✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3637 to 3648 of 5263
n8n Workflow Automation Hit by Critical RCE Vulnerability (CVE-2025-68613)
In December 2025, a critical vulnerability (CVE-2025-68613) was disclosed in the popular open-source workflow automation tool n8n, allowing unauthenticated attackers to execute arbitrary code remotely under specific conditions. The flaw, rated CVSS 9.9, was identified by security researcher Fatih Çelik and reportedly affects thousands of publicly accessible n8n instances globally. By exploiting weak access controls and improper sanitization of user input, threat actors could gain control over affected servers, leading to potential data theft, lateral movement within networks, and disruption of workflow automations. This incident highlights the persistent risks posed by software supply chain vulnerabilities and the urgent need for organizations to monitor and remediate critical flaws in automation platforms. With workflow automation tools increasingly integrated into business operations, their exploitation represents a growing vector for both targeted and opportunistic cyberattacks.
7 months ago
Kill Chain
DoJ Takes Down Fraud Domain Powering $14.6M Account Takeover Scheme
In December 2025, the U.S. Department of Justice (DoJ), working with international partners, seized the domain web3adspanels[.]org at the heart of a large-scale bank account takeover scheme. The criminal group exploited fraudulent search ads to trick users into accessing spoofed bank login portals, harvesting credentials through malicious site components. These stolen credentials enabled attackers to infiltrate legitimate banking sites, drain victim accounts, and inflict confirmed losses of $14.6 million across 19 U.S. victims, including two companies. The backend database hosted by the seized domain contained thousands of login credentials and operated through November 2025. This incident is part of a broader surge in credential-based financial fraud, leveraging sophisticated phishing infrastructure and real-time abuse of search advertising. With attackers refining techniques to bypass user suspicion, enforcement agencies are increasing pressure on such online infrastructure in response to rising losses and evolving digital fraud tactics.
7 months ago
Kill Chain
MongoBleed 2025: Critical MongoDB Vulnerability Exposes Data on 87K Servers
In early June 2025, the MongoBleed vulnerability (CVE-2025-14847) was actively exploited against MongoDB servers worldwide, exposing sensitive database secrets and credentials on over 87,000 publicly accessible systems. Attackers exploited a flaw present in multiple MongoDB versions, allowing unauthorized access to in-transit data and internal database secrets without authentication. The exposure occurred as a result of inadequate encryption and misconfiguration, providing an entry point for lateral movement, data exfiltration, and potentially further compromise of enterprise networks. Organizations in finance, healthcare, SaaS, and retail sectors have been especially impacted by this incident, given their widespread MongoDB adoption for critical workloads. This breach highlights an increasingly common pattern of weaponizing newly disclosed database vulnerabilities at scale by sophisticated threat actors. The incident underscores the urgent need for robust encryption practices, Zero Trust segmentation, and vigilant patch management to protect highly sensitive data and prevent large-scale exposure as regulatory scrutiny and attacker sophistication intensify.
7 months ago
Kill Chain
Condé Nast 2024 Breach: Hacker Leaks 2.3M WIRED Subscriber Records
In March 2024, a hacker claimed to have breached Condé Nast's systems, exfiltrating and leaking a database containing over 2.3 million subscriber records from WIRED. The attacker published samples of the data on a known cybercrime forum, alleging access to databases belonging to other major Condé Nast brands and threatening to release up to 40 million more records. The exposed data reportedly included names, email addresses, postal codes, company names, and subscription specifics but did not involve payment card information. The breach highlights ongoing risks associated with third-party access, inadequate segmentation, and insufficient detection controls in the media sector. This incident underscores the growing trend of targeting high-profile media companies for large-scale data theft, aligning with broader increases in B2C sector breaches and information theft campaigns. Increased regulatory scrutiny and investor attention on data security make robust segmentation, encrypted transit, and rapid anomaly detection particularly relevant.
7 months ago
Kill Chain
CISA Alerts: Digiever NVR Botnet Exploitation via CVE-2023-52163
In December 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) flagged an actively exploited vulnerability (CVE-2023-52163, CVSS 8.8) in Digiever DS-2105 Pro network video recorders. Attackers exploited a missing authorization flaw to perform remote code execution via command injection, requiring authentication. Security researchers confirmed that this vulnerability enabled the deployment of IoT botnets such as Mirai and ShadowV2, allowing attackers to gain persistent control and leverage compromised devices for further attacks. The product’s end-of-life status means no patch is available, compounding organizational risk for operators of affected models. This incident is part of a broader trend of threat actors targeting unpatched and unsupported IoT devices for malware delivery and botnet growth. With critical infrastructure and surveillance systems at risk, timely mitigation is paramount amid surging exploitation and regulatory pressure for proactive defense.
7 months ago
Kill Chain
SEC Uncovers $14M Crypto Scam Using Fake AI-Themed Investment Clubs
In late 2025, the U.S. Securities and Exchange Commission charged a network of fraudulent crypto trading platforms and investment clubs for orchestrating a $14 million scam targeting retail investors. The scammers operated platforms such as Morocoin Tech Corp., Berge Blockchain Technology Co., Ltd., and Cirkor Inc., as well as front groups like AI Wealth Inc. and others, leveraging social media ads and WhatsApp messages promising AI-driven trading tips. Victims were enticed to buy into phony 'Security Token Offerings' with guarantees of high returns, only to be tricked a second time by advance withdrawal fees before all funds were siphoned to overseas accounts, predominantly in Asia. This incident underscores the urgent risk of AI-wash fraud and the exploitation of digital messaging channels to build investor trust. As cryptocurrency scams grow more sophisticated and regulatory scrutiny intensifies, organizations and individuals should exercise heightened vigilance against elaborate schemes blending false credentials, social engineering, and AI-themed deception.
7 months ago
Kill Chain
Active Exploitation of Fortinet SSL VPN 2FA Bypass Shows Criticality of Patch Hygiene
In December 2025, Fortinet disclosed ongoing, active exploitation of a previously known vulnerability (CVE-2020-12812) affecting FortiOS SSL VPN devices. The flaw allows attackers to bypass two-factor authentication (2FA) by manipulating the case sensitivity of usernames when certain configurations are in place, specifically when integrating local users with LDAP groups. This misconfiguration enables unauthorized access for administrative and VPN users, as attackers can skip required 2FA checks and authenticate directly via LDAP. The vulnerability, originally patched in 2020, has resurfaced due to a large number of unpatched and exposed Fortinet devices, with over 9,700 instances still vulnerable worldwide as of January 2026. This incident exemplifies the persistent risk of legacy vulnerabilities, particularly in Internet-facing VPN and perimeter security devices. Attackers are increasingly revisiting older weaknesses to target unpatched infrastructure, elevating the urgency for ongoing patch management and configuration reviews in enterprise environments.
7 months ago
Kill Chain
Critical Vulnerability in LangChain Core Exposes Secrets and Enables Prompt Injection
In December 2025, a critical vulnerability was disclosed in LangChain Core, a widely used Python package within the LangChain open-source ecosystem. Attackers were able to exploit a flaw in the serialization process, resulting in exposure of sensitive secrets and the ability to manipulate large language model (LLM) responses via prompt injection. The underlying vulnerability allowed threat actors to craft malicious payloads, leading to remote code execution in environments where untrusted input could be serialized, posing major risks to organizations relying on LangChain-powered AI workflows. This supply-chain attack path also opened the door for access to credentials and proprietary data. This incident highlights the expanding threat landscape targeting AI infrastructure and software supply chains. With the surge of enterprise adoption of AI and LLMs, vulnerabilities in core AI frameworks are increasingly attractive to threat actors, underscoring regulatory scrutiny and the need for robust code security practices within open-source dependencies.
7 months ago
Kill Chain
Critical MongoDB Flaw Exposes Sensitive Server Memory to Unauthenticated Threats
In December 2025, a critical security flaw (CVE-2025-14847) was publicly disclosed in multiple versions of MongoDB, exposing organizations to the risk of uninitialized memory disclosure by unauthenticated attackers. The flaw stems from improper handling of length parameter inconsistencies within zlib compressed protocol headers, allowing remote, unauthenticated clients to read uninitialized heap memory. Impacted versions span major MongoDB releases 3.6 through 8.2, potentially exposing sensitive data in server memory. MongoDB responded by releasing patches and advised urgent upgrades or the disabling of zlib compression. This incident gains heightened significance as memory disclosure vulnerabilities enable threat actors to harvest sensitive information without authentication. The vulnerability underscores the increasing importance of rigorous software supply chain security and timely patch management amid a growing landscape of data exposure risks in widely used open-source technologies.
7 months ago
Kill Chain
Trust Wallet Chrome Extension Supply Chain Attack Results in $7 Million Crypto Theft
In December 2023, Trust Wallet, a prominent cryptocurrency wallet provider, suffered a supply chain attack via its Chrome extension. Attackers compromised the extension update process on December 24, distributing malicious code to unsuspecting users. As a result, users who installed the tainted update had their crypto wallets drained, collectively losing over $7 million worth of digital assets. The attack leveraged phishing domains to trick users and highlighted gaps in software supply chain security. Trust Wallet responded swiftly with advisories and efforts to contain further compromise while warning all extension users. This breach underscores the escalating threat and sophistication of supply chain attacks targeting digital assets, echoing a sharp rise in attacks exploiting third-party software update channels. Organizations must prioritize controls around extension security, continuous monitoring, and response plans to mitigate similar high-impact incidents.
7 months ago
Kill Chain
Trust Wallet Chrome Extension Breach: $7M in Crypto Lost to Supply Chain Attack
In December 2025, Trust Wallet suffered a major supply chain attack when a malicious version (2.68) of its Chrome browser extension was published via a compromised Chrome Web Store API key. The attacker embedded backdoored code that exfiltrated users’ decrypted mnemonic phrases to an external server, allowing theft of approximately $7 million in cryptocurrencies. Over 2,500 wallet addresses were impacted, with stolen funds laundered through centralized exchanges and cross-chain bridges. Trust Wallet responded by urging users to upgrade to a safe version, launching a reimbursement program, and enhancing release procedures. This breach highlights the growing risks of supply chain attacks targeting widely-used browser extensions, especially in the cryptocurrency sector. With attackers demonstrating sophistication by bypassing official release processes and leveraging trusted analytics tools for data exfiltration, organizations face mounting pressure to secure development and release pipelines against insider threats and credential misuse.
7 months ago
Kill Chain
Evasive Panda APT Uses DNS Poisoning for Prolonged Espionage: 2022–2024 Campaign
Between November 2022 and November 2024, the China-linked Evasive Panda APT group conducted a sophisticated cyber espionage campaign targeting entities in Türkiye, China, and India. The attackers leveraged DNS poisoning techniques to redirect requests for popular software updates (such as SohuVA and Tencent QQ) to attacker-controlled infrastructure. Through adversary-in-the-middle attacks, victims received trojanized loaders, which proceeded to fetch and decrypt highly targeted MgBot backdoors. The attack chain involved supply chain and AitM vectors, advanced encryption and obfuscation methods, and allowed persistent compromise and broad data theft, including keylogging and credential exfiltration. This campaign highlights the growing sophistication of APT operations exploiting core network infrastructure such as DNS to evade perimeter defenses. The increased prevalence of similar DNS-manipulation campaigns and targeted malware delivery emphasizes the urgent need for robust segmentation, encrypted traffic, and thorough network and endpoint visibility.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

