✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Askul Hit by RansomHouse: 740,000 Customer Records Stolen in 2023 Ransomware Attack
In October 2023, Japanese e-commerce giant Askul Corporation suffered a ransomware attack attributed to the RansomHouse group. Attackers infiltrated Askul's systems, exfiltrating approximately 740,000 customer records containing sensitive personal and contact details before deploying ransomware to encrypt internal data. The breach forced Askul to temporarily suspend some business operations while it investigated the extent of the compromise. The attackers reportedly demanded a ransom in exchange for not releasing the stolen data, putting immense pressure on both customer trust and company reputation. This incident highlights the ongoing threat posed by sophisticated ransomware groups targeting large enterprises, especially in the retail and e-commerce sectors. The scale and impact underscore the necessity for organizations to strengthen data protection, incident response, and segmentation controls, as ransomware actors increasingly focus on data theft before encryption to maximize leverage.
6 months ago
Kill Chain
Critical Apple 0-Days and WinRAR Exploits: How Multi-Vector Threats Changed 2025
In December 2025, a wave of critical zero-day vulnerabilities targeting Apple devices, WinRAR, OAuth implementations, and the .NET framework was actively exploited by various cybercriminal groups. Attackers leveraged these flaws to bypass authentication mechanisms, execute remote code, and escalate privileges across both consumer and enterprise environments. Notably, some exploits were weaponized in the wild before official patches became available, resulting in widespread exposure of unencrypted traffic, unauthorized access to internal networks, and large-scale credential theft. Organizations experienced data breaches, ransomware infections, and regulatory scrutiny, particularly where weak segmentation or inadequate traffic visibility allowed lateral movement. This incident highlights the persistent threat posed by simultaneous multi-vector exploits, especially as attackers rapidly adopt new vulnerabilities in mainstream software. Increased regulatory focus on immediate patching and advanced segmentation underscores the necessity for robust, real-time threat detection and zero trust enforcement across hybrid and multi-cloud ecosystems.
6 months ago
Kill Chain
ShadyPanda’s Browser Extension Supply-Chain Attack Exposes Millions in 2025
In December 2025, security researchers uncovered a widespread supply-chain attack perpetrated by the threat group ShadyPanda, which had silently compromised several popular Chrome and Edge browser extensions. Over the course of seven years, ShadyPanda either published or acquired seemingly innocuous extensions, allowed them to build credibility and large user bases, and then weaponized them through malicious updates. The attackers exploited the implicit trust in browser extension ecosystems to exfiltrate user data and potentially inject hostile code into millions of browsers worldwide, impacting individuals and organizations alike. This incident underscores persistent risks in software supply chains, as threat actors increasingly target trusted application ecosystems to achieve broad access. As browser extensions remain integral to productivity and daily workflows, the event highlights the urgency for organizations to monitor third-party components and reassess extension management, especially amid evolving regulatory scrutiny and attacker sophistication.
6 months ago
Kill Chain
Urban VPN Chrome Extension Found Harvesting AI Chat Prompts from Millions
In late 2025, the "Urban VPN Proxy" Chrome extension—prominently labeled 'Featured' in the Chrome Web Store and boasting over six million users—was discovered silently harvesting all prompts users entered into popular AI chatbots such as ChatGPT, Anthropic Claude, Microsoft Copilot, Google Gemini, and others. Security researchers found the extension covertly intercepted and exfiltrated sensitive data in real time, leveraging its widespread user base and the inherent trust of its browser privileges. The extension’s activity amounted to a massive privacy breach, putting both individuals and enterprises at risk of data exposure. This breach highlights a surge in supply chain and third-party risks posed by browser extensions in the modern SaaS ecosystem. Enterprise security teams face heightened challenges as unregulated extensions become vectors for data harvesting, especially as reliance on AI tools increases. Privacy expectations, compliance obligations, and trust in official app marketplaces are now under renewed scrutiny.
6 months ago
Kill Chain
CISA Adds Apple & Gladinet Vulnerabilities to Known Exploited List (2025)
In December 2025, the Cybersecurity & Infrastructure Security Agency (CISA) added CVE-2025-14611 (Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability) and CVE-2025-43529 (Apple Multiple Products Use-After-Free WebKit Vulnerability) to its Known Exploited Vulnerabilities (KEV) Catalog following confirmed reports of active exploitation. These flaws allow attackers to gain unauthorized access, execute arbitrary code, and compromise sensitive data by leveraging weaknesses in encryption and browser components. Federal Civilian Executive Branch (FCEB) agencies are mandated to remediate these vulnerabilities by the stipulated deadlines to mitigate risks to critical government infrastructure. These additions reflect an ongoing surge in sophisticated vulnerability exploitation targeting both proprietary business platforms and widely used consumer products. Emerging attacker tactics and the regulatory environment reinforce the importance of robust, timely vulnerability management—underscoring that prioritizing patching of KEV-listed CVEs is now a best practice for all organizations.
6 months ago
Kill Chain
FreePBX 2025: Critical SQL Injection & Authentication Bypass Threatens Telecom Security
In September 2025, researchers from Horizon3.ai disclosed multiple severe vulnerabilities in FreePBX, an open-source private branch exchange (PBX) platform. These flaws, notably including a critical authentication bypass (CVE-2025-61675) and SQL injection issues, enabled remote code execution under certain configurations. Attackers could exploit these weaknesses to upload malicious files, bypass authentication controls, and potentially gain full system access. The vulnerabilities were responsibly reported to project maintainers, prompting urgent security patches and advisories to all FreePBX users. Organizations using affected versions faced significant risks, ranging from service disruption to compromise of sensitive communications and voicemail data. This incident highlights the persistent threat posed by application-layer vulnerabilities in widely deployed open-source communications platforms. The rise of telephony-based attacks and increasingly sophisticated exploitation tactics underscore the need for proactive patch management, rigorous code auditing, and supply chain security in telecom infrastructure.
6 months ago
Kill Chain
React2Shell CVE-2025-55182: Remote Code Execution Attacks Surge in 2025
In December 2025, active exploitation of a critical vulnerability in React2Shell (CVE-2025-55182) was detected, enabling remote code execution on unpatched servers. Attackers deployed a sequence of crafted HTTP requests to download and write malicious binaries onto world-writable Linux directories, such as /dev/shm and /tmp, then modified permissions to prepare for subsequent execution. The threat was identified by security researchers monitoring exploit payloads, which often leveraged ambiguous malware—classified as either adware or crypto miners—resulting in the compromise of affected servers and potentially unauthorized resource usage or data exfiltration. This campaign exemplifies the ongoing risk posed by delayed patch management, with adversaries swiftly evolving their payloads and exploiting widespread attack surfaces. The frequency of similar incidents underscores the importance of timely security updates and hardened configurations, particularly for widely deployed web services.
6 months ago
Kill Chain
VolkLocker 2025: Flaw in CyberVolk Ransomware Lets Victims Self-Decrpyt
In December 2025, the pro-Russia hacktivist group CyberVolk launched a new version of its VolkLocker ransomware-as-a-service (RaaS), targeting public sector and government organizations. The attackers leveraged Telegram automation for command-and-control, and conducted attacks on both Windows and Linux systems. However, investigators discovered a critical flaw: the ransomware stored its master encryption key in plaintext in the %TEMP% directory, allowing victims to recover encrypted files independently without paying ransom. This lapse likely resulted from debug functionality inadvertently left in production, significantly weakening the group's operations and credibility. This incident is highly relevant as ransomware groups are modernizing with advanced automation—but basic operational mistakes can undermine even sophisticated threat actors. For blue teams, it offers a real-world example of why continuous code auditing and rapid incident response are crucial, while for attackers, it’s a cautionary tale regarding quality control in criminal tooling.
6 months ago
Kill Chain
Critical React & Next.js Deserialization Bug Leads to RCE: What You Need to Know
In April 2025, security researchers disclosed critical vulnerabilities (CVE-2025-55182 and CVE-2025-66478) affecting the React and Next.js frameworks, specifically tied to unsafe data serialization and deserialization mechanisms in the Server Actions and Flight protocol. Attackers exploited the flaw to achieve remote code execution (RCE), enabling credential harvesting, lateral movement, and persistent access across affected environments. Within days of the CVEs’ disclosures, weaponized public exploit scripts proliferated on GitHub, compressing defenders’ reaction times and raising the risk of widespread attacks on applications running modern web stacks. This incident highlights the persistent danger of insecure serialization across software ecosystems, a threat pattern seen across at least a decade and multiple development languages. As AI-augmented coding accelerates release cycles, the lessons of past serialization flaws remain vital to protect emerging cloud-native applications from rapidly evolving threats.
6 months ago
Kill Chain
10 Critical November 2025 CVEs: Quality Over Quantity in Exploitation Trends
In November 2025, a sharp 69% drop in reported critical vulnerabilities masked a surge in the intensity of exploitation campaigns. Threat intelligence from Recorded Future revealed 10 high-risk CVEs—including two critical Fortinet FortiWeb flaws—actively targeted by threat actors. Notably, the LANDFALL spyware campaign weaponized Samsung's image processing vulnerability for zero-click remote attacks, while seven of ten vulnerabilities had public proof-of-concept code released. Vulnerabilities included OS command injection, out-of-bounds writes, access control failures, and issues affecting major vendors such as Microsoft, Oracle, and Google. This incident highlights how attackers are shifting to fewer but far more impactful vulnerabilities, emphasizing quality over quantity in their exploitation. Security teams must adapt, maintaining vigilance even during perceived lulls and prioritizing fast patching, advanced monitoring, and comprehensive exposure management to counter rapidly evolving threats.
6 months ago
Kill Chain
ClickFix Attackers Get Creative: Finger Protocol Exploitation in Ongoing Social Engineering Campaigns (2025)
In December 2025, ongoing ClickFix social engineering campaigns, notably KongTuke and SmartApeSG, exploited the legacy finger protocol to deliver malicious payloads to Windows hosts. Attackers enticed users to interact with fake CAPTCHA pages, triggering finger.exe commands that retrieved further instructions—such as encoded PowerShell commands or direct downloads of malware—from attacker-controlled servers over TCP port 79. These techniques allowed adversaries to bypass conventional detection and deliver remote access tools or additional scripts, posing operational threats to unprotected enterprise environments. This campaign highlights the resurgence of creative use of legacy or overlooked network protocols in modern attack chains. The persistence of ClickFix-driven social engineering and the reuse of finger.exe underline the importance for organizations to reassess traffic filtering strategies, as attackers are diversifying their initial access and payload delivery vectors.
6 months ago
Kill Chain
Ransomware Gets Hacked: CyberVolk’s VolkLocker Crumbles Under Weak Crypto
In June 2024, the pro-Russia hacktivist group CyberVolk introduced its VolkLocker ransomware-as-a-service (RaaS) platform, targeting organizations with file-encrypting malware. However, security researchers quickly discovered significant cryptographic vulnerabilities in its implementation, allowing many victims to recover encrypted files without paying the ransom. The flawed encryption methods meant attackers’ efforts to monetize were largely ineffective, reducing financial impact for most affected organizations but still causing temporary operational disruption and alarm. This incident highlights the persistent evolution of ransomware delivery via RaaS models, even by newly emerging threat actors with insufficient technical sophistication. As ransomware groups proliferate and adapt, businesses face the dual challenges of staying current on new threats and maintaining fundamental security practices, including robust encryption and incident response readiness.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports