✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 5125 to 5136 of 5299
Global Surge in PhaaS: 17,500 Phishing Domains Exploit 316 Brands
In mid-2025, cybersecurity researchers exposed an extensive global phishing campaign orchestrated via Phishing-as-a-Service (PhaaS) platforms Lighthouse and Lucid. These services facilitated the deployment of more than 17,500 phishing domains impersonating 316 brands across 74 countries. The PhaaS operators provided subscription access to professionally maintained phishing kits targeting both enterprises and individual users, enabling attackers with minimal technical expertise to launch widespread credential theft attacks. As a result, organizations in sectors ranging from finance to technology experienced increases in fraudulent account access, financial loss, and reputational harm. The scale and automation lowered barriers for entry, allowing rapid exploitation and high turnover of malicious domains. This incident underscores the rapid evolution of cybercriminal business models, notably the rise of PhaaS, which commoditizes phishing attacks on a global scale. Its effectiveness and accessibility are driving a surge in targeted brand impersonation attempts and amplifying regulatory attention around authentication, threat monitoring, and user awareness.
7 months ago
Kill Chain
Fortra GoAnywhere MFT 2025: CVE-2025-10035 Exposed Critical Enterprise File Transfers
In September 2025, Fortra disclosed a critical security vulnerability (CVE-2025-10035) in its GoAnywhere Managed File Transfer (MFT) platform. The flaw, a deserialization weakness in the License Servlet, enabled remote attackers to execute arbitrary commands if they could submit a forged license request. Malicious activity leveraging this zero-day allowed threat actors to gain unauthorized access to sensitive file transfers, escalate privileges, and potentially exfiltrate confidential information before a patch was issued. The vulnerability received a maximum CVSS score of 10.0, emphasizing its severe risk and widespread exploitability. This incident highlights the ongoing surge in weaponization of zero-day vulnerabilities affecting popular enterprise software. Threat actors are increasingly exploiting deserialization bugs to bypass security controls and facilitate ransomware operations, putting organizations and their supply chains at heightened risk unless immediate mitigations are applied.
7 months ago
Kill Chain
SystemBC-Powered REM Proxy Botnet: 1,500 VPSs Compromised Daily in 2025
In mid-2025, cybersecurity researchers from Lumen's Black Lotus Labs identified a large-scale proxy botnet operation named REM Proxy, powered primarily by the SystemBC malware. Attackers leveraged SystemBC to compromise over 1,500 virtual private servers (VPS) daily, utilizing them to fuel a criminal proxy-as-a-service spanning 80 command-and-control (C2) servers. The network enabled threat actors to anonymize malicious activities and included access to approximately 20,000 vulnerable Mikrotik routers and additional open proxies. This infrastructure facilitated evasion, lateral movement, and widespread malicious activity with significant security implications for targeted and intermediary organizations. This incident underscores the ongoing evolution of proxy botnets and malware-as-a-service ecosystems, which pose critical risks for organizations across various sectors. As the boundaries between cybercrime infrastructure and legitimate cloud assets blur, defenders must place renewed emphasis on advanced threat detection, network segmentation, and zero trust principles to mitigate similar emergent threats.
7 months ago
Kill Chain
UNC1549: Iranian Cyber Espionage Breaches 11 European Telecoms Using LinkedIn Lures
In mid-2025, an Iran-affiliated cyber espionage group tracked as UNC1549 executed a coordinated attack targeting 11 European telecommunications firms. Using LinkedIn job recruitment lures and the custom MINIBIKE malware, the attackers successfully infiltrated 34 devices within these organizations, gaining persistent access to sensitive internal systems. The campaign, discovered by Swiss cybersecurity company PRODAFT, leveraged sophisticated social engineering alongside stealthy lateral movement, indicating considerable operational capability and intent to harvest confidential information potentially valuable for nation-state interests. This incident underscores a rising trend of strategic supply chain and telecom attacks using spear phishing and novel malware, highlighting the importance of strong east-west traffic controls and threat detection. It also reflects growing geopolitical tensions fueling state-sponsored cyber campaigns against critical infrastructure in Europe.
7 months ago
Kill Chain
AdaptixC2 in Real-World Attacks: Open-Source C2 Framework Alters the Threat Landscape
In early 2024, security researchers discovered that AdaptixC2, a newly released open-source command and control (C2) framework, was actively leveraged by threat actors in real-world intrusion campaigns. The attackers employed AdaptixC2 for post-exploitation activities, enabling covert command execution, lateral movement, and persistent access within targeted enterprise networks. The framework’s encrypted traffic and modular architecture allowed actors to evade traditional security controls, complicating detection and response efforts and increasing business risk. The widespread adoption of open-source C2 frameworks like AdaptixC2 underscores a shift where commodity offensive tools rapidly enter the arsenal of both sophisticated and opportunistic threat actors. This trend increases attack surface for organizations and challenges defenders to implement advanced incident detection, with regulatory bodies stressing the importance of proactive east-west and anomaly monitoring.
7 months ago
Kill Chain
Shai-Hulud Worm Breach: npm Supply Chain Attack in 2023
In November 2023, the self-replicating 'Shai-Hulud' worm orchestrated a large-scale supply chain attack targeting the npm ecosystem. The threat actor compromised hundreds of npm packages, inserting malicious code that enabled lateral propagation and potential backdoor access for anyone who installed the affected libraries. The attack illustrates how deeply embedded dependencies and trusted registries can be manipulated to impact thousands of downstream projects and potentially expose sensitive systems. Swift action from npm and security researchers helped mitigate the spread, but several organizations experienced heightened risk before remediation. This incident underscores the growing threat and frequency of software supply chain compromises, particularly targeting open-source registries. With adversaries leveraging automation and worm-like propagation, the security of development pipelines and third-party code ingestion remains an urgent focus for digital businesses.
7 months ago
Kill Chain
Scattered Spider Exposed: 2024 Ransomware Hits Critical Infrastructure and Healthcare
In September 2024, UK authorities arrested two teenagers, Thalha Jubair and Owen Flowers, for their significant roles in numerous cyberattacks attributed to the Scattered Spider gang—a notorious offshoot of The Com collective. Operating since at least May 2022, the pair leveraged social engineering techniques to infiltrate a range of organizations, including Transport for London, U.S. critical infrastructure, healthcare providers, and the federal court system. They stole and encrypted sensitive data, then demanded ransom payments, netting at least $115 million from 47 U.S. victims alone. Cryptocurrency wallets tied to the suspects were seized, totaling over $36 million, and both face serious charges on both sides of the Atlantic. This incident illustrates the growing threat from young, highly skilled ransomware groups utilizing sophisticated extortion tactics. As extortion and identity-driven ransomware evolve, organizations—especially those in critical industries—face increasing pressure to bolster defenses against lateral movement and social engineering-based breaches.
7 months ago
Kill Chain
SonicWall 2024 Breach: Firewall Backup Data Compromised in MySonicWall Attack
In June 2024, SonicWall confirmed that threat actors breached its MySonicWall portal and gained unauthorized access to a set of firewall backup configuration files. The attackers were able to obtain configuration data belonging to less than 5% of customers through this service, which could potentially reveal sensitive network information such as network structures, credentials, and policy configurations. SonicWall indicated that the breach was swiftly detected, affected accounts were notified, and the scope was limited, but details regarding the initial attack vector or threat actor remain undisclosed. This incident comes at a time of heightened targeting of network infrastructure management portals and supply chain entry points. As attackers increasingly look to exploit enterprise-grade device management platforms, organizations must reinforce segmentation, monitor lateral movements in east-west traffic, and continually validate zero trust architectures across all privileged network and cloud control panels.
7 months ago
Kill Chain
Critical Azure Entra ID Flaw Reveals Cloud IAM Security Gaps
In mid-2024, a critical cloud misconfiguration vulnerability was discovered in Microsoft Azure Entra ID, exposing severe weaknesses in the cloud provider’s identity and access management (IAM) infrastructure. The flaw allowed attackers, had it been exploited, to escalate privileges and potentially gain unauthorized access to sensitive assets across tenant environments. The vulnerability was quietly remediated by Microsoft prior to public disclosure, but security researchers noted it could have resulted in catastrophic, widespread attacks on enterprise data and operations if abused by malicious actors. This incident underscores growing concerns over cloud platform security and identity-centric attack vectors, coinciding with a broader surge in high-impact IAM misconfigurations. Organizations are increasingly urged to review cloud IAM policies and controls, as regulatory pressure intensifies and attackers shift focus to exploiting identity weaknesses within as-a-service environments.
7 months ago
Kill Chain
Charming Kitten’s 2024 Campaign: Telecoms and Satellite Companies Breached by Iranian APT
In early 2024, an Iranian state-linked advanced persistent threat (APT) group known as "Subtle Snail," associated with Charming Kitten, executed a series of highly customized cyberattacks targeting 11 global telecommunications, satellite operators, and aerospace manufacturers. The attackers, leveraging detailed reconnaissance via LinkedIn and other platforms, impersonated recruiters from major aerospace firms to lure high-value IT and engineering personnel into sophisticated spearphishing campaigns. Victims were tricked into downloading a modular backdoor malware dubbed 'MiniBike,' which allowed the group to evade detection through unique variants for each target. The breaches resulted in the theft of sensitive documents, credentials, personally identifiable information, proprietary business data, and call data records, posing significant risks to corporate and national security across regions from the Middle East to North America. This attack highlights sharply increased innovation in APT social engineering tactics and malware obfuscation. It underscores the need for organizations to bolster identity verification, east-west segmentation, and behavioral anomaly detection, especially as state-aligned threat actors refine tools for targeting critical infrastructure and global communications.
7 months ago
Kill Chain
Synthetic Identity Fraud Surges: US Finance Faces $3.3B in Damages (2024)
In 2024, US financial institutions, particularly those in the automotive lending sector, experienced a significant surge in synthetic identity fraud, resulting in estimated damages of $3.3 billion. Cybercriminals leveraged data amassed from previous breaches to construct convincing synthetic profiles used to obtain loans and open accounts, often nurturing these fraudulent identities with legitimate activity to evade detection. Both individual and business identities were targeted, with institutions facing growing pressure to enhance detection capabilities amid an ongoing arms race with sophisticated attackers employing AI and cloud tools. This increase in synthetic identity fraud reflects an evolving threat landscape, where attackers capitalize on remote-first processes and richer data sources to outpace traditional defenses. The accelerating adoption of digital banking and lending has heightened urgency for adaptive, real-time security controls and improved identity verification as financial firms confront complex, persistent fraud schemes.
7 months ago
Kill Chain
SonicWall MySonicWall Breach Puts Firewall Backups and Credentials at Risk
In September 2025, SonicWall disclosed a security incident impacting its MySonicWall cloud platform, where firewall configuration backup files were accessed by threat actors following a series of brute-force attacks. The breach, affecting less than 5% of SonicWall firewalls, exposed configuration data that included encrypted passwords and sensitive information, potentially easing future exploitation of affected devices. SonicWall responded by disabling unauthorized access, notifying affected customers, and issuing urgent guidance to reset credentials, keys, and secrets for all related accounts and services. The vendor also coordinated with cybersecurity and law enforcement agencies as part of its investigation. This incident highlights a rising trend of attackers targeting cloud-based administrative services and configuration backups, exploiting brute-force methods and known vulnerabilities such as CVE-2024-40766. Organizations face increased pressure to secure not only device firmware but also backup repositories and credentials, underscoring the persistent threat of credential-based and configuration compromise attacks.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

