Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 5113 to 5124 of 5935
Survision LPR Cameras: Unauthenticated Access Vulnerability (CVE-2025-12108)
In November 2025, a critical vulnerability (CVE-2025-12108) was disclosed in Survision License Plate Recognition (LPR) cameras, affecting all product versions globally. The flaw stems from missing authentication safeguards, allowing threat actors to remotely access device configuration wizards without credentials. This enables full system compromise—enabling attackers to alter settings, exfiltrate data, or use compromised cameras as entry points for broader attacks on commercial infrastructure. Researchers at Microsec identified the issue and notified stakeholders, prompting immediate remediation efforts and a firmware update (v3.5) from Survision. No confirmed active exploitation has been reported so far. With physical security increasingly integrated with digital management systems, unauthenticated access to surveillance infrastructure exposes environments to cyber-physical risks. The urgency of this disclosure reflects a broader industry trend: attackers actively seek exposed IoT and operational tech lacking basic authentication, prompting rising regulatory scrutiny and heightened compliance mandates.
8 months ago
Kill Chain
Global Airports at Risk: Radiometrics VizAir 2025 Unauthenticated Access Exposes Critical Infrastructure
In November 2025, critical vulnerabilities were publicly disclosed in Radiometrics VizAir, a system widely deployed in global airport transportation infrastructure. The flaws (CVE-2025-61945, CVE-2025-54863, CVE-2025-61956) permit unauthenticated remote attackers to manipulate weather parameters, runway settings, and extract sensitive meteorological data via missing authentication controls and exposed credentials. Exploitation could disrupt airport operations, mislead air traffic control and pilots, and create hazardous flight conditions by disabling vital alerts or injecting false data. The vulnerabilities were reported by a security researcher and were assigned the highest CVSS score of 10.0, reflecting severe risk to operational safety. This incident highlights the escalating risk facing critical infrastructure as attackers increasingly target operational technology systems with low-complexity, high-impact exploits. Given the global reliance on secure flight operations, the breach underscores the urgency for robust authentication, segmentation, and credential management controls across transportation-critical systems.
8 months ago
Kill Chain
Hackers Weaponize Remote Access: Cargo Freight Hijacking Hits Supply Chain
In early 2024, cybercriminals orchestrated a sophisticated supply-chain attack targeting the logistics sector by weaponizing remote monitoring and management (RMM) tools to seize control over freight operations. Exploiting weak access controls and leveraging legitimate remote-access software, attackers infiltrated trucking company systems and issued unauthorized commands, redirecting and physically stealing cargo from moving supply chains. This intrusion resulted in significant operational disruption, untraceable cargo losses, and highlighted severe gaps in network segmentation and east-west traffic security. This attack marks a rise in real-world impacts from IT compromise, illustrating how digital breaches are now driving tangible disruptions across critical infrastructure. The incident underscores escalating regulatory scrutiny and the urgency of advanced security controls to mitigate supply-chain and identity-driven threats.
8 months ago
Kill Chain
SesameOp: AI API Abused as C2 in Advanced Malware Attack (2024)
In early 2024, cybersecurity researchers uncovered a sophisticated malware campaign involving the "SesameOp" backdoor, which leveraged OpenAI's API as a covert Command and Control (C2) channel. Threat actors behind this attack established persistence within targeted organizations using a custom Linux backdoor, routing communications through encrypted API calls to OpenAI infrastructure, thus evading traditional detection methods. The malware's use of legitimate AI service channels enabled threat actors to obfuscate malicious activity, complicating incident response and extending dwell time inside compromised environments. The incident underscored the rapid innovation of attacker tactics and the challenges enterprises face as generative AI ecosystems become embedded in critical workflows. This breach exemplifies a wider, emerging risk: attackers abusing popular cloud-based and AI-driven services for lateral movement, data exfiltration, and stealthy C2 operations. With AI adoption accelerating across industries, security teams must urgently reassess control frameworks, enhance anomaly detection, and enforce visibility on legitimate platforms often overlooked in legacy monitoring.
8 months ago
Kill Chain
Android BankBot-YNRK: 2024 Indonesian Mobile Wallets Targeted by Muting Malware
In 2024, a variant of the Android/BankBot malware known as YNRK targeted mobile users in Indonesia by disguising itself as legitimate applications, often distributed via third-party app stores or phishing campaigns. Once installed, the malware muted system alerts and abused accessibility services to perform unauthorized actions, including theft of credentials and the draining of cryptocurrency and mobile banking wallets. The attack leveraged overlays to capture user inputs and bypassed security mechanisms, resulting in significant financial losses for affected users, with widespread impacts across consumer mobile banking apps in the country. This incident highlights the ongoing evolution and sophistication of mobile banking malware, which increasingly targets emerging markets and exploits weak security controls on non-official app stores. The rapid adoption of mobile wallets and cryptocurrency platforms has made these attacks more lucrative and frequent, intensifying the need for proactive mobile security, user awareness, and regulatory oversight.
8 months ago
Kill Chain
Apple Patches 110 Vulnerabilities in Massive 2024 Security Update
In early November 2024, Apple released urgently needed security updates for its operating systems, patching 110 vulnerabilities across iOS, macOS, iPadOS, watchOS, tvOS, visionOS, Safari, and Xcode. Key vulnerabilities included memory corruption flaws in ImageIO and WebKit, with previous instances of such bugs leading to remote code execution. Several vulnerabilities could allow unauthorized access to sensitive user data or privilege escalation, and most major Apple product families were impacted. No active exploitation was reported, but these vulnerabilities posed significant risks, especially if exploited in the wild. This incident underscores the importance of timely patching for organizations leveraging Apple hardware, amid escalating regulatory expectations and sophisticated exploit development targeting zero-day vulnerabilities. With Apple devices often pivotal in hybrid and remote work environments, large-scale multi-platform vulnerabilities present an attack surface of interest to both cybercriminals and nation-state actors.
8 months ago
Kill Chain
Lazarus Breaches UAV Sector: 2024 Cyberespionage Attack Analysis
In early 2024, ESET researchers uncovered a targeted cyberespionage campaign orchestrated by the North Korea-aligned Lazarus Group against a prominent company in the Unmanned Aerial Vehicle (UAV) sector. The attackers leveraged the Operation DreamJob social engineering scheme, luring victims with fake job offers and delivering custom malware through malicious attachments. Once inside, Lazarus gained remote access, exfiltrated sensitive data, and attempted to move laterally across the compromised network, emphasizing the group's advanced targeting of critical aerospace technologies. This incursion exposed operational blueprints, intellectual property, and potentially sensitive communications, raising industry-wide alarm about advanced persistent threats targeting high-value sectors. This incident is especially relevant today due to increased targeting of defense and aerospace industries by state-sponsored actors using sophisticated social engineering paired with malware. The techniques seen in Operation DreamJob reflect a broader trend of highly-customized attacks utilizing credible lures and persistent denial detection tactics.
8 months ago
Kill Chain
SnakeStealer: 2024's Most Prolific Infostealer and Its Impact on Data Security
In early 2024, cybersecurity researchers identified a widespread surge in SnakeStealer malware infections targeting individuals and organizations across multiple sectors. This sophisticated infostealer penetrates devices through malicious attachments and compromised software, rapidly harvesting valuable personal and corporate information including browser credentials, cryptocurrency wallets, and sensitive documents. Once data is collected, it is exfiltrated to attacker-controlled servers, fueling cybercrime operations and secondary attacks. The rapid spread and effectiveness of SnakeStealer has led to significant business and operational risks, such as unauthorized access, data breaches, and identity theft. This incident highlights the escalating threat posed by modern infostealers, which continue to evolve their techniques to bypass security controls and evade detection. The sustained activity of SnakeStealer, coupled with copycat variants, underscores a trend of increasingly sophisticated, financially motivated cybercrime targeting both enterprise and individual data at scale.
8 months ago
Kill Chain
North Korean Operatives Pose as IT Job Seekers to Infiltrate Western Companies
In 2023, multiple Western technology firms fell victim to a sophisticated insider threat campaign involving North Korean operatives posing as freelance IT job seekers. These actors used false identities and forged CVs to secure remote employment and gain access to sensitive corporate environments. Once inside, they leveraged their positions to siphon proprietary information, commit financial fraud, and, in some cases, facilitate broader cyber-espionage activities by collecting credentials and mapping internal systems. The impact spanned financial loss, reputation damage, and increased exposure to supply chain attacks. This incident highlights the growing trend of well-resourced nation-state actors exploiting remote work arrangements and third-party talent networks. As companies aggressively scale digital transformation and outsourcing, vigilance against social engineering and identity fraud is critical to mitigate the risk of covert infiltration and regulatory non-compliance.
8 months ago
Kill Chain
Pixel KASLR Bypass: Linear Map Non-Randomization Threatens Android Kernel Security
In November 2025, security researchers from Google Project Zero disclosed a significant design flaw in the Linux kernel’s implementation of Kernel Address Space Layout Randomization (KASLR) on modern Android devices, specifically Google Pixel phones. The weakness stems from the lack of randomization in both the linear kernel mapping and the physical memory loading address of the kernel itself. As a result, attackers with an arbitrary read/write primitive could derive static kernel virtual addresses, bypassing KASLR protections without leaks—thereby making exploitation significantly easier and increasing the risk of privilege escalation and persistence. This incident underscores a broader industry challenge where operating system mitigations lag behind evolving attacker techniques. The exposure of predictable kernel virtual addresses on widely deployed Android devices highlights the urgency for stronger kernel randomization and renewed attention to memory safety for mobile platforms.
8 months ago
Kill Chain
Rogue Incident Responders Deploy ALPHV/BlackCat Ransomware Against US Companies
In 2023, three US-based cybersecurity professionals, including an incident response manager from Sygnia and a ransomware negotiator from DigitalMint, were indicted after orchestrating a wave of ransomware attacks using the ALPHV/BlackCat strain. Beginning in May 2023, the group compromised five US organizations spanning healthcare, pharmaceuticals, engineering, and tech, deploying ransomware to encrypt critical data and extort payments. Only a Florida medical company paid, sending nearly $1.3 million in ransom; the other four victims did not make payments. The attacks were uncovered through joint law enforcement efforts, leading to arrests and criminal charges for the conspirators. This case is significant as it highlights the ongoing risk of insider threats even among trusted cybersecurity professionals. The exploitation of privileged insider knowledge paired with advanced ransomware-as-a-service tooling demonstrates how internal actors can subvert security postures, fueling industry concerns about vigilance, vetting, and zero trust principles within security teams.
8 months ago
Kill Chain
How OAuth Device Code Phishing Targets Azure and Google: What CISOs Need to Know in 2024
In 2024, new phishing campaigns emerged that weaponize the OAuth Device Code flow against major cloud platforms, notably Azure and Google. Attackers send users to authentic device code portals, tricking them into entering codes controlled by adversaries. Once codes are entered, threat actors receive valid OAuth tokens granting extensive access to cloud services, often bypassing multi-factor authentication. Researchers noted that Azure’s device flow presented a larger attack surface than Google’s, making it a high-value target for phishing and account compromise. The result is unauthorized access to sensitive email, data, and other cloud resources, with potential for lateral movement and persistent compromise. This breach showcases a rapidly escalating attack vector exploiting weaknesses in cloud identity flows. The rise in device code phishing reflects a broader shift by threat actors toward abusing legitimate authentication processes, especially as organizations depend more heavily on cloud services and OAuth-based SSO.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

