✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4741 to 4752 of 5297
Critical Command Injection Flaw Found in TP-Link Omada Gateways (2024)
In June 2024, TP-Link disclosed a critical security vulnerability (CVE-2024-5035) affecting several Omada gateway models. The flaw is a pre-authentication operating system command injection that could allow remote, unauthenticated attackers to execute arbitrary commands on vulnerable devices, compromising the integrity and availability of network infrastructure. TP-Link quickly released firmware patches, urging customers to update immediately. This exposure heightened the risk of unauthorized access to internal networks, potentially leading to data breaches, lateral movement, or infrastructure disruption for organizations reliant on impacted Omada devices. The incident underscores an ongoing trend of targeting network infrastructure via supply chain or firmware vulnerabilities, which have become increasingly prevalent as attackers seek to exploit core networking hardware. This highlights the need for vigilant patch management and segmentation in defense strategies, as well as resilience against emerging firmware and gateway attacks.
7 months ago
Kill Chain
North Korean Hackers Employ EtherHiding for Unprecedented Cryptocurrency Heist
In October 2025, threat group UNC5342—attributed to North Korea—executed an advanced cryptocurrency theft operation by leveraging the novel EtherHiding technique. Attackers embedded malicious code within blockchain smart contracts to distribute malware, evading conventional detection mechanisms. Google Threat Intelligence Group (GTIG) identified this as the first known use of EtherHiding by a state-sponsored actor, resulting in the covert compromise of multiple cryptocurrency platforms and significant asset loss. The incident underscores an evolving trend: nation-state actors are adopting increasingly sophisticated blockchain-based attack methods. With rising blockchain adoption, such TTPs present serious risks for organizations involved in digital assets, regulation, and financial technology.
7 months ago
Kill Chain
Microsoft Revokes Fraudulent Certificates Exploited by Rhysida Ransomware in 2025 Campaign
In June 2025, Microsoft discovered and responded to a sophisticated campaign in which a threat actor known as Vanilla Tempest (also tracked as Storm-0785) fraudulently issued over 200 code-signing certificates. These certificates were leveraged to make malicious files appear legitimate, facilitating the distribution of a fake Microsoft Teams installer that ultimately delivered the Oyster backdoor and deployed Rhysida ransomware across targeted environments. Microsoft quickly moved to revoke all compromised certificates to mitigate the risk and prevent further exploitation by the attackers. The breach highlights the growing sophistication of ransomware groups in leveraging trusted supply chain components for malware delivery. This incident underscores the heightened threat landscape in which adversaries exploit trusted relationships and digital certificates to evade security controls. It also signals an increasing trend of ransomware utilizing living-off-the-land and supply chain abuse techniques, compounding challenges for organizations striving to maintain software integrity and regulatory compliance.
7 months ago
Kill Chain
Vidar Stealer 2.0: Infostealer Adopts Multi-threaded Data Theft & Evasion in 2024
In early 2024, the operators behind Vidar Stealer—a notorious malware-as-a-service (MaaS)—released version 2.0, introducing significant upgrades such as multi-threaded data theft and improved evasion techniques. Threat actors are leveraging this new version to accelerate theft of sensitive information, targeting both personal and enterprise environments by deploying the stealer via malicious emails, cracked software, and malvertising. The enhanced capabilities enable Vidar Stealer to exfiltrate data more efficiently and undermine traditional security controls, heightening the risks for organizations that rely on endpoint- or signature-based defenses. This evolution signals a broader trend in infostealer threats, where malware authors are quickly integrating advanced techniques for bypassing detection and maximizing operational speed. Enterprises should expect an uptick in automated, distribution-scale credential and data theft campaigns driven by increasingly sophisticated MaaS offerings like Vidar 2.0.
7 months ago
Kill Chain
Researchers Reveal Critical WatchGuard VPN Vulnerability Enabling Device Takeover
In October 2025, cybersecurity researchers disclosed a critical vulnerability (CVE-2025-9242, CVSS 9.3) in WatchGuard Fireware devices affecting OS versions 11.10.2 to 11.12.4_Update1 and 12.0. The flaw involved an out-of-bounds write in the VPN functionality, allowing unauthenticated remote attackers to execute arbitrary code. Attackers exploiting this bug could gain full control of affected appliances, potentially intercepting encrypted traffic, moving laterally within networks, or establishing persistent access. Patches were released urgently, but some organizations may remain exposed due to delayed patching or legacy hardware. This incident highlights ongoing attacker targeting of perimeter and VPN infrastructure. With rising reliance on remote access, vulnerabilities in widely deployed appliances continue to provide high-value entry vectors. Timely patching and layered network defenses are essential in light of increased regulatory scrutiny and sophisticated threat landscapes.
7 months ago
Kill Chain
North Korean APT Combines BeaverTail and OtterCookie in Major 2025 JS Malware Campaign
In October 2025, a North Korean state-sponsored hacking group with ties to the Contagious Interview campaign was observed integrating features from its BeaverTail and OtterCookie malware into a sophisticated new JavaScript-based attack. Security research from Cisco Talos revealed the group’s evolving approach: combining credential theft, evasion, and persistent access in targeted spear-phishing campaigns directed at global enterprises, which enabled stealthy lateral movement and prolonged network compromise. Analysis showed that this fusion malware increased the attackers’ efficiency and resilience, leading to significant data exposure risks and operational disruptions for affected organizations. This incident highlights a broader trend—North Korean APTs are rapidly developing multipurpose malware platforms capable of bypassing traditional defenses. The blending of well-established tools signals a new level of technical maturity, raising the urgency for organizations to shore up east-west traffic security, zero trust segmentation, and advanced threat detection controls.
7 months ago
Kill Chain
PassiveNeuron: Unraveling the 2024–2025 Advanced Persistent Attack on Global Servers
Between June 2024 and August 2025, the advanced persistent threat (APT) campaign codenamed "PassiveNeuron" targeted government, financial, and industrial organizations primarily across Asia, Africa, and Latin America. Attackers exploited SQL servers—likely leveraging vulnerabilities or credential brute-forcing—to gain initial access, followed by repeated attempts to deploy web shells. When thwarted by robust endpoint protections, the attackers escalated to advanced techniques, implementing a multi-stage DLL loader chain to deliver custom implants ('Neursite' and 'NeuralExecutor') and leveraging Cobalt Strike for lateral movement and persistence. These tools enabled sophisticated data gathering, process management, and network proxying, all while leveraging various encryption and obfuscation tactics to evade detection. This incident exemplifies the ongoing evolution of targeted cyberespionage against server infrastructure, with attribution leaning towards a Chinese-speaking threat actor based on tactics and C2 infrastructure, though with some ambiguity due to apparent false flags. It reflects a rise in multi-stage, stealthy attacks leveraging both custom and widely abused tools, highlighting the elevated risk posed to internet-exposed critical servers.
7 months ago
Kill Chain
2025’s Phishing Evolution: QR-PDFs, Calendar Attacks, and MFA Relay
In early 2025, organizations faced a surge of advanced phishing attacks leveraging revitalized and sophisticated tactics. Threat actors used emails with password-protected PDF attachments containing QR codes, evading traditional email security solutions and enticing users to open links via less-protected mobile devices. Calendar invitations embedding phishing links, voice message lures with CAPTCHA-guarded landing pages, and high-fidelity credential harvesting forms that relayed real MFA challenges in real-time all contributed to more successful credential thefts. These approaches eroded user trust in standard verification mechanisms and bypassed established detection methods, leading to increased account compromise risks and potential business disruptions. This shift signals a broader trend of attackers reusing and refining both traditional and novel phishing techniques, with rising use of multi-step evasion and identity-focused targeting. Enterprise email, cloud collaboration services, and end user authentication have become critical targets, driving new regulatory scrutiny and requirements for layered, adaptive defenses.
7 months ago
Kill Chain
Silver Fox Targets Japan & Malaysia: Winos 4.0 & HoldingHands RAT in Regional Cyber Attack
In October 2025, the Silver Fox cybercrime group broadened their Winos 4.0 (ValleyRAT) operations outside China and Taiwan by targeting organizations in Japan and Malaysia using the recently identified HoldingHands RAT (also called Gh0stBins). Attackers used phishing emails containing malicious PDFs with embedded links, leading recipients to unknowingly download and execute the remote access Trojan. Once deployed, the malware allowed unauthorized access and remote control over infected endpoints, posing significant threats to sensitive data and operational integrity for both public and private sector entities in the affected regions. This breach underscores the growing prevalence of multi-stage phishing attacks orchestrated by established threat actors, and highlights the transnational expansion of remote access trojan campaigns in Asia. The incident increases urgency for regional organizations to strengthen email security, endpoint defenses, and adopt zero-trust principles as attacker sophistication and geographic reach expand.
7 months ago
Kill Chain
New CAPI Backdoor Targets Russian Auto & E-Commerce with Phishing ZIPs
In October 2025, cybersecurity researchers uncovered a sophisticated phishing campaign targeting Russian automobile and e-commerce firms. The attackers distributed phishing emails containing malicious ZIP files, which, when opened, triggered the deployment of a never-before-seen .NET-based malware known as the CAPI Backdoor. Once installed, the malware established persistent access, enabling threat actors to conduct internal network reconnaissance, exfiltrate sensitive information, and potentially disrupt business operations. Seqrite Labs, who analyzed the activity, report that the campaign’s execution appears highly tailored to exploit Russia’s rapidly digitizing sectors. This incident is significant amid a sharp increase in spear phishing and backdoor campaigns against supply chain and commercial organizations across Eastern Europe. The novelty of the CAPI Backdoor highlights evolving attacker sophistication and amplifies regulatory attention around encrypted traffic inspection, zero trust, and rapid anomaly detection.
7 months ago
Kill Chain
Europol Busts Global SIM Farm Fueling Industrial-Scale Fake Accounts and Cybercrime
In October 2025, Europol led Operation SIMCARTEL to dismantle a sophisticated cybercrime-as-a-service (CaaS) organization running an extensive SIM farm network. This criminal service provisioned more than 49 million SIM cards to cybercriminals worldwide, enabling the rapid creation and management of fake online accounts. Threat actors leveraged the infrastructure for phishing campaigns, investment fraud, impersonation, and large-scale social engineering schemes, causing substantial financial and reputational harm to both individuals and businesses. The coordinated law enforcement operation involved 26 property searches, resulted in seven arrests, and the seizure of equipment and digital assets tied to the illicit platform. This incident highlights the growing industrialization of cybercrime, where turnkey services significantly lower the barrier to entry and accelerate threat actor operations. Law enforcement and the security industry face increasing challenges as cybercriminals exploit scalable CaaS platforms, requiring organizations to modernize their defenses and policy enforcement.
7 months ago
Kill Chain
NSA’s Multi-Tool Cyber Assault on Beijing’s National Time Service Center: Lessons for Critical Infrastructure
In October 2025, China's Ministry of State Security (MSS) accused the U.S. National Security Agency (NSA) of orchestrating a sophisticated, multi-stage cyberattack against the National Time Service Center (NTSC) in Beijing. The MSS claims that the NSA deployed at least 42 distinct cyber tools to penetrate critical national infrastructure, leveraging advanced techniques such as encrypted and east-west traffic manipulation, zero trust segmentation circumvention, and covert remote access. The compromise included strategic lateral movement and evasion of detection, reportedly leaving a significant impact on the operational integrity of NTSC, which serves as a reference point for the nation’s official timekeeping and scientific endeavors. This incident marks an escalation in cyber power projection between nation-states and spotlights the increasing use of multi-tool modular attack frameworks by advanced persistent threats (APTs). The breach underscores the urgency for critical infrastructure operators worldwide to reevaluate network segmentation, encrypted communications, and visibility gaps in light of evolving nation-state tactics.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

