Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 685 to 696 of 5935
Critical Adobe Commerce Vulnerability CVE-2026-71362: Immediate Action Required
In August 2026, a critical vulnerability (CVE-2026-71362) was identified in Adobe's Commerce and Magento platforms, allowing unauthenticated attackers to hijack customer accounts. The flaw, stemming from improper handling of customer identity in session management, enabled unauthorized access to sensitive customer data. Security firm Sansec reported active exploitation attempts, emphasizing the urgency for immediate patching. This incident underscores the persistent threat posed by web application vulnerabilities, highlighting the necessity for robust session management and prompt application of security updates to protect customer information and maintain trust.
1 month ago
Kill Chain
Hundreds of Fake Chrome VPN Extensions Compromise User Security
In August 2026, researchers uncovered a campaign involving over 737 malicious Chrome browser extensions that impersonated reputable VPN services such as Proton VPN, NordVPN, and ExpressVPN. These extensions, downloaded nearly 75,000 times primarily by Russian users, rerouted all browser traffic through SOCKS5 proxies controlled by a single operator. This setup allowed the threat actor to monitor users' browsing activities, including destination URLs and any unencrypted data transmitted over HTTP. The extensions employed deceptive tactics, including advertising non-existent premium server locations and using misleading disclosures to evade detection. Despite Google's removal of over 200 of these extensions, more than 500 remained available in the Chrome Web Store at the time of discovery. This incident underscores the persistent threat posed by malicious browser extensions and highlights the need for vigilant scrutiny of browser add-ons. Users are advised to verify the authenticity of extensions before installation and to regularly review and manage their browser's proxy settings to prevent unauthorized data interception.
1 month ago
Kill Chain
Understanding the 'Plug and Pwn' Attack: A New Threat to Windows Systems
In August 2026, security researchers unveiled the 'Plug and Pwn' attack, exploiting Windows' Plug and Play feature to gain SYSTEM privileges by emulating USB devices. By presenting fake USB hardware, attackers could trigger Windows to install vulnerable vendor software automatically, leading to unauthorized access. Notably, some attack vectors required no user interaction or physical device connection, utilizing Remote Desktop Protocol (RDP) to achieve the same outcome. This method underscores significant vulnerabilities in Windows' device installation processes, potentially allowing attackers to execute arbitrary code with elevated privileges. The 'Plug and Pwn' attack highlights the evolving sophistication of hardware-based exploits and the critical need for organizations to reassess endpoint security measures. As attackers increasingly leverage legitimate system functionalities for malicious purposes, it becomes imperative to implement stringent device installation policies and monitor for anomalous hardware behaviors to mitigate such threats.
1 month ago
Kill Chain
Lazarus Group's Operation Dream Job: Exploiting Windows Zero-Day to Deploy 'Troy' Backdoor
In August 2026, the North Korean state-sponsored Lazarus Group exploited a zero-day vulnerability, CVE-2026-68820, in the Windows Ancillary Function Driver for WinSock (AFD.sys) to target defense and aerospace companies across France, Germany, Brazil, and India. Utilizing their 'Operation Dream Job' campaign, they lured professionals with fake job offers, leading victims to download malicious PDFs or trojanized PDF viewers. This method facilitated the deployment of a new backdoor named 'Troy,' granting the attackers remote access and control over compromised systems. The campaign's sophistication underscores the persistent threat posed by Lazarus Group to critical industries worldwide. This incident highlights the evolving tactics of nation-state actors in leveraging zero-day vulnerabilities combined with social engineering to infiltrate high-value targets. Organizations must remain vigilant, ensuring timely patching of vulnerabilities and educating employees about the risks of unsolicited job offers and phishing attempts.
1 month ago
Kill Chain
Android Malware Exploits NFC to Commit Financial Fraud
In August 2026, cybersecurity firm Group-IB uncovered a sophisticated Android malware campaign combining the SpyNote Remote Administration Tool (RAT) and WindRelay NFC relay malware. Attackers impersonated bank employees, convincing victims to install a malicious app granting remote access. Utilizing SpyNote, they installed WindRelay, transforming the device into a fraudulent contactless reader to capture and relay credit card data, enabling unauthorized transactions. This operation, executed within a 13-minute phone call, resulted in unauthorized loans and financial losses for victims. This incident underscores a significant escalation in mobile malware sophistication, particularly in exploiting NFC technology for financial fraud. The seamless integration of remote access tools with NFC relay capabilities highlights the evolving tactics of cybercriminals, emphasizing the need for heightened vigilance and advanced security measures to protect against such multifaceted threats.
1 month ago
Kill Chain
City-Forum Data Theft Attacks: A Wake-Up Call for SaaS Security
In August 2026, a data theft campaign named 'City-Forum' was identified, targeting misconfigured Salesforce Experience Cloud and ServiceNow customer portals. The attackers exploited overly permissive sharing rules and portal configurations, allowing unauthorized access to sensitive data through anonymous guest accounts. The campaign, traced to the IP address 158.220.87.79 associated with the domain city-forum.com, has been active since at least March 2025, affecting various sectors including telecommunications, finance, enterprise software, and public services. The 'City-Forum' attacks underscore the critical importance of securing SaaS platforms against unauthorized access. Organizations must review and tighten guest-user permissions and sharing settings to prevent data exposure. This incident highlights a growing trend of cybercriminals exploiting misconfigurations in widely used platforms, emphasizing the need for continuous monitoring and proactive security measures.
1 month ago
Kill Chain
Microsoft's August 2026 Patch Tuesday: Addressing 398 Security Vulnerabilities
In August 2026, Microsoft released patches for 398 security vulnerabilities across its Windows operating systems and supported software. Among these, CVE-2026-68820, a privilege escalation flaw in the afd.sys component, was actively exploited. This vulnerability allows attackers to elevate privileges by exploiting race conditions in the Windows socket driver. Additionally, two other vulnerabilities, CVE-2026-62832 and CVE-2026-72971, were publicly disclosed prior to the patch release, highlighting the critical need for timely updates. The increasing volume of vulnerabilities, attributed to AI-driven discovery methods, underscores the necessity for organizations to enhance their patch management processes. The active exploitation of CVE-2026-68820 emphasizes the urgency of applying these patches promptly to mitigate potential security breaches.
1 month ago
Kill Chain
Gunra Ransomware's 2026 Exploitation of Fortinet Vulnerabilities: A Wake-Up Call for Cybersecurity
In early 2026, the Gunra ransomware group, a Ransomware-as-a-Service (RaaS) operation, exploited known vulnerabilities in Fortinet products, notably CVE-2026-24858, to bypass multi-factor authentication (MFA) and gain unauthorized access to critical infrastructure and government organizations worldwide. Utilizing the leaked Conti ransomware code, Gunra executed double-extortion attacks, encrypting data and threatening to publish stolen information unless ransoms were paid. The group's operations expanded through a structured affiliate program, targeting sectors such as healthcare, finance, manufacturing, transportation, and government services. ([shellcodex.com](https://shellcodex.com/ransomware/group/gunra?utm_source=openai)) This incident underscores the persistent threat posed by ransomware groups leveraging known vulnerabilities and the importance of timely patching and robust security measures. The exploitation of Fortinet flaws highlights the need for organizations to prioritize vulnerability management and implement comprehensive security protocols to mitigate such risks. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-22572/?utm_source=openai))
1 month ago
Kill Chain
Ransomware Attack Disrupts Colombian Justice Ministry Amid Political Transition
In early August 2026, Colombia's Ministry of Justice experienced a ransomware attack that disrupted several public-facing services, including those related to illicit-drug monitoring and legal processes. The incident occurred just days before the nation's presidential transition, highlighting the vulnerability of critical government infrastructure during periods of political change. While some files were encrypted, acting Minister of Justice Cielo Rusinque confirmed that no data was exfiltrated. This attack is part of a broader trend of increasing cyber threats targeting Colombian government agencies and critical infrastructure. In the past year, exploit attempts in the country have more than tripled, with attackers focusing on exposed and potentially vulnerable systems. The incident underscores the urgent need for enhanced cybersecurity measures to protect national assets, especially during times of political transition.
1 month ago
Kill Chain
Critical Cisco ASA and FTD Vulnerability (CVE-2026-20349) Exploited in the Wild
In August 2026, Cisco disclosed a high-severity vulnerability (CVE-2026-20349) in its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. This flaw allows unauthenticated remote attackers to trigger a denial-of-service (DoS) condition by sending crafted HTTP requests to the Remote Access SSL VPN service on affected devices. Exploitation results in device reloads, causing service disruptions. The vulnerability affects devices with specific configurations, including IKEv2 Remote Access VPN, SSL-VPN, and Zero Trust Network Access2. Cisco has released software updates to address this issue, as no workarounds are available. The active exploitation of CVE-2026-20349 underscores the critical need for organizations to promptly apply security patches to network infrastructure devices. Delayed responses to such vulnerabilities can lead to significant operational disruptions and potential security breaches. This incident highlights the importance of maintaining up-to-date systems and monitoring for emerging threats to ensure network resilience.
1 month ago
Kill Chain
ShieldBreak Zero-Day PoC Exposes Microsoft Defender Patch Bypass
In August 2026, security researcher Chaotic Eclipse released a proof-of-concept (PoC) for a new Microsoft zero-day vulnerability named ShieldBreak. This vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656, also known as RoguePlanet. RoguePlanet is a race condition that, if exploited, allows an attacker to spawn a shell with SYSTEM-level privileges, enabling the execution of arbitrary code or unauthorized actions. Despite Microsoft's release of a patch in July 2026 to address RoguePlanet, the ShieldBreak PoC indicates that the patch is ineffective, as it can be fully bypassed, maintaining a 100% success rate in tests on Windows 11 25H2 and Windows Server 2025. The release of ShieldBreak underscores the persistent challenges in effectively patching critical vulnerabilities. It highlights the need for organizations to adopt comprehensive security measures beyond relying solely on vendor patches. This incident also emphasizes the importance of continuous monitoring and rapid response strategies to mitigate potential exploits that can arise even after patches are applied.
1 month ago
Kill Chain
Critical Vulnerability in SAP Commerce Cloud: CVE-2026-58231
In August 2026, SAP released patches to address a critical vulnerability (CVE-2026-58231) in SAP Commerce Cloud's Data Hub Adapter. This flaw, rated 10.0 on the CVSS scale, allows unauthenticated attackers to exploit default authentication clients and submit specially crafted inputs to functions lacking sufficient validation. Successful exploitation could lead to arbitrary code execution, compromising the confidentiality, integrity, and availability of the application. This incident underscores the ongoing risks associated with insufficient authorization checks and input validation in enterprise applications. Organizations must prioritize timely patch management and implement robust security measures to mitigate such vulnerabilities.
1 month ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

