Validated Containment Architectures are here. →Explore

STRUCTURED THREAT INTELLIGENCE FOR THE CLOUD COMMUNITY

Aviatrix Threat Research Center

Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.

The Aviatrix Threat Research Center provides security teams with:

  • A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
  • What attackers exploited, and which enforcement gaps let them move.
  • Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.
Kill Chain Coverage
ATT&CK Mapped
Real-World IOCs
Graphic-for-second-Salt-Typhoon-blog-2
Threat ReportsLive Intelligence

Recent Breaches, Security Incidents & Vulnerabilities

A unified view of real-world cloud threats — combining AI-powered analysis, security research, and expert perspectives through a consistent, cloud-specific framework.

AI-Powered Threat Analysis

Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.

Browse by Industry
Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Displaying 4009 to 4020 of 5292

Critical King Addons Elementor Plugin Flaw Exploited in WordPress Sites (CVE-2025-8489)
Impact· low
Critical King Addons Elementor Plugin Flaw Exploited in WordPress Sites (CVE-2025-8489)

In early 2025, attackers began actively exploiting a critical privilege escalation flaw (CVE-2025-8489) in the King Addons for Elementor plugin on WordPress sites. By abusing an insecure registration process, threat actors were able to escalate privileges and gain administrative control over vulnerable sites without authorization. This access could be used to manipulate website content, add malicious backdoors, or exfiltrate sensitive data, impacting website owners' security and reputation. The attacks have been widespread due to the plugin's popularity and ease of exploitation, highlighting the persistent risks present in third-party WordPress extensions. This incident is particularly relevant as it exemplifies an ongoing wave of attacks targeting web application vulnerabilities in widely used CMS platforms. The proliferation of such zero-day exploits magnifies risk for organizations, especially as adversaries move quickly to weaponize flaws before patches are broadly applied.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Supply Chain Attack: Malicious Rust Crate Targets Web3 Developer Ecosystems
Impact· medium
Supply Chain Attack: Malicious Rust Crate Targets Web3 Developer Ecosystems

In April 2025, cybersecurity researchers identified a malicious Rust package named "evm-units" that was uploaded to crates.io, the central Rust package registry. Disguised as an Ethereum Virtual Machine (EVM) helper tool, the crate targeted developers working in Web3 environments across Windows, macOS, and Linux systems. Once installed, the package stealthily executed OS-specific malware to compromise developer endpoints, enabling threat actors to potentially gain access to sensitive credentials and project intellectual property. The incident underscores sophisticated, hard-to-detect supply chain tactics exploiting trusted ecosystems and automated developer workflows. This attack highlights the increasing prevalence of supply chain threats targeting open source development pipelines and blockchain ecosystems. Recent trends show attackers adapting to security controls by embedding malware into widely used software components, pressuring organizations to enhance package vetting, anomaly detection, and Zero Trust strategies.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Marquis Data Breach: 2024 Supply Chain Attack Exposes US Banking Customers
Impact· high
Marquis Data Breach: 2024 Supply Chain Attack Exposes US Banking Customers

In early 2024, Marquis Software Solutions, a financial marketing service provider, was the victim of a significant data breach that compromised sensitive personal information across more than 74 US banks and credit unions. The attackers gained unauthorized access through a third-party vulnerability and exfiltrated data sets containing names, addresses, Social Security numbers, financial account details, and demographic information of hundreds of thousands of customers. The breach not only impacted Marquis’s direct clients but also exposed downstream institutions and their end-users, triggering regulatory notifications and potential reputational damage to affected financial entities. This incident highlights the enduring risk posed by supply chain vulnerabilities within highly regulated industries, as attackers continue targeting trusted vendors with access to sensitive data. It underscores increasing regulatory scrutiny on vendor risk management and data protection, especially within financial and healthcare sectors.

7 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Leroy Merlin Customer Data Breach Exposes Personal Information in France
Impact· high
Leroy Merlin Customer Data Breach Exposes Personal Information in France

In June 2024, French home improvement retailer Leroy Merlin disclosed a security incident impacting its French customer base. Attackers gained unauthorized access to customer accounts and personal data, including names, email addresses, physical addresses, phone numbers, and order histories. While no financial data or passwords were compromised, the company became aware of unusual activity and swiftly launched an internal investigation and incident response procedures. Affected users were notified and advised to remain vigilant against phishing attempts. The incident has triggered regulatory attention and widespread concern among customers. The breach at Leroy Merlin highlights the increasing frequency of attacks targeting customer data in the retail sector. As organizations digitize more customer interactions, they face mounting regulatory pressure to safeguard personal information and promptly report security incidents to minimize reputational and financial risk.

7 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Freedom Mobile Data Breach 2024: Customer Information Compromised via Account Platform
Impact· high
Freedom Mobile Data Breach 2024: Customer Information Compromised via Account Platform

In June 2024, Freedom Mobile, Canada's fourth-largest wireless carrier, publicly disclosed a significant data breach after attackers compromised its customer account management platform. Unauthorized access allowed threat actors to steal sensitive customer data, including personal information such as names, contact details, and possibly financial information. The breach's scope is still being assessed, but the incident highlighted vulnerabilities in the exposed platform, prompting a swift operational and security review. Immediate remedial measures included engaging external cybersecurity experts, notifying impacted customers, and alerting regulatory authorities as required by Canadian privacy law. This incident underscores the continued risk posed by attacks targeting customer portals and account management systems—an increasingly common vector across the telecom sector. With regulatory scrutiny around privacy and data protection intensifying globally, this breach offers a stark reminder of the critical importance of securing customer data and internal administrative interfaces.

7 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Shai Hulud 2.0: The npm Supply Chain Worm Disrupting DevOps
Impact· high
Shai Hulud 2.0: The npm Supply Chain Worm Disrupting DevOps

In September 2023, a sophisticated supply-chain attack dubbed Shai Hulud 2.0 targeted the JavaScript ecosystem by compromising over 800 Node Package Manager (npm) packages. The malware leveraged stolen npm tokens to spread and infect trusted packages with a worm-like, two-stage payload. Upon download, it harvested GitHub and cloud credentials, aggressively scanned files for secrets, and exfiltrated stolen data via malicious public GitHub repositories. If unable to gain access tokens for exfiltration, the malware triggered a destructive file-wiping payload, disrupting both individual developers and organizations. Widespread impact was observed across Russia, India, Brazil, Vietnam, and more. This incident underscores the escalating risk of deep supply-chain compromise through open-source ecosystems and highlights attackers' evolving Tactics, Techniques, and Procedures (TTPs). It demonstrates the urgent need for enhanced monitoring, credential protection, and robust controls within software supply chains.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Picklescan Bugs Expose PyTorch Supply Chain: Malicious Models Bypass Security
Impact· low
Critical Picklescan Bugs Expose PyTorch Supply Chain: Malicious Models Bypass Security

In December 2025, severe vulnerabilities were revealed in Picklescan, an open-source security tool designed to scan Python pickle files for malicious code, particularly those used with PyTorch models. Attackers were able to exploit three critical flaws, bypassing Picklescan’s intended protections to execute arbitrary code during model loading processes. This effectively enabled the distribution of malicious machine learning models that could compromise developer and production environments. The risk was amplified due to Picklescan’s popularity in data science and AI workflows, potentially impacting organizations across multiple sectors relying on PyTorch. The incident is a stark reminder of the growing risk posed by supply-chain vulnerabilities in open-source AI and machine learning tooling, especially as the adoption of MLOps and automated model deployment platforms accelerates. Organizations now face increased regulatory scrutiny and operational risks tied to software supply chain security in the era of AI-driven applications.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Brazil Faces 2025 Banking Trojan Crisis Spread via WhatsApp and NFC Relay Fraud
Impact· medium
Brazil Faces 2025 Banking Trojan Crisis Spread via WhatsApp and NFC Relay Fraud

In late 2025, Brazil was struck by a sophisticated banking trojan campaign perpetrated by the threat actor Water Saci. Leveraging WhatsApp as a wormable transmission channel, attackers delivered highly obfuscated HTA and PDF payloads to users. Once opened, these files initiated a new Python-based trojan variant, enabling credential theft and fraudulent banking transactions. The attack chain also included NFC relay tactics (RelayNFC), amplifying transactional fraud by hijacking contactless payment operations. The campaign evaded detection using advanced scripting and lateral propagation, causing financial and reputational damage within the Brazilian financial sector. This incident marks a significant escalation in multichannel malware delivery, combining social engineering, banking trojans, and NFC payment interception. It underscores the converging risk between consumer messaging apps and new payment technologies, highlighting the urgency for layered east-west and egress network protection.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
2025 WordPress King Addons Breach: Unauthenticated Admin Access & Website Takeover
Impact· medium
2025 WordPress King Addons Breach: Unauthenticated Admin Access & Website Takeover

In December 2025, attackers actively exploited a critical vulnerability (CVE-2025-8489, CVSS 9.8) in the popular King Addons for Elementor WordPress plugin. The flaw allowed unauthenticated individuals to escalate privileges by specifying the 'administrator' user role at registration, instantly granting themselves administrative access. Threat actors leveraged this zero-day to seize complete control of vulnerable sites, install malicious content, and potentially exfiltrate sensitive data or deploy further attacks. Affected organizations risked significant operational disruption, data compromise, reputational harm, and potential compliance violations due to unauthorized admin creation and persistence. This incident highlights the increasing trend of exploiting supply-chain and plugin vulnerabilities in widely used CMS platforms. The rapid weaponization of unauthenticated privilege escalation flaws underscores the need for continuous patch management, threat detection, and segmentation controls to counter evolving web application and identity-focused attack techniques.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Exploited in the Wild: Microsoft’s Windows LNK Flaw Finally Patched After Years of Attacks
Impact· low
Exploited in the Wild: Microsoft’s Windows LNK Flaw Finally Patched After Years of Attacks

