✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3805 to 3816 of 5272
How Google's 2024 Research Uncovered Chinese APT Exploitation of React2Shell
In June 2024, Google's Threat Analysis Group expanded the attribution of recent attacks exploiting the critical "React2Shell" remote code execution vulnerability to at least five more Chinese nation-state hacking groups. These attackers leveraged the unpatched React2Shell flaw to gain unauthorized access to systems across multiple sectors, using sophisticated spear-phishing and lateral movement techniques to deploy malware and establish persistence. The affected organizations experienced potential data exposure, operational interruptions, and increased remediation costs while scrambling to patch impacted environments. This incident highlights the evolving capabilities and coordination among multiple Chinese APTs targeting software supply chain weaknesses. The React2Shell exploitation surge demonstrates a significant escalation in the speed and scale of zero-day abuse by coordinated state-affiliated groups. Organizations face heightened urgency to accelerate vulnerability management and enhance east-west traffic monitoring as attackers rapidly weaponize public vulnerabilities.
7 months ago
Kill Chain
ShinyHunters Extort PornHub: 2024 Analytics Breach Exposes Premium Member Data
In June 2024, adult content platform PornHub became the target of a significant data breach when the ShinyHunters extortion group claimed to have stolen search and viewing history data linked to the site’s Premium members. Attackers reportedly exploited Mixpanel analytics integrations to exfiltrate sensitive user data, including logs of user activity, then threatened public release unless a ransom was paid. PornHub’s operations and brand reputation face heightened scrutiny, especially given the highly sensitive nature of the data involved, with many users fearing exposure and potential blackmail. This incident underscores the ongoing threats facing organizations that handle sensitive personal data, especially as extortion groups increasingly target user activity logs for leverage. Regulatory and reputational risks are amplified by attackers’ focus on analytics platforms, and similar tactics are expected to proliferate across other high-traffic digital properties in 2024.
7 months ago
Kill Chain
SantaStealer: The 2024 Memory-Based Infostealer Malware Targeting Credentials and Crypto Wallets
In early 2024, a new information-stealing malware known as SantaStealer emerged on cybercriminal Telegram channels and hacker forums, operating as a malware-as-a-service (MaaS). Designed to run primarily in memory, SantaStealer avoids traditional file-based detection and targets sensitive data in browsers, cryptocurrency wallets, and installed application credentials. Attackers typically distribute the malware through phishing campaigns and malicious attachments. Once executed, SantaStealer exfiltrates stolen data to command-and-control servers, enabling threat actors to harvest victims' digital assets and credentials for further exploitation or sale on underground markets. The incident underlines a growing trend of evasive, memory-resident stealer malware leveraging MaaS models. Cybercriminals are accelerating adoption of these techniques, raising the stakes for organizations and individuals who store credentials and assets on personal and enterprise endpoints.
7 months ago
Kill Chain
VolkLocker Ransomware Thwarted by Leaked Master Key: Lessons from the CyberVolk 2025 Attack
In August 2025, the pro-Russian hacktivist group known as CyberVolk (aka GLORIAMIST) launched VolkLocker, a new ransomware-as-a-service aimed at both Windows and Linux systems. SentinelOne researchers discovered that VolkLocker suffered a critical security flaw: a hard-coded master key was inadvertently left in test artifacts, enabling anyone to decrypt files encrypted by the ransomware, bypassing ransom payments. Attackers used typical RaaS deployment methods, leveraging phishing and malicious attachments for initial access. While the group attempted to extort victims, the encryption flaw significantly undermined their efforts. The incident highlights the increased frequency and complexity of ransomware-as-a-service offerings, while underscoring the role of sloppy operator security in containing damage. As similar attacks proliferate, organizations must prioritize incident response and security validation against emerging threats.
7 months ago
Kill Chain
Phantom Stealer Phishing: 2025 Attack Hits Russian Finance via ISO Emails
In late 2025, an active phishing campaign dubbed "Operation MoneyMount-ISO" began targeting the Russian financial sector and related industries, with threat actors distributing phishing emails containing malicious ISO disk image attachments. Once opened, these ISO files delivered the Phantom Stealer malware, enabling attackers to exfiltrate sensitive data from finance, accounting, procurement, legal, and payroll departments. The malware operated covertly, seeking credentials and financial information, leading to notable data exposure risks and potential regulatory disruptions for victim organizations. This campaign highlights the increasing sophistication of phishing operations leveraging disk image formats for initial access and the persistent targeting of high-value sectors with advanced infostealer malware. Financial and critical infrastructure organizations face heightened pressure to improve detection and segmentation as threat actors continually refine their social engineering tactics.
7 months ago
Kill Chain
Askul Hit by RansomHouse: 740,000 Customer Records Stolen in 2023 Ransomware Attack
In October 2023, Japanese e-commerce giant Askul Corporation suffered a ransomware attack attributed to the RansomHouse group. Attackers infiltrated Askul's systems, exfiltrating approximately 740,000 customer records containing sensitive personal and contact details before deploying ransomware to encrypt internal data. The breach forced Askul to temporarily suspend some business operations while it investigated the extent of the compromise. The attackers reportedly demanded a ransom in exchange for not releasing the stolen data, putting immense pressure on both customer trust and company reputation. This incident highlights the ongoing threat posed by sophisticated ransomware groups targeting large enterprises, especially in the retail and e-commerce sectors. The scale and impact underscore the necessity for organizations to strengthen data protection, incident response, and segmentation controls, as ransomware actors increasingly focus on data theft before encryption to maximize leverage.
7 months ago
Kill Chain
Critical Apple 0-Days and WinRAR Exploits: How Multi-Vector Threats Changed 2025
In December 2025, a wave of critical zero-day vulnerabilities targeting Apple devices, WinRAR, OAuth implementations, and the .NET framework was actively exploited by various cybercriminal groups. Attackers leveraged these flaws to bypass authentication mechanisms, execute remote code, and escalate privileges across both consumer and enterprise environments. Notably, some exploits were weaponized in the wild before official patches became available, resulting in widespread exposure of unencrypted traffic, unauthorized access to internal networks, and large-scale credential theft. Organizations experienced data breaches, ransomware infections, and regulatory scrutiny, particularly where weak segmentation or inadequate traffic visibility allowed lateral movement. This incident highlights the persistent threat posed by simultaneous multi-vector exploits, especially as attackers rapidly adopt new vulnerabilities in mainstream software. Increased regulatory focus on immediate patching and advanced segmentation underscores the necessity for robust, real-time threat detection and zero trust enforcement across hybrid and multi-cloud ecosystems.
7 months ago
Kill Chain
ShadyPanda’s Browser Extension Supply-Chain Attack Exposes Millions in 2025
In December 2025, security researchers uncovered a widespread supply-chain attack perpetrated by the threat group ShadyPanda, which had silently compromised several popular Chrome and Edge browser extensions. Over the course of seven years, ShadyPanda either published or acquired seemingly innocuous extensions, allowed them to build credibility and large user bases, and then weaponized them through malicious updates. The attackers exploited the implicit trust in browser extension ecosystems to exfiltrate user data and potentially inject hostile code into millions of browsers worldwide, impacting individuals and organizations alike. This incident underscores persistent risks in software supply chains, as threat actors increasingly target trusted application ecosystems to achieve broad access. As browser extensions remain integral to productivity and daily workflows, the event highlights the urgency for organizations to monitor third-party components and reassess extension management, especially amid evolving regulatory scrutiny and attacker sophistication.
7 months ago
Kill Chain
Urban VPN Chrome Extension Found Harvesting AI Chat Prompts from Millions
In late 2025, the "Urban VPN Proxy" Chrome extension—prominently labeled 'Featured' in the Chrome Web Store and boasting over six million users—was discovered silently harvesting all prompts users entered into popular AI chatbots such as ChatGPT, Anthropic Claude, Microsoft Copilot, Google Gemini, and others. Security researchers found the extension covertly intercepted and exfiltrated sensitive data in real time, leveraging its widespread user base and the inherent trust of its browser privileges. The extension’s activity amounted to a massive privacy breach, putting both individuals and enterprises at risk of data exposure. This breach highlights a surge in supply chain and third-party risks posed by browser extensions in the modern SaaS ecosystem. Enterprise security teams face heightened challenges as unregulated extensions become vectors for data harvesting, especially as reliance on AI tools increases. Privacy expectations, compliance obligations, and trust in official app marketplaces are now under renewed scrutiny.
7 months ago
Kill Chain
CISA Adds Apple & Gladinet Vulnerabilities to Known Exploited List (2025)
In December 2025, the Cybersecurity & Infrastructure Security Agency (CISA) added CVE-2025-14611 (Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability) and CVE-2025-43529 (Apple Multiple Products Use-After-Free WebKit Vulnerability) to its Known Exploited Vulnerabilities (KEV) Catalog following confirmed reports of active exploitation. These flaws allow attackers to gain unauthorized access, execute arbitrary code, and compromise sensitive data by leveraging weaknesses in encryption and browser components. Federal Civilian Executive Branch (FCEB) agencies are mandated to remediate these vulnerabilities by the stipulated deadlines to mitigate risks to critical government infrastructure. These additions reflect an ongoing surge in sophisticated vulnerability exploitation targeting both proprietary business platforms and widely used consumer products. Emerging attacker tactics and the regulatory environment reinforce the importance of robust, timely vulnerability management—underscoring that prioritizing patching of KEV-listed CVEs is now a best practice for all organizations.
7 months ago
Kill Chain
FreePBX 2025: Critical SQL Injection & Authentication Bypass Threatens Telecom Security
In September 2025, researchers from Horizon3.ai disclosed multiple severe vulnerabilities in FreePBX, an open-source private branch exchange (PBX) platform. These flaws, notably including a critical authentication bypass (CVE-2025-61675) and SQL injection issues, enabled remote code execution under certain configurations. Attackers could exploit these weaknesses to upload malicious files, bypass authentication controls, and potentially gain full system access. The vulnerabilities were responsibly reported to project maintainers, prompting urgent security patches and advisories to all FreePBX users. Organizations using affected versions faced significant risks, ranging from service disruption to compromise of sensitive communications and voicemail data. This incident highlights the persistent threat posed by application-layer vulnerabilities in widely deployed open-source communications platforms. The rise of telephony-based attacks and increasingly sophisticated exploitation tactics underscore the need for proactive patch management, rigorous code auditing, and supply chain security in telecom infrastructure.
7 months ago
Kill Chain
React2Shell CVE-2025-55182: Remote Code Execution Attacks Surge in 2025
In December 2025, active exploitation of a critical vulnerability in React2Shell (CVE-2025-55182) was detected, enabling remote code execution on unpatched servers. Attackers deployed a sequence of crafted HTTP requests to download and write malicious binaries onto world-writable Linux directories, such as /dev/shm and /tmp, then modified permissions to prepare for subsequent execution. The threat was identified by security researchers monitoring exploit payloads, which often leveraged ambiguous malware—classified as either adware or crypto miners—resulting in the compromise of affected servers and potentially unauthorized resource usage or data exfiltration. This campaign exemplifies the ongoing risk posed by delayed patch management, with adversaries swiftly evolving their payloads and exploiting widespread attack surfaces. The frequency of similar incidents underscores the importance of timely security updates and hardened configurations, particularly for widely deployed web services.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

