✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 3937 to 3948 of 5272
Cloudflare 2024 Outage: Why Network Resilience and Redundancy Matter More Than Ever
On June 20, 2024, Cloudflare, a major internet infrastructure and security provider, suffered a widespread service outage that disrupted access to thousands of websites and web services globally. The event was characterized by persistent 500 Internal Server Error messages for end users. Cloudflare initiated an internal investigation, ultimately attributing the incident to a critical infrastructure failure rather than a cyberattack or external threat. Throughout the outage, web-facing businesses, SaaS providers, and end-users experienced degraded network performance, extended downtime, and impact to brand trust, illustrating the magnitude of hyperscaler dependencies. The Cloudflare outage highlights the increasing risks associated with concentration of critical internet services and underscores the urgency for organizations to bolster resilience strategies. In an era of heightened service interdependencies and upticks in both incidents and attacks targeting fundamental service providers, outage preparedness and robust incident response planning are more essential than ever.
7 months ago
Kill Chain
AI Agent Prompt Injection Turns GitHub Actions Into Supply Chain Backdoor
In early 2024, cybersecurity researchers at Aikido disclosed a critical supply-chain vulnerability affecting major AI coding tools such as Google Gemini, Claude Code, OpenAI Codex, and GitHub AI Inference. The flaw enables attackers to inject malicious prompts into software automation workflows like GitHub Actions, causing integrated AI agents with elevated privileges to execute unauthorized commands. Cunning use of crafted commit messages and pull requests can trick large language models into treating these inputs as actionable instructions, leading to code modifications, shell command execution, and privilege escalation within software repositories. The vulnerability, reported via responsible disclosure, has prompted urgent fixes in some tools, but similar weaknesses remain present in other platforms. This incident highlights the expanding risks of AI-powered automation in the software development supply chain. With organizations increasingly relying on LLM integrations, the potential for prompt injection and privilege abuse creates new avenues for compromise, underscoring the urgency for robust controls, regular audit, and architectural safeguards around agentic AI workflows.
7 months ago
Kill Chain
How Sophisticated Attackers Exploited the 2025 React2Shell Zero-Day
In June 2025, a critical remote code execution vulnerability named React2Shell (CVE-2025-55182) was exploited in the wild against organizations using React Server Components. Within hours of the public disclosure and patch release, Chinese state-linked groups such as UNC5174 (CL-STA-1015), Earth Lamia, and Jackpot Panda, alongside opportunistic cybercriminals, began mass scanning and targeting exposed systems. The threat actors successfully deployed malware (notably Snowlight and Vshell), established persistent access, conducted credential theft, and attempted to extract Amazon Web Services configuration and credential files. Over 30 organizations across industries suffered breaches, including documented impact on customer cloud environments. This campaign demonstrates the increasing speed and coordination of attackers exploiting newly public vulnerabilities, especially in widely deployed frameworks like React and Next.js. The incident underscores the necessity of rapid patching, improved east-west traffic security, and continuous threat detection, as adversaries quickly weaponize disclosures for initial access and persistent footholds.
7 months ago
Kill Chain
China-Linked Supply Chain Breach Exploits React2Shell Flaw in 2025
In mid-2025, multiple China-linked threat actors launched widespread exploitation of the React2Shell vulnerability (CVE-2025-55182), a critical supply-chain flaw impacting React and Next.js applications. Within hours of the flaw’s public disclosure, attackers initiated automated scanning and weaponization campaigns, targeting internet-exposed services to quickly gain unauthorized, remote code execution. Successful intrusions enabled attackers to harvest sensitive data, escalate privileges, and pivot laterally within affected cloud environments. The rapid adoption of malicious payloads and swift exploitation before most organizations could patch led to substantial business risk, data loss, and potential compliance violations across sectors. This incident underscores an escalated threat landscape where nation-state actors rapidly exploit newly-disclosed supply-chain vulnerabilities. The speed and scope of these attacks reflect a significant uptick in zero-day exploitation campaigns and highlight the urgent need for organizations to strengthen patching velocity, endpoint monitoring, and east-west segmentation controls.
7 months ago
Kill Chain
Inotiv 2025 Ransomware Breach: Pharma Data at Risk
In August 2025, Inotiv, a leading American pharmaceutical firm, suffered a significant ransomware attack resulting in the theft of sensitive personal data belonging to thousands of individuals. Threat actors infiltrated the company’s network, deployed ransomware, and exfiltrated confidential information before encrypting internal systems. The breach led to data exposure and operational disruption, prompting Inotiv to notify impacted parties and regulatory authorities. Forensic investigation indicated unauthorized access over an extended period prior to the ransomware detonation, increasing the scope of compromised information. This incident highlights the escalating risks faced by the pharmaceutical industry, where highly regulated data attracts sophisticated ransomware groups. The resurgence of data-exfiltration ransomware tactics underlines the urgent need for advanced segmentation, egress controls, and integrated detection to defend against evolving threats and meet compliance expectations.
7 months ago
Kill Chain
Cloudflare’s 2024 Outage: Lessons from the React2Shell RCE Emergency
In June 2024, Cloudflare experienced a significant outage after emergency patching efforts to address an actively exploited remote code execution (RCE) vulnerability in the React framework, dubbed "React2Shell." The incident unfolded as threat actors began leveraging the vulnerability to attempt unauthorized code execution on internet-facing workloads, prompting Cloudflare to rush critical security mitigations. While the attack itself targeted exploitation routes via React, it was the swift application of mitigations—rather than a direct breach—which triggered widespread downtime, temporarily impacting Cloudflare's global network operations and customer accessibility. This incident underscores the increasing speed and aggression of active exploitation cycles, particularly for zero-day vulnerabilities in widely used frameworks. As attacker sophistication grows and organizations race to patch critical flaws, operational disruptions and collateral damage are becoming more frequent in the ongoing effort to balance security with business continuity.
7 months ago
Kill Chain
Intellexa Predator Spyware Strikes Pakistani Civil Society via WhatsApp (2025)
In June 2025, a human rights lawyer based in Balochistan, Pakistan, was targeted by Intellexa's highly advanced Predator spyware via a malicious WhatsApp link, according to Amnesty International. This marks the first documented case of a civil society member in Pakistan being targeted by this tool. The attacker, likely operating with government-grade resources, used zero-day exploits and an advertising-based infection vector to bypass conventional defenses, aiming to infiltrate the lawyer's mobile device and access sensitive communications. This incident underscores the growing sophistication of spyware campaigns and the expansion of mercenary surveillance tools targeting individuals beyond political figures or journalists. It highlights the urgent need for robust communication security and regulatory scrutiny of commercial spyware vendors.
7 months ago
Kill Chain
Clop Ransomware Hits Barts Health NHS via Oracle Zero-Day
In early 2024, Barts Health NHS Trust disclosed a data breach after Clop ransomware actors exploited a zero-day vulnerability in Oracle E-Business Suite. The attackers gained unauthorized access to internal systems, exfiltrated sensitive files from a key database, and threatened further leaks. The attack leveraged unpatched software flaws as the entry vector, allowing for rapid lateral movement and data theft before being detected. The incident disrupted operations and triggered regulatory notifications due to the sensitive nature of patient and operational information. This breach highlights the ongoing risks posed by sophisticated ransomware groups exploiting zero-day vulnerabilities in widely used enterprise software. Attacks of this kind are increasingly common, especially in the healthcare sector, which remains a high-value target for ransomware due to legacy systems and critical service mandates.
7 months ago
Kill Chain
CISA Discloses PRC Hackers Using BRICKSTORM Backdoor for Stealthy U.S. System Access
In June 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) reported that state-sponsored hackers affiliated with the People's Republic of China (PRC) utilized a newly identified backdoor dubbed BRICKSTORM to infiltrate and maintain long-term access within VMware vSphere and Windows environments of U.S. critical infrastructure entities. The campaign started months prior, leveraging advanced persistent threat (APT) tactics such as lateral movement, encrypted C2 channels, and sophisticated evasion techniques to bypass network defenses and persist undetected. This led to extensive exfiltration of sensitive data and raised major concerns about the resilience of core U.S. operational systems. The BRICKSTORM attack signals a rising tide of highly targeted intrusions on virtualization platforms, as nation-state actors adopt increasingly stealthy and persistent approaches. Organizations must now contend with the growing complexity and scale of APT operations, which often elude legacy tools and monitoring strategies.
7 months ago
Kill Chain
Active Command Injection Attacks Hit Array AG Series Gateways in 2025
In mid-2025, JPCERT/CC reported that a command injection vulnerability in Array Networks AG Series secure access gateways had been actively exploited in the wild since at least August of that year. The flaw, residing in the DesktopDirect remote desktop access feature, allowed unauthenticated attackers to execute arbitrary commands on targeted devices. The vulnerability, lacking a CVE at the time of disclosure, was patched by Array Networks in May 2025, but unpatched systems remained exposed to attacks that could lead to further compromise and unauthorized network access. This incident underscores the persistent risks of unpatched infrastructure and weak segmentation in network environments. The rise of zero-day exploits targeting remote access solutions combined with increased regulatory scrutiny makes rapid detection, patching, and least privilege policy enforcement more critical than ever.
7 months ago
Kill Chain
Supply-Chain Emergency: Critical XXE Bug (CVE-2025-66516) in Apache Tika Imperils Enterprises
In December 2025, a critical XML External Entity (XXE) vulnerability, CVE-2025-66516, with a maximum CVSS score of 10.0, was discovered in multiple core Apache Tika modules. This flaw enables unauthenticated attackers to exploit XXE processing to remotely access sensitive files, exfiltrate data, and launch further attacks through maliciously crafted XML payloads. Because Apache Tika is widely employed in data extraction and content analysis across enterprise, cloud, and supply-chain systems, the exposure has immediate downstream risk for any organizations leveraging impacted Tika libraries. The incident highlights a significant supply-chain security challenge, reinforcing the urgency for immediate patching and improved review of third-party open-source components. Increasingly, threat actors are exploiting foundational software dependencies to bypass traditional security perimeters, making software supply-chain vigilance a key priority for 2025 and beyond.
7 months ago
Kill Chain
Chinese Hackers Exploit React2Shell RCE—Critical React Server Vulnerability in 2025
In December 2025, two Chinese nation-state threat groups rapidly began exploiting CVE-2025-55182—dubbed 'React2Shell'—a critical unauthenticated remote code execution vulnerability affecting React Server Components (RSC). Within hours of public disclosure, attackers scanned for and targeted vulnerable servers globally, leveraging the flaw to gain full control over application environments, execute arbitrary commands, and establish persistent footholds for lateral movement. The wide adoption of React in enterprise and SaaS environments increased the exposure and impact of these attacks, putting sensitive business-critical data at risk and causing major security teams to issue rapid patch advisories. This incident underscores the growing speed with which advanced threat actors weaponize zero-day vulnerabilities in widely used software frameworks. It highlights the urgent need for rapid vulnerability management, enhanced east-west segmentation, and robust threat detection, as attackers increasingly exploit supply chain and development stack exposures in cloud and hybrid environments.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

