Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 5569 to 5580 of 5924
Cl0p Ransomware Targets Oracle E-Business Suite: 2025 Executive Extortion Wave Uncovered
In October 2025, Google Mandiant and the Google Threat Intelligence Group reported a new extortion campaign targeting organizations using Oracle E-Business Suite. The campaign, believed to be orchestrated by the financially motivated Cl0p ransomware group, involved the distribution of extortion emails to C-level executives, claiming theft of sensitive business data. Attackers leveraged weaknesses in Oracle’s environment to exfiltrate confidential information, applying pressure for payment through credible threats of public disclosure and operational disruption. This incident highlights the evolving nature of ransomware tactics towards high-value enterprise applications and direct executive outreach. This case demonstrates the increasing trend of threat actors focusing on business-critical cloud and ERP platforms, not only for data theft but also to maximize ransom leverage. Sophisticated phishing, lateral movement, and exploitation of complex SaaS ecosystems make such attacks especially challenging to detect and contain.
8 months ago
Kill Chain
Multi-Vector Cyber Assault 2025: CarPlay, Cloud SQL, & iCloud Under Attack
In October 2025, coordinated threat actors launched a multi-vector attack campaign leveraging a critical CarPlay exploit, BYOVD (Bring Your Own Vulnerable Driver) tactics, SQL server compromise for covert command-and-control (C2), and targeted backdoor deployments against iCloud accounts. Attackers exploited unpatched vulnerabilities across automotive infotainment systems, enterprise firewalls, and cloud environments, enabling lateral movement and persistent access. The campaign demonstrated a sophisticated blend of supply chain targeting, abuse of trusted encryption protocols, malicious browser extension injection, and data exfiltration at scale. Impacted organizations faced substantial operational disruption, data loss, and the risk of regulatory penalties due to exposure of sensitive customer information and business-critical systems. This incident underscores the rapid evolution of attacker tradecraft, particularly in hybrid infrastructures and connected vehicles. The convergence of cloud, automotive, and critical business services in a single campaign highlights the increasing necessity for comprehensive, real-time security that spans east-west traffic, encrypted channels, and multi-cloud platforms.
8 months ago
Kill Chain
Confucius Launches Targeted Campaign Against Pakistan with WooperStealer and Anondoor Malware
In October 2025, the advanced persistent threat group Confucius launched a sophisticated phishing campaign targeting Pakistani government, defense, and critical industry sectors. Leveraging spear-phishing emails and malicious documents, the attackers deployed two custom malware strains—WooperStealer and Anondoor—to infiltrate victim environments. These tools enabled the exfiltration of sensitive information and lateral movement across internal networks, potentially exposing military secrets and compromising operational capabilities. The attack underlines the evolving TTPs used by regional espionage actors and demonstrates substantial gaps in defending east-west traffic and data exfiltration from secure environments. This incident highlights the growing prevalence of specialized information-stealing malware and the targeting of governmental infrastructure by geopolitical adversaries. It reflects broader trends in cyber-espionage and underscores heightened regulatory expectations for securing critical east-west and outbound traffic flows.
8 months ago
Kill Chain
Malicious PyPI Package 'soopsocks' Infects 2,653 Systems in Supply-Chain Breach
In October 2025, security researchers discovered a malicious Python package named "soopsocks" on the official Python Package Index (PyPI) repository, which was designed to masquerade as a legitimate SOCKS5 proxy tool while covertly delivering backdoor functionalities to affected Windows machines. Attackers used this supply-chain vector to reach unsuspecting developers and organizations, resulting in 2,653 downloads before the package was taken down by PyPI administrators. The malware enabled attackers to deploy additional payloads, potentially leading to data exfiltration and further system compromise across multiple organizations. This incident exemplifies the persistent risk of open-source ecosystem attacks, as threat actors increasingly target software supply chains and code repositories. It highlights the urgent need for organizations to harden software development pipelines and monitor third-party dependencies for tampering or malicious behavior.
8 months ago
Kill Chain
US Government 2025 Shutdown: Cyber Intel Sharing and Defense at Risk
In October 2025, a US federal government shutdown led to the temporary lapse of critically important cyber threat information sharing, coinciding with the expiration of the Cybersecurity Information Sharing Act of 2015. As Congressional inaction prevented reauthorization, legal protections for companies sharing threat data vanished, making organizations hesitant or unable to exchange intelligence. Mass furloughs affected over 65% of Cybersecurity & Infrastructure Security Agency (CISA) personnel, and many critical contractors were released, significantly slowing incident response, vulnerability patching, and cross-sector collaboration. The resulting operational gaps increased the risk of adversaries targeting federal networks and exploiting unpatched vulnerabilities. This incident highlights the risks posed by government policy disruptions and shrinking cyber workforce capacity, underscoring how national cybersecurity posture is deeply interconnected with policy stability. Its relevance is underscored by mounting state-backed cyber threats, increased phishing targeting vulnerable personnel, and heightened urgency for robust identity and incident response controls.
8 months ago
Kill Chain
ShinyHunters Target Salesforce: Social Engineering Breach Exposes SaaS Security Gaps
In early 2024, Google’s Mandiant research team identified a targeted campaign by the ShinyHunters threat group leveraging advanced social engineering techniques against Salesforce environments. The attackers—tracked as UNC6040—used convincing phishing lures and manipulation of Salesforce user credentials to gain unauthorized access to sensitive corporate data. By circumventing authentication measures and exploiting insufficient internal network segmentation and monitoring, ShinyHunters exfiltrated confidential business records, customer data, and intellectual property. The breach highlighted the group’s evolving tactics and the risks posed to organizations that rely on cloud SaaS platforms like Salesforce for critical operations. This incident underscores the increasing sophistication of social engineering attacks, with criminals exploiting both technical and human vulnerabilities in cloud platforms. As SaaS adoption accelerates, similar threats are expected to rise, placing renewed emphasis on identity security, comprehensive threat detection, and adherence to zero trust principles.
8 months ago
Kill Chain
Android Spyware Attack Impersonates UAE Government App in 2024
In early June 2024, security analysts uncovered a sophisticated campaign in which attackers distributed Android spyware posing as a well-known UAE government surveillance app. By leveraging convincing social engineering and impersonation tactics, the threat actors tricked users into installing malicious software capable of exfiltrating sensitive data, monitoring communications, and maintaining persistent control over compromised devices. The spyware utilized encrypted and covert exfiltration methods, giving attackers broad access to user data while evading standard detection. The incident quickly raised concerns among organizations and citizens in the region about mobile device security and privacy. This attack is part of a growing trend using brand impersonation and sophisticated spyware packaging, targeting both individuals and potentially organizations. The resurgence of mobile surveillance threats underscores the evolving risks facing users in high-risk regions and highlights the need for robust mobile device security and compliance with privacy frameworks.
8 months ago
Kill Chain
Confucius APT Evolves: Python Backdoors Target Pakistan in 2025 Cyber-Espionage Escalation
In 2025, the Confucius advanced persistent threat (APT) group intensified its cyber-espionage operations targeting Pakistani government, military, and critical infrastructure organizations. Originally operating with infostealers like WooperStealer, Confucius shifted to deploying highly-obfuscated, Python-based surveillance backdoors such as AnonDoor. Attackers exploited spear phishing using spoofed authority emails and action-driven malicious attachments, which initiated complex infection chains via DLL sideloading, LNK files, and PowerShell loaders. This evolution improved persistence and evasiveness, resulting in increased risks to sensitive data and operational security for targeted institutions in Pakistan. The incident reflects a broader trend in state-sponsored cyberthreats: threat actors are adopting modular backdoors, diversifying attack vectors, and leveraging scripting languages to bypass security controls. Such agile TTPs (tactics, techniques, and procedures) heighten challenges for defenders, underscoring the urgent need for real-time threat detection and robust network segmentation.
8 months ago
Kill Chain
Red Hat's 2024 GitLab Breach: Supply Chain Risks and the Rise of Crimson Collective
In September 2024, Red Hat disclosed a breach of its self-managed GitLab instance used by its Consulting services, following claims by the Crimson Collective ransomware group of compromising over 28,000 private repositories. The attackers allegedly exfiltrated software source code and Customer Engagement Reports (CERs), which may contain network details, configuration data, and sensitive credentials. Red Hat initiated remediation steps and assured that its primary software supply chain and core products were not impacted. Belgian authorities warned of potential high-risk exposure for organizations with ties to Red Hat Consulting. This incident underscores a growing trend of supply chain attacks targeting private code repositories and related assets, especially in environments where critical infrastructure and third-party integrations are involved. As ransomware groups pivot to extortion and supply chain vectors, organizations must urgently review their repository and credential management, even on self-managed systems.
8 months ago
Kill Chain
Oracle 2025: Clop Ransomware Group Launches Extortion Campaign Against E-Business Suite Clients
In late September 2025, Oracle E-Business Suite customers were subjected to a wave of targeted extortion emails reportedly sent by threat actors aligned with the Clop ransomware group. The campaign leveraged hundreds of compromised legitimate third-party accounts to send messages claiming theft of customer data from Oracle environments. While Oracle confirmed the outreach and ongoing investigations, it did not specify which vulnerabilities were exploited nor confirm any customer data breach. Multiple Oracle E-Business Suite vulnerabilities, including remotely exploitable flaws, had been patched in July 2025, but ongoing research has yet to verify attack details or data loss. This incident is emblematic of the growing sophistication of financially motivated ransomware groups, who now often use large-scale phishing and extortion campaigns before confirming a breach. The campaign highlights increasing pressure on organizations to patch critical software rapidly and maintain heightened vigilance against social engineering, especially as adversaries leverage supply chain vectors and undermine trust with third-party compromise.
8 months ago
Kill Chain
How North Korean IT Workers Infiltrated Global Businesses: 2025 Insider Threat Surge
Between 2021 and mid-2025, North Korean nationals covertly infiltrated thousands of businesses worldwide by posing as legitimate remote IT and finance workers. According to Okta and other cyber threat intelligence sources, over 130 unique identities were linked to North Korean operatives who participated in more than 6,500 job interviews across roughly 5,000 companies, affecting industries from technology and finance to healthcare and manufacturing. The scheme enabled the North Korean regime to launder payments in violation of international sanctions, while threat actors refined methods to evade common screening controls and exploit global hiring pipelines. High volumes of applications, especially in remote roles, allowed these operatives to bypass national and enterprise-level defenses, embedding deeper into victim organizations’ critical workflows and data environments. The global expansion and sophistication of North Korea’s IT worker operation underscore a dangerous evolution in cyber-enabled insider threats and economic espionage. With a 220% increase in detected North Korean IT worker activity year-over-year, businesses worldwide now face heightened risk regardless of geography or sector, making identity vetting and remote work controls a top security priority.
8 months ago
Kill Chain
WestJet 2025 Data Breach: How Social Engineering and Remote Access Led to Massive Data Exposure
In June 2025, Canadian airline WestJet suffered a major data breach affecting approximately 1.2 million customers. Threat actors exploited social engineering to reset an employee’s password, gaining access through Citrix systems and compromising both Windows and Microsoft cloud networks. The attackers were able to exfiltrate sensitive personal data, including full names, dates of birth, physical addresses, passport or government IDs, travel information, rewards member data, and select customer service interactions. While no credit card numbers or passwords were disclosed, the incident required investigation by law enforcement and forced WestJet to notify affected users and authorities across North America, offering free identity monitoring. This breach highlights the growing effectiveness of identity-based attacks, particularly those leveraging social engineering to bypass traditional security controls via remote access platforms. With aviation and travel industries increasingly targeted, this incident underscores the urgent need for modern Zero Trust approaches and continuous monitoring of east-west traffic within enterprise networks.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

