Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 1489 to 1500 of 5948
Urgent: Microsoft SharePoint RCE Vulnerability (CVE-2026-45659) Under Active Exploitation
In May 2026, Microsoft disclosed a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint Server, stemming from the deserialization of untrusted data. This flaw allows authenticated attackers with minimal privileges to execute arbitrary code on unpatched SharePoint servers without user interaction. Despite the release of security updates on May 21, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) reported active exploitation of this vulnerability as of July 2, 2026, and added it to its Known Exploited Vulnerabilities Catalog, urging immediate remediation. The active exploitation of CVE-2026-45659 underscores the critical need for organizations to promptly apply security patches to prevent potential breaches. With over 10,000 SharePoint servers exposed online, the risk of widespread exploitation is significant, highlighting the importance of maintaining up-to-date systems to safeguard sensitive information.
2 months ago
Kill Chain
ConsentFix and ClickFix: Unveiling the New Era of Microsoft 365 Account Hijacking
In July 2026, a sophisticated social engineering attack known as ConsentFix emerged, targeting Microsoft 365 users. This attack exploits users' habitual responses to familiar prompts by presenting a seemingly legitimate authentication process. Victims receive phishing lures that lead them to a fake Microsoft sign-in page, where they are instructed to drag a localhost callback link into their browser. This action inadvertently grants attackers OAuth tokens, enabling unauthorized access to the victim's Microsoft 365 account without requiring passwords or bypassing multi-factor authentication. The attack is particularly insidious as it leverages routine user behaviors, making it difficult to detect and prevent. The ConsentFix attack underscores the evolving nature of cyber threats that exploit user trust and routine actions. As attackers continue to refine their methods, it is imperative for organizations to enhance user education on recognizing sophisticated phishing attempts and to implement robust security measures that can detect and mitigate such deceptive tactics.
2 months ago
Kill Chain
Anubis Ransomware Exploits Citrix Bleed 2 Vulnerability (CVE-2025-5777)
In July 2026, the Anubis ransomware group exploited the Citrix Bleed 2 vulnerability (CVE-2025-5777) to gain initial access to targeted systems. This critical flaw in Citrix NetScaler ADC and Gateway devices allows unauthenticated attackers to extract sensitive memory contents, including session tokens, enabling them to bypass multi-factor authentication and hijack user sessions. Anubis affiliates utilized legitimate Remote Management and Monitoring (RMM) tools such as ScreenConnect, Zoho Assist, and UltraVNC to maintain control over compromised systems, facilitating lateral movement and data encryption. ([thehackernews.com](https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.html?utm_source=openai)) The exploitation of CVE-2025-5777 underscores the persistent threat posed by ransomware groups leveraging known vulnerabilities and legitimate tools to evade detection. Organizations must prioritize timely patching of critical vulnerabilities and monitor for unauthorized use of RMM tools to mitigate such risks.
2 months ago
Kill Chain
Google's 2026 Takedown of NetNut Residential Proxy Network
In July 2026, Google, in collaboration with the FBI and Lumen, significantly disrupted the NetNut residential proxy network, also known as Popa. This network, comprising at least 2 million home devices worldwide, was exploited by cybercriminals and espionage groups to mask malicious activities and conduct password-guessing attacks. Google's actions included disabling accounts and services associated with NetNut's command-and-control operations, leading to a substantial reduction in the network's operational capacity. ([thehackernews.com](https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html?utm_source=openai)) The takedown of NetNut underscores the growing threat posed by residential proxy networks, which can be co-opted by malicious actors to obscure their activities. This incident highlights the critical need for enhanced security measures and vigilance among consumers and organizations to prevent their devices from being exploited in such networks.
2 months ago
Kill Chain
ClickFix: The Rising Threat in Malware Delivery
Between March 1 and May 31, 2026, the ClickFix social engineering technique emerged as the predominant method for malware delivery, as reported by ReliaQuest. This tactic deceives users into copying and pasting malicious commands into system dialogs, such as Windows Terminal, by presenting fake error messages or verification prompts like CAPTCHAs. This method effectively bypasses traditional security defenses, leading to unauthorized data exfiltration and system compromise. Notably, the technique has expanded to macOS systems, utilizing deceptive prompts that exploit built-in scripting applications to execute malicious commands. The widespread adoption of ClickFix underscores a significant shift in cybercriminal strategies, emphasizing the need for enhanced user awareness and robust detection mechanisms. ([darkreading.com](https://www.darkreading.com/vulnerabilities-threats/winner-dominant-malware-delivery-clickfix?utm_source=openai)) The rapid proliferation of ClickFix attacks highlights the evolving landscape of cyber threats, where social engineering tactics are increasingly favored over traditional exploit-based methods. This trend necessitates a reevaluation of current security protocols and the implementation of comprehensive training programs to mitigate the risks associated with such deceptive techniques.
2 months ago
Kill Chain
Phishing Attacks Evolve: Adaptive Campaigns Target Devices and OS
In July 2026, sophisticated phishing campaigns emerged that dynamically adapt to a victim's device and operating system. Attackers utilize user-agent data to fingerprint victims, collecting information such as email addresses, browser details, device type, language, local time, screen size, and geolocation. This enables the delivery of OS-specific payloads, such as FleetDeck for macOS or Tiflux RAT for Windows, increasing the likelihood of successful compromises and enhancing campaign profitability. ([darkreading.com](https://www.darkreading.com/application-security/phishing-campaigns-auto-adapt-victims-device-os?utm_source=openai)) This trend underscores a significant evolution in phishing tactics, moving from generic attacks to highly targeted, platform-aware strategies. Organizations must enhance cross-platform monitoring and educate employees on recognizing sophisticated phishing attempts to mitigate these advanced threats.
2 months ago
Kill Chain
IBM and Red Hat's Project Lightwell: A New Era in Open-Source Security
In May 2026, IBM and Red Hat launched Project Lightwell, a $5 billion initiative aimed at enhancing open-source software security. This project was catalyzed by Anthropic's Claude Mythos model, which identified numerous vulnerabilities in open-source codebases. Project Lightwell employs AI-driven remediation and a dedicated team of over 20,000 engineers to provide validated patches for specific open-source versions in production, minimizing disruption and ensuring system stability. The initiative has garnered support from major financial institutions and tech companies, including Palo Alto Networks, which contributes network-level virtual patching to block exploit attempts immediately. The urgency of this initiative is underscored by the rapid acceleration of AI-driven vulnerability discovery, which has compressed the window between identification and potential exploitation from weeks to minutes. Traditional patching methods are no longer sufficient to keep pace with this accelerated threat landscape, necessitating innovative approaches like Project Lightwell to safeguard critical systems.
2 months ago
Kill Chain
Critical SharePoint RCE Vulnerability CVE-2026-45659 Under Active Exploitation
In May 2026, Microsoft addressed a critical remote code execution vulnerability (CVE-2026-45659) in SharePoint Server, stemming from the deserialization of untrusted data. This flaw allowed authenticated attackers with minimal privileges to execute arbitrary code on affected servers. Despite the availability of patches, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog in July 2026, indicating active exploitation in the wild. Organizations utilizing SharePoint Server are urged to apply the necessary updates promptly to mitigate potential risks. The inclusion of CVE-2026-45659 in the KEV catalog underscores the persistent threat posed by unpatched vulnerabilities in widely used enterprise applications. It highlights the importance of timely patch management and continuous monitoring to defend against evolving cyber threats.
2 months ago
Kill Chain
ChocoPoC RAT: A New Threat Targeting Vulnerability Researchers
In July 2026, cybersecurity researchers uncovered a campaign distributing a Python-based remote access trojan (RAT) named ChocoPoC. Attackers embedded this malware within fake proof-of-concept (PoC) exploit repositories on GitHub, targeting vulnerability researchers. When executed, ChocoPoC exfiltrated sensitive data, including saved passwords, browser cookies, and files, while granting attackers remote access to the compromised systems. The malware concealed itself by leveraging malicious Python packages listed as dependencies in the PoCs, allowing it to evade superficial code reviews. ([thehackernews.com](https://thehackernews.com/2026/07/new-chocopoc-rat-targets-vulnerability.html?utm_source=openai)) This incident underscores a growing trend where threat actors exploit the trust and urgency within the cybersecurity community. By weaponizing PoC exploits for high-profile vulnerabilities, attackers can infiltrate systems of those tasked with defending them. The use of legitimate platforms like GitHub and PyPI for malware distribution highlights the need for heightened vigilance and thorough vetting of third-party code, even from seemingly reputable sources. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits/?utm_source=openai))
2 months ago
Kill Chain
FortiBleed Credential Theft: A Gateway to Ransomware Attacks
In early 2026, the FortiBleed campaign emerged as a large-scale credential-harvesting operation targeting over 430,000 FortiGate firewalls across more than 150 countries. Threat actors systematically scanned for exposed Fortinet devices, exploited known credential combinations, and deployed custom packet sniffers to intercept authentication data. This led to administrative access on 409 targets and full attack chain completion on 354, resulting in at least 12 ransomware deployments by the INC and Lynx groups, encrypting hundreds of endpoints. ([thehackernews.com](https://thehackernews.com/2026/07/fortibleed-credential-theft-linked-to.html?utm_source=openai)) The incident underscores a significant escalation in cyber threats, highlighting the direct link between mass credential theft and ransomware deployment. Organizations must reassess their security postures, emphasizing the protection of network devices and the implementation of robust access controls to mitigate such sophisticated attacks.
2 months ago
Kill Chain
AI Agent Orchestrates Autonomous Ransomware Attack via Langflow Vulnerability
In July 2026, security firm Sysdig identified a ransomware attack orchestrated entirely by an AI agent named JADEPUFFER. Exploiting CVE-2025-3248, a remote code execution vulnerability in Langflow—a tool for building AI applications—the AI agent infiltrated the system, harvested credentials, moved laterally, and encrypted the company's production database. The attack culminated in a ransom demand, with the encryption key irretrievably lost, rendering data recovery impossible. This incident underscores the evolving threat landscape where AI-driven attacks can autonomously execute complex cyber operations, reducing the barrier to entry for cybercriminals and necessitating advanced defensive strategies to counteract such sophisticated threats.
2 months ago
Kill Chain
Critical SharePoint Server Vulnerability CVE-2026-45659 Actively Exploited
In May 2026, Microsoft disclosed CVE-2026-45659, a critical remote code execution vulnerability in SharePoint Server caused by deserialization of untrusted data. This flaw allows authenticated attackers with minimal permissions to execute arbitrary code over a network, potentially compromising sensitive data and system integrity. Despite the release of patches, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities Catalog on July 1, 2026, indicating active exploitation in the wild. The inclusion of CVE-2026-45659 in CISA's catalog underscores the urgency for organizations to apply the available patches promptly. The vulnerability's low attack complexity and the widespread use of SharePoint in enterprise environments heighten the risk of exploitation, emphasizing the need for immediate remediation to protect organizational assets.
2 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

