✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 829 to 840 of 5051
Critical Vulnerabilities in Apollo Pharmacy's Blood Glucose Monitoring System APG-01 BT
In June 2026, vulnerabilities were identified in the Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT, specifically affecting version 0x0110_v1.1.0. These vulnerabilities, CVE-2026-50034 and CVE-2026-52866, allow attackers within Bluetooth Low Energy (BLE) range to intercept sensitive health data and disrupt device connectivity. The first vulnerability enables unauthorized access to glucose measurement values, while the second allows an attacker to monopolize the device's BLE connection, preventing legitimate use. These issues highlight the critical need for robust security measures in medical devices, especially those utilizing wireless communication protocols. As healthcare increasingly relies on connected devices, ensuring the confidentiality and availability of patient data is paramount to maintaining trust and compliance with regulatory standards.
1 month ago
Kill Chain
Critical DoS Vulnerability in Mitsubishi Electric's MELSEC iQ-F Series FX5-ENET/IP Module (CVE-2026-1876)
In March 2026, Mitsubishi Electric disclosed a high-severity denial-of-service (DoS) vulnerability (CVE-2026-1876) in its MELSEC iQ-F Series FX5-ENET/IP Ethernet Module. This flaw allows remote attackers to render the device unresponsive by continuously sending UDP packets, necessitating a system reset for recovery. The vulnerability affects all versions of the FX5-ENET/IP module, posing significant risks to industrial control systems reliant on this equipment. The incident underscores the critical importance of securing industrial control systems against network-based attacks. As similar vulnerabilities continue to emerge, organizations must proactively implement robust network security measures, including firewalls and VPNs, to mitigate potential threats and ensure operational continuity.
1 month ago
Kill Chain
Fortinet Credential Exposure 2026: Massive 'FortiBleed' Campaign
In June 2026, a significant cybersecurity incident known as 'FortiBleed' exposed credentials associated with approximately 74,000 Fortinet devices, including firewalls and VPN gateways. Security researchers discovered a massive archive containing FortiGate firewall URLs, usernames, emails, and plaintext passwords from major corporations such as Chevron, Samsung, Foxconn, and Toyota. The attackers, reportedly Russian-speaking, executed over 1.1 billion credential attempts against 320,000 FortiGate VPN instances, leading to the compromise of Active Directory environments and, in some cases, the exfiltration of classified documents. Fortinet responded by emphasizing best practices like regular credential updates and enabling multi-factor authentication (MFA) to mitigate risks. This incident underscores the critical importance of robust credential management and the implementation of MFA, especially for internet-facing systems. The scale and sophistication of the 'FortiBleed' campaign highlight the evolving tactics of cyber adversaries and the necessity for organizations to proactively secure their network infrastructures.
1 month ago
Kill Chain
Belgian Bank Customers Targeted in Sophisticated Phishing Attack Using IPv4-Mapped IPv6 Addresses
In June 2026, a phishing campaign targeted customers of a major Belgian bank by exploiting IPv4-mapped IPv6 addresses to obfuscate malicious URLs. The attackers sent emails containing links formatted as IPv6 literals, such as 'hxxp://[::ffff:5511:74be]/kWC5PHA1', which, when decoded, resolved to an IPv4 address hosting the phishing content. This technique aimed to bypass security controls that rely on detecting suspicious domain names or IP addresses. Upon clicking the link, victims were redirected to a fraudulent website designed to harvest sensitive banking credentials. The campaign underscores the evolving tactics of cybercriminals in leveraging less commonly monitored aspects of internet protocols to evade detection. ([isc.sans.edu](https://isc.sans.edu/diary/32804?utm_source=openai)) The use of IPv4-mapped IPv6 addresses in phishing attacks highlights a growing trend where attackers exploit the complexities of IPv6 to conceal malicious activities. As IPv6 adoption increases, security systems must adapt to recognize and mitigate threats that utilize these advanced obfuscation methods. Organizations are urged to enhance their monitoring capabilities to detect such techniques and educate users about the risks associated with unfamiliar URL formats.
1 month ago
Kill Chain
Critical Vulnerability in AzeoTech DAQFactory: CVE-2026-12390
In June 2026, a critical vulnerability (CVE-2026-12390) was identified in AzeoTech's DAQFactory software, versions 21.1 and prior. This Type Confusion flaw allows attackers to execute arbitrary code by tricking users into opening malicious .ctl files. The vulnerability poses significant risks to systems utilizing DAQFactory, potentially leading to unauthorized access and control. The disclosure underscores the ongoing challenges in securing industrial control systems, especially as attackers increasingly target such environments. Organizations are urged to apply recommended mitigations promptly to prevent exploitation and maintain operational integrity.
1 month ago
Kill Chain
Operation Endgame: A Major Blow to SocGholish Malware Infrastructure
In June 2026, an international law enforcement coalition comprising agencies from the Netherlands, Canada, the United States, and Germany executed Operation Endgame, targeting the SocGholish malware infrastructure. This coordinated effort led to the takedown of 106 servers and the remediation of 14,971 WordPress websites infected with SocGholish, a JavaScript-based downloader malware. SocGholish, active since 2017, masquerades as browser updates to distribute additional malicious payloads, often leading to ransomware attacks orchestrated by groups like Evil Corp. The operation significantly disrupted the malware's distribution channels, mitigating further risks to global digital systems. ([politie.nl](https://www.politie.nl/en/news/2026/june/18/international-law-enforcement-initiate-hunt-on-malware-group-socgholish.html?utm_source=openai)) The success of Operation Endgame underscores the effectiveness of international collaboration in combating cyber threats. However, the persistent evolution of malware tactics necessitates continuous vigilance and adaptive cybersecurity measures. Organizations are urged to regularly update their systems, monitor for unauthorized access, and educate users about the dangers of deceptive software updates to prevent future infections.
1 month ago
Kill Chain
Anthropic's Fable 5 AI Model Suspended Amid National Security Concerns
In June 2026, Anthropic released its advanced AI model, Fable 5, designed to autonomously identify and exploit software vulnerabilities. Shortly after its release, the U.S. government classified Fable 5 as a potential national security threat, citing concerns over its capability to be 'jailbroken' and misused by malicious actors. Consequently, Anthropic was ordered to suspend access to the model for all foreign nationals, leading the company to disable Fable 5 entirely due to the inability to selectively restrict access. This abrupt shutdown has sparked significant debate within the cybersecurity community, with experts arguing that such restrictions may hinder defensive research more than deter malicious use. The incident underscores the challenges in balancing AI innovation with national security and the need for clear regulatory frameworks to manage the dual-use nature of advanced AI technologies.
1 month ago
Kill Chain
TeamPCP's Supply Chain Attacks: A Wake-Up Call for Open-Source Security
Between February and June 2026, the cybercriminal group TeamPCP executed a series of supply chain attacks, compromising over 1,000 open-source software packages. By infiltrating widely used tools such as Trivy, Checkmarx KICS, LiteLLM, and the Telnyx Python SDK, TeamPCP exploited vulnerabilities in CI/CD pipelines and AI development tools to inject malicious code, leading to the exfiltration of sensitive data and credentials. This campaign underscored the critical weaknesses in the software supply chain, particularly the reliance on unverified code dependencies and the lack of rigorous security checks in automated deployment systems. The incident highlights the urgent need for organizations to reassess their software development practices, emphasizing the importance of verifying the integrity of open-source components and implementing robust security measures within CI/CD pipelines. As supply chain attacks become more prevalent, the industry must prioritize security to prevent similar large-scale compromises in the future.
1 month ago
Kill Chain
Global Operation Dismantles SocGholish Botnet Linked to Evil Corp
In June 2026, an international law enforcement operation, including agencies from the United States, Canada, Germany, the Netherlands, and Europol, successfully disrupted the SocGholish botnet, a malware framework linked to the Russian cybercriminal group Evil Corp. The coordinated effort led to the takedown of 106 servers and the remediation of nearly 15,000 infected websites, primarily hosted on WordPress platforms. SocGholish, active since 2017, compromised legitimate websites to redirect users to malicious traffic distribution systems, facilitating further malware infections and enabling ransomware campaigns and espionage activities. This operation significantly impaired Evil Corp's ability to exploit these compromised sites for malicious purposes. The takedown of the SocGholish botnet underscores the persistent threat posed by sophisticated cybercriminal organizations like Evil Corp. Despite this disruption, the group's leaders remain at large, and similar malware campaigns continue to evolve. Organizations must remain vigilant, implementing robust cybersecurity measures to protect against such threats and staying informed about emerging attack vectors. ([moncloa.com](https://www.moncloa.com/2026/06/18/desmantelamiento-evil-corp-2026-3386510/?utm_source=openai))
1 month ago
Kill Chain
Critical NGINX Vulnerabilities CVE-2026-42530 and CVE-2026-42055 Disclosed by F5
In June 2026, F5 disclosed two critical vulnerabilities in NGINX, identified as CVE-2026-42530 and CVE-2026-42055. These flaws reside in the ngx_http_v3_module and the ngx_http_proxy_v2_module/ngx_http_grpc_module, respectively. Unauthenticated remote attackers can exploit these vulnerabilities to cause denial-of-service conditions or execute arbitrary code on systems with non-default configurations. Exploitation leads to use-after-free or heap-based buffer overflow in the NGINX worker process, potentially resulting in system crashes or code execution, especially on systems where Address Space Layout Randomization (ASLR) is disabled or bypassed. The disclosure underscores the persistent risk posed by vulnerabilities in widely used web server software. Organizations relying on NGINX should promptly apply the provided security patches or implement recommended mitigations to prevent potential exploitation. This incident highlights the importance of regular security assessments and timely updates to maintain system integrity.
1 month ago
Kill Chain
Apple Addresses Critical Bluetooth Vulnerability in Beats Studio Buds
In June 2026, Apple addressed a critical vulnerability (CVE-2025-20701) in its Beats Studio Buds wireless earbuds. This flaw allowed attackers within Bluetooth range to access the device's microphone without user consent, potentially enabling eavesdropping on conversations. The issue originated from a missing authentication mechanism in the Airoha Bluetooth audio SDK used in the earbuds. Apple released firmware update 1B211 to mitigate this risk, which is automatically applied when the earbuds are paired with an iPhone, iPad, or Mac. This incident underscores the importance of securing Bluetooth devices against unauthorized access. As wireless peripherals become more prevalent, ensuring robust authentication protocols is crucial to prevent potential breaches and protect user privacy.
1 month ago
Kill Chain
ShapedPlugin Supply Chain Attack: A Wake-Up Call for WordPress Security
In May 2026, ShapedPlugin, a WordPress plugin vendor, experienced a supply chain attack where malicious code was injected into their update system. This breach affected three paid plugins—Product Slider Pro, Real Testimonials Pro, and Smart Post Show Pro—leading to the installation of fake plugins that impersonated WooCommerce components. These malicious plugins stole credentials and granted attackers remote file-writing capabilities. The compromise was identified in June 2026, prompting ShapedPlugin to initiate an investigation and release updated, secure versions of the affected plugins. This incident underscores the growing trend of supply chain attacks targeting software vendors to distribute malware through legitimate update channels. It highlights the critical need for robust security measures in software development and distribution processes to prevent such breaches.
1 month ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

