Keysight ATI Content 2025 Recap
The Application Threat Intelligence team creates realistic, modern representation of network traffic. It’s a flexible distillation of the internet that can be wielded in many forms: consumer apps, enterprise platforms, industrial protocols, and AI systems.
2025 broadened and deepened the attack and applications both on the internet and ATI library.
Numbers: Anatomy of the landscape
Chart 1: ATI Strikes broken into categories.
Chart 2: Applications release by type.
Highlights: Prominent entries that deserve attention
Applications
Github MCP
This demonstrates communication between a GitHub MCP client and a GitHub MCP server. The GitHub MCP implementation models a privileged control plane where JSONRPC–style messages initialize sessions, enumerate tools, and configure logging, establishing the trust boundary between LLMs and backend systems.
Parallel Virtual File System V2
SCADA protocol that enables parallel access to distributed file systems, improving I/O performance in high-performance computing environments.
Grok
Grok pushed deeper into interactive AI workflows: conversational queries, file-based reasoning.
ElevenLabs
Voice AI is mainstream. This entry is a high-quality text-to-speech and Speech-to-text pipeline application that is both highly used in the industry and intriguing.
Strikes
Apache Tomcat TOCTOU RCE (CVE-2024-50379)
Critical RCE in widely deployed infrastructure that exploited a timing gap (time-of-check vs time-of-use). This shows that classic bugs still causing modern damage.
Router & IoT RCE Wave (D-Link, Netgear, TP-Link)
Multiple CVSS 10.0 issues across vendors with easy exploitation paths. It’s a massive attack surface due to device proliferation across consumer and enterprise spaces.
“React2Shell” React Server Components RCE (CVE-2025-55182)
Next.js HTTP request using unsafe deserialization.
Blogs
Write-ups by the ATI R&D team detailing their findings of research, development and effective methods of execution.
- Dissecting the Network Traffic of Grok: AI with Real-Time Intelligence
- The Sugar-Coated Poison Prompt Injection Attack
- CVE-2025-24813: Apache Tomcat Path Equivalence Vulnerability
- Introducing New LLM PII Disclosure Strikes in BreakingPoint
The Big Picture
ATI attempts to simulate the most meaningful and impactful portions of the network traffic as a whole, a special emphasis is put on the new and re-emerging trends. This is both where a lot of feedback from customers and quantitate analysis showed dominated this year:
AI Everywhere
AI apps dominated new content—and introduced entirely new security challenges.
Edge is the New Battleground
From Ivanti to routers, internet-facing devices remain high-risk.
Realism Matters
From HAR replays to full attack chains, simulations are getting closer to real-world behavior.
ATI in BreakingPoint
Keysight's Application and Threat Intelligence subscription provides daily malware and bi-weekly updates of the latest application protocols and vulnerabilities for use with Keysight test platforms. The ATI Research Centre continuously monitors threats as they appear in the wild. Customers of BreakingPointnow have access to attack campaigns for different advanced persistent threats, allowing them to test their currently deployed security control's ability to detect or block such attacks