✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3697 to 3708 of 5272
Cisco VPNs and Email Service Campaigns: How Multi-Vector Attacks Are Changing the Cyber Risk Landscape
In early 2024, Cisco VPN appliances and various enterprise email services were targeted in two distinct but nearly simultaneous cyber campaigns. The first, a highly coordinated attack, leveraged zero-day vulnerabilities and credential harvesting to infiltrate corporate VPNs, granting attackers lateral access to sensitive networks. Around the same period, a separate 'spray-and-pray' phishing wave indiscriminately targeted a wide swath of business email services, seeking to exploit weak authentication and unpatched systems. Combined, the incidents led to multiple business disruptions, credential leaks, and prompted extensive incident response efforts across affected organizations. This incident is part of a larger trend where cybercriminals simultaneously exploit both remote-access infrastructure and cloud-based email, reflecting a shift toward multi-vector, blended attacks. Organizations are facing heightened regulatory and operational pressure to defend against ever more sophisticated and opportunistic threats targeting identity, access points, and critical communications systems.
7 months ago
Kill Chain
FBI Reveals Years-Long Deepfake Impersonation Campaign Against U.S. Officials
From 2023 onward, unknown threat actors used AI-powered voice cloning and deepfake techniques to impersonate senior U.S. government officials, including members of the White House and Congress. These attacks targeted officials, their families, and associates via initial SMS contact, escalating to encrypted messaging platforms such as Signal, WhatsApp, and Telegram. Once rapport was established, attackers used tailored pretexts to request sensitive personal information, passport photos, device syncing, introductions, or even funds transfers, posing as, or on behalf of, high-profile government leaders. The campaign enabled further impersonation by harvesting victims’ contact lists and executing subsequent rounds of targeted smishing and vishing attacks. This incident underscores the escalation of social engineering campaigns powered by generative AI, as adversaries blend deepfake technologies with encrypted communications to evade detection and amplify deception. The evolving tactics, targeting highly sensitive circles, highlight both the sophistication of modern impersonation attacks and the urgent need for updated identity verification protocols.
7 months ago
Kill Chain
Former Insiders Launch ALPHV/BlackCat Ransomware Attacks in 2023
In 2023, two former cybersecurity professionals, Ryan Clifford Goldberg and Kevin Tyler Martin, exploited their trusted positions at incident response firms Sygnia and DigitalMint to perpetrate a series of targeted ransomware attacks. Acting in collusion with a third party and leveraging the ALPHV (BlackCat) ransomware variant, they compromised the networks of organizations across several critical sectors, including healthcare, engineering, and manufacturing. The group successfully extorted nearly $1.3 million from a Florida-based medical company and caused total damages exceeding $9.5 million across multiple states, before being apprehended and pleading guilty in federal court within months of indictment. This breach stands out for the attackers’ abuse of insider knowledge and privileged access, highlighting a new threat vector where trusted security personnel become adversaries. The case draws industry-wide attention to potential insider threats, the rising sophistication of ransomware groups, and the urgent need for enhanced monitoring and zero trust practices.
7 months ago
Kill Chain
Critical WatchGuard Firebox Firewall Flaw Enables RCE Attacks in 2025
In December 2025, WatchGuard disclosed a critical remote code execution (RCE) vulnerability (CVE-2025-14733) impacting numerous Firebox firewall models running Fireware OS versions 11.x and later. The flaw, stemming from an out-of-bounds write bug, allows unauthenticated attackers to deploy malicious code on unpatched devices via low-complexity attacks, without user interaction. Exploitation is linked to IKEv2 VPN configurations, including those previously deleted but with lingering branch office VPN settings, making many organizations vulnerable. Active exploitation was observed, prompting WatchGuard to provide urgent mitigation steps and indicators of compromise to aid detection and response. The incident poses serious risks to over 250,000 businesses worldwide, as Firebox devices are extensively used in SMBs and managed service environments. This breach highlights the ongoing escalation of attacks targeting network infrastructure, particularly security appliances that underpin VPN and edge services. With similar device vulnerabilities making headlines throughout 2025, attackers are increasingly exploiting remote access flaws to establish persistence, demonstrating a worrying trend for organizations that depend on always-on network security.
