✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 5221 to 5232 of 5299
AsyncRAT Attackers Exploit ConnectWise ScreenConnect—Credential & Crypto Theft on the Rise
In September 2025, cybersecurity researchers identified a sophisticated attack leveraging the ConnectWise ScreenConnect remote monitoring tool to deliver AsyncRAT, a potent remote access trojan. Threat actors exploited legitimate RMM infrastructure to establish unauthorized access, bypass defenses, and deploy a VBScript-based loader on victim systems. Once installed, AsyncRAT facilitated unauthorized credential harvesting and cryptocurrency theft from compromised hosts, exposing sensitive business and personal data. The campaign’s use of trusted IT management software as an initial entry vector complicated detection and posed significant risks to organizations relying on remote administration tools. This incident underscores an increasing security challenge: the abuse of legitimate remote management solutions by attackers to evade detection and propagate malware. As identity-driven and tool-based attacks surge, businesses must re-examine their controls, segmentation, and monitoring to counter exploitation of sanctioned IT utilities.
7 months ago
Kill Chain
Microsoft September 2025 Patch Tuesday: Critical Vulnerabilities in Cloud, URL Security Zones, and More
On September 9, 2025, Microsoft released its September Patch Tuesday updates, addressing 177 vulnerabilities across its ecosystem, including 86 that impacted Microsoft products directly. Among these, 13 were rated as critical, and two had already been publicly disclosed. Notable vulnerabilities included improper URL security zone classification (CVE-2025-54107, CVE-2025-54917), which could allow attackers to bypass security features, and several remote code execution flaws affecting critical workloads. While none of these vulnerabilities were exploited before disclosure, their wide range—including issues in Azure, Office, and the Windows kernel—signals continued risk across cloud and on-premises environments. These vulnerabilities highlight evolving attacker techniques, such as zone misclassification and privilege escalation in cloud services, while underscoring the complexity of patch management in hybrid infrastructures. The scale of affected Microsoft and open-source components (like Azure Linux/Mariner) points to the growing regulatory and operational urgency for comprehensive and timely vulnerability management.
7 months ago
Kill Chain
Vyro AI 2024 GenAI Data Leak: Why Cyber Hygiene Can't Wait
In early 2024, Vyro AI experienced a significant data leak involving the unintentional exposure of proprietary and sensitive user data via a GenAI platform. The incident occurred when internal users, unaware of best security practices, shared confidential information with generative AI tools that did not have adequate encryption or access controls. This exposed private data to unauthorized individuals and third parties, highlighting deficiencies in the company’s data protection policies and cloud application oversight. This breach is emblematic of the growing risks associated with GenAI usage in enterprise environments, where shadow IT and user-driven data sharing can sidestep traditional security controls. As organizations adopt AI at scale, ensuring robust data governance and compliance is more critical than ever to avoid regulatory and reputational fallout.
7 months ago
Kill Chain
VMScape: 2025’s Critical Hypervisor Isolation Attack Exposes Cloud Risks
In September 2025, security researchers from ETH Zurich disclosed 'VMScape,' a sophisticated side-channel attack that breaks guest-host isolation in virtualized environments by exploiting incomplete speculative execution mitigations in modern AMD and Intel CPUs. The exploit enables a malicious guest VM to leak sensitive data, such as cryptographic keys, from the unmodified QEMU hypervisor memory, bypassing existing Spectre defenses without requiring host compromise. The attack impacts AMD Zen 1–5 and Intel Coffee Lake CPUs, allowing memory leaks at rates that threaten cloud multi-tenancy and data privacy. While VMScape requires deep technical expertise and sustained attack duration, its discovery highlights ongoing challenges in securing virtualization infrastructure against novel hardware-level threats. The incident underscores the need for prompt hardware and software mitigation deployment and a renewed focus on isolation techniques amid rising CPU vulnerability disclosures.
7 months ago
Kill Chain
Apple 2025 Spyware Surge: Targeted Zero-Day Attacks Threaten High-Profile Users
In 2025, Apple issued multiple urgent notifications to users after detecting a series of targeted spyware attacks leveraging zero-day vulnerabilities on iOS devices. According to French CERT-FR, at least four documented incidents since the beginning of the year involved highly sophisticated, zero-click exploits that required no user interaction. Victims included journalists, politicians, lawyers, activists, and executives in sensitive sectors. Attackers used a combination of a patched Apple zero-day (CVE-2025-43300) and a WhatsApp vulnerability (CVE-2025-55177) to compromise devices, potentially granting remote access to communications and sensitive data. Apple recommended enabling Lockdown Mode and soliciting help from digital security hotlines, but did not attribute the attacks to a specific group or region. This incident underscores increasing use of mercenary spyware and zero-day exploits for high-profile targeting, reflecting the growing challenges of defending against advanced persistent threats. The case highlights the urgency for rapid patching, proactive security postures, and global awareness of targeted surveillance campaigns in both the public and private sectors.
7 months ago
Kill Chain
Ascension Health 2024: Kerberoasting Ransomware Attack Exposes Microsoft Security Risks
In May 2024, Ascension Health experienced a major ransomware breach, impacting over 5.6 million patient records. Attackers exploited a contractor’s click on a malicious Bing search result in Microsoft Edge, leveraging a 'Kerberoasting' attack against Microsoft Active Directory. By abusing weak and legacy RC4-encrypted Kerberos service account credentials, attackers escalated privileges and moved laterally across sensitive healthcare infrastructure, ultimately exfiltrating patient data and disrupting operations. The incident highlighted significant shortcomings in Microsoft's default security settings and communication of critical risks to enterprise customers, even after prior warnings from security experts and U.S. government officials. The breach is emblematic of a rising trend in identity-based and ransomware attacks exploiting outdated cryptographic standards across critical infrastructure sectors, especially healthcare. Regulatory and public scrutiny on vendor responsibility, ransomware defense, and secure default configurations have intensified following this high-profile compromise.
7 months ago
Kill Chain
Panama Ministry of Economy Breach: INC Ransomware’s 2025 Attack Explained
In September 2025, Panama's Ministry of Economy and Finance (MEF) announced a cyber incident after the INC Ransomware gang claimed liability for a breach. The ministry reported detecting malicious software on one workstation, activating security protocols, and asserting no core systems or sensitive data were affected. However, INC Ransom posted evidence and claimed to have exfiltrated over 1.5 TB of emails, financial, and budgeting documents from MEF. The threat actor listed MEF on its leak site and began releasing data samples, raising concerns about the extent of exposure. This incident underscores the continued evolution and impact of ransomware-as-a-service (RaaS) operations targeting government and finance sectors. With INC Ransom’s repeated high-profile attacks, the breach reflects the growing risk of sophisticated data theft and extortion campaigns confronting public sector organizations globally.
7 months ago
Kill Chain
2025 Cursor AI Code Editor Vulnerability: Supply-Chain Risk via Malicious Repositories
In September 2025, a security flaw was disclosed affecting Cursor, an AI-powered code editor, that allowed silent code execution when users opened repositories embedded with malicious payloads. The vulnerability stemmed from a default-disabled security setting, letting attackers execute arbitrary code on victim machines under their own user privileges. Security researchers highlighted the risk of potential supply-chain attacks, as any developer opening a tampered repository could unwittingly trigger the exploit, potentially leading to credential theft, system compromise, or further lateral movement within organizational networks. The impact was amplified by Cursor's AI-driven capabilities and its popularity in modern development environments. This incident spotlights the growing risks at the intersection of AI-driven tools and software supply chains. With more organizations relying on smart code editors and automated workflows, attackers are increasing their focus on weaknesses in tool defaults and developer behaviors, driving regulatory concern and heightening the urgency for robust code execution safeguards.
7 months ago
Kill Chain
Cryptojacking Surge: TOR-Based Attack Exploits Docker API Misconfigurations in 2025
In July 2025, cybersecurity researchers identified a new wave of cryptojacking attacks leveraging the TOR network to hide command-and-control infrastructure. Attackers targeted internet-exposed and misconfigured Docker APIs, deploying malicious containers that mined cryptocurrency on compromised infrastructures. This campaign, tracked by Akamai and initially reported by Trend Micro in June 2025, showed sophisticated behaviors including blocking rival threat actors and securing persistence, which increased the impact on affected organizations by silently draining cloud computing resources and escalating operational costs. This incident highlights the growing convergence of container security risks and anonymizing networks like TOR, reflecting a broader trend of attackers shifting toward stealthy, infrastructure-focused exploits. With cloud-native workloads and container orchestration becoming standard, organizations face urgent regulatory and operational pressure to harden APIs and improve cloud security hygiene.
7 months ago
Kill Chain
Ransomware Surge Hits State & Local Agencies: Lessons from Nevada and St. Paul
In August 2024, both the State of Nevada and the City of St. Paul, Minnesota, experienced disruptive ransomware attacks that resulted in significant outages and data theft. Attackers exploited gaps in cybersecurity readiness and funding reductions to compromise critical municipal systems, leading to the shutdown of public services and exfiltration of sensitive information. Incident response efforts included engagement with federal agencies like the FBI and CISA, although full recovery remained ongoing for several weeks and required costly investigations, with losses projected to reach $17 million for St. Paul alone. These incidents illustrate the rising threat to smaller government entities, exacerbated by declining federal cybersecurity resources. The sophistication and operational impact of ransomware attacks continue to increase, underscoring urgent calls for improved resilience, incident response planning, and investment in cyber hygiene—especially amid tightening budgets and evolving threat tactics.
7 months ago
Kill Chain
How Salt Typhoon & Volt Typhoon Forced a U.S. Critical Infrastructure Cybersecurity Rethink
Between 2021 and 2023, advanced Chinese threat actors known as Salt Typhoon and Volt Typhoon conducted highly covert cyber intrusions targeting U.S. telecommunications networks and critical infrastructure sectors. These groups utilized advanced tactics such as "living off the land," abusing legitimate administrative tools, and blending into east-west network traffic, making detection and remediation extremely challenging for defenders. Their primary objectives ranged from long-term espionage and persistent access to prepositioning for potential disruptive attacks in the event of geopolitical conflict. The hacks led federal agencies like the FBI and CISA to revise investigative methods, shifting to assume attackers may already be inside the network and forcing collaboration to uncover subtle anomalies rather than clear indicators. This incident is indicative of a broader industry trend: state-backed actors increasingly focus on stealth, cloud environments, and edge devices, targeting managed service providers and exploiting blind spots in monitoring. Their evolving tactics closely align with growing regulatory and CISO concern for stronger east-west visibility, zero trust controls, and continuous threat hunting across hybrid cloud infrastructure.
7 months ago
Kill Chain
npm Supply-Chain Attack Exposes Open-Source Dependencies: 2024 Incident Analysis
In June 2024, a supply-chain attack struck the widely used npm ecosystem when a threat actor compromised developer Josh Junon's account via a phishing-enabled two-factor reset. The attacker injected malicious code into 18 high-download open-source JavaScript packages, including 'ansi-styles', 'chalk', and 'debug', targeting cryptocurrency transactions. Although the incident caused significant alarm due to the downloads’ reach (>2 billion/week), rapid detection by the open-source community and immediate takedown by npm limited the impact. The injected packages were removed within hours, and the attacker ultimately stole just over $1,000 in cryptocurrency. This incident highlights the growing sophistication of supply-chain and social engineering attacks on open-source platforms. As attackers target developer credentials and critical project maintainers, organizations face renewed urgency to reassess their software supply chain controls and dependency management.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

