✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Malicious VSCode Extensions Breach Developer Supply Chain in 2024
In early 2024, researchers uncovered a significant supply chain attack affecting the Visual Studio Code Marketplace, where 19 malicious extensions were published and actively distributed since February. These extensions, downloaded by thousands of developers worldwide, secretly harbored trojans within disguised PNG files placed in dependency folders. The attackers leveraged VSCode’s broad adoption as a developer tool to inject remote access trojans (RATs) and facilitate potential compromise of development environments and source code. Microsoft has since removed the malicious extensions, but the campaign illustrates a growing trend of targeting developer ecosystems for initial access and data exfiltration. This incident highlights the increased risk posed by third-party dependencies in software supply chains, especially as attackers shift toward platforms popular among technical professionals. The event also underscores the ongoing regulatory and compliance challenges in managing integrity and security for code repositories and developer tools.
6 months ago
Kill Chain
Notepad++ Supply Chain Attack: Malicious Updater Flaw Exposes Millions (2024)
In June 2024, Notepad++ addressed a critical security vulnerability in its updater component, WinGUp, after researchers revealed that attackers could intercept the update process and deliver malicious executables instead of authentic software updates. The flaw arose because the updater did not enforce encryption or signature verification when retrieving update packages, allowing adversaries to mount supply chain attacks through man-in-the-middle techniques. This exposed users to risk of remote code execution and allowed attackers to propagate malware under the guise of legitimate software updates. This incident highlights the growing wave of software supply chain attacks in 2024, echoing concerns from security leaders and regulators about the risks of unencrypted software delivery channels. Organizations are being urged to ensure proper code signing, encrypted update pipelines, and vigilant anomaly detection in third-party dependencies to defend against evolving threat tactics.
6 months ago
Kill Chain
Gladinet CentreStack 2024: RCE Attacks via Cryptographic Vulnerability
In early June 2024, threat actors began exploiting a previously unknown cryptographic implementation flaw in Gladinet's CentreStack and Triofox products, enabling them to remotely execute code on vulnerable servers. By leveraging crafted payloads targeting insecure cryptographic validation, attackers bypassed authentication mechanisms and gained unauthorized access to sensitive file sharing environments. This led to potential exposure of confidential data, lateral movement, and service disruption for affected organizations, particularly those relying on CentreStack for enterprise file sharing and remote access. This incident highlights the risks of cryptographic implementation errors and the urgent need for patch management, especially for third-party cloud and SaaS solutions. As attackers increasingly weaponize zero-day flaws in commonly used remote file access platforms, enterprises must prioritize robust monitoring and rapid response strategies.
6 months ago
Kill Chain
Chrome Attacked: 2025 Zero-Day Memory Exploit in ANGLE Library Exposed
In December 2025, Google disclosed a high-severity zero-day vulnerability (CVE-2025-14174) affecting its Chrome browser, which had been exploited in the wild. The flaw, residing in Chrome's Almost Native Graphics Layer Engine (ANGLE), allowed attackers to perform out-of-bounds memory access via a crafted HTML page, enabling memory corruption, crashes, or remote code execution. Discovered by Apple's Security Engineering and Google TAG teams, this vulnerability triggered urgent patching across all Chromium-based browsers, as the exploit was independently observed targeting users prior to public awareness. This incident underscores growing risks associated with memory management flaws in popular software and the increasing frequency of zero-day exploits. With regulatory bodies like CISA flagging exploited Chrome vulnerabilities for immediate remediation, the event highlights a rising trend of sophisticated, targeted browser attacks that demand rapid and coordinated enterprise response.
6 months ago
Kill Chain
Gogs Zero-Day Exploit Compromises 700+ Cloud Instances in 2025
In July 2025, more than 700 internet-exposed instances of Gogs, a popular self-hosted Git service, were compromised via exploitation of an unpatched zero-day vulnerability (CVE-2025-8110). Threat actors took advantage of improper symbolic link handling in the file update API, enabling arbitrary file overwrite and remote code execution. Attackers deployed Supershell-based malware through a multi-step process to gain server access, leaving behind uniquely-named repositories and operating in a 'smash-and-grab' campaign style. The campaign exploited a previously patched flaw (CVE-2024-55947) bypass, emphasizing the importance of patch management and reducing attack surface exposure for critical developer infrastructure. This incident is highly relevant as it highlights an ongoing surge in attacks targeting developer and DevOps tools, exposing how rapidly adversaries adapt to security patch cycles and leverage weaknesses in open-source environments. GIT system supply chain risks and attacker agility mandate urgent focus on threat detection, cloud workload security, and privileged access management.
6 months ago
Kill Chain
React2Shell (CVE-2025-55182): New React Server Components Flaw Under Active Attack
In December 2025, attackers rapidly weaponized a critical deserialization vulnerability (CVE-2025-55182, "React2Shell") in React Server Components (RSC), enabling remote code execution on web servers running unpatched React libraries. Threat actors exploited the flaw—scoring a CVSS 10.0—by sending serialized payloads in POST requests, executing arbitrary commands, deploying malware, and exfiltrating credentials. Infections observed include crypto-miners, Mirai/Gafgyt bots, and the advanced RondoDox botnet targeting both Linux servers and IoT devices. Exploit activity began within hours of disclosure, with a sharp increase in attempts against internet-facing systems. This incident highlights the increasing speed at which proof-of-concept exploits are operationalized in the wild, emphasizing risks of deserialization vulnerabilities and dependency hygiene in modern web application stacks. Supply chain and cloud-centric attacks leveraging similar TTPs are expected to become more common, placing organizations with weak patch cycles at heightened risk.
6 months ago
Kill Chain
Spyware, Mirai, Docker Leaks & ValleyRAT: Anatomy of a 2025 Multi-Vector Breach
In December 2025, a sophisticated multivector cyberattack campaign exploited vulnerabilities across popular software, container platforms, and download channels. Hackers leveraged malicious browser extensions, tainted movie torrents, and compromised Docker images to disseminate a blend of Mirai botnet variants, ValleyRAT rootkits, and advanced spyware, evading traditional perimeter defenses. The attackers utilized encrypted communications and east-west movement to escalate privileges and exfiltrate sensitive organizational data. Impacts included operational outages, ransom demands, exposure of proprietary assets, and regulatory notification obligations for affected companies across multiple industries. This attack illustrates the intensifying convergence of commodity malware, supply chain threats, and network infiltration techniques. With ransomware, spyware, and rootkits increasingly delivered via trusted collaboration or cloud platforms, and as attackers exploit hybrid environments, organizations face urgent pressure to revisit segmentation, detection, and zero trust controls.
6 months ago
Kill Chain
Mythic: The Growing Threat of Post-Exploitation C2 Frameworks in Network Traffic
In early 2024, cybersecurity researchers revealed the widespread use of the Mythic post-exploitation framework by multiple threat actors to gain persistent control of compromised networks. Mythic, a versatile multi-platform C2 (command and control) toolkit, has enabled adversaries to evade endpoint detection tools while moving laterally, collecting data, and exfiltrating sensitive assets. By leveraging covert channels such as HTTP(S), SMB, WebSocket, Discord, and GitHub APIs, attackers have masked their traffic from traditional network security defenses. Incident response teams observed tailored communication modules, pivoting tactics, and sophisticated data encoding, resulting in delayed detection and prolonged dwell time within targeted organizations. This incident highlights the growing challenge for defenders as open-source offensive frameworks become more advanced and widely adopted. The surge of network-based C2 detection evasion tactics underscores the need for enhanced behavioral analysis, encrypted traffic inspection, and updated NDR/IDS capabilities, especially as regulatory and compliance scrutiny intensifies.
6 months ago
Kill Chain
Shanya Packer-as-a-Service: Ransomware’s New Obfuscation Arsenal
In May 2024, security researchers uncovered an emerging Packer-as-a-Service (PaaS) called Shanya, designed to help ransomware operators evade modern enterprise defenses. Shanya provides advanced payload obfuscation capabilities to threat actors, enabling the delivery of ransomware that bypasses endpoint detection and response (EDR) solutions. Attackers using Shanya can rapidly pack malware before deployment, making it harder to analyze and detect. Early incidents showed Shanya-packed ransomware used to swiftly gain lateral movement across compromised environments, disrupt business operations, and facilitate significant data encryption and extortion campaigns. The rise of packers like Shanya signals a growing trend: ransomware groups are leveraging SaaS-style services to increase automation, evasion, and reach. With increased regulatory scrutiny on incident response and a surge in ransomware targeting sectors with critical operations, businesses must urgently strengthen detection and response strategies to address evolving malware delivery techniques.
6 months ago
Kill Chain
Microsoft’s 2024 Zero-Day Exploitation: What Security Leaders Must Know
In June 2024, Microsoft released security updates addressing a critical zero-day vulnerability (CVE-2024-30051) that was actively exploited in the wild, targeting Windows operating systems. Threat actors leveraged this privilege escalation flaw to bypass security controls and gain elevated access privileges on compromised systems, potentially enabling further malware deployment and lateral movement. Nearly 50 vulnerabilities were patched in this cycle, with public proof-of-concept code available for several, raising the risk of rapid exploitation by cybercriminal groups and nation-state actors before widespread patch deployment. This incident underscores the persistent threat of zero-day vulnerabilities, the speed at which exploits circulate once publicly disclosed, and the substantial business risk posed to enterprises delaying patch management. Increasing regulatory scrutiny and evolving attack techniques demand urgent, proactive defense strategies.
6 months ago
Kill Chain
Storm-0249's Abuse of EDR Processes: A New Era of Stealth Attacks
In early 2024, threat actor Storm-0249 launched a series of stealthy attacks by weaponizing Endpoint Detection and Response (EDR) platforms alongside native Windows utilities. As an initial access broker, the group circumvented traditional EDR defenses to gain persistent entry into multiple enterprise environments. Leveraging legitimate EDR processes for their own activities, Storm-0249 was able to evade security monitoring, escalate privileges, and facilitate lateral movement. These tactics led to compromised data and footholds that were subsequently sold to other cybercriminal groups, increasing the overall risk for targeted organizations. The emergence of sophisticated actors repurposing security tools for malicious objectives highlights an urgent industry focus on advanced detection, segmentation, and the continual evolution of zero trust strategies. This incident reflects a growing trend: motivated threat groups exploiting trusted processes to blend in and extend dwell time inside modern network environments.
6 months ago
Kill Chain
AI Domain Impersonation Fuels 2024 ClickFix-Style Malware Surge
In early 2024, a cyberattack campaign known as the 'ClickFix Style Attack' emerged, exploiting cutting-edge social engineering and SEO poisoning techniques. Attackers leveraged widely searched AI-related domains such as Grok and ChatGPT, using search engine manipulation to lure unsuspecting users to weaponized websites. Once on these compromised pages, visitors were tricked into downloading malware under the guise of legitimate AI tools and browser extensions, enabling threat actors to gain persistent access to systems and exfiltrate sensitive data. The campaign highlights the growing sophistication and agility of attackers in blending trusted brands with social engineering ploys, ultimately threatening business operations and data integrity. This incident is particularly relevant as it showcases the convergence of AI hype, manipulated search results, and advanced social engineering, which increases the likelihood of successful malware delivery. Security teams must remain vigilant as attackers continue to target the widespread adoption of AI-driven tools and blur lines between legitimate and malicious sources.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports