The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 6301 to 6312 of 6396
SXVM Ransomware PoC Reveals Next-Gen DLL Unhooking to Bypass EDR
In September 2024, a novel ransomware proof-of-concept dubbed 'SXVM' showcased advanced defensive evasion capabilities through DLL unhooking, enabling it to bypass traditional endpoint detection and response (EDR) tools. The threat leverages in-memory manipulation to restore .text sections of key system DLLs—effectively undoing any hooks or software breakpoints set by debuggers and security products. This approach allows ransomware operators to conceal malicious actions and access powerful Windows APIs unchecked. While initial analysis points to a low detection rate and proof-of-concept status, the technique underscores an escalating trend in ransomware sophistication and anti-forensic tactics. This incident is especially relevant as ransomware variants increasingly adopt anti-debugging and anti-EDR methods. The widespread use of DLL unhooking signals a maturing threat landscape, where attackers are continuously innovating to defeat security controls and leverage memory-based evasion techniques.
9 months ago
Kill Chain
Code Assistant LLM Vulnerabilities Expose New AI Supply Chain Risks (2024)
In early 2024, multiple leading code assistant platforms powered by Large Language Models (LLMs) were found to be vulnerable to security threats such as indirect prompt injection, model misuse, and code suggestion manipulation. Attackers exploited weaknesses in prompt handling and insufficient contextual isolation, allowing harmful code or misleading content to be surfaced to end users and potentially exposing enterprise environments to supply chain risks. These risks highlight the growing attack surface in organizations leveraging AI-driven development tools, where impaired oversight can lead to deceptive or insecure code entering production systems. This incident underscores the urgency for enterprises to evaluate the deployment and integration practices for generative AI tools, particularly given the rapid rise in adoption and regulatory focus on AI safety. Attacker tactics are evolving quickly, and threat actors are increasingly targeting AI models and their usage contexts as a new cyber frontier.
9 months ago
Kill Chain
Q2 2025 Mobile Malware Surge: Mamont and Triada Lead Sophisticated Attacks
In Q2 2025, Kaspersky detected a substantial wave of mobile malware impacting Android and iOS, blocking 10.71 million attacks involving Trojans, adware, and unwanted applications. The campaign was notable for a surge in banking Trojans—primarily the Mamont family—pre-installed backdoors like Triada, and novel threats such as SparkKitty, which targets crypto wallet recovery codes via image theft. Attackers leveraged fake app stores, porn-viewing apps that secretly built DDoS botnets, and deceptive VPNs that intercepted OTP codes through notification hijacking. Regionalized attacks exploited localized malware families to increase efficacy and evade global threat visibility, raising risks for financial and privacy exposure worldwide. This incident highlights a persistent trend of increasingly sophisticated mobile threats focused on financial theft and data exfiltration. The continued evolution of malware TTPs, including use of pre-installed Trojans, modular SDK-based payloads, and cross-platform attack vectors, emphasizes the urgent need for advanced endpoint protection and vigilant detection routines in the mobile security domain.
9 months ago
Kill Chain
RevengeHotels 2025: AI-Fueled VenomRAT Breach Hits Hospitality Sector
In the summer of 2025, the RevengeHotels cybercrime group (also tracked as TA558) significantly escalated its campaigns targeting the hospitality sector across Latin America, especially Brazil. Leveraging large language models (LLMs) to dynamically generate phishing lures and scripted malware loaders, the attackers delivered new VenomRAT payloads via sophisticated, invoice-themed phishing emails. These emails led hotel staff to malicious websites that dropped JavaScript and PowerShell-based loaders, ultimately granting persistent remote access for data theft and lateral movement. The attack exploited evolving tactics such as anti-kill mechanisms, registry persistence, custom encryption, and use of AI-generated code to evade detection. This incident demonstrates a marked evolution in attacker methodology, combining commodity malware, AI-driven code generation, and targeted social engineering. Such developments highlight how AI is accelerating the sophistication and reach of cyber threats, particularly in sectors with high-value payment data and limited security resources.
9 months ago
Kill Chain
2025 Salesforce Data Breach: Supply Chain Extortion Hits Retail Sector
In mid-2025, a coordinated cybercriminal campaign led by UNC6395 and affiliates of Muddled Libra targeted Salesforce tenants via a multi-stage supply chain attack stemming from infiltrated third-party integrations such as Salesloft and Drift. Attackers used advanced social engineering and process exploitation rather than technological vulnerabilities to gain access to Salesforce customer data—including sensitive records like accounts, contacts, and opportunities. The operation highlighted the growing focus on data theft extortion tactics and the use of encrypted communications, with threat actors actively marketing stolen data through Telegram channels under monikers like "Scattered LAPSUS$ Hunters." The impact has been significant for retailers and digital platform users, driving urgent defensive and policy changes at Salesforce and affected enterprises. This incident underscores an accelerating threat shift in 2025: attackers are increasingly leveraging social engineering and the SaaS supply chain to circumvent traditional defenses, monetizing access through extortion rather than ransomware. The event has intensified industry efforts to tighten access controls and enforce encryption, amid persistent regulatory and law enforcement actions.
9 months ago
Kill Chain
Apple’s 2025 Zero-Day Puts iOS & macOS Security in Spotlight: What You Need to Know
In September 2025, Apple issued urgent patches for iOS, iPadOS, and macOS in response to several critical vulnerabilities, with CVE-2025-43300 standing out due to active exploitation in sophisticated targeted attacks. The vulnerability, affecting the ImageIO component, enabled attackers to compromise devices by processing malicious image files, potentially resulting in memory corruption and enabling unauthorized access or control. Previous patches were limited to the latest OS versions, leaving older systems exposed until this coordinated rollout addressed those gaps. Apple further backported fixes to supported older releases to mitigate the heightened risk of exploitation. This incident underscores an accelerating wave of zero-day vulnerabilities leveraged in real-world attacks, highlighting the persistent threats facing major software ecosystems like Apple’s. The discovery and rapid backporting response reflects mounting regulatory and industry pressure to quickly secure even legacy platforms and close compliance gaps.
9 months ago
Kill Chain
npm’s Largest Supply Chain Compromise: Phishing and the Fragility of Open Source Security
In June 2024, a major npm supply chain compromise saw attackers inject malicious code into 18 highly popular JavaScript packages, including chalk and debug, which together accounted for over 2.6 billion weekly downloads. The breach began with a successful phishing attack targeting a package maintainer, resulting in the theft of two-factor authentication credentials. Threat actors quickly published backdoored versions of affected packages, which were downloaded millions of times in minutes before rapid detection and disclosure limited the fallout. The immediate financial losses were low, with only minimal amounts of cryptocurrency stolen, but the operational impact included widespread remediation efforts across thousands of organizations dependent on these open-source assets. This incident exemplifies the growing risk and frequency of supply chain attacks leveraging compromised maintainers and rapid malware propagation in software registries. It highlights the urgent need for enhanced account security, ecosystem-level safeguards, and improved transparency, as such compromises are increasingly targeted by sophisticated actors and threaten the core trust mechanisms of modern digital infrastructure.
9 months ago
Kill Chain
Phoenix Attack Bypasses DDR5 Rowhammer Defenses in 2025
In September 2025, researchers from ETH Zurich and Google disclosed the 'Phoenix' attack—a novel Rowhammer-based hardware vulnerability that successfully bypasses the Target Row Refresh (TRR) defenses in popular DDR5 memory chips, specifically targeting modules from market leader SK Hynix. By exploiting specific shortcomings in TRR’s sampling intervals and synchronizing access over precise refresh cycles, the Phoenix attack can reliably induce bit flips in physical memory. In controlled tests, the attack enabled researchers to gain root-level privileges on commodity systems in under two minutes, expose sensitive cryptographic keys across virtual machines, and manipulate binaries such as sudo for rapid local privilege escalation. The vulnerability, now tracked as CVE-2025-6202, impacts DDR5 modules manufactured between January 2021 and December 2024, posing industry-wide risk since current mitigations are ineffective for existing hardware. This incident stands out as it revives concerns over hardware-level attacks that are resistant to conventional software security solutions. As threats like Phoenix emerge, it highlights the rapid evolution of side-channel and privilege-escalation techniques even in the face of new hardware protections, underlining the pressing need for industry collaboration and innovation on memory security standards.
9 months ago
Kill Chain
Malicious MCP Servers: How AI Supply Chain Integrations Were Weaponized in 2024
In early 2024, security researchers uncovered a novel supply chain attack exploiting the Model Context Protocol (MCP), an emerging integration layer for AI assistants. Attackers published seemingly legitimate MCP servers on public repositories such as PyPI, which, once installed by developers, silently harvested sensitive credentials, SSH keys, cloud configs, and API secrets. Data exfiltration was cleverly disguised as benign HTTP requests to plausible endpoints, while the malicious packages mimicked real productivity tools, evading both user scrutiny and common detection mechanisms. This attack leveraged implicit trust in third-party AI extensions, exposing a major blind spot for organizations integrating AI into development workflows. This breach reflects a growing trend where adversaries weaponize trusted AI integration points, mirroring techniques seen in Open Source and DevOps supply chain compromises. As enterprise AI adoption accelerates, similar threats targeting protocol-level integration, plugin ecosystems, and shadow AI deployments are expected to rise, intensifying regulatory and governance pressures around software supply chain security.
9 months ago
Kill Chain
Salesloft GitHub Compromise: How a 2025 Supply-Chain Attack Rippled Across 22 Companies
In mid-2025, Salesloft disclosed a significant data breach stemming from a compromise of its GitHub account linked to its Drift application. The incident was investigated by Mandiant, which attributed the activity to the threat actor group UNC6395. Attackers maintained unauthorized access from March through June 2025, enabling them to pivot laterally and potentially compromise sensitive code, data, and operational assets. The breach's supply-chain nature led to downstream impacts, reportedly affecting at least 22 distinct organizations that relied on the compromised software or APIs. This breach highlights the persistent risk posed by supply-chain compromises and stolen developer credentials within cloud ecosystems. With threat actors increasingly targeting development tools and identity-driven pipelines, organizations face mounting regulatory and operational urgency to remediate authentication weaknesses and enforce segmenting policies across their CI/CD toolchains.
9 months ago
Kill Chain
Bridgestone Americas 2024 Cyberattack Disrupts North American Manufacturing
In early 2024, Bridgestone Americas, a leading tire manufacturer, experienced a cyberattack that impacted several of its North American manufacturing plants. The incident led to operational disruptions, with reports confirming at least one plant in Quebec suspending activity. Bridgestone acted promptly, implementing its established cyber incident response protocols and containing the breach while launching a forensic investigation to determine the incident's scope. According to statements from company officials and local authorities, no employee or customer data was reported compromised, and business operations have largely returned to normal as of the latest updates. This attack highlights how IT/OT convergence in manufacturing continues to expose critical infrastructure to cyber threats, even in the absence of clear threat actor attribution or significant data loss. The event underscores the rising necessity for robust east-west security controls and rapid response capabilities within industrial environments facing increasing cyber risk.
9 months ago
Kill Chain
How Stark Industries Evaded EU Sanctions: The Persistence of Bulletproof Hosts in 2025
In May 2025, Stark Industries Solutions Ltd.—a notorious bulletproof hosting provider closely linked to Russian cyberattacks and disinformation—was placed under EU financial sanctions, alongside its Moldova-based conduits and owners. Despite these efforts, Stark rapidly rebranded as the[.]hosting, shifted its assets to new legal entities (including Dutch-based WorkTitans BV and Moldova's PQ Hosting Plus S.R.L.), and maintained operational infrastructure with covert support from providers like MIRhosting. Investigations revealed continued operations and asset management by the original threat actors, rendering the sanctions ineffective and allowing persistent delivery of DDoS campaigns, Russian-language proxy services, and malware with minimal disruption. This incident highlights the sophisticated resilience and adaptability of bulletproof hosting operations, as well as the challenges for regulators attempting to curtail nation-state-aligned cyber infrastructure. Similar evasion techniques—including cross-border asset transfers and complex corporate rebranding—are on the rise, escalating pressure on global cybersecurity, law enforcement, and compliance efforts.
9 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

