✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 685 to 696 of 5051
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
In June 2026, a critical vulnerability identified as CVE-2026-55200 was discovered in libssh2 versions up to and including 1.11.1. This flaw resides in the ssh2_transport_read() function, which fails to properly validate the packet_length field in incoming SSH packets. As a result, remote attackers can send specially crafted SSH packets with excessively large packet_length values, leading to heap memory corruption and potential remote code execution without requiring authentication or user interaction. The issue was addressed in commit 7acf3df. The release of a public proof-of-concept (PoC) exploit for this vulnerability has heightened the risk of widespread exploitation. Given libssh2's integration into numerous applications and systems, including curl, Git, PHP, and various backup agents, the potential attack surface is extensive. Organizations are urged to assess their environments for affected versions and apply the necessary patches promptly to mitigate the risk of compromise.
1 month ago
Kill Chain
Gamaredon's 2025 Cyber Offensive: Unveiling New Malware and Tactics
In 2025, the Russian-aligned APT group Gamaredon intensified its cyber operations against Ukrainian governmental and military institutions. ESET observed 35 distinct spear-phishing campaigns, primarily in the latter half of the year, utilizing archive attachments and XHTML files with HTML smuggling to deploy malicious HTA downloaders. These campaigns aimed to exfiltrate sensitive information to support Russian interests in the ongoing conflict. Gamaredon also exploited a WinRAR vulnerability (CVE-2025-8088) to achieve persistence by placing malicious files in the Windows Startup folder. Additionally, the group introduced six new PowerShell tools, including PteroDee and PteroCache, to enhance their malware arsenal. ([thehackernews.com](https://thehackernews.com/2026/06/gamaredon-expands-ukraine-attacks-with.html?utm_source=openai)) The group's reliance on third-party services grew significantly, employing tunnel services and serverless platforms to conceal their infrastructure. This evolution underscores the increasing sophistication of state-sponsored cyber threats and the necessity for robust cybersecurity measures to protect sensitive governmental data. ([thehackernews.com](https://thehackernews.com/2026/06/gamaredon-expands-ukraine-attacks-with.html?utm_source=openai))
1 month ago
Kill Chain
Critical DirtyClone Vulnerability in Linux Kernel (CVE-2026-43503) Exposes Systems to Root Access
In June 2026, a critical vulnerability known as DirtyClone (CVE-2026-43503) was discovered in the Linux kernel, allowing local users to escalate privileges to root by exploiting cloned network packets. This flaw, a variant of the earlier DirtyFrag vulnerability, affects multiple Linux distributions, including Debian, Ubuntu, and Fedora. The vulnerability arises from the kernel's mishandling of shared socket-buffer fragments during network packet processing, enabling attackers to manipulate the Linux page cache and gain unauthorized access. ([thehackernews.com](https://thehackernews.com/2026/06/new-dirtyclone-linux-kernel-flaw-lets.html?utm_source=openai)) The emergence of DirtyClone underscores the persistent challenges in securing the Linux kernel against privilege escalation attacks. With the increasing adoption of multi-tenant cloud environments and containerized workloads, the risk of such vulnerabilities being exploited has escalated, highlighting the need for prompt patching and vigilant system monitoring. ([securityweek.com](https://www.securityweek.com/dirtyclone-linux-kernel-vulnerability-leads-to-root-access/?utm_source=openai))
1 month ago
Kill Chain
The Critical Shift to Post-Quantum Cryptography for Credential Security
In June 2026, cybersecurity experts highlighted the imminent threat posed by quantum computing to current cryptographic systems, particularly those safeguarding credentials. As quantum hardware advances, algorithms like RSA and elliptic curve cryptography, which protect sensitive data, are at risk of being compromised. This vulnerability underscores the urgency for organizations to transition to post-quantum cryptography (PQC) to maintain data confidentiality and integrity. ([thehackernews.com](https://thehackernews.com/2026/06/why-post-quantum-cryptography-starts.html?utm_source=openai)) The relevance of this issue is amplified by the increasing prevalence of 'harvest now, decrypt later' attacks, where adversaries collect encrypted data today, anticipating future quantum capabilities to decrypt it. This trend necessitates immediate action to adopt PQC solutions to safeguard long-term data security. ([thehackernews.com](https://thehackernews.com/2026/06/why-post-quantum-cryptography-starts.html?utm_source=openai))
1 month ago
Kill Chain
Massive Crypto Scam Operation Exploits DCloud Uni-App Framework
In June 2026, cybersecurity firm Infoblox uncovered that over 236,000 websites were utilizing investment scam templates built with the DCloud Uni-App framework. These sites facilitated a range of fraudulent activities, including fake cryptocurrency exchanges, phishing schemes, and crypto wallet drainers. The malicious domains spanned multiple continents and languages, indicating a coordinated effort by various threat actors. Notably, the RainbowEx platform, implicated in a Ponzi scheme affecting thousands in Argentina in late 2024, was among the identified domains. ([thehackernews.com](https://thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html?utm_source=openai)) The exploitation of legitimate development frameworks like DCloud Uni-App underscores the evolving tactics of cybercriminals. This incident highlights the critical need for organizations to implement robust security measures, including thorough vetting of third-party tools and continuous monitoring for suspicious activities. ([thehackernews.com](https://thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html?utm_source=openai))
1 month ago
Kill Chain
Russian Intelligence Exploits Fake Support Texts to Breach Messaging Accounts
In June 2026, the Security Service of Ukraine (SSU), in collaboration with the U.S. Federal Bureau of Investigation (FBI), uncovered a prolonged cyber espionage campaign orchestrated by Russian intelligence services. This operation targeted government officials, military personnel, politicians, and activists across Ukraine, Europe, and the United States. The attackers employed social engineering tactics, sending SMS messages that impersonated messaging platform support services to deceive recipients into divulging their account credentials. The primary objective was to access sensitive military, political, and economic information, as well as personal data. ([thehackernews.com](https://thehackernews.com/2026/06/ukraine-says-russian-intelligence-used.html?utm_source=openai)) This incident underscores the escalating sophistication of state-sponsored cyber threats, particularly those leveraging social engineering to exploit human vulnerabilities. Organizations and individuals must remain vigilant, adopting robust security measures such as two-factor authentication and regular monitoring of account activities to mitigate the risks posed by such targeted attacks.
1 month ago
Kill Chain
Exploiting AI Coding Agents: The New Frontier in Supply Chain Attacks
In June 2026, researchers at Mozilla's Zero Day Investigative Network (0DIN) identified a novel supply chain attack targeting AI coding agents. The attack involved a seemingly benign GitHub repository containing standard setup instructions. When an AI coding agent, such as Claude Code, cloned and initialized the repository, it encountered an error message prompting the execution of an initialization command. This command triggered a shell script that retrieved and executed a payload from a DNS TXT record controlled by the attacker, resulting in the establishment of an interactive shell on the developer's machine. This method allowed attackers to gain unauthorized access to sensitive information without any malicious code present in the repository itself. This incident underscores the evolving sophistication of supply chain attacks, particularly those exploiting AI-driven development tools. As AI coding agents become more integrated into software development workflows, they present new vectors for exploitation. Organizations must enhance their security protocols to address these emerging threats, ensuring that AI tools are configured to disclose and verify the full execution chain of setup commands to prevent unauthorized code execution.
1 month ago
Kill Chain
ShinyHunters' Breach of Instructure's Canvas Platform Highlights Third-Party Risks in Education
In May 2026, the cybercriminal group ShinyHunters breached Instructure, the company behind the widely used learning management system Canvas, affecting numerous educational institutions. The attackers demanded a ransom, threatening to leak sensitive data if unpaid. This incident underscores the vulnerability of the education sector to third-party breaches, given its reliance on external vendors for critical services. ([insidehighered.com](https://www.insidehighered.com/news/tech-innovation/administrative-tech/2026/05/05/pay-or-leak-hackers-target-big-higher-ed-vendor?utm_source=openai)) The breach highlights the urgent need for educational institutions to enhance their third-party risk management strategies. As cyber threats targeting third-party vendors increase, schools must implement robust security measures and establish comprehensive incident response plans to mitigate potential damages.
1 month ago
Kill Chain
Critical Vulnerability in Yokogawa FAST/TOOLS and CI Server Exposes Sensitive Information
In June 2026, a critical vulnerability (CVE-2026-11833) was identified in Yokogawa's FAST/TOOLS and Collaborative Information Server (CI Server). The web server component of these systems could return HTTP responses containing sensitive configuration information without requiring authentication. This flaw, present in FAST/TOOLS versions R9.01 through R10.04 and CI Server versions R1.01 through R1.04, exposes system settings that attackers could exploit for further attacks. The vulnerability has been assigned a CVSS 4.0 score of 8.2, indicating high severity. This incident underscores the ongoing risks associated with cleartext transmission of sensitive information in industrial control systems. Organizations utilizing these Yokogawa products should prioritize applying the recommended updates to mitigate potential exploitation and enhance their cybersecurity posture.
1 month ago
Kill Chain
Critical Security Flaws Discovered in EVoke Systems' Charging Station Management System
In June 2026, multiple critical vulnerabilities were identified in EVoke Systems' Charging Station Management System (CSMS), potentially allowing attackers to gain unauthorized administrative control over charging stations or disrupt services via denial-of-service attacks. The vulnerabilities include missing authentication for critical functions, improper restriction of excessive authentication attempts, insufficient session expiration, and insufficiently protected credentials. These flaws affect all versions of EVoke CSMS and pose significant risks to the energy and transportation sectors worldwide. The discovery of these vulnerabilities underscores the growing cybersecurity challenges in the electric vehicle infrastructure. As the adoption of EVs accelerates, ensuring the security of charging networks becomes paramount to prevent potential disruptions and safeguard user data.
1 month ago
Kill Chain
Critical Vulnerability in Horner Automation Cscape: CVE-2026-12897
In June 2026, a critical vulnerability (CVE-2026-12897) was identified in Horner Automation's Cscape software versions prior to 10.2 SP3. This out-of-bounds read flaw in the CSP file parser could allow local attackers to disclose sensitive information and execute arbitrary code. The vulnerability was reported by Michael Heinzl and has a CVSS v3 score of 7.8, indicating high severity. Horner Automation has released Cscape 10.2 SP3 to address this issue. This incident underscores the importance of timely software updates in industrial control systems. As cyber threats targeting critical manufacturing sectors increase, organizations must prioritize patch management and implement robust security measures to protect against potential exploits.
1 month ago
Kill Chain
Schneider Electric PowerLogic P7 Vulnerabilities Disclosed in 2026
In June 2026, Schneider Electric disclosed multiple vulnerabilities in its PowerLogic™ P7 product, including CVE-2026-9716 (NULL Pointer Dereference), CVE-2026-9717 (OS Command Injection), and CVE-2026-9718 (Reachable Assertion). These vulnerabilities could lead to denial-of-service conditions, unauthorized command execution, and system instability. Affected versions include PowerLogic™ P7 version 0.2.003.001.000 and prior. Schneider Electric has released firmware version V02.004.001 to address these issues. Organizations are advised to apply the update promptly to mitigate potential risks. ([radar.offseq.com](https://radar.offseq.com/threat/multiple-vulnerabilities-on-powerlogic-p7-e233bd41?utm_source=openai)) The disclosure underscores the critical importance of timely vulnerability management in industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, maintaining up-to-date systems and adhering to cybersecurity best practices are essential to safeguard operational integrity and prevent potential disruptions.
1 month ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

