✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4825 to 4836 of 5297
Windows 10 End-of-Support: Patch Tuesday Signals Urgent Lifecycle Risk in 2025
In October 2025, Microsoft released KB5066791, the final mandatory Patch Tuesday update for Windows 10 as the operating system officially reached end-of-support status. This update addressed six zero-day vulnerabilities and 172 additional flaws. With free support and security updates discontinued, only customers enrolled in extended security updates (ESUs) are eligible for further patches. The shift leaves millions of endpoints—including in enterprise and consumer environments—potentially vulnerable to emerging threats targeting unpatched or unsupported Windows 10 systems as threat actors historically target end-of-life platforms for exploitation. The update also modified components like the Azure validation chain and removed outdated drivers, signaling a definitive end to mainstream security support. This event is particularly significant due to the accelerated exploitation trends observed following previous Microsoft OS end-of-life events. Attackers rapidly pivot to leverage newly found or previously unreported vulnerabilities, resulting in heightened lateral movement and potential compliance risks. Organizations must act swiftly to upgrade, implement segmentation, and enhance detection capabilities to avoid becoming easy targets.
7 months ago
Kill Chain
How Hacktivists Used Hashtags and DDoS to Disrupt in 2025
In early 2025, a surge in global hacktivist operations was observed, coordinated primarily via Telegram and X (formerly Twitter), with attackers leveraging hashtags to claim credit, issue threats, and organize campaigns. Over 120 hacktivist groups, originating in the MENA region but targeting organizations worldwide—including government, finance, and critical infrastructure—conducted highly visible DDoS attacks. These operations favored impact and propaganda over technical sophistication, resulting in significant service disruptions and reputational challenges for numerous victims, with attack announcements and proof frequently disseminated in near real-time. The campaign reflects a broader shift toward open, social-media-driven hacktivist tactics that often transcend regional geopolitics. As DDoS tools become more accessible and social platforms amplify coordination, all organizations—regardless of direct involvement in conflicts—face increased risk from ideologically motivated cyberattacks.
7 months ago
Kill Chain
Windows 11 Recall: New AI Feature Raises Alarming Data Security Concerns
In May 2025, security researchers highlighted significant privacy and security concerns in the Windows 11 Recall feature, an AI-powered function that automatically captures and stores screenshots and context of user activity. Although designed to enhance productivity by allowing seamless search and recall, the feature stores sensitive information—including potential credentials, private messages, and payment data—without robust controls or proven encryption. The built-in privacy filtering was found to be unreliable, enabling attackers or malware to leverage Recall’s artifacts to reconstruct user activity or exfiltrate high-value data. Because the Recall database is accessible without administrative privilege, organizations relying on default configurations could unintentionally expose critical information or face regulatory risks. This incident underscores the urgent need for organizations to review new operating system features before broad deployment, especially as attackers increasingly target post-compromise artifacts and AI-powered data collectors. High-profile attention to Recall has driven further debate on privacy standards and compliance, with heightened scrutiny from both regulators and security leaders.
7 months ago
Kill Chain
SolarWinds & MOVEit: The Wake-Up Call for Modern Supply Chain Cybersecurity
In recent years, a wave of major supply chain cyberattacks—most notably the SolarWinds compromise in 2020 and the MOVEit Transfer breach in 2023—have demonstrated how adversaries exploit trusted vendors to bypass defenses at scale. In the SolarWinds incident, attackers injected malicious code into the Orion software updates, leading to undetected access across 18,000 organizations, including government agencies and Fortune 500 companies. Just three years later, a zero-day vulnerability in MOVEit’s file transfer software enabled ransomware group Clop to exfiltrate and manipulate sensitive data from more than 2,000 global organizations, impacting over 62 million individuals. These incidents not only inflicted operational and reputational damage but also instigated regulatory and legal scrutiny, highlighting that even the most secure organizations remain vulnerable through third-party dependencies. Supply chain attacks now pose an elevated risk as threat actors increasingly target software providers, managed service firms, and widely used platforms to maximize reach and disruption. Rising regulatory expectations on supply chain oversight, combined with new TTPs like supply chain ransomware and identity abuse, solidify supply chain risk as a top boardroom and CISO concern.
7 months ago
Kill Chain
Fortra GoAnywhere MFT Breach: How CVE-2025-10035 Enabled a Major Ransomware Attack
In September 2025, Fortra disclosed that its GoAnywhere Managed File Transfer (MFT) platform suffered from a critical vulnerability (CVE-2025-10035) that was actively exploited by threat actors. Attackers leveraged this flaw—reportedly requiring a private cryptographic key, the origins of which are still unclear—to gain unauthorized access, moving laterally within cloud-based environments and exfiltrating data. Notably, Microsoft attributed ransomware intrusions and multi-stage attacks to a criminal group tracked as Storm-1175, leading to business disruptions and heightened risk for GoAnywhere users. Fortra responded by patching its services, investigating suspicious activity, and notifying affected customers, though questions remain regarding the root cause and extent of private key compromise. This incident highlights the growing risk of supply chain and third-party software vulnerabilities being exploited in ransomware campaigns. The exploitation of cryptography-dependent mechanisms signals an evolving sophistication among threat actors, pressing organizations to reconsider approaches to privileged cryptographic assets and drive urgency in patch management.
7 months ago
Kill Chain
Flax Typhoon Turns ArcGIS Features Into Espionage Backdoor: 2024 Breach Analysis
In early 2024, security researchers revealed that Chinese state-backed group Flax Typhoon covertly infiltrated ArcGIS server environments, maintaining backdoor access for over a year by exploiting legitimate software features. By compromising a backend administrator account, attackers deployed a malicious Server Object Extension (SOE) that blended with normal operations, enabling a persistent webshell and establishing a hidden workspace inaccessible to others. Critically, the attackers embedded their access into system backups, ensuring reinfection even after potential forensics or restoration activities. This sophisticated campaign allowed Flax Typhoon to spy on entities across the U.S., Europe, and Taiwan with minimal use of detectable malware. The incident demonstrates a significant shift towards using trusted enterprise software as an attack vector and reveals how recovery mechanisms like backups become liabilities if not properly verified. Similar living-off-the-land techniques are rising in frequency, challenging traditional security monitoring and incident response strategies.
7 months ago
Kill Chain
Harvard University Hit by Clop Ransomware Through Oracle Zero-Day Exploit in 2025
In October 2025, Harvard University disclosed an ongoing investigation into a cybersecurity breach linked to the exploitation of a zero-day vulnerability (CVE-2025-61882) in Oracle's E-Business Suite servers. The Clop ransomware gang claimed responsibility after adding Harvard to its data leak site, stating sensitive administrative data was stolen and threatening public release if ransom demands were not met. The attack was part of a broader campaign targeting Oracle E-Business Suite customers globally, exploiting the flaw for extortion and data theft. Harvard applied the vendor’s emergency patch upon notification and reported the breach as limited to a small administrative unit, with no signs of further compromise. This incident underscores the continuous risk universities and other organizations face from sophisticated ransomware groups leveraging zero-day exploits to bypass conventional defenses. The rapid exploitation of newly discovered vulnerabilities and subsequent data thefts reflect an ongoing shift towards extortion-focused campaigns targeting high-profile institutions and critical business systems.
7 months ago
Kill Chain
Oracle E-Business Suite 2025 Flaw Sparks Urgent Clop Ransomware Concerns
In October 2025, Oracle issued an emergency patch addressing CVE-2025-61884, a critical information disclosure vulnerability in its E-Business Suite (EBS) affecting versions 12.2.3 through 12.2.14. The flaw, present in the Runtime UI component, allowed unauthenticated attackers to remotely access sensitive business data, bypassing standard authentication mechanisms. The incident followed the discovery that threat actors—most notably the Clop ransomware group—had recently targeted Oracle EBS zero-days in extortion schemes against executives, leveraging vulnerabilities to facilitate large-scale data theft. Although Oracle has not confirmed active exploitation of CVE-2025-61884, the urgency of the patch highlights heightened threat actor interest and continued risk for organizations with unpatched, internet-facing EBS deployments. This incident underscores an alarming trend: criminal groups exploiting zero-day and recently patched vulnerabilities in widely used business applications for extortion and data theft. The rapid evolution of attacker tactics, combined with the continued exposure of critical SaaS and ERP platforms, raises the stakes for organizations to accelerate patching cycles and strengthen segmentation and threat detection strategies.
7 months ago
Kill Chain
SonicWall VPN Breach 2025: Credential Theft Sparks Widespread Compromise
In October 2025, a widespread cyberattack compromised more than 100 SonicWall SSLVPN accounts across 16 customer environments through the use of stolen, valid credentials. Researchers at Huntress observed the attackers rapidly authenticating into multiple accounts, with some sessions ending abruptly while others progressed to network reconnaissance and attempts at lateral movement by targeting local Windows accounts. The campaign began around October 4, 2025, with most attack traffic tracing back to a single IP address. Although there is no direct link to a previous breach involving SonicWall firewall configuration files, the incident underscores a substantial exposure risk to sensitive systems, business operations, and potentially regulatory compliance requirements. This incident highlights the evolving threat landscape, where credential compromise—not brute force—enables rapid, large-scale intrusions into VPN infrastructures. The continued prevalence of identity-driven attacks against remote access systems amplifies the urgency for enhanced credential hygiene, multi-factor authentication, and zero-trust access controls in the face of sophisticated adversaries.
7 months ago
Kill Chain
Massive Multi-Country Botnet Launches RDP Attacks Against US Organizations
In October 2025, a massive botnet composed of devices spanning over 100 countries launched coordinated attacks targeting Remote Desktop Protocol (RDP) services in the United States. Security researchers first spotted a spike in unusual RDP traffic originating from Brazil, with further malicious activity quickly spreading globally. Attackers leveraged two primary techniques: RD Web Access timing attacks to infer valid usernames, and RDP web client login enumeration to access accounts through analysis of server response behaviors. The campaign utilized over 100,000 unique IP addresses sharing a similar TCP fingerprint, indicating a highly organized cluster-based operation. The attacks put both government and enterprise systems at risk of brute-force intrusion and potential credential compromise. This incident underlines the persistent and evolving threat posed by botnets against remote access services. With increasing remote work reliance and exposed RDP endpoints, such sophisticated, multi-geography attacks exploit common authentication weaknesses and call for urgent upgrades in defense, including MFA and network segmentation.
7 months ago
Kill Chain
Microsoft 2025: Zero-Day Exploit Prompts Emergency IE Mode Restrictions
In October 2025, Microsoft announced urgent restrictions on Internet Explorer (IE) mode within the Edge browser following the discovery of active zero-day exploits targeting the Chakra JavaScript engine. Threat actors leveraged sophisticated social engineering tactics to lure users to spoofed sites, where a previously unknown vulnerability in Chakra enabled remote code execution. Attackers combined this with a privilege escalation flaw to escape the browser sandbox and seize complete device control. Microsoft responded by removing easy methods to activate IE mode in Edge for consumer users, instead requiring manual configuration limited to explicit, approved sites, and urged migration from legacy technologies. This incident underscores the persistent risks associated with maintaining legacy web compatibility features such as IE mode, especially as threat actors increasingly exploit these pathways with sophisticated chains of zero-day vulnerabilities and social engineering. It highlights heightened urgency for organizations to migrate from deprecated software and rigorously manage legacy access points.
7 months ago
Kill Chain
SimonMed Data Breach Exposes Over 1.2 Million Patient Records in 2024
In January 2024, SimonMed Imaging, a major U.S. provider of diagnostic medical imaging, disclosed a data breach impacting over 1.2 million patients. The incident involved unauthorized access to internal systems, which allowed attackers to exfiltrate sensitive health and personal information—including names, birthdates, contact information, health insurance and medical data. The breach was discovered during routine security monitoring, after which SimonMed implemented containment measures and engaged third-party forensics. Regulatory authorities and affected individuals were promptly notified, with the company offering support and identity protection services where relevant. This breach underscores the persistent targeting of healthcare organizations due to the high value of medical data, as well as regulatory scrutiny around the protection of patient information. It highlights the growing sophistication of data exfiltration tactics, emphasizing the critical need for robust east-west security controls, encrypted traffic, and rapid anomaly detection within healthcare IT environments.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

