✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 709 to 720 of 5051
StrikeShark Campaign Unleashes SharkLoader to Deploy Cobalt Strike Beacons
In June 2026, a cyber attack campaign named StrikeShark was identified, deploying a new malware loader called SharkLoader to deliver Cobalt Strike Beacons on compromised systems. The campaign targeted a diverse range of entities, including diplomatic organizations in Indonesia, government bodies in Taiwan, and software development companies across multiple countries. Attackers exploited known vulnerabilities in Microsoft Exchange Server (CVE-2021-26855), Openfire (CVE-2023-32315), and GeoServer (CVE-2024-36401) to gain initial access, subsequently establishing persistence through web shells and DLL side-loading techniques. The use of open-source post-compromise tools like FScan and Pillager suggests potential involvement of Chinese-speaking threat actors. This incident underscores the persistent threat posed by sophisticated malware loaders and the exploitation of known vulnerabilities. Organizations must prioritize timely patching and employ robust detection mechanisms to mitigate such risks. The broad geographic reach and diverse target set of this campaign highlight the evolving tactics of threat actors in the current cyber threat landscape.
1 month ago
Kill Chain
Persistent Cyber Scam Centers in Asia Despite Crackdowns
In June 2026, reports from INTERPOL and Amnesty International highlighted the persistent and escalating issue of cyber scam centers across Asia, particularly in Cambodia, Myanmar, Laos, and the Philippines. Despite high-profile crackdowns and arrests, these operations continue to thrive, generating an estimated $40 billion annually through schemes like romance fraud and investment scams. The resilience of these criminal enterprises is largely attributed to local corruption and collusion with law enforcement, which undermine efforts to dismantle them. ([interpol.int](https://www.interpol.int/News-and-Events/News/2026/New-INTERPOL-report-highlights-escalating-cyber-threats-across-Asia-and-South-Pacific?utm_source=openai)) This situation underscores the urgent need for enhanced international cooperation and robust anti-corruption measures. The continued operation of these scam centers not only results in significant financial losses globally but also involves severe human rights abuses, including human trafficking and forced labor. Addressing this issue is critical to protecting vulnerable populations and maintaining global cybersecurity. ([amnesty.org](https://www.amnesty.org/en/latest/news/2026/06/cambodia-evidence-suggests-scamming-compounds-bypassed-despite-high-profile-crackdown/?utm_source=openai))
1 month ago
Kill Chain
Instructure's Canvas LMS Breached Twice by ShinyHunters in 2026
In early May 2026, Instructure's Canvas learning management system (LMS) suffered two significant cyberattacks orchestrated by the ShinyHunters group. The initial breach on April 29 led to the exfiltration of personal data from approximately 275 million users across nearly 9,000 educational institutions. Compromised information included names, email addresses, student ID numbers, and private messages. Despite Instructure's remediation efforts, ShinyHunters executed a second attack on May 7, defacing Canvas login pages to pressure the company into paying a ransom. In response, Instructure reached an agreement with the attackers, resulting in the return and purported destruction of the stolen data. ([techcrunch.com](https://techcrunch.com/2026/05/12/instructure-strikes-deal-with-hackers-who-breached-it-twice/?utm_source=openai)) This incident underscores a growing trend where cybercriminals target educational technology vendors to exploit vulnerabilities and access vast amounts of sensitive data. The attacks on Instructure highlight the critical need for robust cybersecurity measures within the edtech sector to protect against such large-scale breaches.
1 month ago
Kill Chain
Gamaredon's 2025 Spearphishing Escalation: A Wake-Up Call for Cybersecurity
In 2025, the Russian state-sponsored APT group Gamaredon intensified its cyber espionage activities against Ukrainian governmental institutions. The group launched numerous spearphishing campaigns, introducing six new malware tools leveraging PowerShell and VBScript to enhance stealth, persistence, and lateral movement. Notably, Gamaredon concealed its command-and-control infrastructure behind Cloudflare tunnels and utilized third-party services like Telegram and Dropbox to obfuscate its operations. ([eset.com](https://www.eset.com/uk/about/newsroom/press-releases/eset-research-russias-gamaredon-apt-group-unleashed-spearphishing-campaigns-against-ukraine-with-an-evolved-toolset-uk/?utm_source=openai)) This escalation underscores the evolving threat landscape, highlighting the need for organizations to adopt advanced detection and response strategies to counter sophisticated state-sponsored cyber threats.
1 month ago
Kill Chain
Operation Endgame: A Landmark Blow to Cybercriminal Networks in 2026
In June 2026, Europol, in collaboration with international law enforcement agencies and private sector partners, executed Operation Endgame, a coordinated effort targeting the infrastructure supporting the SocGholish, Amadey, and StealC malware networks. This operation led to the dismantling of 326 servers and 142 domains, the recovery of 27 million stolen login credentials, and the seizure of over €41 million in cryptocurrency assets. The SocGholish malware, linked to the Russian cybercriminal group Evil Corp, had compromised nearly 15,000 legitimate websites to distribute malicious software. Amadey and StealC were utilized to gain initial access to systems and exfiltrate sensitive data, respectively. ([europol.europa.eu](https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks?utm_source=openai)) This operation signifies a strategic shift in combating cybercrime by disrupting entire malware ecosystems rather than focusing on individual threats. The success of Operation Endgame underscores the effectiveness of international cooperation and public-private partnerships in addressing large-scale cyber threats. ([europol.europa.eu](https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks?utm_source=openai))
1 month ago
Kill Chain
Turla's STOCKSTAY Backdoor: A New Cyber Espionage Threat
In June 2026, Google's Threat Intelligence Group identified a new .NET backdoor named STOCKSTAY, attributed to the Russian state-sponsored group Turla. This malware has been deployed against government and military organizations in Ukraine and entities interested in Italian foreign policy. STOCKSTAY, developed since at least December 2022, shares significant code and functional overlaps with Turla's previous implant, Kazuar. The backdoor comprises multiple components that communicate via inter-process communication channels and utilize secure WebSocket connections for command-and-control communication. It supports various commands, including file manipulation, system information gathering, and screen capture. ([cloud.google.com](https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering/?utm_source=openai)) The discovery of STOCKSTAY underscores the evolving sophistication of state-sponsored cyber espionage tools. Its deployment highlights the persistent threat posed by advanced persistent threats (APTs) like Turla, emphasizing the need for robust cybersecurity measures and continuous monitoring to protect sensitive governmental and military information.
1 month ago
Kill Chain
Microsoft Alerts Hospitality Sector to Advanced Phishing Threat
Since April 2026, a sophisticated phishing campaign has been targeting hotel and hospitality organizations across Europe and Asia. Attackers send emails impersonating 'Booking Manager (via Calendly)' with subjects referencing guest complaints or health inspections. These emails contain links leading to ZIP files named 'photo-<numbers>.zip,' which, when opened, execute a Node.js-based remote access trojan (RAT) called TonRAT. The malware establishes command-and-control channels through the TON blockchain API, complicating detection and mitigation efforts. This incident underscores the evolving tactics of cybercriminals who exploit trusted platforms like Calendly and Google’s URL redirect services to bypass traditional email security measures. The use of Node.js implants and blockchain-based command-and-control mechanisms highlights the need for organizations to enhance their cybersecurity defenses against increasingly sophisticated phishing campaigns.
1 month ago
Kill Chain
Russia's Unauthorized Use of Cellebrite Tools on Activist's iPhone
In June 2021, Russian authorities utilized Cellebrite's Universal Forensic Extraction Device (UFED) to access the iPhone of detained opposition activist Andrey Pivovarov. This occurred three months after Cellebrite announced the cessation of sales and services to Russian government clients in March 2021. Forensic evidence and Russian court documents confirm that investigators extracted data, including WhatsApp and Telegram messages, and searched for political terms and opposition figures. This incident underscores the challenges technology vendors face in controlling the use of their tools post-sale, especially when used by authoritarian regimes. The continued operation of Cellebrite's tools in Russia, despite the termination of official support, highlights the need for more robust mechanisms to prevent misuse of surveillance technologies.
1 month ago
Kill Chain
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
In June 2026, a sophisticated supply chain attack known as 'Miasma' compromised 32 npm packages under Red Hat's @redhat-cloud-services namespace. The attackers gained access through a compromised Red Hat employee's GitHub account, allowing them to push malicious commits that bypassed standard peer reviews. These commits exploited GitHub Actions workflows to publish trojanized package versions to the public npm registry. Upon installation, these packages executed an obfuscated payload designed to steal credentials from various platforms, including GitHub, AWS, Azure, and Google Cloud Platform. The malware also attempted to propagate by compromising additional maintainer packages and, in some cases, could destroy the maintainer’s home directory. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/06/02/preinstall-persistence-inside-red-hat-npm-miasma-credential-stealing-campaign/?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting open-source ecosystems. The Miasma campaign highlights the need for enhanced security measures in CI/CD pipelines and vigilant monitoring of package repositories to prevent unauthorized access and mitigate the risk of widespread credential theft and system compromise.
1 month ago
Kill Chain
Understanding the DirtyClone Linux Kernel Vulnerability (CVE-2026-43503)
In June 2026, a critical Linux kernel vulnerability known as 'DirtyClone' (CVE-2026-43503) was disclosed, allowing local users to escalate privileges to root by exploiting cloned network packets. This flaw, part of the DirtyFrag family, arises from the kernel's mishandling of shared memory flags during packet cloning, enabling unauthorized memory corruption. The vulnerability affects systems with unpatched kernels prior to May 21, 2026, particularly those with unprivileged user namespaces enabled, such as Debian, Ubuntu, and Fedora. The disclosure of DirtyClone underscores the persistent challenges in securing kernel-level code, especially concerning memory management and privilege escalation. This incident highlights the necessity for organizations to promptly apply security patches and reassess configurations that permit unprivileged user namespaces, to mitigate potential exploitation risks.
1 month ago
Kill Chain
Amazon Q Developer Vulnerability CVE-2026-12957: What You Need to Know
In June 2026, a critical vulnerability (CVE-2026-12957) was identified in Amazon Q Developer's handling of Model Context Protocol (MCP) servers. This flaw allowed malicious repositories to execute arbitrary commands on a developer's machine upon opening and trusting a workspace, potentially leading to unauthorized access to cloud credentials. The issue was promptly addressed by Amazon with the release of Language Servers for AWS version 1.69.0, mitigating the risk of exploitation. This incident underscores the growing security challenges associated with AI-powered development tools. As these tools become more integrated into the software development lifecycle, ensuring robust security measures and prompt patching of vulnerabilities is imperative to protect sensitive data and maintain trust in development environments.
1 month ago
Kill Chain
Critical Vulnerabilities in Daktronics Controller Firmware Threaten Industrial Systems
In June 2026, multiple critical vulnerabilities were identified in Daktronics Controller Firmware, affecting versions of VFC-DMP-5000, DMP-5000, and DMP-8000. These vulnerabilities include path traversal (CVE-2026-28701), unrestricted file upload (CVE-2026-33560), and hard-coded credentials (CVE-2026-31928). Exploitation could grant unauthenticated users root-level access, compromising system integrity and control. ([daktronics.com](https://www.daktronics.com/en-us/support/kb/000031233?utm_source=openai)) The discovery underscores the persistent risks in industrial control systems, emphasizing the need for timely firmware updates and robust security practices to mitigate potential threats.
1 month ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

