✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 625 to 636 of 5042
Critical Authentication Bypass in Frangoteam FUXA SCADA/HMI Software (CVE-2026-13207)
In June 2026, a critical authentication bypass vulnerability (CVE-2026-13207) was identified in Frangoteam's FUXA SCADA/HMI software versions 1.3.1 and earlier. This flaw allows unauthenticated remote attackers to access sensitive user and role data by exploiting improper path normalization in the REST API. By manipulating URL paths with dot-segment sequences, attackers can bypass authentication checks and retrieve confidential information without credentials. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-13207?utm_source=openai)) This incident underscores the persistent risks associated with authentication bypass vulnerabilities in industrial control systems. As SCADA environments increasingly integrate web-based interfaces, ensuring robust authentication mechanisms becomes paramount to prevent unauthorized access and potential operational disruptions.
1 month ago
Kill Chain
Phantom Squatting: Exploiting AI-Generated Domains for Cyber Attacks
In July 2026, Palo Alto Networks' Unit 42 identified a new cyberattack technique termed 'phantom squatting,' where attackers exploit AI-generated, non-existent domains to conduct phishing and malware distribution. By prompting large language models (LLMs) with queries about official websites, attackers collect these hallucinated domains, register them, and create malicious sites that appear legitimate to users and AI tools alike. This method leverages the trust users place in AI-generated content, leading to increased risks of credential theft and malware infections. The emergence of phantom squatting underscores the evolving landscape of cyber threats, particularly as AI tools become more integrated into daily operations. Organizations must recognize the potential for AI-generated misinformation to be weaponized and implement proactive measures to monitor and secure domains that could be exploited through such techniques.
1 month ago
Kill Chain
Critical Vulnerability in Schneider Electric's EcoStruxure IT Data Center Expert: CVE-2026-8045
In June 2026, Schneider Electric disclosed a vulnerability (CVE-2026-8045) in its EcoStruxure IT Data Center Expert software, versions 9.1.1 and prior. This flaw, identified as an Improper Restriction of XML External Entity Reference (CWE-611), allows authenticated users to submit crafted XML payloads to SOAP service endpoints, potentially leading to unauthorized access and disclosure of sensitive server-side files. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-8045?utm_source=openai)) The vulnerability underscores the critical need for robust input validation and secure XML processing in software applications. Organizations utilizing affected versions should promptly apply the vendor-provided patch to mitigate potential risks associated with this security flaw.
1 month ago
Kill Chain
Critical Vulnerabilities Discovered in Mitsubishi Electric's MELSOFT Update Manager
In June 2026, Mitsubishi Electric disclosed multiple vulnerabilities in its MELSOFT Update Manager SW1DND-UDM-M software, specifically versions 1.000A through 1.014Q. These vulnerabilities, identified as CVE-2025-53816, CVE-2025-53817, CVE-2025-55188, and CVE-2025-11001, stem from issues within the bundled 7-Zip component. Exploitation could allow local attackers to execute arbitrary code, cause denial-of-service conditions, or tamper with information by convincing users to decompress specially crafted archive files. The affected software is widely used in critical manufacturing sectors globally. ([knutmichael.com](https://knutmichael.com/radar/2026-06-30-mitsubishi-electric-melsoft-update-manager-sw1dnd-udm-m?utm_source=openai)) The disclosure underscores the persistent risks associated with third-party components in industrial control systems. Organizations are urged to promptly update to version 1.015R or later and implement recommended security measures to mitigate potential threats. ([knutmichael.com](https://knutmichael.com/radar/2026-06-30-mitsubishi-electric-melsoft-update-manager-sw1dnd-udm-m?utm_source=openai))
1 month ago
Kill Chain
Protecting AI Agents from MCP Tool Poisoning Attacks
In June 2026, Microsoft Incident Response detailed a sophisticated attack pattern targeting enterprise AI agents utilizing the Model Context Protocol (MCP). The attack involved malicious modifications to MCP tool descriptions, leading AI agents to execute unauthorized actions, such as exfiltrating sensitive financial data. This exploitation underscores the vulnerabilities inherent in AI agents that transition from passive content reading to active task execution. The incident highlights the critical need for robust security measures as AI agents become more autonomous and integrated into enterprise workflows. With the projected growth of AI agents in enterprises, securing these systems against such sophisticated attacks is paramount to prevent potential data breaches and operational disruptions.
1 month ago
Kill Chain
Urgent: CVE-2026-8037 Vulnerability in Progress Kemp LoadMaster Under Active Exploitation
In June 2026, a critical security vulnerability identified as CVE-2026-8037 was discovered in Progress Kemp LoadMaster, an application delivery controller widely used in enterprise environments. This OS command injection flaw allows unauthenticated attackers to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple API command endpoints. The vulnerability affects LoadMaster versions GA v7.2.63.1 and earlier, as well as LTSF v7.2.54.17 and earlier. Exploitation attempts were first observed on June 29, 2026, originating from specific IP addresses, though initial attempts were unsuccessful. ([thehackernews.com](https://thehackernews.com/2026/07/latest-progress-kemp-loadmaster-pre.html?utm_source=openai)) The availability of a proof-of-concept exploit and detailed technical analyses has heightened the risk of successful attacks. Organizations using affected LoadMaster versions are urged to apply the patches released by Progress Kemp immediately and restrict API access to trusted networks to mitigate potential exploitation. ([qpulse.quasarcybertech.com](https://qpulse.quasarcybertech.com/news/4414/critical-unauthenticated-rce-vulnerability-in-progress-kemp-loadmaster-cve-2026-8037?utm_source=openai))
1 month ago
Kill Chain
Critical Vulnerabilities in Cursor AI Code Editor Expose Developers to Remote Code Execution
In June 2026, two critical vulnerabilities, CVE-2026-50548 and CVE-2026-50549, were discovered in Cursor, an AI-powered code editor. These flaws allowed malicious agents to bypass the application's sandbox protections, enabling unauthorized execution of commands on a developer's machine without user interaction. The vulnerabilities stemmed from improper handling of the working directory and symlink resolution, permitting attackers to write arbitrary files outside the intended workspace, leading to potential remote code execution. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-50549?utm_source=openai)) The discovery of these vulnerabilities underscores the growing risks associated with AI-integrated development tools. As AI becomes more embedded in software development, ensuring the security of such tools is paramount to prevent exploitation by threat actors.
1 month ago
Kill Chain
Critical Vulnerabilities Discovered in OFFIS DCMTK Toolkit Used in Medical Imaging
In June 2026, multiple critical vulnerabilities were identified in the OFFIS DCMTK Toolkit, a widely used DICOM toolkit in medical imaging software. These vulnerabilities, including CVE-2026-50003, CVE-2026-50254, CVE-2026-35505, CVE-2026-52868, and CVE-2026-44628, could allow attackers to write files outside intended directories, access unauthorized information, exhaust memory, or crash affected DCMTK client or server processes. The vulnerabilities affect DCMTK versions up to 3.7.0. ([hipaajournal.com](https://www.hipaajournal.com/offis-dcmtk-vulnerabilities-june-2026/?utm_source=openai)) The healthcare sector's reliance on DICOM standards for medical imaging makes these vulnerabilities particularly concerning. Exploitation could lead to unauthorized access to sensitive patient data and disruption of critical medical services. Organizations using affected versions are urged to apply the provided patches promptly to mitigate potential risks.
1 month ago
Kill Chain
Critical Vulnerabilities in Schneider Electric's EasyLogic T150 and Saitel DP RTUs
In June 2026, Schneider Electric disclosed two critical vulnerabilities affecting their EasyLogic T150 and Saitel DP Remote Terminal Units (RTUs). The first, CVE-2026-9650, involves insufficiently protected credentials, allowing unauthenticated attackers to access sensitive information stored within firmware or system files. The second, CVE-2026-9651, pertains to incorrect permission assignments for critical resources, enabling attackers with privileged local access to read improperly protected system files, potentially leading to account compromise. These vulnerabilities pose significant risks to critical infrastructure sectors, including manufacturing and energy, as they could lead to unauthorized access and control over essential systems. The disclosure of these vulnerabilities underscores the ongoing challenges in securing industrial control systems (ICS). As cyber threats targeting ICS continue to evolve, organizations must remain vigilant, regularly updating and patching their systems to mitigate potential risks. This incident highlights the importance of proactive cybersecurity measures and the need for continuous monitoring to protect critical infrastructure from emerging threats.
1 month ago
Kill Chain
MetaMask Users Targeted in Sophisticated Phishing Attack - July 2026
In July 2026, a sophisticated phishing campaign targeted MetaMask users by sending emails that falsely claimed their cryptocurrency wallets were at risk. The emails pressured recipients to provide their secret recovery phrases under the guise of securing their accounts. The attackers utilized a recently registered domain, captchasolve[.]help, to host the phishing site, effectively deceiving users into compromising their wallets. This incident underscores the evolving tactics of cybercriminals in exploiting user trust and the critical importance of safeguarding recovery phrases. ([isc.sans.edu](https://isc.sans.edu/diary/TA551%2B?utm_source=openai)) The prevalence of such targeted phishing attacks highlights the urgent need for enhanced user education on recognizing and avoiding social engineering schemes. As cryptocurrency adoption grows, both individuals and organizations must implement robust security measures and remain vigilant against deceptive practices that aim to exploit human vulnerabilities.
1 month ago
Kill Chain
Citrix NetScaler Vulnerability CVE-2026-8451: Critical Memory Disclosure Flaw
In June 2026, Citrix disclosed six vulnerabilities in its NetScaler ADC and NetScaler Gateway appliances, notably CVE-2026-8451, a high-severity memory disclosure flaw. This vulnerability arises from improper parsing of SAML authentication requests when the appliance is configured as a SAML identity provider, potentially allowing unauthenticated attackers to access sensitive memory contents. The flaw shares similarities with the 2023 'CitrixBleed' incident, which also involved memory management issues in NetScaler products. The disclosure underscores ongoing challenges in securing critical network infrastructure. Organizations relying on NetScaler appliances should promptly apply the provided patches and review their configurations to mitigate potential exploitation risks.
1 month ago
Kill Chain
ARToken: The Next Evolution in BEC-as-a-Service Platforms
In April 2026, Cisco Talos identified ARToken, a sophisticated phishing platform linked to the EvilTokens phishing-as-a-service operation. ARToken is designed to bypass multi-factor authentication and compromise Microsoft 365 accounts, featuring advanced capabilities such as inbox rule manipulation and shared access links. The platform employs a seven-layer anti-analysis system to evade detection, and its phishing lures are highly targeted, often impersonating legitimate vendor communications to deceive accounts-payable staff into processing fraudulent invoices. The emergence of ARToken underscores a significant evolution in business email compromise (BEC) tactics, highlighting the increasing sophistication and accessibility of phishing-as-a-service platforms. This development poses a heightened risk to organizations, emphasizing the need for enhanced email security measures and employee vigilance against such targeted attacks.
1 month ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

