✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 673 to 684 of 5051
Black Basta Ransomware Group: A Comprehensive Analysis of Its Rise and Fall
Black Basta, a ransomware-as-a-service (RaaS) group, emerged in April 2022 and rapidly became a significant threat by employing double extortion tactics—encrypting victims' data and exfiltrating sensitive information to pressure organizations into paying ransoms. The group targeted over 500 organizations worldwide across various critical infrastructure sectors, including healthcare, finance, and manufacturing. Their operations involved sophisticated social engineering techniques, exploitation of known vulnerabilities, and partnerships with malware distributors like QakBot to gain initial access. In 2025, internal conflicts and law enforcement actions led to a decline in Black Basta's activities, culminating in the group's shutdown. ([techrepublic.com](https://www.techrepublic.com/article/black-basta-ransomware-attack/?utm_source=openai)) The Black Basta case underscores the evolving nature of ransomware threats, highlighting the importance of robust cybersecurity measures and proactive threat intelligence to defend against sophisticated cybercriminal operations. The group's rapid rise and eventual downfall illustrate the dynamic landscape of cyber threats and the necessity for organizations to remain vigilant and adaptable.
1 month ago
Kill Chain
KDDI Data Breach Exposes 14.2 Million Email Logins Across Six ISPs
In June 2026, KDDI Corporation, a major Japanese telecommunications operator, disclosed a data breach affecting its email systems used by six internet service providers (ISPs). The breach, discovered on June 17, resulted from attackers exploiting a vulnerability in third-party software, potentially exposing up to 14.2 million email addresses and passwords. The affected ISPs include STNet, JCOM, Chubu Telecommunications, NIFTY, BIGLOBE, and KDDI Web Communications. KDDI promptly blocked the attacker and implemented defensive measures upon detection. This incident underscores the critical importance of securing third-party software components within shared infrastructure environments. As cyber threats continue to evolve, organizations must rigorously assess and monitor the security of all integrated software solutions to prevent similar breaches.
1 month ago
Kill Chain
Urgent Alert: Oracle E-Business Suite Vulnerability Under Active Exploitation
In late June 2026, threat intelligence firm Defused reported active exploitation of a critical vulnerability (CVE-2026-46817) in Oracle E-Business Suite's Payments component. This flaw, present in versions 12.2.3 through 12.2.15, allows unauthenticated attackers with HTTP access to execute remote code, potentially leading to full system compromise. Oracle had addressed this issue in their May 2026 Critical Security Patch Update, urging immediate patching. Despite this, numerous unpatched systems remain exposed, with over 450 Oracle EBS instances accessible online, nearly 200 of which are in the United States and Europe. The active exploitation of CVE-2026-46817 underscores the critical importance of timely patch management. Organizations using Oracle E-Business Suite must prioritize applying the latest security updates to mitigate this severe risk. Additionally, this incident highlights the broader trend of attackers targeting unpatched enterprise applications, emphasizing the need for robust vulnerability management practices.
1 month ago
Kill Chain
U.S. Offers $10 Million Reward for Information on Russian Hackers Targeting Encrypted Messaging Apps
In June 2026, the U.S. Department of State announced a reward of up to $10 million for information leading to the identification or location of members of the Russian-linked cyber groups UNC5792 and UNC4221. These groups have been implicated in extensive phishing campaigns targeting Signal and WhatsApp accounts of U.S. government officials, military leaders, and allied personnel. The attackers employed social engineering tactics, impersonating support agents to deceive users into revealing their backup recovery keys, thereby gaining access to their encrypted communications. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/us-offers-10-million-for-hackers-targeting-whatsapp-signal-users/?utm_source=openai)) This incident underscores the evolving nature of cyber threats, particularly the sophisticated use of social engineering to bypass encryption safeguards. It highlights the critical need for heightened vigilance and robust security protocols to protect sensitive communications, especially for individuals in positions of authority or influence.
1 month ago
Kill Chain
Nissan Employee Data Breach Exposes Sensitive Information via Oracle PeopleSoft Exploit
In June 2026, Nissan disclosed a data breach affecting current and former employees across the United States, Canada, Mexico, and Brazil. The breach occurred between May 27 and June 9, 2026, when threat actors exploited a zero-day vulnerability (CVE-2026-35273) in Oracle's PeopleSoft software, which Nissan uses to manage employee information. The attackers, identified as the ShinyHunters extortion group, accessed sensitive personal data, including contact details, banking information, Social Security numbers, and tax information. Nissan promptly activated its incident response plan, engaged external cybersecurity experts, secured affected systems, and is collaborating with Oracle to address the issue. The company is offering free credit and dark web monitoring services to affected individuals and has implemented additional security measures to prevent further unauthorized access. This incident underscores the critical importance of promptly addressing software vulnerabilities and implementing robust security measures to protect sensitive employee data. The exploitation of a zero-day vulnerability by a known threat actor highlights the evolving tactics of cybercriminals and the necessity for organizations to remain vigilant and proactive in their cybersecurity efforts.
1 month ago
Kill Chain
NAIC's 2026 Data Breach: A ShinyHunters Exploit of Oracle PeopleSoft
In June 2026, the National Association of Insurance Commissioners (NAIC) experienced a cyberattack by the ShinyHunters group, who exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft servers. The attackers claimed to have stolen 3.1 TB of data, including insurer regulatory filings and AWS infrastructure configurations. NAIC's investigation indicated that only publicly available data, outdated logs, and configuration files were accessed, with no evidence of personal or financial data exposure. The breach led to operational disruptions, such as temporary suspension of data feeds by credit rating agencies and a pause in NAIC's investment designation work. This incident underscores the critical importance of promptly addressing zero-day vulnerabilities and implementing robust security measures to protect sensitive data. Organizations must remain vigilant against sophisticated threat actors like ShinyHunters, who continue to exploit unpatched systems, emphasizing the need for proactive cybersecurity strategies and timely software updates.
1 month ago
Kill Chain
Mustang Panda's Exploitation of Zoho WorkDrive in Indian Government Cyberattacks
In June 2026, the China-aligned cyber espionage group Mustang Panda launched two concurrent campaigns targeting Indian government entities and the hydropower sector. Utilizing spear-phishing emails with thematic lures, the attackers delivered ZIP archives containing SHARDLOADER, a malicious loader that deployed two new implants: MINIRECON and ZOHOMURK. Notably, ZOHOMURK exploited Zoho WorkDrive, a legitimate cloud storage service, for command-and-control operations, enabling data exfiltration and remote task execution while evading detection by blending with normal network traffic. This incident underscores the evolving tactics of state-sponsored threat actors who increasingly abuse trusted cloud services to conceal malicious activities. Organizations, especially those in critical infrastructure sectors, must enhance their security measures to detect and mitigate such sophisticated threats.
