✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 5149 to 5160 of 5299
SonicWall Cloud Backup Breach: Firewall Configurations Compromised, Credential Resets Urged
In September 2025, SonicWall disclosed a cloud security incident that exposed firewall configuration backup files tied to less than 5% of MySonicWall accounts, prompting a company-wide advisory to reset credentials for impacted users. The breach involved unauthorized access to backup firewall preference files hosted in SonicWall’s cloud backup service, which could potentially allow attackers insight into sensitive network policies and infrastructure details. Upon detection, SonicWall revoked affected credentials, reset authentication tokens, and notified regulatory authorities and end-users. The incident underscores operational risks associated with cloud-based configuration repositories and the downstream consequences for enterprise security posture. This breach highlights ongoing attacker focus on cloud storage services and device configuration files, which are increasingly targeted for initial access or lateral movement. As regulatory scrutiny grows and advanced threats seek out persistent footholds, organizations face mounting urgency to harden cloud storage, segment sensitive data, and enforce continuous credential hygiene.
7 months ago
Kill Chain
CountLoader: The Russian Ransomware Loader Redefining Post-Exploitation in 2025
In September 2025, cybersecurity researchers uncovered a major campaign involving CountLoader, a newly identified malware loader leveraged by Russian ransomware gangs. CountLoader has been deployed to infiltrate organizations by delivering post-exploitation tools such as Cobalt Strike, AdaptixC2, and the PureHVNC RAT via sophisticated phishing and initial access broker (IAB) operations. Notably, the loader is associated with affiliates of the LockBit ransomware group and is suspected to support both initial access sales and direct ransomware attacks. The campaign enabled attackers to establish stealthy persistence and remote control over compromised environments, amplifying threats of data theft, lateral movement, and disruptive encryption attacks. This incident highlights the growing adoption of multi-stage loader malware by established ransomware actors, blending traditional and cutting-edge post-exploitation tools for maximum impact. The tactics seen here illustrate the evolving, service-based ransomware ecosystem—one where payload delivery, access brokering, and command-and-control capabilities are modular and rapidly evolving in response to network defenses.
7 months ago
Kill Chain
NPM Phishing 2024: Developer Credentials Compromised by Sophisticated Email Lures
In September 2024, a targeted phishing campaign compromised multiple npm developer accounts by using convincing emails and deceptive landing pages such as "npmjs.help" and "npmjs.cam." Attackers exploited commonly overlooked weaknesses in email link validation and human trust, causing even experienced developers to disclose credentials. The attackers leveraged lookalike domains and effective social engineering, leading to account takeovers and enabling potential downstream attacks on open-source supply chains. The incident highlighted how traditional security awareness measures and multi-factor authentication (MFA) can be circumvented by advanced phishing tactics. This incident underscores the increasing effectiveness of credential compromise attacks in the software supply chain and the limitations of user training and legacy MFA solutions. As threat actors continue to innovate with sophisticated phishing techniques and pass-through attacks, businesses must urgently reconsider authentication strategies, emphasizing phishing-resistant technologies such as passkeys and cryptographic authenticators.
7 months ago
Kill Chain
Dshield Honeypot Exposes IoT Botnet Worm Using Default Credentials in 2024
In September 2024, analysis of a Dshield honeypot deployed on AWS revealed a campaign targeting internet-exposed systems with IoT-focused botnet malware. Attackers attempted to upload shell scripts and architecture-specific binaries using known default credentials and exploited weak or unchanged passwords, particularly on Raspberry Pi and IoT devices. The payloads, often delivered over unencrypted FTP and SSH methods, led to the installation of UNIX_PIMINE.A malware, which achieves persistence, removes competing malware, and connects to IRC-based command-and-control channels, highlighting an active botnet spreading via automated credential stuffing and remote file uploads. This incident underscores a persistent threat: legacy systems and embedded devices with default or weak credentials remain a prime target for botnets. With continued rises in IoT deployments and exposed services, automated malware propagation using basic scripts and known default logins is resurging, driving renewed regulatory scrutiny and best-practice emphasis for credential management and east-west traffic security.
7 months ago
Kill Chain
GhostRedirector Backdoors Windows Servers with Malicious IIS Modules
In early 2024, ESET researchers uncovered a sophisticated cyber campaign known as GhostRedirector targeting Windows servers worldwide. The attacker employed a passive C++ backdoor and a malicious Microsoft IIS module, granting remote control and enabling the manipulation of Google search results. By compromising internet-facing IIS web servers, the threat actor covertly redirected visitors to malicious domains while maintaining persistent access through undetected, stealthy backdoors. The attack had the potential to facilitate broad influence operations, data exfiltration, and further deployment of malware on compromised networks. This incident highlights the growing risk of advanced web server threats utilizing legitimate application modules for stealthy persistence. Such tactics reflect a wider trend of attackers exploiting trusted infrastructure and automated SEO poisoning, challenging organizations to strengthen threat detection, zero trust controls, and incident response.
7 months ago
Kill Chain
HybridPetya Ransomware: UEFI Secure Boot Under Attack in 2024
In June 2024, ESET researchers discovered a ransomware variant dubbed HybridPetya, modeled after the infamous Petya/NotPetya malware, with a significant escalation in its capabilities. HybridPetya leverages the CVE-2024-7344 vulnerability to compromise UEFI-based systems, effectively bypassing Secure Boot protections on outdated hardware. Although not known to be active in broad campaigns, this bootkit joins a small group of malware capable of undermining the fundamental trust mechanisms securing modern machines, representing a sophisticated evolution in ransomware delivery and persistence techniques. HybridPetya’s emergence highlights the rapid adaptation of cybercriminals to harden malware against defensive controls. UEFI bootkit methods—once advanced nation-state territory—are now appearing in ransomware. Organizations must urgently review endpoint protections, hardware patching, and secure boot configurations to lower exposure to these new attack paths.
7 months ago
Kill Chain
HybridPetya Ransomware: UEFI Secure Boot Bypass Proof-of-Concept Shakes Firmware Security
In July 2025, ESET Research uncovered HybridPetya, a proof-of-concept ransomware closely mimicking the destructive Petya and NotPetya malware. HybridPetya features a novel UEFI bootkit component, capable of targeting both legacy and modern UEFI-based systems by exploiting CVE-2024-7344 to bypass Secure Boot protections. The malware operates by encrypting the Master File Table on NTFS partitions, leveraging advanced techniques such as malicious EFI application deployment and fake CHKDSK screens to evade detection. To date, ESET’s telemetry has found no evidence of HybridPetya in active attacks, and its development suggests an evolving threat landscape for ransomware targeting core system components. HybridPetya’s public discovery underscores an alarming trend: sophisticated ransomware is expanding its reach to firmware and boot processes, previously considered resilient to commodity malware. The rise of UEFI-targeting threats and Secure Boot bypass exploits highlights the urgent need for rigorous patch management and endpoint visibility, especially as new vulnerabilities (like CVE-2024-7344) become weaponized.
7 months ago
Kill Chain
Apple Patches 100+ Vulnerabilities in 2025: What Enterprises Need to Know
In September 2025, Apple released security updates for iPhones, iPads, Macs, and other products, addressing a total of over 100 vulnerabilities across its ecosystem. While none of the patched vulnerabilities were reported as actively exploited at the time, two severe macOS bugs (CVE-2025-43298 and CVE-2025-43304) were highlighted for their potential to confer root privileges to attackers. The updates followed a year marked by several Apple zero-days, some previously exploited in highly targeted attacks, underscoring ongoing risks to user data and privacy. Devices released prior to 2019 are no longer supported by the latest OS versions, leaving older hardware at higher risk. This incident highlights the persistent and evolving nature of software vulnerabilities targeting consumer platforms, reinforcing the critical importance of timely patching. With increasing regulatory attention and attackers swiftly weaponizing new bugs, organizations must remain vigilant in threat monitoring and adopt robust patch management practices.
