✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 5245 to 5256 of 5299
Jaguar Land Rover Ransomware Breach Disrupts Global Operations in 2024
In June 2024, Jaguar Land Rover (JLR), the renowned luxury automotive manufacturer, experienced a major ransomware-related cyber incident that forced the company to shut down vital portions of its IT infrastructure. The disruption, which began on a Sunday and quickly affected production and retail activities globally, resulted in assembly line stoppages at key UK plants including Halewood and Solihull. JLR responded by disabling systems to prevent further attacker movement and data loss, launching an internal investigation with forensics partners to determine entry vectors, potential data exposure, and persistent threats. While the company stated there was no evidence of customer data being compromised, the operational and financial impacts were significant. This incident underscores the ongoing trend of ransomware actors targeting critical manufacturing and supply chain operations, where downtime can rapidly translate into massive losses. The event serves as a stark reminder that even mature organizations face evolving threats that can bypass traditional security controls, highlighting the urgent need for zero trust segmentation, enhanced network monitoring, and rapid anomaly detection.
7 months ago
Kill Chain
45 New Domains Fuel Salt Typhoon's Stealthy APT Campaign (2024)
In mid-2024, security researchers uncovered that the China-based Advanced Persistent Threat group Salt Typhoon (UNC4841) had deployed 45 new domains and previously undiscovered infrastructure to facilitate persistent, stealthy compromises of targeted organizations. Exploiting their advanced tradecraft, Salt Typhoon gained and maintained long-term access undetected, leveraging encrypted traffic and lateral movement techniques. The attacks primarily targeted sectors with sensitive data and critical infrastructure, amplifying operational and reputational risk for the victims. The campaign demonstrates ongoing actor adaptation and the challenges of detecting covert infrastructure expansion. This incident is especially relevant as organizations face a surge in nation-state actor activity leveraging novel infrastructure and sophisticated evasion methods. The discovery highlights the evolving threat landscape, where increased regulatory pressure and cloud adoption make comprehensive visibility and proactive response capabilities more critical than ever.
7 months ago
Kill Chain
2025 NPM Supply Chain Breach: Phishing Attack on JavaScript Developer Risks Crypto Theft
In September 2025, a targeted supply chain attack compromised at least 18 widely used JavaScript packages on the NPM repository after a key developer, Josh Junon, was phished. The attackers created a convincing fake NPM login website, stealing both credentials and a one-time 2FA token to access the developer's account. They injected malicious code into popular packages, enabling browser-based interception of cryptocurrency transactions and redirection of funds to attacker-controlled wallets. The breach was discovered rapidly by Aikido, which alerted the maintainer, enabling a swift cleanup and limiting broader damage. This incident underscores the persistent risks lurking in open-source software supply chains, particularly as threat actors evolve their tactics to bypass conventional security controls using phishing and social engineering. The rapid containment averted a potentially devastating impact, but the episode highlights ongoing vulnerabilities in software ecosystems reliant on centralized package maintainers.
7 months ago
Kill Chain
Iran MOIS Targets Diplomatic Missions Worldwide in Sophisticated Phishing Campaign (2024)
Between August and September 2024, the Iranian state-affiliated APT group 'Homeland Justice,' linked to Iran’s Ministry of Intelligence (MOIS), orchestrated a sophisticated phishing campaign targeting over 50 embassies, government ministries, and international organizations across six continents. Attackers leveraged more than 100 hijacked, legitimate email accounts, using them to distribute infostealing malware concealed in macro-laden Word documents, often themed around timely geopolitical topics. These emails were sent via VPNs to obfuscate their true origin and bypassed basic email filtering due to the use of authentic sender addresses. This incident highlights the sustained threat posed by nation-state actors employing classic social engineering methods with modern evasion techniques. The resurgence of macro-enabled attacks and increasing abuse of compromised trusted accounts point to evolving risk vectors for governmental and international bodies, underscoring the need for continuous vigilance and upgraded detection capabilities.
7 months ago
Kill Chain
MostereRAT Malware: New Era of EDR Bypass and Persistent Threats
In 2024, security researchers uncovered a sophisticated campaign deploying the 'MostereRAT' malware against Windows environments. The threat actor used advanced techniques to deliver an EDR (Endpoint Detection and Response)-killing tool, enabling long-term, covert persistence on infected systems. MostereRAT blends into legitimate network traffic, leverages encrypted channels, and systematically disables or bypasses security controls, making detection and remediation difficult. Impacted organizations faced risks of data exfiltration, lateral movement, and significant business disruption, with attackers maintaining access for extended periods before discovery. This incident highlights the increasing prevalence of anti-EDR malware designed to counter modern defensive capabilities. As organizations adopt stronger endpoint security, attackers are deploying stealthier, more evasive malware, presenting ongoing challenges for incident detection, compliance, and cyber resilience.
7 months ago
Kill Chain
Logit-Gap Steering: New Jailbreak Threat Undermines LLM Security in 2024
In mid-2024, academic security researchers unveiled a novel attack against large language models (LLMs) termed "logit-gap steering." This technique exploits the mathematical limits of alignment training by manipulating the logits—the raw output probabilities—of refusal and affirmation tokens. Attackers found that by identifying and minimizing the gap through tailored prompt suffixes, they could frequently bypass internal model guardrails and elicit harmful or disallowed responses, even on the latest open-source models such as gpt-oss-20b, LLama, Gemma, and Qwen. The published methodology demonstrated over 75% attack success rates and triggered industry-wide concern about the resilience of current AI safety controls. This incident comes at a pivotal time as organizations accelerate adoption of AI and generative language models in production. The research spotlights a significant, previously underestimated vector for LLM jailbreak attacks, amplifying regulatory scrutiny and forcing enterprises to re-evaluate security practices for AI deployments.
7 months ago
Kill Chain
2025 Retail Salesforce Data Heist: Extortion Attack Exposes Cloud Security Gaps
In mid-2025, a sophisticated data extortion campaign targeted high-end retail organizations leveraging Salesforce environments. Threat actors—identified as UNC6040 (responsible for access and reconnaissance) and Bling Libra (aka ShinyHunters, handling extortion)—gained initial access through voice-based phishing (vishing) techniques. After establishing a foothold, they conducted in-depth reconnaissance to collect sensitive customer data, including names, birthdates, contact details, and account metadata, which was then exfiltrated. The attackers threatened public disclosure unless the victim organizations paid a ransom, all while leaving minimal forensic traces due to a lack of malware deployment and custom tools. This incident highlights the increasing sophistication of financially motivated cybercrime operations and an industry-wide shift towards data theft extortion without ransomware. There is an urgent need for retail and cloud-reliant enterprises to reassess their security controls, as social engineering vectors bypass traditional perimeter defenses and regulatory scrutiny around cloud data protections intensifies.
7 months ago
Kill Chain
Exploits for Dassault DELMIA Apriso RCE (CVE-2025-5086) Target Manufacturing Operations
In June 2025, Dassault Systèmes disclosed a critical deserialization vulnerability (CVE-2025-5086) in its DELMIA Apriso Manufacturing Operation Management system, affecting releases from 2020 through 2025. Attackers exploited this remote code execution flaw via crafted SOAP requests containing malicious serialized data, enabling them to upload and execute arbitrary Windows executables on vulnerable servers. The exploit activity, orchestrated through automated scanners—some associated with the Project Discovery framework—originated from multiple geographies and targeted the core manufacturing process integration point, posing risks to operational uptime and potential lateral movement within enterprise environments. This incident underscores the growing threat targeting industrial control applications and critical infrastructure through software supply chain vulnerabilities. Exploiting deserialization bugs in widely deployed operational technology platforms has become a preferred method for threat actors, highlighting the urgent need for timely patching, application-layer anomaly detection, and zero trust segmentation within manufacturing and industrial settings.
7 months ago
Kill Chain
Remote Code Execution via Model Namespace Reuse Hits AI Supply Chains
In early 2024, security researchers identified a novel AI supply-chain attack involving 'model namespace reuse' on popular machine learning platforms such as Hugging Face. Threat actors exploited the inherent trust in model names and namespaces to upload malicious AI models, thereby enabling remote code execution upon download or integration into downstream applications. The attack allowed adversaries to compromise systems within seconds of a user or developer integrating tainted models, potentially resulting in data breach, lateral movement, or disruption of AI-driven business processes. This incident underscores the growing risk within the AI and ML ecosystem, where reliance on third-party and community-contributed models is accelerating. As more organizations rapidly adopt AI across production workloads, supply-chain vulnerabilities like namespace reuse present urgent challenges for security and compliance.
7 months ago
Kill Chain
Sextortion at Scale: Lessons from 1,900 Cryptocurrency Extortion Emails (2021–2025)
Between June 2021 and August 2025, researchers analyzed nearly 1,900 sextortion emails sent globally as part of orchestrated financial extortion campaigns. Threat actors leveraged email as the primary attack vector, issuing blackmail demands and requesting payments to over 200 unique cryptocurrency addresses (primarily Bitcoin). The attackers frequently rotated wallet addresses to hinder tracing, with most being active for only a few days. While 28% of the wallet addresses received no payments, the majority collected varied sums, with a median received amount of approximately $4,315 per address; a handful captured large sums exceeding $75,000. These campaigns underline the continuing prevalence and evolution of cryptocurrency-enabled extortion tactics. Sextortion remains a persistent cybercrime threat, with campaigns adapting to changes in cryptocurrency use and email security. Recent analysis suggests a downward trend in victim willingness to pay, potentially reflecting higher user awareness and stronger resilience to such scams, but attackers are refining techniques to maintain extortion income.
7 months ago
Kill Chain
The New Insider Threat: How a Fake Employee Infiltrated a Tech Giant in 2025
In August 2025, an advanced cyberattack targeted a major tech company when an attacker successfully joined the organization as a new employee using a fabricated identity, bypassing digital and in-person HR and IT onboarding checks. The attacker, under the alias 'Jordan from Colorado,' leveraged expertly forged credentials and references to gain legitimate system access and privileges from day one. Once inside, the attacker rapidly accessed sensitive data, established lateral footholds through internal network movement, and deployed covert remote access tools. The business suffered significant intellectual property theft and operational disruptions before the activity was detected during a routine audit. The incident demonstrates a rising trend in identity-based infiltration, where social engineering is used not to breach perimeters but to abuse trusted onboarding processes. This kind of attack highlights the urgent need for organizations to modernize identity verification and insider threat detection in response to sophisticated credential fraud and evolving attacker tradecraft.
7 months ago
Kill Chain
Gambler Panel: The Rise of Affiliate-Driven Scam Gambling Operations in 2025
In July 2025, researchers uncovered a rapid proliferation of fraudulent online gambling platforms connected to a Russia-based affiliate operation called 'Gambler Panel.' This scheme enables thousands of affiliates to launch polished scam gambling sites using a turnkey fake casino engine and aggressive social media lures—often involving fraudulent endorsements and false claims of free credits. Victims are tricked into making cryptocurrency 'verification deposits' which are subsequently stolen, with attempts to cash out consistently denied. The operation is highly organized, offering detailed playbooks and infrastructure supporting over 1,200 domains run by a network of more than 20,000 affiliates. This incident highlights a new, scalable model for financial fraud: cybercriminals outsourcing risk and execution to large affiliate networks via sophisticated, multi-platform campaigns. The case underscores the dangers posed by accessible, turnkey scam infrastructure and the challenges organizations face in monitoring affiliate-driven threat activity targeting consumers globally.
7 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.

Attackers Learned to Use AI. Now They Built Tools to Destroy It.

Living-off-the-Agent: How AI Tool Misuse Became the Insider Threat Nobody Provisioned
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

