Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 673 to 684 of 5935
City-Forum Campaign: A Wake-Up Call for SaaS Security
Since at least March 2025, an unidentified threat actor has been conducting a prolonged data theft campaign, dubbed "City-Forum," targeting organizations across various sectors by exploiting overly permissive guest access in Salesforce and ServiceNow platforms. The attacker developed custom tools to interact with less-documented interfaces, such as Salesforce's Lightning Web Runtime and ServiceNow's Service Portal search endpoint, enabling unauthorized access to sensitive data including customer information, support tickets, and internal communications. This incident underscores the evolving sophistication of cyber threats, highlighting the need for organizations to reassess and fortify their security configurations, especially concerning third-party integrations and guest access permissions. The campaign's duration and the attacker's ability to exploit undocumented interfaces emphasize the importance of continuous monitoring and proactive security measures.
1 month ago
Kill Chain
Critical Vulnerabilities in Belgium's eID System Expose Citizens to Remote Code Execution
In August 2026, severe vulnerabilities were discovered in Belgium's eID authentication system, specifically within the 'Connective' browser extension. These flaws allowed attackers to steal citizens' identities, payment information, and execute remote code on users' machines. The extension, used by over 2 million individuals, failed to verify the origin of activation tokens, enabling malicious websites to impersonate legitimate services and interact with users' eID systems. Additionally, the native host application could be exploited to load arbitrary DLL files, leading to remote code execution without user interaction. This incident underscores the critical need for rigorous security assessments of browser extensions, especially those integral to national identity and financial systems. It highlights the broader risks associated with browser extension vulnerabilities and the potential for widespread exploitation if not promptly addressed.
1 month ago
Kill Chain
Jewelbug APT's Dual Threat: Espionage Meets Cryptocurrency Theft
In August 2026, the Chinese state-sponsored advanced persistent threat (APT) group known as Jewelbug was identified conducting both cyber espionage and financial theft operations. Utilizing a unified command-and-control platform, Jewelbug managed to infiltrate government, military, and telecommunications organizations across Asia and the Middle East, while simultaneously orchestrating large-scale cryptocurrency thefts through fraudulent exchanges. Their sophisticated tactics included deploying custom malware such as the 'Antino' and 'ClientKing' backdoors, and a malicious browser extension named 'PDF Viewer' to exfiltrate sensitive data and financial assets. This incident underscores the evolving landscape of cyber threats, where state-sponsored actors are increasingly blending espionage with financial crimes. The dual-purpose operations of groups like Jewelbug highlight the necessity for organizations to adopt comprehensive cybersecurity strategies that address both traditional espionage and emerging financial cyber threats.
1 month ago
Kill Chain
Exploitation of SharePoint Authentication Bypass Vulnerability CVE-2026-55040
In July 2026, Microsoft disclosed a critical vulnerability in SharePoint Server, identified as CVE-2026-55040, which allows unauthenticated attackers to bypass authentication mechanisms via weaknesses in the JWT token validation process. This flaw enables adversaries to impersonate legitimate users, including administrators, potentially leading to unauthorized data access and modification. Following the release of a proof-of-concept (PoC) exploit by Rapid7, threat actors began actively exploiting this vulnerability, with multiple incidents reported globally, including a significant breach affecting the Swiss government's IT network. The rapid exploitation of CVE-2026-55040 underscores the critical importance of timely patch management and proactive security measures. Organizations utilizing SharePoint are urged to apply the latest security updates promptly and to implement robust monitoring and access controls to mitigate the risk of unauthorized access and data breaches.
1 month ago
Kill Chain
Bleeding Llama: Critical Memory Leak in Ollama (CVE-2026-7482)
In May 2026, a critical vulnerability known as 'Bleeding Llama' (CVE-2026-7482) was disclosed in Ollama, a widely used framework for running large language models locally. This unauthenticated heap out-of-bounds read flaw allows remote attackers to exfiltrate sensitive data—including API keys, user conversations, and system prompts—from any internet-exposed Ollama server with minimal effort. The vulnerability affects versions up to 0.17.0, with an estimated 300,000 servers exposed at the time of disclosure. Ollama addressed the issue in version 0.17.1, but many instances remain unpatched, leaving organizations vulnerable to data breaches and unauthorized access. ([lyrie.ai](https://lyrie.ai/research/research/2026-05-08-bleeding-llama-ollama-cve-2026-7482?utm_source=openai)) The 'Bleeding Llama' incident underscores the critical importance of timely patch management and robust security practices in AI infrastructure. As AI models become integral to business operations, ensuring their security is paramount to prevent data leaks and maintain trust in AI-driven systems.
1 month ago
Kill Chain
Near-Autonomous AI Cyberattack on Taiwanese Government in 2026
In August 2026, a sophisticated cyberattack targeted the Taiwanese government, marking the first publicly known instance of a near-autonomous AI-driven breach against a state entity. Suspected Chinese hackers employed open-source AI frameworks, Hermes and OpenClaw, to orchestrate the attack, which led to the exfiltration of over 2,500 personnel records. The AI system autonomously adapted during the operation, conducting 'Learning Cycles' to identify vulnerabilities and expanding its reach to government IT supply chain vendors, a nuclear safety agency, and multiple energy sector companies. This incident underscores the escalating use of AI in cyber warfare, highlighting the need for enhanced defensive measures against autonomous threats. The attack's ability to self-correct and adapt without human intervention signifies a paradigm shift in cyberattack methodologies, necessitating a reevaluation of current cybersecurity strategies to address AI-driven threats.
1 month ago
Kill Chain
Unveiling 'ShieldBreak': A New Zero-Day Threat in Microsoft Defender
In August 2026, security researcher Nightmare Eclipse disclosed a zero-day vulnerability named 'ShieldBreak' in Microsoft Defender, allowing attackers to escalate privileges to SYSTEM level on fully patched Windows 10, Windows 11, and Windows Server systems. This exploit leverages a user-mode callback hook during a Defender cloud-hydration scan via the Cloud Filter API (cfapi), effectively bypassing the previous 'RoguePlanet' patch (CVE-2026-50656). The proof-of-concept demonstrated a 100% success rate on tested systems. This incident underscores the persistent challenges in securing endpoint protection platforms and highlights the need for continuous vigilance and rapid response to emerging threats. Organizations must reassess their security postures, especially concerning privilege escalation vulnerabilities, to mitigate potential risks associated with such exploits.
1 month ago
Kill Chain
Signal Introduces Automatic Key Verification to Strengthen Chat Security
In August 2026, Signal introduced Automatic Key Verification, a feature designed to enhance user security by automatically verifying the integrity of encrypted conversations. This system employs trusted third-party auditors to ensure that public encryption keys associated with user accounts remain consistent and unaltered, thereby mitigating the risk of man-in-the-middle attacks. Users can enable this feature through the app's privacy settings, providing a seamless method to confirm secure communications without manual safety number verification. The implementation of Automatic Key Verification addresses the growing concern over sophisticated interception techniques targeting encrypted messaging platforms. By automating the verification process, Signal aims to bolster user confidence and maintain the platform's reputation for robust security in an era where digital communication threats are increasingly prevalent.
1 month ago
Kill Chain
Urgent: Microsoft SharePoint CVE-2026-55040 Exploited in the Wild
In July 2026, a critical vulnerability identified as CVE-2026-55040 was discovered in Microsoft SharePoint's JWT token validation pipeline. This flaw allowed unauthenticated attackers to impersonate any SharePoint user, including administrators, by bypassing authentication mechanisms. Microsoft addressed this issue in their July 2026 Patch Tuesday updates, urging organizations using SharePoint Enterprise Server 2016 and SharePoint Server 2019 to apply the patches promptly. The urgency of this patch was underscored when, shortly after its release, proof-of-concept exploit code became publicly available and was actively used in attacks targeting unpatched SharePoint servers. This rapid weaponization highlights the critical need for organizations to maintain up-to-date security measures and promptly apply patches to mitigate emerging threats.
1 month ago
Kill Chain
Unmasking the Threat: North Korean IT Worker Impersonation in 2026
In July 2026, the U.S. Department of State issued an alert regarding North Korean IT workers impersonating foreign nationals to secure remote employment with U.S. companies. These operatives utilized falsified identities, AI-generated profiles, and deepfake technologies to bypass standard hiring processes. Once employed, they exfiltrated sensitive data, including source code and proprietary information, and funneled salaries back to North Korea, thereby circumventing international sanctions and funding the regime's activities. This incident underscores the evolving sophistication of social engineering tactics in cyber threats. The integration of AI and deepfake technologies into these schemes highlights the urgent need for organizations to enhance their identity verification and remote hiring protocols to prevent similar infiltrations.
1 month ago
Kill Chain
Lazarus Group's Operation Dream Job: Exploiting Windows Zero-Day to Target Defense Firms
In July 2026, the North Korean state-sponsored Lazarus Group exploited a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies in Europe and India. This vulnerability, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys), allowed attackers to escalate local privileges to SYSTEM level. The group utilized this exploit in their Operation Dream Job campaign, delivering malicious payloads through fraudulent recruitment offers to employees in defense, aerospace, and aviation organizations. The attacks led to unauthorized access, data exfiltration, and deployment of advanced malware, including the FudModule rootkit and the Troy backdoor, compromising sensitive military technologies such as surveillance sensors, drones, and robotics. This incident underscores the persistent threat posed by nation-state actors leveraging zero-day vulnerabilities to infiltrate critical sectors. The Lazarus Group's continued evolution in tactics, including the use of sophisticated malware and exploitation of legitimate web infrastructure, highlights the need for organizations to adopt proactive cybersecurity measures, such as timely patch management, employee training on social engineering tactics, and robust network monitoring to detect and mitigate such advanced persistent threats.
1 month ago
Kill Chain
FBI Issues Warning on Rising Sextortion Threats Targeting Online Accounts
In August 2026, the FBI issued a public service announcement warning that cybercriminals are targeting both adults' and children's online accounts to steal sexually explicit images and videos. These attackers gain unauthorized access through methods such as phishing, social engineering, and exploiting weak passwords. Once obtained, the explicit content is used to blackmail victims, sold on criminal marketplaces, or shared with other malicious actors, leading to further exploitation and harassment. This incident underscores a growing trend in cyber threats where personal and sensitive data are exploited for financial gain and coercion. The increasing sophistication of these attacks highlights the urgent need for enhanced cybersecurity measures, public awareness, and proactive defense strategies to protect individuals from such exploitation.
1 month ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