7 months ago
Kill Chain
Ukrainian Ransomware Operator Pleads Guilty in Global Nefilim Extortion Case
Between 2018 and 2021, Artem Aleksandrovych Stryzhak, a Ukrainian national, orchestrated a series of targeted ransomware attacks against high-revenue organizations in the United States and Europe using the Nefilim ransomware strain. The attacks involved gaining unauthorized access to victim networks, exfiltrating sensitive data, and deploying custom ransomware executables, each with unique ransom notes and decryption keys. Victims included companies across multiple sectors such as engineering, aviation, chemicals, insurance, construction, and energy. Stryzhak, arrested in Spain in June 2024 and extradited to the U.S., pleaded guilty to conspiracy to commit fraud and faces up to 10 years in prison. His accomplice, Volodymyr Tymoshchuk, remains at large amid ongoing law enforcement efforts. The incident underscores the operational sophistication of modern ransomware groups, particularly in tailoring attacks to maximize extortion and impact. With financial and reputational damages in the millions, this case highlights the persistent threat of ransomware and the necessity for robust east-west network security, multifactor identity controls, and anomaly detection across the enterprise attack surface.
7 months ago
Kill Chain
Denmark’s Water Utility Cyberattack: Hybrid Warfare Hits Critical Infrastructure in 2025
In December 2025, Danish authorities publicly attributed a destructive cyberattack on a major water utility to Russian state-sponsored groups, primarily Z-Pentest. The attackers penetrated critical operational systems, disrupting water infrastructure and threatening essential services. Danish intelligence described the operation as part of Russia’s ongoing hybrid war strategy, which includes leveraging hacktivist proxies to create insecurity and punish countries supporting Ukraine. Simultaneously, NoName057(16) conducted a DDoS campaign targeting Danish election infrastructure, further elevating national security concerns. This incident underscores the rising threat posed by nation-state actors actively targeting vital infrastructure across Europe. The use of both destructive intrusions and disruptive tactics during sensitive political periods reflects a broader trend of cyber operations designed to undermine public trust and exploit operational technology vulnerabilities on a global scale.
7 months ago
Kill Chain
Fortinet SSO Bypass: 25,000 Devices at Risk from Critical CVE-2025-59718 Exploit
In December 2025, over 25,000 internet-exposed Fortinet devices with FortiCloud Single Sign-On (SSO) enabled were found vulnerable to an actively exploited authentication bypass flaw (CVE-2025-59718/CVE-2025-59719). Threat actors leveraged a malicious SAML message to compromise admin accounts via the SSO interface, gaining unauthorized access to system configuration files that revealed credentials, service details, network layouts, and firewall policies. The wide exposure was confirmed by independent scans, while U.S. government agencies were urgently mandated by CISA to patch within a week due to mounting exploitation. This incident highlights the persistent risk posed by poorly secured administrative interfaces, unpatched vulnerabilities, and credential-access techniques. Escalating regulatory pressure and attacker focus on identity-driven infrastructure demonstrate the need for robust segmentation and detection across all exposed assets.
7 months ago
Kill Chain
Critical 2025 UEFI Flaw Enables Pre-Boot DMA Attacks on Leading Motherboards
In December 2025, researchers from Riot Games identified a critical UEFI firmware vulnerability impacting motherboards from ASUS, Gigabyte, MSI, and ASRock. The flaw, tracked as CVE-2025-11901, CVE-2025‑14302, CVE-2025-14303, and CVE-2025-14304, allows Direct Memory Access (DMA) attacks during the pre-boot phase by bypassing IOMMU protections. Threat actors with physical access can attach malicious PCIe devices to read or alter system memory before the operating system loads, making traditional endpoint protections ineffective. The vulnerability was confirmed by multiple security advisories and coordinated with hardware vendors for urgent firmware updates. This incident highlights the increasing sophistication of firmware-level attacks that can evade operating system and security tool visibility. As hardware supply chains diversify and attackers target pre-boot processes, organizations face heightened risks in both enterprise and consumer hardware ecosystems.
7 months ago
Kill Chain
Microsoft 365 Under Siege: OAuth Device Code Phishing Attacks Surge in 2025
In late 2025, Microsoft 365 accounts across multiple sectors were targeted in a sophisticated phishing campaign leveraging OAuth device code authorization. Threat actors, including financially motivated group TA2723 and a Russia-aligned group tracked as UNK_AcademicFlare, deceived victims into entering attacker-provided device codes on legitimate Microsoft login portals. This granted attacker-controlled applications elevated access to organizational email and data, bypassing credentials and even multi-factor authentication protections. Attackers utilized phishing kits such as SquarePhish and Graphish, and orchestrated lures mimicking document sharing or salary bonus notifications to maximize engagement and scale. Notably, state-aligned campaigns exploited compromised government accounts to build rapport, targeting U.S. and European government, academic, and transportation sectors. These OAuth-based phishing attacks mark a significant escalation in adversary techniques focusing on authorization abuse rather than credential theft. The surge in such activity since September 2025 demonstrates the growing adaptation of sophisticated phishing kits and highlights a strategic shift toward targeting identity and cloud permissions, reflecting evolving attack surfaces and regulatory scrutiny in cloud security.
7 months ago
Kill Chain
UEFI Firmware Vulnerability Leaves Major Motherboards Open to Early-Boot DMA Attacks
In December 2025, researchers disclosed a critical hardware/firmware vulnerability impacting various ASRock, ASUS, GIGABYTE, and MSI motherboards. The flaw allows threat actors to launch direct memory access (DMA) attacks during the early boot process, bypassing typical Unified Extensible Firmware Interface (UEFI) and Input–Output Memory Management Unit (IOMMU) protections. Attackers can exploit this window to inject code or access sensitive memory before system defenses activate. The incident exposes endpoints to risk of credential theft, persistent malware implants, and lateral movement, with potential compromise of high-value IT and OT assets. This incident is highly relevant as firmware attacks and supply chain risks escalate, especially with the push towards Zero Trust security architectures. Hardware-level exposures pose challenges that traditional endpoint or network controls may not immediately mitigate, requiring urgent attention to firmware security and early-boot exploit detection.
7 months ago
Kill Chain
Nigerian Authorities Arrest Raccoon0365 Phishing Platform Developer Linked to Microsoft 365 Attacks
In December 2025, Nigerian authorities arrested three individuals linked to the Raccoon0365 phishing platform, which was responsible for widespread credential theft targeting Microsoft 365 users. The service enabled cybercriminals to create convincing fake Microsoft login pages, facilitating business email compromise, data breaches, and significant financial losses across 94 countries. The investigation and arrests were made possible through intelligence provided by Microsoft via the FBI, leading to the apprehension of the platform's alleged developer and the recovery of digital evidence. Raccoon0365 operated via a Telegram channel with over 800 members, selling access to the phishing kits for cryptocurrency and leveraging Cloudflare infrastructure with compromised credentials. This incident is highly relevant as phishing-as-a-service (PhaaS) platforms continue to industrialize credential theft and make sophisticated attacks broadly accessible. The disruption of Raccoon0365 illustrates the importance of global collaboration, threat intelligence sharing, and proactive law enforcement action in curbing cybercrime.
7 months ago
Kill Chain
New DCOM Object Abuse Enables Lateral Movement via Control Panel (2024)
In early 2024, new research revealed an undisclosed vulnerability in Microsoft Windows, where adversaries can abuse the Distributed Component Object Model (DCOM) to achieve lateral movement and persistence by exploiting Control Panel item registration. Attackers can remotely trigger the loading of malicious DLLs via the COpenControlPanel DCOM object, circumventing common defenses and security controls in enterprise environments. By registering rogue DLLs within specific Windows registry keys and leveraging remote registry manipulation, threat actors obtain both initial code execution and ongoing persistence, with minimal user interaction and limited detection from traditional endpoint defenses. This exposure highlights a shift toward advanced lateral movement techniques exploiting legitimate system components. With the rapid evolution of attacker TTPs, especially those bypassing modern endpoint protections and leveraging system internals, organizations face increased risk of undetected breaches and regulatory scrutiny. Proactive monitoring and refined segmentation are now essential to close these newly exposed attack paths.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

