Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 2053 to 2064 of 5957
DriveSurge: Massive Website Compromise Leads to Widespread Malware Distribution
In June 2026, the DriveSurge operation was uncovered, revealing a sophisticated cybercriminal campaign that compromised thousands of legitimate websites to deliver malware through ClickFix and FakeUpdate attacks. Utilizing the zTDS traffic distribution system, attackers redirected unsuspecting visitors to malicious sites, leading to the installation of backdoors and other malware. This operation functioned as an initial access broker, selling system access to other threat actors for various malicious activities. The campaign targeted both Windows and macOS users and remained undetected for nearly a year, highlighting the evolving tactics of cybercriminals. The DriveSurge incident underscores the increasing complexity and scale of cyberattacks, emphasizing the need for organizations to enhance their cybersecurity measures. The use of trusted websites to distribute malware indicates a shift towards more deceptive and widespread attack vectors, making it imperative for businesses to implement robust security protocols and user education to mitigate such threats.
3 months ago
Kill Chain
Exploiting Google Gemini: The Rise of Prompt Injection Attacks
In June 2026, a security vulnerability was discovered in Google Gemini's voice assistant, allowing attackers to exploit its notification summarization feature through prompt injection techniques. By embedding malicious commands within message notifications, adversaries could manipulate the assistant to perform unauthorized actions such as controlling smart home devices, initiating video streams, conducting social engineering attacks, and compromising the integrity of large language model (LLM) memory. This flaw was identified and responsibly disclosed by SafeBreach, leading Google to implement content classifier updates to mitigate the issue. This incident underscores the evolving threat landscape associated with AI-powered assistants and the critical need for robust security measures to prevent prompt injection attacks. As AI integration in daily applications increases, ensuring the integrity and security of these systems becomes paramount to protect users from sophisticated exploitation methods.
3 months ago
Kill Chain
Global Stock Exchange Email Espionage: A 2025 Cybersecurity Wake-Up Call
In October 2025, an unidentified threat actor infiltrated the Microsoft Outlook mailbox of a senior executive at a global stock exchange, maintaining access for over five months. The attackers utilized legitimate Windows tools to establish persistence, deploying implants disguised as Adobe and OneDrive applications. They exfiltrated sensitive emails containing confidential organizational information via a command-and-control channel set up through Dropbox. The exfiltration occurred bi-weekly until February 2026, with the final observed activity in March 2026. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/global-stock-exchange-hit-monthslong-email-campaign?utm_source=openai)) This incident underscores the increasing sophistication of cyber-espionage campaigns targeting high-value financial institutions. The use of legitimate tools for malicious purposes highlights the necessity for enhanced monitoring and response strategies to detect and mitigate such stealthy attacks. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/global-stock-exchange-hit-monthslong-email-campaign?utm_source=openai))
3 months ago
Kill Chain
Critical HTTP/2 Bomb Vulnerability Threatens Major Web Servers
In June 2026, cybersecurity researchers identified a critical remote denial-of-service (DoS) vulnerability, termed 'HTTP/2 Bomb,' affecting major web servers including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. This exploit leverages the HPACK header compression scheme in HTTP/2, allowing a single attacker to rapidly exhaust server memory by sending minimal data that results in significant memory allocation. A single client on a standard home internet connection can consume up to 32GB of server memory in approximately 20 seconds, rendering the server inaccessible. The discovery of the HTTP/2 Bomb underscores the evolving nature of cyber threats targeting foundational internet protocols. This incident highlights the necessity for continuous vigilance and prompt patching of server software to mitigate emerging vulnerabilities. Organizations are advised to review and adjust their HTTP/2 configurations to prevent potential exploitation.
3 months ago
Kill Chain
WeedHack Malware Campaign: A Wake-Up Call for Minecraft Players
In early 2026, a large-scale malware campaign named 'WeedHack' targeted Minecraft players by distributing malicious mods, clients, and cheats through platforms like YouTube and SEO poisoning. This Malware-as-a-Service operation infected over 116,000 systems globally, with daily infections ranging between 2,000 and 3,000. The malware harvested sensitive information, including browser credentials, Discord tokens, and cryptocurrency wallets, and offered remote access capabilities to attackers. ([mcafee.com](https://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-as-a-service-campaign-research/?utm_source=openai)) The campaign's success underscores the vulnerabilities within gaming communities, particularly among younger users who may lack cybersecurity awareness. The use of popular platforms for distribution and the sophisticated nature of the malware highlight the evolving tactics of cybercriminals targeting the gaming industry. ([mcafee.com](https://www.mcafee.com/blogs/security-news/minecraft-malware-campaign-research-teen-hacker-cyberbullying/?utm_source=openai))
3 months ago
Kill Chain
VS Code Vulnerability Exposes GitHub OAuth Tokens to Attackers
In June 2026, a critical vulnerability was disclosed in Microsoft Visual Studio Code (VS Code) that allowed attackers to steal GitHub OAuth tokens through a single malicious link. Security researcher Ammar Askar demonstrated that by exploiting the webview implementation in VS Code, an attacker could execute malicious JavaScript to install a rogue extension, thereby capturing OAuth tokens with full read and write access to a user's repositories, including private ones. This vulnerability posed significant risks to developers, potentially exposing sensitive code and intellectual property. This incident underscores the growing threat of supply chain attacks targeting development environments. As developers increasingly rely on integrated tools and extensions, the security of these components becomes paramount. Organizations must remain vigilant, ensuring that their development tools are secure and up to date to prevent unauthorized access and data breaches.
3 months ago
Kill Chain
Urgent Advisory: Securing Automatic Tank Gauge Systems Against Cyber Threats
In April 2026, the Cybersecurity and Infrastructure Security Agency (CISA), along with multiple federal partners, issued an urgent advisory regarding active cyberattacks targeting Automatic Tank Gauge (ATG) systems across the United States. These systems, integral to monitoring fuel storage tanks in sectors such as Energy, Chemical, Food and Agriculture, and Transportation, were found to be vulnerable due to internet exposure and weak authentication mechanisms. Threat actors exploited these weaknesses to gain unauthorized access, potentially allowing them to manipulate tank levels, disable alarms, and disrupt operations. While no physical damage was reported, the incidents underscored significant cybersecurity gaps in critical infrastructure. ([infoodandfuel.org](https://www.infoodandfuel.org/news/cybersecurity-alert-automatic-tank-gauge-systems-targeted?utm_source=openai)) This advisory highlights the escalating threat landscape for operational technology (OT) systems, emphasizing the need for immediate action to secure ATG systems. The incidents serve as a stark reminder of the vulnerabilities present in internet-exposed OT devices and the potential for malicious actors to exploit these weaknesses to disrupt essential services.
3 months ago
Kill Chain
CISA Adds Two Known Exploited Vulnerabilities to Catalog
On June 2, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2022-0492, a Linux Kernel Improper Authentication Vulnerability, and CVE-2025-48595, an Android Framework Integer Overflow Vulnerability. Both vulnerabilities are actively exploited, posing significant risks to federal enterprises. CVE-2022-0492 allows unauthorized access to Linux systems, while CVE-2025-48595 enables local privilege escalation on Android devices without user interaction. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-48595?utm_source=openai)) The inclusion of these vulnerabilities in the KEV Catalog underscores the critical need for organizations to promptly address known security flaws. With active exploitation in the wild, timely remediation is essential to mitigate potential threats and protect sensitive information.
3 months ago
Kill Chain
Microsoft Build 2026: Integrating Security Across the Development Lifecycle
At Microsoft Build 2026, held on June 2, 2026, Microsoft unveiled a comprehensive suite of security tools and capabilities aimed at integrating security throughout the development lifecycle. Key announcements included the introduction of the Microsoft Security multi-model agentic scanning harness (codename MDASH), designed to proactively identify and validate exploitable vulnerabilities in codebases, and the integration between Microsoft Defender and GitHub Code Security to prioritize and remediate code vulnerabilities efficiently. Additionally, Microsoft introduced the Agent 365 SDK to help developers build secure, enterprise-ready AI agents by default, and announced Defender AI model scanning to verify the integrity of AI models before deployment. These initiatives reflect Microsoft's commitment to embedding security into the development process, enabling faster and more secure innovation without compromising control. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/06/02/microsoft-build-2026-securing-code-agents-and-models-across-the-development-lifecycle/?utm_source=openai)) The relevance of these announcements is underscored by the increasing complexity and sophistication of cyber threats, particularly those leveraging AI to exploit vulnerabilities. By integrating advanced security measures directly into development tools and workflows, Microsoft aims to empower developers and security teams to stay ahead of emerging threats, ensuring that security is a foundational aspect of the development process rather than an afterthought.
3 months ago
Kill Chain
Trail of Bits Uncovers Critical Flaws in AI Skill Marketplaces
In June 2026, Trail of Bits published an analysis revealing significant vulnerabilities in public AI skill marketplaces, where malicious skills were found to steal credentials, exfiltrate data, and hijack agents. The study demonstrated that existing skill scanners, including those from ClawHub, Cisco, and skills.sh, were ineffective in detecting these threats. The researchers successfully bypassed these scanners using straightforward techniques, highlighting the inadequacy of current defenses against supply chain attacks in AI ecosystems. This incident underscores the urgent need for robust security measures in AI skill distribution channels. As AI agents become integral to various workflows, the proliferation of unvetted skills poses a substantial risk. Organizations must implement stringent governance frameworks, including version control, digital signing, zero-trust access, and centralized repositories, to mitigate these emerging threats.
3 months ago
Kill Chain
CISA Urges Immediate Action on Actively Exploited Oracle WebLogic Vulnerability CVE-2024-21182
In June 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) mandated federal agencies to address a high-severity vulnerability in Oracle WebLogic Server, identified as CVE-2024-21182. This flaw, patched in July 2024, allows unauthenticated attackers to exploit the T3 and IIOP protocols, potentially leading to unauthorized access to critical data. Despite the availability of patches, over 1,500 WebLogic servers remained exposed online, making them susceptible to exploitation. The resurgence of attacks targeting CVE-2024-21182 underscores the persistent threat posed by unpatched vulnerabilities. Organizations are urged to prioritize timely patch management to mitigate risks associated with known exploits, especially those that have been previously addressed but continue to be exploited due to delayed remediation efforts.
3 months ago
Kill Chain
Why the Browser is Now the Front Line for AI Security
In June 2026, a significant cybersecurity incident highlighted the browser as a critical frontline in AI security. Adversaries leveraged AI to rapidly develop and deploy sophisticated phishing kits, outpacing traditional defense mechanisms. Concurrently, employees' unregulated adoption of AI tools, including large language models (LLMs) and AI browser extensions, introduced vulnerabilities by exposing sensitive data and granting unauthorized access. This dual threat underscores the necessity for security platforms with deep visibility into browser sessions to effectively monitor and mitigate AI-driven risks. The incident underscores the evolving threat landscape where AI accelerates both attack capabilities and the proliferation of unvetted tools within organizations. As AI technologies become more integrated into daily operations, the urgency for comprehensive browser security solutions that can adapt to these rapid developments has never been greater.
3 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

