The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 1 to 12 of 6459
ASOS Breach Exposes Critical Gaps in Customer-Facing SaaS Security
In October 2026, the Xuanye Group compromised British fashion retailer ASOS through a sophisticated social engineering attack that targeted a single employee's credentials. The threat actors impersonated a trusted contact to obtain login credentials, then leveraged this initial access to compromise multiple corporate systems including ASOS's mobile app notification platform and potentially their Snowflake data warehouse instance. The attackers accessed personally identifiable information of approximately 17 million customers and demonstrated their breach by sending unauthorized push notifications directly to customers through ASOS's own mobile app, causing significant reputational damage and a 13% stock price drop. This incident highlights the growing trend of attackers targeting customer-facing SaaS platforms and marketing systems, which often receive less security attention than core payment or production systems. The breach demonstrates how a single compromised identity can cascade into extensive corporate network penetration, making it particularly relevant during Cybersecurity Awareness Month 2026's focus on credential security and social engineering defense.
3 hours ago
Kill Chain
Critical Vulnerabilities Expose Red Lion Controls Industrial Switches to Complete Compromise
Red Lion Controls N-Tron 700 Series industrial network switches contain seven critical vulnerabilities (CVE-2026-32645 through CVE-2026-33272) discovered in October 2026. The vulnerabilities include hardcoded credentials, plaintext password storage, unauthenticated SNMP access, and missing firmware integrity checks. Attackers can gain administrative access, extract configuration files, push malicious firmware, and cause denial-of-service conditions through automated rebooting. These switches are deployed worldwide across critical infrastructure sectors including manufacturing, communications, and commercial facilities. This incident highlights the persistent security challenges in industrial control systems, particularly as critical infrastructure becomes increasingly connected. The combination of authentication bypasses and configuration exposure creates significant risk for operational technology environments where network switches serve as foundational infrastructure components.
4 hours ago
Kill Chain
Critical SonicWall SMA1000 Vulnerability Under Active Exploitation: CVE-2026-102255 Analysis
In October 2026, attackers began exploiting CVE-2026-102255, a maximum-severity server-side request forgery (SSRF) vulnerability in SonicWall SMA1000 secure remote access appliances. The flaw affects the Appliance WorkPlace interface on models 6210, 7210, and 8200v, allowing unauthenticated remote attackers to force appliances to issue requests on their behalf and access internal functionality. Security researchers detected exploitation attempts targeting the WorkPlace Extraweb interface using crafted OPTIONS requests to reach internal CouchDB services with default credentials. Over 400 SMA1000 appliances remain exposed online, representing significant risk to enterprise VPN infrastructure used by managed service providers, corporations, and government agencies. This incident follows a pattern of SMA1000 vulnerabilities being actively exploited, with CISA cataloging 19 SonicWall flaws as exploited in the wild over four years, including 13 linked to ransomware operations. The rapid weaponization demonstrates how critical infrastructure components become prime targets for threat actors seeking network access and lateral movement opportunities.
20 hours ago
Kill Chain
FBI Arrests Another ShinyHunters Member After Massive Agency Breach Exposes Employee Data
The FBI arrested another suspected ShinyHunters member in October 2026 following the group's breach of FBI systems through an Oracle PeopleSoft zero-day vulnerability. The attack, which occurred in September 2026, compromised FBI-managed AWS GovCloud infrastructure and resulted in the theft of 2-3TB of sensitive data including employee records, Social Security numbers, medical information, and family member details affecting all FBI personnel. This represents the fourth arrest in recent weeks as law enforcement dismantles the notorious data extortion group. This incident highlights the escalating threat landscape where even premier law enforcement agencies fall victim to sophisticated threat actors exploiting zero-day vulnerabilities and cloud infrastructure weaknesses, demonstrating the urgent need for enhanced cloud security postures across all sectors.
20 hours ago
Kill Chain
AhsayCBS Zero-Day Chain Enables Stealthy Crypto Mining Campaign
In October 2026, threat actors exploited two unpatched vulnerabilities in AhsayCBS backup management platform - CVE-2026-105133 (authentication bypass) and CVE-2026-105134 (OS command injection) - to deploy webshells and cryptocurrency miners. The attackers chained these vulnerabilities to gain initial access, conduct reconnaissance, and install XMRig miners disguised as Microsoft Edge services across at least five organizations. The malware included sophisticated evasion techniques using AI-assisted PowerShell scripts that detect Task Manager activity and automatically suspend mining operations to avoid detection. This incident highlights the growing trend of cryptomining attacks targeting unpatched enterprise software, particularly backup solutions used by managed service providers. The exploitation of critical infrastructure components like backup systems poses significant operational risks and demonstrates how attackers are increasingly using AI-enhanced tools for stealth and persistence.
20 hours ago
Kill Chain
P7 DarkSword: Advanced iOS Exploit Kit Targets Cryptocurrency Wallets
In October 2026, cybersecurity researchers disclosed P7 DarkSword, an enhanced variant of the DarkSword iOS exploit kit that targets iPhones running iOS 18.4-18.7. This commercial exploit toolkit chains multiple iOS vulnerabilities to escape browser sandboxes, escalate to kernel privileges, and inject payloads into SpringBoard. P7 DarkSword introduces advanced capabilities including on-device cryptocurrency wallet theft, iCloud Keychain extraction, and bidirectional command-and-control communication. The kit has been deployed by multiple threat actors including Turkish surveillance vendor PARS Defense and Russian group Star Blizzard, with recent campaigns attributed to Chinese-speaking operators targeting victims across Saudi Arabia, Turkey, Malaysia, and Ukraine. This incident represents the growing commoditization of mobile exploit kits following their leak into second-hand markets, enabling financially motivated cybercriminals to conduct sophisticated iOS attacks previously limited to nation-state actors.
21 hours ago
Kill Chain
GhostAction Campaign: How Compromised GitHub Maintainers Exposed Thousands of Repositories
The GhostAction campaign, active since September 2025, has escalated dramatically in October 2026 with attackers compromising high-profile GitHub maintainer accounts including Takashi Kitao (pyxel game engine) and Henry Wu (Uber's athenadriver author). Using stolen personal access tokens, threat actors injected malicious GitHub Actions workflows disguised as security audits into over 500 repositories across tens of thousands of projects. These workflows systematically exfiltrate CI/CD secrets, cloud credentials, AI API keys, and historical git data to attacker-controlled infrastructure via unencrypted HTTP connections, representing one of the largest supply chain attacks targeting developer infrastructure. This incident highlights the critical vulnerability of modern software supply chains as organizations increasingly rely on automated CI/CD pipelines and cloud-native development practices. The attack's sophisticated targeting of maintainer accounts and abuse of trusted automation workflows demonstrates how threat actors are evolving to exploit the interconnected nature of open-source ecosystems.
21 hours ago
Kill Chain
AgentCorruption: How One AI Prompt Nearly Broke AWS Security
In December 2025, Zenity Labs discovered 'AgentCorruption,' a critical vulnerability in AWS Bedrock AgentCore that allowed attackers to compromise entire AWS environments through a single malicious prompt to AI agents. The flaw exploited AWS Instance Metadata Services (IMDS) access within Firecracker MicroVMs, enabling lateral movement across all AgentCore resources in affected regions. Attackers could obtain temporary credentials, invoke additional agents, access secrets from AWS Secrets Manager, and poison agent memory through overprivileged default roles and insufficient network isolation. This incident highlights the growing security risks as organizations rapidly deploy AI agents in cloud environments without proper isolation controls. The vulnerability demonstrates how AI and cloud security intersect, creating new attack vectors that traditional security measures may not adequately address.
1 day ago
Kill Chain
Social Engineering AI Agents: The Evolution of Business Email Compromise
As artificial intelligence agents become increasingly integrated into business operations with elevated system privileges, cybercriminals are developing sophisticated social engineering techniques to manipulate these autonomous systems. Unlike traditional business email compromise (BEC) attacks that target human decision-makers, threat actors are now crafting attacks specifically designed to exploit AI agents' logical processes and decision trees. These attacks leverage prompt injection techniques, context manipulation, and adversarial inputs to trick AI systems into executing unauthorized transactions, data transfers, or administrative actions. The financial and operational impact mirrors traditional BEC schemes but with potentially greater scale and automation capabilities. This emerging threat vector represents a critical evolution in social engineering as organizations rapidly deploy AI agents for financial transactions, supply chain management, and customer service operations without adequate security controls.
1 day ago
Kill Chain
FBI Takes Down Flax Typhoon: Major Win Against China's Critical Infrastructure Campaign
In October 2024, the FBI and Department of Justice disrupted the China-linked advanced persistent threat group Flax Typhoon by seizing seven domains used to scan and infiltrate U.S. critical infrastructure. The operation blocked access to command and control platforms that the threat actors had been using to maintain persistent access to compromised systems across energy, telecommunications, and transportation sectors. This coordinated law enforcement action represents a significant disruption to an ongoing espionage campaign targeting critical infrastructure organizations. The Flax Typhoon campaign highlights the increasing focus of state-sponsored actors on critical infrastructure targets and demonstrates the growing collaboration between cybersecurity agencies and law enforcement to proactively disrupt threat operations before they can cause significant damage.
1 day ago
Kill Chain
AhsayCBS Zero-Day Exploitation: When Backup Security Becomes a Cryptojacking Gateway
In October 2026, threat actors exploited two critical vulnerabilities in AhsayCBS backup utility (CVE-2026-105133 and CVE-2026-105134) to deploy XMRig cryptocurrency miners disguised as Microsoft Edge processes. The attackers chained an authentication bypass flaw with a command injection vulnerability to achieve remote code execution on affected systems. Exploitation began just three days after CVE publication, targeting five organizations initially. Post-compromise activities included reconnaissance, web shell deployment, and installation of AI-assisted PowerShell scripts designed to evade detection by monitoring and terminating Windows Task Manager during mining operations. This incident highlights the accelerating pace of zero-day weaponization and the evolution of cryptojacking campaigns toward more sophisticated evasion techniques, including AI-generated scripts and legitimate process impersonation.
1 day ago
Kill Chain
Anthropic Launches Free AI Vulnerability Scanner to Defend Open Source Ecosystem
In October 2026, Anthropic launched OSS Scanner, a free AI-powered vulnerability detection service for open-source projects. The initiative leverages Claude AI models to conduct automated security audits without human review, aiming to strengthen the open-source ecosystem's security posture. Through their Project Glasswing research, Anthropic has already identified over 29,000 candidate vulnerabilities across critical software projects, with 6,000 reported to maintainers and 584 advisories issued by October 2026. This development highlights the accelerating arms race between AI-powered offensive and defensive capabilities in cybersecurity. As threat actors increasingly leverage AI to discover and exploit vulnerabilities at scale, organizations must adopt similar AI-driven defensive measures to maintain security parity and protect critical infrastructure.
1 day ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

