Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3666 threat reports
Page 269 of 306

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 32173228 / 3666 reports
Operation Zero Disco: APTs Weaponize Cisco SNMP Flaw to Deploy Linux Rootkits
Impact· low

Operation Zero Disco: APTs Weaponize Cisco SNMP Flaw to Deploy Linux Rootkits

In early October 2025, security researchers uncovered Operation Zero Disco, a targeted cyber campaign leveraging a stack overflow vulnerability (CVE-2025-20352) in Cisco IOS and IOS XE software. Advanced persistent threat (APT) actors weaponized this SNMP flaw to access legacy Cisco networking equipment, deploying covert Linux rootkits and securing long-term persistence on compromised devices. The exploitation enabled attackers to bypass standard defenses, facilitate lateral movement, and maintain undetected access to sensitive east-west network traffic, significantly increasing risk for organizations relying on outdated infrastructure. This incident highlights a growing trend of sophisticated actors exploiting unpatched or unsupported networking systems to achieve deep infrastructure compromise. With the resurgence of supply chain and infrastructure-based attacks, persistent network vulnerabilities demand heightened vigilance, rapid patch adoption, and robust segmentation. Industry-wide, there is mounting urgency to secure critical areas exposed by legacy systems and evolving attacker tactics.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Pwn2Own Ireland 2025: Security Researchers Expose 34 Zero-Day Vulnerabilities
Impact· low

Pwn2Own Ireland 2025: Security Researchers Expose 34 Zero-Day Vulnerabilities

On the first day of Pwn2Own Ireland 2025, security researchers successfully exploited 34 unique zero-day vulnerabilities across a range of enterprise technologies, earning $522,500 in awards. The event, renowned for responsible disclosure and sponsored by leading vendors, demonstrated both the speed and sophistication with which zero-day flaws can be discovered and exploited in widely used software and hardware platforms. While no criminal group was involved (these are sanctioned research efforts), the findings underscore prevailing vulnerabilities in enterprise defenses and often result in rapid product updates and critical security advisories. This incident highlights the ongoing arms race between researchers and vendors to identify and remediate unknown security gaps. The large number of zero-days found in a single day signals both the growing complexity of attack surfaces and the pressing need for automated detection and proactive patching mechanisms across the digital ecosystem.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Inside the LinkPro Linux Rootkit: eBPF Backdoors AWS Cloud in 2025
Impact· medium

Inside the LinkPro Linux Rootkit: eBPF Backdoors AWS Cloud in 2025

In October 2025, security researchers from Synacktiv revealed the discovery of LinkPro, a sophisticated GNU/Linux rootkit targeting AWS-hosted infrastructure. The attackers leveraged advanced eBPF techniques to install two modules: one for stealth, allowing the malware to evade detection, and another granting remote access via specially crafted TCP packets (magic packets). This backdoor enabled threat actors to persist undetected, hide their presence, and maintain control of compromised systems in cloud environments, posing severe risks to the underlying business operations and data confidentiality of affected organizations. This incident highlights the escalating use of kernel-level and cloud-specific attack techniques, exploiting eBPF to bypass traditional defenses. The campaign underscores a growing trend of attackers utilizing cloud-native technologies to achieve stealth and persistence, raising urgent concerns for CISOs overseeing both public cloud and Linux workloads.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(medium)
Read Report
How UNC5142 Hijacked WordPress & Blockchain for Next-Gen Stealer Attacks (2025)
Impact· high

How UNC5142 Hijacked WordPress & Blockchain for Next-Gen Stealer Attacks (2025)

In October 2025, threat actor UNC5142 leveraged compromised WordPress sites to distribute a wave of information-stealing malware using an innovative attack method dubbed 'EtherHiding.' The adversaries abused blockchain-based smart contracts to conceal malicious code, enabling malware such as Atomic Stealer, Lumma, Rhadamanthys, and Vidar to infect both Windows and macOS endpoints. This technique allowed attackers to rapidly update payloads beyond the reach of static blocklists and frequently evade traditional security controls. Victims included a variety of enterprises and individuals, with attackers capitalizing on the popularity and trust of infected WordPress content management platforms. This incident highlights an emerging TTP where blockchain infrastructure is repurposed to enhance delivery persistence and obfuscation for criminal campaigns. The rapid uptake of such blockchain-based methods demonstrates the need for organizations to evolve threat detection and response strategies as attackers diversify beyond conventional web infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Cursor & Windsurf IDEs Hit by 94+ Chromium Vulnerabilities – Supply-Chain Exposure in 2024
Impact· low

