Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 637 to 648 of 5935
AmnesiaStealer: A New Threat to macOS Users
In August 2026, a new macOS-targeted malware named AmnesiaStealer was identified, exploiting ClickFix social engineering tactics to infiltrate systems. The malware deceives users into executing malicious commands, leading to the installation of a payload that captures sensitive data, including browser profiles, passwords, cryptocurrency wallets, and keychain information. Notably, AmnesiaStealer employs a 'stream_module' to duplicate victims' browser sessions in a headless mode, granting attackers real-time control over authenticated sessions without alerting the user. This method allows for seamless data exfiltration and potential misuse of personal and financial information. The emergence of AmnesiaStealer underscores a growing trend in sophisticated social engineering attacks targeting macOS users. The malware's ability to hijack browser sessions and operate undetected highlights the need for heightened vigilance and robust security measures. Organizations and individuals must stay informed about such evolving threats and implement proactive defenses to mitigate potential risks.
1 month ago
Kill Chain
Threema's Secure Messaging Service Disrupted by Large-Scale DDoS Attacks in August 2026
In August 2026, Threema, a Swiss secure messaging service, experienced significant disruptions due to multiple large-scale distributed denial-of-service (DDoS) attacks. These attacks began on August 11, 2026, around 6 PM UTC, causing service interruptions that persisted into the following day. The attackers employed constantly changing patterns, making mitigation efforts challenging. Threema's colocation partner, Nine, was also targeted, further complicating the defense. Organizations using Threema On-Prem, which relies on their own infrastructure, were unaffected. In response, Threema implemented specialized DDoS protection measures to filter attack traffic upstream and reduce the load on its infrastructure. This incident underscores the escalating threat of sophisticated DDoS attacks targeting secure communication platforms. The attackers' adaptive tactics highlight the need for robust and dynamic defense mechanisms. Organizations must remain vigilant and continuously enhance their cybersecurity measures to protect against such evolving threats.
1 month ago
Kill Chain
Evooo1Bot: The Latest Linux Botnet Threatening IoT Security in 2026
In August 2026, security researchers identified a new Mirai-based modular Linux botnet named Evooo1Bot, which has been actively targeting internet-facing gateway devices from manufacturers such as Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link. By exploiting known vulnerabilities, Evooo1Bot compromises these devices, transforming them into SOCKS5 traffic relay nodes. Beyond proxying capabilities, the malware exhibits functionalities including credential theft, SSH brute-forcing, and the execution of distributed denial-of-service (DDoS) attacks. Notably, Evooo1Bot employs encrypted command-and-control communications over port 443 and implements various persistence mechanisms to maintain control over infected systems. The emergence of Evooo1Bot underscores a concerning trend in the evolution of botnet malware, where attackers are increasingly leveraging compromised IoT devices to facilitate anonymized malicious activities. This development highlights the critical need for organizations and individuals to proactively secure their networked devices by regularly updating firmware, changing default credentials, and disabling unnecessary remote access features to mitigate the risk of exploitation by such sophisticated threats.
1 month ago
Kill Chain
Apple's August 2026 Mercenary Spyware Threat Notifications: What You Need to Know
In August 2026, Apple issued threat notifications to users in 110 countries, alerting them to potential mercenary spyware attacks targeting their devices. These sophisticated attacks are typically aimed at individuals based on their profession or activities, such as journalists, activists, politicians, and diplomats. Apple emphasized the severity of these threats and recommended that affected users enable Lockdown Mode and keep their devices updated to mitigate risks. The issuance of these notifications underscores the persistent and evolving nature of mercenary spyware threats. As these attacks become more sophisticated and widespread, it is crucial for individuals and organizations to remain vigilant and adopt comprehensive security measures to protect sensitive information and maintain privacy.
1 month ago
Kill Chain
Brightly Software Data Analyst Sentenced for $2.5M Extortion Scheme
In December 2023, Cameron Curry, a former data analyst contractor for Brightly Software, exploited his access to the company's payroll and corporate data to steal sensitive employee information. After his contract ended, Curry initiated an extortion scheme, sending over 60 emails to Brightly employees between December 11, 2023, and January 24, 2024, demanding a $2.5 million ransom in cryptocurrency. He threatened to release the stolen data and report the company to the SEC for failing to disclose the breach. Brightly paid $7,540 in Bitcoin before involving law enforcement. The FBI's investigation led to Curry's conviction in March 2026 on six counts of cyber extortion, resulting in a two-year prison sentence. This incident underscores the significant risks posed by insider threats, especially when individuals with authorized access misuse their privileges. Organizations must implement robust access controls, continuous monitoring, and employee training to mitigate such risks. The case also highlights the importance of swift incident response and collaboration with law enforcement to address cyber extortion attempts effectively.
1 month ago
Kill Chain
macOS Screen Sharing Flaw Exploited to Deploy Monero Miner
In August 2026, a critical vulnerability (CVE-2026-65400) in macOS's Screen Sharing feature was exploited by attackers to deploy Monero cryptocurrency miners on compromised systems. The flaw allowed unauthenticated remote access via TCP port 5900, enabling attackers to gain root privileges, access files, and modify security settings. The Netherlands' National Cyber Security Centre (NCSC) reported active exploitation of this vulnerability, particularly on systems with port 5900 exposed to the internet. Apple addressed the issue on August 6, 2026, with updates to macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, enhancing state management to enforce proper credential validation. Users unable to update immediately were advised to disable Screen Sharing to mitigate risk. This incident underscores the persistent threat posed by unauthorized cryptocurrency mining and highlights the importance of timely software updates. The exploitation of such vulnerabilities can lead to significant system performance degradation and potential exposure to further malicious activities. Organizations are reminded to regularly review and secure remote access configurations to prevent unauthorized access.
1 month ago
Kill Chain
Vercel Breach 2026: Lessons in OAuth Security and Third-Party Risk Management
In April 2026, Vercel, a prominent cloud platform, experienced a significant security breach initiated through a compromised OAuth token from a third-party AI tool, Context.ai. An attacker exploited this token to access a Vercel employee's Google Workspace account, subsequently infiltrating internal systems and exfiltrating sensitive customer data, including unencrypted credentials and API keys. The breach was publicly disclosed on April 20, 2026, with attackers demanding $2 million for the stolen data. This incident underscores the escalating risks associated with third-party integrations and the critical need for stringent access controls and continuous monitoring of OAuth permissions. The Vercel breach highlights the growing trend of supply chain attacks leveraging OAuth vulnerabilities, emphasizing the necessity for organizations to reassess and fortify their security postures against such sophisticated threats.
1 month ago
Kill Chain
Gunra Ransomware's 2026 Assault on Global Critical Infrastructure
In August 2026, the Gunra ransomware group intensified its attacks on global critical infrastructure sectors, including healthcare, finance, and government. Utilizing malware derived from leaked Conti source code, Gunra employs a double-extortion strategy—encrypting data and threatening to publish stolen information unless a ransom is paid. The group gains initial access by exploiting known vulnerabilities in internet-facing devices, particularly firewalls and VPNs, and uses tools like Impacket for lateral movement. Their operations have expanded through a Ransomware-as-a-Service (RaaS) model, recruiting affiliates to scale attacks. ([itpro.com](https://www.itpro.com/security/ransomware/warning-issued-over-gunra-ransomware-gang-as-attacks-ramp-up-globally?utm_source=openai)) This escalation underscores the evolving threat landscape where ransomware groups are increasingly targeting critical infrastructure with sophisticated tactics. Organizations must prioritize patching known vulnerabilities, implementing robust network segmentation, and maintaining offline backups to mitigate such threats.
1 month ago
Kill Chain
Scottish Government Data Breach: Lessons in Third-Party Security
In August 2026, Scotland's Crown Office and Procurator Fiscal Service (COPFS) disclosed a data breach involving an external supplier managing an online data maturity assessment. The breach exposed personal information of approximately 300 employees, including names, roles, and work email addresses. The incident was detected on August 5, 2026, when the third-party noticed suspicious activity on its network. While COPFS's case-related data remained unaffected, the breach raises concerns about the security of third-party vendors handling sensitive government information. This incident underscores the growing risks associated with third-party service providers in the public sector. As government agencies increasingly rely on external vendors for data management and assessments, ensuring robust security measures and continuous monitoring of these partners becomes imperative to prevent unauthorized access and data breaches.
1 month ago
Kill Chain
Critical Vulnerabilities in Siemens RUGGEDCOM APE1808 Devices with Fortinet FortiOS
In August 2026, Siemens disclosed multiple vulnerabilities in its RUGGEDCOM APE1808 devices, specifically those integrated with Fortinet's FortiOS. The identified vulnerabilities include CVE-2026-23573, an improper neutralization of input during web page generation (cross-site scripting), and CVE-2026-59839, an improper limitation of a pathname to a restricted directory (path traversal). These flaws could allow authenticated remote users to execute arbitrary code or commands and enable privileged authenticated attackers with physical access to delete the file system via crafted CLI commands. Siemens has released updates to address these issues and recommends users update to the latest versions to mitigate potential risks. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-975644.html?utm_source=openai)) This incident underscores the critical importance of timely software updates and vigilant monitoring of industrial control systems. As cyber threats targeting critical infrastructure continue to evolve, organizations must prioritize the implementation of robust security measures and maintain awareness of emerging vulnerabilities to safeguard operational integrity.
1 month ago
Kill Chain
Critical Vulnerabilities in Hitachi Energy APM Edge: CVE-2026-43284 and CVE-2026-43500
In July 2026, Hitachi Energy disclosed two critical vulnerabilities in its APM Edge product, identified as CVE-2026-43284 and CVE-2026-43500. These flaws, present in versions up to and including 6.10, could allow local unprivileged users to escalate privileges to root by exploiting weaknesses in the Linux kernel's IPsec ESP subsystem and RxRPC protocol implementation. Successful exploitation could compromise the confidentiality, integrity, and availability of the affected systems. The disclosure underscores the persistent risks associated with kernel-level vulnerabilities in critical infrastructure components. Organizations relying on Hitachi Energy's APM Edge should prioritize applying the recommended mitigations, such as disabling the esp4, esp6, and rxrpc modules, to safeguard their systems against potential exploitation.
1 month ago
Kill Chain
Critical Vulnerability in AVEVA Enterprise SCADA: CVE-2025-7639
In August 2026, AVEVA disclosed a critical vulnerability (CVE-2025-7639) in its Enterprise SCADA software, affecting versions up to 2025. This flaw allows authenticated users with 'DNA Authority - Operator' privileges to tamper with serialized data, potentially leading to code execution during deserialization under the 'DNA Apps' security group. Exploitation could result in unauthorized control over SCADA systems, posing significant risks to industrial operations. The vulnerability underscores the persistent threat of deserialization flaws in industrial control systems. Organizations are urged to assess their SCADA deployments, apply the recommended patches, and implement robust access controls to mitigate potential exploitation.
1 month ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

