Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4777 to 4788 of 5937
Russian Threat Actors Weaponize Blender Files to Deliver StealC Malware in 2024
In early 2024, a sophisticated cyber campaign was identified where Russian-linked threat actors distributed the StealC V2 infostealing malware using malicious Blender 3D model files uploaded to popular 3D asset marketplaces such as CGTrader. Unsuspecting users who downloaded and opened these Blender files inadvertently executed trojanized Python scripts embedded within, enabling attackers to exfiltrate sensitive information including credentials, browser data, and cryptocurrency wallets. The campaign leveraged trusted platforms to evade detection and maximize potential victims among creative professionals and digital artists worldwide. This incident highlights the growing trend of weaponizing legitimate digital content and developer platforms to deliver sophisticated malware and infostealers. As attackers exploit emerging marketplaces and supply chains, businesses and individuals face increased risk of credential theft and data compromise, driving renewed urgency for Zero Trust security approaches and robust supply chain vetting.
8 months ago
Kill Chain
ShadowPad Malware Leverages New WSUS Flaw for Full-System Compromise (2025)
In November 2025, attackers leveraged a recently patched WSUS vulnerability (CVE-2025-59287) to compromise Windows Servers and distribute ShadowPad malware. According to the AhnLab Security Intelligence Center, the threat actors exploited misconfigurations in Windows Server Update Services to gain initial access, then deployed the open-source PowerCat tool to establish remote control and facilitate lateral movement. This campaign targeted enterprises relying on WSUS for patch management, allowing attackers to achieve persistent, full-system access and exfiltrate sensitive operational data. This incident underscores the growing threat of sophisticated supply chain attacks that exploit ubiquitous IT infrastructure and patched vulnerabilities. It highlights the urgent need for continuous visibility, proactive patch management, and comprehensive zero trust strategies across data centers and cloud environments.
8 months ago
Kill Chain
Fluent Bit 2025: Supply Chain Vulnerabilities Endanger Cloud Infrastructures
In October 2025, researchers unveiled a set of five critical vulnerabilities in Fluent Bit, a widely-adopted open-source cloud telemetry agent. These vulnerabilities allowed threat actors to bypass authentication and carry out path traversal attacks, achieving remote code execution and potential full infrastructure compromise. Exploiting these flaws, attackers could gain lateral movement inside cloud environments, disrupt operations via denial-of-service, and manipulate data tags, threatening confidentiality and availability across cloud deployments. The compromise highlights significant risks inherent in modern cloud supply chains, as compromised upstream dependencies can quickly propagate and affect numerous downstream organizations. This incident is particularly significant as supply-chain vulnerabilities targeting cloud-native tools are rising sharply, mirroring an industry-wide shift toward “living off the land” attacks. As organizations adopt more open-source agents and components, attackers increasingly exploit integration points, elevating the risk profile for even mature cloud infrastructures.
8 months ago
Kill Chain
Sha1-Hulud Strikes npm: Credential Theft Campaign Hits Over 25,000 Open-Source Repositories
In November 2025, security researchers uncovered a widespread supply chain attack dubbed the "Sha1-Hulud" wave targeting the npm registry. Threat actors compromised over 25,000 repositories by trojanizing hundreds of widely used npm packages, injecting malicious code into the preinstall scripts. This code siphoned developer credentials and environmental secrets during package installations, potentially giving attackers unauthorized access to private projects and infrastructure. The campaign relied on malicious npm uploads, affecting downstream open-source users and organizations across the software supply chain. This incident highlights the persistent risk of supply chain attacks via popular package ecosystems, underscoring the need for robust code vetting, audit logging, and least privilege principles. With growing reliance on open-source software, attackers continue to exploit trusted platforms to achieve broad compromise.
8 months ago
Kill Chain
Inside the STORM-2603 & JustAskJacky Multi-Vector macOS Stealer Campaign
In November 2025, a sophisticated multi-vector cyber campaign targeted macOS users, leveraging a cluster of new information stealers and advanced lateral movement techniques. Threat actors, prominently STORM-2603 and JustAskJacky, exploited vulnerabilities in east-west traffic controls and manipulated encrypted traffic in hybrid cloud environments to evade detection. Utilizing covert remote-access tools and exploiting hybrid connectivity pathways, the attackers exfiltrated sensitive business and personal data—including credentials and intellectual property—before security teams were alerted. The coordinated attack spanned several organizations, resulting in notable data leaks and operational disruption. This incident highlights the growing trend of high-performance, cross-platform info-stealing malware and the convergence of cloud, on-prem, and user device threats. Security leaders should note the increased adoption of identity-based policy enforcement, robust segmentation, and enhanced anomaly detection to counter similar campaigns now escalating in prevalence.
8 months ago
Kill Chain
Superbox Android TV Botnet: The Silent Takeover of Consumer Home Networks
In June-November 2025, thousands of Superbox Android TV streaming devices sold through major U.S. retailers were discovered to be covertly enrolled in a global botnet and residential proxy service, relaying internet traffic for cybercriminals without explicit user consent. Forensic analysis revealed pre-installed or required third-party apps that hijacked consumers’ networks for malware distribution, ad fraud, and account takeover campaigns, while redirecting connections to Chinese servers and proxy aggregation services. The incident drew attention from cyber intelligence firms, Google, and law enforcement as a major example of pre-compromised consumer IoT supply chain risk, with impacts ranging from individual privacy invasions to the widescale abuse of residential IP addresses for criminal operations. This breach highlights the accelerating trend of consumer IoT and smart devices being targeted for botnet recruitment and criminal proxy operations, often by exploiting unofficial app ecosystems and distribution channels. The case underscores mounting regulatory scrutiny, the complexity of securing home networks, and the growing need for device supply chain and east-west traffic visibility in both enterprise and residential environments.
