✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Kerberoasting in 2025: Service Account Risks and Zero Trust Imperatives
In early 2025, a significant cyber incident occurred in which attackers leveraged Kerberoasting techniques to compromise Active Directory (AD) environments. Threat actors exploited weakly protected service accounts to request service tickets, subsequently brute-forcing their encrypted credentials offline. This attack method enabled them to escalate privileges and potentially gain domain administrator access, often without triggering security alerts. The intrusion highlighted shortcomings in credential hygiene, detection capabilities, and adherence to modern encryption standards within corporate IT infrastructures. Operational impacts included increased risk of lateral movement, data exfiltration, and potential business disruption had the attackers established persistent access. Kerberoasting attacks have become more prevalent due to their stealthy nature and the widespread reliance on legacy authentication protocols. As organizations accelerate digital transformation and adopt zero trust models, identity-based threats like these place added emphasis on proactive credential management, monitoring, and compliance with encryption regulations.
6 months ago
Kill Chain
The Washington Post Oracle Supply Chain Breach: Lessons on Third-Party Risk in 2024
In June 2024, The Washington Post began notifying nearly 10,000 employees and contractors that their personal and financial information had been exposed following a breach involving Oracle-managed systems. The incident stemmed from an attack on a third-party vendor, believed to be tied to the widespread theft of cloud-stored data, which granted unauthorized access to sensitive HR and payroll details. The compromise was discovered post-incident, and affected individuals include current and former staff spanning back several years. Although there is no evidence of active misuse, the breach has prompted heightened security reviews. This breach exemplifies escalating risks inherent in supply-chain and third-party systems, with attackers increasingly targeting service providers to access large pools of critical enterprise data. Organizations across all sectors are now under pressure to strengthen controls around third-party integrations to reduce exposure.
6 months ago
Kill Chain
Akira Ransomware Targets Nutanix AHV Linux VMs: 2024 Attack Analysis
In early 2024, threat actors associated with the Akira ransomware group expanded their operations to target Nutanix AHV virtual machines (VMs) running on Linux, according to alerts from CISA and other cybersecurity agencies. By leveraging compromised credentials or exploiting vulnerabilities, attackers gained access to enterprise infrastructure and deployed a Linux-based Akira encryptor capable of encrypting entire Nutanix VM environments. This strategy disrupted critical workloads and led to significant operational downtime, as well as potential data loss and extortion threats for affected organizations. This incident underscores a trend of ransomware groups shifting focus toward virtualization platforms and cloud infrastructure, extending risks beyond traditional endpoints. The Akira campaign highlights the growing sophistication of ransomware TTPs and the urgent need for robust segmentation and lateral movement controls within virtualized environments.
6 months ago
Kill Chain
IndonesianFoods npm Worm Floods Registry with 100,000 Packages in Major Supply Chain Incident
In June 2024, the npm package ecosystem was targeted by a self-propagating malware dubbed the 'IndonesianFoods' worm. The worm exploited npm’s open publishing model, rapidly flooding the registry with nearly 100,000 malicious, junk packages at a rate of one every seven seconds. Working autonomously, the malware replicated itself using pre-programmed scripts, creating an unprecedented scale of package spam, which overwhelmed the registry, threatened package discovery, and disrupted normal operations for developers worldwide. No evidence so far points to direct compromise of sensitive data or targeted attacks on organizations, but the overwhelming volume affected the trust and stability of the npm supply chain platform. This event spotlights the vulnerability of open-source ecosystems to automated spam and self-replicating threats, underscoring the growing risk in software supply chains from both criminal and experimental actors. The surge in npm-focused attacks amplifies calls for stronger package validation, improved security automation, and supply-chain controls industry-wide.
6 months ago
Kill Chain
Flood of Fake npm Packages Reveals Growing Supply Chain Attack Risk
In early 2024, a financially-motivated threat actor orchestrated a large-scale spam campaign that flooded the npm package registry with over 67,000 fake packages. By systematically publishing malicious and junk modules, the actor exploited npm’s open nature, allowing the fake packages to persist on the platform for nearly two years. These packages, often uploaded with auto-generated names and code, increased risks for developers by inflating dependency confusion attack surfaces and potentially delivering malware through the software supply chain. The incident underscored ongoing challenges in detecting and mitigating large-scale abuse within open-source ecosystems, disrupting trust and reliability for countless organizations relying on npm. This attack is emblematic of a wider trend in software supply-chain targeting, with threat actors increasingly exploiting public repositories to propagate malicious code or disrupt developer workflows. As software supply chains remain a critical risk focal point, organizations face mounting regulatory scrutiny and require robust governance and anomaly detection controls to safeguard development environments.
6 months ago
Kill Chain
Inside the Cisco 2025 Multi-Vector Breach: 0-Days, State Actors, and Encrypted Threats
In November 2025, Cisco experienced a sophisticated multi-vector cyberattack that leveraged previously unknown zero-day vulnerabilities across its networking equipment. Attackers combined techniques such as encrypted traffic evasion, lateral movement, and zero-trust segmentation bypasses, using advanced tools to avoid detection and compromise both east-west and north-south flows. The intrusion enabled threat actors—suspected of state affiliation—to exfiltrate internal data, disrupt encrypted hybrid connections, and potentially impact customer networks on a global scale before the breach was identified and contained. This incident highlights an emerging trend: attackers are orchestrating multiple, layered techniques to exploit evolving environments, such as hybrid and multi-cloud infrastructure. As organizations rely on AI-driven security and expand east-west traffic, defenders face increased complexity, raising the urgency for integrated, visibility-rich, and compliance-driven zero trust architectures.
