✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3829 to 3840 of 5272
Critical Windows RasMan Zero-Day (2024) Disrupts Remote Access—What You Need To Know
In mid-2024, a new zero-day vulnerability was discovered in the Windows Remote Access Connection Manager (RasMan) service, allowing attackers to crash the service and potentially disrupt VPN and remote networking capabilities. Security researchers published unofficial patches after Microsoft had yet to release an official fix. The flaw enables a local attacker or malware to exploit the service, leading to denial-of-service (DoS) and potential impact on enterprise connectivity and productivity. Organizations relying on Windows-based remote access are particularly affected as attackers can target unpatched systems. This incident underscores the increasing trend of zero-day vulnerabilities targeting critical Windows services and highlights the need for rapid patch cycles and improved anomaly detection in IT environments. With unofficial fixes circulating before vendor patches, organizations face new risks in securing remote workforce infrastructure.
7 months ago
Kill Chain
CISA Flags Critical GeoServer XXE Vulnerability Exploited in the Wild
In December 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical XML External Entity (XXE) vulnerability, CVE-2025-58360, affecting OSGeo GeoServer to its Known Exploited Vulnerabilities catalog. This flaw impacts versions up to 2.25.5 and select subsequent releases, enabling unauthenticated attackers to exploit the /geoserver/wms GetMap endpoint. Successful exploitation may lead to unauthorized file access, Server-Side Request Forgery (SSRF), or denial-of-service attacks. The discovery, reported by vulnerability platform XBOW, has prompted warnings from both CISA and the Canadian Centre for Cyber Security, emphasizing risks to organizations using GeoServer in production environments. This incident underscores the persistent targeting of widely-used open-source tools by threat actors, particularly through unauthenticated exploit paths. Amid increased regulatory focus and real-world exploitation evidence, organizations face mounting pressure to patch vulnerable infrastructure and strengthen detective controls to mitigate post-exploitation impacts.
7 months ago
Kill Chain
Coupang’s 2024 Insider Breach: Ex-Employee Exposes 33.7 Million Customer Records
In June 2024, Coupang suffered a major data breach that exposed the personal information of approximately 33.7 million customers. The incident was traced to a former employee who maintained unauthorized access to internal systems after leaving the company. The ex-employee exploited residual system credentials to retrieve sensitive data, which included names, addresses, and contact details. Coupang discovered the breach during a security review and promptly notified regulatory authorities, emphasizing no financial information or passwords were accessed. Immediate actions included revoking all unnecessary access and tightening access control policies. This breach underscores the persistent issue of insider threats and the dangers of insufficient deprovisioning of system access. As remote work and rapid staff turnovers continue, organizations face heightened pressures to implement robust identity and access management to prevent similar incidents.
7 months ago
Kill Chain
Apple’s 2024 Zero-Day Exploits: Sophisticated Attacks Trigger Emergency Patches
In June 2024, Apple disclosed and swiftly patched two actively exploited zero-day vulnerabilities affecting multiple devices, including iPhones, iPads, and Macs. These flaws—CVE-2024-23296 (Kernel) and CVE-2024-23225 (RTKit)—were leveraged in a highly sophisticated attack that targeted select individuals, likely as part of a nation-state or advanced persistent threat campaign. The attackers bypassed security protections to achieve elevated privileges and potentially execute arbitrary code, underscoring the level of technical prowess and intent to compromise high-value targets. Apple released emergency updates to mitigate ongoing exploitation, emphasizing the urgency of immediate patching. This incident highlights the growing trend of advanced, targeted zero-day attacks aimed at high-profile platforms and users. Security teams should expect continued adversary innovation, accelerated zero-day discovery, and a heightened need for organizations to quickly adopt vendor-released mitigations to safeguard sensitive data and operations.
7 months ago
Kill Chain
How Zigbee Protocol Flaws Exposed Industrial IoT Networks in 2024
In early 2024, security researchers uncovered critical vulnerabilities affecting Zigbee-based industrial IoT and automation environments. By assessing real-world installations, attackers demonstrated how both spoofed packet injection and coordinator impersonation attacks could exploit application-layer protocol weaknesses and misconfigurations. Notably, exposed or hard-coded keys, absence of end-to-end encryption, and insecure default settings enabled adversaries to hijack communications, control relay devices, and ultimately compromise entire sensor networks. The attack techniques bypassed traditional network segmentation and leveraged custom wireless tools to overcome timing and profile mismatches. This incident highlights urgent gaps in IoT and industrial security — especially the risks posed by legacy or proprietary protocol deployments lagging on best-practice cryptographic implementation. With industrial sectors increasingly reliant on automated sensor networks, attackers are expanding TTPs to target low-power wireless protocols like Zigbee, making advanced monitoring and zero trust approaches more critical than ever.
7 months ago
Kill Chain
React2Shell Exploitation: Global RCE Wave Sparks Emergency Security Response
In December 2025, the React2Shell vulnerability (CVE-2025-55182) emerged as a critical remote code execution flaw impacting React Server Components and several key frameworks such as Next.js, Vite, and RedwoodSDK. Threat actors rapidly exploited the unauthenticated deserialization bug, enabling arbitrary privileged JavaScript execution with a single HTTP request. Within days of public disclosure, multiple malicious campaigns leveraged the flaw to deploy malware, compromise sensitive systems—including government, critical infrastructure and technology entities—and conduct mass internet-wide scans. Over 137,200 exposed endpoints were tracked globally, prompting CISA to issue an accelerated mitigation deadline and security vendors to warn of global supply chain risks. React2Shell’s exploitation highlights the growing trend of mass-scale, opportunistic attacks leveraging zero-day vulnerabilities in widely-used cloud-native frameworks. With parallels drawn to systemic exploits like Log4Shell, organizations face rising regulatory and supply chain scrutiny to strengthen cloud security and incident response practices.
7 months ago
Kill Chain
Phishing in 2025: How Stolen Data Hits Telegram and the Dark Web Faster Than Ever
In early-to-mid 2025, a broad wave of phishing campaigns leveraged sophisticated data harvesting tools—including Telegram bots and automated admin panels—to exfiltrate user credentials and personal data from victims worldwide. Attackers collected credentials through fraudulent pages, relayed them instantly over secure messaging apps or specialized dashboards, and then swiftly funneled the stolen information into darknet marketplaces. Stolen data ranged from email logins and banking details to scans of personal documents, which were sorted, validated, and commoditized for direct fraud, resale, or subsequent targeted attacks on individuals and organizations. This incident highlights the acceleration of phishing-as-a-service ecosystems driven by real-time, evasive data exfiltration via commodity tools. The commodification of personal and corporate credentials intensifies regulatory and reputational risks, as stolen data is increasingly recycled for follow-on attacks—including identity theft and business email compromise—months or years after the initial breach.
7 months ago
Kill Chain
Critical React Server Components Flaws in 2025 Enable DoS and Code Leaks
In December 2025, several critical vulnerabilities were discovered in React Server Components (RSC), affecting core packages such as react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. Identified as CVE-2025-55184, CVE-2025-67779, and CVE-2025-55183, these flaws were exploited by attackers to perform pre-authentication denial-of-service (DoS) attacks and, in some cases, access sensitive server-side source code. Exploitation was enabled through unsafe deserialization of HTTP payloads, leading to server hangs, or via crafted requests that exposed function source code. The vulnerabilities impacted RSC versions 19.0.0 through 19.2.2 and were identified following active investigation by security researchers in the wake of CVE-2025-55182 exploitation in the wild. This incident underscores the growing trend of adversaries targeting server-side JavaScript frameworks through exploitation chains and rapid patch circumvention. Organizations relying on React for server-side rendering must remain vigilant, as repeated disclosures highlight both the software supply chain's fragility and the need for rigorous update cycles to fend off evolving threats.
7 months ago
Kill Chain
2025 Advanced Phishing Kits Exploit AI and MFA Bypass to Steal Credentials at Scale
In August 2025, cybersecurity firms identified four sophisticated phishing kits—BlackForce, GhostFrame, InboxPrime AI, and Spiderman—leveraging advanced AI and multi-factor authentication (MFA) bypass tactics to automate credential theft at massive scale. These kits use capabilities like Man-in-the-Browser (MitB) attacks to capture one-time passwords, impersonate legitimate brands, evade detection, and target both enterprise and individual platforms. Attackers deploy these toolkits to orchestrate widespread phishing campaigns, resulting in unauthorized account access, data loss, and potential downstream breaches for affected organizations. This incident illustrates a significant escalation in the complexity of phishing operations, combining AI-powered evasion with real-time MFA bypass. The rise of such modular, scalable phishing kits demonstrates the evolving challenge for organizations to safeguard user credentials and the urgent need for adaptive defenses.
7 months ago
Kill Chain
CISA Adds Google Chromium CVE-2025-14174 to Exploited Vulnerabilities List
In December 2025, CISA added CVE-2025-14174—a Google Chromium out-of-bounds memory access vulnerability—to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation. This vulnerability enables threat actors to execute arbitrary code or potentially escalate privileges via unauthorized memory access within affected Chromium browser instances. Attackers exploited this flaw as an entry vector for malware and credential theft, increasing risks for both federal agencies and organizations relying on Chromium-based browsers. Federal Civilian Executive Branch agencies were directed, under BOD 22-01, to remediate this vulnerability by a strict deadline to mitigate ongoing risks. The rapid inclusion of CVE-2025-14174 in the KEV Catalog highlights persistent challenges posed by zero-day and n-day browser vulnerabilities. Recent increases in browser-based exploitation and strict regulatory mandates underscore the growing urgency to address software supply chain threats and prioritize swift vulnerability management across all industry sectors.
7 months ago
Kill Chain
Fake OSINT and GPT GitHub Repos Used to Spread PyStoreRAT in Supply Chain Attack
In late 2025, cybersecurity researchers uncovered a supply chain attack involving malicious repositories on GitHub impersonating open-source Python utilities themed around OSINT and GPT automation. These repos covertly delivered a previously unseen JavaScript-based Remote Access Trojan dubbed PyStoreRAT, using minimal code to retrieve and execute a remote HTA file. Unsuspecting developers and security professionals, lured by the project's legitimate appearance, risked compromise when cloning or running the code, resulting in unauthorized remote access and potential data exfiltration. The campaign highlights the growing sophistication of attacks abusing trusted developer platforms and open-source supply chains. This incident underscores the urgent need for organizations to audit third-party code sources, bolster code supply chain security, and monitor for emerging malware targeting developer ecosystems. The tactic reflects broader trends in social engineering, weaponized open-source projects, and the exploitation of generative AI themes by threat actors.
7 months ago
Kill Chain
FBI Delivers 630 Million Compromised Passwords to HIBP: 2024 Credential Exposure
In June 2024, the FBI provided Have I Been Pwned (HIBP) with approximately 630 million compromised passwords uncovered during multiple cybercrime investigations. The credentials were amassed from seized devices linked to a criminal suspect and sourced from the open web, Tor-based marketplaces, Telegram channels, and infostealer malware logs. Notably, about 46 million of these passwords were new to HIBP's repository, enabling organizations and individuals to proactively block use of these widely circulated credentials and bolster account security. The addition further expands the scale and utility of accessible credential hygiene tools worldwide. This incident underscores the ongoing and massive prevalence of credential compromise in the cybercrime landscape, as password data continually proliferates across threat actors and dark markets. It highlights the urgent need for organizations to adopt robust password exposure monitoring and zero trust authentication policies.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

