Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4093 to 4104 of 5957
CIRO 2023 Data Breach Exposes Sensitive Data of 750,000 Canadian Investors
In late 2023, the Canadian Investment Regulatory Organization (CIRO) disclosed that a cyberattack compromised the personal and financial data of approximately 750,000 Canadian investors. The breach, involving unauthorized access to sensitive investor information, stemmed from an attack on a third-party IT provider responsible for maintaining the data. The breach's detection and subsequent investigation prompted CIRO to initiate notification procedures with impacted individuals and regulatory bodies. The incident highlighted critical weaknesses in third-party vendor security, raising concerns about the protection of confidential financial data within the regulated investment sector. This event is particularly relevant as it underscores a growing trend of attacks targeting regulatory and financial organizations via supply chain vectors. With increasing regulatory scrutiny and heightened risks from third-party service providers, organizations face renewed pressure to modernize data protection strategies and enforce robust vendor risk management frameworks.
8 months ago
Kill Chain
Fortinet FortiSIEM CVE-2025-64155: Critical Vulnerability Exploited in the Wild
In June 2025, Fortinet disclosed CVE-2025-64155, a critical command injection vulnerability affecting FortiSIEM, its security information and event management solution. Attackers began exploiting the flaw almost immediately after disclosure, leveraging it to execute unauthorized system commands and gain persistent access across multiple targeted networks. Malicious activity was detected from a diverse array of IP addresses, suggesting widespread probing and potential compromise. The rapid weaponization of the vulnerability placed organizations relying on FortiSIEM at risk of data exfiltration, lateral movement, and potential service disruption, underscoring the importance of timely patch management and layered defenses. This incident is emblematic of a growing trend where attackers aggressively target newly disclosed vulnerabilities in widely used security platforms. The event highlights the urgent need for rapid vulnerability response processes and reevaluation of vendor risk in security-critical infrastructure, as threat actors continue to automate exploitation of critical flaws in security tooling itself.
8 months ago
Kill Chain
Inside the 2024 Payroll Social Engineering Breach: Lessons from the Payroll Pirates
In early 2024, a major payroll provider experienced a sophisticated social engineering breach orchestrated by attackers dubbed the 'Payroll Pirates.' The threat actors engineered convincing phishing campaigns targeting payroll staff, tricking them into divulging critical credentials. Once initial access was secured, the attackers leveraged lateral movement techniques to escalate privileges and manipulate internal payroll processes, ultimately leading to fraudulent fund transfers and sensitive data exposure. Rapid detection efforts limited further impact, but the breach resulted in financial losses, operational disruption, and increased scrutiny over internal controls. This incident underscores the resurgence of highly targeted social engineering attacks, specifically in the payroll and finance sectors. As attackers blend human manipulation with advanced technical tactics, organizations must prioritize zero trust architectures, staff awareness, and continuous threat monitoring to defend against this evolving risk landscape.
8 months ago
Kill Chain
Google Pixel 9 (2026): Zero-Click BigWave Driver Breach Exposes Kernel Vulnerabilities
In January 2026, Google Pixel 9 devices were found vulnerable to a sophisticated zero-click exploit chain targeting the Android BigWave hardware driver. Attackers combined a remote code execution exploit affecting a Dolby decoder with a privilege escalation flaw in the /dev/bigwave device, accessible from the mediacodec SELinux sandbox. The chain allowed attackers to escape the sandbox, bypass SELinux protections, and achieve kernel-level arbitrary read/write, essentially gaining full device control. This exploit enabled unauthorized access to sensitive data and even allowed remote data exfiltration by attackers, severely compromising device security. This incident highlights the increasing sophistication of exploit chains leveraging hardware-specific drivers and sandbox escape techniques in mobile ecosystems. With the rise in supply chain threats, use of AI to automate exploit engineering, and growing pressure from privacy regulators, organizations face escalating risks from zero-day attacks targeting embedded devices.
8 months ago
Kill Chain
Google Pixel 9's 2025 Zero-Click Exploit Chain: Lessons in Mobile Supply Chain Security
In 2025, security researchers demonstrated a critical 0-click exploit chain targeting Google Pixel 9 and other Android devices, leveraging vulnerabilities in the Dolby UDC audio codec and the BigWave driver. Attackers could remotely execute code without user interaction by exploiting flaws in audio file processing and privilege escalation within device drivers. Despite early reporting and clear exploitability, it took vendors up to 139 days to release patches, leaving millions of Android users at risk. Gaps in patch management, inconsistent security controls, and delayed vulnerability classification contributed to prolonged exposure and a significant operational risk. This incident underscores the urgency of promptly addressing zero-click vulnerabilities and supply chain security issues in mobile ecosystems. As attackers increasingly exploit overlooked decoders, device drivers, and rapidly introduced AI features, coordinated patching and proactive privilege reduction remain essential to counter evolving mobile threats.
8 months ago
Kill Chain
Fortinet FortiSIEM Zero-Day: Exploitation Surge Exposes SIEM Risks in 2024
In June 2024, attackers began actively exploiting a critical vulnerability (CVE-2024-XXXX) in Fortinet FortiSIEM, a widely deployed security event management solution. The flaw, which allows remote code execution via specially crafted API requests, was leveraged soon after public proof-of-concept exploit code emerged. Threat actors targeted unpatched FortiSIEM instances to gain privileged access, deploy malware, and establish persistence within enterprise environments, impacting security visibility and putting sensitive data at risk. Public advisories highlighted patch urgency, as exploitation was observed globally in both private and government sectors. This incident underscores sharp escalation in exploitation of high-impact vulnerabilities immediately following public disclosure and POC release. The attack illustrates the need for rapid patching, robust segmentation, and comprehensive monitoring, as threat actors increasingly automate targeting of critical management infrastructure.
8 months ago
Kill Chain
Black Basta Ransomware Boss Named, Placed on Interpol Red Notice in Major 2026 Crackdown
In January 2026, international law enforcement, led by Ukraine and Germany, identified Oleg Evgenievich Nefedov as the leader of the Black Basta ransomware-as-a-service (RaaS) gang. Authorities added Nefedov to Interpol's 'Red Notice' and Europol's 'Most Wanted' lists, following coordinated raids that apprehended affiliates specializing in breaching corporate systems, cracking passwords, and escalating privileges to facilitate attacks. Black Basta has been attributed to over 600 global cyber incidents targeting enterprises in sectors from defense to healthcare, employing ransomware and data extortion to extract payments and exfiltrate sensitive information. This incident is significant as it marks one of the first times a major ransomware operation's leadership was officially unmasked and targeted with international warrants. The Black Basta takedown reflects increasing sophistication and coordination in responses to organized cybercrime, underscoring the persistent threat posed by ransomware groups and their rapid evolution post-Conti.
8 months ago
Kill Chain
Sitecore 2025: China-Linked APT UAT-8837’s Zero-Day Attack Reveals Modern Espionage Tactics
In early September 2025, an advanced persistent threat group known as UAT-8837, believed to be linked to China, exploited a zero-day vulnerability (CVE-2025-53690) in Sitecore products to gain initial access to critical infrastructure targets in North America. The attackers obtained credentials and leveraged living-off-the-land tools, open-source utilities, and custom backdoors—including 'WeepSteel'—to conduct deep reconnaissance, move laterally, and collect sensitive data such as credentials and Active Directory configurations. Post-exploitation activity also included disabling security controls and exfiltrating internal DLLs, which could be leveraged for future supply chain attacks. This incident spotlights a surge in targeted espionage exploiting both zero-day and known software vulnerabilities, with an emphasis on credential compromise and lateral movement. Growing overlap in TTPs among China-nexus actors and continued attack innovation reinforce the importance of modernizing defenses against sophisticated identity- and supply-chain-driven attacks.
8 months ago
Kill Chain
Researchers Hijack StealC Malware Operators: 2026's XSS-Driven Counterattack
In January 2026, cybersecurity researchers uncovered and exploited a cross-site scripting (XSS) vulnerability in the web administration panel of the infamous StealC infostealer malware. By leveraging this flaw, the researchers were able to hijack malware operator sessions, collect hardware and geographic fingerprints, observe live threat actor activities, and even seize control of the attackers' own administration panels. One notable instance involved tracking a StealC affiliate operating as 'YouTubeTA', who stole credentials via malicious YouTube links that resulted in over 5,000 compromised devices and the theft of nearly 390,000 passwords and 30 million cookies. The research highlights critical operational risks inherent in the malware-as-a-service (MaaS) model, particularly as platforms surge in popularity and complexity. This incident is especially relevant as the MaaS cybercrime landscape continues to expand, driving rapid adoption of infostealer toolkits like StealC. Security teams must remain vigilant to emerging attacker tradecraft and vulnerabilities, as both operators and defenders look to exploit weaknesses in rival infrastructure.
8 months ago
Kill Chain
China-Linked APT Exploits Cisco Secure Email Gateway Zero-Day (2025)
In late 2025, Cisco disclosed a critical zero-day vulnerability (CVE-2025-20393, CVSS 10.0) within AsyncOS Software powering its Secure Email Gateway and Secure Email and Web Manager appliances. Exploited by China-linked advanced persistent threat group UAT-9686, the flaw—residing in insufficient HTTP request validation by the Spam Quarantine feature—allowed attackers to remotely execute commands as root, install tunneling and persistence tools, and drop a Python backdoor ("AquaShell"). The threat actor’s campaign saw exploitation in the wild ahead of Cisco’s January 2026 patch release, impacting organizations exposing affected appliances to the internet with the vulnerable feature enabled. This incident highlights the increasing sophistication and operational tempo of state-backed APTs exploiting zero-day vulnerabilities in enterprise infrastructure. The case underscores the urgency for rigorous patch management, network segmentation, and rapid detection as attackers target critical security appliances that serve as organizational communication lifelines.
8 months ago
Kill Chain
LOTUSLITE Backdoor: How Mustang Panda Targeted U.S. Policy Organizations in 2026
In January 2026, researchers revealed a spear phishing campaign targeting US government and policy organizations utilizing geopolitical lures themed around US intervention in Venezuela. Attackers distributed a malicious ZIP archive containing a DLL file using side-loading techniques to deploy the LOTUSLITE backdoor. The campaign, attributed to the Chinese state-linked Mustang Panda group, leveraged reliable execution flows such as DLL sideloading, beaconed over WinHTTP APIs, enabled remote command execution, and exfiltrated data. While the exact scope of any successful compromise remains unclear, the operation demonstrates a focused cyber espionage effort using proven tactics for initial access and persistence. This campaign highlights the ongoing trend where threat actors employ familiar, effective tradecraft combined with timely or provocative lures. It underscores the continued risk posed to policy organizations from geopolitical-themed spear phishing as attackers adapt their delivery but rely on consistent, operationally sound techniques.
8 months ago
Kill Chain
GootLoader’s Malformed ZIP Attack: 2026 Lessons for Enterprise Security
In January 2026, security researchers uncovered a sophisticated GootLoader malware campaign leveraging malformed, hashbusting ZIP archives containing JavaScript payloads. These ZIP files, crafted by concatenating 500–1,000 archives and manipulating ZIP header fields, evaded analysis from most extraction tools except Windows' default unarchiver. Distributed via SEO poisoning and malvertising targeting legal template seekers, the attack delivered unique archives to each victim, successfully bypassing many detection workflows. Once executed, the JavaScript payload established persistence and launched additional scripts to gather system info and await remote instructions—potentially leading to further infections, including ransomware. This incident underscores the rising technical sophistication in malware delivery tactics, with adversaries rapidly adapting to security controls by exploiting common utilities and unique, randomized delivery artifacts. The campaign highlights the need for proactive endpoint controls and continuous monitoring, as many legacy detection and response tools may miss such creative evasion methods.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

