✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4933 to 4944 of 5297
Clop Ransomware Targets Oracle E-Business Suite Customers in 2025 Extortion Campaign
In late September 2025, the Clop ransomware group launched a targeted extortion campaign against Oracle E-Business Suite customers. Using compromised third-party email accounts, attackers sent personalized emails to executives, claiming to have exfiltrated sensitive corporate data via known vulnerabilities in Oracle's ERP software. The emails provided 'proof' offers, imposed a payment deadline, and threatened public exposure or resale of stolen data if demands were not met. Oracle acknowledged the incident, referencing vulnerabilities patched in the July 2025 update, but did not confirm direct data exfiltration or specify the flaws under exploitation. This incident highlights the evolution of ransomware-as-a-service models that blend data theft, psychological pressure, and supply-chain targeting. It underscores urgent enterprise risk around unpatched ERP systems, the danger of credential compromise, and the increasing sophistication of financially motivated threat actors such as Clop.
7 months ago
Kill Chain
Android Spyware Masquerades as Messaging Apps in UAE: ESET Uncovers 2024 Mobile Threats
In June 2024, ESET researchers uncovered two Android spyware campaigns—ProSpy and ToSpy—masquerading as popular messaging apps Signal and ToTok, specifically targeting residents in the United Arab Emirates. The malware was distributed via third-party websites impersonating legitimate app stores, such as the Samsung Galaxy Store, and required users to manually install them. Upon installation, the spyware requested extensive permissions, gaining access to contacts, messages, stored files, audio, images, and more, enabling extensive data exfiltration. The campaigns utilized regional delivery tactics to focus on UAE users, exploiting trusted local app brands. These findings highlight a persistent threat trend: attackers disguising malware as legitimate communication apps to bypass official channels and exploit regional trust. With increased scrutiny on privacy and secure messaging, such campaigns pose heightened operational and compliance risks for organizations and individuals alike, underscoring the urgent need for enhanced mobile security measures and user awareness.
7 months ago
Kill Chain
Clop Ransomware Claims Oracle E-Business Suite Data Breach in 2025 Extortion Wave
In late September 2025, a widespread extortion campaign was detected targeting companies using Oracle E-Business Suite, with the Clop ransomware group (also tracked as FIN11) claiming to have exfiltrated sensitive data. Attackers used hundreds of compromised email accounts to send extortion messages to executives, demanding payment to prevent data leaks on Clop's darknet site. While links to previous Clop activity were identified through reused email accounts and familiar tactics, as of early October, no definitive evidence of a successful Oracle E-Business Suite breach has been confirmed by investigators (Mandiant, Google Cloud, and GTIG). As a result, organizations remain on alert as the situation develops, and incident response efforts continue. This attack underscores a continuing trend of cyber extortion groups leveraging data theft and email-based threats rather than traditional encryption. The campaign's timing and targeting highlight rapidly evolving attacker sophistication and the ongoing vulnerability of enterprise applications, emphasizing the importance of robust lateral movement controls and proactive monitoring in the face of persistent ransomware and extortion campaigns.
7 months ago
Kill Chain
Red Hat Hit by GitLab Breach: Crimson Collective Steals Sensitive Consulting Data
In September 2025, Red Hat confirmed a security incident involving unauthorized access to a GitLab instance used by its consulting business. The threat group, Crimson Collective, claims to have exfiltrated nearly 570GB of compressed data from approximately 28,000 internal repositories, including around 800 Customer Engagement Reports (CERs) containing sensitive infrastructure details, authentication tokens, and database URIs. The attackers allegedly leveraged these credentials to potentially access downstream customer environments. Red Hat stated that no other company services or products were affected and initiated remediation steps shortly after detecting the breach. This incident highlights a growing trend of threat actors targeting source code management systems and leveraging poorly secured credentials to escalate access. It underscores the importance of robust secrets management, Zero Trust segmentation, and stringent access controls across cloud-native development environments.
7 months ago
Kill Chain
Red Hat's 2025 Consulting GitLab Breach: Crimson Collective Breaches Development Data
In October 2025, Red Hat, an IBM subsidiary, confirmed a data breach after the Crimson Collective threat group accessed and exfiltrated information from a self-managed GitLab Community Edition instance used for the company’s consulting projects. Attackers reportedly stole over 28,000 code repositories containing project specifications, code samples, internal communications, and potentially sensitive artifacts such as credentials and configuration data shared with consulting customers. The incident did not impact any other Red Hat services or products, and the company promptly launched an investigation, isolated the affected system, and notified relevant authorities and affected customers. This breach highlights growing risks associated with supply chain exposures, particularly when attackers target development and collaboration platforms where sensitive operational data may be stored. The incident is indicative of rising threats from organized cybercrime groups seeking intellectual property, credentials, and internal communications for downstream exploitation.
7 months ago
Kill Chain
Android Spyware Campaigns Target Signal and ToTok Users in Sophisticated 2025 Attack
In June 2025, cybersecurity firm ESET uncovered targeted Android spyware campaigns, dubbed ProSpy and ToSpy, which impersonated upgrades and plugins for the popular messaging apps Signal and ToTok. Threat actors distributed malicious APK files via websites masquerading as official app sites and third-party stores, luring users primarily in the United Arab Emirates. Once installed, these spyware variants harvested sensitive data including device information, contacts, SMS, files, and backups, using sophisticated persistence mechanisms and disguising themselves as legitimate apps. Data exfiltration was conducted using encrypted channels to evade detection. This incident underscores the increasing threat of mobile malware leveraging convincing social engineering tactics and fake branding. It highlights a macro trend of attackers exploiting trust in widely used apps to infiltrate user devices, reflecting rising complexity in mobile threat landscapes and growing regulatory pressure on app distributors.
7 months ago
Kill Chain
Service Desk Social Engineering Attack Exposes Enterprise Vulnerabilities in 2025
In October 2025, organizations witnessed a sharp rise in successful social engineering attacks targeting enterprise service desks. Threat actors such as Scattered Spider exploited help desk processes by impersonating employees and manipulating support staff into resetting credentials or granting privileged access. These attacks bypassed traditional technical defenses by leveraging persuasive phone or chat conversations, resulting in significant business disruptions, data exposure, and potential operational outages. Notable events, such as those at MGM Resorts and Clorox, demonstrated the devastating financial and reputational impact of a single compromised support interaction, with recovery efforts spanning weeks and incurring nine-figure damages. This trend highlights the evolving threat landscape where the human element is now the primary entry vector. The urgency to adopt robust, workflow-driven identity verification, bypassing agent discretion, is underscored by regulatory scrutiny and mounting pressure to align with NIST and similar frameworks. Organizations must shift from relying on staff intuition to standardized, audited processes to mitigate these high-impact risks.
7 months ago
Kill Chain
Urgent: DrayTek Vigor Router RCE Vulnerability (CVE-2025-10547) Exposes SMB Networks
In October 2025, DrayTek disclosed a critical remote code execution vulnerability (CVE-2025-10547) impacting multiple Vigor router models, commonly used by small to medium businesses. The flaw allows unauthenticated attackers to remotely execute arbitrary code by sending specially crafted HTTP or HTTPS requests to the router's Web User Interface (WebUI). Triggered by an uninitialized stack value that facilitates arbitrary memory operations, the vulnerability could lead to full system compromise, crash, or remote takeover if exploited. DrayTek confirmed the issue following responsible disclosure and provided urgent firmware updates for affected devices. This incident exemplifies the rising risks posed by infrastructure vulnerabilities in network devices widely deployed in business environments. As attackers increasingly target edge and remote-management interfaces, proactive patch management has become paramount for organizations seeking to mitigate evolving threats and comply with stricter cybersecurity standards.
