✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 5029 to 5040 of 5299
APT Campaign Exploits Cisco ASA Zero-Days: Persistent Threats to Government Devices in 2025
In September 2025, U.S. federal agencies were ordered by CISA to urgently patch Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices after two critical zero-day vulnerabilities (CVE-2025-20333, CVE-2025-20362) were exploited by the APT group UAT4356 (STORM-1849). Attackers achieved unauthenticated remote code execution and persistent control by manipulating device ROMMON, deploying malware such as LINE VIPER and the RayInitiator bootkit to facilitate malware implants, command execution, and possible data exfiltration. The campaign, linked to the larger ArcaneDoor operation, threatened essential government and global infrastructure by allowing full device compromise, evasion of detection, and resistance to conventional remediation steps. This incident highlights an escalating trend in sophisticated, state-linked attacks targeting edge infrastructure, often leveraging supply-chain weaknesses and persistent malware able to survive reboots and firmware updates. It also underscores renewed regulatory pressure for timely vulnerability mitigation and increased focus on Zero Trust architectures for critical sectors.
7 months ago
Kill Chain
Inside the 2025 Co-op Scattered Spider Cyberattack: Lessons and Impact
In April 2025, the Co-operative Group (Co-op), a major UK member-owned retailer, experienced a sophisticated cyberattack attributed to Scattered Spider affiliates linked to the DragonForce ransomware operation. The attack targeted Co-op’s IT infrastructure, forcing the group to shut down critical systems, causing major disruptions to back-office and call-center operations, and necessitating rapid manual workarounds. Although Co-op's incident response prevented data encryption, attackers stole sensitive personal information of all 6.5 million current and past members, including names and contact details. The breach resulted in significant operational outages, with £80 million ($107 million USD) in immediate financial losses and longer-term revenue reduction due to impacted retail operations and customer trust. This incident highlights the evolving threat of identity-driven ransomware attacks and the increasing willingness of threat actors to disrupt critical infrastructure for financial gain. The scale and impact of the Co-op breach underscore the need for advanced security controls and segmented, resilient architectures to counter modern ransomware groups.
7 months ago
Kill Chain
Unofficial Postmark MCP npm Package: 2024 Supply Chain Breach Exposes Email Data
In February 2024, the unofficial 'postmark-mcp' npm package—a clone of the genuine Postmark MCP email handler—was discovered to have maliciously exfiltrated users' email data. With a single line of code added in its latest update, the package silently sent every processed email to an external domain controlled by the attacker. This supply chain compromise exploited developer trust in open-source libraries, resulting in unintentional leakage of confidential user communications and putting affected organizations and their customers at risk of data exposure or further attacks. This incident underscores the growing frequency and sophistication of supply chain attacks targeting software ecosystems like npm. Organizations face heightened regulatory and reputational risks as attackers leverage trusted distribution platforms to propagate malicious code, making robust dependency monitoring and vendor validation more critical than ever.
7 months ago
Kill Chain
Microsoft Warns: XCSSET macOS Malware Evolves to Target Xcode Devs in 2025
In September 2025, Microsoft Threat Intelligence identified a new, advanced variant of the XCSSET macOS malware targeting Xcode developers. This infostealer propagates by infecting Xcode projects—widely shared among software engineers—allowing it to execute malicious code each time a compromised project is built. The updated malware features enhanced browser data theft (including Firefox), clipboard hijacking to steal cryptocurrency via address swapping, and improved persistence mechanisms. Though observed only in limited, targeted attacks so far, XCSSET poses a significant risk to both assets and sensitive developer tooling. This incident is especially relevant today as targeting the software supply chain and developer toolchains is becoming a favored method for threat actors seeking high-privilege access. The sophistication of XCSSET’s mechanisms mirrors broader trends in stealthy, data-focused attacks against development environments, pressing organizations to reassess internal controls and software sharing practices.
7 months ago
Kill Chain
Massive npm Supply Chain Attack: Shai-Hulud Worm Infects Hundreds of Packages
In September 2025, a major supply chain compromise hit the npm ecosystem with the discovery of the Shai-Hulud worm. Attackers leveraged malicious npm packages to propagate self-replicating malware, which spread by abusing developer credentials and update permissions across over 500 packages—including widely used libraries from organizations such as CrowdStrike. Malicious code executed on install harvested secrets, exfiltrated sensitive GitHub and cloud data, and published infected releases to additional packages, resulting in widespread risk of source code leaks, credential theft, and downstream infections. This incident typifies the escalating trend of highly automated supply chain attacks targeting open-source repositories. Such events highlight the vulnerabilities of complex dependency networks and reinforce the necessity for robust controls, automated monitoring, and zero trust policies for development and CI/CD ecosystems.
7 months ago
Kill Chain
Cisco 2025: Critical SNMP Vulnerability Actively Exploited in IOS and IOS XE
In September 2025, Cisco disclosed that an actively exploited vulnerability (CVE-2025-20352, CVSS 7.7) in its IOS and IOS XE software allows remote attackers to execute arbitrary code or trigger a denial-of-service (DoS) condition via specially crafted SNMP packets. The flaw, which came to light after attacker activity was observed leveraging previously compromised administrative credentials, impacts a broad range of Cisco networking equipment. The immediate impact includes risks of device takeover, network disruption, and possible lateral movement within victims’ environments. This incident underscores the criticality of securing network infrastructure against both external and internal threats, as attackers continue to exploit overlooked or unpatched vulnerabilities at the core of modern networks. The active exploitation highlights an urgent need for organizations to review segmentation, monitoring, and patch management practices in light of evolving attack techniques.
7 months ago
Kill Chain
Malicious Rust Crates Infect Supply Chain, Steal Crypto Wallet Keys in 2025
In May 2025, cybersecurity researchers identified a major supply chain attack targeting the Rust developer ecosystem. Two malicious Rust crates—faster_log and async_println—were published on the popular crates.io repository, masquerading as legitimate packages but designed to covertly exfiltrate Solana and Ethereum wallet private keys from software projects that incorporated them. The threat actors, using the aliases rustguruman and dumbnbased, achieved over 8,400 downloads, heightening the risk of cryptographic asset theft and potentially impacting both individual developers and organizations reliant on decentralized finance. This incident exemplifies the growing risks within open-source ecosystems, where attackers exploit trusted repositories to distribute malware. The trend of targeting crypto assets through developer-centric supply chain attacks highlights an urgent need for more robust vetting of third-party code and increased vigilance against evolving attacker tactics.
7 months ago
Kill Chain
DDoS Tsunami: Tech Overtakes Gaming in 2025 Attack Surge
In early 2025, a wave of Distributed Denial-of-Service (DDoS) attacks targeting the technology sector marked a significant shift in cyberattack patterns, according to Gcore's Q1–Q2 2025 Radar report. Attack volumes surged by 41% year-on-year, with the largest observed DDoS flood peaking at 2.2 Tbps—surpassing previous records set in 2024. Threat actors employed multi-layered strategies and protracted campaigns, specifically targeting technology companies with sophisticated, high-bandwidth assaults that caused operational disruptions, service outages, and reputational harm across multiple organizations. This evolution reflects attackers’ growing technical prowess and focus on critical service providers. The incident is particularly relevant as the threat landscape pivots towards the tech sector and away from previous gaming-centric targets. This trend underscores broader risks for infrastructure providers and the need for adaptive DDoS defenses in the face of escalating attack complexity and regulatory expectations.
7 months ago
Kill Chain
North Korean AkdoorTea Supply Chain Attack Hits Global Crypto Developers
In September 2025, a sophisticated supply chain attack targeting the global cryptocurrency development sector was uncovered, orchestrated by North Korea-linked threat actors associated with the Contagious Interview campaign. Leveraging a newly identified backdoor named AkdoorTea—as well as tools like TsunamiKit and Tropidoor—the adversaries compromised software development environments across all major operating systems, including Windows. According to research from ESET, tracked as part of the DeceptiveDevelopment group, attackers used trojanized developer tools and social engineering tactics to infiltrate their targets and facilitate lateral movement, data theft, and potential deployment of further malware within sensitive crypto-related projects. This incident highlights the rising trend of nation-state attackers exploiting software supply chains to infiltrate innovative sectors such as cryptocurrency. It underscores the urgent need for improved east-west traffic visibility, zero trust segmentation, and threat detection controls, as organizations increasingly become targets for persistent, highly resourced adversaries.
7 months ago
Kill Chain
Salesforce AI Prompt Injection Bug Exposes CRM Data in 2025 Breach
In September 2025, security researchers at Noma Security identified a critical vulnerability, termed ForcedLeak (CVSS 9.4), in Salesforce Agentforce, an AI-powered platform for constructing automation agents. The flaw allowed threat actors to launch indirect prompt injection attacks against Agentforce’s integration with Salesforce’s CRM, opening avenues for exfiltration of sensitive customer relationship data. The attack leveraged manipulated AI prompts that bypassed input validation, ultimately resulting in confidential business and customer information being at risk of exposure until Salesforce deployed a rapid patch. This incident highlights the growing risks stemming from AI prompt injection vulnerabilities as more enterprises embrace AI-integrated SaaS for customer-facing processes. The Salesforce episode underscores regulatory and security urgency to address trust boundaries around rapidly-evolving AI within business-critical platforms.
7 months ago
Kill Chain
Vane Viper Powers 1 Trillion DNS Queries in 2025 Malvertising Mega-Breach
In September 2025, the threat actor group known as Vane Viper was revealed to be operating a vast and covert ad fraud and malvertising network, leveraging a staggering one trillion DNS queries to enable malware distribution globally. According to a detailed Infoblox technical report, Vane Viper manipulated core internet infrastructure using shell companies and complex ownership structures to obfuscate responsibility and perpetuate malicious adtech practices. Their operations enabled widespread malvertising campaigns, significantly impacting advertising platforms and exposing users worldwide to illicit downloads and credential theft. This breach underscores a recent surge in the use of advanced DNS tunneling and obfuscation tactics in cybercrime, particularly within ad fraud and malvertising schemes. The incident exemplifies how attackers increasingly exploit foundational internet protocols, challenging traditional detection and defense measures while prompting urgent regulatory attention and industry-wide response.
7 months ago
Kill Chain
Cisco ASA Zero-Day (CVE-2025-20333) Breach: Inside the CISA Emergency Response
In September 2025, Cisco disclosed a critical zero-day vulnerability (CVE-2025-20333, CVSS 9.9) affecting its Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) Software. Attackers actively exploited improper input validation in the VPN web server, enabling them to bypass authentication and potentially gain unauthorized access to sensitive environments. Cisco urged immediate patching as exploitation was observed targeting both perimeter and internal firewalls, demonstrating advanced lateral movement strategies. This exploitation prompted an emergency mitigation directive from CISA to reduce risk across U.S. federal agencies and private enterprises. This incident underscores the ongoing evolution of threat actors leveraging zero-days to target critical infrastructure firewalls, coinciding with a nationwide spike in sophisticated, identity-driven attacks. Organizations are under increasing regulatory scrutiny to patch rapidly and advance segmentation, threat monitoring, and east-west traffic controls.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