7 months ago
Kill Chain
SonicWall 2024 Breach: Cloud Portal Attack Exposes Firewall Configurations
In June 2024, SonicWall confirmed a security incident impacting its MySonicWall.com portal, where threat actors gained unauthorized access to backup firewall configuration files belonging to fewer than 5% of their customers. The attackers employed targeted brute-force attacks to access encrypted preference files stored in the cloud, potentially exposing sensitive network architecture and policy information. While SonicWall promptly disabled the affected backup feature, notified law enforcement and affected customers, and engaged incident response specialists, the exposure raises substantial risk of follow-on attacks and exploitation due to the detailed nature of the data compromised. This incident highlights a growing concern with threats targeting cloud-managed administrative platforms, especially those operated by key infrastructure vendors. As attackers pivot from device exploits to systemic attacks on cloud portals, organizations must scrutinize cloud data storage and vendor security practices more rigorously to mitigate downstream and supply chain risks.
7 months ago
Kill Chain
Microsoft Seizes RaccoonO365: 2024’s Largest Phishing-as-a-Service Credential Theft Takedown
In July 2024, Microsoft’s Digital Crimes Unit, in collaboration with law enforcement and cybersecurity partners, led a takedown of RaccoonO365—a subscription-based phishing-as-a-service platform operated by the threat group Storm-2246. Over 338 domains linked to RaccoonO365 were seized after being used to steal more than 5,000 Microsoft credentials across 94 countries since July 2024. The group’s kits, leveraging sophisticated evasion techniques and authentic-looking Microsoft branding, enabled cybercriminals to mount tax-themed and healthcare-targeted phishing campaigns, with sessions often bypassing multifactor authentication to harvest both passwords and session cookies. The breadth and pace of RaccoonO365’s operations highlight the commoditization and professionalization of cybercrime. This incident signals a shift towards scalable, as-a-service attack tools, increasing risks to organizations globally. Security teams must rapidly adapt to evolving TTPs and plug new identity-driven attack pathways, especially as phishing toolkits grow in accessibility and sophistication.
7 months ago
Kill Chain
CHILLYHELL and ZynorRAT: Cross-Platform RATs Evade Detection, Threaten Enterprise Environments (2025)
In September 2025, security researchers from Jamf Threat Labs uncovered two sophisticated malware strains: CHILLYHELL, a modular backdoor targeting macOS systems, and ZynorRAT, a Go-based remote access trojan spreading across Windows and Linux environments. CHILLYHELL, written in C++ for Intel macOS architectures, enables persistent remote access and exfiltrates sensitive data, while ZynorRAT facilitates cross-platform attacks and lateral movement. Both threats leverage encrypted communications and modular payloads to evade detection and expand their reach, highlighting attackers’ increasing investment in multi-OS toolkits. The campaign impacted diverse sectors by undermining endpoint trust and exposing organizations to data breaches, extortion, and operational disruption. This incident reflects an ongoing surge in cross-platform malware development, with adversaries targeting heterogeneous enterprise environments using advanced, modular code. The discovery underscores heightened regulatory scrutiny around endpoint security, zero trust enforcement, and incident response as ransomware and espionage risks escalate.
7 months ago
Kill Chain
Chinese APT Bypasses Philippine Military Defenses with EggStreme Fileless Malware (2025)
In September 2025, a Chinese advanced persistent threat (APT) group breached a Philippines-based military company using a sophisticated multi-stage attack leveraging the novel fileless malware framework, EggStreme. According to Bitdefender, the attackers achieved persistence and stealth by injecting their malicious code directly into memory and utilizing DLL sideloading to execute payloads without writing files to disk. This allowed them to maintain an undetected presence, conduct espionage, and potentially exfiltrate sensitive military and government data. The breach underscores ongoing risks to national security organizations from highly resourced nation-state actors employing advanced techniques. This incident highlights the emergence of more evasive, memory-resident malware frameworks targeting defense and critical infrastructure. Fileless attack methods such as those used by EggStreme are increasingly common and harder to detect, urging organizations to adopt advanced threat detection, improved segmentation, and robust incident response capabilities.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

