✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3469 to 3480 of 5257
MongoDB ‘MongoBleed’ (CVE-2025-14847): Critical Memory Leak Exposes Credentials
In December 2025, MongoDB disclosed a critical vulnerability, CVE-2025-14847 ("MongoBleed"), allowing unauthenticated attackers to exploit a flaw in the server's handling of zlib-compressed network messages. By manipulating the compression headers, attackers could trigger the leak of uninitialized heap memory, which often included sensitive data like credentials and PII. The issue stemmed from improper validation of data sizes in pre-authentication network protocols, enabling large-scale data exposure from any reachable MongoDB server. Over 146,000 vulnerable instances were identified as exposed to the internet, with active exploitation observed and a public proof-of-concept released. MongoBleed highlights the resurgence of memory disclosure flaws as attackers shift targets to exposed cloud and database services. Its automated exploitation at scale and inclusion in CISA's Known Exploited Vulnerabilities catalog signal increased regulatory and operational urgency for immediate patching and segmentation of critical data services.
7 months ago
Kill Chain
ServiceNow Patches Critical AI User Impersonation Flaw in 2025
In October 2025, ServiceNow addressed a critical vulnerability (CVE-2025-12420) in its AI platform that enabled unauthenticated attackers to impersonate legitimate users and execute unauthorized activities. Discovered by AppOmni, the flaw impacted the Now Assist AI Agents and Virtual Agent API components. Attackers could have leveraged agent-to-agent collaboration features to escalate privileges, bypass user access controls, and modify or access sensitive records, even with certain protection features enabled. ServiceNow rapidly deployed patches to its cloud customers and provided updates for self-hosted users, stating there was no evidence of active exploitation prior to patch release. This incident underscores the risks associated with AI agent configurability, as well as the need for organizations to enforce strict configuration and segmentation in enterprise AI deployments. The case brings to light a growing trend: sophisticated exploitation of AI agent collaboration and the mounting regulatory and security focus on securing AI-powered enterprise systems.
7 months ago
Kill Chain
Microsoft's 2026 Zero-Day: Desktop Window Manager Exploited in Active Attacks
In January 2026, Microsoft released security patches for 112 vulnerabilities across its product suite, including one actively exploited zero-day affecting Desktop Window Manager (CVE-2026-20805). This information disclosure vulnerability, rated CVSS 5.5, allows unauthorized local attackers to gain access to sensitive system information via memory leaks, potentially facilitating further privilege escalation or data theft. Although exploitation requires local access, threat actors have used similar flaws historically to escalate privileges, and the exposure of memory details can undermine systemic defenses, pathing the way for broader compromise and regulatory exposure. This incident underscores the evolving sophistication of threat actors, who increasingly leverage information disclosure vulnerabilities as stepping stones for multi-stage attacks. The active exploitation of such a zero-day highlights the importance of rapid remediation, comprehensive patch management, and heightened vigilance amid rising regulatory scrutiny and a surge in blended TTPs targeting enterprise environments.
7 months ago
Kill Chain
Microsoft, Europol Disrupt RedVDS Cybercrime Marketplace in Major Global Takedown (2025)
In June 2025, Microsoft, in collaboration with international law enforcement, dismantled the infrastructure powering the RedVDS cybercrime marketplace, a platform notorious for enabling large-scale cyber fraud. Since at least March 2025, RedVDS provided cybercriminals with access to disposable, unlicensed virtual Windows servers for as little as $24 per month, facilitating attacks such as phishing, credential theft, and business email compromise. The platform's operations are tied to over $40 million in U.S. fraud losses, including multi-million-dollar incidents targeting the pharmaceutical and real estate sectors. Over a month, attackers using RedVDS compromised more than 191,000 Microsoft email accounts, demonstrating the platform's operational scale and global reach. This takedown underscores the growing threat of Cybercrime-as-a-Service marketplaces, which lower barriers for cybercriminals and accelerate the pace and scale of attacks. Organizations across industries must prioritize modern security strategies as such platforms proliferate and regulatory bodies intensify their scrutiny of supply chain and email-based threats.
7 months ago
Kill Chain
React2Shell and the December 2025 CVE Tsunami: Multi-Vector Exploitation at Scale
In December 2025, a record-setting wave of critical vulnerabilities led to a 120% surge in high-severity exploits globally, with 22 CVEs actively targeted—double the previous month. The standout event was the mass exploitation of Meta's React Server Components (CVE-2025-55182, dubbed "React2Shell"), which allowed unauthenticated remote code execution and became a magnet for a variety of threat actors, including China-linked groups Earth Lamia and Jackpot Panda plus a mix of financially motivated and state-aligned attackers. Attackers leveraged new and legacy vulnerabilities to deploy malware, pivot across internal networks, and compromise key infrastructure across vendors like Google, Fortinet, Cisco, Microsoft, and more. The incident highlights a dangerous shift: modern web frameworks are becoming high-value targets, attack toolkits are rapidly weaponizing zero-days, and threat actors now freely cycle between old and new vulnerabilities. Organizations operating React/Next.js or affected platforms face urgent patching requirements amid heightened regulatory attention and persistent adversarial activity.
7 months ago
Kill Chain
2024 Ransomware Attack on Global Utility: Speed, Sophistication, and Credential Theft
In March 2024, a leading global utility company suffered a large-scale ransomware attack executed by the BlackBasta threat group. Attackers initially gained entry by exploiting an externally-facing VPN with compromised credentials, bypassing multifactor authentication controls. Upon entry, the threat actors rapidly performed reconnaissance, escalated privileges, and moved laterally using legitimate remote management tools and credential dumping techniques, deploying ransomware payloads across hundreds of critical systems within 48 hours. The incident resulted in massive operational disruptions, including temporary shutdowns of power generation facilities and significant data exfiltration, while the attackers leveraged double extortion to pressure the company into paying a multimillion-dollar ransom. This breach exemplifies the growing sophistication and speed of multi-stage ransomware campaigns targeting critical infrastructure. The incident highlights the importance of pre-encryption detection, intelligence-driven defense, and robust access controls as ransomware groups continue to exploit hybrid environments and rapidly weaponize vulnerabilities.
7 months ago
Kill Chain
CISA Flags Critical Exploited Windows Vulnerability: CVE-2026-20805
In January 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20805, a Microsoft Windows Information Disclosure Vulnerability, to its Known Exploited Vulnerabilities Catalog following evidence of active exploitation. Attackers have leveraged this vulnerability as an entry vector to access sensitive data from federal and private sector Windows machines, potentially exposing unencrypted or inadequately protected data in transit. The incident highlights the ongoing risk to government and enterprise environments from timely, opportunistic exploitation of unpatched known vulnerabilities, particularly those enabling information disclosure and lateral movement within networks. This addition to CISA’s KEV Catalog underscores intensifying efforts by cybercriminals to rapidly weaponize newly disclosed vulnerabilities, especially those impacting widely-deployed products like Microsoft Windows. Regulatory and operational pressure is mounting for organizations to accelerate remediation practices as adversaries increasingly automate exploitation processes.
7 months ago
Kill Chain
YoSmart YoLink 2026: IoT Flaws Enable Remote Takeover and Data Exposure
In January 2026, YoSmart's YoLink Smart Hub platform was found vulnerable to a series of security flaws that placed smart home users at risk worldwide. Discovered and reported by Bishop Fox and disclosed via CISA, these issues included insufficient authorization in device communication, the use of predictable device identifiers, cleartext transmission of sensitive information over MQTT, and excessive session token lifetimes. Attackers could remotely control users' smart devices, intercept data, and hijack sessions without physical access, affecting both the hub and its mobile app ecosystem. The vulnerabilities were present in core server infrastructure, device APIs, and user-facing applications. While YoSmart resolved the vulnerabilities through server-side and over-the-air updates, this incident highlights critical and ongoing risks in the IoT and smart device sector. The attack methods exploited insecure-by-design communication and poor identity management—trends increasingly scrutinized by regulators and targeted by sophisticated threat actors worldwide.
7 months ago
Kill Chain
Rockwell Automation ICS Devices Exposed by Critical DoS Vulnerability (CVE-2025-9368)
In January 2026, Rockwell Automation disclosed a critical vulnerability (CVE-2025-9368) affecting its 432ES-IG3 Series A industrial Ethernet/IP interface. The flaw, classified as a resource allocation vulnerability (CWE-770), can be exploited remotely to cause a denial-of-service (DoS) condition, rendering the device unresponsive and requiring manual power cycling to restore operations. The vulnerability affects version V1.001 of the device, widely deployed in critical manufacturing environments worldwide. No evidence of active exploitation has been reported as of the initial CISA advisory, but the risk of service disruption in operational technology (OT) networks is significant. This incident underscores the persistent threat posed by resource exhaustion flaws in industrial control systems, as attackers continue to seek low-complexity, high-impact vulnerabilities to disrupt critical infrastructure. With global regulatory focus increasing and ICS-targeted attacks on the rise, addressing resource and availability issues has become a pressing operational and compliance priority for manufacturers and critical infrastructure operators.
7 months ago
Kill Chain
Rockwell Automation DataMosaix SQL Injection Exposes Critical Manufacturing Systems
In January 2026, Rockwell Automation disclosed a critical vulnerability in its FactoryTalk DataMosaix Private Cloud platform affecting versions 7.11, 8.00, and 8.01. Identified as CVE-2025-12807, this SQL Injection flaw allows low-privilege users to execute unauthorized sensitive database operations through exposed API endpoints. While no public exploitation has been reported, successful attacks could significantly compromise critical manufacturing infrastructure worldwide by enabling attackers to access or manipulate sensitive industrial data. The incident highlights ongoing risks to industrial control environments from common vulnerabilities like SQL Injection, especially in products globally deployed across critical infrastructure sectors. With attackers increasingly targeting OT platforms, organizations face renewed urgency to review security controls and ensure compliance with updated defensive best practices.
7 months ago
Kill Chain
FBI Warns of Kimsuky APT’s Advanced QR Code Phishing (Quishing) Attacks
In early 2024, the FBI issued an alert warning of advanced quishing (QR-code phishing) campaigns conducted by North Korean state-sponsored group Kimsuky. The group targeted US and foreign government agencies, NGOs, and academic institutions by sending emails laden with malicious QR codes, which, when scanned, redirected victims to credential-harvesting sites. The campaign relied on the growing trust in QR codes and the challenges of securing email and mobile workflows. While no major data breach was announced, the intent was information theft and espionage, representing a significant risk to critical institutions’ security and reputation. This incident highlights the evolution of phishing techniques—from simple emails to advanced, device-hopping attacks using QR codes—mirroring a wider global threat trend. Organizations are urged to update security controls and awareness programs, as quishing is now surging across industries.
7 months ago
Kill Chain
GoBruteforcer Botnet Hits 50K+ Linux Servers with AI-Powered Brute Force
In early 2024, researchers identified a powerful new variant of the GoBruteforcer botnet actively targeting over 50,000 Linux servers worldwide. The attackers leveraged automated brute-force attacks in combination with AI-generated configurations to compromise servers running popular services such as SSH, MySQL, and Redis. Once inside, the botnet deployed additional malware to expand its network, launch further attacks, and facilitate potential data theft or service disruption, posing significant operational risks to exposed organizations. This campaign highlights the evolving nature of automated botnets, now leveraging AI tools to speed up attacks and evade detection. With Linux servers widely used in cloud and enterprise environments, the incident underscores the urgent need for improved credential hygiene, segmentation, and real-time traffic monitoring as botnets increasingly target critical infrastructure at scale.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