1 month ago
Kill Chain
Malicious Perplexity Chrome Extension Compromises User Data
In June 2026, Microsoft identified a malicious Chrome extension named "Search for perplexity ai" that impersonated the AI search engine Perplexity. This extension intercepted users' search queries and address bar inputs, routing them through an attacker-controlled server before redirecting to legitimate search results. The extension set itself as the default search engine upon installation, capturing every character typed into the address bar and transmitting this data, along with browser headers, IP addresses, and user agents, to the attacker's server. Microsoft reported the extension to Google, leading to its removal from the Chrome Web Store. ([thehackernews.com](https://thehackernews.com/2026/06/malicious-perplexity-chrome-extension.html?utm_source=openai)) This incident underscores a growing trend of malicious browser extensions exploiting the popularity of AI tools to harvest sensitive user data. Similar campaigns have targeted users by masquerading as AI assistants, leading to significant data breaches. Organizations must remain vigilant, implementing strict policies on browser extensions and educating users about the risks associated with unverified add-ons. ([techradar.com](https://www.techradar.com/pro/security/fake-chrome-ai-extensions-targeted-over-300-000-users-to-steal-emails-personal-data-and-more?utm_source=openai))
1 month ago
Kill Chain
AWS Threat Technique Catalog June 2026 Update: Enhancing Your AWS Security Posture
In June 2026, the AWS Customer Incident Response Team (AWS CIRT) updated the Threat Technique Catalog (TTC) to address emerging security challenges in container security, organizational trust, and compute hijacking. The update introduces five new entries: EKS workload modification, exploitation of public-facing applications in EKS, assuming root access into organization member accounts, compute hijacking in EKS, and inviting accounts to unknown organizations. These techniques reflect real-world incidents where threat actors exploit legitimate AWS functionalities to compromise environments, emphasizing the need for robust security measures and vigilant monitoring. This update underscores a trend where attackers leverage standard cloud operations to evade detection, highlighting the importance for organizations to enhance their security postures by implementing controls such as admission controllers, service control policies, and resource quotas, and by actively monitoring for anomalous activities within their AWS environments.
1 month ago
Kill Chain
Critical Vulnerability in Amazon Q Developer's VS Code Extension Exposes Cloud Credentials
In June 2026, a high-severity vulnerability (CVE-2026-12957) was discovered in Amazon Q Developer's Visual Studio Code extension. This flaw allowed attackers to execute arbitrary code and steal cloud credentials by convincing developers to open malicious repositories. The issue stemmed from the extension's handling of Model Context Protocol (MCP) servers, which automatically loaded and executed configurations from workspace files without user approval, leading to potential exposure of sensitive information such as AWS credentials and API keys. AWS addressed the vulnerability by releasing an update to Language Server version 1.65.0. This incident highlights the growing risks associated with AI coding tools and the importance of scrutinizing their integration into development environments. Organizations are urged to treat AI tools with environment access as potential security risks and implement appropriate guardrails to prevent unauthorized access and data exfiltration.
1 month ago
Kill Chain
Hijacked npm and Go Packages Exploit VS Code to Deploy Python Infostealer
In June 2026, cybersecurity researchers identified a sophisticated supply chain attack involving hijacked npm and Go packages designed to deploy a Python-based information stealer across Windows, Linux, and macOS systems. The attackers embedded malicious code within Visual Studio Code (VS Code) tasks, configured to execute automatically when a project folder was opened. This method bypassed traditional npm execution paths, allowing the malware to retrieve encrypted JavaScript from blockchain transactions, establish a backdoor via socket.io, and ultimately deploy the Python infostealer. The compromised npm packages, 'html-to-gutenberg' and 'fetch-page-assets', were uploaded on May 25, 2026, and have since been removed from the registry. This incident underscores a growing trend of attackers exploiting development environments and tools to infiltrate systems, highlighting the need for enhanced security measures within the software supply chain. The use of blockchain as a resilient command-and-control mechanism further complicates detection and mitigation efforts, emphasizing the importance of vigilance and proactive defense strategies among developers and organizations.
1 month ago
Kill Chain
Microsoft Eliminates 119 Malicious Edge Extensions Concealing Malware
In June 2026, Microsoft identified and removed 119 malicious extensions from the Edge Add-ons store, collectively known as 'StegoAd.' These extensions, active since at least 2021, utilized steganography to conceal malware within image and font files. After installation, the malware remained dormant, later activating to steal user credentials and conduct ad fraud. The affected extensions, including ad blockers, VPNs, translators, and video downloaders, amassed up to 2.6 million installations. The exact number of compromised users remains undetermined. This incident underscores the evolving sophistication of cyber threats, particularly in the realm of browser extensions. The use of steganography to evade detection highlights the need for enhanced security measures and vigilant monitoring of third-party add-ons. Organizations must prioritize the implementation of robust security protocols to mitigate such risks.
1 month ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

