill Chain
Massive Azure CLI Password Spray Attack Compromises 78 Microsoft Accounts
Between June 12 and June 26, 2026, a massive, automated password spray attack targeted Microsoft's Azure command-line interface (CLI), resulting in over 81 million login attempts and the compromise of at least 78 Microsoft accounts across 64 organizations. The attackers exploited a deprecated OAuth 2.0 grant type known as Resource Owner Password Credentials (ROPC) to bypass Conditional Access Policies (CAP) and multi-factor authentication (MFA) in environments where MFA was not enforced for all cloud applications. The attack originated from an IPv6 address range controlled by internet infrastructure provider LSHIY LLC (AS32167). ([thehackernews.com](https://thehackernews.com/2026/07/azure-cli-password-spray-hits-at-least.html?utm_source=openai)) This incident underscores the critical need for organizations to review and properly configure their Conditional Access Policies to enforce MFA across all applications and user groups. The exploitation of legacy authentication methods like ROPC highlights the importance of disabling deprecated protocols and ensuring that security measures are comprehensive and up-to-date. ([thehackernews.com](https://thehackernews.com/2026/07/azure-cli-password-spray-hits-at-least.html?utm_source=openai))
1 month ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

