✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4333 to 4344 of 5296
SmartApeSG Leverages ClickFix Fake CAPTCHA Pages to Spread NetSupport RAT (2024)
In November 2024, the SmartApeSG campaign shifted tactics by leveraging ClickFix-style fake CAPTCHA pages to deliver the NetSupport RAT, a powerful remote access trojan. Threat actors compromised websites by injecting malicious scripts that, under specific conditions, displayed convincing 'verify you are human' prompts. Unsuspecting users, influenced by the fraudulent CAPTCHA, executed clipboard-injected commands that downloaded and ran NetSupport RAT on their Windows systems, establishing persistent access via Start Menu shortcuts. The campaign was notable for its adaptation and the regular rotation of malicious infrastructure. This incident highlights a rising trend of social engineering combined with hands-on-keyboard malware delivery. The use of fake CAPTCHA solutions is proliferating, making traditional email-filter and endpoint controls less effective. Organizations should be aware of evolving attack chains and regularly review user education programs to counter these sophisticated lures.
7 months ago
Kill Chain
Breakdown: 2024 FormBook Infostealer Delivered via Multi-Stage Script Obfuscation
In November 2024, a sophisticated email campaign delivered the FormBook infostealer via a series of obfuscated scripts. Attackers distributed malicious ZIP email attachments containing an obfuscated VBS file, which initiated multiple layers of PowerShell-based deobfuscation and payload retrieval. The staged infection successfully bypassed standard detection tools by employing complex anti-analysis techniques, eventually injecting FormBook into a legitimate process and establishing command and control through a remote server. Impacts included potential credential theft, session hijacking, and risk of lateral movement within affected organizations. This incident highlights the increasing use of multi-stage script-based delivery vectors and advanced obfuscation in commodity malware campaigns. Detection challenges are heightened as attackers combine legacy script formats and cloud hosting services to evade conventional endpoint security controls and deliver persistent infostealing payloads.
7 months ago
Kill Chain
OpenAI’s Sora 2 Release Fuels New Deepfake Security Risks in 2024
In late 2024, OpenAI released Sora 2, a powerful AI-powered video generation model, without the robust guardrails needed to prevent deepfake abuse. Within weeks, numerous instances emerged of Sora 2 being used to create convincing disinformation, impersonate public figures, and generate unmoderated content, despite minimal or easily removable watermarking. The lack of initial safeguards—such as restrictions on political figures or copyrighted content—and insufficient content provenance led to viral circulation of malicious deepfakes and nonconsensual depictions, raising significant operational, reputational, and regulatory risks for both OpenAI and affected individuals. This incident highlights a critical phase in AI/ML risk management: rapid technology advancement is outpacing the establishment and enforcement of ethical and technical controls. Growing regulatory and societal scrutiny underscores the need for defensible guardrails, provenance tracking, and collaborative risk governance to address the threats posed by generative AI deepfakes.
7 months ago
Kill Chain
Google Takes Legal Aim at Lighthouse Smishing Syndicate in 2024
In June 2024, Google initiated a civil lawsuit targeting the perpetrators of the 'Lighthouse' phishing-as-a-service operation, believed to be managed by individuals based in China. These actors used large-scale SMS phishing (smishing) campaigns, often spoofing Google and other trusted brands, to lure victims into divulging personal and financial information by clicking fraudulent links. Over a short period, the attackers deployed hundreds of thousands of fake sites and reportedly victimized more than one million people worldwide, resulting in significant financial losses and the compromise of millions of payment cards—primarily in the United States. The group’s abuse of Google’s trademarks also led the company to seek legal and technical disruption measures, including the removal of malicious domains. This case illustrates the growing impact and reach of phishing-as-a-service kits, which democratize sophisticated techniques for broader criminal use. The prevalence of smishing, coupled with international threat actor networks, reinforces the need for proactive legal and technical responses, as well as multi-stakeholder legislative and public awareness initiatives.
7 months ago
Kill Chain
Amazon Detects APT Group Exploiting Cisco & Citrix Zero-Days in 2024
In summer 2024, Amazon’s threat intelligence team identified that an advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (CVE-2025-20337) and Citrix NetScaler (CVE-2025-5777), months before official patches were released. The attackers leveraged custom malware with advanced evasion capabilities, demonstrating a deep understanding of enterprise Java and network edge products. Exploitation was detected as early as May, prior to vendor disclosure, allowing the threat actor prolonged access to target environments for likely espionage purposes. Massive exploitation attempts followed public disclosure, impacting thousands of organizations globally. This incident underscores the increased speed and sophistication with which threat groups are identifying and weaponizing zero-day vulnerabilities in critical network and identity infrastructure. The trend poses escalating risks for organizations relying on edge devices, making timely patching and layered defenses more crucial than ever.
7 months ago
Kill Chain
Operation Endgame 2024: Global Law Enforcement Strikes Down Major Malware Networks
In November 2024, a coalition of law enforcement agencies from 11 countries coordinated Operation Endgame, a major crackdown disrupting some of the most prolific malware networks globally. The operation targeted Rhadamanthys infostealer, VenomRAT remote access trojan, and the Elysium botnet—malware that collectively infected hundreds of thousands of computers and enabled the theft of millions of credentials. Authorities arrested the principal VenomRAT suspect in Greece, searched 11 sites across Europe, and dismantled more than 1,000 criminal servers and 20 illicit domains. With assistance from 30-plus cybersecurity companies, the operation also notified thousands of victims and exposed users of these illicit services, mitigating ongoing criminal campaigns. Operation Endgame underscores the rapidly evolving, cross-border nature of malware infrastructure and the growing need for coordinated responses by both public and private sectors. As attackers innovate and leverage distributed networks to evade law enforcement, regular collaborative enforcement actions and heightened detection capability are now critical to cybersecurity defenses worldwide.
