✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4081 to 4092 of 5292
Crisis24 Shuts Down CodeRED Emergency System Following Ransomware Breach
In early June 2024, Crisis24 permanently shut down its OnSolve CodeRED emergency notification system after a ransomware attack severely damaged the platform's environment. The incident, attributed to the INC ransomware group, involved unauthorized access to and exfiltration of user data, including names, addresses, email addresses, phone numbers, and passwords. Forensic analysis indicated the attack was contained within the legacy CodeRED environment. The shutdown left dozens of municipalities and law enforcement agencies temporarily without emergency notification services, though the U.S. government's Emergency Alert System was unaffected. Crisis24 accelerated rollout of its new platform, conducted a security audit, and notified law enforcement. This breach underscores the increasing risk posed by ransomware groups targeting public safety infrastructure. With attackers leaking sensitive personal data and causing operational disruptions, organizations face mounting pressure to modernize legacy systems and enhance both incident response and segmentation controls in light of sophisticated, persistent threats.
7 months ago
Kill Chain
ASUS Issues Urgent Patch for Critical AiCloud Authentication Bypass Flaw in Routers
In June 2024, ASUS disclosed a critical authentication bypass vulnerability (CVE-2024-3080) affecting several router models running AiCloud. Attackers could exploit this flaw remotely, without authentication, to gain administrative access and potentially control router functions—enabling unauthorized changes, interception of network traffic, and further lateral movement within home or small business networks. The flaw was one of nine vulnerabilities addressed by an urgent firmware patch released by ASUS, after receiving responsible disclosure and industry warnings. Although there are no major reports of exploitation in the wild yet, affected users were strongly urged to update immediately to prevent potential compromise. This incident highlights the increasing targeting of network infrastructure and IoT devices by attackers seeking easy entry points into corporate and personal environments. With a surge in authentication bypasses and router-based exploits, organizations and individuals must prioritize timely patching and implement additional network segmentation and anomaly detection controls.
7 months ago
Kill Chain
Microsoft Hardens Entra ID Against Script Injection Attacks in 2026
In October 2026, Microsoft announced significant upgrades to the Entra ID authentication platform to address vulnerabilities exposed by script injection attacks targeting the sign-in process. Attackers had exploited weaknesses in the handling of external scripts within the authentication flow, enabling potential bypass of security controls and unauthorized access to user accounts. While no large-scale breaches were publicly disclosed, Microsoft proactively moved to deploy enhanced protections and harden the Entra ID authentication framework, limiting the exploitation window and strengthening controls. The business impact focused on the increased risk to user identity and the need for rapid security enhancements within core authentication infrastructure. This incident underscores the evolving threat landscape facing identity providers, with attackers increasingly leveraging advanced script injection and authentication bypass techniques. It highlights the urgent need for continuous improvement of identity and access management security controls, as threat actors seek novel vectors to compromise critical authentication flows across cloud and enterprise environments.
7 months ago
Kill Chain
Ransomware Attack Disrupts Multiple London Councils’ IT Systems in 2024
In June 2024, the Royal Borough of Kensington and Chelsea (RBKC) and Westminster City Council experienced operational disruption following a ransomware cyberattack on their shared IT provider, Westminster City Council Integrated IT (WCCIT). Attackers infiltrated municipal digital infrastructure, encrypted data, and impacted critical online services such as resident portals and payment processing. Public-facing platforms were taken offline as a precaution, and council operations shifted to manual workarounds, affecting both internal processes and citizen-facing services. The incident underscores the vulnerabilities within local government supply chains and highlights the ramifications of targeting shared service models in the public sector. This attack is a sobering reminder of the increasing incidence of ransomware campaigns targeting public entities in the UK and globally. With local authorities managing sensitive citizen data and critical services, the urgency for robust cybersecurity controls and incident response processes has never been more acute.
7 months ago
Kill Chain
Old Tech, New Headaches: How 2025’s NTLM Vulnerabilities Fueled Global APT Attacks
In 2025, a wave of advanced persistent threat campaigns exploited persistent vulnerabilities in Microsoft NTLM authentication, impacting organizations across Latin America, Russia, and Central Asia. Attackers such as BlindEagle and Head Mare leveraged newly disclosed Windows flaws (including CVE-2024-43451, CVE-2025-24054, and CVE-2025-33073) to harvest NTLM password hashes via crafted files and phishing emails, enabling credential theft, privilege escalation, and remote malware deployment. High-profile incidents included Remcos RAT and AveMaria Trojan infections following targeted spear-phishing, widespread lateral movement using pass-the-hash techniques, and the abuse of man-in-the-middle and reflection vulnerabilities to gain SYSTEM-level access. These incidents underscore the urgent risks posed by legacy protocols—despite announced NTLM deprecation, its widespread legacy use enables cybercriminals to refine credential relay and privilege escalation tactics. The ongoing threat highlights the necessity for rapid protocol retirement, proactive device auditing, regular patching, and adopting stronger authentication frameworks to defend against evolving identity-driven attacks.
7 months ago
Kill Chain
ShadowV2 Botnet Turns AWS Outage into Opportunity: 2024 IoT and Hybrid Cloud Attacks Surge
In June 2024, a new botnet malware known as ShadowV2 emerged, leveraging Mirai source code to target IoT devices, particularly from D-Link and TP-Link, exploiting known vulnerabilities for large-scale infection. Security researchers observed the malware operators using the widespread AWS outage as an opportunity to test command and control resilience, evade detection, and enhance lateral spread across hybrid and cloud networks. Initial access occurred via unpatched vulnerabilities in internet-facing devices, leading to rapid compromise and recruitment of thousands of endpoints, posing heightened risks to corporate and critical infrastructure systems. Detection was challenged by the use of encrypted and east-west traffic, with attackers adapting quickly to shifting network topologies. This incident highlights the increasing sophistication of IoT-focused botnets and their opportunistic exploitation of cloud service disruptions. Organizations with hybrid or cloud-connected assets are strongly urged to reassess east-west traffic controls, segmentation, and anomaly detection, as automated threats now more readily exploit both vulnerable devices and network instability.
7 months ago
Kill Chain
Comcast Fined After 2024 Vendor Data Breach Hits 270,000 Customers
In February 2024, Comcast, one of the largest U.S. telecommunications providers, suffered a significant data breach due to a third-party vendor's security lapse. The incident resulted in unauthorized access to the personally identifiable information (PII) of nearly 275,000 Comcast customers. Exposed data included names, addresses, and partial account credentials. The breach was traced to vulnerabilities in the vendor's security infrastructure, highlighting risks posed by supply chain and vendor relationships. Following the breach, the Federal Communications Commission fined Comcast $1.5 million as part of its investigation into the company's responsibilities and controls over customer data. This case underscores the persistent and growing threat of supply chain breaches, which are increasingly targeted by cyber adversaries seeking to exploit trust relationships between organizations and their service providers. Regulatory bodies are intensifying scrutiny and penalties around third-party risk management following a pattern of similar high-impact incidents.
7 months ago
Kill Chain
Signature Verification Bypass in node-forge Threatens Software Supply Chains (2024)
In early 2024, a critical security vulnerability (CVE-2024-33298) was discovered in the widely used JavaScript cryptography library 'node-forge'. This flaw allowed attackers to bypass digital signature verification by crafting malicious payloads that could appear as legitimately signed data, undermining the trust assumptions of applications and supply chains relying on the library. Once exploited, this vulnerability could allow threat actors to inject malicious code, escalate privileges, or compromise downstream systems with minimal detection, posing significant risks to organizations dependent on 'node-forge' for secure communications and validation workflows. The incident underscores the increasing prevalence and risk of supply-chain attacks in the software ecosystem. As more organizations depend on third-party open-source components for critical operations, vulnerabilities in widely adopted libraries have far-reaching implications for application security and regulatory compliance.
7 months ago
Kill Chain
FBI: $262M Lost to ATO Fraud as AI Phishing and Holiday Scams Surge in 2025
In late 2025, the FBI reported an alarming uptick in Account Takeover (ATO) fraud totaling over $262 million in losses. Cybercriminals, leveraging advanced AI-driven phishing tactics and holiday-themed scams, targeted individuals, businesses, and financial institutions with convincing impersonations to steal credentials and gain access to banking and sensitive accounts. Upon entry, attackers executed lateral movement, funds transfers, and data exfiltration, impacting organizations of all sizes and sectors by causing substantial financial loss, reputational harm, and regulatory scrutiny. This incident underscores an acceleration in AI-powered social engineering and the increasing sophistication of phishing campaigns, especially during high-activity periods like the holidays. Security teams now face heightened urgency to adapt with advanced detection, identity controls, and zero trust segmentation to address evolving threats using AI and automation.
7 months ago
Kill Chain
RomCom Exploits SocGholish Loader in U.S. Civil Engineering Breach
In June 2025, a U.S.-based civil engineering firm was targeted by the RomCom cybercriminal group leveraging the SocGholish JavaScript loader to deliver the advanced Mythic Agent malware. This marked the first known instance of RomCom using SocGholish for payload distribution. Attackers gained initial access through fake browser update lures hosted on compromised websites, allowing them to deploy the remote access trojan (RAT) and establish persistent control within the victim’s network. The attack resulted in exposure of sensitive engineering data and raised concerns regarding lateral movement and potential data exfiltration. This incident illustrates the ongoing trend of converging threat actor tactics, with attackers combining phishing, living-off-the-land tools, and stealthy malware loaders to increase their reach. As cybercriminal organizations diversify their infection vectors, organizations must swiftly adapt their detection and response strategies.
7 months ago
Kill Chain
Malicious Chrome Extension Diverts Solana in Raydium Swaps: Supply Chain Breach 2024
In May 2024, researchers identified a malicious Chrome extension named 'Crypto Copilot' that was surreptitiously injecting unauthorized Solana (SOL) transfer instructions during Raydium swap transactions, redirecting user assets to an attacker-controlled wallet. Initially published on the Chrome Web Store by a developer under the alias 'sjclark76,' the extension posed as a crypto utility tool but covertly modified transaction data to exfiltrate funds without user knowledge. The breach highlighted the growing risk of supply-chain malware within browser ecosystems and exposed users to direct financial theft via manipulated decentralized finance (DeFi) operations. This incident exemplifies a broader trend of attackers leveraging browser extensions to exploit DeFi and cryptocurrency users at scale. With the proliferation of novel supply-chain vectors and the rise of open-source and web-based crypto tools, organizations and individuals must exercise heightened due diligence and implement robust extension vetting and monitoring practices.
7 months ago
Kill Chain
Shai-Hulud v2 Strikes: Massive npm and Maven Supply Chain Breach Exposes Secrets
In November 2025, a major multi-ecosystem software supply chain attack was uncovered when the Shai-Hulud v2 campaign spread beyond the npm registry into Maven Central. Threat actors compromised over 830 npm packages and at least one Maven package (org.mvnpm:posthog-node:4.18.1), embedding malicious loaders and payloads that silently exfiltrated thousands of developer and organizational secrets. This attack leveraged highly automated techniques to inject stealthy code across registries, making mitigation and detection notably difficult. The campaign’s broad reach threatened applications, organizational infrastructure, and customers reliant on compromised components. This incident highlights a rising trend where sophisticated threat actors exploit trusted open-source software ecosystems, dramatically increasing supply chain risk. Recent surges in attacks targeting developer supply chains have prompted urgent calls for enhanced controls, continuous monitoring, stronger segmentation, and stricter compliance with software integrity standards.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

