Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 5521 to 5532 of 5924
Unity Game Engine Vulnerability 2025: Millions Exposed to Supply Chain Attacks
In October 2025, a significant supply chain vulnerability (CVE-2025-59489) was discovered in the Unity game engine, impacting applications built since version 2017.1 and endangering millions of global end-users. The flaw, identified by security researcher RyotaK, enables attackers to achieve arbitrary code execution or information disclosure by exploiting unsafe file loading mechanisms in the Unity Runtime component. Affected games include widely popular titles like Hearthstone, Fallout Shelter, and Doom (2019). Valve and Microsoft responded quickly, recommending users uninstall vulnerable games and developers patch or rebuild applications, while Unity issued updates and fixes for supported engine versions. This incident underscores the growing risks of supply chain vulnerabilities in modern software ecosystems, particularly as game engines and third-party frameworks become foundational across industries. The rapid coordinated response highlights heightened industry attention to upstream code security, as adversaries increasingly target widely deployed runtime components for maximum impact.
8 months ago
Kill Chain
Redis 2025 Critical RCE: How CVE-2025-49844 Threatens Cloud Data Security
In October 2025, Redis disclosed a critical remote code execution vulnerability (CVE-2025-49844), stemming from a 13-year-old use-after-free bug in the Lua interpreter, impacting all major Redis releases. Exploitable via authenticated Lua scripts—enabled by default—the flaw allows attackers to escape the script sandbox, execute arbitrary code, establish persistent access via reverse shell, and ultimately gain full control of the host system. Security researchers revealed that over 330,000 Redis instances were exposed online, some requiring no authentication, enabling credential theft, data exfiltration, lateral movement, and malware deployment at scale. This incident highlights persistent risks from legacy code, cloud-exposed databases, and default insecure configurations, accelerating regulatory and industry emphasis on proactive patching, network segmentation, and least privilege controls. The vulnerability’s sheer scope and ease of exploitation underline the urgency for organizations to remediate and harden public-facing infrastructure.
8 months ago
Kill Chain
Zeroday Cloud 2025: Cloud and AI Security in the Spotlight
In December 2025, the inaugural Zeroday Cloud hacking contest was announced, offering $4.5 million in bug bounties for security researchers able to compromise open-source cloud and AI technologies. Organized by cloud security firm Wiz with major cloud providers Google Cloud, AWS, and Microsoft, the event is set to coincide with Black Hat Europe in London. Categories span AI platforms, Kubernetes, virtualization, web servers, databases, and DevOps tools, with cash rewards reaching as high as $300,000 for critical exploits that achieve remote code execution or full container escapes. The competition’s rules encourage demonstration of high-impact vulnerabilities in default configurations, drawing attention from the research and bug bounty community worldwide. This contest stands out as the largest ever focused exclusively on cloud-native and AI environments. It highlights industry-wide concerns about tooling security as organizations accelerate public cloud and AI adoption. The timing reflects both the proliferation of adversaries targeting these attack surfaces and coordinated industry efforts to crowdsource vulnerability discovery in critical platforms.
8 months ago
Kill Chain
Microsoft 2025: Storm-1175 Exploits GoAnywhere Zero-Day for Devastating Ransomware Attacks
In September 2025, a cybercrime group tracked as Storm-1175 exploited a critical zero-day deserialization vulnerability (CVE-2025-10035) in Fortra's GoAnywhere Managed File Transfer (MFT) solution. The attackers gained initial access by remotely targeting vulnerable MFT instances and leveraged remote monitoring tools (SimpleHelp, MeshAgent) for persistence. Subsequently, they conducted network reconnaissance with Netscan, moved laterally using Microsoft RDP, exfiltrated sensitive data with Rclone, and ultimately deployed Medusa ransomware payloads to encrypt files. This campaign affected multiple organizations, exposing unpatched systems to significant operational risk and data loss. The incident highlights a continued surge in ransomware operations leveraging zero-day vulnerabilities in widely used enterprise software. Attackers are increasingly exploiting supply chain and infrastructure components to maximize impact, driving regulatory scrutiny and accelerating the need for robust patch management and segmentation practices.
8 months ago
Kill Chain
How Kaspersky’s 2025 ML Models Raised the Bar for DLL Hijacking Detection
In 2025, Kaspersky advanced their detection capabilities against DLL hijacking attacks by developing and deploying machine learning (ML) models. DLL hijacking, used by both organized malware developers (such as those behind Lumma stealer) and advanced persistent threat (APT) groups, involves loading malicious DLLs in place of genuine libraries. Attackers exploited trusted processes to evade detection and complicate incident response. Kaspersky’s internal telemetry revealed a sharp uptick in these attacks across diverse regions and sectors, prompting an iterative ML-driven approach. By refining training datasets, extracting relevant behavioral features, and evolving their models through analyst feedback, Kaspersky achieved higher true positive rates and reduced false positives, integrating the solution into SIEM and MDR offerings to surface live threats.
8 months ago
Kill Chain
Red Hat Breach 2025: ShinyHunters Escalate GitLab Data Extortion
In October 2025, Red Hat suffered a significant data breach after threat actor group Crimson Collective compromised its internal GitLab repositories, exfiltrating nearly 570GB of data including around 800 Customer Engagement Reports (CERs). These reports contained sensitive details about customers’ networks and infrastructure. Following unsuccessful ransom negotiations, Crimson Collective partnered with Scattered Lapsus$ Hunters and ShinyHunters to escalate extortion attempts, publicly posting data samples and demanding payment before a hard deadline. High-profile organizations such as Walmart, HSBC, Bank of Canada, and the US Department of Defense were among affected clients named in the leak. The collaboration between multiple threat actors and the rise of Extortion-as-a-Service operations like ShinyHunters highlight a new era of corporate extortion risk, with increasing pressure on organizations to proactively secure code repositories and sensitive customer communications against rapidly-evolving, multi-actor cyber threats.
8 months ago
Kill Chain
Kaspersky SIEM Uncovers ToddyCat DLL Hijacking Attacks in 2024
In early 2024, Kaspersky detected several advanced persistent threat (APT) incidents during pilot testing of their machine-learning-based DLL-hijacking detection module within their SIEM platform. Notably, the ToddyCat APT group exploited a SharePoint vulnerability (CVE-2021-27076) to gain initial access, then leveraged DLL sideloading to execute Cobalt Strike implants using masqueraded Windows system libraries. Other real-world incidents uncovered included infostealer malware posing as a policy manager, and a malicious loader activated through a USB drive, all utilizing DLL hijacking for code execution and persistence. Kaspersky’s detection tool enabled rapid identification and response, preventing further compromise and data exfiltration. This case highlights the growing sophistication of DLL hijacking techniques in APT operations and the increasing use of AI-driven security products to detect lateral movement and stealthy intrusion behaviors. The incidents underscore the need for robust behavioral analytics and real-time anomaly detection as threat actors increasingly target supply chains and trusted binaries to bypass traditional security defenses.
8 months ago
Kill Chain
How a Zimbra Zero-Day Breach Exposed the Brazilian Military: Lessons for Secure Collaboration
In early 2025, a zero-day vulnerability in Zimbra Collaboration (CVE-2025-27915), a widely used email and collaboration platform, was exploited to target the Brazilian military. Attackers used malicious ICS calendar files containing unsanitized HTML and JavaScript to trigger stored cross-site scripting (XSS) within Zimbra's Classic Web Client. This entry vector effectively bypassed standard security controls and provided attackers the ability to execute malicious code in users' browsers, potentially enabling credential theft, session hijacking, and further movement inside the organization before the vulnerability was patched. The campaign underscores how attackers are increasingly leveraging vulnerabilities in collaborative and communication tools to gain a foothold in targeted organizations and critical infrastructure. This breach is particularly relevant today given the ongoing surge in zero-day exploits against widely deployed business applications, especially in sectors such as government and defense. The rapid weaponization of collaboration-tool vulnerabilities highlights the need for timely patch management, robust segmentation, and vigilant threat detection to combat sophisticated phishing and XSS-based initial access.
8 months ago
Kill Chain
Chinese Cybercrime Group Exploits IIS Servers in Global SEO & Credential Theft Scheme
In October 2025, cybersecurity analysts uncovered a campaign orchestrated by a Chinese-speaking cybercrime group known as UAT-8099. The group exploited vulnerabilities in Microsoft Internet Information Services (IIS) servers, primarily targeting organizations across India and Thailand. Attackers deployed malicious scripts and leveraged the compromised servers for global search engine optimization (SEO) fraud while systematically stealing high-value credentials, configuration files, and certificate data. This sophisticated operation impacted business continuity, undermined trust, and exposed sensitive enterprise assets to further misuse. This breach exemplifies the growing threat from well-resourced cybercrime rings using server-side exploits to conduct financially motivated attacks. Similar credential theft and SEO manipulation TTPs are increasingly prevalent worldwide, highlighting an urgent need for enhanced internal server security, threat detection, and compliance with modern data protection standards.
8 months ago
Kill Chain
Oracle E-Business Suite Hit by Cl0p: CVE-2025-61882 Breach Exposes Enterprise Data
In October 2025, Oracle urgently released a security patch addressing CVE-2025-61882, a critical vulnerability in its E-Business Suite platform with a CVSS score of 9.8. The flaw, allowing unauthenticated remote attackers network access via HTTP, was actively exploited by the Cl0p ransomware gang in a series of data theft attacks. Threat actors leveraged the bug to gain control of impacted systems, enabling lateral movement and the exfiltration of sensitive business data. Oracle customers with exposed E-Business Suite deployments were specifically targeted, prompting a rapid, emergency response. This incident highlights the resurgence of large-scale supply chain ransomware attacks exploiting zero-day vulnerabilities in widely used enterprise software. Threat actors like Cl0p are increasingly automating exploitation campaigns, raising the bar for threat detection, patch management, and regulatory compliance requirements in digital enterprises.
8 months ago
Kill Chain
Oracle’s 2025 Mega Breach: 0-Day, BitLocker Bypass & VMScape Trigger Industry Wake-Up
In October 2025, Oracle faced a significant security incident that exposed critical new 0-day vulnerabilities, impacting key platforms via exploits including a BitLocker bypass, the 'VMScape' hypervisor escape, and a fast-spreading WhatsApp worm. Threat actors leveraged multiple sophisticated attack vectors, targeting both enterprise infrastructure and end-user devices. The campaign enabled unauthorized lateral movement, data exfiltration, and disruption of cloud workloads, with global enterprises and managed service providers feeling downstream impact as security researchers identified widespread exploitation across hybrid and multicloud environments. These multi-pronged intrusions forced urgent mitigation efforts, including rapid patching, segmentation, and new traffic visibility controls to stem active attacks. The incident underscores escalating attacker sophistication in blending 0-day exploitation, social engineering, and cloud platform abuse. As threat campaigns increasingly combine lateral spread mechanisms with supply chain risks and targeted ransomware, it highlights the necessity of modern Zero Trust frameworks, advanced detection, and continuous security governance for organizations operating at cloud scale.
8 months ago
Kill Chain
BIETA & CIII Unmasked: China’s MSS Deploys Espionage Through Research Firms in 2025
In October 2025, a detailed investigation revealed that Chinese research firms BIETA (Beijing Institute of Electronics Technology and Application) and CIII were directly implicated in cyber operations orchestrated by China’s Ministry of State Security (MSS). The report, based on personnel link analysis and institutional relationships, highlights how BIETA coordinated with MSS operatives and academic partners to conduct covert cyber-espionage campaigns targeting international entities. These campaigns leveraged advanced tactics, including exploitation of internal network flows and the use of encrypted traffic, to exfiltrate sensitive data undetected. The exposure underscores the persistent and sophisticated nature of state-sponsored cyber threats, as well as risks posed by non-traditional actors collaborating with government intelligence agencies. This incident reflects a broader escalation in state-driven cyber espionage, demonstrating that commercial and academic organizations may serve as active operational arms for nation-state threat actors. As attribution capabilities improve, organizations must reassess third-party relationships and reinforce east-west and encrypted traffic controls to mitigate lateral movement and exfiltration risks.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

