Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4225 to 4236 of 5957
Global Cisco Switch Reboot Outage: DNS Client Vulnerability Hits Network Operations
In January 2026, numerous Cisco network switches globally experienced widespread, persistent reboot loops due to a software vulnerability in their DNS client service. Beginning around 2 AM UTC, administrators observed affected Cisco models—including CBS250, CBS350, SG350, SG350X, SG550X, and Catalyst C1200—entering repeated crashes when DNS queries for core domains (such as www.cisco.com or NTP servers) failed. The root trigger appears to be a firmware bug in the DNSC task, causing the switch OS to log a critical error and initiate an immediate reboot, with impacts observed across multiple organizations and networks worldwide. Temporary mitigations, such as disabling DNS or SNTP features, helped restore partial stability until Cisco and upstream CDN providers reverted the changes. The incident highlights the ongoing risk that latent software vulnerabilities in ubiquitous infrastructure devices pose to business continuity. As device automation and remote management expand, similar vulnerabilities can cause cascading operational outages across sectors, underscoring the need for robust patching, rigorous QA in embedded systems, and improved visibility over east-west traffic disruptions.
8 months ago
Kill Chain
Chinese APT Exploits VMware ESXi Zero-Days in Stealth Hypervisor Attacks (2025)
In late 2025, threat researchers identified a series of intrusions targeting VMware ESXi hypervisors via a zero-day toolkit attributed to a Chinese-speaking advanced persistent threat group. The attackers initially gained access by compromising a SonicWall VPN device and pivoted through privileged domain accounts, leveraging sophisticated VM escape exploits that chained three ESXi zero-day vulnerabilities (CVE-2025-22226, CVE-2025-22224, and CVE-2025-22225) developed more than a year before disclosure. The exploit chain enabled lateral movement, data staging for exfiltration, and installation of stealth persistence backdoors, placing numerous enterprise virtualization environments at sustained risk for data breach and operational disruption. This incident exemplifies the escalating sophistication of APT operations, underlining the risks posed by supply chain weaknesses, late vulnerability reporting, and the ability of attackers to evade common monitoring. The case also highlights growing regulatory scrutiny on zero-day management and east-west traffic visibility within critical infrastructure.
8 months ago
Kill Chain
Kimsuky Leverages QR Code Phishing to Target U.S. Strategic Organizations in 2025
In June 2025, the FBI identified a sophisticated spearphishing campaign by North Korean state-backed group Kimsuky (APT43) targeting U.S. organizations involved in North Korea-related policy, research, and strategic consultancy. Attackers used emails containing malicious QR codes—an attack known as 'quishing'—to lure victims from think tanks, government agencies, and academic institutions into scanning codes with mobile devices. Scanned QR codes redirected victims to convincing phishing pages impersonating Microsoft 365, Okta, and other login portals, harvesting credentials and cloud session tokens to circumvent multi-factor authentication measures. The attacks bypassed traditional email security by exploiting unmanaged mobile endpoints and compromised inboxes, posing significant risks to identity security and ongoing policy work. This incident highlights an escalating trend of QR code phishing, enabling attackers to sidestep conventional defenses while targeting sensitive organizations. The campaign underscores the growing threat posed by identity-driven attacks, advanced social engineering, and multi-factor authentication bypass techniques, prompting urgent calls for improved mobile device security postures and enhanced employee awareness programs.
8 months ago
Kill Chain
CISA Sounds Alarm on Exploited Microsoft Office & HPE OneView Vulnerabilities (2026)
In January 2026, CISA added critical vulnerabilities affecting Microsoft Office (CVE-2009-0556) and HPE OneView (CVE-2025-37164) to its Known Exploited Vulnerabilities catalog after credible reports of active exploitation. CVE-2009-0556, a code injection flaw in PowerPoint, allows remote code execution via memory corruption, while CVE-2025-37164 enables unauthenticated remote code execution against all affected HPE OneView versions prior to 11.00. eSentire reported public proof-of-concept exploit code for the HPE flaw, further increasing organizational risk. Both vulnerabilities pose severe security threats, prompting urgent remediation directives across Federal Civilian Executive Branch networks. This incident underscores the rising urgency of rapid patch management as threat actors increasingly exploit published vulnerabilities and proof-of-concept exploits. The swift addition to CISA’s catalog highlights regulatory pressure and the need for proactive controls as organizations face growing risks from unpatched enterprise software.
8 months ago
Kill Chain
NodeCordRAT Trojan Exposed in npm Bitcoin-Themed Packages (2026)
In November 2025, cybersecurity researchers uncovered a sophisticated supply chain attack involving malicious npm packages—'bitcoin-main-lib', 'bitcoin-lib-js', and 'bip40'—that distributed the remote access trojan NodeCordRAT. Uploaded by the threat actor 'wenmoonx', these packages mimicked legitimate BitcoinJS repositories, leveraging npm’s postinstall scripts to deliver malware hidden in 'bip40'. NodeCordRAT enabled attackers to exfiltrate Chrome credentials, cryptocurrency wallet seed phrases, and sensitive files to Discord-controlled servers, using Discord’s API for covert communication and command execution. This multi-OS campaign potentially impacted thousands of developers before takedown. The incident stands out for its abuse of trusted open-source components, increasing concern across the software supply chain. Its methodology highlights the growing sophistication of attacker tradecraft leveraging developer ecosystems and API-based covert channels, making such threats relevant for all organizations relying on open-source dependencies.
8 months ago
Kill Chain
Cisco Patches ISE Flaw Following Public Exploit Release: What Enterprises Need to Know
In January 2026, Cisco disclosed a medium-severity vulnerability (CVE-2026-20029, CVSS 4.9) in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products after a public proof-of-concept (PoC) exploit was released. The flaw, originating from improper XML parsing in the web-based management interface, could allow authenticated administrators to upload malicious files and read sensitive files from the underlying operating system—data ordinarily inaccessible, even to admins. The vulnerability was responsibly reported by a Trend Micro researcher and impacts ISE/ISE-PIC versions prior to 3.5. Cisco responded promptly with patches and confirmed there were no reports of in-the-wild exploitation at the time of disclosure. This incident highlights ongoing threats posed by privilege escalation and flaws in web-based management interfaces of critical infrastructure. With increased attacks on network devices and rapid public exploit releases, organizations face urgent pressure to patch exposed systems and reinforce administrative controls.
8 months ago
Kill Chain
China-Linked UAT-7290: Telecom Espionage Strikes via Linux Malware and ORB Nodes
In early 2026, a sophisticated China-linked threat actor designated UAT-7290 orchestrated targeted espionage campaigns against telecommunications providers across South Asia and Southeastern Europe. The attackers conducted meticulous intelligence gathering before leveraging one-day vulnerabilities and SSH brute-forcing to compromise exposed edge devices. Malicious payloads—including RushDrop, DriveSwitch, and the advanced SilentRaid—enabled persistent access, covert lateral movement, and deployment of Operational Relay Box (ORB) infrastructure, which can be used by other threat groups. Their arsenal blends open-source tools and bespoke Linux implants, demonstrating mature tradecraft and adaptability. This campaign reflects the increasing frequency and complexity of transnational espionage assaults on critical infrastructure, exploiting modern hybrid networks and advanced malware suites. Organizations in telecom and related sectors face mounting pressure to enhance east-west traffic controls, patch velocity, and incident response capabilities to defend against evolving APT operations.
8 months ago
Kill Chain
WhatsApp-Based Worm Drives Astaroth Banking Trojan Surge Across Brazil
In late 2025 and early 2026, a major cybersecurity campaign—codenamed Boto Cor-de-Rosa—targeted millions of WhatsApp users in Brazil with the Astaroth (Guildma) banking trojan. Threat actors leveraged a novel worm module written in Python that hijacked victims’ WhatsApp contact lists, automatically sending malicious ZIP files and spreading the malware with unprecedented speed. Upon execution, the ZIP archive dropped a Visual Basic script that downloaded further payloads, including a banking module capable of harvesting credentials when victims accessed online banking sites. Over 95% of reported infections occurred in Brazil, severely impacting personal and financial data security. This campaign highlights how cybercriminals are weaponizing popular messaging apps as attack vectors for financial malware, reflecting the rising sophistication and modularity of their methods. The shift to WhatsApp-based propagation, combined with multi-language modular code, signals a concerning trend for businesses and individuals in regions with high platform adoption rates.
8 months ago
Kill Chain
Critical RCE Flaw in Hitachi Energy Asset Suite: Jasper Report Vulnerability Exposes Critical Infrastructure (2025)
In December 2025, Hitachi Energy disclosed a critical remote code execution (RCE) vulnerability (CVE-2025-10492) affecting its Asset Suite product versions 9.7 and prior. The flaw, found in the Jasper Report third-party component, arises from improper deserialization of untrusted data, allowing attackers to remotely execute arbitrary code on affected systems. The vulnerability particularly impacts organizations using Asset Suite in critical infrastructure sectors, such as energy, potentially exposing operational networks to severe risks of compromise, data breach, or service disruption. This incident underscores the persistent threat posed by supply chain vulnerabilities in industrial control software. As threat actors increasingly target critical infrastructure through third-party and open-source components, organizations face heightened regulatory scrutiny and an urgent need for robust patch and mitigation strategies to close compliance and security gaps.
8 months ago
Kill Chain
D-Link Router Zero-Day Exploited in 2024: A Network Infrastructure Wake-Up Call
In early 2024, security researchers identified active exploitation of a zero-day vulnerability affecting end-of-life D-Link DSL routers. Attackers leveraged the unpatched flaw to execute arbitrary code remotely, enabling them to gain full control over susceptible devices. The campaign targets legacy router models no longer supported with firmware updates, resulting in thousands of home and small-office networks being exposed to malware infection, data interception, and lateral movement within internal networks. Public disclosure led to warnings from multiple security vendors, though permanent remediation is unavailable due to the unsupported status of affected models. This incident highlights the ongoing risks posed by obsolete network infrastructure and the trend of threat actors exploiting unmaintained IoT and edge hardware. As organizations depend on interconnected devices, lack of timely decommissioning and patch management creates persistent attack surfaces for cybercriminals.
8 months ago
Kill Chain
Multi-Vector Malware Attack Targets DShield Honeypots in January 2024
In January 2024, a sophisticated multi-vector malware campaign targeted DShield honeypot sensors, leveraging SSH brute force and automated malware delivery techniques. Multiple threat actors deployed different malware strains, including Redtail, orchestrating the attacks from a wide array of source IPs and employing frequent file uploads with changing hashes and filenames. Analysis of 30 days of ELK database sensor logs revealed that attackers exploited unmonitored remote access opportunities to move laterally and repeatedly bypass conventional defenses, successfully delivering malicious payloads using diverse infrastructure. This incident exemplifies the evolution of malware attacks that integrate automation, multi-stage delivery, and dynamic infrastructure to overwhelm detection systems. It mirrors broader industry concerns about increasingly sophisticated threat actor capabilities, especially as organizations face mounting regulatory pressure to improve east-west traffic visibility, segmentation, and cloud-native threat response.
8 months ago
Kill Chain
Veeam Patches Critical Operator RCE Vulnerability in Backup Software
In early June 2025, Veeam identified and patched a critical security flaw (CVE-2025-59470) in its Backup & Replication v13 software. The vulnerability allows users with the privileged 'Backup Operator' or 'Tape Operator' roles to gain remote code execution capabilities by sending crafted interval or order settings, ultimately permitting execution of commands as the service's database user. While the flaw was discovered through internal testing and no exploitation in the wild has been reported, organizations running affected software faced serious operational and data security risks until patched. This incident underscores the trend of attackers targeting privileged IT roles and backup platforms to gain persistent, high-impact access. As regulatory pressure to secure sensitive data intensifies and threats against backup infrastructure become more sophisticated, timely patching and principle of least privilege are more critical than ever.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