8 months ago
Kill Chain
Spyware Surge: Targeted Attacks on Messaging Apps Expose High-Profile Users (2025)
In November 2025, multiple cyber threat actors leveraged sophisticated commercial spyware to infiltrate popular messaging applications, including Signal and WhatsApp, targeting high-value individuals such as government and military officials, civil society groups, and others across the US, Middle East, and Europe. The attackers used advanced tactics like phishing, malicious device-linking QR codes, zero-click exploits, and app impersonation to compromise accounts and deliver spyware, leading to unauthorized access, lateral movement, and further malicious payloads compromising victims’ mobile devices. This incident underscores an ongoing escalation in targeted mobile surveillance operations, with advanced spyware tools proliferating and threat actors increasingly focusing on messaging platforms. Rapid evolution in attack techniques and regulatory scrutiny make the threat highly relevant for organizations and individuals handling sensitive communications.
8 months ago
Kill Chain
Rondo Botnet Exploits Pentaho URL Mapping Flaws: Lessons from the 2022 Breach
In late 2022, the Hitachi Vantara Pentaho Business Analytics Server was targeted by attackers exploiting CVE-2022-43939 and CVE-2022-43769, leveraging flaws in URL mapping and URL-based access control. Threat actors, including the 'Rondo' botnet group, exploited a template injection vulnerability that allowed unauthenticated command execution by bypassing authentication controls via specific URL paths. This enabled attackers to remotely execute arbitrary code, potentially gaining control over affected systems, exfiltrate data, and laterally move within enterprise networks. The automation and scale of these attacks highlighted application misconfigurations, lapses in secure access control design, and the ongoing risk of vulnerable web application endpoints. This incident underscores a broader trend of threat actors exploiting subtle misconfigurations in URL handling and web server rules. Organizations are now under increased regulatory and operational pressure to audit legacy web applications and APIs, implement zero trust segmentation, and rigorously validate access control rules as attackers aggressively pursue these weaknesses.
8 months ago
Kill Chain
Salesloft Drift SaaS Breach: How Excessive Trust Unlocked CRM Data
In early 2024, the Salesloft Drift SaaS integration breach unfolded when attackers exploited security weaknesses in the Drift chatbot’s OAuth implementation. Malicious actors obtained chatbot OAuth tokens—intended for secure system integrations—and leveraged these for legitimate API calls against customer CRM environments, such as Salesforce. Because the tokens remained valid and were often granted excessive standing privileges, attackers could exfiltrate sensitive business records, contact information, support data, and even embedded credentials across over 700 organizations, all without immediate detection. This breach underscored a powerful new threat vector involving identity and permissions sprawl in SaaS and AI-driven environments. As organizations increasingly rely on deeply integrated third-party systems with broad and persistent access, similar attacks targeting privileged automation and identity-based authorizations are expected to surge without robust governance and continuous monitoring.
8 months ago
Kill Chain
Iberia Data Breach (2024): Supply Chain Compromise Exposes Airline Customer Data
In June 2024, Spanish airline Iberia disclosed a significant data breach originating from the compromise of an external supplier. Attackers leveraged a third-party network to steal approximately 77 GB of sensitive customer data, including contact information, travel details, and partial payment card data. The breach was first publicized on underground forums, with threat actors claiming possession of the data days before Iberia notified its customers. The incident underscores how supply chain vulnerabilities can directly jeopardize core business operations and customer trust, disrupting service continuity and triggering regulatory scrutiny for the airline industry. This breach illustrates the ongoing escalation of supply chain attacks, where organizations are exposed through weak vendor controls. With similar tactics increasingly exploited against critical infrastructure, maintaining robust controls over partners is now essential in light of growing attacker sophistication and tightening data protection requirements.
8 months ago
Kill Chain
CISA Issues Urgent Alert: Oracle Identity Manager Zero-Day (CVE-2025-61757) Exploited in Active Attacks
In June 2025, CISA issued an emergency warning following the discovery of active exploitation against Oracle Identity Manager (OIM), targeting a critical remote code execution vulnerability tracked as CVE-2025-61757. Attackers leveraged this flaw, possibly as a zero-day, to gain unauthorized access to governmental and enterprise identity infrastructures. Evidence shows threat actors performed arbitrary code execution on affected systems, enabling privilege escalation and potential lateral movement within targeted networks. This breach presents serious risks to the integrity and availability of authentication systems, exposing sensitive data and potentially undermining access controls across impacted organizations. The incident stands out due to a surge in direct attacks targeting identity infrastructure and core authentication providers. The increasing reliance on identity management platforms makes these systems high-value targets, highlighting a broader trend towards exploiting supply chain and zero-day vulnerabilities with immediate, widespread consequences.
8 months ago
Kill Chain
Unpacking the Qilin Ransomware Attack: Lessons from a ScreenConnect Breach
In early 2024, a Qilin ransomware attack demonstrated the risks of third-party remote access tools when threat actors gained entry via ScreenConnect to a corporate endpoint. Leveraging this precarious foothold, attackers navigated the environment, launched failed infostealer payloads, then successfully executed ransomware—all while evading detection due to severely limited log visibility. Despite these blind spots, incident responders from Huntress used endpoint forensics and cross-correlation of minimal artifacts to reconstruct the entire attack path, including lateral movement attempts and the precise ransomware execution timeline. This incident highlights the growing sophistication of ransomware actors using remote IT management software for covert entry. As RMM tool vulnerabilities and minimal logging become more prevalent, organizations face heightened risk and pressure to implement deeper east-west threat detection and robust zero trust network segmentation.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

