Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4549 to 4560 of 5948
Siemens Building X Firmware Supply Chain Flaw: Risks and Mitigation
In December 2025, Siemens disclosed a critical vulnerability in its Building X - Security Manager Edge Controller (ACC-AP), affecting all firmware versions. The flaw, tracked as CVE-2022-31807, is an improper verification of cryptographic signature that enables a local—or, in some cases, remote—attacker to upload maliciously altered firmware to the device. This could be exploited by an individual with physical access or by intercepting firmware updates, introducing risks to device integrity and broadening the attack surface in critical manufacturing environments. Siemens has issued operational mitigations but no permanent patch is planned. This incident highlights increasing attention on firmware supply chain vulnerabilities across operational technology (OT) in critical infrastructure. Insecure update mechanisms are a prime target for actors seeking persistent access or sabotage, echoing a trend that is prompting regulators and organizations to strengthen controls—especially amid rising regulatory scrutiny and high-profile supply chain breaches.
8 months ago
Kill Chain
Siemens Discloses Physical Access Flaw in 2025 G5DFR Devices
In December 2025, Siemens Energy Services disclosed a critical vulnerability in all G5DFR versions of its Elspec G5 devices, affecting industrial control systems worldwide. Attackers with physical access could reset the Admin password by inserting a USB drive containing a public reset string, effectively bypassing authentication (CVE-2025-59392, CVSS 7.0). While exploitation required direct device access, successful attacks would allow unauthorized changes to critical system configurations, risking operational integrity within the energy sector. Siemens and CISA advised urgent firmware updates and robust network isolation to mitigate the risk. This incident highlights the persistent risk of physical-layer threats in critical infrastructure environments, even as digital attack surfaces expand. The availability of public reset procedures underscores the urgency in securing endpoints and the importance of layered, defense-in-depth strategies, especially given the evolving regulatory landscape and increased scrutiny on energy sector cybersecurity.
8 months ago
Kill Chain
Critical GDCM Vulnerability Risks Healthcare Medical Imaging Workflows
In December 2025, a significant vulnerability was disclosed in the Grassroots DICOM (GDCM) library, a critical open-source imaging component widely used in healthcare systems worldwide. Identified as CVE-2025-11266, this out-of-bounds write vulnerability could be triggered by simply opening a specially-crafted DICOM file, potentially crashing affected applications such as SimpleITK and medInria. The flaw, present in versions GDCM 3.0.24 and earlier, allows for denial-of-service and partial data and integrity impacts, increasing operational risk for healthcare environments that rely on medical imaging interoperability. This incident highlights the persistent risk posed by vulnerable third-party libraries in regulated industries like healthcare. The rise in supply chain threats and software dependencies magnifies the urgency for organizations to maintain rigorous patching practices and robust segmentation, as attackers increasingly target widely-deployed open-source components to disrupt critical services.
8 months ago
Kill Chain
Johnson Controls iSTAR Ultra Vulnerabilities: 2025 Exposure of OT Systems
In December 2025, Johnson Controls publicly disclosed critical vulnerabilities (CVE-2025-43873 and CVE-2025-43874) affecting several versions of its iSTAR Ultra and Edge G2 door controllers used in building automation across critical infrastructure sectors worldwide. These OS Command Injection flaws, exploitable remotely with low attack complexity and minimal user interaction, could allow attackers to gain full control of vulnerable devices, modify firmware, and potentially disrupt or compromise secure building environments. The vulnerabilities were responsibly reported by Reid Wightman of Dragos, and patches have been made available for affected products. This incident highlights increasing threats targeting operational technology (OT) in critical sectors, as cybercriminals and nation-state actors leverage software supply chain and device-level weaknesses for initial access. The prevalence of command injection vulnerabilities, coupled with rising demands for segmentation and zero trust architectures, elevates the urgency for organizations to update OT and IoT assets and enforce proactive defense strategies.
8 months ago
Kill Chain
Siemens SALT Toolkit Flaw Leaves Industrial Systems Exposed to MITM Attacks
In December 2025, Siemens disclosed a critical vulnerability (CVE-2025-40801) in its Advanced Licensing (SALT) Toolkit, affecting multiple industrial software products such as COMOS, NX, Simcenter, and Tecnomatix. The flaw—improper certificate validation in the SALT SDK when establishing TLS connections—could enable unauthenticated remote attackers to launch man-in-the-middle attacks. With a CVSS v4 score of 9.2, exploitation risk is high, potentially allowing attackers to intercept or manipulate sensitive industrial data and processes in critical manufacturing environments globally. Patches have been released for some products, but others remain without a fix. This incident is significant as it highlights ongoing challenges in implementing secure communication protocols within the industrial sector. The vulnerability underscores a wider trend of attackers exploiting flaws in authentication and encryption controls, emphasizing the urgent need for robust zero trust segmentation, encrypted traffic policies, and active vulnerability management as industries modernize.
8 months ago
Kill Chain
Authentication Bypass Exposes Siemens Gridscale X Prepay ICS: 2025 Breach Analysis
In December 2025, Siemens disclosed critical vulnerabilities impacting its Gridscale X Prepay solution, widely used in energy infrastructure. The flaws—an observable response discrepancy (CVE-2025-40806) and authentication bypass via capture-replay (CVE-2025-40807)—could allow remote attackers to enumerate valid user names and circumvent lockouts, compromising operational security. Discovered by Kira of The Raven Security and coordinated via Siemens ProductCERT and CISA, these issues placed globally deployed ICS systems at risk of unauthorized access by leveraging predictable system responses and token replay, potentially impacting sensitive control environments. This incident highlights an ongoing trend of attackers exploiting authentication weaknesses in industrial control systems, underscoring the need for strict access management and timely vulnerability mitigation. With ICS assets increasingly targeted and regulatory scrutiny rising, implementing robust segmentation and monitoring is more crucial than ever.
8 months ago
Kill Chain
Shanya Packer-as-a-Service: Ransomware’s New Obfuscation Arsenal
In May 2024, security researchers uncovered an emerging Packer-as-a-Service (PaaS) called Shanya, designed to help ransomware operators evade modern enterprise defenses. Shanya provides advanced payload obfuscation capabilities to threat actors, enabling the delivery of ransomware that bypasses endpoint detection and response (EDR) solutions. Attackers using Shanya can rapidly pack malware before deployment, making it harder to analyze and detect. Early incidents showed Shanya-packed ransomware used to swiftly gain lateral movement across compromised environments, disrupt business operations, and facilitate significant data encryption and extortion campaigns. The rise of packers like Shanya signals a growing trend: ransomware groups are leveraging SaaS-style services to increase automation, evasion, and reach. With increased regulatory scrutiny on incident response and a surge in ransomware targeting sectors with critical operations, businesses must urgently strengthen detection and response strategies to address evolving malware delivery techniques.
8 months ago
Kill Chain
CISA & MITRE Unveil 2025 CWE Top 25: The Most Dangerous Software Weaknesses
On December 11, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) and MITRE's HSSEDI jointly released the 2025 CWE Top 25 Most Dangerous Software Weaknesses advisory. This annual compilation highlights the most critical security flaws that are routinely exploited by adversaries to gain unauthorized access, exfiltrate sensitive data, or disrupt operations. The advisory urges software vendors, developers, and enterprise security teams to integrate the Top 25 into their vulnerability management, procurement, and secure development practices, as the listed weaknesses are a leading cause of breaches and operational disruptions sector-wide. The 2025 iteration of the list arrives amid a surge in high-profile breaches linked to software supply chain vulnerabilities and regulatory pressure for Secure by Design practices. Organizations that fail to address these prevalent weaknesses remain at heightened risk of data compromise, operational downtime, and non-compliance with modern security frameworks.
8 months ago
Kill Chain
Microsoft’s 2024 Zero-Day Exploitation: What Security Leaders Must Know
In June 2024, Microsoft released security updates addressing a critical zero-day vulnerability (CVE-2024-30051) that was actively exploited in the wild, targeting Windows operating systems. Threat actors leveraged this privilege escalation flaw to bypass security controls and gain elevated access privileges on compromised systems, potentially enabling further malware deployment and lateral movement. Nearly 50 vulnerabilities were patched in this cycle, with public proof-of-concept code available for several, raising the risk of rapid exploitation by cybercriminal groups and nation-state actors before widespread patch deployment. This incident underscores the persistent threat of zero-day vulnerabilities, the speed at which exploits circulate once publicly disclosed, and the substantial business risk posed to enterprises delaying patch management. Increasing regulatory scrutiny and evolving attack techniques demand urgent, proactive defense strategies.
8 months ago
Kill Chain
Storm-0249's Abuse of EDR Processes: A New Era of Stealth Attacks
In early 2024, threat actor Storm-0249 launched a series of stealthy attacks by weaponizing Endpoint Detection and Response (EDR) platforms alongside native Windows utilities. As an initial access broker, the group circumvented traditional EDR defenses to gain persistent entry into multiple enterprise environments. Leveraging legitimate EDR processes for their own activities, Storm-0249 was able to evade security monitoring, escalate privileges, and facilitate lateral movement. These tactics led to compromised data and footholds that were subsequently sold to other cybercriminal groups, increasing the overall risk for targeted organizations. The emergence of sophisticated actors repurposing security tools for malicious objectives highlights an urgent industry focus on advanced detection, segmentation, and the continual evolution of zero trust strategies. This incident reflects a growing trend: motivated threat groups exploiting trusted processes to blend in and extend dwell time inside modern network environments.
8 months ago
Kill Chain
AI Domain Impersonation Fuels 2024 ClickFix-Style Malware Surge
In early 2024, a cyberattack campaign known as the 'ClickFix Style Attack' emerged, exploiting cutting-edge social engineering and SEO poisoning techniques. Attackers leveraged widely searched AI-related domains such as Grok and ChatGPT, using search engine manipulation to lure unsuspecting users to weaponized websites. Once on these compromised pages, visitors were tricked into downloading malware under the guise of legitimate AI tools and browser extensions, enabling threat actors to gain persistent access to systems and exfiltrate sensitive data. The campaign highlights the growing sophistication and agility of attackers in blending trusted brands with social engineering ploys, ultimately threatening business operations and data integrity. This incident is particularly relevant as it showcases the convergence of AI hype, manipulated search results, and advanced social engineering, which increases the likelihood of successful malware delivery. Security teams must remain vigilant as attackers continue to target the widespread adoption of AI-driven tools and blur lines between legitimate and malicious sources.
8 months ago
Kill Chain
Microsoft December 2025 Patch Tuesday: Critical & Exploited Vulnerabilities Exposed
In December 2025, Microsoft addressed 57 vulnerabilities as part of its Patch Tuesday update, including three critical flaws and one (CVE-2025-62221) already being actively exploited. The vulnerabilities spanned across numerous Microsoft products such as Office, Outlook, Exchange, PowerShell, and the Windows Cloud Files Mini Filter driver. Notably, CVE-2025-64671 affected GitHub Copilot plugins for JetBrains, potentially enabling remote code execution via AI-driven code assistance. Attackers exploited privilege escalation and remote-code execution vectors, posing significant risks to system integrity and user data. The rapid disclosure and exploitation of some flaws before patches were available highlighted increasing attacker sophistication and speed. Incidents such as this emphasize the urgent need for timely patch management, especially as software supply chains and AI integrations become more prevalent. Security teams must remain vigilant against fast-emerging threats, as even mainstream platforms like Microsoft continue to face ongoing and complex exploitation attempts.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