Cursor & Windsurf IDEs Hit by 94+ Chromium Vulnerabilities – Supply-Chain Exposure in 2024

In early 2024, security researchers identified that the latest releases of the Cursor and Windsurf integrated development environments (IDEs) were vulnerable to over 94 known and patched security vulnerabilities within the embedded Chromium browser and V8 JavaScript engine. These n-day vulnerabilities exist because the IDEs relied on outdated Chromium builds, exposing users to a range of critical issues, including remote code execution, privilege escalation, and data leakage. The supply-chain nature of the incident means development teams using these IDEs could inadvertently introduce risk across their entire workflow and environments. This incident underscores the persistent risk posed by vulnerable software dependencies and highlights an urgent need for improved supply-chain security. With attackers increasingly targeting development tools for initial access or lateral movement, organizations must re-evaluate their patch management, vendor risk assessments, and layered network protections.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CISA Flags Oracle E-Business Suite SSRF Exploitation: What You Need to Know
Impact· low

CISA Flags Oracle E-Business Suite SSRF Exploitation: What You Need to Know

In June 2024, the Cybersecurity and Infrastructure Security Agency (CISA) confirmed that threat actors exploited a critical Server-Side Request Forgery (SSRF) vulnerability, CVE-2025-61884, in Oracle E-Business Suite. Attackers leveraged this zero-day flaw to gain unauthorized access to internal systems, potentially allowing data exposure or further lateral movement within affected organizations. The vulnerability has since been added to CISA's Known Exploited Vulnerabilities catalog, highlighting active exploitation in the wild and prompting urgent remediation efforts across the private and public sectors. This incident underscores the growing trend of exploiting SSRF flaws in enterprise applications to bypass perimeter controls and facilitate initial access. Regulatory agencies globally are increasing pressure on vendors and businesses to patch critical application vulnerabilities rapidly as attacker sophistication and exploitation speed accelerate.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Critical Command Injection Flaw Found in TP-Link Omada Gateways (2024)
Impact· medium

Critical Command Injection Flaw Found in TP-Link Omada Gateways (2024)

In June 2024, TP-Link disclosed a critical security vulnerability (CVE-2024-5035) affecting several Omada gateway models. The flaw is a pre-authentication operating system command injection that could allow remote, unauthenticated attackers to execute arbitrary commands on vulnerable devices, compromising the integrity and availability of network infrastructure. TP-Link quickly released firmware patches, urging customers to update immediately. This exposure heightened the risk of unauthorized access to internal networks, potentially leading to data breaches, lateral movement, or infrastructure disruption for organizations reliant on impacted Omada devices. The incident underscores an ongoing trend of targeting network infrastructure via supply chain or firmware vulnerabilities, which have become increasingly prevalent as attackers seek to exploit core networking hardware. This highlights the need for vigilant patch management and segmentation in defense strategies, as well as resilience against emerging firmware and gateway attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
North Korean Hackers Employ EtherHiding for Unprecedented Cryptocurrency Heist
Impact· medium

North Korean Hackers Employ EtherHiding for Unprecedented Cryptocurrency Heist

In October 2025, threat group UNC5342—attributed to North Korea—executed an advanced cryptocurrency theft operation by leveraging the novel EtherHiding technique. Attackers embedded malicious code within blockchain smart contracts to distribute malware, evading conventional detection mechanisms. Google Threat Intelligence Group (GTIG) identified this as the first known use of EtherHiding by a state-sponsored actor, resulting in the covert compromise of multiple cryptocurrency platforms and significant asset loss. The incident underscores an evolving trend: nation-state actors are adopting increasingly sophisticated blockchain-based attack methods. With rising blockchain adoption, such TTPs present serious risks for organizations involved in digital assets, regulation, and financial technology.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft Revokes Fraudulent Certificates Exploited by Rhysida Ransomware in 2025 Campaign
Impact· high

