✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4897 to 4908 of 5297
Microsoft 2025: Storm-1175 Exploits GoAnywhere Zero-Day for Devastating Ransomware Attacks
In September 2025, a cybercrime group tracked as Storm-1175 exploited a critical zero-day deserialization vulnerability (CVE-2025-10035) in Fortra's GoAnywhere Managed File Transfer (MFT) solution. The attackers gained initial access by remotely targeting vulnerable MFT instances and leveraged remote monitoring tools (SimpleHelp, MeshAgent) for persistence. Subsequently, they conducted network reconnaissance with Netscan, moved laterally using Microsoft RDP, exfiltrated sensitive data with Rclone, and ultimately deployed Medusa ransomware payloads to encrypt files. This campaign affected multiple organizations, exposing unpatched systems to significant operational risk and data loss. The incident highlights a continued surge in ransomware operations leveraging zero-day vulnerabilities in widely used enterprise software. Attackers are increasingly exploiting supply chain and infrastructure components to maximize impact, driving regulatory scrutiny and accelerating the need for robust patch management and segmentation practices.
7 months ago
Kill Chain
How Kaspersky’s 2025 ML Models Raised the Bar for DLL Hijacking Detection
In 2025, Kaspersky advanced their detection capabilities against DLL hijacking attacks by developing and deploying machine learning (ML) models. DLL hijacking, used by both organized malware developers (such as those behind Lumma stealer) and advanced persistent threat (APT) groups, involves loading malicious DLLs in place of genuine libraries. Attackers exploited trusted processes to evade detection and complicate incident response. Kaspersky’s internal telemetry revealed a sharp uptick in these attacks across diverse regions and sectors, prompting an iterative ML-driven approach. By refining training datasets, extracting relevant behavioral features, and evolving their models through analyst feedback, Kaspersky achieved higher true positive rates and reduced false positives, integrating the solution into SIEM and MDR offerings to surface live threats.
7 months ago
Kill Chain
Red Hat Breach 2025: ShinyHunters Escalate GitLab Data Extortion
In October 2025, Red Hat suffered a significant data breach after threat actor group Crimson Collective compromised its internal GitLab repositories, exfiltrating nearly 570GB of data including around 800 Customer Engagement Reports (CERs). These reports contained sensitive details about customers’ networks and infrastructure. Following unsuccessful ransom negotiations, Crimson Collective partnered with Scattered Lapsus$ Hunters and ShinyHunters to escalate extortion attempts, publicly posting data samples and demanding payment before a hard deadline. High-profile organizations such as Walmart, HSBC, Bank of Canada, and the US Department of Defense were among affected clients named in the leak. The collaboration between multiple threat actors and the rise of Extortion-as-a-Service operations like ShinyHunters highlight a new era of corporate extortion risk, with increasing pressure on organizations to proactively secure code repositories and sensitive customer communications against rapidly-evolving, multi-actor cyber threats.
7 months ago
Kill Chain
Kaspersky SIEM Uncovers ToddyCat DLL Hijacking Attacks in 2024
In early 2024, Kaspersky detected several advanced persistent threat (APT) incidents during pilot testing of their machine-learning-based DLL-hijacking detection module within their SIEM platform. Notably, the ToddyCat APT group exploited a SharePoint vulnerability (CVE-2021-27076) to gain initial access, then leveraged DLL sideloading to execute Cobalt Strike implants using masqueraded Windows system libraries. Other real-world incidents uncovered included infostealer malware posing as a policy manager, and a malicious loader activated through a USB drive, all utilizing DLL hijacking for code execution and persistence. Kaspersky’s detection tool enabled rapid identification and response, preventing further compromise and data exfiltration. This case highlights the growing sophistication of DLL hijacking techniques in APT operations and the increasing use of AI-driven security products to detect lateral movement and stealthy intrusion behaviors. The incidents underscore the need for robust behavioral analytics and real-time anomaly detection as threat actors increasingly target supply chains and trusted binaries to bypass traditional security defenses.
7 months ago
Kill Chain
How a Zimbra Zero-Day Breach Exposed the Brazilian Military: Lessons for Secure Collaboration
In early 2025, a zero-day vulnerability in Zimbra Collaboration (CVE-2025-27915), a widely used email and collaboration platform, was exploited to target the Brazilian military. Attackers used malicious ICS calendar files containing unsanitized HTML and JavaScript to trigger stored cross-site scripting (XSS) within Zimbra's Classic Web Client. This entry vector effectively bypassed standard security controls and provided attackers the ability to execute malicious code in users' browsers, potentially enabling credential theft, session hijacking, and further movement inside the organization before the vulnerability was patched. The campaign underscores how attackers are increasingly leveraging vulnerabilities in collaborative and communication tools to gain a foothold in targeted organizations and critical infrastructure. This breach is particularly relevant today given the ongoing surge in zero-day exploits against widely deployed business applications, especially in sectors such as government and defense. The rapid weaponization of collaboration-tool vulnerabilities highlights the need for timely patch management, robust segmentation, and vigilant threat detection to combat sophisticated phishing and XSS-based initial access.
7 months ago
Kill Chain
Chinese Cybercrime Group Exploits IIS Servers in Global SEO & Credential Theft Scheme
In October 2025, cybersecurity analysts uncovered a campaign orchestrated by a Chinese-speaking cybercrime group known as UAT-8099. The group exploited vulnerabilities in Microsoft Internet Information Services (IIS) servers, primarily targeting organizations across India and Thailand. Attackers deployed malicious scripts and leveraged the compromised servers for global search engine optimization (SEO) fraud while systematically stealing high-value credentials, configuration files, and certificate data. This sophisticated operation impacted business continuity, undermined trust, and exposed sensitive enterprise assets to further misuse. This breach exemplifies the growing threat from well-resourced cybercrime rings using server-side exploits to conduct financially motivated attacks. Similar credential theft and SEO manipulation TTPs are increasingly prevalent worldwide, highlighting an urgent need for enhanced internal server security, threat detection, and compliance with modern data protection standards.
7 months ago
Kill Chain
Oracle E-Business Suite Hit by Cl0p: CVE-2025-61882 Breach Exposes Enterprise Data
In October 2025, Oracle urgently released a security patch addressing CVE-2025-61882, a critical vulnerability in its E-Business Suite platform with a CVSS score of 9.8. The flaw, allowing unauthenticated remote attackers network access via HTTP, was actively exploited by the Cl0p ransomware gang in a series of data theft attacks. Threat actors leveraged the bug to gain control of impacted systems, enabling lateral movement and the exfiltration of sensitive business data. Oracle customers with exposed E-Business Suite deployments were specifically targeted, prompting a rapid, emergency response. This incident highlights the resurgence of large-scale supply chain ransomware attacks exploiting zero-day vulnerabilities in widely used enterprise software. Threat actors like Cl0p are increasingly automating exploitation campaigns, raising the bar for threat detection, patch management, and regulatory compliance requirements in digital enterprises.
7 months ago
Kill Chain
Oracle’s 2025 Mega Breach: 0-Day, BitLocker Bypass & VMScape Trigger Industry Wake-Up
In October 2025, Oracle faced a significant security incident that exposed critical new 0-day vulnerabilities, impacting key platforms via exploits including a BitLocker bypass, the 'VMScape' hypervisor escape, and a fast-spreading WhatsApp worm. Threat actors leveraged multiple sophisticated attack vectors, targeting both enterprise infrastructure and end-user devices. The campaign enabled unauthorized lateral movement, data exfiltration, and disruption of cloud workloads, with global enterprises and managed service providers feeling downstream impact as security researchers identified widespread exploitation across hybrid and multicloud environments. These multi-pronged intrusions forced urgent mitigation efforts, including rapid patching, segmentation, and new traffic visibility controls to stem active attacks. The incident underscores escalating attacker sophistication in blending 0-day exploitation, social engineering, and cloud platform abuse. As threat campaigns increasingly combine lateral spread mechanisms with supply chain risks and targeted ransomware, it highlights the necessity of modern Zero Trust frameworks, advanced detection, and continuous security governance for organizations operating at cloud scale.
7 months ago
Kill Chain
BIETA & CIII Unmasked: China’s MSS Deploys Espionage Through Research Firms in 2025
In October 2025, a detailed investigation revealed that Chinese research firms BIETA (Beijing Institute of Electronics Technology and Application) and CIII were directly implicated in cyber operations orchestrated by China’s Ministry of State Security (MSS). The report, based on personnel link analysis and institutional relationships, highlights how BIETA coordinated with MSS operatives and academic partners to conduct covert cyber-espionage campaigns targeting international entities. These campaigns leveraged advanced tactics, including exploitation of internal network flows and the use of encrypted traffic, to exfiltrate sensitive data undetected. The exposure underscores the persistent and sophisticated nature of state-sponsored cyber threats, as well as risks posed by non-traditional actors collaborating with government intelligence agencies. This incident reflects a broader escalation in state-driven cyber espionage, demonstrating that commercial and academic organizations may serve as active operational arms for nation-state threat actors. As attribution capabilities improve, organizations must reassess third-party relationships and reinforce east-west and encrypted traffic controls to mitigate lateral movement and exfiltration risks.
7 months ago
Kill Chain
Self-Propagating Malware Targets WhatsApp Users in Brazil with Financial Fraud Infostealer
In early June 2024, an infostealer campaign dubbed Water Saci aggressively targeted WhatsApp users in Brazil using self-propagating malware named Sorvepotel. Attackers leveraged compromised accounts to automatically distribute malicious links via WhatsApp messages, luring recipients to execute malware payloads. Once installed, Sorvepotel exfiltrates credentials and tracks browser activities, enabling threat actors to target and defraud regional financial institutions. The infection chain’s ability to rapidly spread through trusted social contacts increased both the velocity and scale of impact, compromising both individual and enterprise devices in a short time frame. The Water Saci operation highlights the evolution of credential-stealing malware adopting worm-like features to maximize reach. With messaging platforms remaining core to business and personal communications, this incident underscores the urgency of intercepting lateral movement, especially as attackers blend social engineering with advanced propagation and data theft techniques.
7 months ago
Kill Chain
How Chinese Front Organizations Exploited Western Research to Advance State Cyber Capabilities
In early 2024, coordinated investigations revealed that Chinese government-linked academic and research institutions were covertly collaborating with Western organizations and researchers. Operating under seemingly neutral fronts, these entities facilitated the transfer of advanced cyber technologies and expertise, ultimately benefitting the intelligence apparatus of the People’s Republic of China (PRC). The campaign included joint projects, academic exchanges, and technology partnerships that enabled the PRC to sidestep export controls and gain access to cutting-edge cyber defense and offensive capabilities. The outcome potentially undermines intellectual property protections and heightens risks to network and national security within targeted Western sectors. This incident underscores a marked escalation in supply chain and technology transfer tactics used by nation-state actors. As the global competition for cyber advantage intensifies, regulators and organizations must heighten vigilance around academic, research, and cross-border tech collaborations to mitigate risks of inadvertent technology leakage.
7 months ago
Kill Chain
Oracle E-Business Suite 2025: Critical SSRF Exploit Exposed and Analyzed
In October 2025, Oracle E-Business Suite was found to be vulnerable to an actively exploited server-side request forgery (SSRF) vulnerability, tracked as CVE-2025-61882. Threat actors leveraged a publicly available exploit script to manipulate the product’s servlet endpoints, extracting CSRF tokens and delivering a crafted payload capable of executing arbitrary commands via XSLT and Java reflection. The attack enabled remote code execution and potential lateral movement within affected enterprise environments, with indicators of compromise made public shortly after discovery. Oracle’s rapid response included a critical patch and threat intelligence advisory. This incident highlights an ongoing surge in advanced web exploitation techniques, particularly SSRF combined with deserialization and XSLT-based attacks. It underscores the urgent need for timely patching, defense-in-depth, and continuous anomaly detection, as well as the growing focus of attackers on business-critical ERP platforms.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

