✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
React2Shell 2025: When AI-Generated Exploits Complicate Supply Chain Defense
In December 2025, the cybersecurity community was rocked by mass exploitation efforts targeting "React2Shell," a critical vulnerability in the popular React UI framework. Threat actors, including China-linked groups, quickly launched attacks just hours after the initial public advisory. Amid the chaos, researchers and automated AI tools published over a hundred proof-of-concept (PoC) exploits—many of which were either nonfunctional or misrepresented the true risk, leading to widespread confusion. This "AI slop" polluted vulnerability feeds and caused defenders to waste valuable time, potentially resulting in underestimating the urgency to patch real flaws. The incident exposed significant weaknesses in open-source supply chain security, the peer-review process for public PoCs, and how security teams triage emerging threats. The React2Shell event is emblematic of the growing challenges defenders face as AI-generated code and public exploit sharing accelerate the pace and volume of security noise. With enterprises relying on automated detection and research, this incident highlights systemic risks posed by false negatives, delayed remediation, and rushed patch management in the face of incomplete or misleading information.
6 months ago
Kill Chain
Cellik RAT’s Google Play Store Infiltration Exposes Mobile Security Gaps
In June 2024, cybersecurity researchers uncovered that the Cellik Android Remote Access Trojan (RAT) was being distributed through malicious applications on the official Google Play Store. The Cellik RAT allows attackers to remotely control infected Android devices, harvest sensitive credentials, and exfiltrate private data without the user’s knowledge. Threat actors used advanced evasion tactics, including app generation within Play Store guidelines and encrypted communications, to bypass traditional defenses. The incident highlights weaknesses in mobile app review processes and demonstrates the continued use of popular app stores as distribution vectors for sophisticated malware campaigns. This breach is especially notable as attackers continue to exploit trusted platforms like the Google Play Store, elevating risk for both individuals and enterprises. The emergence of Cellik marks an uptick in mobile RAT sophistication and underscores the urgent need for stronger app vetting and threat detection on mainstream digital ecosystems.
6 months ago
Kill Chain
Critical Fortinet Flaws: Active Attacks Compromise Admin Accounts & Configs
In May 2024, threat actors began actively exploiting multiple critical vulnerabilities in Fortinet network devices, specifically targeting admin accounts to gain unauthorized access. Once authenticated, attackers exported sensitive device configurations containing hashed credentials and other proprietary information. The exploit allows lateral movement and increases the risk of sensitive enterprise data exposure, with widespread impacts noted across sectors relying on network infrastructure security. Fortinet urged immediate mitigation after observing attacks in the wild, with rapid patch releases and threat intelligence sharing. This incident highlights a concerning trend of attackers leveraging zero-day or freshly-disclosed vulnerabilities in widely deployed network appliances. As targeting of privileged accounts and network infrastructure rises, organizations must enhance monitoring, patch management, and segmentation strategies to prevent systemic compromise.
6 months ago
Kill Chain
React2Shell: How Diverse Exploit Techniques Targeted React Server Components in 2023
In December 2023, ongoing exploit attempts targeting React Server Components were observed, with attackers leveraging a variant known as 'React2Shell.' The threat actors sent crafted HTTP POST requests containing custom headers and malicious payloads exploiting web application vulnerabilities to execute arbitrary shell commands on compromised systems. Attackers expanded their reach by diversifying target endpoints (e.g., /, /api, /app) as previously vulnerable systems dwindled. The payloads enabled remote code execution, posing a risk of full system compromise and lateral movement across victim networks. The direct business impact includes potential data breach, operational disruptions, compliance failures, and reputational harm for affected organizations. This incident highlights evolving web application exploitation tactics, including the constant adaptation of attackers as defenses improve. The surge in diverse exploit attempts against publicly exposed development components like React reflects broader trends in both sophistication and frequency of web-based threats, stressing the imperative for proactive threat detection and rapid patch management.
6 months ago
Kill Chain
React2Shell Breach: 2025’s Most Widespread Mass Exploitation Campaign
In December 2025, the React2Shell vulnerability (CVE-2025-55182) triggered a global mass exploitation campaign targeting organizations across critical infrastructure, government, and private sectors. Following public disclosure, a record number of exploits surfaced, enabling unauthenticated attackers to gain remote code execution, deploy backdoors, and move laterally within networks. High-profile cybercriminal, ransomware, and nation-state actors—including several Chinese espionage groups—converged to leverage React2Shell for data theft, ransomware deployment, and persistent access. More than 60 organizations confirmed compromise, with hundreds of machines affected, some suffering rapid ransomware execution within minutes of initial access. This incident is notable for both its rapid exploitation timeline and evolving threat actor diversity. The widespread availability of public exploits and patch bypasses underscores the urgent need for robust patch management, active detection, east-west traffic controls, and zero trust segmentation as attackers swiftly weaponize newly disclosed vulnerabilities at unprecedented speed.
6 months ago
Kill Chain
Microsoft 2025 MSMQ and IIS Outage: A Cautionary Tale of Security Permissions Gone Wrong
In December 2025, Microsoft enterprise customers experienced widespread outages in applications and IIS web services following the deployment of Patch Tuesday updates (KB5071546, KB5071544, KB5071543). These updates introduced changes to the Message Queuing (MSMQ) security model, restricting NTFS permissions on the C:\Windows\System32\MSMQ\storage folder. As a result, non-administrator MSMQ users lost write access, causing MSMQ to fail and IIS sites to return misleading 'insufficient resources' errors. This affected core business processes dependent on MSMQ, with no immediate fix available; Microsoft urged affected organizations to reach out for mitigation guidance. This incident highlights ongoing risks from software supply chain updates and privileged permission management changes at the operating system level. As cloud workloads and zero-trust architectures become more prevalent, enterprises must strengthen configuration management and anomaly response to avoid business disruption from untested or misconfigured OS-level security changes.
6 months ago
Kill Chain
DOJ Takes Down E-Note: Ransomware Laundering Hub Disrupted in 2024 Crackdown
In early 2024, the US Department of Justice, in partnership with international law enforcement, dismantled the E-Note cryptocurrency exchange—a major online infrastructure used for laundering illicit proceeds from ransomware and cybercrime. Authorities indicted Mykhalio Petrovich Chudnovets, a Russian national alleged to have operated E-Note since 2010, with facilitating the transfer of over $70 million in stolen or extorted funds from attacks targeting sectors like healthcare and critical infrastructure. Federal and state agencies seized E-Note servers, websites, and mobile apps, obtaining customer and transaction data to further map criminal networks. This takedown highlights cybercriminals’ growing use of specialized laundering platforms to enable ransomware and account takeover monetization at scale. As regulatory scrutiny intensifies and attacker infrastructure becomes more modular and resilient, law enforcement action against these enablers is an increasing priority.
6 months ago
Kill Chain
WhatsApp GhostPairing: How Device Linking Fueled 2024 Account Hijacks
In mid-2024, threat actors launched a sophisticated social engineering campaign dubbed 'GhostPairing' to hijack WhatsApp accounts by abusing the platform's legitimate device-linking feature. Attackers initiated account compromise by tricking victims into sharing pairing codes, which allowed unauthorized access to their WhatsApp accounts on new devices without triggering standard multi-factor authentication. Once inside, attackers could impersonate victims, access chat histories, and leverage compromised accounts for further malicious activity. The attack exploited inherent trust in WhatsApp's device linking and its secure communication channels, highlighting risks even in end-to-end encrypted environments. This incident underscores the growing trend of attackers subverting user authentication processes, exploiting legitimate features for account takeover, and using highly convincing social engineering methods. With messaging apps central to both business and personal communications, the security and user-awareness gaps demonstrated here remain acutely relevant.
6 months ago
Kill Chain
Cisco 2025 AsyncOS Zero-Day: UAT-9686 Exploitation of Email Gateway Appliances
In late November 2025, Cisco discovered a major cybersecurity incident involving active exploitation of an unpatched zero-day vulnerability (CVE-2025-20393) in its AsyncOS operating system, impacting Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances. The flaw, leveraged exclusively on internet-facing appliances with non-standard configurations, enables remote code execution as root when the Spam Quarantine feature is exposed. Attribution points to UAT-9686, a Chinese-nexus advanced persistent threat actor, utilizing malware such as AquaShell, AquaTunnel, Chisel, and AquaPurge for backdoor access, lateral movement, and log deletion. The campaign has resulted in persistent compromise, requiring full appliance rebuilds for remediation. This incident underscores the persisting risk that unpatched zero-days pose to enterprise infrastructure, particularly from advanced threat actors using sophisticated malware implant chains. It illustrates a broader industry trend of increasingly swift exploitation of newly discovered vulnerabilities and public toolkits by nation-state actors.
6 months ago
Kill Chain
GhostPoster Malware Infects 17 Firefox Extensions: Supply Chain Risks Hit 50,000+ Users
In late 2025, cybersecurity researchers discovered a campaign named GhostPoster, which compromised the supply chain of Mozilla Firefox by infiltrating 17 browser add-ons with malicious JavaScript. These extensions, collectively downloaded over 50,000 times, were found to hijack affiliate links, inject tracking scripts, and facilitate click and ad fraud. Threat actors used logo image files within the add-ons to conceal the payload and persist across infected hosts. The extensions were promptly removed from the Mozilla add-ons marketplace upon disclosure, but impacted users may have experienced privacy violations and fraudulent activity. This incident highlights continued escalation in browser extension-based supply chain attacks and the increased sophistication of threat actors at targeting trusted ecosystem channels. With organizations relying on browser tools for productivity, ongoing diligence is required to detect, respond to, and prevent similar infiltrations leveraging obfuscated techniques.
6 months ago
Kill Chain
Critical React2Shell Flaw Triggers Ultra-Fast Weaxor Ransomware Attack (2025)
In December 2025, cybercriminals exploited the critical React2Shell vulnerability (CVE-2025-55182), an unauthenticated remote code execution flaw in React Server Components' Flight protocol, to immediately deploy Weaxor ransomware in targeted organizations. The attackers gained access to public-facing servers running React/Next.js applications, rapidly executed an obfuscated PowerShell script to establish a Cobalt Strike beacon for C2, disabled Windows Defender, and launched the ransomware encryptor within a minute. The incident resulted in data encryption, file extensions changed to '.WEAX', ransom demands, shadow copy deletion, and event log wiping. Impact was limited to the initially compromised server due to the absence of lateral movement or data exfiltration. This incident highlights the increasing speed of cybercriminal exploitation of disclosed critical vulnerabilities, even before widespread patching can occur. The use of automated tooling and rapid weaponization of exploits are fueling a surge in opportunistic ransomware attacks on public-facing infrastructure.
6 months ago
Kill Chain
SonicWall SMA1000 Zero-Day Breach: 2025’s Wake-Up Call for Secure Network Access
In December 2025, SonicWall disclosed active exploitation of two chained zero-day vulnerabilities (CVE-2025-40602 and CVE-2025-23006) in its SMA1000 Appliance Management Console (AMC). Attackers combined a local privilege escalation flaw with a critical pre-authentication deserialization vulnerability to achieve unauthenticated remote code execution with root privileges on exposed appliances. These devices, used by large organizations for secure VPN access, became an attractive target, with at least 950 systems publicly accessible at the time of disclosure. The threats originated from advanced actors leveraging these weaknesses to bypass security controls and gain deep network access. This incident highlights the persistent risk to network infrastructure from zero-day chaining and the ongoing focus of sophisticated attackers on secure remote access gateways. Heightened regulatory focus, increasing state-sponsored attack campaigns, and renewed emphasis on timely patch management are making such incidents highly relevant for CISOs and infrastructure owners today.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports