The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 6265 to 6276 of 6396
HiddenGh0st, Winos & kkRAT Malware: How SEO & Cloud Hosting Fueled a 2025 Chinese-Focused Attack
In September 2025, a sophisticated malware campaign targeted Chinese-speaking users through SEO poisoning and fake software sites, resulting in the widespread distribution of HiddenGh0st, Winos, and kkRAT malware. Attackers manipulated search results using SEO plugins, registered lookalike domains, and leveraged GitHub Pages to host malicious files. Unsuspecting users, believing they were downloading legitimate utilities, instead installed remote access trojans that enabled full compromise of their systems, data theft, and prolonged adversary presence. The campaign demonstrates coordinated threat actor use of both social engineering and modern cloud hosting platforms to bypass traditional security controls. This incident highlights an escalating trend of threat actors combining SEO manipulation with cloud-native infrastructure to launch convincing malware campaigns at scale. The use of popular developer tools like GitHub Pages for payload delivery complicates traditional egress controls, detection, and response, requiring organizations to bolster threat intelligence, web filtering, and zero-trust segmentation strategies.
9 months ago
Kill Chain
AI-Powered Villager Tool: How Cyberspike's PyPI Release Raised Global Supply-Chain Alarm
In 2025, a China-based group known as Cyberspike released an AI-powered penetration testing framework called 'Villager' on the Python Package Index (PyPI). Garnering nearly 11,000 downloads, Villager was marketed as a red teaming tool but drew significant attention after security researchers highlighted its dual-use potential for both legitimate and malicious activities. The framework’s advanced automation and stealth features make it attractive for attackers seeking to exploit software supply chains and pivot across cloud and hybrid environments, raising the risk profile for developers and organizations using open-source components. This incident underscores growing concerns about the unintended consequences of democratized offensive security tooling, particularly when distributed through popular code repositories. The rapid adoption and potential for supply-chain compromise highlight the urgency for heightened code vetting, continuous monitoring, and robust supply-chain security policies.
9 months ago
Kill Chain
Mass Browser-Based Attack Hits Enterprises: 2025’s Session Hijacking Wakeup Call
In August 2025, a sophisticated wave of browser-based attacks exploited vulnerabilities in popular browser components to hijack user sessions across multiple financial and technology firms simultaneously. Attackers leveraged phishing lures and malicious advertising to distribute payloads capable of intercepting authentication tokens and session cookies, enabling widespread unauthorized access. The campaign, attributed to a financially motivated eCrime group, enabled lateral movement within compromised cloud and SaaS applications, resulting in significant data exfiltration, temporary access loss, and incident-driven downtime for several affected organizations. This incident underscores a dramatic uptick in browser-native TTPs targeting identity, session integrity, and trusted cloud access. Threat actors are exploiting the growing reliance on web-based workflows and overlooked intra-browser security, making enhanced endpoint monitoring and Zero Trust controls more urgent than ever.
9 months ago
Kill Chain
Mustang Panda’s SnakeDisk USB Worm Targets Thailand: Advanced APT Breach Breakdown
In September 2025, cybersecurity analysts revealed that the China-aligned APT group Mustang Panda leveraged a novel USB worm dubbed SnakeDisk to target networks with Thailand-based IP addresses. The malware was specifically designed to execute only on devices with these geolocations, enabling highly targeted delivery of the TONESHELL loader and the Yokai backdoor. Attackers gained initial access through infected USB drives, allowing for stealthy lateral movement and installation of persistent remote access tools, posing risks to government, defense, and commercial operations in Thailand. The campaign’s use of an undocumented worm, encrypted command channels, and evasive tactics complicated detection and response efforts for affected organizations. This highly targeted operation demonstrates the continuous evolution of advanced persistent threat techniques, with regional targeting and removable media attacks making a significant comeback. The incident underscores the urgent need for robust east-west traffic controls, endpoint security, and focused detection in the face of increasingly sophisticated nation-state cyber campaigns.
9 months ago
Kill Chain
Self-Replicating Worm Strikes npm: 2025 Supply Chain Attack Exposes Critical Credential Risks
In September 2025, a major supply chain attack targeted the npm ecosystem, compromising over 40 packages and impacting projects worldwide. Attackers utilized a self-replicating worm delivered via manipulated npm modules; these modules would download, alter, and republish themselves by embedding malicious scripts directly into package files. As a result, sensitive developer credentials and system access tokens were harvested at scale, putting thousands of developer environments and downstream applications at risk, eroding trust in open-source software supply chains. This campaign highlights the growing risk and sophistication of supply chain attacks leveraging automated propagation across trusted developer channels. With the expanding reliance on open-source components and increasing regulatory scrutiny, organizations must urgently strengthen controls around development pipelines and dependency security.
9 months ago
Kill Chain
Phoenix RowHammer: How Advanced DDR5 Memory was Hacked in 2025
In August 2025, researchers from ETH Zürich and Google unveiled "Phoenix," a sophisticated RowHammer attack variant (CVE-2025-6202, CVSS 7.1) targeting SK Hynix DDR5 memory chips. Despite modern hardware defenses, Phoenix exploits advanced memory vulnerabilities to flip bits in protected memory rows, fully bypassing current mitigation technologies. The attack achieved successful exploitation in as little as 109 seconds, highlighting a critical weakness in memory protection schemes and raising concern for sensitive computing environments, from cloud servers to critical infrastructure. This incident demonstrates the evolving threat landscape for hardware-level attacks, emphasizing the urgency for chipmakers and enterprises to scrutinize and enhance DDR5 memory protections. Ongoing research into side-channel and memory-based exploitation, alongside increasing hardware reliance, make this a timely warning for organizations relying on modern DRAM.
9 months ago
Kill Chain
Apple 2025 ImageIO Zero-Day Breach Highlights Spyware Risks
In September 2025, Apple urgently released backported security updates to address CVE-2025-43300, a critical out-of-bounds write vulnerability in the ImageIO component exploited by advanced spyware campaigns. Attackers leveraged malicious image files to trigger memory corruption on Apple devices, enabling remote code execution and potential device takeover. The exploit was actively seen in targeted attacks against high-profile individuals, emphasizing the risk of spyware abusing zero-day vulnerabilities for persistent surveillance. The incident underscores the growing sophistication and frequency of attacks exploiting media processing flaws. This breach highlights an intensifying trend of threat actors using zero-day vulnerabilities in consumer devices for espionage. It demonstrates how attackers pivot to less-monitored device components and rapidly weaponize novel flaws, reinforcing the urgent need for continuous patching and proactive detection of anomalous behaviors on endpoints.
9 months ago
Kill Chain
SlopAds: How 224 Android Apps Fueled a $Billion Ad Fraud Scam in 2025
In late 2025, the SlopAds ad fraud ring was exposed running a sophisticated scheme across 224 Android applications, amassing more than 38 million downloads globally. The attackers covertly embedded steganography-based payloads within these apps, enabling them to generate hidden WebViews and surreptitiously route ad clicks and impressions to threat actor-controlled cashout sites. This campaign resulted in a staggering 2.3 billion daily fraudulent ad bids, undermining advertiser spending and trust in mobile advertising. Investigations revealed that the fraud operated across 228 countries and leveraged advanced techniques to evade security controls and detection. This incident highlights a growing trend in large-scale, automated digital ad fraud utilizing supply chain infiltration and advanced evasion. With mobile devices as primary attack surfaces and threat actors exploiting application distribution ecosystems, organizations face heightened regulatory scrutiny, financial risk, and an urgent need for granular visibility, segmentation, and anomaly detection capabilities.
9 months ago
Kill Chain
Multilingual Phishing: FileFix Variant Delivers StealC Infostealer in 2025
In September 2025, security researchers identified a sophisticated phishing campaign delivering a new variant of the StealC information-stealer malware via a convincing, multilingual phishing website impersonating popular brands such as Facebook Security. The attackers leveraged advanced social engineering tactics, widespread language support, heavy anti-analysis measures, and advanced obfuscation to successfully bypass traditional security detections. The campaign’s initial access was achieved through social engineering, leading victims to download malicious payloads disguised as legitimate files, which, once executed, exfiltrated credentials and sensitive data at scale. This incident highlights an ongoing surge in multilingual, highly tailored phishing approaches that utilize advanced anti-detection techniques, making detection and mitigation more difficult. Organizations face mounting pressure to strengthen controls against information stealers as attackers adapt proven TTPs to bypass endpoint protection and target a global victim base.
9 months ago
Kill Chain
Chaos Mesh Critical GraphQL Flaws Put Kubernetes Clusters at Risk in 2025
In September 2025, multiple critical vulnerabilities were discovered in Chaos Mesh, a popular cloud-native chaos engineering platform, exposing Kubernetes clusters to remote code execution (RCE) via unauthenticated GraphQL endpoints. Attackers with minimal in-cluster network access could exploit these flaws to execute arbitrary code, trigger disruptive fault injections (such as pod deletion and network outages), and ultimately achieve full cluster takeover. The vulnerability stemmed from insufficient access controls and improper GraphQL API handling, allowing adversaries to escalate privileges and compromise cluster workloads. As a result, organizations relying on Chaos Mesh in production faced heightened risk to workload integrity and business continuity until patches were applied. This breach highlights the increasing threat to supply-chain components in cloud-native environments, where tools with high privileges can inadvertently expose entire clusters. The rapid disclosure and fix cycle signals a need for strict RBAC, vigilant monitoring, and timely patching as attacker focus shifts towards exploiting platform-level risks.
9 months ago
Kill Chain
Microsoft & Cloudflare Dismantle RaccoonO365 Global Phishing Network (2025)
In September 2025, Microsoft’s Digital Crimes Unit (DCU), in partnership with Cloudflare, coordinated a global takedown of the RaccoonO365 phishing network. The PhaaS operation leveraged 338 domains to deliver convincing Microsoft 365 phishing campaigns, compromising over 5,000 credentials across 94 countries since July 2024. By obtaining a court order from the Southern District of New York, DCU seized infrastructure used by the financially motivated RaccoonO365 group, disrupting ongoing credential theft and reducing further business email compromise (BEC) risk to organizations worldwide. This incident underscores the rapid evolution and global scale of phishing-as-a-service networks, which are automating credential theft across cloud platforms. As attackers exploit trusted SaaS brands with commodity toolkits, vigilance around cloud identity and supply chain access is now a critical board-level concern.
9 months ago
Kill Chain
Scattered Spider Returns: New Wave of Social Engineering Attacks on Financial Services
In late 2025, cybersecurity researchers at ReliaQuest linked a new wave of attacks in the financial services sector to the notorious cybercrime collective Scattered Spider, despite previous claims that the group had disbanded. These attacks featured advanced social engineering tactics, the registration of lookalike domains, and exploitation of internal access paths to facilitate credential compromise and lateral movement inside targeted organizations. Impact resulted in unauthorized access to sensitive financial data, disruption of key operations, and raised concerns about the sector’s preparedness for sophisticated, identity-driven threats. The re-emergence of Scattered Spider underscores a resurgence of high-profile, financially motivated cybercrime against critical industries. The campaign highlights the evolving threat landscape—where even 'retired' threat groups rapidly adapt their tactics—reinforcing the urgency of east-west security monitoring, identity protections, and robust zero trust strategies.
9 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

