✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4513 to 4524 of 5296
Russian Authorities Dismantle Meduza Stealer Malware Group After Major Data Thefts (2024)
In June 2024, Russian law enforcement authorities arrested three alleged administrators behind the Meduza Stealer information-stealing malware in Moscow. The operation was part of a wider investigation following attacks on Russian organizations by the threat actor group, who distributed Meduza Stealer via phishing campaigns and illicit online forums. The malware targeted sensitive credentials, browser data, and cryptocurrency wallets, which were then exfiltrated to attacker-controlled servers. The arrests are expected to significantly disrupt the group’s operations and potentially curb related cybercriminal activity in the region. The Meduza Stealer case underscores the global proliferation of credential-stealing malware and highlights growing law enforcement action against cybercrime groups. With similar infostealer campaigns on the rise and rapid threat actor adaptation, organizations must prioritize endpoint protection and user awareness to stay ahead of evolving tactics.
7 months ago
Kill Chain
University of Pennsylvania 2024 Email Account Compromise: Lessons for Higher Ed
In June 2024, the University of Pennsylvania experienced a cybersecurity incident involving unauthorized access to internal email accounts. Students and alumni received a series of offensive emails from compromised university email addresses, with messages claiming data had been stolen in a security breach. Attackers leveraged email compromise, impersonating trusted university entities, and threatened to leak sensitive data, causing significant alarm among recipients. The university responded swiftly by investigating the breach, working with law enforcement, and reassuring the community that containment efforts were underway. This incident underscores the ongoing threat of email compromise and phishing-driven data breaches within higher education. With educational institutions facing increased attacks targeting both user trust and sensitive information, this event highlights the urgent need for robust email security, lateral movement detection, and strategic incident response planning.
7 months ago
Kill Chain
CISA Flags China-Linked APT Exploitation of VMware Zero-Day (CVE-2025-41244)
In October 2025, a critical zero-day vulnerability, CVE-2025-41244, affecting VMware Aria Operations and VMware Tools was actively exploited by a China-linked Advanced Persistent Threat (APT) group. The attackers leveraged this flaw to achieve remote code execution within enterprise environments, bypassing authentication on exposed VMware instances. Initial access was typically gained via internet-facing management interfaces, followed by lateral movement to access sensitive data and systems. The incident prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the rapid operational impact and the potential for widespread compromise in cloud and hybrid infrastructures. This breach exemplifies the ongoing risk posed by state-sponsored actors exploiting enterprise software supply chain gaps and underscores the need for rigorous patch management and segmentation. Organizations face renewed urgency as attackers increasingly focus on high-value cloud platforms, driving heightened regulatory scrutiny and reinforcing the importance of visibility and agility in security operations.
7 months ago
Kill Chain
Eclipse Foundation Supply Chain Risk: Open VSX Token Exposure Sparks Security Response
In June 2025, the Eclipse Foundation, custodians of the Open VSX open-source project, took immediate remedial action after Wiz security researchers reported that authentication tokens had been unintentionally leaked in several Visual Studio Code (VS Code) extensions across official marketplaces. These exposed tokens could have allowed malicious actors to tamper with extensions, inject malicious code, or compromise downstream developer environments. Upon validation, the Eclipse Foundation promptly revoked a limited set of impacted tokens and notified affected extension maintainers, mitigating potential risks before evidence of active exploitation surfaced. This event underscores the inherent risks in software supply chains, particularly in widely-used open-source development tools. Software supply chain vulnerabilities remain a top concern for enterprises as development workflows increasingly depend on publicly distributed packages and extensions. The growing adoption of open-source ecosystems means that even small credential leaks can impact thousands of users, driving new urgency for continuous monitoring and proactive threat detection.
7 months ago
Kill Chain
CISA and NSA Warn: Immediate Action Required to Harden Exchange & WSUS – 2025 Global Security Advisory
In October 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA), together with Australian and Canadian cyber authorities, issued urgent joint guidance to mitigate widespread exploitation risks targeting on-premises Microsoft Exchange Server and Windows Server Update Services (WSUS) deployments. These critical advisories arise after recent campaigns revealed how sophisticated threat actors leveraged open administrative interfaces and inadequate authentication to gain persistence, move laterally, and exfiltrate sensitive data from unpatched systems. Organizations globally are at risk of business disruption and potential regulatory violation from ensuing breaches. This new wave of advisories underscores the persistent targeting of core enterprise infrastructure by nation-state and criminal groups. The trend toward exploiting unencrypted data in transit, identity and access misconfigurations, and patching gaps makes immediate action essential for IT and security leaders, especially with regulatory scrutiny and ransomware risk at all-time highs.
7 months ago
Kill Chain
China-Linked APT Exploits Windows Shortcut Flaw in 2025 to Breach EU Diplomats
In late 2025, the China-linked threat group UNC6384 orchestrated a targeted cyber espionage campaign against European diplomatic and government institutions. Utilizing a previously unpatched Windows shortcut (LNK) vulnerability, attackers delivered malicious payloads to compromise systems in Hungary, Belgium, Italy, the Netherlands, and Serbia. The group specialized in stealthy lateral movement, data collection, and command-and-control operations while evading standard defenses. As a result, sensitive government data and communications were potentially exposed, undermining national security and international collaboration efforts. This incident underscores the growing sophistication of state-sponsored cyberattacks, intensified by the exploitation of zero-day vulnerabilities and advanced lateral movement techniques. The frequent targeting of government and diplomatic organizations shows a continued evolution in APT tactics and a rising threat to global critical infrastructure.
7 months ago
Kill Chain
2025 Lanscope Zero-Day: Tick APT’s Attack on Corporate Systems
In October 2025, the cyber espionage group Tick (also known as Bronze Butler), believed to be linked to China, exploited CVE-2025-61932—a critical zero-day vulnerability (CVSS 9.3) affecting Motex Lanscope Endpoint Manager. The attackers gained remote SYSTEM-level access to targeted on-premise environments, allowing them to hijack corporate systems and exfiltrate sensitive data. The attack chain involved leveraging the flaw for command execution, facilitating lateral movement and persistence within victim organizations, primarily impacting Japanese and East Asian enterprises. Authorities issued advisory alerts urging immediate remediation to prevent data loss and further intrusions. This incident underscores the growing operational risk posed by nation-state actors exploiting enterprise endpoint vulnerabilities. It highlights an escalation in zero-day weaponization and reinforces the need for robust segmentation, endpoint monitoring, and proactive patch management amid intensifying APT activity and regulatory scrutiny.
7 months ago
Kill Chain
Airstalk Malware: 2025 Nation-State Supply Chain Attack Hits Mobile Device Ecosystems
In October 2025, a suspected nation-state threat actor, tracked as CL-STA-1009, orchestrated a sophisticated supply chain attack involving the novel 'Airstalk' malware. Investigations by Palo Alto Networks Unit 42 revealed that Airstalk exploited the AirWatch mobile device management (MDM) API to gain unauthorized access to victim organizations' internal networks. This enabled adversaries to compromise large numbers of mobile devices, bypass network controls, and pivot laterally within affected systems, causing operational disruption and data loss. The primary targets were organizations with complex supply chains, where the attackers injected malicious code via trusted software providers, highlighting the vulnerabilities inherent in interconnected IT ecosystems. This incident is especially relevant as supply chain attacks become increasingly prevalent, with attackers leveraging trusted third-party relationships to bypass traditional network defenses. Nation-state actors' use of advanced evasion techniques and MDM abuse underscores the need for enhanced visibility, segmentation, and threat detection across distributed and hybrid IT environments.
7 months ago
Kill Chain
LotL Malware Concealed in Windows Native AI Stack Exposes New Risks
In early 2024, security researchers uncovered a Living-off-the-Land (LotL) attack that leveraged Windows' native AI stack to conceal and deploy malware within trusted AI data files. Attackers exploited the inherent trust that many Windows systems grant to files used by the native AI stack, allowing the threat to bypass traditional detection methods. The malicious payloads used fileless techniques, hiding in AI models and exploiting automated processing pipelines to achieve stealthy initial access and lateral movement. The campaign resulted in significant risks of unauthorized access, data theft, and potential disruption to business operations reliant on AI-driven processes. This incident is a timely reminder of evolving threat tactics using fileless malware and trusted native components. As the adoption of AI and automation accelerates, attackers are adapting by targeting supply chains and leveraging trusted AI data flows to bypass security controls and compliance frameworks.
7 months ago
Kill Chain
Claroty Authentication Bypass Threatens OT Security in 2025
In early 2025, a critical vulnerability tracked as CVE-2025-54603 was discovered in Claroty’s industrial cybersecurity products, exposing operational technology (OT) networks and critical infrastructure to potential attacks and data theft. The flaw allowed threat actors to bypass authentication mechanisms, granting unauthorized access to sensitive network segments. Attackers leveraging this security gap could disrupt essential services, compromise confidential process data, and pose significant operational and safety risks. Claroty responded by issuing urgent patches to contain the exposure and mitigate ongoing threats. This incident highlights the increasing risk of authentication bypass exploits in OT environments, as threat actors target weak points in security architectures to gain privileged access. The event underscores an urgent need for robust, zero trust security frameworks and rapid vulnerability management in critical infrastructure sectors.
7 months ago
Kill Chain
2024 Smart Building Zero-Day: Global Infrastructure Exposed
In early 2024, cybersecurity researcher Gjoko Krstic uncovered hundreds of zero-day vulnerabilities within legacy building automation systems still widely deployed in hospitals, schools, and commercial facilities globally. The investigation, codenamed "Project Brainfog," revealed that outdated codebases, some as old as 18 years, exposed critical physical infrastructure to remote compromise by unauthenticated attackers. Exploitable weaknesses in authentication, encryption, and access controls allowed for the manipulation of HVAC, security, and energy systems, putting sensitive environments such as medical and educational facilities at operational risk, and making them potential targets for ransomware and espionage. This incident highlights the growing threat of unpatched operational technology in critical sectors, as attackers increasingly target IoT and building control systems for both sabotage and lateral movement. As digital-physical convergence accelerates, organizations must rapidly modernize and secure these legacy environments to mitigate cascading risks.
7 months ago
Kill Chain
When AI Agents Go Rogue: The Risk of Session Smuggling in Agent2Agent Systems
In early 2024, cybersecurity researchers uncovered a novel vulnerability in agent-to-agent (A2A) AI systems, termed 'Agent Session Smuggling.' The attack allowed malicious actors to hijack sessions between AI agents, abusing trust relationships and manipulating agent behavior. Attackers leveraged weaknesses in session authentication and input validation, circumventing security controls to inject unauthorized commands and siphon sensitive data. Demonstrated through proof of concept, the exploit posed risks to organizations deploying sophisticated autonomous AI workflows and threatened the integrity of operational and business data. This incident highlights a rapidly emerging class of AI/ML security threats, where attacks exploit autonomous system intercommunication. As organizations accelerate AI adoption, understanding and mitigating these exploit techniques—especially in east-west, agent-driven environments—has become a pressing priority for security and compliance teams globally.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