7 months ago
Kill Chain
U.A.E. Android Spyware Alert 2025: ProSpy & ToSpy Impersonate Secure Messaging Apps
In October 2025, cybersecurity researchers at ESET identified two sophisticated Android spyware campaigns, ProSpy and ToSpy, actively targeting users in the United Arab Emirates by masquerading as legitimate apps such as Signal Encryption Plugin and ToTok Pro. The spyware was disseminated through fake websites leveraging social engineering techniques, deceiving users into downloading malicious apps. Once installed, the malware secretly exfiltrated device data, tracked user communications, and introduced significant privacy and data security risks for both individuals and organizations. The campaigns indicate a growing trend of targeted mobile espionage in the region, significantly undermining user trust and operational safety. This incident underscores the escalating threat from mobile spyware distributed via convincing social engineering and fake app storefronts. As more users move critical communications to mobile platforms, adversaries are rapidly advancing their techniques, prompting urgent calls for enhanced mobile threat detection, robust user education, and strict compliance with data protection frameworks.
7 months ago
Kill Chain
Cl0p Ransomware Targets Oracle E-Business Suite: 2025 Executive Extortion Wave Uncovered
In October 2025, Google Mandiant and the Google Threat Intelligence Group reported a new extortion campaign targeting organizations using Oracle E-Business Suite. The campaign, believed to be orchestrated by the financially motivated Cl0p ransomware group, involved the distribution of extortion emails to C-level executives, claiming theft of sensitive business data. Attackers leveraged weaknesses in Oracle’s environment to exfiltrate confidential information, applying pressure for payment through credible threats of public disclosure and operational disruption. This incident highlights the evolving nature of ransomware tactics towards high-value enterprise applications and direct executive outreach. This case demonstrates the increasing trend of threat actors focusing on business-critical cloud and ERP platforms, not only for data theft but also to maximize ransom leverage. Sophisticated phishing, lateral movement, and exploitation of complex SaaS ecosystems make such attacks especially challenging to detect and contain.
7 months ago
Kill Chain
Multi-Vector Cyber Assault 2025: CarPlay, Cloud SQL, & iCloud Under Attack
In October 2025, coordinated threat actors launched a multi-vector attack campaign leveraging a critical CarPlay exploit, BYOVD (Bring Your Own Vulnerable Driver) tactics, SQL server compromise for covert command-and-control (C2), and targeted backdoor deployments against iCloud accounts. Attackers exploited unpatched vulnerabilities across automotive infotainment systems, enterprise firewalls, and cloud environments, enabling lateral movement and persistent access. The campaign demonstrated a sophisticated blend of supply chain targeting, abuse of trusted encryption protocols, malicious browser extension injection, and data exfiltration at scale. Impacted organizations faced substantial operational disruption, data loss, and the risk of regulatory penalties due to exposure of sensitive customer information and business-critical systems. This incident underscores the rapid evolution of attacker tradecraft, particularly in hybrid infrastructures and connected vehicles. The convergence of cloud, automotive, and critical business services in a single campaign highlights the increasing necessity for comprehensive, real-time security that spans east-west traffic, encrypted channels, and multi-cloud platforms.
7 months ago
Kill Chain
Confucius Launches Targeted Campaign Against Pakistan with WooperStealer and Anondoor Malware
In October 2025, the advanced persistent threat group Confucius launched a sophisticated phishing campaign targeting Pakistani government, defense, and critical industry sectors. Leveraging spear-phishing emails and malicious documents, the attackers deployed two custom malware strains—WooperStealer and Anondoor—to infiltrate victim environments. These tools enabled the exfiltration of sensitive information and lateral movement across internal networks, potentially exposing military secrets and compromising operational capabilities. The attack underlines the evolving TTPs used by regional espionage actors and demonstrates substantial gaps in defending east-west traffic and data exfiltration from secure environments. This incident highlights the growing prevalence of specialized information-stealing malware and the targeting of governmental infrastructure by geopolitical adversaries. It reflects broader trends in cyber-espionage and underscores heightened regulatory expectations for securing critical east-west and outbound traffic flows.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