7 months ago
Kill Chain
Rhadamanthys Infostealer Brought Down: Lessons from a Major Malware Disruption
In June 2024, law enforcement and security vendors successfully disrupted the Rhadamanthys infostealer operation, a prominent 'malware-as-a-service' offering used by cybercriminals to harvest sensitive data from infected devices. The takedown resulted in many malware operators reporting loss of access to their command-and-control servers, crippling active campaigns and rendering stolen data inaccessible. This disruption impacted both the malware's customers and the broader illicit ecosystem that depended on Rhadamanthys for credential theft, data exfiltration, and distribution of stolen information for financial gain. The incident highlights growing law enforcement coordination targeting infostealer infrastructure and criminal-as-a-service marketplaces. As infostealers proliferate with new evasion methods, their disruption remains a critical priority for organizations and defenders seeking to reduce exposure to credential theft and secondary breaches.
7 months ago
Kill Chain
Synnovis 2024 Ransomware Breach: UK Healthcare Services and Patient Data Exposed
In June 2024, Synnovis, a leading UK pathology services provider, suffered a significant ransomware attack that led to operational disruption and the exposure of sensitive patient data. The attack, attributed to Russian-speaking threat actor group Qilin, resulted in widespread IT outages across London hospitals, delaying critical healthcare procedures and temporarily halting diagnostic services. Investigations revealed that attackers were able to steal files containing patient information before encrypting core systems, underscoring the vulnerability of healthcare organizations to ransomware campaigns targeting their critical infrastructure. This incident is emblematic of a surge in highly targeted ransomware attacks against the healthcare sector globally. With a marked increase in double-extortion tactics and operationally disruptive attacks, this event highlights escalating cyber risk, increasing regulatory oversight, and the urgent need for robust cyber-resilience in healthcare.
7 months ago
Kill Chain
Citrix & Cisco Face 2025 Zero-Day Onslaught: Custom Malware Targets Network Cores
In early 2025, a sophisticated threat actor leveraged zero-day vulnerabilities—CVE-2025-5777 ('Citrix Bleed 2') in NetScaler ADC/Gateway and CVE-2025-20337 in Cisco Identity Services Engine (ISE)—to gain initial access into targeted enterprise environments. Exploiting these flaws before vendor patches were available, attackers deployed custom malware to establish persistent command-and-control and facilitate lateral movement, affecting sensitive east-west and outbound network traffic. The advanced nature of this attack enabled the evasion of traditional security controls, resulting in unauthorized access to confidential data and business operations disruptions. This breach highlights a critical evolution in adversary tradecraft: coordinated and simultaneous exploitation of zero-day flaws in widely deployed network infrastructure. With threat actors increasingly chaining vulnerabilities to maximize impact, proactive threat detection and effective segmentation are more essential than ever for organizations seeking resilience against such rapid exploitation campaigns.
7 months ago
Kill Chain
DanaBot Returns: Windows Banking Trojan Resurges After Global Takedown
In early 2024, the notorious DanaBot banking Trojan resurfaced after a six-month hiatus following major international law enforcement crackdowns under Operation Endgame in May 2023. This new version targets Windows systems through phishing campaigns, using malicious email attachments to gain initial access. Once deployed, DanaBot leverages modular capabilities for credential theft, lateral movement, and potential data exfiltration, threatening organizations and individuals with financial losses and malware proliferation. The resurgence highlights the continuously evolving tactics of threat actors in the financial malware ecosystem despite decisive takedown efforts. DanaBot's return signals the persistent threat posed by adaptive malware campaigns, with attackers quickly retooling to evade detection and capitalize on lapses in endpoint security. This incident stresses the importance of modern inbound threat detection measures and rapid response to evolving banking malware tactics.
7 months ago
Kill Chain
Google Sues to Dismantle Chinese 'Lighthouse' Phishing Platform Orchestrating US Toll Scams
In June 2024, Google filed a lawsuit to dismantle the 'Lighthouse' phishing-as-a-service (PhaaS) platform operated out of China. Lighthouse enabled global cybercriminals to launch large-scale SMS phishing campaigns, targeting U.S. residents by impersonating the U.S. Postal Service and E-ZPass toll systems. Attackers used automated infrastructure to send convincing text messages, directing victims to fraudulent sites designed to steal credit card and personal information. The campaign resulted in substantial financial losses for consumers and posed major operational risks to U.S. businesses and government agencies. This incident underscores the growing sophistication and accessibility of phishing-as-a-service offerings. With such turnkey solutions readily available on the dark web, attackers are able to scale campaigns with minimal technical skill, escalating both the frequency and severity of credential theft and fraud worldwide.
7 months ago
Kill Chain
2025 Microsoft Kernel Zero-Day: Privilege Escalation Risks & Response
In November 2025, Microsoft disclosed and patched 63 security flaws across its platforms, including a Windows Kernel zero-day vulnerability (CVE-2025-XXXX) that was exploited in the wild prior to the update. Attackers leveraged this privilege escalation flaw to gain elevated access on targeted devices, enabling them to bypass security controls, move laterally, and potentially deploy additional malicious payloads. While the majority of these vulnerabilities were rated as important, four—including the actively exploited zero-day—were rated critical, underlining the heightened risk for organizations that were slow to apply updates. The prompt response in releasing patches aimed to minimize further exploitation and potential operational disruptions for Microsoft enterprise customers globally. This incident highlights increasing attacker focus on privilege escalation flaws within widely-used platforms, particularly those with a large installed base like Windows. The ongoing exploitation of zero-days demonstrates the urgency of timely patch management, robust endpoint defenses, and threat detection as adversaries accelerate the weaponization of newly discovered vulnerabilities.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

