✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 877 to 888 of 5051
Phantom Stealer: The Rise of Fileless Malware Targeting Financial Institutions
In June 2026, a sophisticated phishing campaign targeted banks and high-value organizations, deploying Phantom Stealer—a fileless malware designed to evade traditional endpoint defenses. The attack began with phishing emails containing seemingly legitimate business documents. Upon opening, a heavily obfuscated batch file initiated a multistage infection chain, injecting Phantom Stealer into the Windows Explorer process. Operating entirely in memory, the malware silently exfiltrated browser credentials, session cookies, and financial data through multiple channels, including Telegram, Discord, FTP, and SMTP. This incident underscores the evolving tactics of cybercriminals, highlighting the increasing use of fileless malware and advanced evasion techniques. Organizations must enhance their security posture by adopting behavior-based detection systems and educating employees on recognizing sophisticated phishing attempts to mitigate such threats.
1 month ago
Kill Chain
CISA Adds CVE-2026-48907 to Known Exploited Vulnerabilities Catalog
In June 2026, a critical vulnerability identified as CVE-2026-48907 was discovered in the Joomla Content Editor (JCE) extension, allowing unauthenticated attackers to create new editor profiles and upload arbitrary PHP code, leading to remote code execution. This flaw affects JCE versions prior to 2.9.99.5. The Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on June 16, 2026, following evidence of active exploitation. Joomla released patches on June 3 and June 6, 2026, to address this issue. ([securityweek.com](https://www.securityweek.com/joomla-litespeed-vulnerabilities-exploited-in-attacks/?utm_source=openai)) The active exploitation of CVE-2026-48907 underscores the persistent threat posed by web application vulnerabilities, particularly in widely used content management systems like Joomla. Organizations are urged to promptly apply the latest security updates to mitigate potential risks associated with this vulnerability.
1 month ago
Kill Chain
CISA Issues Warning on Actively Exploited Joomla JCE Vulnerability
In June 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical vulnerability, CVE-2026-48907, affecting the Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities catalog. This flaw, present in JCE versions 1.0.0 through 2.9.99.4, allows unauthenticated users to create new editor profiles, enabling the upload and execution of arbitrary PHP code on the server. The vulnerability has been actively exploited, with attackers leveraging it to gain unauthorized access and control over affected Joomla installations. The active exploitation of this vulnerability underscores the persistent threat posed by improper access controls in widely used content management systems. Organizations utilizing Joomla with the JCE extension are urged to update to version 2.9.99.5 or later to mitigate this risk. Additionally, administrators should audit their systems for unauthorized editor profiles and monitor server logs for suspicious activity to prevent potential breaches.
1 month ago
Kill Chain
Unveiling the VHDX-Based Remcos RAT Attack: A 2026 Cybersecurity Challenge
In June 2026, a sophisticated malware campaign was identified, utilizing a VHDX disk image within a ZIP archive to deliver the Remcos Remote Access Trojan (RAT). Upon extraction, the VHDX file auto-mounted on Windows systems, revealing an obfuscated JavaScript file named 'Partnerschaft_fur_neue_Angebotsanfrage.js', indicating potential targeting of German-speaking users. This JavaScript initiated a multi-stage infection chain involving PowerShell scripts and .NET loaders, ultimately injecting the Remcos RAT into the 'backgroundTaskHost.exe' process. The malware established communication with a command-and-control server at animal342[.]duckdns[.]org:53552, enabling remote surveillance and data exfiltration. Notably, the campaign employed techniques such as WMI for process execution and Base64 encoding with XOR decryption to evade detection by traditional security measures. This incident underscores the evolving tactics of cybercriminals who leverage legitimate system features and complex obfuscation methods to bypass security controls. The use of VHDX files as malware containers highlights the need for enhanced vigilance and advanced detection mechanisms to counter such sophisticated threats.
1 month ago
Kill Chain
Mastra npm Supply Chain Attack: 144 Packages Compromised
In June 2026, a significant supply chain attack targeted the Mastra npm ecosystem, compromising 144 packages associated with the '@mastra' namespace. The attack was initiated through the hijacking of a former contributor's npm account, 'ehindero'. The attackers introduced a malicious dependency named 'easy-day-js', which masqueraded as the legitimate 'dayjs' library. Initially, 'easy-day-js' appeared benign, but subsequent versions contained obfuscated post-install scripts designed to exfiltrate sensitive information from developers' systems. This incident underscores the vulnerabilities inherent in open-source software supply chains, particularly when trusted contributor accounts are compromised. The Mastra framework, widely used for building AI applications, saw its core components, such as '@mastra/core', affected, amplifying the potential impact on downstream projects and organizations. The attack highlights the critical need for robust security measures in package management and dependency verification processes. The increasing frequency of such supply chain attacks emphasizes the urgency for the developer community to adopt stringent security practices, including regular audits of dependencies, implementation of multi-factor authentication for contributor accounts, and continuous monitoring for anomalous activities within software ecosystems.
1 month ago
Kill Chain
Malicious JetBrains Plugins Compromise AI API Keys in 2026
In June 2026, cybersecurity researchers identified a coordinated malware campaign involving at least 15 malicious plugins on the JetBrains Marketplace. These plugins, masquerading as AI coding assistants built on DeepSeek and other large language models, were designed to exfiltrate artificial intelligence (AI) provider keys. The plugins offered functionalities such as chat, commit messages, code review, bug finding, and unit tests, thereby enticing developers to install them. Once installed, the plugins covertly transmitted sensitive API keys to attacker-controlled servers, potentially compromising the security of AI-driven applications and services. This incident underscores a growing trend where threat actors exploit the trust in developer tools and marketplaces to distribute malicious software. The increasing integration of AI into development workflows makes such platforms attractive targets. Organizations must remain vigilant, ensuring the integrity of the tools they incorporate and regularly auditing their development environments to prevent unauthorized access and data exfiltration.
1 month ago
Kill Chain
Understanding the MongoBleed Vulnerability (CVE-2025-14847) and Its Impact
In December 2025, a critical vulnerability known as MongoBleed (CVE-2025-14847) was disclosed, affecting multiple versions of MongoDB Server from 3.6 through 8.2.3. This flaw allows unauthenticated attackers to exploit improper handling of zlib-compressed network traffic, leading to the leakage of uninitialized heap memory. As a result, sensitive data such as credentials, session tokens, and API keys could be exfiltrated from affected servers. The vulnerability has been actively exploited in the wild, with approximately 87,000 MongoDB instances exposed globally, primarily in the United States, China, and Germany. Organizations are strongly advised to apply security patches immediately or disable compression and restrict network exposure to mitigate the risk. ([infoq.com](https://www.infoq.com/news/2026/01/mongodb-mongobleed-vulnerability/?utm_source=openai)) The MongoBleed incident underscores the critical importance of timely patch management and the need for robust security measures to protect against vulnerabilities in widely used database systems. The rapid exploitation of this flaw highlights the evolving threat landscape and the necessity for organizations to remain vigilant in securing their infrastructure.
1 month ago
Kill Chain
Introducing Sulla: Praetorian's Open-Source SMB Secret Scanner
In June 2026, Praetorian released Sulla, an open-source tool designed to scan SMB shares for exposed credentials across enterprise networks. Sulla automates the discovery of readable SMB shares, traverses their file structures, and scans contents for sensitive information using the Titus detection library. This tool addresses the challenge of manually reviewing numerous network shares, which is often tedious and inefficient. By integrating Sulla into their Continuous Threat Exposure Management platform, Guard, Praetorian ensures that SMB secrets are identified promptly as they appear in environments. The release of Sulla highlights the growing need for automated tools to detect and mitigate the risks associated with exposed credentials in network shares. As organizations increasingly rely on complex network infrastructures, tools like Sulla become essential in proactively identifying and addressing security vulnerabilities, thereby enhancing overall cybersecurity posture.
1 month ago
Kill Chain
Critical Vulnerability in SolarWinds Serv-U: CVE-2026-28318
In early June 2026, a high-severity vulnerability (CVE-2026-28318) was identified in SolarWinds Serv-U, a widely used file transfer server. This flaw allows unauthenticated attackers to crash the Serv-U service by sending specially crafted POST requests with the 'Content-Encoding: deflate' header, leading to a denial-of-service (DoS) condition. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed active exploitation of this vulnerability and added it to their Known Exploited Vulnerabilities catalog on June 5, 2026. Organizations are urged to apply the available patch or implement recommended mitigations promptly to prevent service disruptions. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/06/08/cisa-patch-actively-exploited-solarwinds-serv-u-dos-vulnerability-cve-2026-28318/?utm_source=openai)) The exploitation of CVE-2026-28318 underscores the persistent targeting of file transfer services by threat actors. Given the critical role of such services in business operations, this incident highlights the necessity for organizations to maintain vigilant patch management practices and to monitor for emerging threats to ensure operational resilience.
1 month ago
Kill Chain
Earth Lusca's Advanced Windows Malware Targets Government Entities
Between 2023 and 2024, the Chinese state-sponsored threat group Earth Lusca, also known as FishMonger, expanded its cyber espionage operations by deploying Windows variants of the previously Linux-based SprySOCKS malware. These sophisticated backdoors targeted government organizations in Taiwan, Thailand, Pakistan, and Honduras, focusing on sectors such as foreign affairs, technology, and telecommunications. The Windows versions, identified as WIN_DRV and WIN_PLUS, introduced advanced capabilities including kernel-level stealth mechanisms, enabling the malware to hide processes, network connections, and files, thereby evading detection. Both variants support over 30 command-and-control commands, facilitate communication over multiple protocols, and possess functionalities like keystroke logging and SOCKS proxy support. The emergence of these Windows variants underscores a significant evolution in Earth Lusca's tactics, highlighting the group's commitment to enhancing its toolset for broader and more effective cyber espionage campaigns. This development reflects a broader trend among nation-state actors to adapt and refine their malware to target diverse operating systems, emphasizing the need for organizations to implement comprehensive, cross-platform cybersecurity measures.
1 month ago
Kill Chain
iRhythm Data Breach 2026: A Wake-Up Call for Healthcare Cybersecurity
In June 2026, iRhythm Holdings, a digital healthcare company specializing in cardiac monitoring, experienced a significant data breach. On June 8, unauthorized activity was detected in third-party-hosted business applications, leading to the exfiltration of sensitive information, including proprietary data and patient protected health information (PHI). The attackers, employing social engineering tactics, contacted iRhythm on June 9, demanding a ransom to prevent public disclosure of the stolen data. The company promptly activated its cybersecurity response plan, engaged external experts, and confirmed the breach's materiality due to the volume of affected data. Importantly, iRhythm reported no impact on its products, clinical or medical device systems, patient safety, manufacturing and distribution operations, or financial reporting systems. ([streetinsider.com](https://www.streetinsider.com/Reuters/iRhythm%2Bdiscloses%2Bcyber%2Bincident%2C%2Bsays%2Bno%2Bimpact%2Bon%2Bdevice%2Bsystems%2C%2Bpatient%2Bsafety/26648941.html?utm_source=openai)) This incident underscores the escalating threat landscape targeting healthcare organizations, particularly through social engineering and ransomware attacks. The breach highlights the critical need for robust cybersecurity measures, comprehensive employee training to recognize and prevent social engineering attempts, and stringent data protection protocols to safeguard sensitive patient information.
1 month ago
Kill Chain
DragonForce Ransomware's Innovative Exploitation of Microsoft Teams in 2025
In December 2025, the DragonForce ransomware group executed a sophisticated attack against a major U.S. services company. They exploited an unknown vulnerability in an SQL or MSSQL server to gain initial access. Subsequently, they deployed a custom Go-based malware named 'Backdoor.Turn,' which abused Microsoft Teams' Traversal Using Relays around NAT (TURN) protocol to conceal command-and-control (C2) communications within legitimate Teams traffic. This allowed the attackers to evade detection while exfiltrating data and deploying ransomware to encrypt the victim's systems. This incident underscores a concerning trend where threat actors leverage trusted cloud-based collaboration platforms to mask malicious activities. The abuse of Microsoft Teams' infrastructure for C2 communications highlights the need for organizations to scrutinize even legitimate traffic and implement robust monitoring mechanisms to detect anomalies within trusted services.
1 month ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

