Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 5617 to 5628 of 5924
Google Gemini AI Model Vulnerabilities: The 2024 Security Wake-Up Call
In early 2024, significant security and privacy vulnerabilities were discovered across multiple Google Gemini AI models, exposing users and enterprises to attack vectors that could have led to data leakage, privilege escalation, and AI-assisted exploitation. Researchers identified a 'trifecta' of flaws enabling prompt injection, sensitive data exposure, and circumvention of embedded safety controls, highlighting weaknesses in current generative AI guardrails. While no widespread attacker exploitation was confirmed, proof-of-concept attacks demonstrated how these flaws could weaponize Gemini models as an attack surface and vehicle for secondary threats. The disclosure prompted urgent reviews of AI usage and mitigations for enterprise consumers. This incident underscores escalating risks as generative AI platforms become embedded across business workflows. It illustrates the urgent challenge of securing large language models (LLMs) against novel exploitation methods and the rapidly intensifying focus by both attackers and regulators on AI/ML supply chain security.
8 months ago
Kill Chain
Phantom Taurus: Inside the 2025 Chinese APT NET-STAR Espionage Breach
In early 2025, security researchers uncovered a sophisticated espionage campaign attributed to a newly recognized Chinese nation-state actor, Phantom Taurus. Operating since at least late 2022, the group prioritized stealth and advanced tactics, primarily targeting government and telecommunications entities across Africa, the Middle East, and Asia. Attackers leveraged a novel, highly covert malware suite—NET-STAR—capable of remaining fileless within IIS web servers and facilitating persistent, encrypted exfiltration of sensitive diplomatic, military, and geopolitical data. The operation exploited custom-developed tools to move from email theft to direct database compromise, employing in-memory web backdoors and evasion techniques like timestomping and security mechanism bypasses to avoid detection and maintain long-term access. The exposure of Phantom Taurus and the NET-STAR suite highlights an escalating trend of targeted, stealthy cyber espionage campaigns against critical infrastructure by advanced persistent threat (APT) actors. This incident underscores the urgent need for organizations to strengthen east-west security visibility, enforce zero trust principles, and regularly review controls against constantly evolving attacker tradecraft.
8 months ago
Kill Chain
Interpol Uncovers Major Romance Scam and Sextortion Networks in Africa
In June 2024, Interpol coordinated "Operation Contender 3.0" across 14 African countries, arresting 260 individuals involved in cyber-enabled romance scams and sextortion schemes. The operation disrupted 81 cybercrime networks and resulted in the seizure of devices, forged documents, and other cybercrime infrastructure. Authorities uncovered nearly $2.8 million in losses affecting almost 1,500 victims, with Ghana and Senegal among the countries making substantial arrests and asset recoveries. Criminal networks exploited online platforms to deceive victims, using forged identities, stolen images, and blackmail tactics to extort payments or sensitive information. This operation highlights the escalating threat of social engineering attacks and cyber-enabled financial fraud in rapidly digitizing regions. As online interactions increase, so do identity-driven scams, making it critical for organizations and individuals alike to strengthen digital vigilance and invest in layered, resilient cybersecurity controls.
8 months ago
Kill Chain
Harrods Suffers Major Supply Chain Breach: 430,000 Customer Records Exposed in 2025
In September 2025, UK luxury retailer Harrods disclosed a major cybersecurity incident after attackers exploited a vulnerability in a third-party supplier, leading to the exposure of 430,000 e-commerce customer records. The breach, unrelated to earlier attacks by Scattered Spider, leveraged a supply chain vector similar to the widespread Salesloft OAuth attack, allowing data exfiltration from connected Salesforce environments. Compromised data included names, contact information, and internal marketing labels, but excluded financial data and passwords. Harrods responded by promptly notifying affected customers and authorities, while refusing to engage with extortion attempts by the threat actor. This incident illustrates the growing risk of supply chain compromise in the retail and e-commerce sector, where attackers increasingly exploit third-party platforms for large-scale data theft. As regulatory scrutiny intensifies and similar attacks proliferate, organizations must reevaluate supply chain security controls and customer notification protocols.
8 months ago
Kill Chain
Jaguar Land Rover’s 2025 Ransomware Crisis: Lessons on Supply Chain and Zero Trust Resilience
In September 2025, Jaguar Land Rover (JLR) was forced to halt production across multiple plants after suffering a catastrophic ransomware attack. The incident resulted in severe IT system disruption, suspended manufacturing operations, and subsequent data theft. A cybercrime group calling itself 'Scattered Lapsus$ Hunters' – reportedly linked to Scattered Spider and ShinyHunters – claimed responsibility, providing evidence of internal SAP system access. The attack’s impact exposed JLR’s business continuity vulnerabilities, prompted supply chain paralysis, and led the UK government to back a significant £1.5 billion loan guarantee to stabilize operations and prevent wider economic fallout. The breach highlights how ransomware actors are increasingly targeting critical manufacturing and supply chains for greater leverage. With mounting regulatory pressure and evolving attack tactics, strengthening enterprise resilience, zero trust architectures, and segmentation is more urgent than ever.
8 months ago
Kill Chain
Medusa Ransomware’s Failed Insider Recruitment at BBC (2025)
In July 2025, cybercriminals claiming affiliation with the Medusa ransomware group attempted to compromise the BBC by recruiting a journalist as an insider. The threat actor contacted the BBC’s cybersecurity correspondent via Signal, offering a percentage of any ransom if the journalist would provide internal access. Their plan relied on leveraging the journalist’s BBC credentials to infiltrate systems, download sensitive data, and initiate a high-value ransomware attack. The attackers used multiple social engineering tactics, including MFA fatigue (MFA bombing), but the journalist reported the approach to BBC’s security team, preventing a breach and prompting immediate incident response measures. This incident highlights the increasing risk of ransomware groups seeking insiders for network access, as well as the sophistication of social engineering tactics. As double-extortion attacks and insider recruitment surge, organizations must enhance vigilance and reinforce controls to mitigate identity-driven threats.
8 months ago
Kill Chain
Asahi Group 2025: Ransomware Attack Halts Japan's Largest Brewer
In September 2025, Asahi Group Holdings, Japan's largest brewer, suffered a significant cyberattack impacting its Japan-based operations. The attack disrupted critical business functions including ordering, shipping, call center operations, and customer service, forcing a suspension of core activities across the country. Initial reports confirm this was caused by a ransomware incident, though the initial point of entry and perpetrating threat actor remain unconfirmed. As of now, no data leakage or ransom claims have been validated, and the root cause is under active investigation. This incident highlights the expanding risk ransomware poses to critical manufacturing and supply chain operations, especially in the food and beverage sector. The Asahi attack underscores the importance of securing operational technology, internal communications, and implementing robust incident response plans amidst growing threats to large multinational enterprises.
8 months ago
Kill Chain
UK’s £5.5B Bitcoin Seizure: ‘Bitcoin Queen’ Convicted in Landmark Crypto Laundering Case
In September 2025, UK authorities secured a conviction in the world’s largest cryptocurrency seizure, arresting Zhimin Qian, also known as "Bitcoin Queen," for orchestrating a multi-billion pound fraudulent Bitcoin investment scheme between 2014 and 2017. Promising returns of up to 300%, Qian defrauded over 128,000 victims in China, amassing 40 billion yuan, which she later converted into Bitcoin and laundered through the UK after fleeing China. Metropolitan Police seized 61,000 Bitcoin—worth over £5.5 billion today—after a complex multi-year investigation involving international law enforcement and property laundering attempts. This landmark case highlights both the scale and sophistication of modern financial cybercrime, underscoring the growing global focus on cryptocurrency abuse for money laundering. As regulators and law enforcement agencies adapt, similar techniques threaten new sectors and jurisdictions, making robust compliance, asset tracing, and cross-border cooperation critical in cyber risk management.
8 months ago
Kill Chain
Malicious MCP Server Uncovered in 'postmark-mcp' npm Package Supply Chain Breach
In September 2025, cybersecurity researchers identified the first active malicious deployment of a Model Context Protocol (MCP) server, delivered through a compromised open-source npm package called "postmark-mcp." The attacker, masquerading as a legitimate developer, introduced rogue code into the package to stealthily exfiltrate user emails to an adversary-controlled MCP server. The package closely mimicked the official Postmark Labs library, making detection challenging for organizations relying on the trusted supply chain. The incident highlights the growing sophistication and operational impact of supply chain compromise, especially within widely used repositories like npm. This supply chain breach underscores a wider trend of attackers targeting open-source ecosystems to weaponize trusted libraries for data theft and persistent access, driving regulatory scrutiny and risk to software providers and their customers. With the acceleration of software supply chain attacks, organizations face increased pressure to enhance dependency audits and adopt zero trust controls.
8 months ago
Kill Chain
Microsoft Warns: AI-Powered SVG Phishing Campaign Evades Email Security
In September 2025, Microsoft disclosed a sophisticated phishing campaign targeting US-based organizations that leveraged large language models (LLMs) to craft highly obfuscated SVG file payloads. Attackers used these LLM-generated SVG attachments to evade traditional email security filters, employing convincing business terminology and synthetic code structures to deliver malicious links or steal credentials. The campaign demonstrates a notable escalation in phishing tactics, exploiting advancements in AI to automate and disguise attack vectors, with the operational impact ranging from compromised accounts to potential supply chain breaches. This incident exemplifies a new era of phishing attacks empowered by generative AI, underlining the growing urgency for advanced detection capabilities and stricter email security policies. The trend highlights a pivot toward more adaptive, machine-generated threats that traditional tools may be ill-equipped to address.
8 months ago
Kill Chain
EvilAI: Malware Masquerading as AI Tools Targets Global Enterprises in 2025
In September 2025, global organizations became targets of a sophisticated malware campaign in which cybercriminals disguised malicious payloads within seemingly legitimate AI productivity tools and software. Security researchers at Trend Micro identified that attackers leveraged the growing popularity and trust in AI-driven solutions to distribute their malware, affecting companies across Europe, the Americas, and AMEA. Adversaries exploited trusted distribution channels, leveraging convincing phishing and software bundling tactics to achieve initial access, with the primary goal of establishing persistent footholds for future attacks, including lateral movement and data exfiltration. The incident disrupted IT operations, forced incident response, and increased the risk of data theft and regulatory exposure. This breach highlights the rapid evolution of social engineering techniques tied to AI trends, with attackers exploiting user demand for productivity tools as an entry point. It underscores an urgent need for heightened vigilance, zero trust policies, and real-time threat detection in the face of shadow AI and increasingly indistinguishable malicious downloads.
8 months ago
Kill Chain
Ukrainian Police Spoofed: SVG Fileless Phishing Delivers Amatera Stealer in Kyiv
In early 2024, cybercriminals conducted a sophisticated phishing campaign targeting organizations and individuals in Kyiv, Ukraine, by spoofing the National Police of Ukraine. The attackers distributed malicious emails containing Scalable Vector Graphics (SVG) files, which enabled fileless delivery of info-stealing malware such as Amatera Stealer and the cryptocurrency miner PureMiner. By leveraging social engineering and trusted police branding, they bypassed common security defenses, leading to the theft of sensitive credentials, system compromise, and potential financial losses. The breach highlights attackers’ growing reliance on fileless techniques and deceptive lures to infiltrate victims’ environments with minimal detection. This incident underlines a shift toward advanced, stealthy phishing tactics that weaponize graphics files and trusted institutional identities. The approach signifies an escalating trend in cybercrime, where threat actors continue to innovate to evade legacy controls and exploit user trust amid ongoing geopolitical unrest.
8 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

