Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4789 to 4800 of 5937
WhatsApp’s 2024 API Flaw: 3.5 Billion Accounts Exposed via Automated Scraping
In early 2024, a significant data exposure incident affected WhatsApp when researchers discovered and exploited a vulnerability in the platform's contact-discovery API. The API lacked effective rate limiting and permitted mass enumeration of registered user accounts by automating queries, enabling adversaries to harvest data on approximately 3.5 billion mobile phone numbers and associated details. No evidence suggests the involvement of a deliberate threat actor beyond security researchers, but the scale and scope highlight serious privacy and operational risks for both users and WhatsApp’s business integrity. The incident underscores ongoing risks for messaging applications leveraging public-facing APIs without stringent access and abuse controls. This breach is highly relevant as API abuse and large-scale account enumeration techniques are increasingly exploited by attackers seeking personal data. Regulatory scrutiny is poised to intensify, and similar flaws are being reported across numerous communications platforms, making robust API security and anomaly detection critical in today’s threat landscape.
8 months ago
Kill Chain
Cox Enterprises Data Breach 2024: Oracle Zero-Day Exploit Compromises Sensitive Data
In June 2024, Cox Enterprises disclosed a significant data breach where attackers exploited a zero-day vulnerability in Oracle E-Business Suite to gain unauthorized access to the company’s network. The exploitation enabled the threat actors to bypass existing security controls, potentially exfiltrating sensitive personal data of customers and employees. The breach was detected after anomalous network activity was flagged, prompting a forensic investigation and subsequent notification to affected individuals. The incident underscores the ongoing risks associated with unpatched enterprise software and the increasing sophistication of threat actors in targeting supply-chain and business applications. This breach is particularly relevant amid a surge in zero-day exploits targeting enterprise management platforms, highlighting the urgency for robust vulnerability management, continuous monitoring, and rapid incident response. Organizations must reassess their exposure to similar risks due to heightened regulatory scrutiny and the evolving tactics used by cybercriminals.
8 months ago
Kill Chain
CISA Flags Critical Oracle Identity Manager Zero-Day as Actively Exploited
In June 2025, a critical zero-day vulnerability (CVE-2025-61757) affecting Oracle Identity Manager was added to CISA’s Known Exploited Vulnerabilities catalog, following credible reports of active exploitation. Attackers leveraged a missing authentication flaw in a critical function, allowing remote, pre-authenticated access and full compromise of affected systems. Organizations using Oracle Identity Manager faced a risk of unauthorized access, credential theft, and lateral movement, with potential for widespread service disruption and data exfiltration across enterprise networks. Remediation required rapid deployment of patches and security controls to prevent further breaches. This incident underscores the rising impact of identity-driven attack vectors targeting core authentication systems, with adversaries increasingly exploiting zero-day flaws in widely-used identity platforms. The exploitation highlights an urgent need for strengthened identity protection, patch management, and zero-trust segmentation as attackers target the intersection of critical infrastructure and identity orchestration.
8 months ago
Kill Chain
Matrix Push C2 Phishing Exposes Fileless Browser Attacks in 2025
In November 2025, a sophisticated phishing campaign was uncovered utilizing a novel command-and-control (C2) platform called Matrix Push C2. The threat actors exploited browser push notifications, fake alerts, and fileless redirection to lure users across multiple operating systems into interacting with malicious links. Researchers observed that the campaign delivered phishing payloads without traditional downloads, thereby evading many endpoint defenses and expanding its cross-platform reach. Impacted organizations reported heightened risks of credential theft, business email compromise, and data exfiltration stemming from the hard-to-detect, browser-native behavior of Matrix Push C2. This incident highlights the escalating threat of fileless attacks and creative social engineering, particularly as businesses increasingly rely on browser-based workflows. The abuse of browser notifications as a phishing vector presents a growing challenge for security teams and underscores the importance of proactive browser and endpoint defenses.
8 months ago
Kill Chain
Salesforce Data Breached Again: ShinyHunters Exploit Third-Party Gainsight in 2024 Attack
In June 2024, several Salesforce customers experienced a significant data breach perpetrated by the ShinyHunters extortion group. Attackers exploited vulnerabilities in a third-party vendor, Gainsight, which had integrations with Salesforce platforms. By compromising Gainsight, ShinyHunters acquired credentials or access tokens, enabling them to exfiltrate sensitive Salesforce customer data from multiple organizations. The breach demonstrates the persistent risk of attacks originating from trusted third-party software supply chains, resulting in the exposure of business and customer information and raising concerns about the security posture of major SaaS ecosystems. This breach highlights a continued trend in which attackers bypass direct controls by targeting vendors in a SaaS environment, leveraging weak third-party access and inadequate segmentation. As businesses increase SaaS adoption and interconnectivity, these attacks demonstrate the urgent need for enhanced third-party risk management and more granular network and identity controls.
8 months ago
Kill Chain
APT31 Orchestrates Stealthy Cloud-Based Attack on Russian IT Firms (2024–2025)
Between 2024 and 2025, the advanced persistent threat group APT31, linked to China, conducted a series of covert cyberattacks against Russia’s IT sector, specifically targeting firms involved in government contracting. Leveraging cloud services and encrypted traffic, the attackers infiltrated networks while remaining undetected for long periods. APT31 employed sophisticated lateral movement, abuse of multicloud visibility gaps, and zero trust segmentation bypasses, resulting in the exfiltration of sensitive data and potential compromise of government-integrator communication flows. This incident reflects growing tensions and evolving threat tactics in state-sponsored cyberespionage, where cloud infrastructure, stealthy east-west movements, and advanced evasion are exploited. The attack underscores the critical need for enforced segmentation, robust cloud-native security, and proactive anomaly detection to defend against advanced persistent threats targeting the IT supply chain.
8 months ago
Kill Chain
LINE Messaging Bugs Expose Millions to Asian Cyber Espionage in 2024
In June 2024, security researchers disclosed several critical vulnerabilities in the LINE messaging app, widely used across Asia, arising from its use of a proprietary and flawed cryptographic protocol. The bugs enable attackers to intercept and replay message traffic, impersonate users, and siphon sensitive chat data, despite the app's claims of end-to-end encryption. No specific threat actor has been confirmed, but the flaws create opportunities for state-sponsored espionage and criminal data compromise. The weaknesses persist in both in-app and network-level communication, putting millions of users’ private conversations at risk. This incident highlights the dangers of custom security implementations and is of urgent concern given LINE’s importance in business and personal use across Asia. With attackers increasingly targeting messaging platforms and governments ramping up regulatory scrutiny around privacy and secure communications, organizations must prioritize rigorous security architecture and compliance.
8 months ago
Kill Chain
Hacker Exposes 2.3TB in FS Italiane / Almaviva Supply Chain Breach (2024)
In June 2024, a hacker reportedly breached the systems of Almaviva, an Italian IT provider serving FS Italiane Group, the nation’s railway operator. The attacker claimed to have exfiltrated 2.3TB of sensitive corporate data—including documents, contracts, financial information, and communications—garnered by exploiting weaknesses in the supplier’s defenses. Although FS Italiane’s operational technology was not directly compromised, the breach of Almaviva’s infrastructure exposed highly confidential client and business data, raising concerns about third-party risks and data privacy for an array of Italian public sector organizations. This incident highlights a worrying trend of attackers targeting IT services providers as a conduit for large-scale data breaches against critical infrastructure operators. With supply chain vulnerabilities on the rise, organizations must urgently reassess their vendor risk management and network segmentation strategies to prevent similar cascading impacts.
8 months ago
Kill Chain
Scattered Spider Strikes: 2024 Transport for London Cyber Breach
In August 2024, Transport for London (TfL), the body responsible for the UK's capital city transit system, suffered a major cyber incident allegedly orchestrated by members of the Scattered Spider cybercriminal group. Attackers exploited weaknesses in TfL's digital infrastructure to gain unauthorized access, compromising sensitive customer data and disrupting critical services. The breach, which resulted in millions of pounds in damages and regulatory scrutiny, underscored the growing threat that organized cybercriminal gangs pose to public-sector organizations. Two British teenagers have since been arrested and charged, though they have pleaded not guilty in court. This incident highlights the increasing trend of skilled threat actors leveraging sophisticated tactics—such as social engineering and lateral movement—to target essential services. Heightened regulatory pressure and public concern reinforce the urgent need for robust cybersecurity measures across critical infrastructure sectors.
8 months ago
Kill Chain
ToddyCat APT: How a Persistent Attacker Breached Outlook and Microsoft 365 Email in 2024
Between mid-2024 and early 2025, the ToddyCat advanced persistent threat (APT) group executed a sophisticated campaign targeting organizations' internal infrastructures to covertly access business email. Initially leveraging a new PowerShell variant of their TomBerBil tool to extract credentials, cookies, and encryption keys from browsers via SMB on privileged hosts, the group also introduced additional tools—TCSectorCopy and XstReader—to capture locked Outlook OST files and exfiltrate their contents. When detection increased, ToddyCat shifted to harvesting OAuth 2.0 tokens for Microsoft 365 mail through memory dumping, enhancing their ability to bypass on-host monitoring and access cloud emails externally. This campaign resulted in extensive compromise of sensitive correspondence, credentials, and lateral movement across impacted domains. This incident underscores the rapidly evolving tactics of nation-state groups to overcome modern defenses, highlighting trends in cross-cloud compromise, credential harvesting, and exploitation of endpoint-to-cloud trust boundaries. ToddyCat's use of both system-level and identity-driven attacks mirrors the increasing prevalence of multifaceted cyber threat techniques.
8 months ago
Kill Chain
Grafana 2025: Critical Admin Spoofing Flaw Demands Immediate Response
In June 2025, Grafana Labs disclosed a critical security vulnerability (CVE-2025-41115) affecting its Enterprise platform, enabling attackers to register new users and assign them administrator privileges or escalate existing privileges through crafted requests. This flaw made it possible for unauthorized actors to gain full control over instances, potentially compromising sensitive data dashboards and associated integrations. Grafana responded by releasing urgent patches, issuing advisories, and recommending immediate action to all Enterprise customers to prevent exploitation in production environments. This incident is particularly notable given the increasing threat posed by privilege escalation vulnerabilities in widely deployed SaaS and cloud-native products. Enterprises leveraging Grafana or other observability platforms must remain vigilant as attackers increasingly target misconfigurations and logic flaws to bypass identity-based controls and gain elevated access.
8 months ago
Kill Chain
CrowdStrike Insider Breach: How Scattered Lapsus$ Exploited Trusted Access in 2024
In early 2024, cybersecurity firm CrowdStrike identified an insider threat after discovering that an employee had shared screenshots of internal systems with external threat actors. The images, which were later leaked on Telegram by the Scattered Lapsus$ Hunters group, exposed sensitive details about CrowdStrike’s infrastructure and internal processes. CrowdStrike swiftly conducted an internal investigation, isolated the breach, and collaborated with law enforcement to mitigate potential risks. The incident highlights the growing challenge organizations face in protecting against trusted insiders acting maliciously or under external influence. This breach is particularly relevant given the increasing frequency of insider-driven attacks and the adoption of social engineering by advanced threat groups to bypass traditional perimeter defenses. The incident underscores the need for organizations to enhance their monitoring of internal activities and emphasize zero trust models.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

