✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3853 to 3864 of 5272
Active Exploits Target Gladinet CentreStack and Triofox Using Hard-Coded Keys
In December 2025, Gladinet's CentreStack and Triofox platforms were found to contain a critical vulnerability (CVE-2025-14611) arising from hard-coded cryptographic keys. Threat actors exploited this flaw by crafting malicious access tickets, allowing them to decrypt sensitive files—including the web.config file—and ultimately achieve remote code execution through ViewState deserialization. At least nine organizations across healthcare and technology were compromised, with attackers chaining this vulnerability with previously known flaws for greater impact. The attack flow highlights attackers' in-depth knowledge of Gladinet’s codebase and past vulnerabilities. This incident underscores the growing risks from supply chain software flaws and repeated exploitation of insecure cryptography in enterprise products. The rapid addition of this CVE to CISA’s Known Exploited Vulnerabilities catalog reflects intensifying regulatory scrutiny and a pressing need for organizations to identify and remediate insecure authentication mechanisms promptly.
7 months ago
Kill Chain
UK Slaps LastPass with £1.2M Fine for 2022 Data Breach Exposing Encrypted Vaults
In August 2022, password management provider LastPass suffered a sophisticated data breach in which attackers exploited a compromised developer account. The breach led to the exfiltration of source code, proprietary data, and encrypted password vaults for approximately 1.6 million UK users. Investigation revealed gaps in LastPass’s internal security controls and multi-factor authentication implementation, enabling lateral movement and access to critical storage environments storing user vault backups. The breach resulted in substantial reputational and regulatory consequences for LastPass, including a £1.2 million fine from the UK Information Commissioner’s Office (ICO). This incident remains significant as it highlights persistent weaknesses in cloud application security, data vault encryption, and the growing focus of regulators on consumer data privacy practices. Increased cybercriminal targeting of password management services underscores an urgent need for robust internal segmentation and encryption at all stages.
7 months ago
Kill Chain
Malicious VSCode Extensions Breach Developer Supply Chain in 2024
In early 2024, researchers uncovered a significant supply chain attack affecting the Visual Studio Code Marketplace, where 19 malicious extensions were published and actively distributed since February. These extensions, downloaded by thousands of developers worldwide, secretly harbored trojans within disguised PNG files placed in dependency folders. The attackers leveraged VSCode’s broad adoption as a developer tool to inject remote access trojans (RATs) and facilitate potential compromise of development environments and source code. Microsoft has since removed the malicious extensions, but the campaign illustrates a growing trend of targeting developer ecosystems for initial access and data exfiltration. This incident highlights the increased risk posed by third-party dependencies in software supply chains, especially as attackers shift toward platforms popular among technical professionals. The event also underscores the ongoing regulatory and compliance challenges in managing integrity and security for code repositories and developer tools.
7 months ago
Kill Chain
Notepad++ Supply Chain Attack: Malicious Updater Flaw Exposes Millions (2024)
In June 2024, Notepad++ addressed a critical security vulnerability in its updater component, WinGUp, after researchers revealed that attackers could intercept the update process and deliver malicious executables instead of authentic software updates. The flaw arose because the updater did not enforce encryption or signature verification when retrieving update packages, allowing adversaries to mount supply chain attacks through man-in-the-middle techniques. This exposed users to risk of remote code execution and allowed attackers to propagate malware under the guise of legitimate software updates. This incident highlights the growing wave of software supply chain attacks in 2024, echoing concerns from security leaders and regulators about the risks of unencrypted software delivery channels. Organizations are being urged to ensure proper code signing, encrypted update pipelines, and vigilant anomaly detection in third-party dependencies to defend against evolving threat tactics.
7 months ago
Kill Chain
Gladinet CentreStack 2024: RCE Attacks via Cryptographic Vulnerability
In early June 2024, threat actors began exploiting a previously unknown cryptographic implementation flaw in Gladinet's CentreStack and Triofox products, enabling them to remotely execute code on vulnerable servers. By leveraging crafted payloads targeting insecure cryptographic validation, attackers bypassed authentication mechanisms and gained unauthorized access to sensitive file sharing environments. This led to potential exposure of confidential data, lateral movement, and service disruption for affected organizations, particularly those relying on CentreStack for enterprise file sharing and remote access. This incident highlights the risks of cryptographic implementation errors and the urgent need for patch management, especially for third-party cloud and SaaS solutions. As attackers increasingly weaponize zero-day flaws in commonly used remote file access platforms, enterprises must prioritize robust monitoring and rapid response strategies.
7 months ago
Kill Chain
Chrome Attacked: 2025 Zero-Day Memory Exploit in ANGLE Library Exposed
In December 2025, Google disclosed a high-severity zero-day vulnerability (CVE-2025-14174) affecting its Chrome browser, which had been exploited in the wild. The flaw, residing in Chrome's Almost Native Graphics Layer Engine (ANGLE), allowed attackers to perform out-of-bounds memory access via a crafted HTML page, enabling memory corruption, crashes, or remote code execution. Discovered by Apple's Security Engineering and Google TAG teams, this vulnerability triggered urgent patching across all Chromium-based browsers, as the exploit was independently observed targeting users prior to public awareness. This incident underscores growing risks associated with memory management flaws in popular software and the increasing frequency of zero-day exploits. With regulatory bodies like CISA flagging exploited Chrome vulnerabilities for immediate remediation, the event highlights a rising trend of sophisticated, targeted browser attacks that demand rapid and coordinated enterprise response.
7 months ago
Kill Chain
Gogs Zero-Day Exploit Compromises 700+ Cloud Instances in 2025
In July 2025, more than 700 internet-exposed instances of Gogs, a popular self-hosted Git service, were compromised via exploitation of an unpatched zero-day vulnerability (CVE-2025-8110). Threat actors took advantage of improper symbolic link handling in the file update API, enabling arbitrary file overwrite and remote code execution. Attackers deployed Supershell-based malware through a multi-step process to gain server access, leaving behind uniquely-named repositories and operating in a 'smash-and-grab' campaign style. The campaign exploited a previously patched flaw (CVE-2024-55947) bypass, emphasizing the importance of patch management and reducing attack surface exposure for critical developer infrastructure. This incident is highly relevant as it highlights an ongoing surge in attacks targeting developer and DevOps tools, exposing how rapidly adversaries adapt to security patch cycles and leverage weaknesses in open-source environments. GIT system supply chain risks and attacker agility mandate urgent focus on threat detection, cloud workload security, and privileged access management.
7 months ago
Kill Chain
React2Shell (CVE-2025-55182): New React Server Components Flaw Under Active Attack
In December 2025, attackers rapidly weaponized a critical deserialization vulnerability (CVE-2025-55182, "React2Shell") in React Server Components (RSC), enabling remote code execution on web servers running unpatched React libraries. Threat actors exploited the flaw—scoring a CVSS 10.0—by sending serialized payloads in POST requests, executing arbitrary commands, deploying malware, and exfiltrating credentials. Infections observed include crypto-miners, Mirai/Gafgyt bots, and the advanced RondoDox botnet targeting both Linux servers and IoT devices. Exploit activity began within hours of disclosure, with a sharp increase in attempts against internet-facing systems. This incident highlights the increasing speed at which proof-of-concept exploits are operationalized in the wild, emphasizing risks of deserialization vulnerabilities and dependency hygiene in modern web application stacks. Supply chain and cloud-centric attacks leveraging similar TTPs are expected to become more common, placing organizations with weak patch cycles at heightened risk.
7 months ago
Kill Chain
WIRTE’s 2025 Espionage Campaign: Middle East Governments Breached via AshenLoader and AshTag
In late 2025, the advanced persistent threat group WIRTE, linked to Gaza Cyber Gang, launched a far-reaching espionage campaign against government and diplomatic entities across the Middle East using a new malware suite known as AshTag. Attackers used phishing emails with geopolitical lures to entice targets into downloading malicious archives, resulting in the sideloading of AshenLoader and the deployment of AshTag. This modular .NET backdoor enabled remote command execution, persistence, and document exfiltration, specifically targeting sensitive diplomatic materials. Notably, attacks persisted throughout the Israel-Hamas conflict and continued after the Gaza ceasefire, highlighting the threat actors' sustained operational tempo. This campaign is a potent reminder of the increasing sophistication of state-linked espionage operations, including the adoption of advanced malware delivery and in-memory execution tactics designed to evade detection. With attackers broadening their target geography and refining their methods, regional governments and strategic organizations must urgently review and upgrade their defenses.
7 months ago
Kill Chain
Spyware, Mirai, Docker Leaks & ValleyRAT: Anatomy of a 2025 Multi-Vector Breach
In December 2025, a sophisticated multivector cyberattack campaign exploited vulnerabilities across popular software, container platforms, and download channels. Hackers leveraged malicious browser extensions, tainted movie torrents, and compromised Docker images to disseminate a blend of Mirai botnet variants, ValleyRAT rootkits, and advanced spyware, evading traditional perimeter defenses. The attackers utilized encrypted communications and east-west movement to escalate privileges and exfiltrate sensitive organizational data. Impacts included operational outages, ransom demands, exposure of proprietary assets, and regulatory notification obligations for affected companies across multiple industries. This attack illustrates the intensifying convergence of commodity malware, supply chain threats, and network infiltration techniques. With ransomware, spyware, and rootkits increasingly delivered via trusted collaboration or cloud platforms, and as attackers exploit hybrid environments, organizations face urgent pressure to revisit segmentation, detection, and zero trust controls.
7 months ago
Kill Chain
Mythic: The Growing Threat of Post-Exploitation C2 Frameworks in Network Traffic
In early 2024, cybersecurity researchers revealed the widespread use of the Mythic post-exploitation framework by multiple threat actors to gain persistent control of compromised networks. Mythic, a versatile multi-platform C2 (command and control) toolkit, has enabled adversaries to evade endpoint detection tools while moving laterally, collecting data, and exfiltrating sensitive assets. By leveraging covert channels such as HTTP(S), SMB, WebSocket, Discord, and GitHub APIs, attackers have masked their traffic from traditional network security defenses. Incident response teams observed tailored communication modules, pivoting tactics, and sophisticated data encoding, resulting in delayed detection and prolonged dwell time within targeted organizations. This incident highlights the growing challenge for defenders as open-source offensive frameworks become more advanced and widely adopted. The surge of network-based C2 detection evasion tactics underscores the need for enhanced behavioral analysis, encrypted traffic inspection, and updated NDR/IDS capabilities, especially as regulatory and compliance scrutiny intensifies.
7 months ago
Kill Chain
NANOREMOTE: Google Drive-Enabled APT Breach Targets Global Sectors in 2025
In late 2025, security researchers discovered a sophisticated cyber-espionage campaign leveraging a new Windows backdoor known as NANOREMOTE. This malware, attributed to the Chinese-linked threat cluster REF7707 (also called Jewelbug), exploited the Google Drive API for covert command-and-control and data exfiltration. Driven by a loader mimicking legitimate security software, the attack targeted government, defense, telecommunications, education, and aviation organizations across Southeast Asia and South America. NANOREMOTE's powerful features supported reconnaissance, file operations, and encrypted communications, enabling stealthy operations and persistent access for attackers. The initial infection vector remains unknown, but the malware's modular task management and file transfer facilities allowed efficient data theft and staged payload delivery undetected by many security controls. This incident exemplifies emerging threat trends where advanced persistent threat actors abuse benign, widely trusted cloud APIs to hide their operations. As similar tradecraft spreads, organizations face heightened risks of deep lateral movement, multifaceted data breaches, and regulatory scrutiny. Continuous improvements in east-west security and traffic visibility are critical as attackers innovate with cloud-native exfiltration channels.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

