Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 25 to 36 of 5908
Chinese APT UTA0560 Weaponizes Chrome-Windows Zero-Day Chain in GRIMWEDGE Campaign
In September 2026, Chinese threat actor UTA0560 conducted a sophisticated spear-phishing campaign targeting multiple NGOs using a zero-day exploit chain dubbed BlueMoon. The attackers chained three vulnerabilities - CVE-2026-85046 and CVE-2026-87491 in Chrome, plus CVE-2026-85880 in Windows ALPC - to deploy the GRIMWEDGE JavaScript backdoor. The campaign leveraged reflected XSS vulnerabilities on legitimate university websites to redirect victims to malicious infrastructure hosting the multi-stage exploit chain, demonstrating advanced persistent threat capabilities. This incident highlights the growing threat of patch-gap exploitation, where attackers rapidly weaponize vulnerabilities that are patched in open-source codebases but not yet released in stable versions. With AI-powered exploit development accelerating vulnerability research timelines, organizations face compressed windows to defend against sophisticated nation-state campaigns targeting critical infrastructure and NGOs.
20 hours ago
Kill Chain
Critical SAML Flaw in Siemens Mendix Enables Account Hijacking Across Industrial Systems
A critical authentication bypass vulnerability (CVE-2026-80465) was discovered in Siemens Mendix SAML modules across multiple versions, scoring 8.7 on the CVSS scale. The flaw stems from improper validation of SAML response signatures, allowing unauthenticated remote attackers to hijack user accounts and sessions in specific Single Sign-On (SSO) configurations. Affected versions include Mendix 9.24, 10, and 11 compatible modules, with the vulnerability impacting critical manufacturing and IT infrastructure worldwide. Siemens has released patches requiring immediate updates to versions 3.6.27 or 4.2.3 depending on the Mendix platform version. This incident highlights the growing trend of authentication protocol vulnerabilities targeting enterprise SSO systems, particularly as organizations increasingly rely on federated identity management for cloud and hybrid environments.
21 hours ago
Kill Chain
Critical XSS Vulnerability in Siemens Teamcenter Exposes Manufacturing Systems to Web-Based Attacks
A reflected cross-site scripting (XSS) vulnerability (CVE-2026-58113) was discovered in Siemens Teamcenter's authentication redirect flow, affecting multiple versions across V2412, V2506, V2512, and V2606 product lines. The vulnerability allows unauthenticated remote attackers to inject malicious JavaScript into authenticated user sessions through crafted URLs, potentially enabling data theft and unauthorized actions within victims' Teamcenter sessions. Siemens has released patches for all affected versions and recommends immediate updates to mitigate the CVSS 6.1 rated vulnerability. This incident highlights the persistent threat of web application vulnerabilities in critical manufacturing systems, particularly as organizations increasingly rely on web-based PLM platforms for sensitive industrial operations and intellectual property management.
21 hours ago
Kill Chain
Cisco Email Gateway Under Attack: CVE-2026-76461 Grants Root Access via Malicious Emails
In September 2026, Cisco disclosed CVE-2026-76461, a critical vulnerability in AsyncOS Software for Cisco Secure Email Gateway with a CVSS score of 9.8. The flaw stems from insufficient validation in email parsing logic, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges by sending crafted email messages containing malicious SQL statements. Cisco confirmed active exploitation in the wild and directly contacted customers whose devices showed signs of compromise. The U.S. CISA immediately added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies apply patches by September 17, 2026. This incident highlights the escalating threat to email security infrastructure as attackers increasingly target messaging gateways to gain initial foothold and root-level access, coinciding with broader campaigns against network appliances like the concurrent Fortinet VPN credential attacks reported in late August 2026.
21 hours ago
Kill Chain
Critical LiteSpeed Enterprise Flaw Exposes Shared Hosting Infrastructure to Root Access Attacks
A critical privilege escalation vulnerability in LiteSpeed Web Server Enterprise versions before 6.3.7 allows low-privilege hosting account users to gain root access on shared hosting servers. Disclosed by cPanel on September 14, 2026, the flaw bypasses security controls including CageFS that normally isolate hosting accounts from each other. The vulnerability enables attackers with basic hosting accounts to access or alter other customers' websites and compromise the entire server infrastructure. LiteSpeed released version 6.3.7 on September 11 to address the issue, though specific technical details and CVE assignment remain pending. This represents the third LiteSpeed-related privilege escalation flaw reported since May 2026, highlighting ongoing security challenges in shared hosting environments where multiple customer websites coexist on single servers.
21 hours ago
Kill Chain
Critical mySCADA Vulnerabilities Expose Global Industrial Control Systems to Attack
Critical vulnerabilities CVE-2026-73807 and CVE-2026-82567 were discovered in mySCADA myPRO Manager versions 2.1 and earlier, affecting industrial control systems worldwide. The first vulnerability (CVSS 9.8) allows unauthenticated attackers with network access to bypass authentication and access privileged management functions through the command API. The second vulnerability (CVSS 6.3) exposes an unauthenticated HTTP endpoint that enables attackers to send arbitrary SMS messages through connected GSM modems. These flaws impact critical infrastructure sectors including energy, manufacturing, transportation, and water systems globally. These vulnerabilities highlight the growing threat to industrial control systems as attackers increasingly target operational technology environments. With critical infrastructure under heightened scrutiny following recent nation-state campaigns, organizations must urgently address authentication gaps in SCADA systems that could enable devastating disruptions to essential services.
21 hours ago
Kill Chain
Apple's Record-Breaking Security Update: 261 Vulnerabilities Patched Across All Platforms
On September 14, 2024, Apple released comprehensive security updates across all operating systems, patching a record-breaking 261 vulnerabilities in iOS 27, macOS Golden Gate 27, and other platforms. The vulnerabilities spanned critical system components including kernel memory corruption, privilege escalation flaws, and sandbox escape vulnerabilities affecting core frameworks like WebKit, Kernel, CUPS, and SMB protocols. While Apple reported no active exploitation, the patches addressed severe security gaps including remote code execution, information disclosure, and authentication bypass vulnerabilities that could enable attackers to gain root privileges or access sensitive user data. This massive patch release reflects the evolving complexity of modern attack surfaces and Apple's proactive approach to security hardening. The scale of vulnerabilities demonstrates the critical importance of comprehensive endpoint security and zero-trust architectures as threat actors increasingly target foundational system components and inter-service communications.
21 hours ago
Kill Chain
Six Critical Vulnerabilities Expose Digital Watchdog Surveillance Systems to Complete Compromise
In September 2026, CISA disclosed six critical vulnerabilities in Digital Watchdog VMAX DVR and NVR surveillance systems affecting all product versions worldwide. The vulnerabilities include authentication bypass (CVE-2026-68953), hard-coded credentials (CVE-2026-66890, CVE-2026-68950), missing authentication for critical functions (CVE-2026-68070), missing authorization (CVE-2026-66887), and predictable session tokens (CVE-2026-66372). Successful exploitation grants full administrative control, allowing attackers to view surveillance footage, alter configurations, and use devices as network pivot points with root-level access. This disclosure highlights the growing security risks in IoT surveillance infrastructure, particularly as organizations increasingly deploy connected security devices without proper hardening. The vulnerabilities demonstrate classic IoT security failures that enable lateral movement within critical infrastructure networks.
21 hours ago
Kill Chain
BambooToken Malware Exploits MQTT Protocol in Global Multi-Platform Campaign
BambooToken is a sophisticated multi-platform malware campaign discovered in early 2026 that uses MQTT protocol for command and control across Windows and Linux systems. Active since February 2023, the threat actors exploit DLL sideloading techniques via Tendyron's OnKey authentication software to compromise organizations across Asia and South America. The malware demonstrates advanced evasion capabilities by leveraging legitimate PKI security tokens as attack vectors and using Cloudflare-proxied infrastructure to manage infections at scale. Researchers have identified compromised entities including mobile applications, financial organizations, hotels, and critical infrastructure systems across multiple countries. This incident highlights the evolving sophistication of threat actors who are increasingly adopting unconventional communication protocols and supply chain attack vectors to evade traditional security controls and maintain persistent access to high-value targets.
21 hours ago
Kill Chain
Yemen Threat Actors Exploit Claude AI for Advanced Weapons Development
In September 2026, Anthropic disclosed that threat actors based in northern Yemen exploited their Claude AI models to develop guidance, navigation, and control software for advanced weapons systems, including guided rockets, ballistic missiles with 2,000+ km range, and hypersonic glide vehicles. The actors used multiple Claude instances simultaneously, assigning specialized roles to each AI system while employing evasion techniques to bypass safety guardrails. Although Anthropic's safeguards blocked many requests, the actors successfully developed software and conducted field tests of a guided rocket, though initial tests failed. This incident represents a concerning escalation in AI-enabled weapons proliferation, demonstrating how generative AI can democratize sophisticated military engineering capabilities previously limited to nation-states and well-funded organizations.
21 hours ago
Kill Chain
Black Axe Cybercrime Leaders Extradited: International Crackdown on Romance Scam Network
Five alleged leaders of Black Axe's South African operations were extradited to the United States in December 2024 to face charges related to romance scams and advance fee fraud. The Nigerian nationals, including Cape Town zone founder Perry Osagiede, operated sophisticated financial fraud schemes from 2011-2021, using fake identities to manipulate victims into sending money through fabricated emergencies, business partnerships, and romantic relationships. The group leveraged business entities and compromised victim accounts to launder proceeds, with some cases involving extortion through threats to release sensitive photos. This extradition represents the latest phase of intensified global law enforcement action against Black Axe, a hierarchical cybercrime organization generating billions in annual criminal proceeds across dozens of countries. The coordinated international response demonstrates increasing capability to pursue transnational cybercriminals across jurisdictions and disrupt their financial networks.
22 hours ago
Kill Chain
Active GitLab CVE-2026-85706 Exploitation: CISA Issues Emergency Warning
In September 2026, CISA added GitLab vulnerability CVE-2026-85706 to its Known Exploited Vulnerabilities catalog after hackers began actively exploiting the maximum-severity path traversal flaw. The vulnerability stems from missing authentication enforcement in GitLab's repository commits API, allowing unauthenticated attackers to read credentials, secrets, and sensitive information through a single HTTP request. GitLab patched the flaw in versions 19.3.2, 19.2.6, and 19.1, but watchTowr security researchers detected widespread internet probing for vulnerable servers within 24 hours of the patch release. This incident highlights the accelerating timeline between vulnerability disclosure and active exploitation, as threat actors increasingly weaponize DevSecOps platform vulnerabilities to access critical development infrastructure and secrets management systems used by Fortune 100 companies.
1 day ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

