✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Critical React Server Components Flaw Enables RCE in 2025—What You Need to Know
In December 2025, a maximum-severity vulnerability (CVE-2025-55182), codenamed React2shell, was uncovered in React Server Components (RSC), impacting platforms like React and Next.js. The flaw enables unauthenticated remote code execution (RCE) by exploiting how React decodes certain payloads sent to its server components. If left unpatched, attackers can execute arbitrary code on vulnerable servers, leading to full system compromise and severe business disruption. The incident highlights the critical impact of supply chain vulnerabilities in widely-used open-source frameworks and the elevated risk for businesses relying on modern web development stacks. The discovery of React2shell has triggered urgent patch advisories, as similar RCE vulnerabilities in web frameworks have seen rapid weaponization by threat actors. With increasing regulatory expectations for timely patch management and growing attacker focus on open-source component supply chains, this incident reinforces the need for continuous application security monitoring and robust SDLC controls.
6 months ago
Kill Chain
Raptor Framework: AI-Powered Exploit and Patch Creation Disrupts Vulnerability Management
In June 2024, security researchers publicly released the Raptor Framework, an open source AI-powered toolkit capable of autonomously generating both exploit code for software vulnerabilities and their corresponding security patches. Leveraging large language models (LLMs) and novel prompting techniques, the framework orchestrates agentic AI workflows to iterate, test, and refine functional exploit and remediation code at scale. While initially intended for defensive and research use, the dual-use nature of Raptor means malicious actors could similarly employ it to accelerate exploit development or enable broader, automated vulnerability discovery across cloud and on-prem environments. The release of the Raptor Framework highlights urgent concerns around weaponized AI and the rapid democratization of advanced cyber capabilities. Security leaders must act now, as similar agentic LLM tools could fuel faster attack cycles, strain patching processes, and escalate regulatory scrutiny around software security and responsible AI use.
6 months ago
Kill Chain
How Iran's MuddyWater APT Used Memory-Only Malware for Stealthy Espionage in 2024
In early 2024, the Iranian state-backed actor MuddyWater significantly evolved its tradecraft by deploying a new memory-only loader, codenamed Fooder, and the stealthy 'MuddyViper' backdoor in espionage campaigns. The group, previously known for noisy operations, shifted to fileless malware and in-memory tactics targeting government and critical infrastructure networks in the Middle East and beyond. These attacks enabled extended persistence, facilitated lateral movement, and were effective at evading traditional endpoint detection and response solutions. As a result, targeted organizations faced serious risk of data theft and operational compromise before the campaign was exposed by security researchers. This incident marks a growing trend of threat actors adopting advanced memory-only and fileless TTPs to avoid detection. The operational upgrade by MuddyWater highlights increased sophistication among nation-state adversaries and reinforces the urgent need for advanced threat detection and stronger east-west network controls.
6 months ago
Kill Chain
University of Pennsylvania Data Breach Highlights ERP Security Risks in Higher Ed
In August 2024, the University of Pennsylvania confirmed that attackers infiltrated its Oracle E-Business Suite (EBS) systems, resulting in the theft of documents containing sensitive personal information. The breach, which was disclosed after internal investigations, leveraged vulnerabilities in Oracle EBS servers, a critical system for managing finances, supply chains, and human resources, enabling threat actors to compromise and exfiltrate sensitive employee and institutional data. Although the University has taken remediation steps and notified those affected, the attack underscores ongoing risks within higher education due to reliance on complex, legacy ERP platforms and the attractiveness of academic institutions as targets. This incident comes amidst a broader surge in attacks exploiting unpatched ERP systems, highlighting persistent gaps in internal segmentation and the monitoring of east-west traffic. As higher education faces increased regulatory and ransomware pressures, this breach serves as a warning of the urgent need for robust visibility, policy enforcement, and modernized security postures.
6 months ago
Kill Chain
Fake Calendly Invites Target Top Brands to Hijack Business Ad Accounts
In mid-2024, a sophisticated phishing campaign leveraged fake Calendly invitation emails to impersonate established brands such as Unilever, Disney, MasterCard, LVMH, and Uber. The attackers crafted convincing lures to target business users and administrators, aiming to harvest credentials for Google Workspace and Facebook Business accounts. Victims who clicked malicious links were redirected to lookalike phishing pages designed to steal login data, potentially enabling unauthorized access to digital ad campaigns, sensitive corporate data, and financial assets. The tactics combined brand impersonation, social engineering, and business workflow subversion, which heightened trust and success rates for attackers. This incident underscores the growing risks of identity-driven attacks that target business SaaS platforms, as cybercriminals increasingly exploit collaboration tools to penetrate defenses. Such phishing methods continue to evolve, challenging traditional detection and user awareness while putting critical business operations at risk.
6 months ago
Kill Chain
North Korea’s 2024 IT Identity Rental Scheme: Exposing New Supply Chain Dangers
In 2024, cyber intelligence researchers revealed an elaborate North Korean operation targeting engineers and developers worldwide, luring them to rent out their professional identities for conducting unauthorized IT work. North Korean recruiters posed as legitimate job seekers to obtain accounts, credentials, and background checks from unsuspecting professionals, allowing the nation's sanctioned regime to surreptitiously access western technology supply chains and funnel wages into banned state coffers. This campaign created significant risks, enabling North Korea to bypass sanctions, compromise corporate infrastructure, and mask the true origins of its IT contractors within the global tech workforce. This incident highlights a sophisticated continuation of supply-chain compromise methods leveraging social engineering and identity fraud. Recent months have shown a marked increase in similar schemes, illustrating attackers' growing reliance on exploiting human trust, remote work authentication gaps, and the globalized freelance IT marketplace.
6 months ago
Kill Chain
Cybercrime Goes SaaS: The Rise of Crime-as-a-Service in 2024
In early 2024, cybersecurity researchers observed a surge in Crime-as-a-Service (CaaS) operations leveraging a subscription-based model. Attackers now rent access to advanced phishing kits, infostealer logs, Remote Access Trojans (RATs), and one-time password bots on popular chat platforms like Telegram, dramatically lowering the barrier to entry for cybercrime. These CaaS platforms enable even low-skilled actors to execute sophisticated intrusion campaigns targeting organizations across industries, often resulting in credential theft, ransomware outbreaks, and large-scale data breaches. This operational shift has enabled attackers to strike at scale and adapt quickly to new defenses, amplifying business risks and potential regulatory violations. The rise of CaaS signifies a pivotal threat evolution: democratized, on-demand cybercrime. Organizations must now address not just known threat actors, but a growing pool of opportunists leveraging plug-and-play hacking tools. This trend is accelerating, leading to urgent pressures for improved identity controls, network segmentation, and rapid anomaly detection.
6 months ago
Kill Chain
Shai-Hulud 2.0: 2024 NPM Supply Chain Attack Exposes 400,000 Developer Secrets
In June 2024, the 'Shai-Hulud 2.0' campaign executed a large-scale supply chain attack against the JavaScript ecosystem by compromising over 750 packages on the NPM registry. Attackers used malicious dependencies to covertly exfiltrate environment variables and developer secrets to public GitHub repositories, exposing as many as 400,000 authentication credentials and tokens. The attack leveraged automation to rapidly disseminate malware and gather sensitive data from unwitting developers and CI systems, impacting thousands of organizations and potentially enabling downstream breaches. This incident underlines the growing risks of open-source supply chain vulnerabilities and highlights attacker innovation in automated credential harvesting. With supply chain attacks rising and developers relying on public package repositories, proactive controls and zero-trust practices have never been more essential to prevent code-integrity and data-exposure risks.
6 months ago
Kill Chain
Google Fixes 107 Android Vulnerabilities, Including 2 Exploited in the Wild
In June 2025, Google released a critical Android security update addressing 107 vulnerabilities across multiple subsystems, including Framework, System, and third-party vendor components such as Arm, MediaTek, and Qualcomm. Notably, two high-severity Framework vulnerabilities had been exploited in the wild prior to the patch, allowing attackers to potentially bypass defenses, execute code, or gain unauthorized access on unpatched devices. Attackers leveraged these flaws to target unsuspecting Android users before Google issued its advisory and fix, putting millions of devices at risk until users updated their software. This incident highlights the ongoing risk posed by zero-day vulnerabilities in widely used mobile platforms and the rapidity with which sophisticated threat actors exploit unpatched systems. The urgency of timely patching is reinforced, as targeted attacks on mobile users remain an attractive vector for cybercriminals and APT groups alike.
6 months ago
Kill Chain
GlassWorm Returns: 2025 Supply Chain Attack on Developer Tool Extensions
In late 2025, the malicious campaign known as GlassWorm reemerged, infiltrating the Microsoft Visual Studio Marketplace and Open VSX with 24 rogue extensions disguised as legitimate developer tools such as Flutter, React, Tailwind, Vim, and Vue. By impersonating trusted tools, GlassWorm tricked developers into installing compromised extensions containing hidden payloads. Once embedded, these extensions established command-and-control communication over the Solana blockchain and enabled threat actors to perform code exfiltration, credential harvesting, and potentially insert backdoors into enterprise codebases, causing major risks for organizations leveraging these tools in their software supply chain. This incident underscores the ongoing and evolving risk of supply chain attacks targeting popular software development ecosystems. With developers as high-value targets, adversaries are increasingly sophisticated in exploiting marketplaces and open-source repositories to distribute malicious code, highlighting the urgent need for stronger validation, monitoring, and zero trust controls in software development lifecycles.
6 months ago
Kill Chain
Malicious npm Package Outsmarts AI Security Tools in 2024 Supply Chain Breach
In February 2024, researchers identified a supply chain attack leveraging a malicious npm package named eslint-plugin-unicorn-ts-2, published under the guise of a TypeScript extension for ESLint by a user called "hamburgerisland." This package included hidden prompt injections and obfuscated scripts specifically designed to evade detection by AI-driven security scanners. Once integrated into a developer's project, it could execute unauthorized code, exfiltrate data, and potentially propagate laterally within developer environments. The attack highlighted how AI-oriented security tools can be manipulated through adversarial prompts and code concealment, putting countless downstream applications at risk in the dynamic JavaScript/Node.js ecosystem. The incident exemplifies sophisticated adversary adaptation, with attackers now actively engineering open-source supply chain threats to outsmart automated, AI-driven defenses. Organizations relying on package registries and automated code validation face urgent pressure to enhance both technical controls and threat intelligence around third-party dependencies.
6 months ago
Kill Chain
Lazarus APT’s Remote-Worker Ruse: How North Korean Hackers Infiltrated via Trusted IT Contractors
In late 2025, cybersecurity researchers from BCA LTD, NorthScan, and ANY.RUN captured an active infiltration by North Korea’s Lazarus Group (specifically the Famous Chollima division) leveraging remote IT workers implanted in Western organizations. This highly coordinated campaign used the appearance of legitimate remote workers—often hired via freelance and IT staffing platforms—to discreetly gain access to internal systems, exfiltrate sensitive data, and facilitate the deployment of malware directly through trusted accounts. The operation showcased sophisticated methods for circumventing east-west traffic controls and exploiting trusted relationships, posing a direct risk to organizations’ hybrid and cloud environments. This breach exemplifies the quick evolution of nation-state threat actors exploiting global remote work and cloud-native architectures. As the use of remote staff and contractors surges, organizations face mounting pressure to implement zero trust controls and granular segmentation to prevent well-resourced APTs from leveraging trusted credentials for deep access and stealthy lateral movement.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports