Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4213 to 4224 of 5957
APT28 Targets Energy and Policy Sectors With Sophisticated Credential Phishing (2025)
Between February and September 2025, Russian state-sponsored APT28 (aka BlueDelta, linked to the GRU) launched highly targeted credential-harvesting attacks against individuals in Turkish energy and nuclear agencies, a European think tank, and organizations in North Macedonia and Uzbekistan. The campaign relied on phishing emails with region-specific lures and fake login pages imitating Microsoft OWA, Google, and Sophos VPN portals. Stolen credentials were exfiltrated via disposable internet services, and victims were seamlessly redirected to legitimate sites to avoid suspicion, evading typical detection methods. Notably, attackers leveraged legitimate PDF documents themed around high-profile geopolitical events as decoy content. These incidents underscore the increasing sophistication and operational focus of nation-state phishing campaigns, with attackers rapidly exploiting current geopolitical tensions to credibly target sensitive sectors. Repeated use of trusted public infrastructure for data exfiltration further complicates defense and detection efforts.
8 months ago
Kill Chain
Critical RCE Vulnerability Exposes Trend Micro Apex Central (2026)
In January 2026, Trend Micro disclosed a critical security vulnerability (CVE-2025-69258, CVSS 9.8) in its on-premise Apex Central for Windows, allowing unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges. The flaw exploited a LoadLibraryEX vulnerability in the MsgReceiver.exe component, enabling attacker-controlled DLL injection via specially crafted messages sent over TCP port 20001. Two accompanying vulnerabilities (CVE-2025-69259 and CVE-2025-69260, CVSS 7.5) could permit denial-of-service attacks. The vulnerabilities impacted Apex Central installations below Build 7190 and were responsibly disclosed by Tenable in August 2025. Organizations were urged to patch immediately to prevent potential system compromise. This incident highlights ongoing risks from remote code execution vulnerabilities in security management platforms. Attackers increasingly target critical infrastructure using sophisticated message-based exploits, making timely patching and enhanced segmentation crucial, especially amid rising regulatory scrutiny and a surge in supply chain attacks.
8 months ago
Kill Chain
China-Linked Hackers Achieve VMware ESXi VM Escape with Zero-Days (2025)
In December 2025, security researchers discovered a sophisticated cyberattack attributed to Chinese-speaking threat actors who exploited three zero-day vulnerabilities in VMware ESXi (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226). The attackers gained initial access via a compromised SonicWall VPN appliance, followed by deploying a custom exploit toolkit designed to escape virtual machine isolation and compromise the hypervisor itself. Exploiting the flaws allowed attackers to run arbitrary code on the ESXi host, install persistent backdoors (via VSOCKpuppet), and potentially pave the way for ransomware or advanced persistent remote access, posing direct risks to organizations’ virtual infrastructure integrity. This incident highlights the increased sophistication of state-linked APT actors in targeting virtualization platforms using zero-day techniques and bypassing traditional detection methods. As organizations continue to rely on virtualization and hybrid cloud environments, vigilance around hypervisor and access point security is paramount in defending against similar high-impact threats.
8 months ago
Kill Chain
ChatGPT's 2026 ZombieAgent Attack: Persistent Prompt Injection Exploits AI Memory
In January 2026, researchers at Radware disclosed a critical vulnerability in OpenAI's ChatGPT platform, exploiting its new memory and connector features via indirect prompt injection (IPI). The exploit, dubbed "ZombieAgent," allowed attackers to persistently implant malicious prompts within ChatGPT's memory using innocuous-looking emails or document attachments. Once infected, the AI could automatically extract and exfiltrate sensitive information through obfuscated URL requests whenever the user interacted with the compromised bot, bypassing existing controls and traditional user awareness. The attack method leverages ChatGPT integrations with email and third-party applications, increasing the risk of wide propagation and persistence. This incident underscores the rapidly evolving threat landscape in AI/ML security, where feature enhancements such as memory and connectivity can be leveraged by attackers for new classes of attacks. The ZombieAgent case highlights the urgent need for robust prompt source attribution, intent verification, and granular trust boundaries in AI agents as attackers adapt known abuse techniques to advanced AI capabilities.
8 months ago
Kill Chain
The Kimwolf & Aisuru Botnets: How Android TV Devices Fueled a Global Proxyware Crisis
In late 2025, the Kimwolf and Aisuru botnets collectively compromised over two million Android TV streaming boxes by leveraging factory-installed or bundled proxy malware. Attackers, operating through channels like Discord and Telegram, conscripted these devices for DDoS attacks, ad fraud, and mass content scraping. Investigations revealed overlapping cybercriminal operators, shared infrastructure, and direct monetization via residential proxy services such as Plainproxies, Maskify, and ByteConnect. The illicit operations exploited minimal device security, used decentralized technologies like Ethereum Name Service (ENS) for resilient command-and-control, and took advantage of poorly regulated server resellers in the U.S. and Europe. The incident underscores a rapidly evolving threat landscape where IoT/OTT devices are prime targets for distributed, difficult-to-mitigate botnets fueled by proxyware and privacy-invasive apps. It highlights urgent needs for better supply-chain security, IoT device hardening, and more robust detection and segmentation strategies to counter stealthy lateral movement and monetization tactics now seen across botnet campaigns.
8 months ago
Kill Chain
Fake AI Chrome Extensions Expose Sensitive Data of 900,000 Users
In January 2026, security researchers disclosed a major data breach in which two malicious Google Chrome extensions, posing as legitimate AI-powered tools for ChatGPT and DeepSeek, surreptitiously harvested sensitive information from over 900,000 users. These fake extensions, mimicking the functionality and branding of a trusted vendor, exfiltrated entire LLM chat conversations, browsing histories, confidential corporate URLs, internal credentials, and other proprietary data to an external command-and-control server. The scope of the incident included the exposure of intellectual property, business strategies, source code, and user credentials, highlighting significant risks for individuals and organizations whose employees utilized these tools in their workflows. With generative AI increasingly adopted for business and development tasks, this breach is a stark demonstration of the risks posed by third-party browser extensions—particularly those that intercept AI-driven sessions. It underscores the urgent need for stricter vetting controls, robust application security for browser add-ons, and user education in an environment where threat actors leverage AI both as target and tool.
8 months ago
Kill Chain
HPE OneView Critical Zero-Day Exploited for Remote Access in 2025
In June 2025, a critical vulnerability (CVE-2025-37164), was discovered and exploited in the wild against HPE OneView, the company’s IT infrastructure management platform. Attackers leveraged the flaw to achieve remote code execution without authentication, enabling full access to core infrastructure resources. Reported incidents indicate that threat actors used this vulnerability for initial access, privilege escalation, and potentially data exfiltration or ransomware deployment, threatening operational continuity for affected enterprises. HPE acted swiftly to release security advisories and patches, but exploitation occurred before widespread remediation could be implemented. This incident highlights the persistent targeting of critical infrastructure management tools and the increasing sophistication and speed with which attackers weaponize disclosed zero-day vulnerabilities. Organizations must prioritize patch management and vigilant monitoring to prevent compromise in an evolving landscape of high-consequence supply chain and platform attacks.
8 months ago
Kill Chain
Fancy Bear’s 2024 Credential Attacks: The Global Secrets Heist Reinvented
In early 2024, the Russian state-sponsored threat group APT28 (also known as Fancy Bear) intensified credential-harvesting campaigns targeting global governmental and enterprise networks. Leveraging basic techniques such as phishing and exploitation of unencrypted or weakly protected authentication channels, the attackers maintained persistent access and exfiltrated sensitive secrets across multiple sectors. The operations demonstrated a preference for cost-effective methods, including the abuse of stolen credentials, rather than relying on advanced custom malware—resulting in widespread data exposure and persistent breaches with significant geopolitical ramifications. This incident highlights the increasing sophistication of threat actors’ social engineering and credential-focused tactics, signaling a shift in espionage campaigns worldwide. As traditional perimeter defenses become less effective against targeted, credential-driven attacks, organizations face renewed urgency to adopt zero trust models, strong encryption, and robust monitoring to combat these persistent threats.
8 months ago
Kill Chain
How Attackers Manipulate Windows Process Environment Blocks for Evasion (2024 Analysis)
In January 2024, security researchers highlighted a process manipulation technique in Windows environments that allows attackers to modify the Process Environment Block (PEB) of malicious or legitimate processes. By leveraging the CREATE_SUSPENDED flag and directly editing the PEB structure, adversaries can spoof or hide command-line arguments of spawned processes. This method can be further extended to already-running processes, making detection through simple process inspection more challenging. The primary risk lies in attackers masking their operational activities to evade security controls and digital forensics investigation. This incident underscores the evolving sophistication of post-exploitation tactics aimed at defense evasion. Process hollowing, command-line spoofing, and direct PEB tampering are increasingly used in targeted attacks and commodity malware alike, highlighting the critical need for visibility, anomaly detection, and strong endpoint security strategies.
8 months ago
Kill Chain
Inside Vercel’s 2025 React2Shell Race: Supply-Chain RCE and the Open Source Security Wake-up Call
In late 2025, Vercel—maintainers of the popular Next.js framework—faced a critical cybersecurity incident involving the React2Shell vulnerability (CVE-2025-55182). Discovered just after Thanksgiving, this supply-chain flaw in React Server Components enabled unauthenticated remote code execution across multiple frameworks and bundlers in default configurations. A rapid, global response mobilized Vercel, open-source contributors, major cloud providers, and security vendors who coordinated mitigations and validated patches within days. Despite these efforts, over 60 organizations were compromised, with attackers from cybercriminal, ransomware, and nation-state groups exploiting disclosed weaknesses, leading to millions of exploit attempts and sustained attack volumes. The React2Shell episode highlighted the ongoing risks inherent in reliance on open-source components and the urgent need for collaborative, industry-wide response standards. Attackers have rapidly adopted similar techniques, sustaining high exploitation rates and revealing critical gaps in software supply-chain security.
8 months ago
Kill Chain
CISA Flags Critical HPE OneView Vulnerability as Actively Exploited in 2026
In January 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) flagged a critical vulnerability (CVE-2025-37164) in HPE OneView infrastructure management software as being actively exploited in the wild. This flaw, present in versions prior to 11.00, allows unauthenticated attackers to execute low-complexity code-injection attacks, gaining remote code execution on unpatched systems. HPE issued security updates in December 2025, but as no mitigations or workarounds exist, organizations using legacy versions remain exposed. The exploitation of this vulnerability poses significant risks to IT infrastructure due to OneView’s widespread enterprise adoption, which includes the Fortune 500. The prominence of this threat highlights a growing trend in attacks targeting centralized infrastructure management platforms, often leading to widespread lateral movement and potential operational disruption. Regulatory agencies and security teams are increasingly prioritizing rapid patching and zero trust segmentation to address these critical exposures.
8 months ago
Kill Chain
Cisco 2026 ISE Vulnerability: How Public Exploits Undermine Zero Trust
In January 2026, Cisco disclosed a critical vulnerability (CVE-2026-20029) affecting its widely used Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The flaw, caused by improper XML parsing in the web-based management interface, allows attackers with valid administrative credentials to upload a malicious file and access otherwise restricted files on the underlying operating system. While Cisco has not identified any active exploitation in the wild, proof-of-concept exploit code is publicly available and even privileged enterprise environments are exposed until patched. Administrators manage authentication, access, and segmentation policies through ISE, so exploitation could grant attackers access to highly sensitive network information or credentials, potentially undermining zero trust controls and compliance postures. This incident is particularly relevant as it highlights the ongoing risk posed by public exploit code, privilege escalation bugs, and gaps in patch hygiene for critical access-management tools. Increased regulatory scrutiny and the sophistication of attackers targeting identity and segmentation controls mean organizations cannot delay patching or segmentation efforts, especially as similar vulnerabilities continue to be a primary vector for advanced threats.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

