The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 6217 to 6228 of 6396
GoAnywhere 2025: Maximum-Severity Vulnerability Spurs Ransomware Fears Globally
In September 2025, a critical vulnerability (CVE-2025-10035) was disclosed in Fortra's GoAnywhere Managed File Transfer (MFT) service, exposing over 3,000 organizations, including major Fortune 500 companies, to significant risk. The flaw, a maximum-severity deserialization bug requiring no authentication, allows remote attackers to gain unauthorized code execution by leveraging a crafted license response signature. While no exploitation was detected at the time of disclosure, researchers warn that ransomware groups—such as Clop, known for previously targeting file-transfer software—are likely to attempt mass exploitation based on past patterns and the high impact of this vulnerability. If exploited, this flaw could result in widespread data theft, business disruption, and regulatory penalties. This incident is especially important as it mirrors techniques used in highly publicized attacks on file-transfer applications, highlighting increased sophistication and urgency among ransomware operators. The ongoing evolution of such vulnerabilities amplifies the threat to critical data flows and underscores rising compliance and zero trust enforcement needs across enterprises.
9 months ago
Kill Chain
ICS Malware Attacks Spike in Q2 2025: Key Lessons for Industrial Automation Security
In Q2 2025, industrial automation systems worldwide experienced significant and persistent threats, with 20.5% of ICS (Industrial Control Systems) computers encountering malicious objects, despite a slight quarterly decrease. Attackers leveraged a multi-stage campaign, beginning with phishing emails and malicious documents to gain access, and subsequently deploying next-stage malware such as spyware, ransomware, and cryptominers. Regions like Africa and sectors such as biometrics were among the most targeted, while common initial infection sources included malicious internet resources, infected emails, and removable media devices. Multiple sophisticated malware families (over 10,000 variants) exploited ICS security gaps to enable lateral movement, persistent access, and data exfiltration, impacting operational resilience and increasing risk of service disruption for critical industries. This incident underscores the continued evolution of ICS-targeting malware and the increasing sophistication of attack vectors in the operational technology sector. The upward trend in email-based infiltration and malicious cloud links, coupled with persistent use of multi-stage payloads, highlights the urgent need for robust, layered security, Zero Trust policies, and compliance alignment to protect critical infrastructure environments against both commodity and targeted threats.
9 months ago
Kill Chain
CISA Warning: Malware Exploits Ivanti EPMM Vulnerabilities in 2025 Breach
In September 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) disclosed the discovery of two new malware strains that exploited critical zero-day vulnerabilities (CVE-2025-4427, CVE-2025-4428) in Ivanti Endpoint Manager Mobile (EPMM). Threat actors breached an unnamed organization’s EPMM server, deploying custom loader malware which enabled remote code execution and persistent control over the compromised environment. The attack leveraged unpatched flaws to bypass network and application controls, potentially exposing sensitive enterprise and mobile device data, and allowing attackers to pivot deeper within the victim’s infrastructure. This incident highlights a rising trend in sophisticated exploitation of mobile device management (MDM) platforms and underscores the growing risk posed by supply chain attacks, advanced malware loaders, and rapid weaponization of newly disclosed vulnerabilities. Security teams must act swiftly as threat actors increasingly target widely deployed IT infrastructure software with automated, multi-stage campaigns.
9 months ago
Kill Chain
Teen Hackers Arrested for Scattered Spider Cyber Attack on TfL in 2024
In August 2024, Transport for London (TfL) experienced a cyber attack attributed to teen members of the Scattered Spider hacking group, known for leveraging social engineering and identity compromise. Attackers allegedly gained access to internal systems, disrupting service operations and putting critical transport and passenger information at risk. U.K. authorities arrested Thalha Jubair (19) and Owen Flowers (18) in September 2024 for their involvement, underlining the rapid evolution of cybercriminal tactics and the challenge of securing public infrastructure. This incident is a prime example of increasingly sophisticated attacks leveraging compromised credentials and insider tactics, even involving younger threat actors. It highlights both the threat to public services and the urgency for robust Zero Trust controls amid a landscape of rising identity-driven intrusions.
9 months ago
Kill Chain
Russian APTs Gamaredon and Turla Join Forces: Kazuar Backdoor Attack on Ukraine (2025)
In February 2025, cybersecurity researchers observed a coordinated attack on Ukrainian organizations involving collaboration between Russian APT groups Gamaredon and Turla. Utilizing tools such as PteroGraphin and PteroOdd, Gamaredon gained initial access and facilitated the deployment of Turla’s advanced Kazuar backdoor onto a compromised Ukrainian endpoint. This multi-stage intrusion enabled persistent remote access and potential data exfiltration, underscoring a notable escalation in Russian state-sponsored cyber tactics, as adversaries actively combined resources and malware capabilities to maximize operational impact. The attack targeted sensitive Ukrainian infrastructure, heightening concerns over the defense of critical systems. This incident exemplifies the increasing integration and sophistication among nation-state threat actors, specifically through sharing or chaining malware tools for greater effect. The cooperative tactics and advanced persistence mechanisms highlight the evolving threat landscape and emphasize the urgency for enhanced east-west traffic security, zero trust segmentation, and anomaly detection across critical sectors.
9 months ago
Kill Chain
Global Surge in PhaaS: 17,500 Phishing Domains Exploit 316 Brands
In mid-2025, cybersecurity researchers exposed an extensive global phishing campaign orchestrated via Phishing-as-a-Service (PhaaS) platforms Lighthouse and Lucid. These services facilitated the deployment of more than 17,500 phishing domains impersonating 316 brands across 74 countries. The PhaaS operators provided subscription access to professionally maintained phishing kits targeting both enterprises and individual users, enabling attackers with minimal technical expertise to launch widespread credential theft attacks. As a result, organizations in sectors ranging from finance to technology experienced increases in fraudulent account access, financial loss, and reputational harm. The scale and automation lowered barriers for entry, allowing rapid exploitation and high turnover of malicious domains. This incident underscores the rapid evolution of cybercriminal business models, notably the rise of PhaaS, which commoditizes phishing attacks on a global scale. Its effectiveness and accessibility are driving a surge in targeted brand impersonation attempts and amplifying regulatory attention around authentication, threat monitoring, and user awareness.
9 months ago
Kill Chain
Fortra GoAnywhere MFT 2025: CVE-2025-10035 Exposed Critical Enterprise File Transfers
In September 2025, Fortra disclosed a critical security vulnerability (CVE-2025-10035) in its GoAnywhere Managed File Transfer (MFT) platform. The flaw, a deserialization weakness in the License Servlet, enabled remote attackers to execute arbitrary commands if they could submit a forged license request. Malicious activity leveraging this zero-day allowed threat actors to gain unauthorized access to sensitive file transfers, escalate privileges, and potentially exfiltrate confidential information before a patch was issued. The vulnerability received a maximum CVSS score of 10.0, emphasizing its severe risk and widespread exploitability. This incident highlights the ongoing surge in weaponization of zero-day vulnerabilities affecting popular enterprise software. Threat actors are increasingly exploiting deserialization bugs to bypass security controls and facilitate ransomware operations, putting organizations and their supply chains at heightened risk unless immediate mitigations are applied.
9 months ago
Kill Chain
SystemBC-Powered REM Proxy Botnet: 1,500 VPSs Compromised Daily in 2025
In mid-2025, cybersecurity researchers from Lumen's Black Lotus Labs identified a large-scale proxy botnet operation named REM Proxy, powered primarily by the SystemBC malware. Attackers leveraged SystemBC to compromise over 1,500 virtual private servers (VPS) daily, utilizing them to fuel a criminal proxy-as-a-service spanning 80 command-and-control (C2) servers. The network enabled threat actors to anonymize malicious activities and included access to approximately 20,000 vulnerable Mikrotik routers and additional open proxies. This infrastructure facilitated evasion, lateral movement, and widespread malicious activity with significant security implications for targeted and intermediary organizations. This incident underscores the ongoing evolution of proxy botnets and malware-as-a-service ecosystems, which pose critical risks for organizations across various sectors. As the boundaries between cybercrime infrastructure and legitimate cloud assets blur, defenders must place renewed emphasis on advanced threat detection, network segmentation, and zero trust principles to mitigate similar emergent threats.
9 months ago
Kill Chain
UNC1549: Iranian Cyber Espionage Breaches 11 European Telecoms Using LinkedIn Lures
In mid-2025, an Iran-affiliated cyber espionage group tracked as UNC1549 executed a coordinated attack targeting 11 European telecommunications firms. Using LinkedIn job recruitment lures and the custom MINIBIKE malware, the attackers successfully infiltrated 34 devices within these organizations, gaining persistent access to sensitive internal systems. The campaign, discovered by Swiss cybersecurity company PRODAFT, leveraged sophisticated social engineering alongside stealthy lateral movement, indicating considerable operational capability and intent to harvest confidential information potentially valuable for nation-state interests. This incident underscores a rising trend of strategic supply chain and telecom attacks using spear phishing and novel malware, highlighting the importance of strong east-west traffic controls and threat detection. It also reflects growing geopolitical tensions fueling state-sponsored cyber campaigns against critical infrastructure in Europe.
9 months ago
Kill Chain
AdaptixC2 in Real-World Attacks: Open-Source C2 Framework Alters the Threat Landscape
In early 2024, security researchers discovered that AdaptixC2, a newly released open-source command and control (C2) framework, was actively leveraged by threat actors in real-world intrusion campaigns. The attackers employed AdaptixC2 for post-exploitation activities, enabling covert command execution, lateral movement, and persistent access within targeted enterprise networks. The framework’s encrypted traffic and modular architecture allowed actors to evade traditional security controls, complicating detection and response efforts and increasing business risk. The widespread adoption of open-source C2 frameworks like AdaptixC2 underscores a shift where commodity offensive tools rapidly enter the arsenal of both sophisticated and opportunistic threat actors. This trend increases attack surface for organizations and challenges defenders to implement advanced incident detection, with regulatory bodies stressing the importance of proactive east-west and anomaly monitoring.
9 months ago
Kill Chain
Shai-Hulud Worm Breach: npm Supply Chain Attack in 2023
In November 2023, the self-replicating 'Shai-Hulud' worm orchestrated a large-scale supply chain attack targeting the npm ecosystem. The threat actor compromised hundreds of npm packages, inserting malicious code that enabled lateral propagation and potential backdoor access for anyone who installed the affected libraries. The attack illustrates how deeply embedded dependencies and trusted registries can be manipulated to impact thousands of downstream projects and potentially expose sensitive systems. Swift action from npm and security researchers helped mitigate the spread, but several organizations experienced heightened risk before remediation. This incident underscores the growing threat and frequency of software supply chain compromises, particularly targeting open-source registries. With adversaries leveraging automation and worm-like propagation, the security of development pipelines and third-party code ingestion remains an urgent focus for digital businesses.
9 months ago
Kill Chain
Scattered Spider Exposed: 2024 Ransomware Hits Critical Infrastructure and Healthcare
In September 2024, UK authorities arrested two teenagers, Thalha Jubair and Owen Flowers, for their significant roles in numerous cyberattacks attributed to the Scattered Spider gang—a notorious offshoot of The Com collective. Operating since at least May 2022, the pair leveraged social engineering techniques to infiltrate a range of organizations, including Transport for London, U.S. critical infrastructure, healthcare providers, and the federal court system. They stole and encrypted sensitive data, then demanded ransom payments, netting at least $115 million from 47 U.S. victims alone. Cryptocurrency wallets tied to the suspects were seized, totaling over $36 million, and both face serious charges on both sides of the Atlantic. This incident illustrates the growing threat from young, highly skilled ransomware groups utilizing sophisticated extortion tactics. As extortion and identity-driven ransomware evolve, organizations—especially those in critical industries—face increasing pressure to bolster defenses against lateral movement and social engineering-based breaches.
9 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

