✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 5173 to 5184 of 5299
Phoenix RowHammer: How Advanced DDR5 Memory was Hacked in 2025
In August 2025, researchers from ETH Zürich and Google unveiled "Phoenix," a sophisticated RowHammer attack variant (CVE-2025-6202, CVSS 7.1) targeting SK Hynix DDR5 memory chips. Despite modern hardware defenses, Phoenix exploits advanced memory vulnerabilities to flip bits in protected memory rows, fully bypassing current mitigation technologies. The attack achieved successful exploitation in as little as 109 seconds, highlighting a critical weakness in memory protection schemes and raising concern for sensitive computing environments, from cloud servers to critical infrastructure. This incident demonstrates the evolving threat landscape for hardware-level attacks, emphasizing the urgency for chipmakers and enterprises to scrutinize and enhance DDR5 memory protections. Ongoing research into side-channel and memory-based exploitation, alongside increasing hardware reliance, make this a timely warning for organizations relying on modern DRAM.
7 months ago
Kill Chain
Apple 2025 ImageIO Zero-Day Breach Highlights Spyware Risks
In September 2025, Apple urgently released backported security updates to address CVE-2025-43300, a critical out-of-bounds write vulnerability in the ImageIO component exploited by advanced spyware campaigns. Attackers leveraged malicious image files to trigger memory corruption on Apple devices, enabling remote code execution and potential device takeover. The exploit was actively seen in targeted attacks against high-profile individuals, emphasizing the risk of spyware abusing zero-day vulnerabilities for persistent surveillance. The incident underscores the growing sophistication and frequency of attacks exploiting media processing flaws. This breach highlights an intensifying trend of threat actors using zero-day vulnerabilities in consumer devices for espionage. It demonstrates how attackers pivot to less-monitored device components and rapidly weaponize novel flaws, reinforcing the urgent need for continuous patching and proactive detection of anomalous behaviors on endpoints.
7 months ago
Kill Chain
SlopAds: How 224 Android Apps Fueled a $Billion Ad Fraud Scam in 2025
In late 2025, the SlopAds ad fraud ring was exposed running a sophisticated scheme across 224 Android applications, amassing more than 38 million downloads globally. The attackers covertly embedded steganography-based payloads within these apps, enabling them to generate hidden WebViews and surreptitiously route ad clicks and impressions to threat actor-controlled cashout sites. This campaign resulted in a staggering 2.3 billion daily fraudulent ad bids, undermining advertiser spending and trust in mobile advertising. Investigations revealed that the fraud operated across 228 countries and leveraged advanced techniques to evade security controls and detection. This incident highlights a growing trend in large-scale, automated digital ad fraud utilizing supply chain infiltration and advanced evasion. With mobile devices as primary attack surfaces and threat actors exploiting application distribution ecosystems, organizations face heightened regulatory scrutiny, financial risk, and an urgent need for granular visibility, segmentation, and anomaly detection capabilities.
7 months ago
Kill Chain
Multilingual Phishing: FileFix Variant Delivers StealC Infostealer in 2025
In September 2025, security researchers identified a sophisticated phishing campaign delivering a new variant of the StealC information-stealer malware via a convincing, multilingual phishing website impersonating popular brands such as Facebook Security. The attackers leveraged advanced social engineering tactics, widespread language support, heavy anti-analysis measures, and advanced obfuscation to successfully bypass traditional security detections. The campaign’s initial access was achieved through social engineering, leading victims to download malicious payloads disguised as legitimate files, which, once executed, exfiltrated credentials and sensitive data at scale. This incident highlights an ongoing surge in multilingual, highly tailored phishing approaches that utilize advanced anti-detection techniques, making detection and mitigation more difficult. Organizations face mounting pressure to strengthen controls against information stealers as attackers adapt proven TTPs to bypass endpoint protection and target a global victim base.
7 months ago
Kill Chain
Chaos Mesh Critical GraphQL Flaws Put Kubernetes Clusters at Risk in 2025
In September 2025, multiple critical vulnerabilities were discovered in Chaos Mesh, a popular cloud-native chaos engineering platform, exposing Kubernetes clusters to remote code execution (RCE) via unauthenticated GraphQL endpoints. Attackers with minimal in-cluster network access could exploit these flaws to execute arbitrary code, trigger disruptive fault injections (such as pod deletion and network outages), and ultimately achieve full cluster takeover. The vulnerability stemmed from insufficient access controls and improper GraphQL API handling, allowing adversaries to escalate privileges and compromise cluster workloads. As a result, organizations relying on Chaos Mesh in production faced heightened risk to workload integrity and business continuity until patches were applied. This breach highlights the increasing threat to supply-chain components in cloud-native environments, where tools with high privileges can inadvertently expose entire clusters. The rapid disclosure and fix cycle signals a need for strict RBAC, vigilant monitoring, and timely patching as attacker focus shifts towards exploiting platform-level risks.
7 months ago
Kill Chain
Microsoft & Cloudflare Dismantle RaccoonO365 Global Phishing Network (2025)
In September 2025, Microsoft’s Digital Crimes Unit (DCU), in partnership with Cloudflare, coordinated a global takedown of the RaccoonO365 phishing network. The PhaaS operation leveraged 338 domains to deliver convincing Microsoft 365 phishing campaigns, compromising over 5,000 credentials across 94 countries since July 2024. By obtaining a court order from the Southern District of New York, DCU seized infrastructure used by the financially motivated RaccoonO365 group, disrupting ongoing credential theft and reducing further business email compromise (BEC) risk to organizations worldwide. This incident underscores the rapid evolution and global scale of phishing-as-a-service networks, which are automating credential theft across cloud platforms. As attackers exploit trusted SaaS brands with commodity toolkits, vigilance around cloud identity and supply chain access is now a critical board-level concern.
7 months ago
Kill Chain
Scattered Spider Returns: New Wave of Social Engineering Attacks on Financial Services
In late 2025, cybersecurity researchers at ReliaQuest linked a new wave of attacks in the financial services sector to the notorious cybercrime collective Scattered Spider, despite previous claims that the group had disbanded. These attacks featured advanced social engineering tactics, the registration of lookalike domains, and exploitation of internal access paths to facilitate credential compromise and lateral movement inside targeted organizations. Impact resulted in unauthorized access to sensitive financial data, disruption of key operations, and raised concerns about the sector’s preparedness for sophisticated, identity-driven threats. The re-emergence of Scattered Spider underscores a resurgence of high-profile, financially motivated cybercrime against critical industries. The campaign highlights the evolving threat landscape—where even 'retired' threat groups rapidly adapt their tactics—reinforcing the urgency of east-west security monitoring, identity protections, and robust zero trust strategies.
7 months ago
Kill Chain
DOJ Resentences BreachForums Founder in 2025 Cybercrime Marketplace Crackdown
In September 2025, the U.S. Department of Justice resentenced Conor Brian Fitzpatrick—known online as Pompompurin and the former administrator of the notorious BreachForums cybercrime marketplace—to three years in prison. Fitzpatrick pleaded guilty after orchestrating access device fraud and facilitating the sale of stolen data, in addition to possessing child sexual abuse material (CSAM). BreachForums had become a major platform for trading compromised credentials, payment card information, and illicit content before law enforcement seized the site and apprehended its leader. The takedown disrupted a key meeting ground for cybercriminals involved in massive data breaches and identity theft operations. This incident underlines heightened law enforcement focus on cybercrime forums as hubs for illegal commerce, reflecting rising pressure on both administrators and users. The prosecution of BreachForums’ founder highlights regulatory and investigative trends aimed at deterring similar platforms and enforcing accountability for cyber-enabled offenses.