In November 2025, Microsoft silently patched CVE-2025-9491, a Windows Shortcut (LNK) file vulnerability, after years of active exploitation dating back to 2017. This flaw allowed threat actors to leverage malicious LNK files for privilege escalation and potential remote code execution through user interface misinterpretation. Attackers routinely embedded harmful LNKs in phishing emails or compromised archives, enabling them to bypass security controls and gain unauthorized access to targeted Windows systems. The issue was resolved only after mounting pressure from researchers and documented abuse by multiple attacker groups. This incident is notable as it underscores persistent risks from longstanding Windows flaws exploited in the wild. The continued abuse of LNK vulnerabilities highlights the importance for organizations to prioritize patching and segment internal networks to limit the blast radius of privilege escalation attacks.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical React Server Components Flaw Enables RCE in 2025—What You Need to Know
Impact· medium
Critical React Server Components Flaw Enables RCE in 2025—What You Need to Know

In December 2025, a maximum-severity vulnerability (CVE-2025-55182), codenamed React2shell, was uncovered in React Server Components (RSC), impacting platforms like React and Next.js. The flaw enables unauthenticated remote code execution (RCE) by exploiting how React decodes certain payloads sent to its server components. If left unpatched, attackers can execute arbitrary code on vulnerable servers, leading to full system compromise and severe business disruption. The incident highlights the critical impact of supply chain vulnerabilities in widely-used open-source frameworks and the elevated risk for businesses relying on modern web development stacks. The discovery of React2shell has triggered urgent patch advisories, as similar RCE vulnerabilities in web frameworks have seen rapid weaponization by threat actors. With increasing regulatory expectations for timely patch management and growing attacker focus on open-source component supply chains, this incident reinforces the need for continuous application security monitoring and robust SDLC controls.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Raptor Framework: AI-Powered Exploit and Patch Creation Disrupts Vulnerability Management
Impact· low
Raptor Framework: AI-Powered Exploit and Patch Creation Disrupts Vulnerability Management

In June 2024, security researchers publicly released the Raptor Framework, an open source AI-powered toolkit capable of autonomously generating both exploit code for software vulnerabilities and their corresponding security patches. Leveraging large language models (LLMs) and novel prompting techniques, the framework orchestrates agentic AI workflows to iterate, test, and refine functional exploit and remediation code at scale. While initially intended for defensive and research use, the dual-use nature of Raptor means malicious actors could similarly employ it to accelerate exploit development or enable broader, automated vulnerability discovery across cloud and on-prem environments. The release of the Raptor Framework highlights urgent concerns around weaponized AI and the rapid democratization of advanced cyber capabilities. Security leaders must act now, as similar agentic LLM tools could fuel faster attack cycles, strain patching processes, and escalate regulatory scrutiny around software security and responsible AI use.

7 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report

Security Research & Insights

Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
anthropic
OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Matt Snyder
Matt Snyder

Jul 31, 2026

12 min read
Read More
Attackers Learned to Use AI. Now They Built Tools to Destroy It.
ai attack
Attackers Learned to Use AI. Now They Built Tools to Destroy It.
Matt Snyder
Matt Snyder

Jul 21, 2026

12 min read
Read More
Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
ai-insider
Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Sachin Saurabh
Sachin Saurabh

Jul 07, 2026

14 min read
Read More

Market Perspectives

Market Perspectives offering expert commentary and select breach analysis from industry leaders

What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust
What Could Have Stopped the 2023 MGM Breach v4
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust
John Qian
John Qian

Jul 31, 2025

7 min read
Read More
HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
Tom Davis
Tom Davis

Jun 25, 2025

7 min read
Read More

How CNSF Protects Cloud Workloads

Cloud attackers don’t rely on a single exploit — they rely on paths.

Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.

Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

Utilize the Network Layer

With CNSF, enterprises can:

  • Contain attack paths at runtime

    Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.

  • Eliminate blind spots in workload-to-workload traffic

    Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.

  • Secure modern and AI-driven workloads

    Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.

  • Apply consistent Zero Trust controls without slowing teams

    Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.

See Your Attack Paths. Close the Gaps with CNSF.

Blast radius starts where your enforcement stops.

Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

The Executive Assistant That Broke the Company Why Shadow AI is the New Cloud Crisis card image

Your assessment delivers:

  • The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.

Containment Era Intelligence

The threat landscape has changed.
Has your question changed with it?

In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.

8
Tracked Campaigns
82%
Intrusions are malware-free
CrowdStrike GTR 2026
29 min
Avg. eCrime breakout time
CrowdStrike GTR 2026
27 sec
Fastest observed breakout
CrowdStrike GTR 2026

This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.

Contain the Blast Radius

See the attack paths already present in your environment — and where CNSF containment controls would break them.

Cta pattren Image