Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 5533 to 5544 of 5924
Self-Propagating Malware Targets WhatsApp Users in Brazil with Financial Fraud Infostealer
In early June 2024, an infostealer campaign dubbed Water Saci aggressively targeted WhatsApp users in Brazil using self-propagating malware named Sorvepotel. Attackers leveraged compromised accounts to automatically distribute malicious links via WhatsApp messages, luring recipients to execute malware payloads. Once installed, Sorvepotel exfiltrates credentials and tracks browser activities, enabling threat actors to target and defraud regional financial institutions. The infection chain’s ability to rapidly spread through trusted social contacts increased both the velocity and scale of impact, compromising both individual and enterprise devices in a short time frame. The Water Saci operation highlights the evolution of credential-stealing malware adopting worm-like features to maximize reach. With messaging platforms remaining core to business and personal communications, this incident underscores the urgency of intercepting lateral movement, especially as attackers blend social engineering with advanced propagation and data theft techniques.
8 months ago
Kill Chain
How Chinese Front Organizations Exploited Western Research to Advance State Cyber Capabilities
In early 2024, coordinated investigations revealed that Chinese government-linked academic and research institutions were covertly collaborating with Western organizations and researchers. Operating under seemingly neutral fronts, these entities facilitated the transfer of advanced cyber technologies and expertise, ultimately benefitting the intelligence apparatus of the People’s Republic of China (PRC). The campaign included joint projects, academic exchanges, and technology partnerships that enabled the PRC to sidestep export controls and gain access to cutting-edge cyber defense and offensive capabilities. The outcome potentially undermines intellectual property protections and heightens risks to network and national security within targeted Western sectors. This incident underscores a marked escalation in supply chain and technology transfer tactics used by nation-state actors. As the global competition for cyber advantage intensifies, regulators and organizations must heighten vigilance around academic, research, and cross-border tech collaborations to mitigate risks of inadvertent technology leakage.
8 months ago
Kill Chain
Oracle E-Business Suite 2025: Critical SSRF Exploit Exposed and Analyzed
In October 2025, Oracle E-Business Suite was found to be vulnerable to an actively exploited server-side request forgery (SSRF) vulnerability, tracked as CVE-2025-61882. Threat actors leveraged a publicly available exploit script to manipulate the product’s servlet endpoints, extracting CSRF tokens and delivering a crafted payload capable of executing arbitrary commands via XSLT and Java reflection. The attack enabled remote code execution and potential lateral movement within affected enterprise environments, with indicators of compromise made public shortly after discovery. Oracle’s rapid response included a critical patch and threat intelligence advisory. This incident highlights an ongoing surge in advanced web exploitation techniques, particularly SSRF combined with deserialization and XSLT-based attacks. It underscores the urgent need for timely patching, defense-in-depth, and continuous anomaly detection, as well as the growing focus of attackers on business-critical ERP platforms.
8 months ago
Kill Chain
Salesloft Drift Supply Chain Breach: How Okta and Zscaler Responded in 2023
In August 2023, a sophisticated supply chain attack targeting Salesloft and Drift exposed the vulnerabilities of OAuth token management in SaaS integrations. Threat actor group UNC6395 compromised Salesloft's GitHub and later leveraged compromised OAuth tokens from the Drift platform, affecting over 700 customers—including security leaders Okta and Zscaler. While Okta’s proactive use of IP restrictions blocked malicious API requests and prevented data loss, Zscaler experienced a significant breach, exposing both customer and internal data. The campaign unfolded rapidly, relying on automated scripts for widespread data extraction via legitimate channels before defenses were activated. This incident underscores the growing pipeline threat of API- and token-driven attacks across integrated SaaS ecosystems. As organizations increasingly rely on third-party applications, traditional security mechanisms and risk due diligence are proving insufficient against lateral supply-chain intrusion tactics and the automated exploitation of tokenized access.
8 months ago
Kill Chain
ParkMobile 2021 Data Breach: Lessons from a 22 Million User Exposure
In March 2021, ParkMobile, a widely used parking payment platform, suffered a significant data breach that exposed sensitive information of nearly 22 million users. Threat actors exploited a vulnerability in the company’s third-party software, exfiltrating a 4.5 GB dataset containing names, email addresses, phone numbers, license plate data, mailing addresses, usernames, bcrypt-hashed passwords, and vehicle information. The full database was later leaked on a popular hacking forum, fueling risks of identity theft and fraud. Legal proceedings culminated in late 2024, with ParkMobile settling a class action lawsuit by offering $1 in-app credits per user. The breach highlights persistent challenges around protecting personal data, enforcing regulatory standards, and responding to data leaks in the mobility and payments sector. It emphasizes the urgent need for encrypted communications, strong segmentation, and robust threat detection as organizations confront increasingly sophisticated attack methods and legal repercussions.
8 months ago
Kill Chain
How Attackers Exploited a Zimbra Zero-Day via iCalendar Files in 2024
In early 2024, attackers exploited a previously unknown zero-day vulnerability in Zimbra Collaboration Suite (ZCS), targeting organizations via specially crafted .ICS (iCalendar) attachments. The vulnerability allowed threat actors to execute code by delivering malicious calendar files through email, bypassing traditional security filters. Incident responders observed attackers using this method for initial access, resulting in potential data theft, lateral movement, and disruption of email communications for affected businesses. The exploitation remained undetected for a significant period, amplifying operational and reputational risks for impacted entities. This incident highlights a growing trend of attackers leveraging supply chain and collaboration software vulnerabilities for sophisticated phishing and malware campaigns, often exploiting zero-days before vendors can respond. Organizations relying on common email and collaboration platforms face increased exposure to targeted file-type exploits and require improved visibility and rapid patching capabilities.
