✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Dutch Police Dismantle Bulletproof Hosting Platform Backing Global Cybercrime in 2024
In May 2024, Dutch police executed a large-scale operation seizing approximately 250 servers linked to a notorious bulletproof hosting provider, long used by cybercriminals to anonymously deploy malware, phishing sites, and command-and-control infrastructure. With coordinated assistance from international partners, Dutch law enforcement dismantled the physical hosting environment and arrested several individuals believed to be operators of the service. This action disrupted ongoing criminal campaigns, significantly hindering multiple ransomware groups, credential theft operations, and other cybercrime syndicates that relied on the provider’s infrastructure to evade detection and takedown efforts worldwide. This takedown comes amid increased law enforcement focus on infrastructure-level cybercriminal enablers, highlighting a shift from targeting individual attackers to undermining the technical ecosystems that fuel large-scale cyber threats. The collapse of this hosting service may cause short-term disruption to criminal activity, but also signals growing regulatory and legal scrutiny on infrastructure managed for malicious purposes.
6 months ago
Kill Chain
RondoDox Botnet Turns XWiki Flaw into Malware Launchpad in 2025
In June 2025, the RondoDox botnet began exploiting a critical remote code execution (RCE) vulnerability tracked as CVE-2025-24893 in the widely used XWiki platform. Threat actors leveraged this zero-day flaw to gain unauthorized control of vulnerable servers, rapidly conscripting them into a growing botnet for malicious purposes, including distributed denial-of-service (DDoS) attacks and potential data theft. Victims included enterprises and service providers relying on exposed or poorly-secured XWiki installations, with incident response teams rushing to contain infections and patch affected systems. This incident exemplifies the increasing sophistication of botnets that exploit newly-disclosed vulnerabilities, highlighting persistent risks to organizations running unpatched collaborative or CMS platforms. The trend underscores an urgent need for proactive vulnerability management, robust segmentation, and real-time traffic monitoring.
6 months ago
Kill Chain
Fortinet FortiWeb Admin Bypass Flaw Fuels 2025 Breach Wave
In November 2025, Fortinet's FortiWeb Web Application Firewall was discovered to be vulnerable to a critical authentication bypass flaw that was actively exploited in the wild. Threat actors leveraged the vulnerability—patched silently by Fortinet—to create unauthorized admin accounts, gaining immediate and unrestricted control over affected devices. This allowed attackers to compromise the integrity and security of network environments relying on FortiWeb for defense. The flaw's exploitation was widespread and indiscriminate, affecting organizations across various sectors, putting their web applications and sensitive data at high risk through privilege escalation and configuration manipulation. The FortiWeb incident highlights an ongoing trend of targeting security infrastructure, particularly via authentication bypass flaws. With attackers capitalizing on delays in patch adoption and the exposure of edge security devices, organizations must rapidly address such vulnerabilities or risk severe breaches. This event accentuates the urgent need for continuous threat monitoring and timely patching as the threat landscape evolves towards sophisticated, identity-driven compromises.
6 months ago
Kill Chain
Ransomware at a Breaking Point: 85 New Gangs and LockBit’s 2025 Re-Emergence
In Q3 2025, the ransomware threat landscape reached unprecedented fragmentation with 85 active ransomware and extortion groups, including the high-profile resurgence of LockBit following international law enforcement takedowns. Attackers targeted organizations across sectors, leveraging decentralized affiliate models to rapidly launch new ransomware 'brands' — 14 of which debuted this quarter. Tactics included sophisticated lateral movement, exploit of unencrypted east-west traffic, and multifaceted extortion through leak sites. Over 1,590 public victim disclosures underscored the sustained operational tempo, with significant financial and reputational losses reported by victims. This incident signals new urgency for defenders, as ransomware operations grow increasingly resilient and adaptive. The proliferation of new actor groups, coupled with a strong affiliate network and advanced techniques, means that traditional prevention strategies are being routinely bypassed, demanding adoption of modern security controls aligned to emerging frameworks and zero trust principles.
6 months ago
Kill Chain
Chinese State Hackers Weaponize Anthropic AI in Automated 2025 Espionage Campaign
In September 2025, state-sponsored Chinese cyber actors launched a highly automated espionage campaign leveraging artificial intelligence technology developed by Anthropic. The attackers exploited the 'agentic' capabilities of advanced AI systems, automating reconnaissance, payload development, and intrusion execution at a scale not previously observed. Attack vectors included automating phishing, adaptive malware payloads, and real-time east-west movement within compromised enterprise networks. The campaign resulted in significant data exfiltration from several multinational organizations, exposing sensitive proprietary information and triggering high-level security responses. This incident marks a turning point in offensive cyber operations, as AI-driven, autonomous attacks blur the line between traditional human-led tactics and machine-accelerated campaigns. Organizations face urgent pressure to redesign controls that address rapidly evolving AI-based threats that often outpace traditional detections and response frameworks.
6 months ago
Kill Chain
Dragon Breath Breaches Defenses: RONINGLOADER Deploys Gh0st RAT in Sophisticated 2025 Attack
In November 2025, the threat actor group known as Dragon Breath launched a targeted cyber campaign aimed at Chinese-speaking users, leveraging a sophisticated multi-stage loader called RONINGLOADER. By deploying trojanized NSIS installers disguised as popular applications like Google Chrome and Microsoft Teams, attackers successfully delivered a modified variant of Gh0st RAT. The malware chain allowed adversaries to bypass security tools, perform covert surveillance, and remotely exfiltrate sensitive data from compromised systems, achieving persistent access and extensive control over infected endpoints. This incident highlights the increasing use of advanced loader chains and tailored social engineering vectors to breach defenses. It reflects a broader trend in cyber threats shifting towards multi-stage, modular attacks capable of disabling endpoint protections and evading detection through highly customized payloads and targeted distribution tactics.
6 months ago
Kill Chain
How ClickFix-Driven EVALUSION Attacks Delivered Amatera Stealer and NetSupport RAT in 2025
In June 2025, a threat campaign tracked as 'EVALUSION' leveraged sophisticated ClickFix social engineering lures to distribute the Amatera Stealer and NetSupport RAT. Cybersecurity researchers observed the attackers primarily targeting organizations through crafted phishing emails and malicious web downloads, enticing victims to execute payloads. Once inside, Amatera Stealer—an evolution of previous AcridRain infostealer variants—exfiltrated credentials and system information, while NetSupport RAT enabled persistent remote control. This resulted in a significant compromise of sensitive data and elevated risks of follow-on attacks, including lateral movement and further intrusions across corporate networks. This incident highlights the rapid professionalization and diversification of infostealer toolkits. The growing adoption of ClickFix social engineering and commodity remote access tools by organized threat actors magnifies data exposure and regulatory risks, especially as hybrid and multi-cloud attack surfaces expand.
6 months ago
Kill Chain
Microsoft Patch Tuesday November 2025: Zero-Day & Critical Vulnerabilities Impact Enterprise Security
In November 2025, Microsoft released patches to address over 60 vulnerabilities affecting Windows operating systems and a broad suite of its applications, including Office, SQL Server, Visual Studio, and Azure Monitor Agent. Notably, this cycle contained at least one actively exploited zero-day flaw (CVE-2025-62215), a memory corruption vulnerability requiring local access, as well as a critical GDI+ bug (CVE-2025-60274) impacting broad swathes of enterprise and third-party applications. Additionally, a low-complexity Office vulnerability (CVE-2025-62199) enabling remote code execution was highlighted as a high priority for patching. Some users also faced complications enrolling in an extended Windows 10 security update program, partially addressed by out-of-band releases. This incident underscores the ongoing acceleration of zero-day and high-impact vulnerabilities targeting ubiquitous enterprise software, making timely patch deployment mission-critical. As the cadence and exploitation of software vulnerabilities increases, organizations must bolster patch management processes and align with evolving regulatory pressures to minimize risk exposure.
6 months ago
Kill Chain
Fortinet 2025: Multi-Vector AI Campaign Disrupts Global Networks
In early November 2025, a coordinated multi-vector campaign targeted Fortinet infrastructure worldwide, exploiting unpatched vulnerabilities in FortiGate VPN appliances. Attackers—some with ties to Chinese state-affiliated threat groups—combined AI-driven phishing-as-a-service (PhaaS) toolkits, malicious code deployment, and supply chain manipulation to bypass legacy perimeter defenses. The campaign leveraged trusted encrypted channels and cloud infrastructure to evade detection, enabling lateral movement and data exfiltration from government agencies, finance firms, and Fortune 500 companies. Cleanup and containment efforts required full infrastructure reviews and forensic triage, disrupting operations across multiple sectors. This incident exemplifies the accelerating convergence of advanced attacker automation, trusted-tool abuse (AI, VPNs), and commercial cybercrime platforms. Organizations must urgently address gaps in segmentation, encrypted traffic inspection, and detection controls to withstand increasingly stealthy, multi-stage attacks.
6 months ago
Kill Chain
Fortinet FortiWeb WAF Zero-Day Breach: 2024 Vulnerability Exposes Perimeter Defenses
In early June 2024, Fortinet disclosed a critical remote code execution (RCE) vulnerability in its FortiWeb Web Application Firewall (WAF). Identified as CVE-2024-21762, this zero-day bug enables unauthenticated attackers to remotely execute administrative commands on affected WAF devices via specially crafted HTTP requests. Threat actors were observed actively exploiting the flaw in the wild before the vendor released patches, allowing them to potentially compromise sensitive networks, bypass perimeter defenses, and gain high-privilege access to protected applications. Burdened by the high privilege level of administrative access, compromised systems are exposed to data theft, operational disruption, or lateral movement within enterprise networks. The incident highlights an ongoing surge in zero-day exploitation of critical infrastructure solutions, particularly targeting network perimeter and cloud security devices. Preliminary evidence suggests opportunistic attackers and advanced persistent threats are both involved, driving renewed urgency for timely patching, actionable threat detection, and Zero Trust strategies across enterprise and cloud environments.
6 months ago
Kill Chain
Cursor Vulnerability: AI Code Assistant Supply-Chain Flaw Exposes Credentials
In early 2024, security researchers uncovered a significant supply-chain vulnerability affecting Cursor, an AI-powered coding assistant, enabling attackers to hijack Cursor's internal application browser via a malicious MCP (Model Control Protocol) server. Exploiting this weakness, threat actors could inject malicious code through the compromised server, control the tool’s browser processes, and steal sensitive user credentials, potentially jeopardizing developer environments and broader organizational security. The vulnerability allows attackers to manipulate trusted workspace sessions, escalating the risk of lateral movement within corporate infrastructure. This incident highlights the increasing risks associated with AI-driven developer tools and the broader supply chain, reflecting a growing attacker focus on abusing trust relationships within cloud-native and collaborative software platforms. Organizations must revisit supply-chain security and adopt robust detection and response strategies for AI-enabled environments.
6 months ago
Kill Chain
US Citizens Busted for Aiding North Korean IT Worker Supply-Chain Fraud in 2024
In 2024, four United States citizens pleaded guilty to helping North Korean nationals surreptitiously secure IT positions at American companies by misrepresenting the workers’ identities and providing remote access to corporate assets. This insider-assisted scheme enabled foreign IT professionals to bypass typical background checks and compliance controls, giving them potential access to sensitive information and intellectual property. The activities ran over a sustained period and leveraged supply-chain weaknesses in remote workforce onboarding and equipment provisioning, ultimately exposing numerous U.S. firms to regulatory and operational risk. This incident underscores a worrying trend in which threat actors exploit remote work arrangements, weak identity verification protocols, and gaps in third-party management—highlighting increased regulatory scrutiny on supply-chain and insider vulnerabilities, especially amid ongoing geopolitical tensions involving North Korea.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports