✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4777 to 4788 of 5297
F5 Supply Chain Breach 2025: China-Linked Attack Exposes Global BIG-IP Risk
In October 2025, F5 Networks disclosed a major cybersecurity incident involving a China-linked nation-state group (UNC5291) that gained unauthorized access to its infrastructure. Attackers reportedly maintained covert access for at least a year, stealing F5 BIG-IP source code and information on as-yet-undisclosed vulnerabilities. While F5 stated there’s no evidence of active exploitation of these flaws, the breach affects more than 266,000 exposed BIG-IP instances worldwide. The attackers leveraged advanced persistence techniques and deployed specialized malware, raising serious concerns about global supply chain integrity. This breach highlights the persistent targeting of critical infrastructure vendors by highly resourced nation-state actors. Government agencies and enterprises face heightened urgency as regulatory bodies issue emergency directives to patch devices, with compliance and operational risks elevated by the scale and sophistication of the attack.
7 months ago
Kill Chain
Microsoft Patches Highest-Severity ASP.NET Core Vulnerability in 2025
In October 2025, Microsoft patched CVE-2025-55315—the highest-severity vulnerability ever identified in ASP.NET Core. The flaw, found in the Kestrel web server, allowed authenticated attackers to perform HTTP request smuggling, enabling them to hijack user credentials, bypass security controls, and potentially carry out privilege escalation or injection attacks. The vulnerability exposed sensitive data, permitted internal malicious requests, and in certain scenarios, enabled attackers to compromise integrity and availability by altering server files or forcing crashes. Microsoft responded with urgent patches for multiple ASP.NET Core and Visual Studio versions. The urgency around this incident reflects a rising trend in the exploitation of critical web application vulnerabilities. Such flaws highlight the importance of prompt patch management and robust internal segmentation controls, as sophisticated attacks continue to target application-layer weaknesses for lateral movement and data exfiltration.
7 months ago
Kill Chain
Europol Busts Massive SIM-Box Cybercrime Network in 2025
In October 2025, Europol led a major operation codenamed 'SIMCARTEL' that dismantled an extensive SIM-box network servicing global cybercriminals. The illicit operation spanned multiple countries, employed 1,200 SIM-box devices and 40,000 SIM cards, and provided fake phone numbers for cybercrimes such as phishing, fraud, impersonation, and extortion. Two key websites, gogetsms.com and apisim.com, were seized. Authorities arrested seven suspects, confiscated servers and luxury assets, and froze significant cryptocurrency and bank funds. Investigators linked the service to at least 3,200 fraud cases and a direct financial loss exceeding €4.5 million, with indications the service was used to create over 49 million fraudulent online accounts. This incident underscores a growing trend in Cybercrime-as-a-Service, where sophisticated tools enable large-scale identity obfuscation and fraud. The takedown reflects mounting law enforcement pressure on criminal infrastructure rentals fueling online financial crime, highlighting urgent regulatory and security challenges for organizations reliant on voice and messaging account verification.
7 months ago
Kill Chain
Clop Breaches Envoy Air via Oracle EBS Zero-Day in 2025: Key Lessons in Ransomware Defense
In October 2025, Envoy Air, a regional subsidiary of American Airlines, confirmed that attackers compromised business information from its Oracle E-Business Suite (EBS) application. The Clop ransomware/extortion group exploited a newly discovered Oracle EBS zero-day (CVE-2025-61882) to access internal systems in August 2025. Upon discovery, Envoy initiated an investigation, notifying law enforcement and confirming that no sensitive customer or employee data was affected, though limited business and commercial contact details were exposed. This incident underscores the rising trend of ransomware and extortion groups leveraging zero-day vulnerabilities in key enterprise platforms. The Clop gang continues to target multiple industries through advanced attacks on widely used software, emphasizing the urgent need for robust patch management, east-west traffic security, and zero trust segmentation strategies.
7 months ago
Kill Chain
ConnectWise Automate 2025 Vulnerabilities: AiTM & Malicious Update Risks in the Supply Chain
In October 2025, ConnectWise disclosed and patched critical vulnerabilities in its Automate remote monitoring and management platform, widely used by managed service providers (MSPs) and enterprises. The most severe issue (CVE-2025-11492, CVSS 9.6) allowed agents to communicate sensitive information in cleartext over unencrypted HTTP, exposing them to adversary-in-the-middle (AiTM) attacks capable of intercepting or altering management traffic, including credentials and update payloads. A second flaw (CVE-2025-11493, CVSS 8.8) enabled attackers to bypass update integrity checks, facilitating the delivery of malicious software disguised as legitimate updates. Together, these vulnerabilities posed a significant supply chain threat, enabling network-based attackers to compromise customer environments via trusted management channels. This incident underscores the heightened attention on software supply chain vulnerabilities and AiTM risks, particularly among platforms entrusted with privileged access across thousands of customer endpoints. With adversaries increasingly exploiting weak encryption, incomplete update verification, and RMM tool supply chains, organizations must urgently strengthen controls around update validation, encrypted communications, and least privilege management to stay ahead of evolving attacker tactics.
7 months ago
Kill Chain
Critical Multi-Vendor Vulnerabilities Exploited in September 2025: Key Lessons for Zero Trust and Compliance
In September 2025, a wave of critical vulnerabilities across major vendors – including Cisco, TP-Link, Sitecore, and Adminer – were actively exploited by threat actors in high-impact campaigns. Attackers leveraged CVEs such as CVE-2025-20333 and CVE-2025-20362 in Cisco ASA devices to deploy advanced malware (RayInitiator and LINE VIPER), and exploited deserialization flaws in Sitecore (CVE-2025-53690) and Adminer SSRF (CVE-2021-21311) to enable data exfiltration, lateral movement, and persistent control. The vulnerabilities affected a diverse range of enterprise products and cloud platforms, enabling remote code execution and privilege escalation via sophisticated attack chains and, in some cases, public proof-of-concept exploits. This wide-ranging exploitation underscores the growing sophistication of attacker tradecraft and the urgent need for proactive, risk-driven vulnerability management. Given the increasing regulatory and operational impact of such incidents, organizations must prioritize patching, improve detection for abuse of critical CVEs, and strengthen security posture across hybrid environments.
7 months ago
Kill Chain
SEO Spam Surge: How Hidden Links Threaten Your Website's Reputation in 2025
In September 2025, numerous legitimate websites were compromised through the injection of hidden HTML blocks containing SEO spam links, primarily directing to pornographic and gambling domains. Attackers leveraged a variety of entry vectors, including exploited CMS vulnerabilities, compromised administrator credentials, outdated plugins, and insecure website templates, to insert invisible links that manipulated search engine rankings. The result was immediate: affected sites suffered sharp declines in search visibility, loss of reputation, visitor complaints, and in many cases, were misclassified as “Adult content” or “Gambling” by filtering systems. This exposed organizations to both operational and reputational damage, and in some circumstances, to regulatory or legal risks. The attack highlights an ongoing surge in web application compromise driven by automated tools and AI, accelerating the spread and sophistication of black hat SEO tactics. As search engines enhance their detection, attackers are turning to increasingly evasive techniques, stressing the urgent need for organizations to secure website platforms and adopt robust monitoring against such silent intrusions.
7 months ago
Kill Chain
NPM Supply Chain Attack Exposes AdaptixC2 Framework via https-proxy-utils (2025)
In October 2025, security researchers discovered a malicious npm package named 'https-proxy-utils' which surreptitiously delivered the AdaptixC2 post-exploitation framework. The package mimicked legitimate proxy utility modules—closely resembling widely used packages like 'http-proxy-agent' and 'https-proxy-agent'—and included a post-installation script designed to download and execute the AdaptixC2 agent based on the victim's operating system. Once deployed, the agent enabled attackers to access infected machines, execute commands, and establish persistence, resulting in potential internal reconnaissance, lateral movement, and elevated risk of data exfiltration for organizations inadvertently including the tainted module in their development pipeline. This incident is emblematic of a rising wave of supply-chain attacks targeting open-source software ecosystems. The use of trusted distribution channels to propagate sophisticated frameworks like AdaptixC2 highlights the necessity for increased scrutiny of third-party software and ongoing vigilance against impersonation tactics in popular package registries.
