✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4021 to 4032 of 5292
How Iran's MuddyWater APT Used Memory-Only Malware for Stealthy Espionage in 2024
In early 2024, the Iranian state-backed actor MuddyWater significantly evolved its tradecraft by deploying a new memory-only loader, codenamed Fooder, and the stealthy 'MuddyViper' backdoor in espionage campaigns. The group, previously known for noisy operations, shifted to fileless malware and in-memory tactics targeting government and critical infrastructure networks in the Middle East and beyond. These attacks enabled extended persistence, facilitated lateral movement, and were effective at evading traditional endpoint detection and response solutions. As a result, targeted organizations faced serious risk of data theft and operational compromise before the campaign was exposed by security researchers. This incident marks a growing trend of threat actors adopting advanced memory-only and fileless TTPs to avoid detection. The operational upgrade by MuddyWater highlights increased sophistication among nation-state adversaries and reinforces the urgent need for advanced threat detection and stronger east-west network controls.
7 months ago
Kill Chain
CISA Flags OpenPLC ScadaBR Vulnerability Amid Active Exploitation in 2025
In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2021-26828, an unrestricted file upload vulnerability impacting OpenPLC ScadaBR systems, to its Known Exploited Vulnerabilities (KEV) catalog after evidence emerged of active exploitation. This vulnerability allows attackers to upload malicious files to vulnerable systems, potentially enabling remote code execution or complete system takeover. Threat actors have exploited this flaw as an entry vector to target operational technology (OT) and industrial control system (ICS) environments, posing a significant risk for both federal agencies and the private sector reliant on automation and SCADA networks. The incident highlights the persistent threat to critical infrastructure from unpatched software and the growing focus of attackers on OT/ICS vulnerabilities. With regulatory directives like CISA’s BOD 22-01 mandating urgent remediation, organizations face increasing accountability for securing their environments against rapidly evolving exploits.
7 months ago
Kill Chain
Salt Typhoon: Chinese APT Breaches U.S. Telecom Networks via Basic Vulnerabilities
In 2023, the Chinese state-sponsored threat group known as Salt Typhoon (a Microsoft designation) successfully compromised at least nine major U.S. telecommunications providers. Exploiting longstanding weaknesses—including unpatched vulnerabilities, weak passwords, and lack of multifactor authentication—attackers gained persistent network access and targeted high-level U.S. politicians, emergency service entities, and critical infrastructure. The intrusions, described by U.S. officials as unprecedented in scale, were undetected for a prolonged period and raised alarms about the broader security and resilience of telecom networks. This incident exemplifies the growing sophistication and persistence of nation-state cyber threats, especially against critical infrastructure sectors. It has spurred debate on regulation versus voluntary information sharing, highlighting urgent gaps in basic cyber hygiene and the systemic risk posed by failing to address widely known vulnerabilities.
7 months ago
Kill Chain
Clop Ransomware Hits University of Pennsylvania in Oracle EBS Supply Chain Attack
In August 2023, the University of Pennsylvania became one of nearly 100 organizations targeted in a sweeping data theft and extortion campaign by the Clop ransomware group. Exploiting previously unknown vulnerabilities in Oracle E-Business Suite (EBS), attackers gained unauthorized access to sensitive university systems over several days. Personal data, including names, Social Security numbers, and financial information, was exposed for thousands of individuals, primarily detected when Clop issued extortion demands and Oracle disclosed the vulnerability late September. Patch deployment followed, with no public evidence of further data misuse. The mass exploitation of Oracle EBS by Clop highlights a rising trend of sophisticated ransomware groups targeting widely used enterprise applications through zero-day attacks. This incident underscores renewed urgency for robust patch management, vigilant monitoring, and segmentation in response to evolving ransomware tactics and large-scale supply chain risks.
7 months ago
Kill Chain
University of Pennsylvania Data Breach Highlights ERP Security Risks in Higher Ed
In August 2024, the University of Pennsylvania confirmed that attackers infiltrated its Oracle E-Business Suite (EBS) systems, resulting in the theft of documents containing sensitive personal information. The breach, which was disclosed after internal investigations, leveraged vulnerabilities in Oracle EBS servers, a critical system for managing finances, supply chains, and human resources, enabling threat actors to compromise and exfiltrate sensitive employee and institutional data. Although the University has taken remediation steps and notified those affected, the attack underscores ongoing risks within higher education due to reliance on complex, legacy ERP platforms and the attractiveness of academic institutions as targets. This incident comes amidst a broader surge in attacks exploiting unpatched ERP systems, highlighting persistent gaps in internal segmentation and the monitoring of east-west traffic. As higher education faces increased regulatory and ransomware pressures, this breach serves as a warning of the urgent need for robust visibility, policy enforcement, and modernized security postures.
7 months ago
Kill Chain
Fake Calendly Invites Target Top Brands to Hijack Business Ad Accounts
In mid-2024, a sophisticated phishing campaign leveraged fake Calendly invitation emails to impersonate established brands such as Unilever, Disney, MasterCard, LVMH, and Uber. The attackers crafted convincing lures to target business users and administrators, aiming to harvest credentials for Google Workspace and Facebook Business accounts. Victims who clicked malicious links were redirected to lookalike phishing pages designed to steal login data, potentially enabling unauthorized access to digital ad campaigns, sensitive corporate data, and financial assets. The tactics combined brand impersonation, social engineering, and business workflow subversion, which heightened trust and success rates for attackers. This incident underscores the growing risks of identity-driven attacks that target business SaaS platforms, as cybercriminals increasingly exploit collaboration tools to penetrate defenses. Such phishing methods continue to evolve, challenging traditional detection and user awareness while putting critical business operations at risk.
