Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3629 threat reports
Page 220 of 303

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 26292640 / 3629 reports
Escalating Credential Attacks on Palo Alto GlobalProtect VPNs: 2024 Threat Review
Impact· low

Escalating Credential Attacks on Palo Alto GlobalProtect VPNs: 2024 Threat Review

In early 2024, cybersecurity analysts observed a widespread campaign targeting Palo Alto Networks’ GlobalProtect VPN portals and SonicWall SonicOS API endpoints with aggressive login attempts and scanning activity. Threat actors used automated tools to conduct credential stuffing and exploit potential vulnerabilities in exposed VPN portals, aiming to gain unauthorized network access. While no specific breaches were confirmed, the campaign's scope affected numerous organizations globally relying on these remote access solutions, highlighting the heightened risk to large enterprises and managed service providers leveraging vulnerable or misconfigured VPN infrastructure. This incident illustrates the surge in identity-driven and credential-based attacks exploiting remote access technologies, especially as hybrid and remote workforces remain prevalent. The rapid evolution and broad targeting underscore the urgent need for continuous VPN hardening, robust access governance, and threat monitoring to preempt similar intrusion attempts impacting business continuity.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical React2Shell Flaw (CVE-2025-55182) Added to CISA KEV After Confirmed Exploitation
Impact· low

Critical React2Shell Flaw (CVE-2025-55182) Added to CISA KEV After Confirmed Exploitation

In June 2025, a critical remote code execution (RCE) vulnerability, CVE-2025-55182, impacting React Server Components (RSC) was added to CISA's Known Exploited Vulnerabilities catalog following confirmed reports of active exploitation. Attackers leveraged the flaw, known as 'React2Shell,' to execute arbitrary code on vulnerable servers by exploiting inadequate input validation, enabling lateral movement and potential compromise of sensitive systems and data. Several organizations in sectors reliant on JavaScript-based web infrastructures were affected, resulting in service disruptions and the risk of unauthorized data access and exfiltration. This incident highlights a broader trend in targeting supply chain and open-source components within modern web development stacks. The increasing frequency and sophistication of attacks on widely adopted frameworks like React underscore the urgency for rapid vulnerability remediation, improved code validation, and enterprise adoption of proactive threat detection to mitigate future large-scale RCE campaigns.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
AI IDEsaster: 30+ Vulnerabilities Expose Developer Environments to Prompt Injection & RCE (2025)
Impact· medium

AI IDEsaster: 30+ Vulnerabilities Expose Developer Environments to Prompt Injection & RCE (2025)

In December 2025, over 30 serious security flaws—collectively named "IDEsaster"—were uncovered in popular AI-powered Integrated Development Environments (IDEs) by researcher Ari Marzouk (MaccariTA). Exploiting these vulnerabilities, attackers could inject malicious prompts, leading to unauthorized data exfiltration and remote code execution within developer environments. The flaws stemmed from unsafe integrations of AI features, including insufficient sandboxing and lack of network traffic controls, exposing sensitive code and credentials to threat actors. Notably, vulnerabilities allowed for lateral movement and direct access to code repositories, risking business continuity and intellectual property. This incident is especially significant as AI adoption in coding workflows accelerates, creating new attack vectors. The surge in prompt injection and AI supply chain threats, paired with evolving attacker tactics targeting developer tools, highlights the urgent need for organizations to strengthen segmentation, monitoring, and AI risk governance.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
How MCP Prompt Injection Attacks Bypassed AI Security Controls in 2024
Impact· medium

How MCP Prompt Injection Attacks Bypassed AI Security Controls in 2024

In early 2024, cybersecurity researchers from Unit 42 uncovered a series of novel prompt injection attack vectors targeting applications built on the Model Context Protocol (MCP), an emerging technology that connects large language models (LLMs) to external data sources and tools. Threat actors exploited weaknesses in MCP sampling to inject malicious prompts, enabling sensitive data exfiltration, command execution, and unauthorized access to downstream APIs. The compromised LLM applications posed significant risks across industries utilizing MCP to enhance automation and efficiency, ultimately raising concerns over AI/ML-powered business processes. The attack highlighted urgent visibility, policy enforcement, and segmentation shortfalls in cloud-native environments. The MCP prompt injection incident underscores a surge in AI-driven threats, particularly as generative AI is rapidly being integrated into enterprise workflows. Regulatory bodies and CISOs now place a premium on robust framework adherence and continuous monitoring as generative AI vulnerabilities and supply-chain risks multiply.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Cloudflare 2024 Outage: Why Network Resilience and Redundancy Matter More Than Ever
Impact· high

Cloudflare 2024 Outage: Why Network Resilience and Redundancy Matter More Than Ever

On June 20, 2024, Cloudflare, a major internet infrastructure and security provider, suffered a widespread service outage that disrupted access to thousands of websites and web services globally. The event was characterized by persistent 500 Internal Server Error messages for end users. Cloudflare initiated an internal investigation, ultimately attributing the incident to a critical infrastructure failure rather than a cyberattack or external threat. Throughout the outage, web-facing businesses, SaaS providers, and end-users experienced degraded network performance, extended downtime, and impact to brand trust, illustrating the magnitude of hyperscaler dependencies. The Cloudflare outage highlights the increasing risks associated with concentration of critical internet services and underscores the urgency for organizations to bolster resilience strategies. In an era of heightened service interdependencies and upticks in both incidents and attacks targeting fundamental service providers, outage preparedness and robust incident response planning are more essential than ever.

6 months ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
AI Agent Prompt Injection Turns GitHub Actions Into Supply Chain Backdoor
Impact· medium

AI Agent Prompt Injection Turns GitHub Actions Into Supply Chain Backdoor

In early 2024, cybersecurity researchers at Aikido disclosed a critical supply-chain vulnerability affecting major AI coding tools such as Google Gemini, Claude Code, OpenAI Codex, and GitHub AI Inference. The flaw enables attackers to inject malicious prompts into software automation workflows like GitHub Actions, causing integrated AI agents with elevated privileges to execute unauthorized commands. Cunning use of crafted commit messages and pull requests can trick large language models into treating these inputs as actionable instructions, leading to code modifications, shell command execution, and privilege escalation within software repositories. The vulnerability, reported via responsible disclosure, has prompted urgent fixes in some tools, but similar weaknesses remain present in other platforms. This incident highlights the expanding risks of AI-powered automation in the software development supply chain. With organizations increasingly relying on LLM integrations, the potential for prompt injection and privilege abuse creates new avenues for compromise, underscoring the urgency for robust controls, regular audit, and architectural safeguards around agentic AI workflows.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How Sophisticated Attackers Exploited the 2025 React2Shell Zero-Day
Impact· medium

How Sophisticated Attackers Exploited the 2025 React2Shell Zero-Day

In June 2025, a critical remote code execution vulnerability named React2Shell (CVE-2025-55182) was exploited in the wild against organizations using React Server Components. Within hours of the public disclosure and patch release, Chinese state-linked groups such as UNC5174 (CL-STA-1015), Earth Lamia, and Jackpot Panda, alongside opportunistic cybercriminals, began mass scanning and targeting exposed systems. The threat actors successfully deployed malware (notably Snowlight and Vshell), established persistent access, conducted credential theft, and attempted to extract Amazon Web Services configuration and credential files. Over 30 organizations across industries suffered breaches, including documented impact on customer cloud environments. This campaign demonstrates the increasing speed and coordination of attackers exploiting newly public vulnerabilities, especially in widely deployed frameworks like React and Next.js. The incident underscores the necessity of rapid patching, improved east-west traffic security, and continuous threat detection, as adversaries quickly weaponize disclosures for initial access and persistent footholds.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
China-Linked Supply Chain Breach Exploits React2Shell Flaw in 2025
Impact· low

China-Linked Supply Chain Breach Exploits React2Shell Flaw in 2025

In mid-2025, multiple China-linked threat actors launched widespread exploitation of the React2Shell vulnerability (CVE-2025-55182), a critical supply-chain flaw impacting React and Next.js applications. Within hours of the flaw’s public disclosure, attackers initiated automated scanning and weaponization campaigns, targeting internet-exposed services to quickly gain unauthorized, remote code execution. Successful intrusions enabled attackers to harvest sensitive data, escalate privileges, and pivot laterally within affected cloud environments. The rapid adoption of malicious payloads and swift exploitation before most organizations could patch led to substantial business risk, data loss, and potential compliance violations across sectors. This incident underscores an escalated threat landscape where nation-state actors rapidly exploit newly-disclosed supply-chain vulnerabilities. The speed and scope of these attacks reflect a significant uptick in zero-day exploitation campaigns and highlight the urgent need for organizations to strengthen patching velocity, endpoint monitoring, and east-west segmentation controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Cloudflare’s 2024 Outage: Lessons from the React2Shell RCE Emergency
Impact· medium

Cloudflare’s 2024 Outage: Lessons from the React2Shell RCE Emergency

In June 2024, Cloudflare experienced a significant outage after emergency patching efforts to address an actively exploited remote code execution (RCE) vulnerability in the React framework, dubbed "React2Shell." The incident unfolded as threat actors began leveraging the vulnerability to attempt unauthorized code execution on internet-facing workloads, prompting Cloudflare to rush critical security mitigations. While the attack itself targeted exploitation routes via React, it was the swift application of mitigations—rather than a direct breach—which triggered widespread downtime, temporarily impacting Cloudflare's global network operations and customer accessibility. This incident underscores the increasing speed and aggression of active exploitation cycles, particularly for zero-day vulnerabilities in widely used frameworks. As attacker sophistication grows and organizations race to patch critical flaws, operational disruptions and collateral damage are becoming more frequent in the ongoing effort to balance security with business continuity.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Clop Ransomware Hits Barts Health NHS via Oracle Zero-Day
Impact· high

Clop Ransomware Hits Barts Health NHS via Oracle Zero-Day

In early 2024, Barts Health NHS Trust disclosed a data breach after Clop ransomware actors exploited a zero-day vulnerability in Oracle E-Business Suite. The attackers gained unauthorized access to internal systems, exfiltrated sensitive files from a key database, and threatened further leaks. The attack leveraged unpatched software flaws as the entry vector, allowing for rapid lateral movement and data theft before being detected. The incident disrupted operations and triggered regulatory notifications due to the sensitive nature of patient and operational information. This breach highlights the ongoing risks posed by sophisticated ransomware groups exploiting zero-day vulnerabilities in widely used enterprise software. Attacks of this kind are increasingly common, especially in the healthcare sector, which remains a high-value target for ransomware due to legacy systems and critical service mandates.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Discloses PRC Hackers Using BRICKSTORM Backdoor for Stealthy U.S. System Access
Impact· low

CISA Discloses PRC Hackers Using BRICKSTORM Backdoor for Stealthy U.S. System Access

In June 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) reported that state-sponsored hackers affiliated with the People's Republic of China (PRC) utilized a newly identified backdoor dubbed BRICKSTORM to infiltrate and maintain long-term access within VMware vSphere and Windows environments of U.S. critical infrastructure entities. The campaign started months prior, leveraging advanced persistent threat (APT) tactics such as lateral movement, encrypted C2 channels, and sophisticated evasion techniques to bypass network defenses and persist undetected. This led to extensive exfiltration of sensitive data and raised major concerns about the resilience of core U.S. operational systems. The BRICKSTORM attack signals a rising tide of highly targeted intrusions on virtualization platforms, as nation-state actors adopt increasingly stealthy and persistent approaches. Organizations must now contend with the growing complexity and scale of APT operations, which often elude legacy tools and monitoring strategies.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Active Command Injection Attacks Hit Array AG Series Gateways in 2025
Impact· low

Active Command Injection Attacks Hit Array AG Series Gateways in 2025

In mid-2025, JPCERT/CC reported that a command injection vulnerability in Array Networks AG Series secure access gateways had been actively exploited in the wild since at least August of that year. The flaw, residing in the DesktopDirect remote desktop access feature, allowed unauthenticated attackers to execute arbitrary commands on targeted devices. The vulnerability, lacking a CVE at the time of disclosure, was patched by Array Networks in May 2025, but unpatched systems remained exposed to attacks that could lead to further compromise and unauthorized network access. This incident underscores the persistent risks of unpatched infrastructure and weak segmentation in network environments. The rise of zero-day exploits targeting remote access solutions combined with increased regulatory scrutiny makes rapid detection, patching, and least privilege policy enforcement more critical than ever.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports