✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4921 to 4932 of 5297
ShinyHunters Extorts 39 Firms in Salesforce OAuth Supply Chain Breach
In October 2025, the extortion group known as 'Scattered Lapsus$ Hunters'—a coalition including ShinyHunters, Scattered Spider, and Lapsus$—launched a data leak site to extort 39 companies after a coordinated campaign exploiting Salesforce OAuth integrations. The attackers used sophisticated voice phishing to trick employees into connecting malicious OAuth apps to corporate Salesforce instances, enabling unauthorized database access. Stolen data included sensitive customer records from major global brands such as FedEx, Disney, Google, and Marriott, with threat actors demanding ransom to prevent broader public disclosure. Salesforce stated there was no compromise of its platform, but investigations continue. This incident highlights the rising threat of supply chain and identity-based attacks targeting SaaS platforms, exploiting user trust and third-party integrations. With the growing adoption of SaaS solutions and increasing regulatory focus (e.g., GDPR), enterprises face mounting pressure to implement robust identity, access governance, and monitoring controls to defend against mass-scale data exfiltration and extortion.
7 months ago
Kill Chain
Asahi Ransomware Disruption: Lessons from a 2024 Supply Chain Attack
In June 2024, Asahi Group Holdings, a leading Japanese beverage manufacturer, experienced a disruptive ransomware attack that targeted its IT infrastructure. The incident led to shutdowns across several of its breweries and bottling plants, impacting production and distribution operations in Japan and parts of Europe. Initial investigations revealed that attackers penetrated corporate systems and deployed ransomware, encrypting critical files and demanding payment for restoration. While Asahi swiftly shut down affected systems to contain the threat, the disruption highlighted business continuity vulnerabilities and the risks inherent in operational technology integration. This attack underscores a rising trend in ransomware targeting critical supply chain sectors, particularly food and beverage manufacturing. As threat actors refine their methods and exploit operational downtime pressure, organizations across sectors face increasing urgency to harden east-west traffic security and implement zero trust segmentation to minimize lateral movement risks.
7 months ago
Kill Chain
CISA Confirms Active Exploitation of Meteobridge CVE-2025-4008 Command Injection Flaw
On October 24, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) flagged an actively exploited command injection vulnerability (CVE-2025-4008) within Smartbedded Meteobridge's web interface. This critical flaw, assigned a CVSS score of 8.7, permits remote attackers to execute arbitrary code by exploiting improper input handling. Threat actors are leveraging this vulnerability in the wild, potentially compromising sensitive data and gaining unauthorized access to affected networks. The exposure primarily impacts organizations deploying Meteobridge for environmental monitoring or network-connected IoT operations, raising significant concerns about operational integrity and data confidentiality. This incident highlights a persistent trend in adversaries targeting device management interfaces and exploiting command injection vulnerabilities for lateral movement or further compromise. With regulatory scrutiny increasing and attackers rapidly capitalizing on newly discovered flaws, swift patching and enhanced network segmentation are more crucial than ever.
7 months ago
Kill Chain
Signal Launches SPQR: A Quantum-Safe Encryption Upgrade for 2025
In October 2025, Signal introduced a major upgrade to its encryption suite by deploying the Sparse Post-Quantum Ratchet (SPQR), designed to secure user communications against present and future quantum computing threats. Developed in collaboration with leading academic and industry partners, SPQR brings a 'triple ratchet' protocol leveraging hybrid cryptography based on both traditional and quantum-resistant key exchange mechanisms. This system provides continual key rotation, forward secrecy, and robust post-compromise security, ensuring that even if current keys are compromised, future messages remain protected. The rollout will be gradual and backward-compatible, affecting Signal’s 100 million global users without requiring manual intervention. The launch of SPQR is a landmark response to the rise of quantum computing, which threatens conventional encryption schemes. Its introduction reflects mounting industry urgency to adopt advanced cryptographic standards and maintain trust in privacy-critical communications platforms amid rapid shifts in the threat landscape.
7 months ago
Kill Chain
Renault and Dacia UK 2025: Customer Data Breach Highlights Supply Chain Risks
In October 2025, Renault and Dacia UK notified customers of a data breach resulting from a cyberattack at an undisclosed third-party provider. The breach exposed sensitive information including full names, gender, phone numbers, email and postal addresses, as well as vehicle identification and registration numbers. While no financial data was compromised, this incident potentially increases the risk of phishing, scams, and targeted social engineering. Renault confirmed that the third-party provider contained the incident and regulatory authorities, including the UK’s Information Commissioner's Office, were notified as part of standard response. This event highlights the persistent risks posed by supply chain vulnerabilities, where companies are exposed through third-party relationships. As cyberattackers increasingly target vendors to bypass primary defenses, organizations must intensify scrutiny of their supply chains and enhance segmentation, monitoring, and incident response to align with evolving regulatory and threat landscapes.
7 months ago
Kill Chain
Cavalry Werewolf APT Hits Russian Agencies with FoalShell and StallionRAT in 2025
In October 2025, a sophisticated threat actor known as Cavalry Werewolf, believed to share links with the YoroTrooper group, orchestrated targeted cyber attacks against Russian public sector agencies. Utilizing custom malware families FoalShell and StallionRAT, the attackers infiltrated key government systems, establishing covert access for potential espionage and data theft. Security firm BI.ZONE detected the activity, noting operational overlaps with other known clusters such as SturgeonPhisher and Comrade Saiga. The cyber-espionage campaign leveraged a mix of spear-phishing, credential theft, and advanced persistence techniques to evade detection and conduct lateral movement within critical infrastructure environments. This incident highlights a continuing trend of state-aligned espionage campaigns that exploit zero trust gaps, advanced malware, and blended tactics to compromise sensitive government data. The increasing frequency and sophistication of such attacks elevate the urgency for robust segmentation and monitoring strategies within public sector networks.
7 months ago
Kill Chain
SORVEPOTEL: New WhatsApp-Driven Malware Campaign Hits Brazil
In late 2025, cybersecurity researchers identified a rapid outbreak of a self-spreading malware targeting Brazilian Windows users through WhatsApp, labeled SORVEPOTEL and tracked as the Water Saci campaign. The malware leverages the inherent trust and widespread popularity of WhatsApp by delivering malicious payloads via chat messages, which entice users to download infected files. Once inside a system, SORVEPOTEL propagates by messaging victims’ contacts, enabling swift lateral movement and widespread distribution. Notably, the campaign appears engineered for rapid proliferation rather than for data theft or ransomware deployment, showcasing evolving malware propagation tactics. This incident highlights the increasing sophistication and speed of messaging app-based malware and reflects a broader trend of social engineering campaigns capitalizing on trusted digital platforms. Organizations should re-examine endpoint protections and user awareness in light of emerging threats exploiting popular communications channels.
7 months ago
Kill Chain
Detour Dog Exposes DNS-Powered Stealer Risk: A 2025 Campaign Analysis
In October 2025, threat intelligence researchers revealed that the actor known as Detour Dog orchestrated wide-scale campaigns to deliver the Strela Stealer information stealer using DNS-powered malware infrastructure. Detour Dog’s operation involved maintaining control over a network of malicious domains, enabling initial delivery of a backdoor named StarFish, which then facilitated deployment of Strela Stealer. This campaign leveraged covert DNS traffic and evasion techniques, making threat detection and containment difficult for enterprise defenders. Victimized organizations faced increased risk of credential theft, data exfiltration, and operational disruption as a result. This incident highlights the rising trend of weaponizing benign protocols like DNS for malware delivery and lateral movement, as well as the emergence of advanced information stealers targeting enterprise networks and cloud environments. Organizations must adapt controls and detection strategies to defend against increasingly sophisticated, protocol-abusing threats.
7 months ago
Kill Chain
Rhadamanthys Stealer 2025: Device Fingerprinting, Steganography, and the New Face of Data Theft
In October 2025, cybersecurity researchers uncovered significant new capabilities in the Rhadamanthys Stealer malware, including advanced device fingerprinting and the use of PNG steganography to distribute malicious payloads. Initially spread via cybercrime forums, the malware author has expanded its ecosystem with additional tools like Elysium Proxy Bot and Crypt Service, targeting organizations worldwide. Threat actors leveraged these upgrades to collect detailed browser and system data while evading detection, resulting in an uptick of credential, financial, and sensitive data thefts across enterprise environments. The evolution of Rhadamanthys Stealer highlights a broader trend of information stealer malware using novel evasion tactics and multi-tool ecosystems. Its modularity and innovative payload delivery have driven increased attention from security teams and regulators, as businesses seek to defend against ever-more-sophisticated data exfiltration methods.
7 months ago
Kill Chain
Microsoft AI Voice Cloning: A New SaaS Security Exposure in 2024
In early 2024, Microsoft’s ‘Speak for Me’ AI-powered voice cloning technology emerged as a significant security risk when researchers and privacy advocates highlighted its potential for abuse. Attackers could exploit the deep integration of this feature into productivity platforms like Teams, enabling the creation of near-perfect voice replicas for use in live calls or AI-driven agent interactions across SaaS environments. The risk is compounded by the platform’s capability to reproduce voices without comprehensive enrollment checks, opening avenues for sophisticated impersonation attacks and social engineering, ultimately undermining trust in corporate communications and user authentication. This incident underscores an urgent trend: as generative AI technologies become embedded in mainstream communications platforms, attackers are adopting new TTPs focused on identity and voice deception. Enterprises must address these risks proactively, with regulatory scrutiny growing over AI misuse in both authentication and privacy contexts.
7 months ago
Kill Chain
UAT-8099 Hijacks IIS Servers: SEO Fraud and Data Theft Exposed
In early 2024, the Chinese-language cybercrime group UAT-8099 orchestrated a sophisticated series of attacks targeting Internet Information Services (IIS) web servers belonging to reputable organizations worldwide, including technology firms, telecoms, and universities. Exploiting insecure internet-facing servers with weak file upload controls, the attackers established footholds using open source web shells. They escalated privileges, enabled remote access with OSS reverse proxy tools, and deployed 'BadIIS' implants to perform SEO poisoning, redirecting search engine traffic to fraudulent gambling and scam sites. Simultaneously, the threat actors exfiltrated credentials, configuration files, and certificates, setting the stage for future attacks or data sales on darknet markets. This campaign demonstrates the threat actor's multi-pronged approach, blending fraud and espionage in ways that evade immediate detection. The incident highlights a growing global trend where SEO manipulation and credential theft converge, exposing organizations to operational, reputational, and regulatory risks amidst rising regulatory scrutiny around digital trust and supply chain integrity.
7 months ago
Kill Chain
Jaguar Land Rover Ransomware Breach: 2024 Supply Chain Disruption Case Study
In early 2024, Jaguar Land Rover (JLR) suffered a disruptive ransomware attack that exposed the company’s vulnerability to advanced persistent threats. Attackers, suspected to be Medusa ransomware operators, leveraged residual access from a prior breach to re-enter JLR’s systems, eventually encrypting sensitive data and disrupting operations across its supply chain. The breach forced significant production slowdowns, delayed supplier payments, and prompted the company to enact emergency IT protocols and notify regulatory authorities. This incident highlights the growing threat of repeat ransomware campaigns targeting global manufacturers and their digital supply chains. It underscores the critical need for continuous detection, east-west network visibility, and rigorous post-breach remediation in defending against evolving ransomware tactics.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

