Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4849 to 4860 of 5935
Sanctions Hit Russian Bulletproof Hosting Providers Backing Global Ransomware
In June 2024, the United States, together with the United Kingdom and Australia, imposed sanctions on Russian bulletproof hosting provider Media Land and associated entities. Investigations revealed these providers had knowingly facilitated ransomware operations and other cybercriminal activities by offering infrastructure shielding malicious actors from law enforcement, particularly ransomware gangs operating out of Russia. The sanctions block their financial assets and prohibit transactions, aiming to disrupt the ecosystem supporting high-profile global ransomware attacks and cybercrime. This incident is significant amid a surge in ransomware and supply-chain attacks worldwide, with threat actors increasingly relying on bulletproof hosting to evade detection. Governments are moving quickly to cut off these enablers as part of a broader strategy against organized cybercrime.
8 months ago
Kill Chain
Phishing-as-a-Service Evolves: Sneaky2FA Adds Browser-in-the-Browser Attacks in 2024
In early June 2024, cybersecurity researchers reported that the Sneaky2FA phishing-as-a-service (PhaaS) kit has adopted the Browser-in-the-Browser (BitB) attack tactic, previously used by red teamers, to improve the effectiveness of credential phishing campaigns. This new feature enables threat actors using the Sneaky2FA service to launch highly convincing fake login pop-ups, closely mimicking legitimate authentication flows, including prompts for multifactor authentication (MFA). The update broadens the risks for both organizations and individuals, as traditional indicators of phishing are increasingly hard to spot. The deployment of BitB tactics by a turnkey phishing kit marks a concerning development in the automation and commercial accessibility of advanced cybercrime techniques. This incident underscores the escalating sophistication of phishing attacks driven by the commoditization of offensive security techniques. Organizations face renewed urgency to revisit their authentication controls, user awareness training, and phishing-resistant MFA, as adversary innovation quickly outpaces conventional defense measures.
8 months ago
Kill Chain
Critical W3 Total Cache Plugin Vulnerability Enables PHP Command Injection on WordPress Sites
In June 2024, a critical security vulnerability was disclosed in the W3 Total Cache WordPress plugin, which is widely used to optimize website performance. Attackers could exploit this flaw by submitting a specially crafted comment to a vulnerable website, enabling them to execute arbitrary PHP commands on the underlying server. This vulnerability, involving insufficient sanitization and validation within comment processing, exposes affected websites to full compromise, including unauthorized data access, web defacement, and further lateral movement inside hosting environments. Immediate patching is required as active exploitation has been observed in the wild. This incident underscores the persistent risk of supply chain attacks and plugin vulnerabilities in content management systems like WordPress. As attackers increasingly target high-profile plugins to gain initial access, maintaining up-to-date software and implementing robust security controls has never been more critical.
8 months ago
Kill Chain
FortiWeb CVE-2025-58034: Command Injection Attack on Fortinet's WAF
In November 2025, Fortinet disclosed a medium-severity vulnerability in its FortiWeb application firewall, tracked as CVE-2025-58034 (CVSS 6.7), which was found exploited in the wild. The flaw is an OS command injection issue (CWE-78) that allows authenticated attackers to execute unauthorized OS commands via improper neutralization of special elements. Attackers leveraged this weakness to gain control over vulnerable web application environments, potentially facilitating lateral movement, data access, and further exploitation, with threat activity detected before a patch was widely adopted. This incident highlights a persistent trend of attackers rapidly weaponizing new vulnerabilities in widely deployed web application security platforms. With adversaries increasingly targeting edge appliances and exploiting authentication weaknesses, organizations must prioritize timely vulnerability management and layered defense to protect sensitive workloads.
8 months ago
Kill Chain
Ransomware Disrupts European Airports in 2025: HardBit & SonicWall VPN Exploit
In September 2025, a coordinated HardBit ransomware attack caused significant operational disruptions across several European airports. The attack exploited a vulnerability in SonicWall SSL VPN devices (CVE-2024-40766), allowing threat actors to bypass multi-factor authentication and gain unauthorized access to critical infrastructure. Prompt law enforcement action led to the arrest of an initial suspect by the UK’s National Crime Agency, though details remain limited as investigations continue. The attack, labeled by researchers as primitive yet effective, underscores how quickly threat actors are leveraging both publicly available exploits and compromised credentials to disrupt essential services with ransomware. This event made headlines due to its impact on vital transportation infrastructure and prompted an international response highlighting the growing urgency for robust network segmentation, encrypted traffic measures, and rapid threat detection. The incident also reflects a broader trend of ransomware actors increasingly targeting critical sectors using innovative entry vectors and expanding their global footprint.
8 months ago
Kill Chain
Mobile Malware Soars in Q3 2025: Key Insights from Kaspersky's Global Report
In Q3 2025, Kaspersky reported a significant surge in mobile malware activity, with 47 million attacks prevented globally targeting Android devices with Trojans, adware, banking malware, and ransomware. Threat actors exploited new variants—including BADBOX and sophisticated Trojans like Triada and Fakemoney—utilizing methods such as pre-installed backdoors and malicious app mods. Mobile banking Trojans (especially Mamont and Coper) and region-targeted malware attacks in Turkey, India, Iran, and Germany impacted financial data security and user privacy, highlighting expanding attacker sophistication and supply chain compromise. This incident is critical as it illustrates the rising prevalence and complexity of mobile threats, coinciding with increased ransomware attacks and evolving delivery channels. The continued targeting of financial apps and global user bases signals an urgent need for organizations to strengthen mobile security, visibility, and compliance with privacy mandates.
8 months ago
Kill Chain
ServiceNow AI Agents Breached in 2025 via Second-Order Prompt Injection
In November 2025, security researchers uncovered a novel method by which ServiceNow's Now Assist generative AI platform could be manipulated through second-order prompt injection attacks. By exploiting default configurations and inherent agent-to-agent communication, attackers could coerce agentic AI features into executing unauthorized operations. This exposure allowed malicious actors to access, copy, and exfiltrate sensitive enterprise data without proper user authorization. The attack leverages prompt injection to bypass intended policy boundaries, posing significant data risk to organizations relying on ServiceNow’s AI-driven automations. This incident highlights a growing threat landscape in which AI agent-to-agent interactions are harnessed for sophisticated attacks. With increased enterprise adoption of generative AI and autonomous agents, security around configuration and prompt validation has become mission-critical. Organizations should assess agent communication safeguards and be vigilant against emerging prompt injection and shadow AI risks.
8 months ago
Kill Chain
EdgeStepper: PlushDaemon’s DNS Hijack Shakes Supply Chain Trust
In late 2025, the threat actor PlushDaemon leveraged a custom Go-based implant named EdgeStepper to facilitate a sophisticated supply chain attack targeting organizations relying on automated software updates. By hijacking DNS queries via EdgeStepper, attackers rerouted legitimate update traffic to attacker-controlled infrastructure, covertly delivering malware payloads. This adversary-in-the-middle campaign exploited a weakness in outbound traffic validation and DNS trust, leading to silent compromise of enterprise endpoints through poisoned software update mechanisms. The incident resulted in widespread concerns over supply chain integrity and exposed gaps in security monitoring of encrypted or internal network flows. This incident highlights the growing trend of adversaries exploiting DNS and software supply chains as primary attack vectors. With regulatory and industry focus tightening on secure update mechanisms and zero trust, similar AitM tactics are escalating in both frequency and sophistication, requiring renewed urgency for organizations to enhance detection at the DNS and network boundary layers.
8 months ago
Kill Chain
Operation WrtHug: Tens of Thousands of ASUS Routers Hijacked in Global Botnet Surge
In late 2025, tens of thousands of end-of-life ASUS routers worldwide were hijacked in a large-scale operation dubbed "WrtHug." The attackers exploited six unpatched vulnerabilities in outdated ASUS WRT firmware, targeting devices primarily in Taiwan, the U.S., and Russia, among others. After gaining unauthorized access, WrtHug actors enrolled these routers into a global botnet, leveraging them for coordinated command-and-control traffic and potentially for further attacks. The campaign highlighted the sustained risk posed by unsupported network equipment in both consumer and business environments. This incident underscores an ongoing surge in attacks targeting aging and end-of-life IoT devices, as cybercriminals capitalize on lapses in patching and lifecycle management. Organizations globally are under renewed pressure to inventory, segment, and securely retire vulnerable network infrastructure as such botnet tactics intensify.
8 months ago
Kill Chain
NHS Flags PoC Exploit for 7-Zip Symlink RCE Vulnerability (CVE-2025-11001)
In November 2025, NHS England Digital issued an advisory regarding a significant vulnerability (CVE-2025-11001) in the popular 7-Zip compression software. While no active in-the-wild exploitation was detected, a publicly available proof-of-concept (PoC) exploit for a symbolic link–based remote code execution (RCE) flaw raised concerns of imminent risk. The flaw, if exploited, could allow attackers to execute arbitrary code on systems using 7-Zip, threatening the confidentiality, integrity, and availability of healthcare data critical to NHS operations. Security teams were urged to prioritize patching and closely monitor for suspicious activity. This incident highlights a broader industry trend: attackers are rapidly weaponizing PoC exploits for newly disclosed vulnerabilities, targeting widely used utilities to enable lateral movement and privilege escalation. The urgency of patching and proactive threat detection has never been greater, especially for organizations in regulated sectors like healthcare.
8 months ago
Kill Chain
WhatsApp Hijack: Eternidade Stealer Campaign Hits Brazilian Users via Python Worm
In November 2025, cybersecurity researchers identified a sophisticated campaign targeting Brazilian users via WhatsApp, where attackers leveraged a Python-based worm combined with social engineering tactics. Victims were tricked into installing a worm that hijacked WhatsApp sessions and propagated itself to contacts, while delivering a Delphi-based banking trojan known as Eternidade Stealer. The campaign exploited IMAP to dynamically resolve command-and-control infrastructure, enabling threat actors to orchestrate info-stealing and credential harvesting at scale and with resilience to takedown attempts. The incident had significant implications for financial fraud and impacted numerous personal and business WhatsApp accounts across Brazil. This campaign is emblematic of a wider surge in malware leveraging messaging platforms for lateral movement and rapid propagation. The popularity of WhatsApp, combined with increasingly modular infostealers and TTP reuse by criminal groups, highlights the urgent need for proactive controls and visibility across both east-west and outbound communication paths.
8 months ago
Kill Chain
Cloudflare 2025 Outage: A Wakeup Call for Web Security Resilience
In November 2025, Cloudflare suffered a significant intermittent outage lasting approximately eight hours, which disrupted access for many major websites relying on its services for security and DNS management. The outage was caused by an internal configuration error that expanded a critical feature file, impacting Cloudflare's Bot Management system and resulting in platform instability. Some organizations temporarily bypassed Cloudflare, exposing themselves directly to internet traffic and revealing vulnerabilities previously shielded by Cloudflare's protective layers, such as web application firewall (WAF), bot filtering, and DNS controls. These exposures led to increased malicious probing, raising concerns about previously undetected weaknesses and an overreliance on single-vendor security solutions. The incident highlights the growing operational and security risks of single-vendor dependency, especially as organizations rely more heavily on integrated cloud platforms for web security and availability. Broad industry adoption of zero trust and multi-cloud strategies is now a pressing priority to mitigate similar service disruptions and emergent threats.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