8 months ago
Kill Chain
Discord 2024 Breach: Third-Party Support Attack Exposes User Data
In early March 2024, Discord disclosed a data breach after threat actors compromised a third-party customer service provider’s systems. Attackers gained access to customer support tickets, exposing partial payment information, names, email addresses, and government-issued IDs of Discord users who had interacted with support. The breach occurred through unauthorized access to the provider’s internal systems, allowing exfiltration of sensitive, personally identifiable information linked to support requests. Discord promptly investigated, notified affected users, and terminated the third party’s access to its systems. This incident highlights the increasing risks associated with third-party vendors handling sensitive data, especially as social engineering and supply chain attacks become more common. Growing scrutiny from regulators and customers underscores the need for robust supply chain security and continuous monitoring of vendor access.
8 months ago
Kill Chain
Palo Alto Networks Faces Massive Surge in Login Portal Recon Scans
In early October 2025, cybersecurity firm GreyNoise detected a sharp 500% spike in reconnaissance scans targeting Palo Alto Networks GlobalProtect and PAN-OS login portals. Over 1,285 unique suspicious IP addresses, predominantly from the U.S., but also from the UK, Canada, the Netherlands, and Russia, launched automated probes against these authentication portals. The campaign appeared targeted, leveraging data from public scanning platforms like Shodan and Censys. No verified exploit or compromise has been confirmed, with Palo Alto Networks asserting their systems remain secure and attributing much of the observed activity to external fingerprinting, not internal breach. This incident highlights a broader escalation in focused reconnaissance tactics against major infrastructure platforms, often preceding attempts to weaponize new vulnerabilities. Organizations should remain vigilant about emerging threats, monitor authentication endpoints, and proactively patch known and zero-day-related risks.
8 months ago
Kill Chain
Palo Alto Networks Portals Targeted by 500% Surge in Reconnaissance Scanning
On October 3, 2025, cybersecurity researchers at GreyNoise detected an unprecedented 500% spike in scanning activity targeting Palo Alto Networks login portals, marking the highest volume observed over a three-month period. The scanning involved a surge of IP addresses systematically probing these portals, suggesting highly targeted reconnaissance efforts by unknown threat actors. While no direct exploitation or breach was reported, such coordinated scanning is often the precursor to exploitation attempts against potential vulnerabilities in security infrastructure, especially as targeted technologies are foundational for enterprise security postures. This incident exemplifies the growing trend of automated reconnaissance on high-value network assets as adversaries aim to map attack surfaces for later campaigns. Organizations relying on exposed management interfaces must bolster detection, segmentation, and access controls to address these evolving reconnaissance tactics.
8 months ago
Kill Chain
CometJacking: How a Single Click Turned Perplexity's Comet AI Browser into a Data Thief
In October 2025, cybersecurity researchers uncovered a significant prompt injection attack targeting Perplexity's Comet AI browser. Dubbed "CometJacking," this incident involved adversaries embedding malicious prompts in links, which—when clicked by users—triggered unauthorized data siphoning through the browser's agentic AI capabilities. Sensitive information, including from connected services like email and calendars, was exposed, demonstrating how AI-driven interfaces can be subverted via crafted input. The attack exploited trust in browser automation and the deep integration of third-party services, raising concerns about the security of AI-powered productivity tools. This incident is highly relevant as prompt injection attacks are rapidly emerging as a primary risk vector for generative AI environments. The growth in agentic AI and interconnected browser-based workflows has exposed new attack surfaces, prompting urgent calls for improved input validation, isolation of automation agents, and strengthened compliance for AI SaaS applications.
8 months ago
Kill Chain
Salesforce Breach 2024: Scattered Lapsus$ Hunters' Massive Data Extortion Campaign
In October 2024, the cybercriminal collective Scattered Lapsus$ Hunters resurfaced with a dedicated leak site, threatening to publish stolen data related to Salesforce customers if their extortion demands were not met. This group, an alliance of threat actors including Scattered Spider, Lapsus$, and ShinyHunters, allegedly compromised Salesforce environments through social engineering—specifically vishing IT support personnel to obtain credentials and, in parallel campaigns, exploiting OAuth token theft. The attackers claimed to possess approximately one billion records from 39 prominent organizations, including sensitive personally identifiable information (PII) like Social Security and driver’s license numbers. This incident underscores the increased targeting of SaaS platforms via identity and access manipulation, as well as the growing sophistication of multinational threat actor collaborations. It signals elevated risk for organizations relying on cloud applications and highlights the necessity of enforcing multi-factor authentication and vigilant third-party access controls.
8 months ago
Kill Chain
Dutch Teens Arrested for Wi-Fi Sniffer Recon in 2024 Russian Espionage Case
In June 2024, Dutch law enforcement arrested two 17-year-olds suspected of conducting cyber-espionage for Russian-backed threat actors. The teens reportedly canvassed high-profile locations in The Hague, including several embassies and European law enforcement headquarters, using a Wi-Fi sniffer to gather network intelligence. Authorities allege they were recruited via Telegram and that state-sponsored Russian actors utilized the pair for reconnaissance, leveraging youth engagement to mask attribution. The operation came to light after a tip-off from Dutch intelligence, resulting in swift arrests and raising significant policy concerns. This incident underscores a rising trend of nation-states outsourcing early reconnaissance to foreign youth via social media, reducing their risk of direct detection. The use of simple yet effective tools for physical/digital hybrid espionage highlights growing operational sophistication—and creates new urgency for organizations to shore up network perimeter and monitoring controls.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

