✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3757 to 3768 of 5272
Zeroday Cloud 2025: $320,000 Awarded for Critical Cloud Platform Zero-Days
In December 2025, the inaugural Zeroday Cloud hacking competition in London highlighted severe risks facing cloud infrastructure by awarding $320,000 for the demonstration of 11 zero-day vulnerabilities across components like Redis, PostgreSQL, Grafana, and the Linux kernel. Notably, researchers exploited a container escape flaw in the Linux kernel, threatening tenant isolation—a cornerstone of cloud security. The impacted databases are integral to storing sensitive information, including credentials and user data. Although the event was hosted in a controlled environment, it provided a real-world showcase of how adversaries can achieve lateral movement and severe impact using previously unknown vulnerabilities. As critical cloud services grow more ubiquitous and attackers continue to innovate, this incident underscores the urgency for organizations to address emerging threats through proactive vulnerability management, layered defense, and rapid response capabilities.
7 months ago
Kill Chain
France's Ministry of the Interior Breached in Nation-State Attack: 2024 Suspect Arrested
In June 2024, French authorities arrested a 22-year-old suspect in connection with a cyberattack targeting the Ministry of the Interior. The attack took place earlier in the month and was orchestrated using sophisticated nation-state level tactics, resulting in unauthorized access to sensitive government infrastructure. Although the Ministry quickly identified the incursion and initiated prompt containment measures, the breach underscored significant vulnerabilities in the security perimeter of key government agencies. Investigators believe the attacker leveraged advanced persistence techniques and attempted to exfiltrate confidential information before being apprehended. This incident underscores the growing sophistication of cyber operations targeting European governmental institutions. As nation-state and advanced persistent threats (APTs) escalate in frequency and impact, public sector organizations must reinforce zero trust segmentation, threat detection, and traffic encryption controls to stay ahead of evolving risks.
7 months ago
Kill Chain
APT28 Targeted Ukrainian UKR.net Users in Sophisticated Credential Phishing Campaign (2024–2025)
Between June 2024 and April 2025, the Russian state-sponsored group APT28 orchestrated a prolonged credential harvesting operation targeting users of UKR.net, one of Ukraine’s most popular webmail and news platforms. Threat intelligence from Recorded Future’s Insikt Group indicates that the attackers leveraged spear-phishing emails, cleverly masquerading as legitimate UKR.net communications, to deceive victims into disclosing their login details on malicious lookalike sites. This campaign continued APT28’s longstanding focus on geopolitical and military targets associated with Ukraine, and raises serious concerns about national security and the exposure of sensitive communications during a period of heightened regional conflict. The incident spotlights a surge in state-sponsored credential theft using advanced social engineering, capitalization on trusted local brands, and persistent, evolving methodologies. As phishing techniques become more adept at bypassing basic controls, organizations are under pressure to bolster identity protection, phishing awareness, and multifactor authentication while aligning closely with regulatory guidance for detection and response.
7 months ago
Kill Chain
ForumTroll APT Strikes Again: Russian Political Scientists Hit by Sophisticated Phishing Scheme
In October 2025, the ForumTroll advanced persistent threat (APT) group launched a spear-phishing campaign targeting Russian political science scholars and researchers. Victims received personalized emails disguised as plagiarism report notifications from a fake scientific library domain, prompting them to download a malicious archive. Opening the archive triggered a PowerShell-based attack chain, culminating in the deployment of the Tuoni red-teaming framework via a custom obfuscated loader, with persistence achieved through COM Hijacking. Attacker infrastructure included typosquatted domains and Fastly-based C2 servers. This incident underscores the increasing shift by APT actors to highly targeted, socially engineered phishing attacks, even when technical sophistication is dialed back. Organizations must contend with the reality of persistent, multi-phase campaigns adapting both commercial and bespoke toolkits, heightening the urgency for advanced detection and resilient user training.
7 months ago
Kill Chain
Inside Kimwolf: How 1.8 Million Android TVs Became a DDoS Botnet Army
In December 2025, cybersecurity researchers discovered the Kimwolf botnet had hijacked over 1.8 million Android-based smart TVs, set-top boxes, and tablets globally. The attackers leveraged the NDK (Native Development Kit) to compile malware that turned these consumer devices into a massive botnet used primarily for launching large-scale distributed denial-of-service (DDoS) attacks. The infected endpoints were recruited silently and spread across both residential and enterprise networks, enabling the attackers to conduct coordinated, high-bandwidth attacks and evade conventional network defenses. Initial findings also suggest a link between Kimwolf and the previously observed AISURU botnet, indicating possible collaboration or shared tooling between threat actors. This incident highlights a disturbing trend: threat actors increasingly targeting loosely protected IoT and smart device ecosystems for botnet creation. The scale and performance of Kimwolf underscore the growing risk posed by unpatched consumer electronics, calling for urgent improvements in east-west traffic security, segmentation, and network visibility across hybrid environments.
7 months ago
Kill Chain
ForumTroll Launches Sophisticated Phishing Attack on Russian Scholars Using Fake eLibrary Emails
In October 2025, Operation ForumTroll, a previously identified threat actor, launched a targeted phishing campaign against Russian academic and scholarly communities. Using convincingly crafted phishing emails that impersonated official eLibrary notifications, attackers distributed malicious attachments designed to harvest credentials and enable broader espionage operations. The campaign, identified by Kaspersky, marks a decisive tactical shift from prior attacks on organizations to focused targeting of individuals, raising concerns about the security posture of research and educational institutions in the region. This incident highlights the increasing trend of sophisticated phishing campaigns that employ social engineering and trusted brands to bypass traditional defenses. The focused targeting of scholars and intellectuals points towards a rise in espionage-motivated threats seeking sensitive research data, emphasizing the need for robust user education, multifactor authentication, and advanced anomaly detection.
7 months ago
Kill Chain
SonicWall SMA 100 Breach 2025: CVE-2025-40602 Actively Exploited
In December 2025, SonicWall disclosed a security breach affecting its Secure Mobile Access (SMA) 100 series appliances, driven by exploitation of CVE-2025-40602—a local privilege escalation vulnerability. The issue arose due to insufficient authorization in the Appliance Management Console (AMC), enabling threat actors to elevate local privileges and gain greater control within affected systems. SonicWall confirmed active exploitation in the wild, prompting an urgent release of security patches while urging all customers to apply updates immediately. The incident underscores the risks facing network appliances and the rapid speed with which attackers can leverage new vulnerabilities to compromise enterprise infrastructure. This event occurs amidst a wider uptick in attacks targeting edge appliances from network security vendors, as adversaries increasingly exploit publicly disclosed software flaws soon after their publication. Organizations are under intensified regulatory and operational pressure to patch critical vulnerabilities rapidly and reinforce privilege management strategies.
7 months ago
Kill Chain
How BlueDelta (APT28) Targeted UKR.NET with Persistent Credential Harvesting (2024-2025)
Between June 2024 and April 2025, Russian state-sponsored threat group BlueDelta (APT28) orchestrated a persistent credential-harvesting campaign targeting users of UKR.NET, a leading Ukrainian webmail and news service. The threat actor employed convincing UKR.NET-lookalike login portals hosted on free services like Mocky, DNS EXIT, ngrok, and Serveo to steal usernames, passwords, and two-factor authentication codes. Phishing lures, primarily PDF attachments embedded with malicious links, were distributed to evade email scanning and sandboxing. Attackers continuously evolved their infrastructure—moving from compromised routers to anonymized tunneling platforms and adding new operational layers—reflecting increasing sophistication and resilience in support of GRU intelligence goals. This campaign exemplifies ongoing adaptations by nation-state actors to Western infrastructure takedowns and detection mechanisms, highlighting escalating risks to critical digital identities. Its advanced evasion techniques, modular infrastructure, and creative abuse of free online services signal a new phase in credential theft, underscoring the urgent need for organizations to reassess their defenses, particularly in the face of targeted phishing and lateral movement threats.
7 months ago
Kill Chain
CISA Flags 3 New Actively Exploited Vulnerabilities: Cisco, SonicWall, ASUS
In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added three newly discovered vulnerabilities (CVE-2025-20393, CVE-2025-40602, and CVE-2025-59374) to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence. These flaws impact multiple Cisco products, SonicWall SMA1000, and ASUS Live Update, allowing attackers to gain unauthorized access, insert malicious code, or bypass input validations. Such exposures provide fertile ground for cybercriminals to enter networks, move laterally, and compromise data, posing significant operational and business continuity risks to affected organizations across sectors. Their rapid inclusion into the KEV Catalog reflects a surge in the exploitation of software supply chains and critical infrastructure technologies. With attackers leveraging faster exploit-to-impact timelines, government agencies and enterprises face mounting pressure to patch immediately and update their vulnerability and segmentation strategies to prevent cascading breaches.
7 months ago
Kill Chain
A $0 Transaction Triggers a Nation-State Cyberattack on Anthropic’s AI Platform
In early 2024, Anthropic, a leading artificial intelligence company, was targeted in a sophisticated nation-state cyber espionage campaign. Adversaries utilized compromised payment cards—previously validated through Chinese-operated card-testing services—to attempt unauthorized access to Anthropic's AI platform. The attackers leveraged an established cybercriminal kill chain: stealing card data, validating credentials through tester merchants, and ultimately using the compromised accounts to escalate their intrusion attempts. While no sensitive customer data was confirmed to be compromised, the incident underscored the vulnerability of downstream cloud-based AI assets to upstream financial fraud and highlighted the intersection of cybercrime with state-sponsored intelligence objectives. This attack serves as a high-profile example of how advanced fraud intelligence can act as an early detection mechanism for state-sponsored cyber operations. The incident exemplifies rapid convergence between financial fraud and targeted espionage, emphasizing the need for cross-domain threat visibility and proactive controls.
7 months ago
Kill Chain
Russian Nation-State Hackers Breach Critical Infrastructure via Edge Device Flaws
In early 2024, Russian-linked APT actors launched a prolonged cyberattack campaign targeting critical infrastructure organizations globally, with a particular focus on the energy sector. Leveraging misconfigured edge networking devices, attackers gained initial access to internal networks, allowing them to perform lateral movement and conduct espionage on sensitive operational systems. The campaign, detailed by Amazon's security division, utilized unencrypted management traffic, enabling threat actors to intercept data-in-transit and issue command-and-control instructions undetected. Widespread exploitation resulted in data exfiltration, system compromise, and operational disruptions for affected organizations. This incident highlights a surge in advanced persistent threats exploiting basic configuration weaknesses in edge devices. The continued targeting of critical sectors by nation-state actors underscores the urgent need for stronger segmentation, encrypted network traffic, and improved detection capabilities, as attackers are increasingly adept at bypassing conventional perimeter defenses.
7 months ago
Kill Chain
2025 Ransomware Attack Disrupts Venezuela’s State Oil Giant PDVSA
In December 2025, Petróleos de Venezuela (PDVSA), Venezuela’s national oil and gas company, experienced a significant ransomware attack that targeted its administrative systems. While official company communications downplayed the incident and attributed blame to international adversaries, media reports indicated substantial disruption: the attack resulted in major outages, took down vital IT systems, impacted cargo deliveries, and forced network disconnections. Efforts to remediate using antivirus software exacerbated downtime, and export activities, including loading instructions, were suspended. The incident highlighted operational fragility due to reliance on legacy infrastructure and a lack of segmentation between administrative and critical operational technologies. This breach spotlights the ongoing wave of ransomware attacks targeting energy and critical infrastructure sectors worldwide. It underscores how geopolitically charged environments, and legacy technologies without zero trust segmentation, remain especially vulnerable. The incident serves as a stark warning for the urgent adoption of robust east-west traffic controls and resilient response playbooks to mitigate emerging ransomware TTPs.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

