✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Sanctions Hit Russian Bulletproof Hosting Providers Backing Global Ransomware
In June 2024, the United States, together with the United Kingdom and Australia, imposed sanctions on Russian bulletproof hosting provider Media Land and associated entities. Investigations revealed these providers had knowingly facilitated ransomware operations and other cybercriminal activities by offering infrastructure shielding malicious actors from law enforcement, particularly ransomware gangs operating out of Russia. The sanctions block their financial assets and prohibit transactions, aiming to disrupt the ecosystem supporting high-profile global ransomware attacks and cybercrime. This incident is significant amid a surge in ransomware and supply-chain attacks worldwide, with threat actors increasingly relying on bulletproof hosting to evade detection. Governments are moving quickly to cut off these enablers as part of a broader strategy against organized cybercrime.
6 months ago
Kill Chain
Phishing-as-a-Service Evolves: Sneaky2FA Adds Browser-in-the-Browser Attacks in 2024
In early June 2024, cybersecurity researchers reported that the Sneaky2FA phishing-as-a-service (PhaaS) kit has adopted the Browser-in-the-Browser (BitB) attack tactic, previously used by red teamers, to improve the effectiveness of credential phishing campaigns. This new feature enables threat actors using the Sneaky2FA service to launch highly convincing fake login pop-ups, closely mimicking legitimate authentication flows, including prompts for multifactor authentication (MFA). The update broadens the risks for both organizations and individuals, as traditional indicators of phishing are increasingly hard to spot. The deployment of BitB tactics by a turnkey phishing kit marks a concerning development in the automation and commercial accessibility of advanced cybercrime techniques. This incident underscores the escalating sophistication of phishing attacks driven by the commoditization of offensive security techniques. Organizations face renewed urgency to revisit their authentication controls, user awareness training, and phishing-resistant MFA, as adversary innovation quickly outpaces conventional defense measures.
6 months ago
Kill Chain
FortiWeb CVE-2025-58034: Command Injection Attack on Fortinet's WAF
In November 2025, Fortinet disclosed a medium-severity vulnerability in its FortiWeb application firewall, tracked as CVE-2025-58034 (CVSS 6.7), which was found exploited in the wild. The flaw is an OS command injection issue (CWE-78) that allows authenticated attackers to execute unauthorized OS commands via improper neutralization of special elements. Attackers leveraged this weakness to gain control over vulnerable web application environments, potentially facilitating lateral movement, data access, and further exploitation, with threat activity detected before a patch was widely adopted. This incident highlights a persistent trend of attackers rapidly weaponizing new vulnerabilities in widely deployed web application security platforms. With adversaries increasingly targeting edge appliances and exploiting authentication weaknesses, organizations must prioritize timely vulnerability management and layered defense to protect sensitive workloads.
6 months ago
Kill Chain
Ransomware Disrupts European Airports in 2025: HardBit & SonicWall VPN Exploit
In September 2025, a coordinated HardBit ransomware attack caused significant operational disruptions across several European airports. The attack exploited a vulnerability in SonicWall SSL VPN devices (CVE-2024-40766), allowing threat actors to bypass multi-factor authentication and gain unauthorized access to critical infrastructure. Prompt law enforcement action led to the arrest of an initial suspect by the UK’s National Crime Agency, though details remain limited as investigations continue. The attack, labeled by researchers as primitive yet effective, underscores how quickly threat actors are leveraging both publicly available exploits and compromised credentials to disrupt essential services with ransomware. This event made headlines due to its impact on vital transportation infrastructure and prompted an international response highlighting the growing urgency for robust network segmentation, encrypted traffic measures, and rapid threat detection. The incident also reflects a broader trend of ransomware actors increasingly targeting critical sectors using innovative entry vectors and expanding their global footprint.
6 months ago
Kill Chain
Mobile Malware Soars in Q3 2025: Key Insights from Kaspersky's Global Report
In Q3 2025, Kaspersky reported a significant surge in mobile malware activity, with 47 million attacks prevented globally targeting Android devices with Trojans, adware, banking malware, and ransomware. Threat actors exploited new variants—including BADBOX and sophisticated Trojans like Triada and Fakemoney—utilizing methods such as pre-installed backdoors and malicious app mods. Mobile banking Trojans (especially Mamont and Coper) and region-targeted malware attacks in Turkey, India, Iran, and Germany impacted financial data security and user privacy, highlighting expanding attacker sophistication and supply chain compromise. This incident is critical as it illustrates the rising prevalence and complexity of mobile threats, coinciding with increased ransomware attacks and evolving delivery channels. The continued targeting of financial apps and global user bases signals an urgent need for organizations to strengthen mobile security, visibility, and compliance with privacy mandates.
6 months ago
Kill Chain
ServiceNow AI Agents Breached in 2025 via Second-Order Prompt Injection
In November 2025, security researchers uncovered a novel method by which ServiceNow's Now Assist generative AI platform could be manipulated through second-order prompt injection attacks. By exploiting default configurations and inherent agent-to-agent communication, attackers could coerce agentic AI features into executing unauthorized operations. This exposure allowed malicious actors to access, copy, and exfiltrate sensitive enterprise data without proper user authorization. The attack leverages prompt injection to bypass intended policy boundaries, posing significant data risk to organizations relying on ServiceNow’s AI-driven automations. This incident highlights a growing threat landscape in which AI agent-to-agent interactions are harnessed for sophisticated attacks. With increased enterprise adoption of generative AI and autonomous agents, security around configuration and prompt validation has become mission-critical. Organizations should assess agent communication safeguards and be vigilant against emerging prompt injection and shadow AI risks.
6 months ago
Kill Chain
EdgeStepper: PlushDaemon’s DNS Hijack Shakes Supply Chain Trust
In late 2025, the threat actor PlushDaemon leveraged a custom Go-based implant named EdgeStepper to facilitate a sophisticated supply chain attack targeting organizations relying on automated software updates. By hijacking DNS queries via EdgeStepper, attackers rerouted legitimate update traffic to attacker-controlled infrastructure, covertly delivering malware payloads. This adversary-in-the-middle campaign exploited a weakness in outbound traffic validation and DNS trust, leading to silent compromise of enterprise endpoints through poisoned software update mechanisms. The incident resulted in widespread concerns over supply chain integrity and exposed gaps in security monitoring of encrypted or internal network flows. This incident highlights the growing trend of adversaries exploiting DNS and software supply chains as primary attack vectors. With regulatory and industry focus tightening on secure update mechanisms and zero trust, similar AitM tactics are escalating in both frequency and sophistication, requiring renewed urgency for organizations to enhance detection at the DNS and network boundary layers.
6 months ago
Kill Chain
Operation WrtHug: Tens of Thousands of ASUS Routers Hijacked in Global Botnet Surge
In late 2025, tens of thousands of end-of-life ASUS routers worldwide were hijacked in a large-scale operation dubbed "WrtHug." The attackers exploited six unpatched vulnerabilities in outdated ASUS WRT firmware, targeting devices primarily in Taiwan, the U.S., and Russia, among others. After gaining unauthorized access, WrtHug actors enrolled these routers into a global botnet, leveraging them for coordinated command-and-control traffic and potentially for further attacks. The campaign highlighted the sustained risk posed by unsupported network equipment in both consumer and business environments. This incident underscores an ongoing surge in attacks targeting aging and end-of-life IoT devices, as cybercriminals capitalize on lapses in patching and lifecycle management. Organizations globally are under renewed pressure to inventory, segment, and securely retire vulnerable network infrastructure as such botnet tactics intensify.
6 months ago
Kill Chain
NHS Flags PoC Exploit for 7-Zip Symlink RCE Vulnerability (CVE-2025-11001)
In November 2025, NHS England Digital issued an advisory regarding a significant vulnerability (CVE-2025-11001) in the popular 7-Zip compression software. While no active in-the-wild exploitation was detected, a publicly available proof-of-concept (PoC) exploit for a symbolic link–based remote code execution (RCE) flaw raised concerns of imminent risk. The flaw, if exploited, could allow attackers to execute arbitrary code on systems using 7-Zip, threatening the confidentiality, integrity, and availability of healthcare data critical to NHS operations. Security teams were urged to prioritize patching and closely monitor for suspicious activity. This incident highlights a broader industry trend: attackers are rapidly weaponizing PoC exploits for newly disclosed vulnerabilities, targeting widely used utilities to enable lateral movement and privilege escalation. The urgency of patching and proactive threat detection has never been greater, especially for organizations in regulated sectors like healthcare.
6 months ago
Kill Chain
WhatsApp Hijack: Eternidade Stealer Campaign Hits Brazilian Users via Python Worm
In November 2025, cybersecurity researchers identified a sophisticated campaign targeting Brazilian users via WhatsApp, where attackers leveraged a Python-based worm combined with social engineering tactics. Victims were tricked into installing a worm that hijacked WhatsApp sessions and propagated itself to contacts, while delivering a Delphi-based banking trojan known as Eternidade Stealer. The campaign exploited IMAP to dynamically resolve command-and-control infrastructure, enabling threat actors to orchestrate info-stealing and credential harvesting at scale and with resilience to takedown attempts. The incident had significant implications for financial fraud and impacted numerous personal and business WhatsApp accounts across Brazil. This campaign is emblematic of a wider surge in malware leveraging messaging platforms for lateral movement and rapid propagation. The popularity of WhatsApp, combined with increasingly modular infostealers and TTP reuse by criminal groups, highlights the urgent need for proactive controls and visibility across both east-west and outbound communication paths.
6 months ago
Kill Chain
Cloudflare 2025 Outage: A Wakeup Call for Web Security Resilience
In November 2025, Cloudflare suffered a significant intermittent outage lasting approximately eight hours, which disrupted access for many major websites relying on its services for security and DNS management. The outage was caused by an internal configuration error that expanded a critical feature file, impacting Cloudflare's Bot Management system and resulting in platform instability. Some organizations temporarily bypassed Cloudflare, exposing themselves directly to internet traffic and revealing vulnerabilities previously shielded by Cloudflare's protective layers, such as web application firewall (WAF), bot filtering, and DNS controls. These exposures led to increased malicious probing, raising concerns about previously undetected weaknesses and an overreliance on single-vendor security solutions. The incident highlights the growing operational and security risks of single-vendor dependency, especially as organizations rely more heavily on integrated cloud platforms for web security and availability. Broad industry adoption of zero trust and multi-cloud strategies is now a pressing priority to mitigate similar service disruptions and emergent threats.
6 months ago
Kill Chain
CISA Flags New Chromium Browser Exploit: CVE-2025-13223 in Active Use
On November 19, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-13223—an actively exploited type confusion vulnerability in the Google Chromium V8 JavaScript engine—to its Known Exploited Vulnerabilities (KEV) Catalog. This flaw allows remote attackers to execute arbitrary code via a crafted web page, exploiting weaknesses in Chromium-based browsers used by federal and commercial entities. Threat actors have been leveraging this vulnerability to deliver malware and potentially gain unauthorized access to systems, heightening risk across government and enterprise environments. This incident is highly relevant as attackers continue to target zero-day and rapidly weaponized browser flaws, reflecting a broader trend of exploiting client-side vulnerabilities to bypass traditional network defenses. Regulatory and industry pressure for rapid patch management and strong endpoint protection is intensifying as attackers' tactics evolve.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports