Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3629 threat reports
Page 218 of 303

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 26052616 / 3629 reports
Multi-APT Exploitation of WinRAR CVE-2025-6218: A Recurring Supply Chain Risk
Impact· medium

Multi-APT Exploitation of WinRAR CVE-2025-6218: A Recurring Supply Chain Risk

In mid to late 2025, a critical vulnerability in WinRAR (CVE-2025-6218), enabling path traversal and arbitrary code execution on Windows systems, was exploited by multiple sophisticated threat groups. Notably, GOFFEE, Bitter APT (APT-C-08), and the Russian state-linked Gamaredon leveraged spear-phishing emails with booby-trapped RAR archives to compromise targets, including Ukrainian government, South Asian organizations, and others. Attackers used malicious archives to persistently install remote access malware, capable of keylogging, data exfiltration, and credential theft, while some incidents involved destructive attacks deploying wiper malware. The vulnerability was patched in June 2025, but active exploitation continued through the year, forcing urgent defensive measures across critical sectors. This incident highlights the rapid weaponization of newly disclosed vulnerabilities by nation-state and criminal groups, as well as the challenges organizations face in managing unstructured file transfer risks. The coordinated exploitation across regions and APTs underscores an upward trend in supply chain and endpoint software attacks, increasing regulatory and operational urgency to close patching and phishing resilience gaps.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
PCIe Encryption Vulnerabilities Disclosed: 2025 Hardware Security Risks
Impact· high

PCIe Encryption Vulnerabilities Disclosed: 2025 Hardware Security Risks

In December 2025, three critical hardware vulnerabilities were disclosed in the Peripheral Component Interconnect Express (PCIe) Integrity and Data Encryption (IDE) protocol, impacting PCIe Base Specification Revision 5.0 and newer systems. These vulnerabilities—CVE-2025-9612, CVE-2025-9613, and CVE-2025-9614—enable local attackers with physical or low-level access to manipulate encrypted traffic, cause information disclosure, escalate privileges, or disrupt services. Affected products include select Intel Xeon and AMD EPYC processor lines. The flaws are notable for potentially undermining the core security objectives of IDE, especially in environments relying on trusted execution and encrypted data flows. This disclosure is particularly relevant as hardware-level vulnerabilities are increasingly leveraged by attackers seeking to evade conventional endpoint and network security controls. The need for integrity in encrypted data pathways is surging amid rising adoption of zero trust and compliance mandates, underscoring the urgency of prompt firmware patches and adherence to updated PCIe standards.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
React2Shell Exploitation Delivers Crypto Miners and Advanced Malware Across Multiple Sectors
Impact· medium

React2Shell Exploitation Delivers Crypto Miners and Advanced Malware Across Multiple Sectors

In December 2025, a sophisticated multi-vector cyber campaign exploited a critical vulnerability (CVE-2025-55182) in React Server Components, enabling unauthenticated remote code execution across more than 50 organizations in industries including construction, entertainment, finance, and government. Attackers orchestrated automated scans to identify vulnerable Next.js deployments and delivered a suite of malware, notably the PeerBlight backdoor, CowTunnel reverse proxy, ZinFoq implant, and various cryptominers. The campaign leveraged both Linux and Windows endpoints, indicating indiscriminate targeting. Highly persistent payloads established robust command-and-control connections, enabled lateral movement, and facilitated data exfiltration while evading detection using masquerading and decentralized C2 mechanisms. This incident underscores the urgency of prompt patching for popular web frameworks and highlights the growing sophistication and prevalence of automated exploitation tools. Security teams face amplified risk as threat actors now combine opportunistic cryptomining with advanced post-exploitation techniques across geographic regions and sectors, outpacing conventional defenses and incident response speeds.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
.NET SOAPwn Flaw (2025): Remote Code Execution via Rogue WSDL
Impact· medium

.NET SOAPwn Flaw (2025): Remote Code Execution via Rogue WSDL

In December 2025, security researchers at WatchTowr Labs revealed the 'SOAPwn' vulnerability (CVE-2025-34392 and CVE-2025-13659) impacting .NET Framework applications, including Barracuda Service Center RMM and Ivanti Endpoint Manager. Exploiting unsafe Web Services Description Language (WSDL) imports and HTTP client proxies, attackers could achieve remote code execution and arbitrary file writes on affected enterprise-grade systems. The flaw enabled threat actors to upload web shells, execute PowerShell scripts, or exfiltrate NTLM credentials via rogue SMB shares, potentially compromising entire application environments. Despite responsible disclosure, Microsoft stated the vulnerability is an application-level issue, leaving many unpatched systems at risk—especially those using components now at end-of-life such as Umbraco 8. This incident underscores the widespread risks associated with dynamic SOAP and WSDL usage in legacy frameworks and highlights attackers' growing focus on exploiting insecure software supply chains and overlooked application behaviors. The public disclosure has intensified scrutiny of web service integrations and spurred new urgency around secure coding practices in software built atop widely adopted frameworks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How the Shai-Hulud Worm Exposed npm’s Supply-Chain Weaknesses in 2024
Impact· medium

How the Shai-Hulud Worm Exposed npm’s Supply-Chain Weaknesses in 2024

In May 2024, the Shai-Hulud worm re-emerged in a sophisticated supply-chain attack targeting the npm ecosystem. Attackers compromised popular npm packages to inject malicious code capable of propagating to developer environments globally. Once installed via npm, the worm enabled lateral movement, credential theft, and unauthorized access, significantly elevating the risk for organizations relying on open-source JavaScript components. Detection lag and incomplete remediation allowed the campaign to impact a broad swath of organizations and developers. This incident marks a resurgence of highly automated supply-chain malware targeting open source software, mirroring broader industry concerns around software dependencies and third-party risk. Increased attacker automation and stealthy propagation tactics underscore the critical need for vigilant dependency management and advanced detection.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
01flip Ransomware Strikes APAC Critical Infrastructure—Rust-Based Attacks Escalate
Impact· high

01flip Ransomware Strikes APAC Critical Infrastructure—Rust-Based Attacks Escalate

In June 2025, a financially motivated cybercrime group tracked as CL-CRI-1036 launched targeted ransomware attacks using a new cross-platform strain called 01flip—written in Rust—against select organizations in the Asia-Pacific region. Initial access appears to have been gained by exploiting known vulnerabilities in internet-facing applications, including CVE-2019-11580, followed by lateral movement and mass deployment of ransomware payloads across Windows and Linux systems. The attackers demanded payment in Bitcoin and posted evidence of stolen data on dark web forums, impacting at least one critical infrastructure operator and resulting in operational disruption and data exposure. This incident highlights the rapid evolution of ransomware, with threat actors increasingly adopting modern development languages for advanced evasion. The emergence of 01flip demonstrates the ongoing risk posed by zero-day exploitation, inadequate segmentation, and cross-platform malware, underscoring the need for organizations to prioritize proactive threat detection and incident response capabilities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
North Korean Threat Actors Weaponize React2Shell to Deploy Stealthy EtherRAT in 2025 Supply Chain Campaign
Impact· medium

North Korean Threat Actors Weaponize React2Shell to Deploy Stealthy EtherRAT in 2025 Supply Chain Campaign

In late 2025, North Korea-linked threat actors exploited the critical React2Shell (CVE-2025-55182) vulnerability in React Server Components to deploy an advanced remote access trojan named EtherRAT. The campaign, tracked under 'Contagious Interview', targeted blockchain and Web3 developers through sophisticated social engineering on platforms such as LinkedIn, Upwork, and GitHub. Attackers leveraged a fake recruitment ruse, ultimately delivering EtherRAT via malicious scripts. The malware exhibits persistent mechanisms across Linux environments, utilizes Ethereum smart contracts for resilient C2, and aggressively evades detection with self-updating, obfuscated payloads. This attack demonstrates how advanced actors are increasingly adapting novel supply chain and social engineering tactics to target cloud-native developer ecosystems. The incident foreshadows a shift in the threat landscape, underlining the urgent need for robust east-west traffic controls, zero trust segmentation, and advanced anomaly detection for organizations exposed to modern DevOps and open-source risks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Ransomware Reimagined: Attackers Deploy Their Own QEMU VM for Stealth and Persistence
Impact· medium

Ransomware Reimagined: Attackers Deploy Their Own QEMU VM for Stealth and Persistence

In early 2025, a sophisticated ransomware incident was revealed by Red Canary Intelligence when an adversary launched a coordinated attack combining email bombing, social engineering, and abuse of legitimate remote access tools. Initially, victims endured email inundation designed to cause confusion and open the door to a convincing technical support ruse. Leveraging remote assistance software, attackers deployed a custom QEMU virtual machine (VM) into the compromised environment—a novel method for persistent access. Within this VM, tools such as Sliver C2, QDoor backdoor, and ScreenConnect enabled internal reconnaissance, lateral movement, and external command and control, all while evading conventional endpoint security controls. This incident is noteworthy for both its multi-layered attack chain and the adversary’s use of their own pre-configured VM for persistence, representing a shift toward virtualization-based evasion and resilience. The detection highlights a rise in blended attacks using social engineering, legitimate tools, and bespoke infrastructure, stressing the importance of defense-in-depth and advanced anomaly detection capabilities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(medium)
Read Report
SAP’s December 2023 Patch: Three Critical Vulnerabilities Explained
Impact· medium

SAP’s December 2023 Patch: Three Critical Vulnerabilities Explained

In December 2023, SAP released security updates that addressed 14 vulnerabilities across several of its products, three of which were rated as critical. The most severe flaws affected fundamental SAP systems such as ABAP and NetWeaver, with CVSS scores as high as 9.9, potentially allowing attackers to execute unauthorized actions, access sensitive data, or disrupt business operations. The vulnerabilities could be exploited remotely, and patching delays threatened core business processes of organizations running SAP in enterprise and cloud environments. No active exploitation was publicly reported at disclosure, but SAP strongly urged immediate patching to mitigate risk. This incident highlights the persistent risks associated with complex enterprise application platforms widely used across industries. With attackers increasingly targeting software supply chains and critical business infrastructure, timely patch management and continuous vulnerability monitoring in environments like SAP remain essential to maintaining regulatory compliance and business continuity.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Flags New High-Risk Vulnerabilities in 2025 KEV Catalog
Impact· medium

CISA Flags New High-Risk Vulnerabilities in 2025 KEV Catalog

In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added two actively exploited vulnerabilities—CVE-2025-6218 (RARLAB WinRAR Path Traversal) and CVE-2025-62221 (Microsoft Windows Use After Free)—to its Known Exploited Vulnerabilities (KEV) Catalog. These critical flaws are utilized by cyber attackers to gain unauthorized access, facilitate lateral movement, and potentially execute arbitrary code within federal and enterprise environments. CISA’s directive mandates that all Federal Civilian Executive Branch (FCEB) agencies remediate these vulnerabilities by specified dates to mitigate significant risk, reinforcing the growing threat from rapid exploitation of newly discovered CVEs. This incident illustrates the ongoing challenges faced by organizations, as adversaries increasingly exploit widely used software at scale. The timely identification and remediation of KEV Catalog vulnerabilities are vital for maintaining strong security postures amid an uptick in exploitation and regulatory pressure to close known gaps.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
US Treasury Highlights $4.5B in Ransomware Payments: 2024 Threat Landscape
Impact· high

US Treasury Highlights $4.5B in Ransomware Payments: 2024 Threat Landscape

In February 2024, the US Treasury’s Financial Crimes Enforcement Network (FinCEN) reported that ransomware attacks have resulted in over $4.5 billion in ransom payments since 2013, underscoring a dramatic surge in both scale and sophistication. Attackers typically infiltrated organizations through phishing campaigns, exploitation of unpatched vulnerabilities, and compromised remote desktop protocols, deploying ransomware variants to encrypt data and demand payment. These incidents disrupted critical business operations across sectors, forced enterprises to halt services, and left many struggling with reputational and financial damage. This report is especially relevant as ransomware strains evolve, facilitating large-scale attacks on enterprises, healthcare, and infrastructure. Heightened regulatory scrutiny, such as OFAC and FinCEN advisories, means organizations face intensified pressure to monitor, report, and prevent ransomware-related activities.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
React2Shell: Exploitation Surge Hits Businesses in 2025
Impact· low

React2Shell: Exploitation Surge Hits Businesses in 2025

In June 2025, attackers began widespread exploitation of CVE-2025-55182, a critical vulnerability known as React2Shell, shortly after it was publicly disclosed. Threat actors rapidly leveraged the unauthenticated remote code execution flaw to gain access to vulnerable web servers running the React2Shell component, allowing lateral movement, data exfiltration, and in some cases, ransomware deployment. The initial wave targeted a range of businesses, exploiting the window between disclosure and patch adoption, thus exposing organizations to operational disruption and compliance risks. The surge in React2Shell exploitation underscores an ongoing trend: cybercriminals are taking advantage of zero-day and recently publicized vulnerabilities with renewed speed and sophistication. Security teams must deal with shrinking patch windows, automated exploit tools, and increasing pressure from regulators to secure internet-facing applications.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports