Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 169 to 180 of 5916
Grindr's £26 Million Settlement Exposes Critical Gaps in Dating App Data Privacy
In September 2026, Grindr agreed to pay £26 million ($35.1 million) to settle a U.K. class action lawsuit involving over 10,000 users whose sensitive personal data, including HIV status, was shared with third-party advertising companies Apptimize and Localytics between 2018-2020. The incident, originally exposed by Norwegian research group SINTEF in April 2018, occurred while Grindr was owned by Chinese gaming company Kunlun, before its 2020 acquisition by San Vicente Acquisition LLC. The settlement covers historical data practices that violated U.K. privacy laws through unauthorized sharing of location data, sexual orientation, and medical information for commercial advertising purposes. This incident highlights the ongoing regulatory scrutiny of data privacy violations in dating apps and social platforms, particularly as GDPR enforcement intensifies and class action lawsuits become more prevalent in addressing historical privacy breaches involving sensitive personal information.
1 week ago
Kill Chain
BengalSEO Campaign Weaponizes Search Results for MayaBot Distribution
The BengalSEO campaign represents a sophisticated search engine optimization poisoning operation that has been active since 2015, targeting Bing search results to deliver MayaBot malware and facilitate tech support scams. Operating from Rajasthan, India, the threat actors behind this campaign manipulate search engine results to redirect victims to malicious websites, where they deploy malware or engage in fraudulent technical support schemes. The campaign demonstrates the evolution of SEO poisoning techniques and their effectiveness in reaching unsuspecting users through legitimate search queries. This incident highlights the growing sophistication of search engine manipulation attacks and their integration with traditional malware distribution methods. As organizations increasingly rely on digital visibility and search engine optimization, the weaponization of these same techniques by threat actors represents a significant shift in attack vectors that security teams must address.
1 week ago
Kill Chain
Critical FreeIPA Vulnerability Exposes Enterprise Authentication Infrastructure to Anonymous Attackers
In September 2026, Red Hat disclosed a critical vulnerability chain in FreeIPA (CVE-2026-76578) with a CVSS score of 9.8 that allows anonymous clients to create reusable administrator credentials without authentication. The flaw exploits a weakness in FreeIPA's access control rules combined with a secondary vulnerability in 389 Directory Server (CVE-2026-76560), enabling attackers to bypass authentication mechanisms and gain administrative privileges on Linux domain controllers. Red Hat successfully reproduced the attack chain twice on default installations, demonstrating how unauthenticated attackers can inject Kerberos identities and obtain administrator group membership. This vulnerability highlights the growing sophistication of identity-based attacks targeting enterprise authentication infrastructure, particularly as organizations increasingly rely on centralized identity management systems for zero trust architectures and cloud-native environments.
1 week ago
Kill Chain
When AI Attacks AI: The 2026 Autonomous Agent Credential Harvesting Campaign
In September 2026, threat actors deployed autonomous AI agent frameworks to conduct large-scale credential harvesting operations, compromising thousands of third-party credentials in under six hours. Google Threat Intelligence Group identified multiple financially motivated groups, including TeamPCP, leveraging AI-assisted tools like DUSTMAKER malware to target AI coding assistants, cloud environments, and supply chains across PyPI, npm, and Docker Hub repositories. The attacks demonstrated unprecedented automation capabilities, with AI systems autonomously managing vulnerability scanning, real-time troubleshooting, and IP rotation without human intervention. This incident represents a critical escalation in AI-enabled cyber threats, coinciding with the rapid adoption of generative AI tools in enterprise environments and the emergence of 'abliterated' open-weight models that bypass safety guardrails.
1 week ago
Kill Chain
Liquid Network Suffers $320M Bitcoin Theft Through Elements Software Vulnerability
In September 2026, unknown attackers claiming to be white hat hackers exploited a vulnerability in the Elements software powering Liquid Network's Bitcoin sidechain, withdrawing nearly 4,000 bitcoin worth approximately $320 million. The attackers used a bug in Elements to create unauthorized L-BTC tokens and then executed a peg-out transaction through SideSwap's authorization key, draining 95% of Liquid's bitcoin reserves. After communicating with Blockstream through encrypted messages embedded in Bitcoin transactions, the attackers returned 3,400 bitcoin but retained approximately 598.5 bitcoin worth $47 million. This incident highlights the growing sophistication of cryptocurrency protocol attacks and the blurred lines between legitimate security research and extortion in the DeFi ecosystem, particularly as Bitcoin layer-2 solutions become increasingly targeted by threat actors.
1 week ago
Kill Chain
ChatGPT Prompt Injection Flaw Exposed Gmail Data Through Hidden Cross-Account Channels
In September 2026, Check Point Research disclosed a critical vulnerability in OpenAI's ChatGPT that allowed attackers to inject malicious prompts that could silently exfiltrate user data from connected applications like Gmail. The attack exploited a shared internal JFrog Artifactory service used by ChatGPT's isolated containers, creating an unauthorized communication channel between different user accounts. Attackers could plant instructions through shared conversations, custom GPTs, or user-pasted prompts that would execute hidden data theft operations while displaying normal responses to victims. OpenAI confirmed the vulnerability and took the internal service offline after disclosure. This incident highlights the emerging risks of AI systems as attack vectors, particularly as organizations increasingly integrate AI tools with sensitive business applications and data sources, making prompt injection attacks a critical new threat category requiring immediate security attention.
1 week ago
Kill Chain
WeChat Zero-Click Worm: How 1.4 Billion Users Were at Risk from Incoming Calls
In July 2026, security researchers at Calif discovered a critical zero-click vulnerability in WeChat that allowed attackers to take complete control of user accounts through incoming calls without any user interaction. The exploit worked by leveraging WeChat's contact trust system, enabling worm-like propagation where compromised accounts could automatically infect other contacts. Affecting WeChat's 1.4 billion user base across iPhone and Android platforms, the vulnerability granted attackers full access to messages, payments, and WeChat's extensive ecosystem of mini-programs and services. Tencent patched the flaw in August 2026 versions 8.0.77 for Android and 8.0.76 for iOS. This incident highlights the growing sophistication of mobile application attacks and the critical importance of securing communication platforms that serve as digital wallets and business ecosystems, particularly as zero-click exploits become increasingly weaponized against high-value messaging applications.
1 week ago
Kill Chain
AI Reasoning Traces Theft: The 2026 Vulnerability That Exposed AI's Hidden Thoughts
In 2026, security researchers discovered a critical vulnerability affecting major AI providers including OpenAI, Anthropic, and Google, where encrypted reasoning traces from large language models could be stolen and decoded. The attack exploited the interchangeable nature of encrypted reasoning blocks across different sessions and models, allowing adversaries to inject traces into weaker models to extract proprietary reasoning in plaintext. This vulnerability enabled four distinct attack vectors: circumventing anti-distillation mechanisms, large-scale private data extraction, revealing hidden hazardous information, and executing invisible prompt injections. Researchers successfully extracted 367 PII artifacts and 182 credentials from 315,320 reasoning blocks scraped from public repositories, demonstrating the significant privacy and security implications. This incident highlights the emerging risks in AI security as organizations increasingly deploy autonomous AI agents and rely on cloud-based AI services, making AI-specific vulnerabilities a critical new attack surface that traditional security measures may not adequately address.
1 week ago
Kill Chain
July 2024 Water Utility Attacks Expose Critical Infrastructure Blind Spots
In July 2024, over 100 water and wastewater treatment systems across multiple states were compromised through vulnerable industrial controllers connected directly to public cellular networks. CISA identified the widespread campaign targeting Rockwell Allen-Bradley, Schneider Electric, and Siemens equipment, with attackers gaining operational control and causing service disruptions including pump station failures and boil-water advisories. The incidents exposed critical infrastructure gaps where operational technology exists outside traditional IT security boundaries, with many systems invisible to network scans but trackable through carrier invoices. This campaign highlights the urgent need for comprehensive network visibility and microsegmentation in critical infrastructure, as traditional network perimeter defenses fail to protect cellular-connected industrial control systems that operate independently of municipal IT networks.
1 week ago
Kill Chain
N-able N-central CVE-2026-86218: When RMM Platforms Become Attack Vectors
N-able released an emergency hotfix for CVE-2026-86218, a maximum-severity remote code execution vulnerability in its N-central remote monitoring and management platform used by IT departments and MSPs. The flaw allows unprivileged attackers to execute malicious code on exposed N-central instances through low-complexity attacks. With nearly 1,500 N-central servers exposed online and evidence of active exploitation flagged by Huntress cybersecurity, the company urged immediate patching to N-central 2026.3 Hotfix 4. This incident highlights the persistent targeting of remote management platforms that provide privileged access to client networks and infrastructure. RMM platforms continue to be attractive targets as they offer attackers potential access to multiple downstream organizations through a single compromise, making them critical components in supply chain attack scenarios.
1 week ago
Kill Chain
ConnectWise Issues Emergency Alert for Unpatched ScreenConnect Vulnerability
In September 2026, ConnectWise disclosed a critical file transfer vulnerability in ScreenConnect Remote Access that affects both cloud and on-premises deployments. The flaw, which has not yet received a CVE identifier, impacts file transfer behavior in ScreenConnect support and access sessions. ConnectWise released temporary mitigation measures requiring administrators to disable TransferFiles permissions while a permanent patch is developed. With nearly 6,000 ScreenConnect instances exposed online according to Shadowserver, this vulnerability poses significant risk to managed service providers and IT departments. This incident highlights the ongoing targeting of remote access tools by threat actors, particularly as organizations increasingly rely on cloud-hosted management platforms. ScreenConnect has been repeatedly exploited by ransomware groups and state-sponsored attackers, making this unpatched vulnerability a critical concern for enterprise security teams.
1 week ago
Kill Chain
Mathspace Breach Exposes 1M+ Records: How ShinyHunters Weaponized Metabase Vulnerabilities
On August 10, 2026, threat actors exploited a critical SQL injection vulnerability in Mathspace's self-hosted Metabase instance, gaining administrator access and stealing personal data from over 1 million students, staff, and parents across Australia and New Zealand. The attack was executed by the ShinyHunters extortion gang, who downloaded the data on August 27 before the breach was confirmed on September 3. This incident was part of a broader campaign targeting multiple organizations' Metabase installations worldwide, affecting companies including Trezor, Framework, and Tally. This breach highlights the critical importance of securing internal reporting systems and data analytics platforms, as threat actors increasingly target business intelligence tools that often have broad database access. The incident demonstrates how zero-day vulnerabilities in widely-used SaaS tools can be weaponized at scale, creating cascading impacts across multiple organizations simultaneously.
1 week ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