7 months ago
Kill Chain
Zendesk's 2025 Email Bomb: How Lax Authentication Led to Mass Inbox Floods
In October 2025, a campaign exploited insecure ticket creation configurations across hundreds of Zendesk customer accounts, allowing attackers to bombard target inboxes with thousands of emails by abusing anonymous support workflows. Attackers submitted forged support requests via vulnerable Zendesk setups that lacked mandatory user authentication; as a result, victim inboxes were flooded with email notifications that appeared to originate from major brands like NordVPN, The Washington Post, and Discord. This distributed email flood (email bomb) compromised brand integrity, overloaded recipient systems, and created significant disruption for both targeted individuals and the affected organizations, highlighting the dangers of misconfigured application authentication and notification systems. Incidents like this reflect a rising trend in application-layer abuse, where attackers exploit lenient platform defaults and automated workflow triggers to amplify malicious campaigns. As business reliance on cloud-based customer service solutions increases, proper authentication and anti-abuse controls have become critical to both user and organizational protection.
7 months ago
Kill Chain
Viral TikTok Malware Campaign Bypasses Security via Social Engineering and Infostealer
In October 2024, cyber attackers launched a widespread malware campaign on TikTok, leveraging viral videos that promised free software activations—such as Photoshop—to lure unsuspecting users. Victims were instructed to execute malicious PowerShell scripts, leading to the silent download of infostealers like AuroStealer and additional payloads that achieved persistence and utilized advanced in-memory code execution techniques. The highly effective social engineering exploited TikTok’s reach, spreading through multiple videos and targeting users seeking pirated software, resulting in significant risks of credential theft and further compromise. This attack exemplifies the growing trend of financially motivated threat actors exploiting popular social platforms for initial access. The use of self-compiling malware and in-memory shellcode injection reflects advanced tactics that bypass traditional security controls, highlighting the urgent need for robust endpoint protection, increased security awareness, and stricter monitoring of social media for malicious content.
7 months ago
Kill Chain
F5 Breach 2024: Nation-State Actors Steal Source Code and Vulnerabilities
In early 2024, F5 Networks suffered a significant security breach attributed to a sophisticated nation-state actor, which resulted in the theft of BIG-IP source code and undisclosed vulnerability details. The attackers leveraged targeted intrusion tactics, exploiting gaps in F5's internal protections to gain access to proprietary codebases and sensitive vulnerability information. This breach elevated the risk for F5’s enterprise and government customers, as the exposed vulnerabilities could facilitate future attacks on critical infrastructure globally. The incident highlights both supply chain implications and the heightened impact of intellectual property theft. This attack underscores a strategic shift where advanced threat actors seek not only data but also exploit software supply chains and zero-day vulnerabilities, raising urgent concerns for organizations dependent on key network infrastructure vendors. With regulatory scrutiny sharpening around supply chain risk and software assurance, incidents like this set new urgency for proactive defense and vendor risk management.
7 months ago
Kill Chain
Satellite Communications Exposed: 2025’s Unencrypted Data Crisis
In mid-2025, a landmark study revealed that a vast portion of global geostationary satellite communications—including critical infrastructure, government, corporate, and consumer data—are transmitted unencrypted. Security researchers, using inexpensive commercially available satellite equipment, intercepted highly sensitive transmissions such as internal communications, private calls and SMS, and in-flight internet traffic. Because thousands of geostationary transponders broadcast across enormous geographic areas, these unprotected signals can be passively accessed by unauthorized parties from virtually anywhere within satellite coverage zones, putting confidential data at significant risk of interception and exploitation. This incident underscores a persistent and growing concern regarding the lack of robust encryption in satellite communications, even as regulations and cyber threats evolve rapidly. Increasing satellite connectivity for aviation, maritime, and remote access drives urgency around encryption, as adversaries and data brokers exploit these vulnerabilities on a global scale.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

