✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4729 to 4740 of 5297
How Attackers Bypass Synced Passkeys: Lessons from the 2025 Incident
In October 2025, a significant security incident highlighted how attackers are bypassing synced passkey protections via adversary-in-the-middle (AiTM) techniques. Attackers exploited weaknesses in the synchronization of passkeys—where user credentials are stored in the cloud and synchronized across devices—to circumvent strong authentication requirements. By leveraging AiTM phishing kits and triggering fallback authentication flows, adversaries gained unauthorized access to enterprise accounts, exposing sensitive data and business operations. This vector sidesteps traditional multi-factor authentication and identity-first defenses, putting organizations reliant on passkey sync at risk. This incident demonstrates an urgent shift in attacker tactics toward abusing authentication recovery and synchronization flows that are increasingly common with passwordless deployments. As more businesses move to passkeys for convenience, the associated risks with synced secrets and recoveries have become a major security concern that demands new approaches and controls.
7 months ago
Kill Chain
VS Code Extension Access Token Leak: A 2025 Supply Chain Wake-Up Call
In October 2025, a major supply chain risk was exposed when over 100 Visual Studio Code (VS Code) extensions were found to have leaked access tokens, allowing threat actors to publish malicious updates to widely used extensions. Attackers who obtained these tokens could have distributed compromised software versions to millions of developers globally, undermining trust in open-source ecosystems and introducing the risk of code tampering, credential theft, or insertion of backdoors into organizational environments. The vulnerability lay in the mishandling and inadvertent leakage of personal access tokens (PATs) for both the VSCode Marketplace and Open VSX, giving adversaries an insidious update path into developer workstations and CI/CD pipelines. This incident highlights the increasing frequency and sophistication of supply chain attacks targeting developer tools and open-source dependencies. As the software landscape grows more interconnected, private access tokens and code-signing credentials now represent high-value targets, requiring robust security controls and zero trust validation across the development lifecycle.
7 months ago
Kill Chain
F5 Breach 2025: Nation-State Hackers Steal BIG-IP Source Code in Supply-Chain Attack
In October 2025, F5, a leading U.S. cybersecurity vendor, reported a significant breach attributed to a sophisticated nation-state threat actor. Attackers infiltrated F5's internal systems, gaining persistent access and exfiltrating files containing proprietary BIG-IP source code as well as details on undisclosed vulnerabilities. The breach underscores advanced adversary tactics, likely leveraging supply-chain vectors or unpatched entry points, with the attackers remaining undetected for an extended period. The exposure of source code and sensitive vulnerability information has significant security and operational implications for F5 customers and the wider ecosystem. This incident illustrates an escalating trend of nation-state-backed attacks targeting critical infrastructure vendors and supply chains. The F5 breach spotlights the urgent need for vigilant monitoring, robust threat detection, and transparent vulnerability management as attackers increasingly focus on extracting valuable code and intelligence from IT suppliers.
7 months ago
Kill Chain
Chinese APT 'Jewelbug' Compromises Russian IT Provider in Stealthy 2025 Attack
In early 2025, the Chinese state-linked threat group known as 'Jewelbug' stealthily infiltrated a prominent Russian IT service provider over a five-month period, according to findings from Symantec. The attackers gained initial access in January, likely leveraging supply chain or credential compromise vectors, and subsequently maintained persistent, undetected presence until May. Jewelbug is known for sophisticated tactics, including advanced lateral movement, encrypted traffic, and covert exfiltration. As a result, sensitive data and core IT systems within the provider’s infrastructure were at risk, potentially impacting downstream Russian clients who relied on its managed services. This incident highlights the expanding global reach of advanced persistent threats (APTs), with Jewelbug moving beyond historical targets in Southeast Asia and South America to now conduct espionage in Russia. The breach demonstrates increasing sophistication in supply chain and east-west attack techniques, underscoring urgent need for robust lateral movement prevention, segmentation, and cloud visibility controls.
7 months ago
Kill Chain
Adobe AEM 2025 Breach: CISA Flags Critical Application Flaw Under Active Attack
In June 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) raised alarms about a critical misconfiguration vulnerability (CVE-2025-54253) impacting Adobe Experience Manager (AEM). This flaw, assigned a CVSS score of 10.0, allows remote unauthenticated attackers to achieve arbitrary code execution on vulnerable AEM instances. Active exploitation was confirmed as attackers leveraged the bug to gain foothold, escalate privileges, and deploy malware on targeted organizations, potentially exposing sensitive data and compromising internal operations. The incident highlights the risks of unpatched enterprise software within digital supply chains and data-driven organizations. The AEM vulnerability is currently notable due to increased exploitation by multiple threat actors, coinciding with a larger trend of critical zero-day application flaws being used in advanced persistent attacks. Regulatory agencies and security experts underscore the urgency for patching exposed business applications given the frequency and sophistication of exploitation campaigns in 2025.
7 months ago
Kill Chain
Russian Hackers Evolve Malware via 'I am not a robot' Captchas in 2024
In early 2024, the Russian state-sponsored group Star Blizzard intensified its cyber-espionage operations, leveraging advanced malware strains (NoRobot, MaybeRobot) delivered via deceptive "I am not a robot" CAPTCHA prompts in targeted ClickFix phishing campaigns. Attackers executed multi-stage infection chains, enticing victims to enable malicious browser extensions or download trojanized payloads under the guise of legitimate productivity fixes. These campaigns enabled persistent access to sensitive organizational data, posed risks of lateral movement within networks, and facilitated exfiltration of proprietary intelligence. This incident underscores a concerning trend: the use of dynamic, highly-adaptive social engineering and malware delivery methods by state-backed actors. As similar tactics are increasingly observed across sectors, organizations must harden entry-point protections and improve internal visibility to counter evolving nation-state threats.
7 months ago
Kill Chain
Operation Zero Disco: APTs Weaponize Cisco SNMP Flaw to Deploy Linux Rootkits
In early October 2025, security researchers uncovered Operation Zero Disco, a targeted cyber campaign leveraging a stack overflow vulnerability (CVE-2025-20352) in Cisco IOS and IOS XE software. Advanced persistent threat (APT) actors weaponized this SNMP flaw to access legacy Cisco networking equipment, deploying covert Linux rootkits and securing long-term persistence on compromised devices. The exploitation enabled attackers to bypass standard defenses, facilitate lateral movement, and maintain undetected access to sensitive east-west network traffic, significantly increasing risk for organizations relying on outdated infrastructure. This incident highlights a growing trend of sophisticated actors exploiting unpatched or unsupported networking systems to achieve deep infrastructure compromise. With the resurgence of supply chain and infrastructure-based attacks, persistent network vulnerabilities demand heightened vigilance, rapid patch adoption, and robust segmentation. Industry-wide, there is mounting urgency to secure critical areas exposed by legacy systems and evolving attacker tactics.
7 months ago
Kill Chain
Pwn2Own Ireland 2025: Security Researchers Expose 34 Zero-Day Vulnerabilities
On the first day of Pwn2Own Ireland 2025, security researchers successfully exploited 34 unique zero-day vulnerabilities across a range of enterprise technologies, earning $522,500 in awards. The event, renowned for responsible disclosure and sponsored by leading vendors, demonstrated both the speed and sophistication with which zero-day flaws can be discovered and exploited in widely used software and hardware platforms. While no criminal group was involved (these are sanctioned research efforts), the findings underscore prevailing vulnerabilities in enterprise defenses and often result in rapid product updates and critical security advisories. This incident highlights the ongoing arms race between researchers and vendors to identify and remediate unknown security gaps. The large number of zero-days found in a single day signals both the growing complexity of attack surfaces and the pressing need for automated detection and proactive patching mechanisms across the digital ecosystem.
7 months ago
Kill Chain
Inside the LinkPro Linux Rootkit: eBPF Backdoors AWS Cloud in 2025
In October 2025, security researchers from Synacktiv revealed the discovery of LinkPro, a sophisticated GNU/Linux rootkit targeting AWS-hosted infrastructure. The attackers leveraged advanced eBPF techniques to install two modules: one for stealth, allowing the malware to evade detection, and another granting remote access via specially crafted TCP packets (magic packets). This backdoor enabled threat actors to persist undetected, hide their presence, and maintain control of compromised systems in cloud environments, posing severe risks to the underlying business operations and data confidentiality of affected organizations. This incident highlights the escalating use of kernel-level and cloud-specific attack techniques, exploiting eBPF to bypass traditional defenses. The campaign underscores a growing trend of attackers utilizing cloud-native technologies to achieve stealth and persistence, raising urgent concerns for CISOs overseeing both public cloud and Linux workloads.
7 months ago
Kill Chain
How UNC5142 Hijacked WordPress & Blockchain for Next-Gen Stealer Attacks (2025)
In October 2025, threat actor UNC5142 leveraged compromised WordPress sites to distribute a wave of information-stealing malware using an innovative attack method dubbed 'EtherHiding.' The adversaries abused blockchain-based smart contracts to conceal malicious code, enabling malware such as Atomic Stealer, Lumma, Rhadamanthys, and Vidar to infect both Windows and macOS endpoints. This technique allowed attackers to rapidly update payloads beyond the reach of static blocklists and frequently evade traditional security controls. Victims included a variety of enterprises and individuals, with attackers capitalizing on the popularity and trust of infected WordPress content management platforms. This incident highlights an emerging TTP where blockchain infrastructure is repurposed to enhance delivery persistence and obfuscation for criminal campaigns. The rapid uptake of such blockchain-based methods demonstrates the need for organizations to evolve threat detection and response strategies as attackers diversify beyond conventional web infrastructure.
7 months ago
Kill Chain
Cursor & Windsurf IDEs Hit by 94+ Chromium Vulnerabilities – Supply-Chain Exposure in 2024
In early 2024, security researchers identified that the latest releases of the Cursor and Windsurf integrated development environments (IDEs) were vulnerable to over 94 known and patched security vulnerabilities within the embedded Chromium browser and V8 JavaScript engine. These n-day vulnerabilities exist because the IDEs relied on outdated Chromium builds, exposing users to a range of critical issues, including remote code execution, privilege escalation, and data leakage. The supply-chain nature of the incident means development teams using these IDEs could inadvertently introduce risk across their entire workflow and environments. This incident underscores the persistent risk posed by vulnerable software dependencies and highlights an urgent need for improved supply-chain security. With attackers increasingly targeting development tools for initial access or lateral movement, organizations must re-evaluate their patch management, vendor risk assessments, and layered network protections.
7 months ago
Kill Chain
CISA Flags Oracle E-Business Suite SSRF Exploitation: What You Need to Know
In June 2024, the Cybersecurity and Infrastructure Security Agency (CISA) confirmed that threat actors exploited a critical Server-Side Request Forgery (SSRF) vulnerability, CVE-2025-61884, in Oracle E-Business Suite. Attackers leveraged this zero-day flaw to gain unauthorized access to internal systems, potentially allowing data exposure or further lateral movement within affected organizations. The vulnerability has since been added to CISA's Known Exploited Vulnerabilities catalog, highlighting active exploitation in the wild and prompting urgent remediation efforts across the private and public sectors. This incident underscores the growing trend of exploiting SSRF flaws in enterprise applications to bypass perimeter controls and facilitate initial access. Regulatory agencies globally are increasing pressure on vendors and businesses to patch critical application vulnerabilities rapidly as attacker sophistication and exploitation speed accelerate.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

