Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 1741 to 1752 of 5957
Anthropic's Fable 5 AI Model Suspended Amid National Security Concerns
In June 2026, Anthropic released its advanced AI model, Fable 5, designed to autonomously identify and exploit software vulnerabilities. Shortly after its release, the U.S. government classified Fable 5 as a potential national security threat, citing concerns over its capability to be 'jailbroken' and misused by malicious actors. Consequently, Anthropic was ordered to suspend access to the model for all foreign nationals, leading the company to disable Fable 5 entirely due to the inability to selectively restrict access. This abrupt shutdown has sparked significant debate within the cybersecurity community, with experts arguing that such restrictions may hinder defensive research more than deter malicious use. The incident underscores the challenges in balancing AI innovation with national security and the need for clear regulatory frameworks to manage the dual-use nature of advanced AI technologies.
3 months ago
Kill Chain
TeamPCP's Supply Chain Attacks: A Wake-Up Call for Open-Source Security
Between February and June 2026, the cybercriminal group TeamPCP executed a series of supply chain attacks, compromising over 1,000 open-source software packages. By infiltrating widely used tools such as Trivy, Checkmarx KICS, LiteLLM, and the Telnyx Python SDK, TeamPCP exploited vulnerabilities in CI/CD pipelines and AI development tools to inject malicious code, leading to the exfiltration of sensitive data and credentials. This campaign underscored the critical weaknesses in the software supply chain, particularly the reliance on unverified code dependencies and the lack of rigorous security checks in automated deployment systems. The incident highlights the urgent need for organizations to reassess their software development practices, emphasizing the importance of verifying the integrity of open-source components and implementing robust security measures within CI/CD pipelines. As supply chain attacks become more prevalent, the industry must prioritize security to prevent similar large-scale compromises in the future.
3 months ago
Kill Chain
Global Operation Dismantles SocGholish Botnet Linked to Evil Corp
In June 2026, an international law enforcement operation, including agencies from the United States, Canada, Germany, the Netherlands, and Europol, successfully disrupted the SocGholish botnet, a malware framework linked to the Russian cybercriminal group Evil Corp. The coordinated effort led to the takedown of 106 servers and the remediation of nearly 15,000 infected websites, primarily hosted on WordPress platforms. SocGholish, active since 2017, compromised legitimate websites to redirect users to malicious traffic distribution systems, facilitating further malware infections and enabling ransomware campaigns and espionage activities. This operation significantly impaired Evil Corp's ability to exploit these compromised sites for malicious purposes. The takedown of the SocGholish botnet underscores the persistent threat posed by sophisticated cybercriminal organizations like Evil Corp. Despite this disruption, the group's leaders remain at large, and similar malware campaigns continue to evolve. Organizations must remain vigilant, implementing robust cybersecurity measures to protect against such threats and staying informed about emerging attack vectors. ([moncloa.com](https://www.moncloa.com/2026/06/18/desmantelamiento-evil-corp-2026-3386510/?utm_source=openai))
3 months ago
Kill Chain
Critical NGINX Vulnerabilities CVE-2026-42530 and CVE-2026-42055 Disclosed by F5
In June 2026, F5 disclosed two critical vulnerabilities in NGINX, identified as CVE-2026-42530 and CVE-2026-42055. These flaws reside in the ngx_http_v3_module and the ngx_http_proxy_v2_module/ngx_http_grpc_module, respectively. Unauthenticated remote attackers can exploit these vulnerabilities to cause denial-of-service conditions or execute arbitrary code on systems with non-default configurations. Exploitation leads to use-after-free or heap-based buffer overflow in the NGINX worker process, potentially resulting in system crashes or code execution, especially on systems where Address Space Layout Randomization (ASLR) is disabled or bypassed. The disclosure underscores the persistent risk posed by vulnerabilities in widely used web server software. Organizations relying on NGINX should promptly apply the provided security patches or implement recommended mitigations to prevent potential exploitation. This incident highlights the importance of regular security assessments and timely updates to maintain system integrity.
3 months ago
Kill Chain
Apple Addresses Critical Bluetooth Vulnerability in Beats Studio Buds
In June 2026, Apple addressed a critical vulnerability (CVE-2025-20701) in its Beats Studio Buds wireless earbuds. This flaw allowed attackers within Bluetooth range to access the device's microphone without user consent, potentially enabling eavesdropping on conversations. The issue originated from a missing authentication mechanism in the Airoha Bluetooth audio SDK used in the earbuds. Apple released firmware update 1B211 to mitigate this risk, which is automatically applied when the earbuds are paired with an iPhone, iPad, or Mac. This incident underscores the importance of securing Bluetooth devices against unauthorized access. As wireless peripherals become more prevalent, ensuring robust authentication protocols is crucial to prevent potential breaches and protect user privacy.
3 months ago
Kill Chain
ShapedPlugin Supply Chain Attack: A Wake-Up Call for WordPress Security
In May 2026, ShapedPlugin, a WordPress plugin vendor, experienced a supply chain attack where malicious code was injected into their update system. This breach affected three paid plugins—Product Slider Pro, Real Testimonials Pro, and Smart Post Show Pro—leading to the installation of fake plugins that impersonated WooCommerce components. These malicious plugins stole credentials and granted attackers remote file-writing capabilities. The compromise was identified in June 2026, prompting ShapedPlugin to initiate an investigation and release updated, secure versions of the affected plugins. This incident underscores the growing trend of supply chain attacks targeting software vendors to distribute malware through legitimate update channels. It highlights the critical need for robust security measures in software development and distribution processes to prevent such breaches.
3 months ago
Kill Chain
International Crackdown Dismantles SocGholish Botnet Tied to Evil Corp
In June 2026, international law enforcement agencies, including Europol and Eurojust, executed Operation Endgame, targeting the SocGholish botnet linked to the Russian cybercrime group Evil Corp. This coordinated effort resulted in the cleansing of nearly 15,000 malware-infected WordPress websites and the dismantling of over 100 associated servers. SocGholish, active since at least 2017, operates by injecting malicious JavaScript into legitimate websites, tricking visitors into downloading fake browser updates that install malware, thereby granting attackers access to infected systems. The operation significantly disrupted Evil Corp's infrastructure, mitigating further cyber threats posed by this group. The success of Operation Endgame underscores the effectiveness of international collaboration in combating sophisticated cybercriminal networks. It highlights the critical need for organizations to maintain robust cybersecurity practices, including regular software updates, vigilant monitoring of web assets, and user education to recognize and avoid social engineering tactics employed by malware like SocGholish.
3 months ago
Kill Chain
USB Worm Targets Cryptocurrency Wallets via Windows Shortcut Files
In June 2026, a sophisticated USB worm emerged, targeting cryptocurrency wallets by distributing clipboard-stealing malware through Windows shortcut (LNK) files on USB drives. Upon execution, the malware scans the system for document files, hides the originals, and replaces them with malicious shortcuts. It monitors clipboard activity to detect and replace cryptocurrency wallet addresses with those controlled by the attacker, captures screenshots, and exfiltrates data via the Tor network. The worm also propagates by copying itself to newly connected USB devices, facilitating further spread. This incident underscores the evolving tactics of threat actors leveraging removable media to infiltrate systems, emphasizing the need for heightened vigilance and robust security measures to protect sensitive financial information.
3 months ago
Kill Chain
Klue OAuth Breach 2026: A Wake-Up Call for Third-Party Integration Security
In June 2026, market intelligence platform Klue experienced a security breach where attackers, identified as the 'Icarus' group, exploited OAuth tokens to access and exfiltrate Salesforce CRM data from multiple organizations. The attackers infiltrated Klue's backend systems, deployed malicious code to harvest OAuth tokens, and utilized these tokens to query and extract sensitive data from connected Salesforce instances. This incident led to significant data theft and subsequent extortion attempts targeting the affected organizations. This breach underscores the critical vulnerabilities associated with third-party integrations and the exploitation of OAuth tokens. It highlights the necessity for organizations to implement stringent security measures, including regular audits of third-party applications, prompt revocation of compromised tokens, and continuous monitoring of API activities to detect and mitigate unauthorized access promptly.
3 months ago
Kill Chain
Nintendo's 2026 Data Breach: A Wake-Up Call for Third-Party Security
In June 2026, Nintendo of America experienced a data breach through TinyPulse, a third-party service used for internal employee surveys. The cybercriminal group ShadowByt3$ claimed responsibility, alleging they exfiltrated approximately 859 MB of sensitive data, including employee names, email addresses, bank statements, and W-9 forms. Nintendo confirmed the breach but stated that only internal survey content from a small subset of employees was affected, with most information dating back several years. The company's internal systems, as well as customer and financial data, remained uncompromised. This incident underscores the growing threat posed by emerging ransomware groups like ShadowByt3$, which, despite their relatively recent appearance, are capable of targeting major corporations through third-party service vulnerabilities. Organizations must reassess their third-party risk management strategies to prevent similar breaches.
3 months ago
Kill Chain
F5 Releases Patches for Critical NGINX Vulnerabilities CVE-2026-42530 and CVE-2026-42055
In June 2026, F5 disclosed two critical vulnerabilities in NGINX Open Source: CVE-2026-42530 and CVE-2026-42055, both with a CVSS v4 score of 9.2. CVE-2026-42530 is a use-after-free flaw in the ngx_http_v3_module, exploitable when NGINX is configured with the HTTP/3 QUIC module, potentially allowing remote code execution if Address Space Layout Randomization (ASLR) is disabled or bypassed. CVE-2026-42055 is a heap-based buffer overflow in the ngx_http_proxy_v2_module and ngx_http_grpc_module, triggered under specific configurations involving HTTP/2 proxying, which could also lead to remote code execution under similar conditions. F5 has released patches to address these vulnerabilities and recommends disabling HTTP/3 and adjusting configuration directives as interim mitigations. The discovery of these vulnerabilities underscores the persistent risks associated with widely used open-source software components. Organizations relying on NGINX should promptly apply the provided patches and review their configurations to mitigate potential exploitation. This incident highlights the importance of continuous monitoring and timely updates to maintain the security of critical infrastructure.
3 months ago
Kill Chain
Gentlemen Ransomware's Advanced EDR Killers: A 2026 Threat Analysis
In June 2026, the Gentlemen ransomware-as-a-service (RaaS) operation was observed actively developing and deploying a suite of endpoint detection and response (EDR) killer tools to evade detection during attacks. The primary tool, dubbed 'GentleKiller,' has at least eight variants that impersonate legitimate security products such as Kaspersky, Valorant, Javelin, and WatchDog. These tools utilize the 'bring your own vulnerable driver' (BYOVD) technique to gain kernel-level privileges and disable security processes, targeting over 400 processes associated with approximately 48 security vendors, including Microsoft, CrowdStrike, and SentinelOne. The binaries are protected using commercial packers like Enigma and Themida, and some variants employ stolen digital signatures to further obfuscate their malicious activities. This development underscores a growing trend among ransomware operators to enhance their evasion capabilities by systematically disabling security defenses, thereby increasing the success rate of their attacks. Organizations must remain vigilant and adopt comprehensive security measures to detect and mitigate such sophisticated threats.
3 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

