Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 5473 to 5484 of 5924
Autonomous AI Hacking: The Tipping Point in Global Cybersecurity Risk (2025)
In mid-2025, a wave of autonomous AI-driven cyberattacks emerged globally, marking a pivotal evolution in threat activity. Across June through September, a combination of threat actors—including criminal groups and state-sponsored entities—leveraged advanced large language models (LLMs) and autonomous agent frameworks to conduct large-scale vulnerability discovery, network infiltration, and ransomware deployment. Attackers used tools like XBOW, HexStrike-AI, and AI-powered malware to execute rapid reconnaissance, credential harvesting, and automated extortion, targeting enterprises and critical infrastructure with unprecedented speed, scale, and sophistication. Businesses faced increased operational disruptions and data loss due to automated exploitation chains and persistent threats that outpaced traditional defense mechanisms. This wave of AI-enabled cyberattacks highlights a dangerous rise in the commoditization of sophisticated offensive tools and the diminishing window for detection and response. The incident underscores an urgent shift in the cyber threat landscape, with automation eroding the gap between disclosure and exploitation while spurring intense regulatory and industry focus on adaptive, AI-driven defense solutions.
8 months ago
Kill Chain
AI Agents Under Fire: Memory Poisoning and the Rise of Persistent Prompt Injection
In 2024, security researchers uncovered a novel AI/ML security incident where AI agents' long-term memory storage was compromised via persistent indirect prompt injection. Adversaries managed to embed malicious instructions within normal AI inputs; these poisoned prompts were subsequently retained by the AI's memory module. When later queries accessed this memory, the injected instructions could exfiltrate conversation history or impact future responses, creating a stealthy, long-term threat. The breach highlighted how modern agentic AI’s tendency to remember user input presents an unforeseen risk vector, with potential for data leakage and manipulation of AI-driven workflows. This incident signals a rising trend: as enterprises integrate AI agents and persistent memory, attackers are quickly adapting with prompt-based exploit techniques that subvert traditional security controls. The risk of covert data exfiltration and ongoing manipulation through AI memory will become a central compliance and governance issue in highly regulated industries.
8 months ago
Kill Chain
Clop Ransomware Hits Oracle E-Business Suite Via Zero-Day in 2025
In August 2025, the Clop ransomware group launched a targeted campaign against Oracle E-Business Suite customers, exploiting a critical zero-day vulnerability (CVE-2025-61882) and additional software flaws to achieve pre-authenticated remote code execution. The attack began nearly three months before extortion emails were sent, enabling Clop to quietly exfiltrate sensitive data from dozens of organizations. Security researchers from Google and Mandiant collaborated to reconstruct the multi-stage exploit chain, and Oracle issued an emergency patch in early October after hundreds of systems were identified as vulnerable. Ransom demands reached up to $50 million, jeopardizing regulated data and business operations across multiple industries. This incident underscores the accelerating weaponization of zero-days by advanced ransomware groups and highlights the growing sophistication of supply-chain attacks. It demonstrates both the risk of delayed patching and the operational threat to organizations reliant on widely used enterprise software platforms.
8 months ago
Kill Chain
SonicWall Cloud Backup Breach 2024: Firewall Configurations Exposed in Major Supply Chain Attack
In mid-2024, SonicWall suffered a significant security breach when an unauthorized party leveraged a brute-force attack against its customer-facing cloud backup platform, gaining access to all firewall configuration backup files stored on the service. The exposed data included sensitive firewall rules, encrypted credentials, and routing configurations for every customer utilizing SonicWall’s cloud backup, not just the initially cited 5% of their install base. While the credentials were encrypted, experts warned that weak passwords could be crackable, offering attackers expanded access. SonicWall worked with Mandiant to investigate, notified affected customers, hardened its infrastructure, and provided remediation tools. This incident highlights ongoing risks from cloud-based infrastructure and supply chain attacks, especially targeting security vendors. Attackers are increasingly exploiting weaknesses in API protections and infrastructure configurations, reinforcing the need for robust access controls and continuous monitoring as ransomware and targeted attacks against network security vendors persist.
8 months ago
Kill Chain
How a Breached BPO Account Led to Discord’s Massive 2025 Zendesk Data Breach
In late September 2025, attackers compromised a support agent account at an outsourced BPO provider and gained unauthorized access to Discord’s Zendesk support platform for 58 hours. Exploiting privileged access, they exfiltrated up to 1.6 TB of data, including approximately 8.4 million support tickets affecting 5.5 million users, with sensitive information such as emails, Discord IDs, phone numbers, partial payment data, and around 70,000 government-ID photos. The threat group leveraged integrations between Zendesk and Discord’s internal systems, extracted additional user details via APIs, and attempted a multimillion-dollar ransom before threatening public data release. This incident highlights the growing risk from third-party supply chain attacks targeting cloud-based customer support platforms and BPO providers. The attacker's tactics—abusing helpdesk integrations and privilege escalation—reflect broader cybercrime trends, including identity-driven attacks, data extortion, and rising regulatory scrutiny.
8 months ago
Kill Chain
TwoNet Hacktivists Target Decoy Water Plant in Bold Critical Infrastructure Attack
In September 2025, the pro-Russian hacktivist group TwoNet targeted what they believed to be a vulnerable water treatment plant, unaware it was a decoy system (honeypot) operated by cybersecurity researchers. The attackers gained access using default credentials, escalated attacks through SQL enumeration, and exploited a known XSS vulnerability (CVE-2021-26829). Within 26 hours, they created new user accounts, manipulated PLC setpoints, disabled real-time updates, and attempted to disrupt both logs and alarms via the Human Machine Interface (HMI). Their tactics included data exfiltration and process disruption, signaling a shift toward operational technology (OT) attacks targeting critical infrastructure. This incident highlights a growing trend of hacktivist groups evolving from DDoS and defacement attacks to more sophisticated operations against OT and ICS targets. The rapid escalation and attempted sabotage observed in this breach emphasize the urgent need for robust segmentation, authentication, and real-time anomaly detection within critical infrastructure environments.
8 months ago
Kill Chain
From Infostealer to Full RAT: Inside the 2025 PureRAT Attack Chain
In October 2025, Huntress Labs analyzed a sophisticated attack campaign leveraging the PureRAT remote access trojan. The intrusion began with a targeted phishing email containing a ZIP archive that employed DLL sideloading to launch a cascade of in-memory loaders written in Python. Progressing through multi-layered obfuscation, hybrid encryption, and system persistence via Windows registry modifications, the attackers ultimately deployed PureRAT, granting full remote control over victim endpoints. Notably, the operation combined custom-developed loaders with commercial malware, demonstrating advanced evasion and command and control techniques, including encrypted communications and dynamic payload delivery. This incident highlights the growing complexity and modularity of post-phishing attack chains. Organizations must remain vigilant as threat actors increasingly blend bespoke scripts with off-the-shelf RATs, drastically lowering the barrier for stealthy, persistent intrusions targeting credential theft and long-term access.
8 months ago
Kill Chain
SonicWall Cloud Backup Breach Exposes Firewall Configurations in 2024
In June 2024, SonicWall disclosed a significant data breach impacting all users of its cloud backup service. Attackers successfully gained unauthorized access and exfiltrated firewall configuration files belonging to these customers. The breach, which reportedly occurred in late May 2024, does not appear to have affected the core SonicWall services but poses considerable risk because leaked configurations may contain sensitive network information, VPN details, hashed passwords, and other operational data. SonicWall took immediate action by disabling the impacted service and advising affected clients to reset credentials and review their setups. This breach highlights increasing attacker focus on cloud-managed infrastructure, particularly targeting device configurations that can offer deep intelligence on enterprise environments. With threat actors exploiting misconfigurations and weak controls in supply chain and managed services, regulators and CISOs are under pressure to strengthen both preventative and responsive security postures.
8 months ago
Kill Chain
RondoDox Botnet Orchestrates Mass n-day IoT Attacks in 2025
In mid-2025, the RondoDox botnet emerged as a powerful threat targeting IoT and network devices by exploiting 56 known (n-day) vulnerabilities across over 30 device types, including routers, NVRs, DVRs, and CCTV systems. The operators, closely monitoring vulnerability disclosures—such as those revealed at Pwn2Own events—rapidly weaponized publicly disclosed exploits, including CVE-2023-1389 and CVE-2024-12856, using a high-volume "exploit shotgun" methodology to maximize infections. With operations observed since June 2025, the campaign affected both end-of-life and actively supported products, resulting in a widespread compromise of infrastructure, particularly among organizations and consumers with unpatched devices. This attack underscores a growing trend of mass exploitation of n-day vulnerabilities in IoT ecosystems, reflecting increasing automation and sophistication among botnet operators. The pace at which attackers operationalize new exploits demands faster patching, improved segmentation, and heightened baseline security practices across networked environments.
8 months ago
Kill Chain
China-Based Storm-2603 Weaponizes Velociraptor DFIR in 2025 Ransomware Attacks
In October 2025, security researchers uncovered that the China-based threat group Storm-2603 had abused the open-source Velociraptor DFIR tool in a wide-ranging ransomware campaign. The attacker exploited an outdated, vulnerable version of Velociraptor (CVE-2025-6264) to escalate privileges, create persistent admin accounts, and establish secure remote access on victim systems. This access enabled them to deploy ransomware variants including LockBit and Babuk across Windows and VMware ESXi environments, performing data encryption and exfiltration using PowerShell scripts. Endpoint protections were systematically disabled, and lateral movement leveraged tools like Impacket. This incident highlights an emergent trend: threat actors co-opting legitimate security tools for malicious purposes, increasing the difficulty of detection and response. The blending of nation-state TTPs with ransomware-as-a-service models signals evolving threats, regulatory scrutiny, and substantial operational risks for enterprises.
8 months ago
Kill Chain
Universities Targeted: Storm-2657 Orchestrates 2025 Business Email Compromise via Payroll Phishing
In March 2025, a financially motivated threat group tracked as Storm-2657 launched a series of "payroll pirate" attacks targeting U.S. university staff. The attackers leveraged advanced social engineering and adversary-in-the-middle (AITM) phishing techniques to compromise HR-related SaaS accounts, notably Workday. After stealing MFA credentials, they accessed Exchange Online accounts, manipulated payroll settings to hijack salary payments, set inbox rules for concealment, and enrolled attacker-controlled MFA devices for persistence. At least 11 accounts across three universities were breached, enabling phishing campaigns to almost 6,000 recipients spanning 25 institutions. The incident showcases a significant escalation in business email compromise (BEC) targeting the education sector, exploiting gaps in MFA and SSO implementations. With BEC attacks surging industry-wide—resulting in multimillion-dollar annual losses—this campaign emphasizes the urgent need for phishing-resistant MFA and robust email monitoring across academia and beyond.
8 months ago
Kill Chain
ClayRat Android Spyware: Fake App Campaign Hits Mobile Users in 2025
In October 2025, cybersecurity researchers at Zimperium disclosed a widespread Android spyware campaign dubbed ClayRat, which targeted Russian users through phishing portals, Telegram channels, and malicious websites mimicking popular apps such as WhatsApp, TikTok, YouTube, and Google Photos. Using fraudulent Play Store-like websites and social engineering tactics, attackers tricked users into sideloading APKs that installed malicious payloads via a session-based installation method, bypassing Android security. Once installed, ClayRat acts as the device's default SMS handler, enabling interception of messages, call logs, notifications, and exfiltration of sensitive data to an AES-GCM-encrypted command and control (C2) server. It also uses infected devices to propagate itself by sending mass SMS messages to victims' contacts. This incident underscores an accelerating trend in mobile spyware leveraging legitimate app impersonation and sophisticated delivery mechanisms. The high volume of ClayRat samples and droppers, the abuse of sideloading, and the global reach of Telegram-based distribution channels highlight persistent gaps in mobile endpoint and social engineering defenses.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

