Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4465 to 4476 of 5948
Amazon Reveals Years-Long GRU Cyber Espionage on Critical Cloud & Energy Infrastructure
Between 2021 and 2025, Amazon's threat intelligence team uncovered a multi-year cyber campaign attributed to Russia's Main Intelligence Directorate (GRU), specifically associated with APT44/Sandworm. The attackers targeted Western energy sector organizations, critical infrastructure providers, and cloud-hosted network environments by exploiting vulnerabilities and, increasingly, leveraging misconfigured network edge devices. This facilitated credential interception and lateral movement through persistent network access, with efforts focused on credential harvesting and replay against victim organizations. Amazon responded by notifying affected customers and disrupting active operations, limiting further impact. This incident underscores the sophistication and persistence of nation-state actors in targeting vital infrastructure by adapting TTPs to minimize exposure. The campaign signals an urgent shift towards exploiting cloud and network misconfigurations rather than relying solely on zero-day vulnerabilities—a trend that broadens risk for organizations across sectors.
8 months ago
Kill Chain
Inside the 2025 KPop Malware Hunter Takedowns: Exposing Cloud Attack Trends
In 2025, a coordinated intelligence operation led by an international alliance of cybersecurity researchers, dubbed the KPop Malware Hunters, dismantled several prolific malware campaigns targeting global cloud and data center environments. Threat actors, including the group Salt Typhoon, exploited east-west traffic routes and unencrypted data in transit to achieve lateral movement post-compromise. Using advanced encrypted traffic analytics and inline IPS, defenders identified high-volume command-and-control exchanges masked within routine inter-region traffic. The operation led to significant disruption of adversary infrastructure, restoration of business operations, and improved threat visibility for impacted organizations worldwide. This takedown is highly relevant amid heightened attacks on hybrid and multicloud architectures, where sophisticated adversaries increasingly exploit internal cloud pathways and vulnerable segmentation. 2025’s events spotlight the urgent need for zero trust, inline threat detection, and rigorous compliance alignment as attackers leverage AI-driven evasion and cloud-native persistence.
8 months ago
Kill Chain
Compromised IAM Credentials Fuel AWS Cryptomining Attack in 2025
In November 2025, Amazon Web Services (AWS) became the target of a widespread cryptomining campaign exploiting compromised Identity and Access Management (IAM) credentials. The attackers used stolen keys to access AWS accounts, deploy cryptomining operations, and leverage persistence mechanisms to avoid detection and maintain access. Amazon’s GuardDuty threat detection tools were instrumental in uncovering the activity, which leveraged novel Tactics, Techniques, and Procedures (TTPs) including lateral movement and privilege escalation, putting customer cloud resources and budgets at risk through accelerated resource consumption and possible data exposure. This incident is emblematic of an escalating trend where threat actors exploit cloud identity weaknesses for financial gain. It underscores the urgent necessity for robust multi-factor authentication, real-time anomaly detection, and comprehensive cloud security strategies as identity-driven attacks proliferate in the cloud era.
8 months ago
Kill Chain
Rogue NuGet Impersonates Tracer.Fody, Orchestrates Multi-Year Crypto Wallet Theft
Between February 2020 and December 2025, a malicious NuGet package named "Tracer.Fody.NLog" posed as the legitimate .NET tracing library, Tracer.Fody, and was covertly distributed via typosquatting and mimicking developer identities. The package, uploaded by a threat actor under the handle "csnemess," evaded detection for almost six years, collecting over 2,000 downloads. Instead of offering legitimate functionality, this package deployed a wallet stealer: scanning the default Stratis wallet directory on Windows systems, exfiltrating wallet data and passwords to threat actor infrastructure hosted in Russia, with attackers leveraging crafted code and hidden routines to bypass superficial code reviews. The prolonged success of this attack underscores the persistent risk supply chain threats pose to open-source ecosystems, especially for developer tools and libraries. It highlights attackers’ sophistication in mimicking trusted maintainers, the difficulty of detecting such manipulation, and ongoing regulatory and security pressures to improve package repository hygiene and detection.
8 months ago
Kill Chain
CISA Flags Fortinet CVE-2025-59718: Improper Signature Verification Under Active Exploitation
In December 2025, CISA added CVE-2025-59718 to its Known Exploited Vulnerabilities catalog, citing confirmed active exploitation targeting Fortinet's multiple products. This vulnerability involves improper verification of cryptographic signatures, allowing attackers to bypass security controls, execute unauthorized code, or escalate privileges on affected devices. Federal agencies, per BOD 22-01, must remediate this critical issue by the mandated deadline to protect their networks. The flaw’s exploitation risks device compromise and potential lateral movement by sophisticated threat actors, with broad implications for data integrity and operational continuity across affected organizations. This alert reflects the escalating trend of attackers rapidly weaponizing supply chain or cryptographic flaws in core network infrastructure. As organizations increasingly rely on complex integrations and encrypted communications, such vulnerabilities underscore persistent challenges in managing risk and ensuring trust in critical systems.
8 months ago
Kill Chain
Johnson Controls IoT Devices Exposed: 2025 Encryption Vulnerabilities in PowerG, IQPanel & IQHub
In December 2025, security researchers at NCC Group identified and responsibly disclosed four cryptographic vulnerabilities (CVE-2025-61738, CVE-2025-61739, CVE-2025-26379, CVE-2025-61740) impacting Johnson Controls’ PowerG, IQPanel, and IQHub products. The flaws included cleartext transmission of sensitive information, nonce reuse, weak pseudo-random number generation, and inadequate origin validation. Threat actors could exploit these issues to intercept, decrypt, or manipulate encrypted wireless traffic, potentially altering system behavior or disrupting services in commercial facilities globally. Johnson Controls issued advisories and firmware updates, especially urging customers to migrate to IQPanel 4 with firmware 4.6.1 or later. The incident highlights the continued importance of secure-by-design principles in IoT and OT devices, as attacks increasingly pivot toward embedded and building automation systems. Heightened regulatory focus and attacker sophistication underscore the need for proactive vulnerability management and segmenting critical infrastructure networks.
8 months ago
Kill Chain
Parked Domains Weaponized: Inside the 2025 Typosquatting Malvertising Surge
In late 2025, security researchers uncovered that over 90% of parked domains—unused, expired, or misspelled web addresses—were actively redirecting visitors to malicious destinations, including scams, malware, and deceptive subscription offers. Utilizing techniques like device fingerprinting, IP geolocation, and chained redirects, threat actors profited by manipulating the domain parking ecosystem, turning innocuous navigation mistakes into vectors for malware delivery and fraud. The campaign targeted high-profile brands and government offices, often bypassing detection by profiling user access (e.g., residential IPs or VPN use), with some domains weaponized for business email compromise. This incident highlights an alarming shift: parked and typo domains are now a primary malvertising risk, not a minor threat. As domain registration and ad platform policies evolve, attackers rapidly adapt, exploiting weaknesses in digital trust and endpoint security. Organizations must broaden threat detection and policy enforcement to address direct navigation attacks and affiliate-driven malvertising.
8 months ago
Kill Chain
Critical RADIUS MD5 Vulnerability Exposes Hitachi Energy Infrastructure — 2025 Analysis
In December 2025, Hitachi Energy disclosed a critical vulnerability (CVE-2024-3596) impacting their AFS, AFR, and AFF series infrastructure hardware, widely deployed in the global energy sector. The issue centers on improper enforcement of message integrity in RADIUS communications, allowing attackers in a local network to exploit a chosen-prefix collision attack against the MD5 response authenticator. This could let a malicious actor forge RADIUS authentication responses — potentially leading to unauthorized network access, disruption of critical systems, or exfiltration of sensitive data. The flaw carries a CVSS score of 9.0 (critical), but exploitation requires high attack complexity. This case highlights the continued risks posed by legacy authentication protocols and cryptographic weaknesses within operational technology environments. As adversaries increasingly target energy and critical infrastructure supply chains, prioritizing secure authentication and traffic integrity mechanisms is vital to maintaining resilience and regulatory compliance.
8 months ago
Kill Chain
Mitsubishi Electric's GT Designer3 Vulnerability (2025): Cleartext Credentials Endanger Industrial Systems
In December 2025, Mitsubishi Electric disclosed a vulnerability (CVE-2025-11009) impacting their GT Designer3 software, widely used in industrial control panel applications. Security researchers at Red Alert Lab discovered that plaintext credentials were being stored in project files, exposing critical manufacturing assets worldwide to potential unauthorized access. Although successful exploitation requires local access and has a high attack complexity, an attacker could obtain plaintext credentials to operate GOT2000 or GOT1000 series devices maliciously, raising risks for organizations with misconfigured networks or insufficient access controls. This incident highlights the persistent risk of cleartext credential exposures in operational technology, an issue often underestimated in critical infrastructure. With incidents involving credential theft and unauthorized device control on the rise, compliance frameworks and supply chain partners are placing increased urgency on eliminating weak storage practices in industrial environments.
8 months ago
Kill Chain
Güralp Systems 2025: Unauthenticated DoS Threat Hits Critical OT Devices
In December 2025, Güralp Systems disclosed a vulnerability affecting its Fortimus, Minimus, and Certimus Series devices, widely deployed in critical manufacturing and infrastructure sectors globally. The flaw (CVE-2025-14466) in the devices' web interface allows unauthenticated attackers on the network to send specially crafted HTTP requests, forcing the web service to restart and causing a temporary denial-of-service (DoS) condition. While the process automatically recovers, repeated exploitation could severely impact system availability for organizations relying on these seismic monitoring instruments. This type of DoS vulnerability is increasingly significant as threat actors increasingly target industrial control devices and operational technology (OT) with low-complexity attacks from unauthenticated vectors. Regulatory scrutiny of ICS network hygiene and cross-industry best practices is intensifying, pushing organizations to proactively address resource allocation and network exposure.
8 months ago
Kill Chain
CISA Issues 2025 Industrial Control System Vulnerability Advisories
In December 2025, CISA disclosed six critical advisories highlighting a series of vulnerabilities across multiple industrial control system (ICS) products, including those from Güralp Systems, Johnson Controls, Hitachi Energy, Mitsubishi Electric, and Fuji Electric. The advisories detail software and firmware flaws that could allow unauthorized access, remote code execution, or complete system compromise in essential ICS devices. Exploitation could give attackers the means to disrupt critical infrastructure operations. Security teams are urged to apply mitigations, restrict network exposure, and follow vendor instructions to reduce risk. This incident underscores the growing frequency and severity of cybersecurity threats targeting ICS environments. With the expanding attack surface in operational technology (OT) networks, attackers increasingly focus on exploiting ICS vulnerabilities to disrupt important sectors. Regulators and asset owners are under pressure to implement robust, up-to-date defenses.
8 months ago
Kill Chain
8 Million Users' AI Conversations Exposed: Urban VPN Browser Extension's Hidden Data Harvest
In December 2025, security researchers exposed that the popular Urban VPN Proxy browser extension—marketed for privacy—was actively harvesting and exfiltrating sensitive conversation data from over eight million users interacting with leading AI chatbot platforms such as ChatGPT, Claude, Gemini, and Copilot. The malicious behavior was introduced in versions released after July 2025, with the extension injecting scripts into browser sessions to intercept, package, and transmit users’ chatbot prompts, responses, and session metadata to servers operated by Urban VPN’s parent, BiScience, a known data broker. Users were not offered any meaningful way to disable this data collection besides uninstalling the extension, and the privacy disclosure was deeply buried within the setup process, leaving the majority unaware. This incident underscores the growing risk posed by privacy-violating browser extensions, especially those with elevated reputations and millions of installations. As AI assistants become repositories for sensitive personal and corporate data, the implications of such data leaks—from regulatory compliance to business confidentiality—are amplified, driving urgent reassessment of browser extension governance and AI data security controls.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

