✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3733 to 3744 of 5272
Sha1-Hulud 2025: The Multi-Vector Threat Campaign that Redefined Cloud Security
In December 2025, security researchers observed a sophisticated multi-vector attack campaign, dubbed 'Sha1-Hulud,' targeting organizations across North America, Europe, and Asia. The campaign leveraged vulnerabilities in remote management tools such as ScreenConnect and MacSync to gain initial access, then proceeded laterally using encrypted traffic, zero trust segmentation evasion, and cloud-native pivoting. Attackers deployed covert remote access tools and exploited gaps in cloud firewall and egress controls to move data out, leaving organizations grappling with data theft, systems downtime, and regulatory exposure. This incident is notable for its integration of advanced encryption bypass, multicloud movement, and the blending of traditional and cloud-native evasion tactics. The convergence of infrastructure and cloud threats highlights the need for ubiquitous visibility, modern segmentation, and coordinated policy enforcement in response to increasingly diverse and distributed attacks.
7 months ago
Kill Chain
Axis Communications 2025: Critical Camera System Vulnerabilities Threaten OT Security
In December 2025, Axis Communications disclosed multiple critical vulnerabilities affecting their Camera Station Pro, Camera Station, and Device Manager products. The issues, discovered by cybersecurity researchers from Claroty Team82, include flaws such as deserialization of untrusted data, improper certificate validation, authentication bypass, and local privilege escalation. These vulnerabilities could allow an attacker to remotely execute arbitrary code, intercept communications via man-in-the-middle attacks, or bypass authentication mechanisms, significantly compromising the security posture of organizations using these systems globally. Patches are now available and users are urged to upgrade immediately. This incident highlights a growing trend in targeting surveillance and control infrastructure, reflecting the increased attention threat actors are placing on operational technology and critical manufacturing environments. The convergence of IT and OT risks, as well as heightened regulatory expectations, make robust security controls for IoT and camera systems more critical than ever.
7 months ago
Kill Chain
CISA Flags Critical ICS Flaws Threatening National Infrastructure in 2025
In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released nine advisories covering serious vulnerabilities discovered in multiple industrial control systems (ICS) from vendors including Inductive Automation, Schneider Electric, Siemens, Mitsubishi Electric, Advantech, National Instruments, Rockwell Automation, and Axis Communications. These vulnerabilities potentially allow attackers to gain unauthorized access, move laterally, and disrupt or manipulate key operations in sectors such as energy, manufacturing, and transportation. Many of the issues arise from insecure configurations, insufficient encryption, outdated software components, and lack of segmentation between critical assets. This incident highlights the alarming persistence of security gaps across ICS environments. As operational technology (OT) converges with IT, attackers increasingly exploit these systems to launch ransomware, disrupt supply chains, or conduct cyber-physical sabotage, emphasizing the urgent need for robust controls, patching, and increased network visibility in critical infrastructure.
7 months ago
Kill Chain
Critical OS Command Injection Vulnerability Hits Mitsubishi Electric Iconics Products (2025)
In December 2025, Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric Products disclosed a critical vulnerability (CVE-2025-11774) affecting GENESIS64, ICONICS Suite, MobileHMI, and MC Works64 software. This OS command injection flaw resides in the software keyboard (keypad) function, enabling local attackers to execute arbitrary executable files (.EXE) by tampering with configuration files. If successfully exploited, adversaries could trigger denial-of-service (DoS), information tampering, and unauthorized information disclosure or destruction on systems running these products. A fix is available for most products by upgrading to GENESIS64 v10.97.3 or higher, but MC Works64 users must migrate as no patch is planned. The incident is significant for the critical manufacturing sector, highlighting persistent risks tied to ICS software supply chains. As attackers increasingly exploit software flaws in operational technology, prompt patching and network segmentation remain vital. This vulnerability’s disclosure underscores the necessity for maintaining robust controls on critical infrastructure endpoints and monitoring for lateral movement threats.
7 months ago
Kill Chain
Rockwell Automation PLC Flaws Put Industrial Control Systems at Risk in 2025
In December 2025, Rockwell Automation disclosed multiple vulnerabilities affecting its Micro820, Micro850, and Micro870 programmable logic controllers (PLCs). The most critical issues (CVE-2025-13823, CVE-2025-13824) were found in the IPv6 stack and improper handling of malformed CIP packets, potentially allowing unauthenticated attackers to cause denial-of-service conditions. Successful exploitation could lead to systems becoming unresponsive and requiring physical intervention to restore operation. Affected product versions are widely deployed across critical manufacturing sectors worldwide, increasing the risk of operational disruptions. This incident highlights the growing exposure of operational technology (OT) devices to network-borne threats and the importance of promptly securing ICS environments. The prevalence of fuzzing-based vulnerability discovery and dependency on third-party components heighten the urgency to apply vendor-recommended mitigations and adopt defense-in-depth strategies.
7 months ago
Kill Chain
Critical LabVIEW 2025 Vulnerabilities Expose Industrial Control Systems to Code Execution Risk
In December 2025, multiple critical vulnerabilities (CVE-2025-64461 through CVE-2025-64469) were disclosed in National Instruments LabVIEW, a widely used industrial control software. The flaws, which include out-of-bounds write, out-of-bounds read, use-after-free, and stack-based buffer overflow, enable attackers to execute arbitrary code or exfiltrate information when a user opens a specially crafted VI file. Impacted versions span from LabVIEW 2021 up to 2025 Q3, affecting sectors such as critical manufacturing, defense, IT, and transportation globally. National Instruments released patches addressing these flaws, with older versions receiving limited or no support. Though there have been no reports of active exploitation, this incident highlights the persistent risk of supply chain and software vulnerabilities in critical ICS environments. Recent trends show a rise in sophisticated attacks leveraging user interaction and file-based exploits, emphasizing the growing need for robust patch management and secure software usage.
7 months ago
Kill Chain
Schneider Electric 2025: Critical WSUS Flaw Threatens Global Industrial Networks
In December 2025, Schneider Electric disclosed a critical vulnerability—CVE-2025-59287—in its EcoStruxure Foxboro DCS Advisor, an industrial automation component used worldwide across critical manufacturing and energy sectors. The vulnerability, rooted in untrusted data deserialization within Microsoft WSUS, could allow unauthenticated remote code execution with system-level privileges if exploited, threatening core operational networks. The exposure prompted Schneider Electric and CISA to issue urgent advisories urging immediate patching via provided Microsoft updates and to isolate control networks from business operations to prevent exploitation. Despite official advisories, any systems running unpatched software remain at high risk. The incident highlights the persistent challenges in securing dependencies within operational technology (OT) environments. With critical infrastructure increasingly targeted by sophisticated threat actors leveraging software supply chain and remote execution flaws, this case underscores the importance for organizations to proactively patch, segment networks, and reinforce incident response capabilities tailored for industrial control systems.
7 months ago
Kill Chain
Inductive Automation Ignition Vulnerability Exposes Critical Infrastructure to Privilege Escalation in 2025
In December 2025, Inductive Automation disclosed a privilege escalation vulnerability (CVE-2025-13911) in its Ignition SCADA platform widely used across critical manufacturing, energy, and IT sectors. The flaw arises from inadequate controls in the Python scripting environment, enabling authenticated administrators to execute arbitrary code with SYSTEM-level privileges on affected Windows hosts. Attackers can upload malicious project files to the Ignition Gateway, potentially leading to complete host compromise if exploited. Although there are currently no reports of public exploitation, this issue underscores growing risks associated with misconfigured automation platforms and the importance of adhering to least-privilege principles. Recent trends in supply chain and ICS-targeted attacks have increased regulatory pressure on critical infrastructure operators to address privilege escalation vectors.
7 months ago
Kill Chain
React2Shell 2025: When AI-Generated Exploits Complicate Supply Chain Defense
In December 2025, the cybersecurity community was rocked by mass exploitation efforts targeting "React2Shell," a critical vulnerability in the popular React UI framework. Threat actors, including China-linked groups, quickly launched attacks just hours after the initial public advisory. Amid the chaos, researchers and automated AI tools published over a hundred proof-of-concept (PoC) exploits—many of which were either nonfunctional or misrepresented the true risk, leading to widespread confusion. This "AI slop" polluted vulnerability feeds and caused defenders to waste valuable time, potentially resulting in underestimating the urgency to patch real flaws. The incident exposed significant weaknesses in open-source supply chain security, the peer-review process for public PoCs, and how security teams triage emerging threats. The React2Shell event is emblematic of the growing challenges defenders face as AI-generated code and public exploit sharing accelerate the pace and volume of security noise. With enterprises relying on automated detection and research, this incident highlights systemic risks posed by false negatives, delayed remediation, and rushed patch management in the face of incomplete or misleading information.
7 months ago
Kill Chain
Advantech WebAccess/SCADA 2025: Critical Vulnerabilities Threaten Industrial Control Systems
In December 2025, critical vulnerabilities were disclosed in Advantech WebAccess/SCADA software (version 9.2.1), widely used across critical manufacturing, energy, and water infrastructure worldwide. Discovered by Pellera Technologies, the weaknesses included multiple instances of path traversal (CVE-2025-14850, CVE-2025-67653, CVE-2025-14848), unrestricted file upload (CVE-2025-14849), and SQL injection (CVE-2025-46268). Exploitation could enable a remote, authenticated attacker to read or modify sensitive database content, delete files, or execute arbitrary code on impacted systems, significantly increasing cyber-physical risk for operations. Advantech advised immediate upgrades to v9.2.2 to remediate these flaws. This incident underscores ongoing challenges in the security of industrial control systems amid rising cyber threats targeting critical infrastructure. With no current evidence of public exploitation, practitioners must remain vigilant due to the highly impactful nature of the vulnerabilities and their corresponding attack surface across essential industries.
7 months ago
Kill Chain
Cellik RAT’s Google Play Store Infiltration Exposes Mobile Security Gaps
In June 2024, cybersecurity researchers uncovered that the Cellik Android Remote Access Trojan (RAT) was being distributed through malicious applications on the official Google Play Store. The Cellik RAT allows attackers to remotely control infected Android devices, harvest sensitive credentials, and exfiltrate private data without the user’s knowledge. Threat actors used advanced evasion tactics, including app generation within Play Store guidelines and encrypted communications, to bypass traditional defenses. The incident highlights weaknesses in mobile app review processes and demonstrates the continued use of popular app stores as distribution vectors for sophisticated malware campaigns. This breach is especially notable as attackers continue to exploit trusted platforms like the Google Play Store, elevating risk for both individuals and enterprises. The emergence of Cellik marks an uptick in mobile RAT sophistication and underscores the urgent need for stronger app vetting and threat detection on mainstream digital ecosystems.
7 months ago
Kill Chain
Critical Fortinet Flaws: Active Attacks Compromise Admin Accounts & Configs
In May 2024, threat actors began actively exploiting multiple critical vulnerabilities in Fortinet network devices, specifically targeting admin accounts to gain unauthorized access. Once authenticated, attackers exported sensitive device configurations containing hashed credentials and other proprietary information. The exploit allows lateral movement and increases the risk of sensitive enterprise data exposure, with widespread impacts noted across sectors relying on network infrastructure security. Fortinet urged immediate mitigation after observing attacks in the wild, with rapid patch releases and threat intelligence sharing. This incident highlights a concerning trend of attackers leveraging zero-day or freshly-disclosed vulnerabilities in widely deployed network appliances. As targeting of privileged accounts and network infrastructure rises, organizations must enhance monitoring, patch management, and segmentation strategies to prevent systemic compromise.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