Microsoft Revokes Fraudulent Certificates Exploited by Rhysida Ransomware in 2025 Campaign

In June 2025, Microsoft discovered and responded to a sophisticated campaign in which a threat actor known as Vanilla Tempest (also tracked as Storm-0785) fraudulently issued over 200 code-signing certificates. These certificates were leveraged to make malicious files appear legitimate, facilitating the distribution of a fake Microsoft Teams installer that ultimately delivered the Oyster backdoor and deployed Rhysida ransomware across targeted environments. Microsoft quickly moved to revoke all compromised certificates to mitigate the risk and prevent further exploitation by the attackers. The breach highlights the growing sophistication of ransomware groups in leveraging trusted supply chain components for malware delivery. This incident underscores the heightened threat landscape in which adversaries exploit trusted relationships and digital certificates to evade security controls. It also signals an increasing trend of ransomware utilizing living-off-the-land and supply chain abuse techniques, compounding challenges for organizations striving to maintain software integrity and regulatory compliance.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Vidar Stealer 2.0: Infostealer Adopts Multi-threaded Data Theft & Evasion in 2024
Impact· medium

Vidar Stealer 2.0: Infostealer Adopts Multi-threaded Data Theft & Evasion in 2024

In early 2024, the operators behind Vidar Stealer—a notorious malware-as-a-service (MaaS)—released version 2.0, introducing significant upgrades such as multi-threaded data theft and improved evasion techniques. Threat actors are leveraging this new version to accelerate theft of sensitive information, targeting both personal and enterprise environments by deploying the stealer via malicious emails, cracked software, and malvertising. The enhanced capabilities enable Vidar Stealer to exfiltrate data more efficiently and undermine traditional security controls, heightening the risks for organizations that rely on endpoint- or signature-based defenses. This evolution signals a broader trend in infostealer threats, where malware authors are quickly integrating advanced techniques for bypassing detection and maximizing operational speed. Enterprises should expect an uptick in automated, distribution-scale credential and data theft campaigns driven by increasingly sophisticated MaaS offerings like Vidar 2.0.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Researchers Reveal Critical WatchGuard VPN Vulnerability Enabling Device Takeover
Impact· medium

Researchers Reveal Critical WatchGuard VPN Vulnerability Enabling Device Takeover

In October 2025, cybersecurity researchers disclosed a critical vulnerability (CVE-2025-9242, CVSS 9.3) in WatchGuard Fireware devices affecting OS versions 11.10.2 to 11.12.4_Update1 and 12.0. The flaw involved an out-of-bounds write in the VPN functionality, allowing unauthenticated remote attackers to execute arbitrary code. Attackers exploiting this bug could gain full control of affected appliances, potentially intercepting encrypted traffic, moving laterally within networks, or establishing persistent access. Patches were released urgently, but some organizations may remain exposed due to delayed patching or legacy hardware. This incident highlights ongoing attacker targeting of perimeter and VPN infrastructure. With rising reliance on remote access, vulnerabilities in widely deployed appliances continue to provide high-value entry vectors. Timely patching and layered network defenses are essential in light of increased regulatory scrutiny and sophisticated threat landscapes.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
North Korean APT Combines BeaverTail and OtterCookie in Major 2025 JS Malware Campaign
Impact· low

North Korean APT Combines BeaverTail and OtterCookie in Major 2025 JS Malware Campaign

In October 2025, a North Korean state-sponsored hacking group with ties to the Contagious Interview campaign was observed integrating features from its BeaverTail and OtterCookie malware into a sophisticated new JavaScript-based attack. Security research from Cisco Talos revealed the group’s evolving approach: combining credential theft, evasion, and persistent access in targeted spear-phishing campaigns directed at global enterprises, which enabled stealthy lateral movement and prolonged network compromise. Analysis showed that this fusion malware increased the attackers’ efficiency and resilience, leading to significant data exposure risks and operational disruptions for affected organizations. This incident highlights a broader trend—North Korean APTs are rapidly developing multipurpose malware platforms capable of bypassing traditional defenses. The blending of well-established tools signals a new level of technical maturity, raising the urgency for organizations to shore up east-west traffic security, zero trust segmentation, and advanced threat detection controls.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports