✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 961 to 972 of 5068
Critical Vulnerability in Splunk Enterprise: CVE-2026-20253
In June 2026, a critical vulnerability (CVE-2026-20253) was identified in Splunk Enterprise versions below 10.2.4 and 10.0.7, allowing unauthenticated users to perform arbitrary file operations via a PostgreSQL sidecar service endpoint lacking authentication controls. This flaw could lead to remote code execution, data destruction, and full system compromise. Splunk has released patches to address this issue, urging immediate updates to mitigate potential exploitation. The disclosure of CVE-2026-20253 underscores the ongoing risks associated with unauthenticated access points in enterprise software. Organizations are advised to review their security postures, apply the latest patches promptly, and implement robust access controls to prevent similar vulnerabilities from being exploited.
1 month ago
Kill Chain
Unveiling App.MenuItem: A New Forensic Artifact in macOS Tahoe 26
In June 2026, researchers identified a new artifact in macOS Tahoe 26, named App.MenuItem, which logs specific menu selections made by users across the operating system. This artifact provides a detailed record of user actions, such as compressing files or emptying the trash, offering critical context for forensic investigations. Located at ~/Library/Biome/streams/restricted/App.MenuItem/local, the artifact contains SEGB-encapsulated protobuf entries that require specific tools to parse. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/?_wpnonce=c8aaaf1bea&lg=en&pdf=download&utm_source=openai)) The discovery of App.MenuItem is significant for digital forensics, as it allows examiners to reconstruct user workflows with greater precision. By capturing exact menu choices and timestamps, investigators can gain insights into user intent and actions, enhancing the accuracy of forensic analyses. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/?_wpnonce=c8aaaf1bea&lg=en&pdf=download&utm_source=openai))
1 month ago
Kill Chain
Critical Unauthenticated RCE Vulnerability in Oracle PeopleSoft Exploited: CVE-2026-35273
In early June 2026, Oracle disclosed a critical vulnerability (CVE-2026-35273) in its PeopleSoft Enterprise PeopleTools, specifically within the Updates Environment Management component. This flaw, present in versions 8.61 and 8.62, allows unauthenticated attackers with network access via HTTP to execute remote code, potentially leading to full system compromise. The vulnerability was actively exploited between May 27 and June 9, 2026, before Oracle released a patch on June 10. Over 100 organizations were affected, with data exfiltration reported from nearly 300 PeopleSoft instances. The cyber extortion group ShinyHunters is believed to be behind these attacks, though some experts suggest possible impersonation. ([techradar.com](https://www.techradar.com/pro/security/oracle-warns-customers-of-critical-peoplesoft-attack-after-hundreds-of-servers-hacked-by-apparent-shinyhunters-data-theft-attacks?utm_source=openai)) This incident underscores the persistent threat posed by unauthenticated remote code execution vulnerabilities in widely used enterprise applications. The rapid exploitation of CVE-2026-35273 highlights the importance of timely patch management and proactive monitoring to detect and mitigate such threats before they can cause significant damage.
1 month ago
Kill Chain
ShinyHunters' Exploitation of Oracle PeopleSoft CVE-2026-35273: A Wake-Up Call for Higher Education
In late May 2026, the cybercriminal group ShinyHunters exploited a zero-day vulnerability, CVE-2026-35273, in Oracle PeopleSoft PeopleTools versions 8.61 and 8.62. This flaw allowed unauthenticated remote code execution, leading to the compromise of over 100 organizations, predominantly in the U.S. higher education sector. The University of Nottingham confirmed significant student data theft following the group's data leak. Oracle disclosed the vulnerability on June 10, 2026, and released a critical patch, urging immediate application to mitigate further risks. This incident underscores the critical importance of timely patch management and proactive vulnerability monitoring. The exploitation of unpatched systems by threat actors like ShinyHunters highlights the need for organizations to enhance their cybersecurity posture to prevent similar breaches.
1 month ago
Kill Chain
FBI Dismantles Outsider Cybercrime Network Responsible for $1.9 Billion in Losses
In June 2026, the FBI, in collaboration with Google and Lumen Technologies, dismantled a significant China-based cybercrime network known as Outsider Enterprise. This operation, dubbed 'Operation Ghost Hook,' targeted a phishing-as-a-service platform that had been active since July 2023. Outsider provided cybercriminals with phishing kits and hosted infrastructure, enabling them to impersonate trusted brands and defraud victims across 55 countries, including the United States. The takedown resulted in the seizure of several core admin server domains, a Shopify storefront, approximately $100,000 from Outsider's payment wallets, and thousands of domains registered through U.S.-based providers. Authorities linked Outsider's phishing domains to nearly 3.9 million stolen credit cards, contributing to an estimated $1.9 billion in losses. This incident underscores the evolving sophistication of cybercriminal operations, particularly the use of AI to enhance phishing campaigns. The Outsider platform's integration of AI tools like Google's Gemini allowed for the creation of highly convincing phishing lures, making it increasingly challenging for individuals and organizations to detect and prevent such attacks. The takedown highlights the necessity for continuous advancements in cybersecurity measures and the importance of international cooperation in combating cyber threats.
1 month ago
Kill Chain
Conti Ransomware Member Pleads Guilty to Wire Fraud Conspiracy
In June 2026, Ukrainian national Oleksii Lytvynenko pleaded guilty to conspiracy to commit wire fraud for his role in the Conti ransomware group. Lytvynenko admitted to joining Conti in September 2021, developing malware used in attacks, and possessing data from 12 victims, including eight in the United States. Conti was responsible for over 1,000 ransomware attacks globally, resulting in at least $150 million in ransom payments. Lytvynenko faces up to 20 years in prison, with sentencing scheduled for September 10, 2026. This case underscores the persistent threat posed by ransomware groups and highlights the importance of international cooperation in combating cybercrime. Organizations should remain vigilant, as threat actors continue to evolve their tactics and rebrand under new identities, necessitating robust cybersecurity measures and proactive defense strategies.
1 month ago
Kill Chain
Tchap Messenger Breach: Data of 73,000 French Government Employees Exposed
In June 2026, the French government's encrypted messaging platform, Tchap, experienced a security breach when a threat actor gained access through a compromised user account. This intrusion led to the exposure of data from public chat rooms, affecting over 73,000 public sector employees. The compromised information included users' names, email addresses, avatar images, and their affiliated public sector organizations. Private conversations remained encrypted and were not accessed during the breach. This incident underscores the persistent threat posed by social engineering attacks and highlights the importance of securing even internal communication platforms. Organizations must remain vigilant and continuously enhance their security measures to protect sensitive information from unauthorized access.
1 month ago
Kill Chain
Detecting Early Warning Signs of Supply Chain Attacks on the Dark Web
In June 2026, cybersecurity researchers identified early indicators of potential supply chain attacks emerging from the dark web. Threat actors were observed advertising access to developer accounts, private repositories, and source code, which could be exploited to infiltrate organizations through trusted third-party relationships. These findings underscore the critical need for proactive monitoring of underground forums to detect and mitigate supply chain vulnerabilities before they escalate into full-scale breaches. The increasing sophistication of cybercriminals in targeting supply chains highlights the urgency for organizations to enhance their threat intelligence capabilities. By identifying and addressing these early warning signs, businesses can strengthen their defenses against complex attacks that exploit trusted connections and third-party services.
1 month ago
Kill Chain
Urgent: CISA's Directive on Patching Critical Ivanti Sentry Vulnerability
In June 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a directive mandating federal agencies to patch a critical vulnerability (CVE-2026-10520) in Ivanti Sentry devices within three days. This OS command injection flaw allows unauthenticated remote attackers to execute code with root privileges. Despite Ivanti's initial statement of no evidence of exploitation, reports emerged of attackers backdooring exposed Sentry gateways. This incident underscores the escalating threat landscape where critical vulnerabilities are rapidly exploited. Organizations must prioritize timely patching and robust vulnerability management to mitigate risks associated with such high-severity flaws.
1 month ago
Kill Chain
Novo Nordisk's 2026 Data Breach: A Wake-Up Call for Pharma Cybersecurity
In June 2026, Danish pharmaceutical company Novo Nordisk experienced a cybersecurity incident resulting in unauthorized access to certain internal IT systems. The breach led to the external copying of non-public data, including pseudonymized patient information from some clinical trials. This data encompassed patient IDs, trial participation details, sex, year of birth, biomarkers, health data, and lifestyle factors. Importantly, the data did not include direct identifiers such as patient names, mitigating the risk of immediate patient identification. The company promptly launched an investigation with external cybersecurity experts and notified relevant authorities. While certain internal systems were temporarily taken offline, Novo Nordisk confirmed that core business operations remained unaffected. This incident underscores the persistent threat of cyberattacks targeting sensitive health data within the pharmaceutical industry. Organizations handling such data must continually enhance their cybersecurity measures to protect against unauthorized access and data breaches. The event also highlights the importance of rapid response and transparent communication in maintaining trust and compliance in the face of security incidents.
1 month ago
Kill Chain
Ukrainian National's Guilty Plea Highlights Ongoing Ransomware Threats
In June 2026, Ukrainian national Oleksii Oleksiyovych Lytvynenko pleaded guilty to conspiracy to commit wire fraud for his involvement in the Conti ransomware attacks between 2021 and 2022. Lytvynenko and his co-conspirators deployed Conti ransomware on victim networks in the United States and abroad, stealing data and encrypting devices to extort Bitcoin ransom payments. He admitted to possessing data stolen from eight U.S. victims and four overseas victims and to developing malware loaders used in these attacks. The Conti ransomware operation, active from 2019 to 2022, targeted over 1,000 victims worldwide, collecting over $150 million in ransom payments. The group was known for large-scale attacks against healthcare organizations, governments, and enterprises before shutting down in 2022 following internal leaks and increased law enforcement pressure. Former Conti members have since splintered into other ransomware groups, including BlackCat, Black Basta, and Hive.
1 month ago
Kill Chain
Arch Linux AUR Compromise 2026: A Wake-Up Call for Open-Source Security
In June 2026, over 400 packages in the Arch User Repository (AUR) were compromised to distribute a Linux rootkit and infostealer malware. Attackers spoofed trusted publishers to inject malicious preinstall scripts that downloaded and executed the 'atomic-lockfile' npm package. This malware targeted sensitive information, including credentials and access tokens, and utilized eBPF rootkit capabilities to conceal its presence. The incident underscores the vulnerabilities inherent in community-maintained repositories and the critical need for stringent package verification processes. This breach highlights the escalating threat of supply chain attacks, particularly within open-source ecosystems. Organizations must enhance their security postures by implementing robust monitoring and validation mechanisms to detect and prevent such infiltrations.
1 month ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

