Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 4885 to 4896 of 5935
Critical 2025 METZ CONNECT EWIO2 Vulnerabilities: Auth Bypass and RCE Expose Industrial Control Risks
In November 2025, multiple critical vulnerabilities were disclosed in METZ CONNECT EWIO2 industrial control devices, enabling remote attackers to bypass authentication and gain full control, execute arbitrary code, and read sensitive device information. The flaws include authentication bypass (CVE-2025-41733), PHP remote file inclusion (CVE-2025-41734), unrestricted file upload (CVE-2025-41735), path traversal (CVE-2025-41736), and improper access control (CVE-2025-41737), with CVSS v4 scores ranging from 8.7 to 9.3. Affected devices are used globally in critical manufacturing environments, and exploitation could trigger operational disruption or unauthorized control. This incident is highly relevant as it targets the operational technology (OT) sector—a high-value, often less-protected attack surface increasingly sought after by threat actors. As convergence between IT and OT grows, unpatched, internet-exposed devices in critical infrastructure remain susceptible to devastating attacks, underscoring urgent need for robust patching, segmentation, and proactive defense.
8 months ago
Kill Chain
Schneider Electric 2025 SCADA Cryptography Flaw: What It Means for Industrial Cybersecurity
In November 2025, Schneider Electric disclosed a critical vulnerability (CVE-2025-9317) in its EcoStruxure Machine SCADA Expert and Pro-face BLUE Open Studio platforms, widely used across energy, manufacturing, and commercial sectors. The flaw involved the use of a broken or risky cryptographic algorithm within an AVEVA-supplied component, allowing local attackers with read access to project or cache files to reverse-engineer user passwords by brute-forcing weak password hashes. This could result in loss of confidentiality and integrity within impacted environments. No remote exploitation was identified, and there are no public reports of in-the-wild attacks as of the advisory date. This incident underscores persistent risks in ICS/OT software supply chains, where cryptographic weaknesses can enable privilege escalation and lateral movement by adversaries. With global regulators increasingly pressuring critical infrastructure providers on cyber hygiene and segmentation, this advisory highlights the urgency for supply chain and password management reforms.
8 months ago
Kill Chain
CISA Releases Critical ICS Vulnerability Advisories: 2025 Update for Industrial Systems
In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released six Industrial Control Systems (ICS) advisories addressing multiple critical vulnerabilities impacting popular ICS products, including Schneider Electric EcoStruxure and Pro-face BLUE Open Studio, Shelly Pro series, METZ CONNECT EWIO2, and PowerChute Serial Shutdown. These advisories alert asset owners, operators, and administrators about exploitation risks and provide detailed technical information and mitigation steps. The vulnerabilities, if left unaddressed, expose essential operational technology environments to risks such as unauthorized access, manipulation, and potential disruption of critical infrastructure services. This disclosure comes amidst a surge in attacks targeting industrial and OT environments, underscoring increased adversary focus on exploiting ICS vulnerabilities. With regulatory pressures mounting and recent attacks on critical infrastructure making headlines, organizations are urged to address these risks with urgency.
8 months ago
Kill Chain
Shelly Pro 4PM 2025 Vulnerability: Unchecked Resource Allocation Triggers Industrial DoS
In November 2025, a significant vulnerability (CVE-2025-11243) was disclosed in Shelly Pro 4PM, a smart DIN rail switch commonly used in critical manufacturing environments worldwide. The flaw, arising from improper resource allocation and lack of input bounds checking, allowed an attacker on the local network to trigger a denial-of-service condition by sending specially crafted RPC requests. This caused the device to overallocate memory and reboot, risking loss of control or downtime in industrial settings. No exploitation has been reported publicly, but affected firmware versions prior to 1.6 remain at risk until patched. This incident underscores the persistent risk of denial-of-service vulnerabilities in IoT and industrial devices, especially as connected manufacturing assets proliferate. The failure in secure resource management highlights the growing regulatory and operational focus on robust device security amid expanding threat surfaces.
8 months ago
Kill Chain
2025 Shelly Pro 3EM ICS Flaw Exposes Modbus Devices to DoS
In November 2025, a critical Out-of-Bounds Read vulnerability (CVE-2025-12056) was disclosed in the Shelly Pro 3EM, a smart DIN rail switch used in industrial control systems worldwide. Security researchers revealed that a specially crafted Modbus request allows attackers on the adjacent network to trigger an illegal memory access, causing a denial-of-service condition by repeatedly rebooting the device. All versions of the Pro 3EM are affected, including deployments across critical manufacturing sectors. Shelly did not issue an official response, leaving users to rely on CISA defensive guidance. This incident exemplifies the growing risk of targeted vulnerabilities in widely deployed OT (operational technology) and industrial IoT devices. As criminals and nation-state actors increasingly focus on ICS and critical infrastructure, maintaining robust segmentation, access controls, and secure outbound communications is more relevant than ever.
8 months ago
Kill Chain
KongTuke 2025: Real-World Insights from a Fake CAPTCHA Malware Campaign
In November 2025, the KongTuke threat actor (also referenced as LandUpdate808 or TAG-124) orchestrated a malware campaign leveraging sophisticated Traffic Distribution System (TDS) techniques. The attackers compromised legitimate websites by injecting malicious scripts that displayed fake CAPTCHA pages designed to lure victims into executing clipboard-injected PowerShell commands. Once executed, these commands downloaded a ZIP archive containing a Windows-compatible Python environment and a malicious Python script, which established persistence via scheduled tasks and generated encrypted HTTPS traffic to external infrastructure. The infection sequence was confirmed within Active Directory environments, highlighting the attacker's ability to evade detection and automate persistence. This incident underscores an increasing trend in malware distribution leveraging trusted websites as initial access vectors, blending social engineering with technical innovation. Organizations should take note of the evolving sophistication in initial lure tactics and persistence mechanisms, as such approaches complicate traditional detection methods and pose substantial risk to enterprise endpoints.
8 months ago
Kill Chain
Fortinet’s Silent Patch Leaves FortiWeb Customers Exposed to Critical Exploit in 2024
In October 2024, Fortinet faced significant criticism after a critical vulnerability (CVE-2025-64446) in its FortiWeb application firewall was exploited by attackers before the flaw was publicly disclosed or a CVE was assigned. Although a patch was silently released on October 28, public notification and technical details were delayed for over two weeks, leaving customers unaware of the immediate risk posed by the vulnerability. During this window, attackers leveraged a path-traversal bug to gain administrative command execution and persistent access, potentially compromising affected infrastructures and evading detection until after widespread exploitation was underway. This incident highlights the increasing risk that delayed vulnerability disclosures pose to organizations, as attackers can weaponize defects before defenders are informed. The event has intensified calls for timely vendor transparency and reinforced scrutiny from regulators as the cyber threat landscape evolves toward faster exploitation cycles and greater demands for coordinated defensive action.
8 months ago
Kill Chain
Pennsylvania Attorney General Hit by Ransomware: 2025 Data Breach Exposes Medical Information
In August 2025, the office of Pennsylvania's Attorney General fell victim to a ransomware attack orchestrated by the INC Ransom group. Attackers infiltrated internal networks and subsequently encrypted critical systems, ultimately exfiltrating files containing sensitive information, including personal and medical data belonging to individuals engaged with the office. The breach disrupted business operations and prompted an immediate investigation and regulatory disclosure. Investigators found that the attackers leveraged privilege escalation, moved laterally within the network, and evaded basic security controls, showcasing the advanced tactics employed by today’s ransomware operators. This incident highlights the growing threat of sophisticated ransomware gangs targeting public sector entities, expanding their focus to sensitive government-held data. The frequency and impact of ransomware incidents on critical services underscore an urgent need for robust segmentation, modern encryption, and relentless threat monitoring.
8 months ago
Kill Chain
Microsoft Azure Faces Unprecedented 15 Tbps DDoS Attack Driven by Aisuru Botnet
In June 2024, Microsoft revealed that its Azure cloud network was targeted by the Aisuru botnet in a record-breaking Distributed Denial-of-Service (DDoS) attack that peaked at 15.72 terabits per second. The attack leveraged over 500,000 globally distributed IP addresses to inundate Azure’s infrastructure, demonstrating sophisticated command and control and massive botnet scale. Microsoft successfully mitigated the assault, which represented the largest DDoS attack it had ever recorded, but the event highlighted the evolving threat landscape and ongoing attacker focus on major cloud service providers. The incident is highly relevant today as DDoS tactics grow in scale and complexity, frequently outpacing conventional network defenses. The use of enormous botnets like Aisuru and automated attack infrastructure underscores the urgent need for advanced mitigation, segmentation, and resilient cloud architectures across all industries.
8 months ago
Kill Chain
Eurofiber France Data Breach 2024: Ticket System Compromise Exposes Customer Records
In June 2024, Eurofiber France disclosed a significant data breach after its ticket management system was compromised by threat actors who exploited a vulnerability. The attackers gained unauthorized access to the ticketing platform, proceeding to exfiltrate customer data before attempting to sell it on an underground forum. The breach exposed personal and business information, prompting notification to affected clients and regulatory authorities, and forced Eurofiber to review and enhance its internal security measures. This incident highlights the persistent targeting of essential infrastructure vendors via vulnerable business applications, such as ticketing systems. It reflects the growing risks of data exfiltration and underground marketplaces, prompting renewed scrutiny on third-party software security and compliance requirements.
8 months ago
Kill Chain
Princeton University Data Breach Exposes Alumni and Donor Information
On November 10, 2023, Princeton University experienced a significant data breach when unauthorized actors gained access to a university database containing sensitive information on alumni, donors, students, and faculty. The intrusion exposed personal details such as names, contact information, and donation records, with initial reports indicating the compromise originated from the university’s advancement and fundraising systems. Princeton moved quickly to secure impacted systems, notify affected individuals, and engage cybersecurity experts and law enforcement. The exposure raises concerns regarding the safeguarding of high-value personal and financial data held by educational institutions. This incident underscores the persistent threat higher education institutions face from cyberattacks targeting personal and philanthropic data. The Princeton breach highlights a surge in attacks exploiting third-party platforms and unencrypted internal data flows, aligning with broader trends toward increased ransomware and data extortion pressures observed throughout 2023.
8 months ago
Kill Chain
Dutch Police Dismantle Bulletproof Hosting Platform Backing Global Cybercrime in 2024
In May 2024, Dutch police executed a large-scale operation seizing approximately 250 servers linked to a notorious bulletproof hosting provider, long used by cybercriminals to anonymously deploy malware, phishing sites, and command-and-control infrastructure. With coordinated assistance from international partners, Dutch law enforcement dismantled the physical hosting environment and arrested several individuals believed to be operators of the service. This action disrupted ongoing criminal campaigns, significantly hindering multiple ransomware groups, credential theft operations, and other cybercrime syndicates that relied on the provider’s infrastructure to evade detection and takedown efforts worldwide. This takedown comes amid increased law enforcement focus on infrastructure-level cybercriminal enablers, highlighting a shift from targeting individual attackers to undermining the technical ecosystems that fuel large-scale cyber threats. The collapse of this hosting service may cause short-term disruption to criminal activity, but also signals growing regulatory and legal scrutiny on infrastructure managed for malicious purposes.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

