✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4405 to 4416 of 5296
LANDFALL Spyware: Exploiting CVE-2025-21042 Against Samsung Android Devices
In early 2025, the commercial-grade spyware known as LANDFALL was discovered targeting Samsung Android devices. Leveraging the newly identified CVE-2025-21042, attackers embedded the spyware in specially crafted malicious DNG image files. When unsuspecting users opened these images, the exploit chain compromised the underlying image processing library, granting attackers unauthorized access to device data, communications, and possibly real-time surveillance capabilities. This incident highlights yet another example of sophisticated supply chain exploitation aimed at high-value mobile assets, resulting in potential data exposure, loss of privacy, and reputational damage for affected organizations and individuals. LANDFALL’s attack chain signals an alarming new era for mobile threats, emphasizing the rapid weaponization of zero-days on widely deployed platforms. With growing regulatory scrutiny, businesses must closely examine mobile security controls and incident response readiness given the increasing complexity of modern spyware campaigns.
7 months ago
Kill Chain
SonicWall 2024 Cloud Backup Breach: Nation-State Attack Exposes Supply Chain Risks
In 2024, SonicWall disclosed a major supply-chain security incident where a state-sponsored threat actor exploited an API flaw to access the company's firewall cloud backup service. This breach, initially downplayed, resulted in the exposure and exfiltration of firewall configuration files for all customers leveraging SonicWall’s cloud backup. These files contained sensitive data such as firewall rules, encrypted credentials, and routing details, representing a significant risk for impacted organizations. An investigation by Mandiant confirmed the full scale of the compromise, though the specific country or threat group responsible remains undisclosed. This attack is especially relevant due to increasing targeting of security vendors and the potential for cascading risk across the customer base. The incident underscores persistent concerns over supply-chain vulnerabilities and the sophistication of nation-state actors focusing on critical infrastructure providers.
7 months ago
Kill Chain
Nation-State Breach Hits Congressional Budget Office: 2024 Lessons
In early June 2024, the Congressional Budget Office (CBO), a key federal agency supplying budget and economic analysis to Congress, experienced a cybersecurity breach by a suspected nation-state actor. Attackers reportedly infiltrated CBO systems and may have accessed sensitive communications between lawmakers and agency researchers. Upon discovery, CBO moved quickly to contain the incident, implemented additional monitoring, and strengthened security controls. The breach echoed previous attacks on congressional entities by sophisticated threat actors aiming to compromise confidential governmental data and influence legislative processes. This incident highlights increasing targeting of government research bodies by foreign espionage groups seeking sensitive intelligence. With agencies routinely handling politically sensitive and high-value data, robust cybersecurity defenses and rapid incident response are now critical amid heightened global threat actor activity.
7 months ago
Kill Chain
Sandworm Deploys Data Wipers in Sophisticated Attack on Ukraine’s Grain Sector
In early 2024, Russian state-backed threat actor Sandworm orchestrated a series of cyberattacks using multiple data-wiping malware families against Ukraine’s grain sector, education, and government organizations. These attacks involved deploying destructive wiper malware to erase data and disrupt critical operations, with the attackers leveraging lateral movement and advanced intrusion techniques to maximize impact. The campaign caused significant operational downtime, data loss, and posed a direct threat to Ukraine’s primary revenue source, severely impacting the grain production and export processes during a period of geopolitical tension. This incident reflects a trend of increased use of wiper malware in state-sponsored cyberwarfare, targeting national critical infrastructure. Organizations globally are urged to bolster their defenses, as these techniques are being replicated by other well-resourced threat actors beyond the Ukraine conflict.
7 months ago
Kill Chain
Cisco's 2024 Critical UCCX Flaw Exposes Root-Level Risks
In June 2024, Cisco disclosed a critical vulnerability (CVE-2024-20253) in its Unified Contact Center Express (UCCX) software, which could allow remote attackers to execute arbitrary commands with root privileges on affected systems. The flaw, which is due to improper validation of user-supplied input, does not require user authentication and is rated 9.9 out of 10 in severity. Malicious actors exploiting this vulnerability could gain full control over the underlying infrastructure, potentially leading to data breaches, service interruptions, or lateral movement within an organization's network. Cisco has issued security patches, and there are currently no reports of exploitation in the wild. The incident underscores the urgent need for prompt patch management and reinforces the trend of attackers rapidly leveraging zero-day and critical vulnerabilities in widely deployed enterprise platforms. Organizations must prioritize vulnerability management and maintain strict network segmentation to contain similar risks in their environments.
7 months ago
Kill Chain
ClickFix Evolves: Multi-OS Malware Delivered with Social Engineering and Video Tutorials
In early 2024, cybersecurity researchers observed a sharp evolution in the ClickFix malware campaign, which began targeting users with tailored multi-operating system payloads accompanied by step-by-step video tutorials to aid self-infection. The attackers employed social engineering by pressuring victims with countdown timers and offering clear, OS-specific instructions, effectively lowering the barrier for successful compromise. Leveraging these tactics, the malware operators could achieve widespread distribution, enabling credential theft and system control on both Windows and macOS platforms, and increasing risk of lateral movement across enterprise environments. This incident highlights a broader trend of combining technical innovation with advanced social engineering, making malware delivery easier and more efficient. The streamlined, multi-OS approach and use of multimedia content signal a significant shift in attacker tactics, accelerating the threat landscape and challenging traditional security awareness programs.
7 months ago
Kill Chain
SonicWall Cloud Backup Breach: How State-Sponsored Attackers Exploited API Weaknesses in 2025
In September 2025, SonicWall confirmed that state-sponsored threat actors orchestrated a security breach targeting its cloud backup environment. The attackers exploited an API vulnerability to gain unauthorized access to firewall configuration backup files stored in a specific cloud deployment. SonicWall's investigation determined the breach was limited to the exposure of these configuration files, with no evidence of lateral movement or impact to production systems. The breach prompted immediate containment actions, disclosure to affected customers, and a global review of cloud access controls and incident response procedures. This incident underscores the increasing risk posed by sophisticated, nation-state adversaries targeting cloud environments and API endpoints. It highlights how misconfigurations and insufficient segmentation in cloud infrastructure can facilitate data exposure, driving industry-wide reassessment of cloud-native security and compliance practices.
7 months ago
Kill Chain
Malicious AI Extension Sneaks onto VS Code Marketplace in Supply Chain Breach (2024)
In early June 2024, a malicious extension possessing rudimentary ransomware functionality, allegedly built with the aid of artificial intelligence, was discovered in Microsoft's Visual Studio Code (VS Code) Marketplace. The extension leveraged VS Code's trusted distribution to sneak past safeguards and, once installed, had the capability to encrypt targeted user files and demand a ransom. This supply chain attack was detected before it could be widely abused, but it highlights how adversaries are using AI to generate and deploy sophisticated threats within software ecosystems. This incident demonstrates a growing trend where supply chain platforms, such as code repositories and marketplaces, are exploited to gain privileged entry within developer environments. The blending of AI-enabled malware automation and trusted application channels raises urgent visibility, compliance, and policy enforcement concerns for organizations.
7 months ago
Kill Chain
How Ransomware Crippled Nevada State Agencies in 2025
In August 2025, the State of Nevada experienced a significant ransomware attack that disrupted the operations of over 60 state agencies, including those responsible for health and public safety. Attackers gained unauthorized access to internal systems, likely through a compromised credential or exposed remote access service. They rapidly deployed ransomware across the network, encrypting critical data and rendering multiple state services inaccessible while officials initiated emergency response protocols. The impact included delayed or suspended services for residents and a comprehensive recovery process lasting several weeks. This incident underscores a persistent trend: ransomware threat actors are increasingly targeting government entities, leveraging lateral movement and broad access to cripple essential public services. As attacks escalate and recovery costs rise, organizations face greater pressure to modernize segmentation, detection, and incident response strategies.
7 months ago
Kill Chain
Curly COMrades Weaponize Hyper-V: How Linux VMs Helped Evade Detection in 2025 Breach
In October 2025, the advanced persistent threat group Curly COMrades launched a sophisticated attack campaign exploiting Windows Hyper-V virtualization to evade endpoint detection and response (EDR) solutions. By covertly enabling Hyper-V on targeted systems, attackers deployed a minimal Alpine Linux-based virtual machine (VM) hidden within Windows hosts. This VM served as an isolated enclave to execute custom malware and facilitate command-and-control activities, significantly complicating detection and forensics for defenders. Victims experienced unauthorized data access and increased potential for lateral movement, while standard EDR tools failed to monitor the malicious payloads running inside the guest VM. This attack highlights a growing trend of leveraging virtualization and container technologies to bypass security controls. As organizations increasingly adopt hybrid and multi-cloud environments, adversaries are developing novel methods to mask malicious operations from traditional detection mechanisms, underscoring the need for advanced visibility and zero trust segmentation.
7 months ago
Kill Chain
Cisco Firewall DoS Attack: How CVE-2025-20333 & CVE-2025-20362 Disrupted Critical Networks
In November 2025, Cisco disclosed a vulnerability exploitation campaign targeting its Secure Firewall ASA and Threat Defense (FTD) devices. Threat actors actively weaponized two zero-day vulnerabilities, CVE-2025-20333 and CVE-2025-20362, to force vulnerable appliances to unexpectedly reload, resulting in denial-of-service (DoS) conditions that disrupted network operations. Affected organizations saw service disruptions, increased operational risk, and potential visibility gaps, especially where patch management or segmentation was lacking. Cisco responded by recommending immediate updates, enhanced monitoring, and deployment of compensating security controls until all devices are patched. This incident underscores a continuing trend of attackers rapidly exploiting unpatched firewall vulnerabilities, threatening the network perimeter’s reliability. The rise in sophisticated DoS tactics against infrastructure devices points to an urgent need for proactive patching, segmentation, and visibility into both perimeter and east-west traffic.
7 months ago
Kill Chain
Credential Stuffing at Scale: 2 Billion Email Addresses and 1.3 Billion Passwords Exposed in 2025
In late 2025, a massive credential stuffing incident came to light when nearly 2 billion email addresses and 1.3 billion unique passwords – sourced over years from various cybercriminal forums and compromised stealer logs – were aggregated and indexed by Synthient, then processed by Have I Been Pwned (HIBP) for user notification. The dataset included credentials from countless breaches, consolidated into one of the largest exposures of its kind to date. While the original leaks stemmed from malware infections, phishing, and prior breaches, the impact was compounded by password reuse and the easy redistribution of these records in the criminal underground. HIBP took technical and privacy-preserving steps to verify and notify affected users while preventing further risk of data linkage. This incident illustrates the ongoing risks posed by credential stuffing and highlights the long lifecycle of exposed data as threat actors continuously recycle and combine compromised information. The event underscores the importance of password hygiene, multi-factor authentication, and proactive notification as recycled data fuels ongoing cyberattacks across industries.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