6 months ago
Kill Chain
CISA Flags Critical WatchGuard Fireware Flaw: 54,000 Fireboxes at Risk from Unauthenticated Attacks
In November 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-9242, a critical out-of-bounds write vulnerability in WatchGuard Fireware OS, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. Attackers leveraged this flaw—rated CVSS 9.3—to gain unauthenticated remote access to over 54,000 exposed WatchGuard Firebox appliances worldwide, enabling potential system compromise and lateral network movement. The vulnerability affects Fireware OS versions 11.10.2 through recent releases, putting a significant number of network security devices at risk. This incident highlights the urgent need for aggressive patching and improved visibility into network infrastructure exposures. With attackers increasingly targeting edge devices and exploiting unpatched vulnerabilities, organizations must prioritize vulnerability management and zero trust network segmentation to contain emerging threats.
6 months ago
Kill Chain
Operation Endgame 2025: Law Enforcement Disrupts Rhadamanthys, Venom RAT, and Elysium Botnet
Between November 10 and 13, 2025, international law enforcement agencies led by Europol and Eurojust conducted Operation Endgame, a sweeping crackdown targeting malicious cyber infrastructures. The operation succeeded in dismantling key components of the Rhadamanthys Stealer, Venom RAT, and Elysium botnet, disrupting networks that facilitated global credential theft, remote access, and command-and-control activities. The coordinated seizures involved simultaneous server takedowns across multiple countries and the arrest of key individuals behind these malware operations, significantly diminishing the power and reach of these cybercriminal networks. This incident highlights an increasing trend of robust international cooperation in targeting advanced malware and botnet ecosystems. The disruption of these criminal infrastructures sends a strong message to threat actors, demonstrating both the technical capabilities and resolve of law enforcement to combat cybercrime at scale.
6 months ago
Kill Chain
When Vulnerabilities Strike at Machine Speed: The 2026 Supply Chain Attack
In early 2026, a sophisticated global supply chain attack exploited vulnerabilities in widely used software components just hours after new CVEs were publicly disclosed. Threat actors weaponized exploit code at unprecedented speed, targeting unpatched enterprise systems across cloud, hybrid, and on-prem environments. The adversaries leveraged compromised update channels and lateral east-west movement to deploy malicious payloads, exfiltrate data, and disrupt critical services. Businesses faced operational downtime, data loss, and compliance exposures as traditional patch cycles failed to keep pace with machine-speed attacks. This breach underscores how the rapid turn from vulnerability disclosure to global exploitation has become a defining security risk. The event highlights the urgent need for automation, zero trust segmentation, and machine-speed threat detection to mitigate threats that now outpace human-led response.
6 months ago
Kill Chain
Malicious ‘Safery’ Chrome Extension Steals Ethereum: Anatomy of a 2025 Infostealer Attack
In November 2025, cybersecurity researchers identified a malicious Chrome extension named "Safery: Ethereum Wallet," which masqueraded as a legitimate cryptocurrency management tool but was designed to steal users' Ethereum wallet seed phrases. The extension was covertly uploaded to the Chrome Web Store, targeting unsuspecting cryptocurrency holders by promising enhanced security and flexible settings. After users entered their wallet credentials, the extension exfiltrated sensitive seed phrases via transactions on the Sui blockchain, effectively enabling attackers to compromise and drain user wallets. The incident rapidly gained attention due to its stealthy distribution and use of decentralized channels for data exfiltration. This breach underscores a growing trend of sophisticated infostealers leveraging browser extensions and blockchain-based exfiltration routes to exploit gaps in endpoint and cloud application security. The persistent evolution of phishing and credential theft tactics increases regulatory pressure and demands more robust zero trust and egress policy enforcement across digital ecosystems.
6 months ago
Kill Chain
Russian Hackers Create 4,300 Fake Travel Sites to Phish Hotel Guests
In early 2025, a Russian-speaking threat group orchestrated a widespread phishing campaign targeting the hospitality sector by registering over 4,300 fraudulent travel and hotel websites. Posing as legitimate booking platforms, the attackers lured hotel guests via persuasive spam emails, harvesting sensitive payment data and personal information from unsuspecting travelers. The threat actor leveraged sophisticated domain registration strategies and rapid site turnover to evade detection, resulting in a significant exposure of financial data and reputational harm to both guests and affected hospitality brands. This incident signals an ongoing trend of highly targeted phishing operations in the travel industry, exploiting the surge in online bookings and trust in familiar brand identities. The campaign underscores the critical need for advanced threat detection, greater scrutiny of online domains, and robust security awareness for organizations and their customers.
6 months ago
Kill Chain
2024 Salesloft-Drift Supply Chain Breach: AWS Credential Exposure and Cloud Security Lessons
In early 2024, a sophisticated supply chain attack targeted the Salesloft and Drift integration, leading to the compromise of AWS credentials and unauthorized access to cloud environments. Threat actors exploited weaknesses in the integration pipeline, leveraging exposed secrets to move laterally and access sensitive customer data before the breach became public. Red Canary detected anomalous cloud activity tied to this attack, providing early detection prior to broad public awareness and response, thereby helping to mitigate further impact. This incident is significant as it demonstrates the growing frequency and sophistication of supply chain attacks within SaaS and cloud services, especially those exploiting secret leaks and third-party application integrations. The breach highlights the need for heightened vigilance, identity and credential protection, and advanced threat detection capabilities in the cloud ecosystem.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports