✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Amazon AWS 2025: Credential-Based Cryptomining Breach Hits the Cloud
In late 2025, Amazon's AWS GuardDuty team uncovered a significant cryptomining campaign that exploited compromised IAM credentials to gain access to AWS Elastic Compute Cloud (EC2) and Elastic Container Service (ECS) environments. The attackers used valid credentials, rather than technical vulnerabilities, to deploy a malicious Docker Hub image carrying an SBRMiner-MULTI cryptominer. By rapidly launching large-scale EC2 and ECS tasks with high compute and memory allocations, the threat actor inflicted resource exhaustion and financial losses upon AWS customers. Attackers also enabled termination protection on compromised instances, effectively delaying incident response and extending mining profits. This incident is emblematic of the growing sophistication and automation in cloud resource abuse, highlighting an uptick in attacks leveraging stolen credentials rather than software flaws. As cloud adoption surges and cryptomining threats evolve, organizations face urgent pressure to enhance IAM hygiene, monitoring, and automated remediation to reduce risk.
6 months ago
Kill Chain
China-Linked Ink Dragon Breaches Governments With ShadowPad and FINALDRAFT Malware
Between July and October 2025, a sophisticated cyber-espionage campaign orchestrated by the China-linked group 'Ink Dragon' (a.k.a. Jewelbug, CL-STA-0049, Earth Alux, REF7707) targeted multiple European, Southeast Asian, and South American governments. The attackers leveraged advanced tools such as ShadowPad and FINALDRAFT malware to infiltrate official networks, move laterally through compromised systems, and exfiltrate sensitive government data via encrypted channels. Their operations exhibited a high degree of stealth, blending custom malware with legitimate administrative tools and exploiting trust in east-west network flows, putting confidential geopolitical and citizen information at direct risk. This incident underscores the increasing frequency and sophistication of state-sponsored espionage operations against government entities worldwide. It marks a significant trend where threat actors are adopting modular malware and advanced lateral movement techniques, emphasizing the urgent need for stronger east-west security controls and real-time anomaly detection in critical infrastructure.
6 months ago
Kill Chain
Zeroday Cloud 2025: $320,000 Awarded for Critical Cloud Platform Zero-Days
In December 2025, the inaugural Zeroday Cloud hacking competition in London highlighted severe risks facing cloud infrastructure by awarding $320,000 for the demonstration of 11 zero-day vulnerabilities across components like Redis, PostgreSQL, Grafana, and the Linux kernel. Notably, researchers exploited a container escape flaw in the Linux kernel, threatening tenant isolation—a cornerstone of cloud security. The impacted databases are integral to storing sensitive information, including credentials and user data. Although the event was hosted in a controlled environment, it provided a real-world showcase of how adversaries can achieve lateral movement and severe impact using previously unknown vulnerabilities. As critical cloud services grow more ubiquitous and attackers continue to innovate, this incident underscores the urgency for organizations to address emerging threats through proactive vulnerability management, layered defense, and rapid response capabilities.
6 months ago
Kill Chain
SonicWall SMA 100 Breach 2025: CVE-2025-40602 Actively Exploited
In December 2025, SonicWall disclosed a security breach affecting its Secure Mobile Access (SMA) 100 series appliances, driven by exploitation of CVE-2025-40602—a local privilege escalation vulnerability. The issue arose due to insufficient authorization in the Appliance Management Console (AMC), enabling threat actors to elevate local privileges and gain greater control within affected systems. SonicWall confirmed active exploitation in the wild, prompting an urgent release of security patches while urging all customers to apply updates immediately. The incident underscores the risks facing network appliances and the rapid speed with which attackers can leverage new vulnerabilities to compromise enterprise infrastructure. This event occurs amidst a wider uptick in attacks targeting edge appliances from network security vendors, as adversaries increasingly exploit publicly disclosed software flaws soon after their publication. Organizations are under intensified regulatory and operational pressure to patch critical vulnerabilities rapidly and reinforce privilege management strategies.
6 months ago
Kill Chain
CISA Flags 3 New Actively Exploited Vulnerabilities: Cisco, SonicWall, ASUS
In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added three newly discovered vulnerabilities (CVE-2025-20393, CVE-2025-40602, and CVE-2025-59374) to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence. These flaws impact multiple Cisco products, SonicWall SMA1000, and ASUS Live Update, allowing attackers to gain unauthorized access, insert malicious code, or bypass input validations. Such exposures provide fertile ground for cybercriminals to enter networks, move laterally, and compromise data, posing significant operational and business continuity risks to affected organizations across sectors. Their rapid inclusion into the KEV Catalog reflects a surge in the exploitation of software supply chains and critical infrastructure technologies. With attackers leveraging faster exploit-to-impact timelines, government agencies and enterprises face mounting pressure to patch immediately and update their vulnerability and segmentation strategies to prevent cascading breaches.
6 months ago
Kill Chain
A $0 Transaction Triggers a Nation-State Cyberattack on Anthropic’s AI Platform
In early 2024, Anthropic, a leading artificial intelligence company, was targeted in a sophisticated nation-state cyber espionage campaign. Adversaries utilized compromised payment cards—previously validated through Chinese-operated card-testing services—to attempt unauthorized access to Anthropic's AI platform. The attackers leveraged an established cybercriminal kill chain: stealing card data, validating credentials through tester merchants, and ultimately using the compromised accounts to escalate their intrusion attempts. While no sensitive customer data was confirmed to be compromised, the incident underscored the vulnerability of downstream cloud-based AI assets to upstream financial fraud and highlighted the intersection of cybercrime with state-sponsored intelligence objectives. This attack serves as a high-profile example of how advanced fraud intelligence can act as an early detection mechanism for state-sponsored cyber operations. The incident exemplifies rapid convergence between financial fraud and targeted espionage, emphasizing the need for cross-domain threat visibility and proactive controls.
6 months ago
Kill Chain
AWS IAM Credential Theft Drives Massive Cloud Cryptomining in 2024
In early 2024, threat actors exploited stolen Amazon Web Services (AWS) Identity and Access Management (IAM) credentials to launch an extensive cryptomining campaign. Attackers gained unauthorized access to multiple customer environments, leveraging compromised IAM keys to provision and operate Amazon EC2 instances at scale. This unauthorized infrastructure was then used to mine cryptocurrency, resulting in significant financial losses, increased resource utilization, and additional operational overhead for affected organizations. The incident exposed critical gaps in cloud credential management and highlighted the attackers’ agility in abusing cloud-native services for illicit profit. This attack underscores a growing trend where cybercriminals are rapidly pivoting to cloud environments, exploiting mismanaged or stolen credentials. As more businesses migrate workloads to multi-cloud platforms, identity-driven threats and cryptojacking incidents are rising, urging organizations to reexamine their cloud security postures and access controls.
6 months ago
Kill Chain
ESET H2 2025 Report: Multi-Vector Cyberattacks Disrupt Enterprise Defenses
In the second half of 2025, ESET’s telemetry detected a significant uptick in multi-vector cyberattacks targeting enterprises across cloud, hybrid, and on-premises environments. Adversaries leveraged sophisticated tactics such as encrypted traffic evasion, lateral movement through east-west traffic, and exploitation of cloud misconfigurations to bypass traditional security controls and exfiltrate sensitive data. These campaigns combined advanced persistent threat (APT) techniques, ransomware deployment, and the abuse of shadow AI tools, often resulting in business disruption, regulatory exposure, and reputational harm for affected organizations. This incident reflects an intensifying trend: cyber actors are increasingly combining multiple techniques to evade detection, overwhelm defenses, and exploit both legacy and cloud-native infrastructure. With regulatory scrutiny mounting and a surge in identity-driven and AI-enabled threats, proactive segmentation and real-time threat detection are now vital for enterprise resilience.
6 months ago
Kill Chain
How RansomHouse's 2025 Encryption Upgrade Disrupted Critical Sectors
In December 2025, the RansomHouse ransomware-as-a-service (RaaS) group, operated by the Jolly Scorpius threat actor, was observed deploying a significantly upgraded encryption process against high-value victims. Attackers exploited compromised credentials and ESXi server vulnerabilities to infiltrate enterprise environments, moving laterally and using tools like MrAgent to disable firewalls and maintain persistent access. Once established, they deployed the enhanced Mario encryptor, which used multi-layered, two-stage file encryption and selective chunk processing to maximize data disruption. This double extortion campaign resulted in data theft, operational outages, and public leaks for at least 123 organizations across healthcare, finance, government, and transportation sectors. This incident highlights both the increasing technical sophistication of ransomware operations and the rapid evolution of RaaS offerings. The shift to more complex encryption makes detection, containment, and recovery far more challenging, calling for organizations to adopt dynamic, layered security controls and anticipate future trends in ransomware capabilities.
6 months ago
Kill Chain
Illusory Systems 2022 Crypto Breach: Smart Contract Flaw Leads to FTC Settlement
In July 2022, Illusory Systems (also known as Nomad) suffered a major security breach when attackers exploited an application security flaw in its Token Bridge smart contract platform. After pushing inadequately tested and poorly secured code to production, the company left the cross-chain bridge exposed to a vulnerability that was quickly leveraged by hackers to drain approximately $186 million in user-held cryptocurrencies. The breach went undetected internally, with staff first learning about it from a user on social media; response delays and lack of effective controls allowed attackers to empty the bridge. Regulatory investigation found misaligned security claims, absence of key safeguards, lack of automated fraud monitoring, and ineffective incident response processes, leading to severe financial and reputational damages for Illusory Systems. This incident echoes the rising threat landscape targeting blockchain infrastructure, with smart contract vulnerabilities increasingly exploited for high-value thefts. The FTC’s enforcement action against Illusory Systems highlights growing regulatory scrutiny and the urgent need for strong application security practices in the crypto-asset sector.
6 months ago
Kill Chain
How Attackers Exploit Windows Race Conditions with Path Lookups
In December 2025, security researchers identified a critical exploitation technique leveraging race conditions within the Windows Object Manager namespace. Attackers can use specially crafted path lookups, combining recursive directories, symbolic links, shadow directories, and hash collisions, to artificially inflate kernel resource lookup times—sometimes up to several minutes. By exploiting this behavior, an attacker could significantly increase the window to win race conditions, potentially bypassing security checks and securing unauthorized access or escalating privileges. The impact of this exploit affects modern Windows 11 systems and is especially relevant for environments relying heavily on object access protections. This exploitation method highlights an enduring structural weakness that remains open even in recent Windows releases. With a broader trend toward complex system attacks and system resource manipulation, awareness and mitigations for race-based vulnerabilities have become a growing priority for enterprises and regulators.
6 months ago
Kill Chain
VirtualBox Slirp Flaw Enables 2025 Virtualization Escape — What Enterprises Must Know
In late 2025, a critical vulnerability was disclosed in Oracle VirtualBox related to its use of a modified Slirp networking stack for NAT mode. Security researchers demonstrated a reliable virtualization escape technique by exploiting unsafe memory handling in the packet heap allocator. By manipulating packet headers from within a VM, attackers could achieve arbitrary code execution on the host, effectively breaching isolation and enabling full control over the underlying system. No authentication was required; only network access from the guest to the host's NAT interface. The incident prompted urgent patching and highlighted the continued risk of legacy code in hypervisor environments. This incident remains highly relevant as virtualization escape attacks are escalating, with attackers targeting cloud and data center hypervisor layers. Trends in lateral movement, advanced VM attacks, and increasing regulatory focus on workload security are intensifying the urgency for robust virtual infrastructure defenses.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports