Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 5017 to 5028 of 5935
Quantum Route Redirect PhaaS: The 2024 Microsoft 365 Phishing Surge
In 2024, cybersecurity researchers discovered that a Phishing-as-a-Service (PhaaS) platform named Quantum Route Redirect orchestrated a large-scale credential theft campaign targeting Microsoft 365 users globally. The threat actors leveraged a distributed network of roughly 1,000 malicious domains to automate phishing attacks and evade detection. Victims were lured through convincing emails, redirecting them seamlessly through multiple stages to capture login credentials. The campaign exploited the trust in corporate SaaS platforms, enabling attackers to compromise user identities, access sensitive business data, and potentially facilitate subsequent attacks across affected organizations. The incident highlighted widespread operational and reputational risks for enterprises relying on cloud collaboration platforms. This incident underscores the growing threat posed by PhaaS platforms, which are lowering the entry barrier for cybercriminals to launch sophisticated, scalable phishing campaigns. As email and identity-based attacks surge, organizations face urgent pressure to reinforce cloud security, strengthen user awareness, and adopt zero-trust frameworks to defend against evolving social engineering tactics.
8 months ago
Kill Chain
AI-Powered Malware & Hyper-V Exploits: The 2025 Multi-Vector Attack Recap
In early November 2025, a series of sophisticated cyberattacks targeted enterprise and consumer systems worldwide, exploiting vulnerabilities in Hyper-V virtual machines, RDP protocols, and leveraging malicious AI bots. Attackers deployed stealthy malware within virtualized environments to evade detection, while advanced spyware campaigns targeted Android devices using side-channel techniques to capture sensitive AI chat data. Additionally, high-profile service disruptions, including a mass WhatsApp account lockdown, affected millions of users and raised concerns about systemic vulnerabilities and cross-platform exploitation. The threat actors behind these incidents demonstrated new levels of coordination and adaptability, with alliances between major cybercrime groups amplifying the scope and impact of the campaigns. This incident underscores an accelerating trend toward multi-vector, AI-enabled cybercrime and highlights the convergence of ransomware, lateral movement, and novel attack methods across cloud and hybrid infrastructures. Security leaders should anticipate further escalation in both the sophistication and frequency of such attacks through 2025, heightening urgency for layered defenses and zero trust strategies.
8 months ago
Kill Chain
Konni APT Exploits Google’s Find Hub to Launch Data-Wiping Attacks
In late 2025, the North Korea-linked threat actor known as Konni (also referred to as Earth Imp, Opal Sleet, TA406, and Vedalia) launched a sophisticated campaign targeting Android and Windows users by abusing Google’s Find Hub functionality as a remote data-wiping weapon. The attackers impersonated psychological counselors and North Korean human rights activists, distributing malware via fake stress-relief applications that enabled remote access, data theft, and destructive wipes. The operation leveraged advanced evasion tactics, encrypted traffic channels, and targeted high-value individuals, resulting in significant loss and compromise of sensitive personal and organizational information. This incident exemplifies the growing risk from state-affiliated actors using social engineering and legitimate platform abuse to bypass defenses. With threat techniques evolving, organizations must now prioritize threat hunting, advance east-west traffic visibility, and enforce robust segmentation policies to catch and contain similar attacks.
8 months ago
Kill Chain
Triofox Flaw Exploited: How CVE-2025-12480 Enabled Remote Access Tool Attacks
In June 2025, cybersecurity researchers at Google's Mandiant Threat Defense uncovered active exploitation of a critical authentication bypass vulnerability (CVE-2025-12480, CVSS 9.1) affecting Gladinet's Triofox file-sharing and remote access platform. Attackers leveraged this n-day vulnerability—now patched—to gain unauthorized access to Triofox administrative configuration panels. With authentication circumvented, they uploaded and executed malicious payloads, specifically deploying remote access tools via the platform’s integrated antivirus feature. This enabled adversaries to establish persistent footholds, move laterally, and potentially exfiltrate sensitive corporate data and credentials. The incident underscores the ongoing urgency of patch management and monitoring, as threat actors continue to weaponize critical vulnerabilities within widely used collaboration and remote access tools. Industry experts warn of increasing attacks exploiting n-day vulnerabilities before patch adoption, reflecting a broader trend toward highly targeted lateral movement and remote tool deployment campaigns.
8 months ago
Kill Chain
CISA Flags Samsung Mobile Devices for Critical Exploited Vulnerability (CVE-2025-21042)
In November 2025, CISA added CVE-2025-21042, an out-of-bounds write vulnerability affecting Samsung Mobile Devices, to its Known Exploited Vulnerabilities (KEV) Catalog following active exploitation in the wild. Threat actors have leveraged this flaw to gain unauthorized control over affected devices, potentially allowing them to execute arbitrary code, escalate privileges, and compromise sensitive user data. The vulnerability poses significant risks to both federal agencies and commercial enterprises, prompting CISA to mandate remediation by federal civilian agencies under Binding Operational Directive (BOD) 22-01. Failure to remediate exposes organizations to data breaches and operational disruption. This incident highlights a broader wave of targeted exploits against widely used mobile platforms, illustrating attackers’ ongoing shift toward mobile devices as primary entry vectors. With regulatory attention intensifying, the urgency for rapid vulnerability management and proactive defense measures is escalated for all sectors.
8 months ago
Kill Chain
ClickFix Hospitality Breach: Infostealer Attack Impacts Hotels and Their Customers
In early 2024, a cybercrime campaign known as "ClickFix" targeted hospitality providers globally using infostealer and remote access trojan (RAT) malware. Threat actors gained initial access via spear phishing and malicious links, compromising hotel systems to harvest sensitive booking data and customer contact information. Attackers leveraged this stolen data to conduct highly convincing secondary phishing attacks directed at hotel customers via both email and WhatsApp channels, exposing guests to social engineering, fraud, and further credential theft. This cascading impact emphasized the attacker's focus on exploiting trusted relationships across business and customer environments. The incident is notable for its dual-target strategy, harnessing a single breach to fuel broader downstream attacks and demonstrating attackers' sophisticated use of layered social engineering. As infostealer activity surges across the hospitality and service sectors, defenders must adapt to increasingly persistent, multi-stage campaigns that pose risks for both enterprise operations and their customers.
8 months ago
Kill Chain
TEE.fail: 2025 Hardware Attack Cracks Latest Secure Enclaves
In November 2025, researchers disclosed a critical hardware attack known as TEE.fail, which compromised secure enclaves (trusted execution environments or TEEs) across Intel, AMD, and ARM chips. By placing a small hardware device between a DDR5 memory chip and the motherboard, and leveraging kernel-level privileges, attackers were able to bypass the most advanced TEE protections including Confidential Compute, SEV-SNP, and TDX/SDX. Once exploited, these secure enclaves could no longer be trusted to protect sensitive data in-use, raising major concerns for cloud providers, enterprises, and users reliant on confidential computing. The attack’s low cost, simplicity, and applicability to modern hardware make it a significant development, reflecting growing sophistication in hardware-level threats. Regulatory scrutiny and industry attention have intensified as organizations reevaluate their trust assumptions and risk models for sensitive workloads.
8 months ago
Kill Chain
runC Vulnerabilities Threaten Container Security: Docker and Kubernetes Breach 2024
In June 2024, critical vulnerabilities (CVE-2024-21626, CVE-2024-21627, and CVE-2024-21628) were disclosed in the runC container runtime, which underpins Docker, Kubernetes, and many modern container platforms. These flaws could be exploited by attackers to break out of a container, bypassing isolation controls and gaining unauthorized access to the underlying host system. A successful exploit would allow lateral movement and potentially compromise entire cloud or on-premises environments. Prompt patching and risk assessment are essential, as proof-of-concept exploits have already been published in the wild. This incident underscores the increasing sophistication and focus of attackers on supply chain and containerization technologies, as organizations accelerate cloud and DevOps adoption. As regulatory expectations around zero trust and runtime controls intensify, keeping pace with container threat vectors is now mission-critical for enterprise security teams.
8 months ago
Kill Chain
GlassWorm Supply Chain Attack: Malicious VSCode Extensions Threaten Open Source Ecosystem
In June 2024, the GlassWorm malware resurfaced in a significant supply chain attack on the OpenVSX and Visual Studio Code (VSCode) extension marketplaces. Threat actors uploaded three malicious extensions, which were collectively downloaded over 10,000 times before detection and removal. These extensions were designed to compromise developer environments by deploying malware capable of exfiltrating credentials and enabling persistent access. The attack leveraged trusted open-source ecosystems, making it difficult for end users and organizations to detect the compromise until indicators of compromise (IoCs) were published, potentially exposing sensitive data and intellectual property. This event underscores a broader rise in supply chain attacks targeting developer tools and open-source package ecosystems. The campaign highlights the urgent need for rigorous code vetting, extension auditing, and enhanced supply chain security controls as attackers increasingly exploit automated trust in widely used development platforms.
8 months ago
Kill Chain
Microsoft's 'Whisper Leak' Side-Channel Attack Bypasses Encryption for AI Traffic
In late 2025, Microsoft researchers uncovered the 'Whisper Leak' side-channel attack, a novel method allowing passive adversaries to deduce the topics of conversations with streaming AI language models despite the use of encrypted, high-performance network protocols. Attackers exploited traffic analysis techniques, observing packet timing and size patterns, to infer sensitive discussion details traversing enterprise VPNs and encrypted links. Although private circuit encryption such as MACsec and IPsec was in place, the attack effectively bypassed traditional data-in-transit security controls, raising concerns for sectors leveraging AI in sensitive communications. This incident is significant as it highlights an emerging risk where encrypted cloud AI traffic can be compromised via sophisticated traffic analysis, just as generative AI adoption is surging across regulated industries. It illustrates evolving attacker sophistication beyond classical exploits, prompting urgent review of AI data security and zero trust segmentation strategies.
8 months ago
Kill Chain
'Ransomvibing' Supply Chain Attack Strikes Visual Studio Extension Marketplace
In early 2024, a malicious Visual Studio Code extension named 'Ransomvibing' was discovered on the Visual Studio Marketplace. The extension used AI-generated code to encrypt and exfiltrate sensitive project data from developer environments, leveraging encrypted outbound traffic to evade traditional detection methods. Despite containing telltale signs of automation and suspicious behavior, the extension bypassed security controls and was downloaded before being taken down, exposing users to significant intellectual property and operational risks associated with a compromised development supply chain. This incident highlights growing risks in open-source and extension marketplaces, as attackers increasingly exploit trusted software ecosystems with novel supply-chain techniques. Organizations should prioritize continuous monitoring of third-party integrations and reinforce their zero trust controls in response to evolving adversary methods.
8 months ago
Kill Chain
Landfall Malware: Covert Mobile Surveillance Hits Samsung Galaxy in 2024
In early 2024, cybersecurity researchers uncovered a sophisticated mobile surveillance campaign targeting Samsung Galaxy users through a malware strain dubbed 'Landfall.' Delivered primarily via malicious apps and phishing schemes, Landfall granted attackers covert access to device microphones, cameras, geolocation, and sensitive stored data. The threat actors capitalized on advanced evasion tactics to remain undetected, enabling them to record conversations, track user locations, collect photos, and exfiltrate contacts without the victims’ knowledge. The incident highlights the growing complexity of targeted mobile threats and the operational risks facing organizations with a mobile workforce. With the rise of mobile malware like Landfall exploiting modern smartphones’ vast attack surface, security teams must reassess their controls for device management, east-west traffic monitoring, and policy enforcement. This case underscores the urgency for enterprises to adopt zero trust defenses and adapt to evolving mobile threat tactics.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

