Keysight ATI Content 2025 Recap

The Application Threat Intelligence team creates realistic, modern representation of network traffic. It’s a flexible distillation of the internet that can be wielded in many forms: consumer apps, enterprise platforms, industrial protocols, and AI systems.

2025 broadened and deepened the attack and applications both on the internet and ATI library.

Numbers: Anatomy of the landscape

Chart 1: ATI Strikes broken into categories.

Chart 2: Applications release by type.

Chart 3: Malware by release type, family and total samples.

Highlights: Prominent entries that deserve attention

Applications

Github MCP

This demonstrates communication between a GitHub MCP client and a GitHub MCP server. The GitHub MCP implementation models a privileged control plane where JSONRPC–style messages initialize sessions, enumerate tools, and configure logging, establishing the trust boundary between LLMs and backend systems.

Parallel Virtual File System V2

SCADA protocol that enables parallel access to distributed file systems, improving I/O performance in high-performance computing environments.

Grok

Grok pushed deeper into interactive AI workflows: conversational queries, file-based reasoning.

ElevenLabs

Voice AI is mainstream. This entry is a high-quality text-to-speech and Speech-to-text pipeline application that is both highly used in the industry and intriguing.

Strikes

Apache Tomcat TOCTOU RCE (CVE-2024-50379)

Critical RCE in widely deployed infrastructure that exploited a timing gap (time-of-check vs time-of-use). This shows that classic bugs still causing modern damage.

Multiple CVSS 10.0 issues across vendors with easy exploitation paths. It’s a massive attack surface due to device proliferation across consumer and enterprise spaces.

“React2Shell” React Server Components RCE (CVE-2025-55182)

Next.js HTTP request using unsafe deserialization.

Blogs

Write-ups by the ATI R&D team detailing their findings of research, development and effective methods of execution.

The Big Picture

ATI attempts to simulate the most meaningful and impactful portions of the network traffic as a whole, a special emphasis is put on the new and re-emerging trends. This is both where a lot of feedback from customers and quantitate analysis showed dominated this year:

AI Everywhere

AI apps dominated new content—and introduced entirely new security challenges.

Edge is the New Battleground

From Ivanti to routers, internet-facing devices remain high-risk.

Realism Matters

From HAR replays to full attack chains, simulations are getting closer to real-world behavior.

ATI in BreakingPoint

Keysight's Application and Threat Intelligence subscription provides daily malware and bi-weekly updates of the latest application protocols and vulnerabilities for use with Keysight test platforms. The ATI Research Centre continuously monitors threats as they appear in the wild. Customers of BreakingPointnow have access to attack campaigns for different advanced persistent threats, allowing them to test their currently deployed security control's ability to detect or block such attacks

limit
3