The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 6205 to 6216 of 6396
DPRK Leverages ClickFix Job Scams to Infest Crypto Firms with BeaverTail Infostealer
In September 2025, threat actors linked to North Korea (DPRK) orchestrated a targeted phishing campaign leveraging ClickFix-style lures against employees in the cryptocurrency and retail sectors. Masquerading as legitimate job opportunities for marketing and trader roles, attackers distributed malicious files leading to infection with BeaverTail and InvisibleFerret malware. This allowed adversaries to employ infostealing techniques, facilitating lateral movement and potential data exfiltration, while avoiding traditional security controls. The campaign highlights DPRK’s continued focus on crypto-enabled theft, using sophisticated social engineering, custom tooling, and industry-specific targeting. This incident underscores a recent surge in state-sponsored campaigns prioritizing non-technical roles and leveraging advanced lure techniques. Organizations in high-value verticals like crypto are increasingly attractive to financially motivated adversaries, elevating the urgency for zero trust defenses and robust internal traffic security controls.
9 months ago
Kill Chain
2025 Picus Blue Report: Why Ransomware Still Evades Defenses
In early 2025, the Picus Blue Report identified a concerning trend in global ransomware attacks: despite widespread awareness of ransomware tactics, organizations failed to prevent over a third of attack attempts, with prevention rates plummeting to 62%. Far more alarming, only 3% of simulated data exfiltration attempts were effectively blocked, exposing substantial gaps in data security frameworks. Attackers leveraged a blend of known and emerging ransomware variants to infiltrate networks, bypassing traditional and next-gen defenses by exploiting east-west traffic and insufficient segmentation. This led to successful encryption and large-scale data theft, disrupting business continuity for multiple sectors globally. This incident underscores a broader industry challenge: as ransomware evolves, so do the techniques for bypassing established defenses. The drastic fall in exfiltration prevention highlights an urgent need for modernized controls, especially with the regulatory and reputational stakes of breaches rising sharply in 2025.
9 months ago
Kill Chain
Fortra GoAnywhere MFT 2024: License Servlet Zero-Day Exposes File Transfer Infrastructure
In June 2024, Fortra disclosed a critical vulnerability (CVE-2024-XXXX) in its GoAnywhere Managed File Transfer (MFT) product’s License Servlet, enabling unauthenticated attackers to execute system commands remotely via command injection. Researchers discovered that by submitting crafted requests to the vulnerable servlet, attackers could gain full control of affected servers. No authentication was required, significantly increasing the risk of exploitation. Fortra released immediate security updates and guidance after reports of active exploitation attempts surfaced. Impacted organizations primarily included enterprises leveraging GoAnywhere MFT for secure file transfers, resulting in heightened risk of data exfiltration and business disruption. This incident underscores the ongoing importance of timely patch management, especially for widely used secure transfer solutions. The vulnerability’s ease of exploitation and criticality reflects trends of attackers targeting third-party file transfer products—often for extortion or ransomware campaigns—prompting renewed regulatory and industry scrutiny.
9 months ago
Kill Chain
Inside the Ivanti EPMM 2025 Breach: How China-Linked APTs Exploited Zero-Day Flaws
In May 2025, advanced threat actors exploited two zero-day vulnerabilities (CVE-2025-4427 and CVE-2025-4428) in Ivanti Endpoint Manager Mobile (EPMM), targeting on-premise deployments. Attackers used an authentication bypass and code injection to deliver modular malware kits via crafted API requests, enabling them to gain initial access, perform reconnaissance, harvest credentials, and establish persistence within target environments. While Ivanti released patches shortly after discovery, the exploits were reportedly active before disclosure, affecting a limited set of organizations—primarily through an advanced persistent threat (APT) operation attributed by third-party researchers to a China-nexus espionage group. This incident underscores the growing trend of sophisticated supply chain and zero-day attacks on enterprise mobile device management (MDM) platforms, which are increasingly treated as high-value assets due to their access to sensitive business operations. Organizations must remain vigilant by prioritizing comprehensive patch management and strengthening internal traffic monitoring to mitigate similar risks.
9 months ago
Kill Chain
Canada Seizes $40 Million in Historic Crackdown on TradeOgre Crypto Exchange
In September 2025, the Royal Canadian Mounted Police (RCMP) dismantled the TradeOgre cryptocurrency exchange, seizing over $40 million in digital assets linked to alleged financial crimes. The operation was initiated following intelligence from Europol, leading to an investigation by the Money Laundering Investigative Team (MLIT) that uncovered the exchange's lack of regulatory compliance, such as evading Know Your Customer (KYC) protocols and failing to register with Canada's FINTRAC. The lack of oversight facilitated the laundering of cybercrime proceeds, particularly via privacy-focused cryptocurrencies like Monero, culminating in the country's largest-ever asset seizure. This incident underscores the growing scrutiny and regulatory pressure on privacy-centric platforms facilitating anonymous digital transactions. The enforcement action highlights heightened law enforcement capabilities targeting underground exchanges and reflects broader trends in global efforts to curb illicit finance within the crypto sector.
9 months ago
Kill Chain
ShadowLeak: Zero-Click OpenAI ChatGPT Bug Exposes Gmail Data in 2025
In June 2025, a critical zero-click vulnerability, codenamed ShadowLeak, was discovered in OpenAI ChatGPT’s Deep Research agent. This flaw enabled attackers to exfiltrate sensitive Gmail inbox content merely by sending a specially crafted email to victims using the agent, requiring no user action. Security researchers from Radware, after identifying the issue, disclosed it responsibly to OpenAI, which released a fix in early August 2025. The flaw had the potential to compromise confidential data across enterprise and personal Gmail accounts, raising major concerns around AI-driven integrations and email ecosystem security. This breach highlights the accelerating convergence of artificial intelligence with traditional email attack surfaces, raising unique risks around invisible, automated threat vectors. With GenAI agents increasingly embedded into communication flows, attackers are rapidly adapting zero-click tactics to exploit new behaviors and trust assumptions.
9 months ago
Kill Chain
MalTerminal: GPT-4-Powered Malware Signals New Era of AI Cyberattacks
In September 2025, SentinelOne’s SentinelLABS revealed the existence of 'MalTerminal,' the first documented malware leveraging GPT-4-powered Large Language Model (LLM) capabilities. Demonstrated at LABScon 2025, MalTerminal introduces LLM-driven automation within the malware lifecycle—enabling it to generate ransomware payloads, establish reverse shells, and craft social engineering content in real time. The attack method shows that malware authors are blending AI models directly into code to rapidly escalate privilege, automate lateral movement, and obfuscate command-and-control traffic. Business impact includes advanced, adaptive attacks that defeat legacy detection, heightening risks of data exfiltration, extended dwell time, and operational disruption. MalTerminal’s emergence is a bellwether for the rapid weaponization of generative AI technology by threat actors. This incident highlights the urgent need for organizations to re-evaluate traditional controls and accelerate adoption of cognitive security, visibility, and real-time policy enforcement frameworks to keep pace with evolving adversary techniques.
9 months ago
Kill Chain
LastPass Exposes macOS Atomic Infostealer Attack via Fake GitHub Repositories
In mid-2025, LastPass identified and warned users about a sophisticated information-stealing campaign targeting Apple macOS users. Attackers set up fraudulent GitHub repositories impersonating reputable projects, including LastPass, to distribute versions of the 'Atomic' infostealer malware. Unsuspecting users downloading these fake tools had their credentials, browser data, and sensitive files compromised. The campaign leveraged social engineering, search poisoning, and open-source developer trust to infiltrate victims’ systems, posing significant risk to both individual and enterprise security. The incident highlights continued abuse of trusted development platforms to target the software supply chain. This breach is noteworthy as it reflects the growing trend of attacker focus on macOS endpoints and the exploitation of open-source ecosystems. With supply chain attacks and infostealer campaigns rising sharply in 2025, organizations face increasing pressure to enhance their controls for code provenance, user awareness, and endpoint defense.
9 months ago
Kill Chain
How 'ShadowLeak' Turned ChatGPT into a Data Exfiltration Channel
In mid-2024, security researchers uncovered a novel cyberattack—dubbed 'ShadowLeak'—that exploits OpenAI’s ChatGPT platform to surreptitiously exfiltrate emails and sensitive enterprise data. Threat actors leveraged covert techniques to route data through OpenAI’s infrastructure, effectively bypassing traditional network security controls and leaving virtually no forensic traces within the victim organization. The attack exploits the trusted status of sanctioned AI platforms inside corporate environments, making malicious exfiltration activity blend in with legitimate AI-assisted workflow traffic. As a result, internal monitoring and traditional DLP tools fail to identify or intercept the breach, putting confidential business communications and data at risk. This incident spotlights the growing risk posed by increasingly sophisticated methods of data exfiltration over legitimate AI services. With organizations accelerating the adoption of generative AI in critical business processes, attackers are exploiting technical and policy blind spots, making traditional perimeter defenses inadequate against such stealthy insider threats.
9 months ago
Kill Chain
Critical Fortra GoAnywhere 2025 Vulnerability Enables Command Injection Attacks
In early June 2025, Fortra disclosed a critical command injection vulnerability (CVE-2025-10035) in its GoAnywhere managed file transfer (MFT) solution. The flaw could be exploited by unauthenticated attackers if the management interface was exposed to the Internet, allowing remote code execution and potential takeover of affected servers. Fortra warned that active exploitation had been observed, and threat actors were leveraging the vulnerability to move laterally within compromised networks and facilitate data exfiltration. The incident affected a broad range of organizations reliant on GoAnywhere for secure file transfers, raising concerns about operational continuity and potential data exposure. The attack underscores the ongoing risk posed by internet-exposed enterprise services and highlights the urgent need for timely patching of high-severity vulnerabilities. Increasingly, ransomware and data theft campaigns are targeting known security flaws in widely-used third-party solutions, putting supply chains and regulatory compliance at risk.
9 months ago
Kill Chain
AI Supercharges Ransomware: SMBs Face New Extortion Tactics in 2024
In early 2024, small and medium-sized businesses (SMBs) experienced a significant surge in ransomware attacks, with threat actors leveraging AI-driven tools to automate reconnaissance, exploit vulnerabilities, and escalate extortion tactics. Attackers typically gained initial access through phishing emails, credential compromise from infostealer malware, or unpatched systems, then deployed dual-pronged ransomware campaigns involving both data encryption and data theft for double extortion. These incidents were characterized by rapidly evolving tactics, including deployment of 'EDR killer' malware to neutralize security controls and the emergence of AI-powered ransomware strains like PromptLock, further complicating incident recovery. Businesses reported severe operational disruptions, permanent data loss, and in some cases, closure due to the financial and reputational fallout. The proliferation of ransomware-as-a-service (RaaS), combined with AI-enabled attack chains, has dramatically widened the threat landscape for SMBs—who account for nearly 9 in 10 ransomware breaches. The current wave highlights the urgent need for organizations of all sizes to revisit their defensive posture, ensure visibility, and adopt zero trust and modern detection solutions to mitigate evolving risks.
9 months ago
Kill Chain
Gamaredon & Turla: Joint APT Campaign Strikes Ukraine in 2025
In early 2025, a previously unseen collaboration between advanced persistent threat groups Gamaredon and Turla was discovered in Ukraine. Utilizing ESET telemetry, researchers identified co-compromises in which Gamaredon provided initial access using spearphishing and malicious PowerShell-based tools (such as PteroGraphin and PteroOdd), allowing Turla to deploy its exclusive Kazuar backdoor on select high-value targets. The attacks, attributed to Russian FSB-linked groups, targeted governmental entities and leveraged encrypted channels, PowerShell scripting, and multi-stage malware delivery via compromised web services and cloud platforms. Impact was mainly concentrated on the potential exfiltration of sensitive national intelligence. This incident underscores a growing trend of threat actor collaboration within nation-state cyber operations, blurring lines between operational roles and increasing attack efficiency. The overlapping TTPs and use of novel access and persistence mechanisms signal heightened complexity in the Eastern European threat landscape, demanding urgent operational and strategic defensive improvements.
9 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

