✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3217 to 3228 of 5227
Safeguarding AI Assets: Lessons from the 2025 Model Extraction Attack
In 2025, a significant AI model extraction attack was identified, where adversaries systematically queried a proprietary machine learning model's API to replicate its functionality. By sending carefully crafted inputs and analyzing the outputs, attackers reconstructed a substitute model that closely mirrored the original's behavior. This breach exposed the model's intellectual property, leading to potential competitive disadvantages and financial losses for the organization. The incident underscores the vulnerabilities inherent in exposing AI models through APIs without adequate security measures. ([techtarget.com](https://www.techtarget.com/searchsecurity/tip/AI-model-theft-Risk-and-mitigation-in-the-digital-era?utm_source=openai)) The rise of such model extraction attacks highlights the urgent need for organizations to implement robust defenses, including rate limiting, output perturbation, and behavioral monitoring, to protect their AI assets from unauthorized replication and misuse. ([snyk.io](https://snyk.io/articles/ai-model-theft/?utm_source=openai))
6 months ago
Kill Chain
Swarmer Tool: Exploiting Windows Legacy Features for Stealthy Registry Persistence
In February 2025, Praetorian Inc. introduced 'Swarmer,' a tool designed to achieve stealthy Windows registry persistence without triggering Endpoint Detection and Response (EDR) systems. By exploiting legacy Windows features such as mandatory user profiles and the Offline Registry API, Swarmer allows low-privilege users to modify the NTUSER hive covertly. This method bypasses standard registry APIs monitored by EDR solutions, enabling attackers to establish persistence without detection. The release of Swarmer underscores the ongoing challenges in cybersecurity, particularly the exploitation of overlooked system functionalities. As attackers continue to innovate, it is imperative for organizations to reassess and fortify their security postures against such sophisticated techniques.
6 months ago
Kill Chain
Oracle WebLogic Server Proxy Plugin Vulnerability (CVE-2026-21962): What You Need to Know
In January 2026, Oracle disclosed a critical vulnerability (CVE-2026-21962) affecting Oracle HTTP Server and WebLogic Server Proxy Plug-ins for both Apache HTTP Server and Microsoft IIS. This flaw allows unauthenticated remote attackers to bypass security controls, potentially gaining unauthorized access to backend WebLogic systems. Given that these proxy plugins often reside in DMZ environments, the exposure is significant. The vulnerability has a CVSS 3.1 Base Score of 10.0, indicating its high severity due to low attack complexity and the potential for substantial compromise. ([netspi.com](https://www.netspi.com/blog/executive-blog/vulnerability-management/oracle-weblogic-server-proxy-plugin-cve-2026-21962-overview-takeaways/?utm_source=openai)) The current relevance of this incident is underscored by the ease of exploitation and the critical nature of the affected systems. Organizations utilizing the impacted versions are urged to apply Oracle's Critical Patch Update immediately to mitigate the risk of unauthorized data access and potential system compromise. ([netspi.com](https://www.netspi.com/blog/executive-blog/vulnerability-management/oracle-weblogic-server-proxy-plugin-cve-2026-21962-overview-takeaways/?utm_source=openai))
6 months ago
Kill Chain
TA584's Escalation: Deploying Tsundere Bot and XWorm in Ransomware Campaigns
In late 2025, the threat actor TA584 significantly escalated its operations, tripling campaign volumes and expanding targets beyond North America and the UK to include Germany, other European countries, and Australia. Utilizing sophisticated phishing emails, TA584 employed the Tsundere Bot malware alongside the XWorm remote access trojan to gain unauthorized network access. These campaigns often began with emails from compromised accounts, leading victims through CAPTCHA and ClickFix pages that prompted the execution of PowerShell commands, resulting in the deployment of malware directly into system memory. Tsundere Bot, a malware-as-a-service platform, functions as both a backdoor and loader, requiring Node.js for operation and retrieving command-and-control addresses from the Ethereum blockchain using the EtherHiding technique. The malware is capable of system profiling, executing arbitrary JavaScript code, and turning infected machines into SOCKS proxies. Given TA584's history and the capabilities of the deployed malware, these infections pose a significant risk of leading to ransomware attacks. The rapid evolution and expansion of TA584's tactics underscore the increasing sophistication of initial access brokers and the persistent threat they pose to organizations worldwide.
6 months ago
Kill Chain
Match Group's 2026 Data Breach: A Wake-Up Call for Digital Security
In late January 2026, Match Group, the parent company of popular dating platforms such as Hinge, Match.com, and OkCupid, experienced a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers claimed to have exfiltrated over 10 million user records, including user IDs, transaction details, IP addresses, and internal corporate documents. The breach was reportedly facilitated through a vulnerability in AppsFlyer, a mobile marketing analytics platform utilized by Match Group. Match Group promptly initiated an investigation with external cybersecurity experts and began notifying affected users. Preliminary findings indicated that user login credentials, financial information, and private communications were not accessed. ([cybernews.com](https://cybernews.com/security/hinge-okcupid-data-leak-shinyhunters-claims/?utm_source=openai)) This incident underscores the persistent threat posed by sophisticated cybercriminal organizations like ShinyHunters, known for targeting high-profile companies and leaking sensitive data. The breach highlights the critical importance of securing third-party integrations and the need for robust cybersecurity measures to protect user data. Organizations must remain vigilant and proactive in identifying and mitigating potential vulnerabilities to prevent similar incidents.
6 months ago
Kill Chain
How the 2024 Microsoft Office Zero-Day Shaped Urgent Security Responses
In June 2024, Microsoft was compelled to release an emergency patch for a critical zero-day vulnerability affecting Microsoft Office products. The issue allowed attackers to exploit crafted Office documents, enabling remote code execution if a victim opened a malicious file. Attackers leveraged social engineering—including phishing—to trick users into opening infected attachments, bypassing standard email and endpoint defenses. Rapid weaponization of the exploit by criminal groups and likely state-backed actors resulted in significant risk for businesses using vulnerable Office deployments, with potential for data theft, malware infection, and lateral movement across networks. This attack highlights a pervasive trend of adversaries capitalizing on zero-day vulnerabilities in widely used productivity platforms. As seen in recent high-profile breaches, rapid exploitation before patches can be applied increases organizational risk and regulatory scrutiny, necessitating faster detection, patching, and user education across industries.
6 months ago
Kill Chain
Sicarii Ransomware: The 2024 False-Flag Attack with Unbreakable Encryption
In early 2024, a new ransomware variant dubbed 'Sicarii' surfaced, reportedly leveraging poorly designed, obfuscated code and incorporating Hebrew language elements that may serve as a false flag to mislead investigators about its origin. The ransomware, first detected in late 2023, compromises victim environments, encrypts files, and delivers notes demanding payment in cryptocurrency for data recovery. Although initial analysis indicates programming weaknesses, security researchers confirmed that its encryption implementation is resilient, making recovery without payment infeasible. The malware also exhibits unique lateral movement and persistence behaviors before exfiltrating data to attacker-controlled infrastructure. This incident is reflective of a broader increase in ransomware operations deploying deceptive attribution techniques and leveraging unconventional languages or scripts. The emergence of ‘Sicarii’ underscores the persistent threat and ever-evolving tactics used by ransomware groups to evade detection and complicate response efforts for organizations worldwide.
6 months ago
Kill Chain
2024 Critical Telnet Flaw: How Legacy Protocols Created a Global Attack Surface
In early 2024, security researchers uncovered a critical vulnerability affecting widely used Telnet server software running on hundreds of thousands of legacy and IoT devices worldwide. Attackers exploited the bug, which allowed unauthenticated remote access using unencrypted Telnet sessions, to compromise network and industrial systems, bypass access controls, and rapidly pivot laterally. Many affected devices remained unpatched due to lack of vendor support, making remediation difficult and exposing organizations in healthcare, manufacturing, and critical infrastructure to potential downtime and data theft. This incident highlights the enduring risk of forgotten, legacy protocols like Telnet persisting in enterprise environments. Attackers increasingly scan for and exploit such overlooked attack surfaces, emphasizing the need for proactive inventory, segmentation, and the retirement of obsolete network services to defend against emergent threats.
6 months ago
Kill Chain
WinRAR Patch Delays Enable Nation-State Attackers in 2024
In early 2024, nation-state threat actors from Russia and China exploited a critical WinRAR vulnerability (CVE-2023-38831) well after a public patch became available in July 2023. Attackers leveraged the flaw via malicious archive files to gain initial access, with phishing lures targeting small- and medium-sized businesses (SMBs) and government targets. Despite availability of security updates and widespread coverage, a significant number of organizations remained unpatched, enabling cyber-espionage operations, data theft, and operational disruptions. This incident highlights the persistent risk posed by software supply chain vulnerabilities, especially when patch adoption is slow. The continued exploitation of a months-old flaw underscores how threat actors weaponize common utilities and rely on lagging defenses, driving urgency for improved vulnerability management and zero trust controls.
6 months ago
Kill Chain
China-Backed PeckBirdy APT Orchestrates Cross-Platform Attacks in 2024
In early 2024, the China-linked threat group dubbed 'PeckBirdy' orchestrated sophisticated cross-platform cyberattacks against Asian government entities and gambling platforms. Utilizing the JScript C2 framework, the attackers deployed new backdoors to penetrate both Windows and Linux systems, enabling remote command execution and persistent access. The dual-campaign approach demonstrated PeckBirdy's flexibility, targeting sectors with rich data and financial value. The initial compromise was achieved via spear-phishing emails and exploit delivery, followed by lateral movement to critical systems. Exfiltration of sensitive data and ongoing espionage activities resulted in operational disruptions and an increased risk of regulatory exposure for targeted organizations. This incident underscores the evolving nature of state-sponsored APT operations, notably the growing crossover between espionage and financially-motivated attacks. PeckBirdy's toolset and cross-platform reach reflect a trend where threat actors innovate rapidly, blending custom malware with proven C2 tactics, raising the stakes for defenders in Asia and beyond.
6 months ago
Kill Chain
Fortinet’s 2024 Zero-Day SSO Breach: Key Lessons in Cloud Identity Security
In June 2024, Fortinet disclosed a critical zero-day vulnerability that was actively exploited by threat actors to compromise FortiCloud single sign-on (SSO) authentication, enabling unauthorized access to customer devices. Attackers leveraged the flaw to perform malicious SSO logins, bypassing authentication controls and potentially moving laterally within affected network environments. In response, Fortinet took the unprecedented step of disabling FortiCloud SSO services temporarily for all users while investigating and developing a fix. This incident underscores significant risks associated with identity and access management in cloud-delivered network security platforms. This breach highlights the growing prevalence of zero-day exploitation targeting authentication mechanisms and cloud infrastructure. As attackers increasingly focus on SSO and federated identity systems, organizations must reassess their reliance on third-party authentication, strengthen monitoring, and accelerate adoption of zero trust strategies.
6 months ago
Kill Chain
Fortinet 2026 Breach: Authentication Bypass via FortiCloud SSO Drives Widespread Exploitation
In January 2026, Fortinet suffered a critical security incident when attackers exploited CVE-2026-24858, an authentication bypass vulnerability impacting FortiCloud SSO on key products like FortiOS, FortiManager, FortiWeb, FortiProxy, and FortiAnalyzer. Malicious actors with valid FortiCloud accounts could access devices registered to other users, enabling unauthorized firewall changes, new privileged account creation, and illicit VPN reconfiguration, even on systems patched for earlier SSO flaws. Fortinet responded by temporarily disabling and then remediating FortiCloud SSO, and CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog. This incident underscores the risks of centralized identity platforms and SSO misconfigurations, as well as the persistent attacker interest in cloud-managed network appliances. Growing exploitation of authentication bypass vulnerabilities has regulatory and operational implications for organizations reliant on integrated cloud services.
6 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

