Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 5581 to 5592 of 5924
Allianz Life Data Breach 2025: Cloud CRM Attack Exposes 1.5 Million
In July 2025, Allianz Life, a major American insurance provider, suffered a significant data breach after threat actors—suspected to be part of the ShinyHunters extortion group—gained unauthorized access to a third-party cloud-based CRM system. The breach exposed sensitive personal information including names, addresses, dates of birth, and Social Security numbers for nearly 1.5 million individuals, encompassing customers, financial professionals, and employees. The incident was publicly disclosed shortly after it occurred, with Allianz confirming that Allianz SE, its global parent company, was not impacted. In response, Allianz initiated notifications to affected parties and regulatory authorities and is offering two years of free identity theft monitoring. This incident highlights the persistent risks posed by supply chain and third-party service vulnerabilities, especially as attackers increasingly target trusted cloud-based platforms such as Salesforce. The breach underscores the necessity for vigilant monitoring, rigorous access controls, and enhanced segmentation within cloud ecosystems for all organizations handling sensitive data.
8 months ago
Kill Chain
Klopatra Trojan: VNC-Powered Android Banking Attacks Sweep Europe in 2025
In March 2025, a newly identified Android trojan named Klopatra emerged, targeting over 3,000 devices across Europe by masquerading as a legitimate IPTV and VPN app. Researchers from Cleafy discovered that this banking and remote access trojan—believed to be operated by a Turkish-speaking cybercrime group—leveraged VNC-based remote control, overlay attacks, anti-analysis techniques, and Accessibility Service abuse to steal banking credentials, manipulate transactions, exfiltrate clipboard and keystroke data, and harvest cryptocurrency wallet information. The malware sidestepped Google Play protections by distributing its dropper app on unofficial websites and continuously evolving, with at least 40 builds detected since its appearance. This incident underscores the growing sophistication and adaptability of Android malware, including the deployment of advanced evasion techniques and real-time remote access capabilities. As mobile banking adoption rises globally, such attacks signal an urgent need for stronger app vetting, user awareness, and holistic endpoint security strategies in enterprise and consumer environments.
8 months ago
Kill Chain
Motility Software Suffers Major Ransomware Breach Impacting Over 766,000 Clients
In June 2024, Motility Software Solutions, a prominent provider of dealer management software, suffered a ransomware attack that resulted in the unauthorized access and exposure of sensitive data from approximately 766,000 clients. The attackers infiltrated Motility's networks, deployed ransomware to encrypt critical systems, and exfiltrated customer data, including personal and financial information. The attack caused significant operational disruptions for both Motility and its dealership clients, who rely on the platform for daily business operations. The incident highlights the persistent threat ransomware actors pose to software supply chains serving multiple downstream businesses. This breach is especially noteworthy amid an ongoing rise in ransomware targeting SaaS and vertical market providers, with attackers prioritizing data exfiltration for extortion. Regulators and business partners are increasing their demands for improved security controls and rapid incident disclosure, especially for service providers entrusted with large volumes of sensitive client data.
8 months ago
Kill Chain
Adobe Analytics 2025 Bug Exposes Cross-Tenant Tracking Data
In September 2025, an ingestion bug in Adobe Analytics caused cross-tenant data exposure, allowing customer tracking data from some organizations to appear in the analytics reports of others for nearly a day. The incident began on September 17 due to a performance optimization update that led to incorrect data values surfacing in Analysis Workspace reports. Approximately 3-5% of collected data—across Data Feeds, Live Stream, and scheduled reports—was impacted, with some fields being overwritten by data from other tenants. Adobe promptly reverted the change on September 18 and undertook remediation to cleanse datasets, advising customers to purge affected data from systems and backups to prevent further exposure. This incident underscores the risk posed by inadvertent data exposure within multi-tenant SaaS platforms and the criticality of robust data segregation and validation controls. With regulatory scrutiny over data privacy at an all-time high, such events illustrate how operational changes, even absent malicious intent, can have significant compliance and business ramifications for all affected customers.
8 months ago
Kill Chain
Ukraine 2025: CABINETRAT Backdoor Attack Leveraged Signal & XLL Add-ins
In September 2025, CERT-UA reported a targeted cyberattack campaign against Ukrainian organizations involving the CABINETRAT backdoor. The threat group tracked as UAC-0245 employed malicious Microsoft Excel XLL add-ins, disguised within ZIP archives distributed via Signal messenger, to covertly establish persistent backdoor access on victim systems. These XLL files, once executed, enabled attackers to conduct reconnaissance, data theft, and potential lateral movement inside compromised networks, raising concerns about operational disruption, espionage, and data confidentiality. This incident highlights the evolving threat landscape where adversaries leverage secure messaging platforms and file add-ins to bypass traditional email security and endpoint controls. The appearance of CABINETRAT underscores increasing sophistication in malware delivery and emphasizes the need for modern controls and East-West traffic visibility.
8 months ago
Kill Chain
Klopatra Android Banking Trojan Orchestrates VNC-Based Fraud in Spain and Italy
In August 2025, the Klopatra Android banking trojan was discovered by Cleafy, an Italian fraud prevention firm, after it compromised more than 3,000 smartphones—primarily in Spain and Italy. This sophisticated malware leveraged a hidden Virtual Network Computing (VNC) module that enabled threat actors to stealthily control infected devices remotely, bypassing traditional security measures and enabling real-time fraudulent activities. The attackers employed social engineering and malicious app delivery techniques to distribute the trojan, ultimately enabling the theft of sensitive banking credentials and direct manipulation of banking apps on compromised phones. The Klopatra campaign reflects the evolution of mobile threats in Europe, combining advanced remote access with banking-focused exfiltration. Its success underlines an urgent need for rigorous mobile device security as banking trojans rapidly adopt more covert control and anti-detection techniques.
8 months ago
Kill Chain
Attackers Exploit Milesight Routers to Launch European SMS Phishing Wave
In early 2025, unidentified threat actors exploited vulnerabilities in Milesight industrial cellular routers to launch a large-scale smishing campaign across Europe. By abusing the routers’ publicly exposed APIs, attackers sent malicious SMS messages containing phishing URLs directly to mobile users in countries including Sweden and Italy. This campaign has been ongoing since at least February 2022, with attackers leveraging compromised infrastructure to bypass traditional security filters, resulting in widespread delivery of credential-theft links and potential downstream attacks. This incident highlights the increasing trend of attackers targeting edge infrastructure and IoT devices to amplify their phishing and malware operations. As threat actors shift tactics toward abusing legitimate network equipment, organizations face new regulatory and operational risks, with urgent need to secure device APIs, implement segmentation, and strengthen monitoring to counter evolving smishing threats.
8 months ago
Kill Chain
2025 Red Hat OpenShift AI Vulnerability Exposes Hybrid Cloud to Full Takeover
In October 2025, a critical privilege escalation vulnerability was disclosed in Red Hat OpenShift AI, a popular platform for managing AI workloads across hybrid cloud infrastructures. The flaw allowed attackers to obtain elevated permissions and, under certain conditions, seize full control of affected environments. Security researchers identified that threat actors could exploit weak internal segmentation and misconfigurations within the AI lifecycle management layers, resulting in potential unauthorized lateral movement and broad operational impact across connected workloads. Red Hat promptly released advisories and patches, but organizations running unpatched versions remain at risk of infrastructure takeover and sensitive data exposure. This incident comes amid a surge in attacks targeting AI infrastructure and hybrid cloud environments, as adversaries increasingly exploit complex, interconnected platforms. The breach highlights the escalating risk posed by privilege escalation flaws in widely adopted enterprise AI solutions and underscores the urgent need for rigorous segmentation, threat detection, and rapid patch cycles.
8 months ago
Kill Chain
Wiretap Unveiled: DDR4 Side-Channel Attack Extracts Intel SGX ECDSA Keys in 2025
In October 2025, cybersecurity researchers from Georgia Institute of Technology and Purdue University disclosed a novel hardware-based attack that compromises Intel SGX enclaves by exploiting the DDR4 memory bus. By physically placing a wiretap interposer on the memory channel, the attackers were able to observe and ultimately extract ECDSA private keys used for remote attestation, undermining the core protection mechanisms of Intel’s SGX. This passive attack method does not require malware on the target, posing risk for highly sensitive operational environments and organizations reliant on enclave-based security. This incident underscores the growing sophistication of hardware side-channel research and the urgent need to assess trust boundaries in server environments. With critical infrastructure and cloud offerings often relying on SGX for confidential computing, organizations must scrutinize physical and hardware-layer exposures amid a surge of advanced hardware attack demonstrations.
8 months ago
Kill Chain
OneLogin 2025: OIDC/API Key Flaw Exposes Client Secrets to Attackers
In October 2025, a critical security vulnerability (CVE-2025-59363, CVSS 7.7) was disclosed in the One Identity OneLogin IAM platform. The flaw allowed threat actors to use compromised or exposed API keys to retrieve sensitive OpenID Connect (OIDC) application client secrets. Attackers exploiting this vulnerability could potentially impersonate trusted applications, resulting in unauthorized access to protected enterprise resources and disruption of identity-based authentication flows. OneLogin responded with a patch following public disclosure, but the exposure window placed numerous organizations at risk of credential theft and downstream compromise. This incident highlights persistent risks in identity and access management platforms, especially around API security and secret handling. Recent trends show attackers increasingly targeting IAM tools and exploiting weak OIDC/OAuth implementations, making robust zero trust segmentation, continuous threat monitoring, and compliance with established frameworks more critical than ever.
8 months ago
Kill Chain
Chinese APT Group Abuses VMware Privilege Escalation Flaw Throughout 2023
In 2023, sophisticated threat actors attributed to China exploited a previously unknown privilege-escalation vulnerability in VMware platforms for nearly a year before its discovery. Attackers leveraged this flaw, which appeared benign, to gain persistent and stealthy access to targeted virtual infrastructure. Their methods enabled lateral movement, data gathering, and privileged actions within highly segmented data center and cloud environments, affecting a broad range of organizations relying on virtualization for critical workloads. The long-term nature of the operation underscores challenges in detecting nation-state activity exploiting zero-day and privilege-related weaknesses. This incident highlights a broader escalation in advanced persistent threat (APT) campaigns targeting cloud and virtualization layers. As attackers increasingly exploit such integral software stacks with subtle techniques, organizations must reevaluate network segmentation, privilege management, and continuous monitoring to remain resilient.
8 months ago
Kill Chain
Klopatra: The Stealth Android Banking Trojan Draining European Accounts Overnight
In mid-2024, the Klopatra Android banking Trojan emerged as a major threat to mobile users in Italy and Spain. Disguised as the popular but illicit Mobdro streaming app, the malware leveraged social engineering tactics to trick users into granting dangerous Accessibility permissions. Once installed, Klopatra used advanced obfuscation, anti-analysis techniques, and commercial packers to avoid detection. Attackers remotely took control of compromised devices while users slept, using stolen credentials and simulated taps to access and empty bank accounts through a series of stealthy transfers—all while remaining undetected until victims discovered their losses in the morning. The Klopatra incident underscores a rising trend in real-time, remote-controlled mobile banking fraud, combining overlays, credential theft, and session manipulation. As attackers continue targeting mobile banking, organizations and end-users must adapt defenses to evolving TTPs and maintain vigilance toward app sideloading.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