7 months ago
Kill Chain
TA558 Leverages AI-Generated Scripts to Deploy Venom RAT in 2025 Brazilian Hotel Attacks
In the summer of 2025, the threat actor group TA558 launched a series of targeted phishing campaigns against hotels and the hospitality sector in Brazil and other Spanish-speaking regions. Leveraging AI-generated scripts, TA558 distributed Remote Access Trojans (RAT) such as Venom RAT via malicious email attachments disguised as business invoices. The attackers gained unauthorized access to hotel infrastructure, enabling surveillance, data theft, and lateral movement within targeted environments. Kaspersky researchers attributed the activity to the RevengeHotels cluster and noted reliance on sophisticated social engineering and automation. This incident exemplifies the rising integration of AI in cyberattacks, increasing the efficacy and resilience of threat actors like TA558. Organizations in hospitality and other sectors with valuable customer data face growing risks from AI-driven malware and must adapt their defenses to faster-evolving adversarial techniques.
7 months ago
Kill Chain
Chinese TA415 Breaches US Economic Policy Experts Using VS Code Remote Tunnels
In mid-2025, the China-aligned threat actor TA415 launched a sophisticated spear-phishing campaign targeting U.S. government agencies, economic policy think tanks, and academic organizations. The attackers leveraged social engineering tactics, masquerading as high-profile U.S. officials, and delivered phishing emails containing malicious links. Through these lures, TA415 exploited Visual Studio Code Remote Tunnels—a legitimate feature used for remote development—to establish persistent, covert remote access within target environments. This allowed them to conduct extended espionage operations, exfiltrate sensitive economic policy data, and evade traditional endpoint and network defenses. The attack highlights the convergence of advanced phishing techniques with legitimate remote access tools, underscoring a shift toward stealthy, “living off the land” tactics by nation-state adversaries. Organizations are urged to address internal monitoring, east-west security, and robust detection of unauthorized remote connectivity, as similar techniques are expected to proliferate across sectors.
7 months ago
Kill Chain
ChillyHell: The macOS Backdoor That Outsmarted Notarization in 2024
In early May 2024, security researchers from Jamf Threat Labs identified a new version of the previously dormant "ChillyHell" modular backdoor targeting macOS systems. Initially observed in attacks against Ukrainian officials in 2021 and reported again by Mandiant in 2023, ChillyHell resurfaced in a sample uploaded to VirusTotal and discovered to have been publicly hosted on Dropbox. The malware achieves persistence through multiple mechanisms, brute-forces passwords, exfiltrates sensitive data, and communicates over several protocols, all while leveraging Apple notarization to evade detection before its certificates were revoked. With built-in timestamp manipulation and extensive C2 capabilities, ChillyHell poses a significant risk to macOS enterprise environments, blending stealth, flexibility, and longevity in its operations. This incident underscores the growing sophistication and targeting of macOS platforms by advanced threat actors, moving beyond Windows-centric malware trends. The use of valid codesigning and notarization further demonstrates challenges for defenders, highlighting the need for robust detection controls and ongoing vigilance for notarized—but malicious—macOS software.
7 months ago
Kill Chain
Chinese Hackers Impersonate US Congressman in Sophisticated 2024 Spear-Phishing Campaign
In early 2024, Chinese state-sponsored hackers allegedly orchestrated spear-phishing attacks by impersonating Michigan Congressman John Moolenaar. The threat actors crafted convincing emails designed to gain the trust of recipients, targeting government and private sector individuals. Using tailored messaging, the adversaries sought to trick victims into engaging with malicious links or attachments, potentially enabling credential theft, malware installation, or further lateral movement within targeted organizations. The incident demonstrates the growing sophistication and persistence of social engineering tactics deployed by advanced persistent threat (APT) groups with strategic intelligence-gathering objectives. This attack reflects a broader rise in politically themed spear-phishing campaigns leveraging impersonation of public officials to increase credibility. Organizations must remain alert as nation-state groups continually evolve their tactics, conducting highly targeted attacks that bypass technical safeguards and prey on human vulnerabilities.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

