Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 613 to 624 of 5935
GitLab Patches Critical GraphQL Vulnerability (CVE-2026-19478)
In August 2026, GitLab identified and patched a critical vulnerability (CVE-2026-19478) in its Community and Enterprise Editions. This flaw allowed unauthenticated attackers to remotely modify or delete public projects and user data via a GraphQL directive. The vulnerability affected versions from 18.2 up to 18.11.10, 19.0 up to 19.0.7, 19.1 up to 19.1.5, and 19.2 up to 19.2.3. GitLab released patches in versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4 to address this issue. This incident underscores the critical importance of timely vulnerability management and patching in software development environments. The exploitation of such vulnerabilities can lead to significant data loss and operational disruptions, emphasizing the need for robust security practices and continuous monitoring.
1 month ago
Kill Chain
Evooo1Bot: A New Era of Botnet Threats Targeting IoT Devices
In August 2026, security researchers identified a new Linux-based botnet named Evooo1Bot, which extends the capabilities of the infamous Mirai malware beyond traditional Distributed Denial of Service (DDoS) attacks. Evooo1Bot exploits vulnerabilities in various Internet-facing devices, including those from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link, some dating back to 2007. Once compromised, these devices are utilized for credential theft, establishing encrypted command-and-control communications, and setting up reverse SOCKS proxies, effectively transforming them into persistent attacker infrastructure. ([arstechnica.com](https://arstechnica.com/security/2026/03/14000-routers-are-infected-by-malware-thats-highly-resistant-to-takedowns/?utm_source=openai)) The emergence of Evooo1Bot underscores the evolving threat landscape where botnets are increasingly used for multifaceted cyberattacks beyond DDoS. This development highlights the critical need for organizations to secure Internet of Things (IoT) devices, promptly apply security patches, and implement robust network monitoring to detect and mitigate such sophisticated threats.
1 month ago
Kill Chain
WindRelay Malware: A New Threat to Contactless Payments
In August 2026, cybersecurity researchers identified 'WindRelay,' a novel Android malware that exploits Near Field Communication (NFC) technology to facilitate contactless payment fraud. The attack begins with social engineering tactics, where victims are deceived into installing a Remote Access Trojan (RAT) named SpyNote. This RAT enables attackers to remotely deploy the WindRelay malware onto the victim's device. Once installed, WindRelay transforms the compromised smartphone into an unauthorized NFC relay, capturing live card data when victims are manipulated into tapping their payment cards against their own infected devices. This data is then transmitted in real-time to fraudsters, who use it to perform unauthorized transactions at payment terminals. The campaign has primarily targeted individuals in Czechia, Slovakia, and Slovenia, with at least 23 samples of WindRelay identified between November 2025 and July 2026. This incident underscores a significant evolution in mobile payment fraud, combining advanced malware capabilities with sophisticated social engineering to exploit NFC technology. The emergence of WindRelay highlights the increasing sophistication of cybercriminals in leveraging mobile technologies for financial fraud. As NFC-based payment systems become more prevalent, the risk of similar attacks is likely to rise, emphasizing the need for enhanced security measures and user awareness to mitigate such threats.
1 month ago
Kill Chain
AmnesiaStealer: A New Threat to macOS Security
In August 2026, cybersecurity researchers identified AmnesiaStealer, a sophisticated Rust-based malware targeting macOS systems. Distributed via counterfeit GitHub pages, it employs a multi-stage attack to harvest sensitive data, including Keychain credentials, browser information, and files from applications like Apple Notes and Telegram. Notably, it hijacks Chromium-based browsers, granting attackers live control over user sessions. The malware's deployment involves deceptive prompts to capture system passwords, enabling deep system access and data exfiltration. This incident underscores a growing trend of advanced malware targeting macOS platforms, exploiting user trust through social engineering tactics. The emergence of such threats highlights the necessity for enhanced security measures and user awareness to mitigate risks associated with sophisticated information stealers.
1 month ago
Kill Chain
APT36's PATCHCORD Backdoor: A New Threat to South Asian Critical Infrastructure
In August 2026, a cyber espionage campaign attributed to the Pakistan-aligned threat actor APT36 (Transparent Tribe) targeted Afghan telecom providers and South Asian critical infrastructure. The attackers deployed a previously undocumented backdoor named PATCHCORD, delivered through sector-specific lures such as fake VPN installers impersonating Afghan Telecom. PATCHCORD establishes persistence by hijacking browser shortcuts and communicates with a command-and-control server to execute arbitrary commands, enumerate processes, and deploy additional payloads. The campaign also introduced SHEETCORD, a Go-based backdoor utilizing Google Sheets for command-and-control, delivered via domains impersonating India's National Informatics Center. This incident underscores the evolving tactics of APT36, highlighting their focus on critical infrastructure and the use of sophisticated malware to maintain long-term access and exfiltrate sensitive information. Organizations in the region should enhance their cybersecurity measures to detect and mitigate such threats.
1 month ago
Kill Chain
August 2026 Cybersecurity Incidents: City-Forum Campaign, ShipMonk Data Breach, and Cursor CLI Vulnerability
In August 2026, multiple cybersecurity incidents emerged, including the 'City-Forum' campaign targeting unauthenticated guest user access in Salesforce Experience Cloud and ServiceNow Service Portals, leading to significant data exfiltration. Additionally, ShipMonk, a shipping provider for Trezor, suffered a data breach exposing sensitive customer information. Furthermore, Cursor's CLI coding agent was found to execute untrusted repository code without user consent, posing a significant security risk. These incidents underscore the evolving threat landscape, highlighting the need for robust security measures and vigilance against sophisticated attack vectors.
1 month ago
Kill Chain
GeoServer Zero-Day SQL Injection Vulnerability Leads to RCE
In August 2026, a critical zero-day SQL injection vulnerability was discovered in GeoServer's 'jsonArrayContains' function, potentially leading to remote code execution (RCE). The flaw was publicly disclosed on August 12, 2026, by researcher @q1uf3ng, and active exploitation attempts were observed within hours. Attackers probed vulnerable systems, triggering errors without further action, but the risk of full exploitation remained high. GeoServer released patches on August 14, 2026, addressing the issue in versions 3.0.1, 2.28.5, and 2.27.6. Organizations were advised to update immediately to mitigate the risk. This incident underscores the persistent threat posed by SQL injection vulnerabilities in widely used open-source platforms. The rapid exploitation attempts highlight the need for prompt patching and vigilant monitoring of geospatial data servers to prevent potential RCE attacks.
1 month ago
Kill Chain
Jewelbug's Exploitation of XG-Web: A Dual Threat to Governments and Cryptocurrency Users
In August 2026, the China-linked threat actor known as Jewelbug was identified conducting cyber espionage operations targeting governments and militaries, alongside engaging in cryptocurrency fraud. Utilizing a sophisticated tool named XG-Web, Jewelbug transformed victims' browsers into remote-control channels, enabling deep infiltration into host systems and internal networks. This dual-purpose framework facilitated both espionage against governmental entities across the Middle East, Southeast Asia, and South Asia, and financially motivated cryptocurrency fraud aimed at Chinese-speaking users. The group's operations were marked by the development of multiple generations of command-and-control code and a suite of implants affecting browsers, Windows endpoints, Linux servers, and network devices, all feeding into a centralized victim database. The significance of this incident lies in the convergence of state-sponsored cyber espionage and cybercrime within a single operational framework. Jewelbug's activities underscore the evolving landscape where nation-state actors increasingly blur the lines between political objectives and financial gain. This trend highlights the urgent need for organizations to adopt comprehensive cybersecurity measures that address both traditional espionage tactics and emerging cybercriminal methodologies.
1 month ago
Kill Chain
U.S. Private Sector Empowered to Combat Foreign Cybercriminals
On August 12, 2026, President Donald Trump signed a memorandum instructing the National Coordination Center (NCC) to establish a program enabling vetted U.S. private sector companies to conduct cyber operations against foreign Transnational Criminal Organizations (TCOs). This initiative allows authorized firms to perform cyber surveillance and cyber effects operations, including accessing sensitive data and disrupting information systems, under federal oversight. The program aims to counter cyber-enabled crimes such as ransomware, phishing, and financial fraud targeting American citizens. This policy marks a significant expansion of the private sector's role in offensive cyber operations, raising legal and security considerations. Existing U.S. laws prohibit private entities from conducting cyber attacks without court authorization, and this development parallels international trends, such as Germany's recent legislation granting its intelligence agencies broader cyber capabilities.
1 month ago
Kill Chain
Apple Issues Warnings on Mercenary Spyware Threats in 110 Countries
In August 2026, Apple issued threat notifications to users in 110 countries, alerting them to potential targeting by mercenary spyware attacks. These sophisticated attacks are designed to remotely compromise iPhones, often focusing on individuals such as journalists, activists, politicians, and diplomats. Apple emphasized the severity of these threats and advised recipients to take the notifications seriously. The prevalence of mercenary spyware attacks underscores the evolving landscape of cyber threats, highlighting the need for heightened vigilance and robust security measures among high-risk individuals and organizations.
1 month ago
Kill Chain
CTM360's 'RecruitTrap' Campaign Unveils Sophisticated Phishing Tactics
In August 2026, CTM360 uncovered a large-scale phishing campaign named 'RecruitTrap,' involving over 3,000 malicious URLs designed to steal Google and Facebook credentials. The attackers impersonated recruiters from more than 50 organizations across 14 sectors, primarily targeting marketing professionals. Victims received unsolicited emails or meeting invitations leading to counterfeit interview scheduling pages. These pages employed Browser-in-the-Browser (BitB) techniques to display fake authentication pop-ups, tricking users into entering their credentials and multi-factor authentication codes, which were then relayed to the attackers in real time. This incident highlights the increasing sophistication of phishing attacks, particularly those leveraging BitB techniques to bypass traditional security measures. The focus on marketing professionals underscores the strategic targeting of roles with access to sensitive corporate resources, emphasizing the need for heightened vigilance and advanced security protocols to protect against such evolving threats.
1 month ago
Kill Chain
Exploiting Chrome DevTools Protocol: A New Vector for Session Hijacking in Windows Browsers
In August 2026, cybersecurity researchers disclosed a post-exploitation technique that leverages the Chrome DevTools Protocol (CDP) within active Google Chrome or Microsoft Edge processes on Windows systems. This method allows attackers with existing code execution capabilities to access cookies, saved data, and authenticated browser sessions without exploiting any specific browser vulnerabilities. The technique involves injecting code into running browser processes to activate the CDP, thereby exposing the browser's current context over a specified port. This approach builds upon prior research and tools, such as the CDP-Enable-BOF developed by SpecterOps, which facilitates the activation of the debugging server from within an existing browser process. The method requires a running browser process and is limited to x64 systems. The significance of this technique lies in its ability to bypass traditional security measures by operating within the authenticated context of the browser. This development underscores the evolving nature of post-exploitation strategies and highlights the need for robust detection mechanisms to identify unauthorized process injections and anomalous activities within browser processes.
1 month ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