7 months ago
Kill Chain
Google 2025 Android Zero-Day Attacks: Lessons on Mobile Vulnerability Exploitation
In December 2025, Google disclosed that it had patched 107 Android vulnerabilities, including two zero-day flaws exploited in active attacks. These zero-days, tracked as CVE-2025-23027 (privilege escalation in the System component) and CVE-2025-23028 (in the Kernel), were weaponized by threat actors to target select Android devices, likely via malicious apps or tailored exploits. Google's rapid response involved issuing security updates through its December Android Security Bulletin, minimizing the attack surface and urging device manufacturers and users to deploy patches immediately. The incident highlights the ongoing challenges of mobile platform security and the rapid exploitation of unknown flaws by attackers. This event is emblematic of the rise in advanced mobile vulnerability exploitation, where threat actors seek to bypass native OS security and target sensitive mobile endpoints. With the prevalence of bring-your-own-device (BYOD) policies and increasing mobile workforce reliance, timely patching and comprehensive visibility are more crucial than ever to defending against agile, targeted attackers.
7 months ago
Kill Chain
North Korea’s 2024 IT Identity Rental Scheme: Exposing New Supply Chain Dangers
In 2024, cyber intelligence researchers revealed an elaborate North Korean operation targeting engineers and developers worldwide, luring them to rent out their professional identities for conducting unauthorized IT work. North Korean recruiters posed as legitimate job seekers to obtain accounts, credentials, and background checks from unsuspecting professionals, allowing the nation's sanctioned regime to surreptitiously access western technology supply chains and funnel wages into banned state coffers. This campaign created significant risks, enabling North Korea to bypass sanctions, compromise corporate infrastructure, and mask the true origins of its IT contractors within the global tech workforce. This incident highlights a sophisticated continuation of supply-chain compromise methods leveraging social engineering and identity fraud. Recent months have shown a marked increase in similar schemes, illustrating attackers' growing reliance on exploiting human trust, remote work authentication gaps, and the globalized freelance IT marketplace.
7 months ago
Kill Chain
Cybercrime Goes SaaS: The Rise of Crime-as-a-Service in 2024
In early 2024, cybersecurity researchers observed a surge in Crime-as-a-Service (CaaS) operations leveraging a subscription-based model. Attackers now rent access to advanced phishing kits, infostealer logs, Remote Access Trojans (RATs), and one-time password bots on popular chat platforms like Telegram, dramatically lowering the barrier to entry for cybercrime. These CaaS platforms enable even low-skilled actors to execute sophisticated intrusion campaigns targeting organizations across industries, often resulting in credential theft, ransomware outbreaks, and large-scale data breaches. This operational shift has enabled attackers to strike at scale and adapt quickly to new defenses, amplifying business risks and potential regulatory violations. The rise of CaaS signifies a pivotal threat evolution: democratized, on-demand cybercrime. Organizations must now address not just known threat actors, but a growing pool of opportunists leveraging plug-and-play hacking tools. This trend is accelerating, leading to urgent pressures for improved identity controls, network segmentation, and rapid anomaly detection.
7 months ago
Kill Chain
Shai-Hulud 2.0: 2024 NPM Supply Chain Attack Exposes 400,000 Developer Secrets
In June 2024, the 'Shai-Hulud 2.0' campaign executed a large-scale supply chain attack against the JavaScript ecosystem by compromising over 750 packages on the NPM registry. Attackers used malicious dependencies to covertly exfiltrate environment variables and developer secrets to public GitHub repositories, exposing as many as 400,000 authentication credentials and tokens. The attack leveraged automation to rapidly disseminate malware and gather sensitive data from unwitting developers and CI systems, impacting thousands of organizations and potentially enabling downstream breaches. This incident underlines the growing risks of open-source supply chain vulnerabilities and highlights attacker innovation in automated credential harvesting. With supply chain attacks rising and developers relying on public package repositories, proactive controls and zero-trust practices have never been more essential to prevent code-integrity and data-exposure risks.
7 months ago
Kill Chain
Inside the 2024 Korea IP Camera Mass-Hack: A Wake-Up Call for IoT Security
In early 2024, South Korean authorities arrested four suspects for hacking into more than 120,000 IP cameras nationwide, exfiltrating sensitive video footage, and distributing it through a foreign adult website. Attackers exploited insecure and poorly configured IoT camera devices lacking adequate network segmentation or encrypted traffic, allowing for remote access and large-scale unauthorized surveillance. The breach exposed thousands of individuals to privacy violations and highlighted severe weaknesses in the deployment and security of IoT devices within residential and business environments. This incident underscores a rising trend of IoT device exploitation for privacy invasions, raising alarms globally about insufficient network protections and the urgency for robust segmentation, encrypted communications, and egress security policies as IoT adoption grows.
7 months ago
Kill Chain
Illuminate Education's 2021 Data Breach Spurs FTC-Driven Security Overhaul
In 2021, Illuminate Education, a major provider of educational software, suffered a significant data breach that exposed the personal information of approximately 10 million students across the United States. Attackers leveraged insufficient data security controls, including unencrypted data in transit and inadequate segmentation, to access sensitive data such as names, academic records, and demographic information. The breach led to widespread notification requirements and regulatory scrutiny from the Federal Trade Commission (FTC), highlighting critical security shortcomings and resulting in institutional reputational impact. This incident remains highly relevant as regulators continue to raise data protection standards, with the FTC mandating significant operational changes and data minimization from EdTech vendors. The breach underscores ongoing risks to student data in cloud environments and the heightened expectations for privacy safeguards, encryption, and Zero Trust policies.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

