The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Aviatrix Threat Research Center
Cloud breaches are accelerating — across identities, workloads, supply chains, and cloud-native services. In the Containment Era, understanding how a breach unfolds is how you architect to stop it.
The Aviatrix Threat Research Center provides security teams with:
- A structured understanding of how breaches unfold — kill chain, ATT&CK techniques, CVEs, and IOCs in a consistent format.
- What attackers exploited, and which enforcement gaps let them move.
- Where workload-level controls would have broken the attack chain — including paths that posture tools and endpoint detection don't model.

Recent Breaches, Security Incidents & Vulnerabilities
AI-Powered Threat Analysis
Agentic AI that analyzes real-world attacks — across security incidents, breaches, and exploited vulnerabilities — to produce structured, actionable intelligence.
Displaying 6337 to 6348 of 6396
Meta's WhatsApp Security Lapses: Insider Risks and Lessons for Compliance in 2025
In April 2025, Meta (parent company of WhatsApp) faced legal action from a former security manager, Attaullah Baig, who alleged that systemic cybersecurity and privacy failures were ignored within WhatsApp. Baig claimed that a Red Team exercise revealed approximately 1,500 engineers had unrestricted access to sensitive user data, with no audit trails, logging, or adequate operational controls, violating regulatory requirements and a 2020 FTC consent order. Baig raised alarms about deficiencies—such as lack of data inventory, improper data access controls, and insufficient security staffing—which he asserts led to retaliatory actions and his eventual dismissal under the pretense of poor performance. This high-profile lawsuit underscores urgent concerns about insider risk, weak internal security policy enforcement, and regulatory noncompliance in large tech platforms. As regulators increase scrutiny and whistleblowers continue to come forward, enterprises must address internal blind spots and strengthen controls to prevent privilege misuse and data exposure.
9 months ago
Kill Chain
Microsoft 2025 Zero-Day Patch Tuesday: SMB & SQL Server Vulnerabilities Fixed
In September 2025, Microsoft addressed 81 security flaws in its monthly Patch Tuesday, including two significant zero-day vulnerabilities—one impacting the Windows SMB Server (CVE-2025-55234) and another affecting Microsoft SQL Server through the Newtonsoft.Json library (CVE-2024-21907). The SMB Server flaw enabled attackers to perform relay attacks that could escalate user privileges, while the SQL Server vulnerability allowed unauthenticated remote attackers to trigger denial of service conditions. These flaws were publicly disclosed prior to the release and posed a heightened risk, as threat actors could exploit them before organizations applied the necessary patches. The broad spectrum of vulnerabilities underscores potential exposure across a wide range of Microsoft products and services. This incident exemplifies the urgent need for organizations to keep patch management processes rigorous and up-to-date. The increasing sophistication of attacker TTPs and the frequency of zero-day exploitation have positioned timely security updates as a frontline defense against data compromise and operational disruption.
9 months ago
Kill Chain
Hackers Deploy Advanced Botnet Over Exposed Docker APIs via Tor (2025)
In September 2025, a sophisticated threat campaign was uncovered targeting exposed Docker APIs, where attackers leveraged the Tor network to obfuscate their activities and deploy a new, evolving botnet. The attackers used automated scanning to discover open Docker API endpoints (commonly on port 2375), then executed a multi-stage infection chain utilizing malicious containers. These payloads established persistent SSH access, blocked further exploitation by others, and launched additional tools for internal scanning, lateral movement, and covert communication. While earlier versions dropped cryptominers, the updated tooling focused on botnet expansion, user monitoring, and groundwork for additional attacks such as credential theft or DDoS. This incident exemplifies the rapid shift toward automation and stealth in cloud-native threats. Its relevance is underscored by the proliferation of misconfigured APIs and cloud workloads, combined with attackers’ increasing use of anonymizing networks (like Tor) and multi-vector attacks. Organizations with exposed or poorly secured container environments are urgently at risk.
9 months ago
Kill Chain
Ransomware's New Playbook: 2024 Sophisticated Extortion Hits Major Enterprises
In early 2024, a prominent enterprise fell victim to a highly sophisticated ransomware attack orchestrated by the notorious LockBit gang. Attackers gained entry through compromised credentials, swiftly encrypting critical systems and demanding a $30 million ransom within 72 hours, threatening public data exposure. The perpetrators leveraged professional, SaaS-style operations, exploiting sensitive internal documentation—such as financials and cyber insurance details—to tailor their extortion tactics. Business operations were severely disrupted as the company rushed to contain the breach, initiate crisis response procedures, and engage third-party negotiators. This incident underscores the growing maturity of ransomware groups, who now use advanced negotiation and psychological tactics alongside technical exploits. The increased reliance on credential theft and swift lateral movement, combined with extortion strategies targeting both IT infrastructure and organizational psychology, reflects a broader trend impacting all sectors.
9 months ago
Kill Chain
Salesloft's GitHub Compromise Sparks 2024 Supply Chain Breach
In early 2024, Salesloft experienced a significant cybersecurity breach after attackers compromised a developer's GitHub account. By exploiting weak authentication protocols, threat actors were able to steal OAuth tokens, which enabled them to access and manipulate connected Salesforce instances of downstream customers, resulting in a widespread supply chain attack. The attackers leveraged their foothold to propagate malicious code and gain privileged access to hundreds of enterprise environments, exposing sensitive data and business operations across multiple organizations. This incident highlights the escalating risk presented by software supply chain attacks, particularly those exploiting code repositories and third-party integrations. It underscores the urgent need for organizations to implement strong access controls, enforce zero trust principles, and continuously monitor code and account activity in their development workflows.
9 months ago
Kill Chain
Jaguar Land Rover Ransomware Breach Disrupts Global Operations in 2024
In June 2024, Jaguar Land Rover (JLR), the renowned luxury automotive manufacturer, experienced a major ransomware-related cyber incident that forced the company to shut down vital portions of its IT infrastructure. The disruption, which began on a Sunday and quickly affected production and retail activities globally, resulted in assembly line stoppages at key UK plants including Halewood and Solihull. JLR responded by disabling systems to prevent further attacker movement and data loss, launching an internal investigation with forensics partners to determine entry vectors, potential data exposure, and persistent threats. While the company stated there was no evidence of customer data being compromised, the operational and financial impacts were significant. This incident underscores the ongoing trend of ransomware actors targeting critical manufacturing and supply chain operations, where downtime can rapidly translate into massive losses. The event serves as a stark reminder that even mature organizations face evolving threats that can bypass traditional security controls, highlighting the urgent need for zero trust segmentation, enhanced network monitoring, and rapid anomaly detection.
9 months ago
Kill Chain
45 New Domains Fuel Salt Typhoon's Stealthy APT Campaign (2024)
In mid-2024, security researchers uncovered that the China-based Advanced Persistent Threat group Salt Typhoon (UNC4841) had deployed 45 new domains and previously undiscovered infrastructure to facilitate persistent, stealthy compromises of targeted organizations. Exploiting their advanced tradecraft, Salt Typhoon gained and maintained long-term access undetected, leveraging encrypted traffic and lateral movement techniques. The attacks primarily targeted sectors with sensitive data and critical infrastructure, amplifying operational and reputational risk for the victims. The campaign demonstrates ongoing actor adaptation and the challenges of detecting covert infrastructure expansion. This incident is especially relevant as organizations face a surge in nation-state actor activity leveraging novel infrastructure and sophisticated evasion methods. The discovery highlights the evolving threat landscape, where increased regulatory pressure and cloud adoption make comprehensive visibility and proactive response capabilities more critical than ever.
9 months ago
Kill Chain
2025 NPM Supply Chain Breach: Phishing Attack on JavaScript Developer Risks Crypto Theft
In September 2025, a targeted supply chain attack compromised at least 18 widely used JavaScript packages on the NPM repository after a key developer, Josh Junon, was phished. The attackers created a convincing fake NPM login website, stealing both credentials and a one-time 2FA token to access the developer's account. They injected malicious code into popular packages, enabling browser-based interception of cryptocurrency transactions and redirection of funds to attacker-controlled wallets. The breach was discovered rapidly by Aikido, which alerted the maintainer, enabling a swift cleanup and limiting broader damage. This incident underscores the persistent risks lurking in open-source software supply chains, particularly as threat actors evolve their tactics to bypass conventional security controls using phishing and social engineering. The rapid containment averted a potentially devastating impact, but the episode highlights ongoing vulnerabilities in software ecosystems reliant on centralized package maintainers.
9 months ago
Kill Chain
Iran MOIS Targets Diplomatic Missions Worldwide in Sophisticated Phishing Campaign (2024)
Between August and September 2024, the Iranian state-affiliated APT group 'Homeland Justice,' linked to Iran’s Ministry of Intelligence (MOIS), orchestrated a sophisticated phishing campaign targeting over 50 embassies, government ministries, and international organizations across six continents. Attackers leveraged more than 100 hijacked, legitimate email accounts, using them to distribute infostealing malware concealed in macro-laden Word documents, often themed around timely geopolitical topics. These emails were sent via VPNs to obfuscate their true origin and bypassed basic email filtering due to the use of authentic sender addresses. This incident highlights the sustained threat posed by nation-state actors employing classic social engineering methods with modern evasion techniques. The resurgence of macro-enabled attacks and increasing abuse of compromised trusted accounts point to evolving risk vectors for governmental and international bodies, underscoring the need for continuous vigilance and upgraded detection capabilities.
9 months ago
Kill Chain
MostereRAT Malware: New Era of EDR Bypass and Persistent Threats
In 2024, security researchers uncovered a sophisticated campaign deploying the 'MostereRAT' malware against Windows environments. The threat actor used advanced techniques to deliver an EDR (Endpoint Detection and Response)-killing tool, enabling long-term, covert persistence on infected systems. MostereRAT blends into legitimate network traffic, leverages encrypted channels, and systematically disables or bypasses security controls, making detection and remediation difficult. Impacted organizations faced risks of data exfiltration, lateral movement, and significant business disruption, with attackers maintaining access for extended periods before discovery. This incident highlights the increasing prevalence of anti-EDR malware designed to counter modern defensive capabilities. As organizations adopt stronger endpoint security, attackers are deploying stealthier, more evasive malware, presenting ongoing challenges for incident detection, compliance, and cyber resilience.
9 months ago
Kill Chain
Logit-Gap Steering: New Jailbreak Threat Undermines LLM Security in 2024
In mid-2024, academic security researchers unveiled a novel attack against large language models (LLMs) termed "logit-gap steering." This technique exploits the mathematical limits of alignment training by manipulating the logits—the raw output probabilities—of refusal and affirmation tokens. Attackers found that by identifying and minimizing the gap through tailored prompt suffixes, they could frequently bypass internal model guardrails and elicit harmful or disallowed responses, even on the latest open-source models such as gpt-oss-20b, LLama, Gemma, and Qwen. The published methodology demonstrated over 75% attack success rates and triggered industry-wide concern about the resilience of current AI safety controls. This incident comes at a pivotal time as organizations accelerate adoption of AI and generative language models in production. The research spotlights a significant, previously underestimated vector for LLM jailbreak attacks, amplifying regulatory scrutiny and forcing enterprises to re-evaluate security practices for AI deployments.
9 months ago
Kill Chain
2025 Retail Salesforce Data Heist: Extortion Attack Exposes Cloud Security Gaps
In mid-2025, a sophisticated data extortion campaign targeted high-end retail organizations leveraging Salesforce environments. Threat actors—identified as UNC6040 (responsible for access and reconnaissance) and Bling Libra (aka ShinyHunters, handling extortion)—gained initial access through voice-based phishing (vishing) techniques. After establishing a foothold, they conducted in-depth reconnaissance to collect sensitive customer data, including names, birthdates, contact details, and account metadata, which was then exfiltrated. The attackers threatened public disclosure unless the victim organizations paid a ransom, all while leaving minimal forensic traces due to a lack of malware deployment and custom tools. This incident highlights the increasing sophistication of financially motivated cybercrime operations and an industry-wide shift towards data theft extortion without ransomware. There is an urgent need for retail and cloud-reliant enterprises to reassess their security controls, as social engineering vectors bypass traditional perimeter defenses and regulatory scrutiny around cloud data protections intensifies.
9 months ago
Kill Chain
Security Research & Insights
Security Research & Insights with human-led deep dives into campaigns and cloud-native TTPs

The Edge Device Isn't Your Last Line of Defense. It's Their First Target.

AI Trust Abuse: A Detection Engineer's Field Guide to Agent-Abuse Attacks
Aug 18, 2026

OpenAI Lost Control of Its Models. Then Anthropic Did Too. That Is Not a Coincidence.
Market Perspectives
Market Perspectives offering expert commentary and select breach analysis from industry leaders
What Could Have Stopped the 2023 MGM Breach? A Study in the Power of Embedded Zero Trust

The Zero Trust Gap: Only 8% of US Enterprises Use Zero Trust Architectures

HITRUST CSF Compliance in the Cloud—How Aviatrix Secures Healthcare Data
How CNSF Protects Cloud Workloads
Cloud attackers don’t rely on a single exploit — they rely on paths.
Once inside, attackers move laterally between workloads, establish command-and-control through egress paths, and exfiltrate data through legitimate cloud services — often before detection tools generate an alert. These paths exist because most security architectures enforce at centralized inspection points, not at every workload. The paths that matter most are the ones that never reach a central firewall.
Aviatrix Cloud Native Security Fabric (CNSF) contains attacks by enforcing policy at every workload communication path — containing blast radius, blocking lateral movement, and cutting off egress before data leaves the environment.

With CNSF, enterprises can:
- Contain attack paths at runtime
Gain visibility into east-west and egress workload communication and apply controls that limit lateral movement, unauthorized egress, and uncontrolled trust expansion.
- Eliminate blind spots in workload-to-workload traffic
Observe traffic across VPCs/VNets, regions, and cloud providers using cloud native telemetry — including paths that posture tools and point controls don’t model.
- Secure modern and AI-driven workloads
Understand how agents, services, and workloads communicate at runtime, and enforce policy to reduce the risk of misuse, over-privileged access, or unintended data flows.
- Apply consistent Zero Trust controls without slowing teams
Enforce segmentation, egress control, and encryption centrally across clouds — without agents, application changes, or developer friction.
See Your Attack Paths. Close the Gaps with CNSF.
Blast radius starts where your enforcement stops.
Most security architectures enforce at centralized inspection points. Attackers move between workloads on paths that never reach those points — building blast radius invisibly until detection tools fire, often too late.

Your assessment delivers:
The Aviatrix Workload Attack Path Assessment (WAPA) analyzes real workload communication using cloud native telemetry to uncover attack paths already present in your environment — and shows how Cloud Native Security Fabric (CNSF) can break those paths with runtime enforcement.
The threat landscape has changed.
Has your question changed with it?
In March 2026, TeamPCP proved that detection-first architectures cannot contain attacks that move through trusted code, not around defenses. Today’s threat actors don’t break in — they log in, blend in, and expand silently. This command center tracks the evolving threat landscape and helps you measure your Blast Radius — the architectural metric that defines resilience in the Containment Era.
This command center tracks 8 active campaigns and measures your Blast Radius: what an attacker can reach once inside your environment.
Contain the Blast Radius
See the attack paths already present in your environment — and where CNSF containment controls would break them.

