✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4033 to 4044 of 5292
Google Fixes 107 Android Vulnerabilities, Including 2 Exploited in the Wild
In June 2025, Google released a critical Android security update addressing 107 vulnerabilities across multiple subsystems, including Framework, System, and third-party vendor components such as Arm, MediaTek, and Qualcomm. Notably, two high-severity Framework vulnerabilities had been exploited in the wild prior to the patch, allowing attackers to potentially bypass defenses, execute code, or gain unauthorized access on unpatched devices. Attackers leveraged these flaws to target unsuspecting Android users before Google issued its advisory and fix, putting millions of devices at risk until users updated their software. This incident highlights the ongoing risk posed by zero-day vulnerabilities in widely used mobile platforms and the rapidity with which sophisticated threat actors exploit unpatched systems. The urgency of timely patching is reinforced, as targeted attacks on mobile users remain an attractive vector for cybercriminals and APT groups alike.
7 months ago
Kill Chain
GlassWorm Returns: 2025 Supply Chain Attack on Developer Tool Extensions
In late 2025, the malicious campaign known as GlassWorm reemerged, infiltrating the Microsoft Visual Studio Marketplace and Open VSX with 24 rogue extensions disguised as legitimate developer tools such as Flutter, React, Tailwind, Vim, and Vue. By impersonating trusted tools, GlassWorm tricked developers into installing compromised extensions containing hidden payloads. Once embedded, these extensions established command-and-control communication over the Solana blockchain and enabled threat actors to perform code exfiltration, credential harvesting, and potentially insert backdoors into enterprise codebases, causing major risks for organizations leveraging these tools in their software supply chain. This incident underscores the ongoing and evolving risk of supply chain attacks targeting popular software development ecosystems. With developers as high-value targets, adversaries are increasingly sophisticated in exploiting marketplaces and open-source repositories to distribute malicious code, highlighting the urgent need for stronger validation, monitoring, and zero trust controls in software development lifecycles.
7 months ago
Kill Chain
Iranian APT Deploys MuddyViper Backdoor in Widespread Israeli Attacks (2025)
In late 2025, Iranian nation-state threat group MuddyWater launched a series of targeted cyberattacks against Israeli organizations spanning academia, engineering, local government, manufacturing, transportation, and utilities. Leveraging a newly identified malware backdoor dubbed MuddyViper, attackers infiltrated critical Israeli networks through spear-phishing and supply chain compromise, enabling persistent access and lateral movement across sensitive environments. The campaign was detected following unusual network activity and led to the exposure and disruption of operations, sparking concerns about the security of key national infrastructure. This incident highlights an ongoing evolution in APT tactics—particularly the development of custom malware for stealthy attacks on critical sectors tied to geopolitical tensions. The breach underscores the need for advanced detection, east-west traffic controls, and zero trust strategies to counter sophisticated nation-state actors.
7 months ago
Kill Chain
Malicious npm Package Outsmarts AI Security Tools in 2024 Supply Chain Breach
In February 2024, researchers identified a supply chain attack leveraging a malicious npm package named eslint-plugin-unicorn-ts-2, published under the guise of a TypeScript extension for ESLint by a user called "hamburgerisland." This package included hidden prompt injections and obfuscated scripts specifically designed to evade detection by AI-driven security scanners. Once integrated into a developer's project, it could execute unauthorized code, exfiltrate data, and potentially propagate laterally within developer environments. The attack highlighted how AI-oriented security tools can be manipulated through adversarial prompts and code concealment, putting countless downstream applications at risk in the dynamic JavaScript/Node.js ecosystem. The incident exemplifies sophisticated adversary adaptation, with attackers now actively engineering open-source supply chain threats to outsmart automated, AI-driven defenses. Organizations relying on package registries and automated code validation face urgent pressure to enhance both technical controls and threat intelligence around third-party dependencies.
7 months ago
Kill Chain
Lazarus APT’s Remote-Worker Ruse: How North Korean Hackers Infiltrated via Trusted IT Contractors
In late 2025, cybersecurity researchers from BCA LTD, NorthScan, and ANY.RUN captured an active infiltration by North Korea’s Lazarus Group (specifically the Famous Chollima division) leveraging remote IT workers implanted in Western organizations. This highly coordinated campaign used the appearance of legitimate remote workers—often hired via freelance and IT staffing platforms—to discreetly gain access to internal systems, exfiltrate sensitive data, and facilitate the deployment of malware directly through trusted accounts. The operation showcased sophisticated methods for circumventing east-west traffic controls and exploiting trusted relationships, posing a direct risk to organizations’ hybrid and cloud environments. This breach exemplifies the quick evolution of nation-state threat actors exploiting global remote work and cloud-native architectures. As the use of remote staff and contractors surges, organizations face mounting pressure to implement zero trust controls and granular segmentation to prevent well-resourced APTs from leveraging trusted credentials for deep access and stealthy lateral movement.
7 months ago
Kill Chain
CopyCop: Unmasking Russia's AI-Driven Disinformation Offensive in 2024
In early-to-mid 2024, cybersecurity researchers uncovered the extensive "CopyCop" campaign, a Russian-connected influence operation leveraging AI technologies to scale disinformation globally. The operation orchestrated over 300 AI-generated fake news sites mimicking legitimate Western media outlets, flooding North America, Europe, and other regions with fabricated stories and deepfakes targeting public perception about the conflict in Ukraine. CopyCop used self-hosted large language models to mass-produce convincing articles, fake fact-checkers, and synthetic visuals, eroding trust in authentic journalism and amplifying Kremlin narratives. The sophisticated use of generative AI and automation enabled unprecedented speed, reach, and content variability, evading traditional detection tactics and spreading misinformation at scale. This incident highlights an accelerating trend: threat actors and nation-state proxies are operationalizing generative AI for influence campaigns, making synthetic media and coordinated digital manipulation a top concern for governments, enterprises, and critical infrastructure organizations worldwide.
7 months ago
Kill Chain
CISA Flags Critical Android Framework Flaws in 2025: Urgent Action Required
In December 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two newly discovered Android Framework vulnerabilities—CVE-2025-48572 (Privilege Escalation) and CVE-2025-48633 (Information Disclosure)—to its Known Exploited Vulnerabilities Catalog. These flaws, which have already been actively exploited in the wild, allow malicious actors to escalate privileges and potentially access sensitive data on affected Android devices. The vulnerabilities create substantial risk, particularly for federal agencies and enterprises relying on Android in their operations, prompting CISA to mandate urgent remediation under Binding Operational Directive 22-01. This incident highlights the persistent targeting of mobile platforms and increased sophistication in privilege escalation techniques observed by threat actors. Organizations are urged to prioritize patching and reinforce security monitoring, as the exploitation of unpatched Android vulnerabilities continues to fuel regulatory and cyber risk concerns in both public and private sectors.
7 months ago
Kill Chain
Iskra iHUB 2025: Missing Authentication Exposes Critical Energy Infrastructure
In December 2025, a critical vulnerability (CVE-2025-13510) was disclosed for Iskra iHUB and iHUB Lite smart metering gateways, extensively used in the global energy sector. The devices exposed a web management interface lacking authentication, allowing remote attackers to reconfigure settings, update firmware, or manipulate connected systems without needing valid credentials. Reported by researcher Souvik Kandar and publicized by CISA, the issue affected all versions of these products, placing energy utilities at heightened risk. Successful exploitation could compromise grid operations, disrupt data collection, and enable broader attacks on critical infrastructure. This incident underscores the persistent risk of weak or missing authentication in industrial control systems amid heightened regulatory scrutiny. As similar vulnerabilities drive attacks on critical infrastructure worldwide, energy sector organizations must urgently reevaluate their security postures against remotely exploitable threats and adopt robust access controls in alignment with zero trust principles.
7 months ago
Kill Chain
Critical RCE Flaw in Industrial Video & Control Longwatch Threatens Global OT Networks
In December 2025, a critical remote code execution vulnerability (CVE-2025-13658) was discovered in Industrial Video & Control’s Longwatch systems (versions 6.309 to 6.334). An unauthenticated attacker could exploit a lack of access controls and code signing via an exposed HTTP endpoint, gaining SYSTEM-level privileges across vulnerable energy and water infrastructure deployments worldwide. This exploitation method requires minimal technical expertise and impacts operational technology (OT) integrity in sectors fundamental to public safety. This vulnerability exemplifies persistent gaps in OT device security and comes amid heightened global concerns around the security of essential infrastructure. With regulatory scrutiny and sophistication of attacker tactics increasing, organizations must urgently address privilege escalation routes and remote code execution exposures within their ICS/SCADA environments.
7 months ago
Kill Chain
CISA Unveils 2025 Critical ICS Vulnerabilities Affecting Industrial and Medical Sectors
In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released five separate advisories detailing multiple vulnerabilities discovered across widely deployed industrial control systems (ICS) products, including platforms from Industrial Video & Control, Iskra, Mirion Medical, and Mitsubishi Electric. These vulnerabilities range from improper authentication and unencrypted data flows to weak access controls and, if left unmitigated, could enable threat actors to compromise critical infrastructure, hijack remote operations, or disrupt medical and industrial processes. The affected organizations were notified, and remediation guidance was provided to reduce risk and limit exploitation by sophisticated actors. This disclosure underscores an ongoing trend of vulnerability discoveries in ICS environments, where legacy protocols, insufficient segmentation, and growing connectivity increasingly expose operational networks to targeted attacks. Continued disclosures by agencies like CISA emphasize the urgent need for robust visibility, segmentation, and zero trust architectures in protecting critical infrastructure.
7 months ago
Kill Chain
Mirion Medical 2025: Critical Vulnerabilities in NMIS BioDose Software Threaten Healthcare Security
In December 2025, Mirion Medical disclosed multiple high-severity vulnerabilities affecting its EC2 Software NMIS BioDose product, versions prior to 23.0. These flaws—incorrect permission assignments, use of hard-coded credentials, and client-side authentication weaknesses—could be exploited by attackers to gain unauthorized access, elevate privileges, manipulate executables, steal sensitive medical data, or execute arbitrary code. Impacting the healthcare and public health sectors globally, these vulnerabilities pose critical operational and patient-data risks, especially in environments with networked installations and exposed Microsoft SQL Server databases. No active exploitation has yet been reported, but CISA urges urgent mitigation measures due to the vulnerabilities’ remote exploitability and low attack complexity. This incident highlights intensifying regulatory scrutiny on medical device security as threat actors increasingly target healthcare systems for sensitive patient data and intellectual property. The vulnerabilities in Mirion’s product underscore persistent gaps in authentication and privilege controls—a growing concern amid adoption of connected medical technologies and regulatory frameworks such as HIPAA and NIST.
7 months ago
Kill Chain
Law Enforcement Dismantles Cryptomixer, Deals Major Blow to Ransomware Laundering Networks
In June 2024, a coalition of European law enforcement agencies successfully disrupted Cryptomixer, a cryptocurrency mixing service allegedly used to launder proceeds from ransomware and cybercrime. Authorities seized infrastructure and millions in digital assets linked to illicit transactions, following months of cross-border investigation and digital forensics. Cryptomixer was reportedly favored by ransomware groups to obfuscate the trail of stolen funds, complicating recovery efforts and hampering international financial tracking of illicit operations. This incident underscores the escalation of law enforcement action against cryptographic financial laundering tools, which remain instrumental to cybercriminal operations. Increasing scrutiny and regulatory collaboration highlight a growing intolerance for shadow financial ecosystems enabling ransomware and cyber extortion.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

