Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3666 threat reports
Page 272 of 306

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 32533264 / 3666 reports
Microsoft Patches Highest-Severity ASP.NET Core Vulnerability in 2025
Impact· medium

Microsoft Patches Highest-Severity ASP.NET Core Vulnerability in 2025

In October 2025, Microsoft patched CVE-2025-55315—the highest-severity vulnerability ever identified in ASP.NET Core. The flaw, found in the Kestrel web server, allowed authenticated attackers to perform HTTP request smuggling, enabling them to hijack user credentials, bypass security controls, and potentially carry out privilege escalation or injection attacks. The vulnerability exposed sensitive data, permitted internal malicious requests, and in certain scenarios, enabled attackers to compromise integrity and availability by altering server files or forcing crashes. Microsoft responded with urgent patches for multiple ASP.NET Core and Visual Studio versions. The urgency around this incident reflects a rising trend in the exploitation of critical web application vulnerabilities. Such flaws highlight the importance of prompt patch management and robust internal segmentation controls, as sophisticated attacks continue to target application-layer weaknesses for lateral movement and data exfiltration.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Europol Busts Massive SIM-Box Cybercrime Network in 2025
Impact· high

Europol Busts Massive SIM-Box Cybercrime Network in 2025

In October 2025, Europol led a major operation codenamed 'SIMCARTEL' that dismantled an extensive SIM-box network servicing global cybercriminals. The illicit operation spanned multiple countries, employed 1,200 SIM-box devices and 40,000 SIM cards, and provided fake phone numbers for cybercrimes such as phishing, fraud, impersonation, and extortion. Two key websites, gogetsms.com and apisim.com, were seized. Authorities arrested seven suspects, confiscated servers and luxury assets, and froze significant cryptocurrency and bank funds. Investigators linked the service to at least 3,200 fraud cases and a direct financial loss exceeding €4.5 million, with indications the service was used to create over 49 million fraudulent online accounts. This incident underscores a growing trend in Cybercrime-as-a-Service, where sophisticated tools enable large-scale identity obfuscation and fraud. The takedown reflects mounting law enforcement pressure on criminal infrastructure rentals fueling online financial crime, highlighting urgent regulatory and security challenges for organizations reliant on voice and messaging account verification.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Clop Breaches Envoy Air via Oracle EBS Zero-Day in 2025: Key Lessons in Ransomware Defense
Impact· high

Clop Breaches Envoy Air via Oracle EBS Zero-Day in 2025: Key Lessons in Ransomware Defense

In October 2025, Envoy Air, a regional subsidiary of American Airlines, confirmed that attackers compromised business information from its Oracle E-Business Suite (EBS) application. The Clop ransomware/extortion group exploited a newly discovered Oracle EBS zero-day (CVE-2025-61882) to access internal systems in August 2025. Upon discovery, Envoy initiated an investigation, notifying law enforcement and confirming that no sensitive customer or employee data was affected, though limited business and commercial contact details were exposed. This incident underscores the rising trend of ransomware and extortion groups leveraging zero-day vulnerabilities in key enterprise platforms. The Clop gang continues to target multiple industries through advanced attacks on widely used software, emphasizing the urgent need for robust patch management, east-west traffic security, and zero trust segmentation strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
ConnectWise Automate 2025 Vulnerabilities: AiTM & Malicious Update Risks in the Supply Chain
Impact· low

ConnectWise Automate 2025 Vulnerabilities: AiTM & Malicious Update Risks in the Supply Chain

In October 2025, ConnectWise disclosed and patched critical vulnerabilities in its Automate remote monitoring and management platform, widely used by managed service providers (MSPs) and enterprises. The most severe issue (CVE-2025-11492, CVSS 9.6) allowed agents to communicate sensitive information in cleartext over unencrypted HTTP, exposing them to adversary-in-the-middle (AiTM) attacks capable of intercepting or altering management traffic, including credentials and update payloads. A second flaw (CVE-2025-11493, CVSS 8.8) enabled attackers to bypass update integrity checks, facilitating the delivery of malicious software disguised as legitimate updates. Together, these vulnerabilities posed a significant supply chain threat, enabling network-based attackers to compromise customer environments via trusted management channels. This incident underscores the heightened attention on software supply chain vulnerabilities and AiTM risks, particularly among platforms entrusted with privileged access across thousands of customer endpoints. With adversaries increasingly exploiting weak encryption, incomplete update verification, and RMM tool supply chains, organizations must urgently strengthen controls around update validation, encrypted communications, and least privilege management to stay ahead of evolving attacker tactics.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Critical Multi-Vendor Vulnerabilities Exploited in September 2025: Key Lessons for Zero Trust and Compliance
Impact· medium

Critical Multi-Vendor Vulnerabilities Exploited in September 2025: Key Lessons for Zero Trust and Compliance

In September 2025, a wave of critical vulnerabilities across major vendors – including Cisco, TP-Link, Sitecore, and Adminer – were actively exploited by threat actors in high-impact campaigns. Attackers leveraged CVEs such as CVE-2025-20333 and CVE-2025-20362 in Cisco ASA devices to deploy advanced malware (RayInitiator and LINE VIPER), and exploited deserialization flaws in Sitecore (CVE-2025-53690) and Adminer SSRF (CVE-2021-21311) to enable data exfiltration, lateral movement, and persistent control. The vulnerabilities affected a diverse range of enterprise products and cloud platforms, enabling remote code execution and privilege escalation via sophisticated attack chains and, in some cases, public proof-of-concept exploits. This wide-ranging exploitation underscores the growing sophistication of attacker tradecraft and the urgent need for proactive, risk-driven vulnerability management. Given the increasing regulatory and operational impact of such incidents, organizations must prioritize patching, improve detection for abuse of critical CVEs, and strengthen security posture across hybrid environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
SEO Spam Surge: How Hidden Links Threaten Your Website's Reputation in 2025
Impact· high

SEO Spam Surge: How Hidden Links Threaten Your Website's Reputation in 2025

In September 2025, numerous legitimate websites were compromised through the injection of hidden HTML blocks containing SEO spam links, primarily directing to pornographic and gambling domains. Attackers leveraged a variety of entry vectors, including exploited CMS vulnerabilities, compromised administrator credentials, outdated plugins, and insecure website templates, to insert invisible links that manipulated search engine rankings. The result was immediate: affected sites suffered sharp declines in search visibility, loss of reputation, visitor complaints, and in many cases, were misclassified as “Adult content” or “Gambling” by filtering systems. This exposed organizations to both operational and reputational damage, and in some circumstances, to regulatory or legal risks. The attack highlights an ongoing surge in web application compromise driven by automated tools and AI, accelerating the spread and sophistication of black hat SEO tactics. As search engines enhance their detection, attackers are turning to increasingly evasive techniques, stressing the urgent need for organizations to secure website platforms and adopt robust monitoring against such silent intrusions.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
NPM Supply Chain Attack Exposes AdaptixC2 Framework via https-proxy-utils (2025)
Impact· low

NPM Supply Chain Attack Exposes AdaptixC2 Framework via https-proxy-utils (2025)

In October 2025, security researchers discovered a malicious npm package named 'https-proxy-utils' which surreptitiously delivered the AdaptixC2 post-exploitation framework. The package mimicked legitimate proxy utility modules—closely resembling widely used packages like 'http-proxy-agent' and 'https-proxy-agent'—and included a post-installation script designed to download and execute the AdaptixC2 agent based on the victim's operating system. Once deployed, the agent enabled attackers to access infected machines, execute commands, and establish persistence, resulting in potential internal reconnaissance, lateral movement, and elevated risk of data exfiltration for organizations inadvertently including the tainted module in their development pipeline. This incident is emblematic of a rising wave of supply-chain attacks targeting open-source software ecosystems. The use of trusted distribution channels to propagate sophisticated frameworks like AdaptixC2 highlights the necessity for increased scrutiny of third-party software and ongoing vigilance against impersonation tactics in popular package registries.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Zendesk's 2025 Email Bomb: How Lax Authentication Led to Mass Inbox Floods
Impact· high

Zendesk's 2025 Email Bomb: How Lax Authentication Led to Mass Inbox Floods

In October 2025, a campaign exploited insecure ticket creation configurations across hundreds of Zendesk customer accounts, allowing attackers to bombard target inboxes with thousands of emails by abusing anonymous support workflows. Attackers submitted forged support requests via vulnerable Zendesk setups that lacked mandatory user authentication; as a result, victim inboxes were flooded with email notifications that appeared to originate from major brands like NordVPN, The Washington Post, and Discord. This distributed email flood (email bomb) compromised brand integrity, overloaded recipient systems, and created significant disruption for both targeted individuals and the affected organizations, highlighting the dangers of misconfigured application authentication and notification systems. Incidents like this reflect a rising trend in application-layer abuse, where attackers exploit lenient platform defaults and automated workflow triggers to amplify malicious campaigns. As business reliance on cloud-based customer service solutions increases, proper authentication and anti-abuse controls have become critical to both user and organizational protection.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
F5 Breach 2024: Nation-State Actors Steal Source Code and Vulnerabilities
Impact· high

F5 Breach 2024: Nation-State Actors Steal Source Code and Vulnerabilities

In early 2024, F5 Networks suffered a significant security breach attributed to a sophisticated nation-state actor, which resulted in the theft of BIG-IP source code and undisclosed vulnerability details. The attackers leveraged targeted intrusion tactics, exploiting gaps in F5's internal protections to gain access to proprietary codebases and sensitive vulnerability information. This breach elevated the risk for F5’s enterprise and government customers, as the exposed vulnerabilities could facilitate future attacks on critical infrastructure globally. The incident highlights both supply chain implications and the heightened impact of intellectual property theft. This attack underscores a strategic shift where advanced threat actors seek not only data but also exploit software supply chains and zero-day vulnerabilities, raising urgent concerns for organizations dependent on key network infrastructure vendors. With regulatory scrutiny sharpening around supply chain risk and software assurance, incidents like this set new urgency for proactive defense and vendor risk management.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
North Korean Hackers Target Job Seekers with Advanced Malware & Blockchain C2 (2024)
Impact· high

North Korean Hackers Target Job Seekers with Advanced Malware & Blockchain C2 (2024)

In early 2024, cybersecurity researchers from Cisco Talos and Google Threat Intelligence Group uncovered a sophisticated cyber-espionage campaign led by North Korea-aligned groups, Famous Chollima and UNC5342. These actors exploited job recruitment platforms by duping job seekers into downloading malicious code, including new malware strains—namely BeaverTail, OtterCookie, JadeSnow, and InvisibleFerret—during fake interview processes. The attackers leveraged advanced techniques such as blockchain-based command and control (EtherHiding) to exfiltrate credentials, steal cryptocurrency, and deploy ransomware. Information-stealing modules captured keystrokes and screen data, highlighting the ongoing evolution of North Korea’s threat ecosystem while successfully avoiding conventional detections. This incident underscores the persistent risks posed by nation-state threat actors utilizing social engineering and innovative evasion tactics. The convergence of credential theft, ransomware delivery, data exfiltration, and resilient C2 infrastructure signals an escalation in global threat sophistication, especially targeting corporate and finance sectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
North Korean Hackers Deploy Blockchain Malware via EtherHiding
Impact· medium

North Korean Hackers Deploy Blockchain Malware via EtherHiding

In early 2025, North Korean state-backed threat actors, specifically UNC5342, leveraged a new malware distribution technique called 'EtherHiding' to conduct advanced social engineering attacks against software and web developers. Utilizing smart contracts on public blockchains like Ethereum and Binance Smart Chain, the attackers embedded JavaScript payloads, allowing them to deliver and update malware with anonymity and resistance to takedowns. The lures involved fake job interviews that convinced victims to run malicious code, ultimately resulting in the in-memory deployment of the JADESNOW and InvisibleFerret malware for credential theft, financial data exfiltration, and ongoing espionage. This breach is particularly significant as it marks the first known nation-state operation using EtherHiding to evade detection and persistently update attack tools on-chain. The campaign signals a macro shift to blockchain-based malware delivery, complicating threat intelligence, response, and regulatory postures in the face of evolving infostealer and espionage techniques.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Adobe AEM Forms Zero-Day (CVE-2025-54253) Actively Exploited for Remote Code Execution
Impact· low

Adobe AEM Forms Zero-Day (CVE-2025-54253) Actively Exploited for Remote Code Execution

In October 2025, a maximum-severity vulnerability (CVE-2025-54253) in Adobe Experience Manager (AEM) Forms was discovered to be actively exploited in the wild. The flaw, allowing unauthenticated remote code execution via authentication bypass, affected AEM Forms on JEE versions 6.5.23 and earlier. Researchers from Searchlight Cyber originally reported the issue in April, but public exploit code and detailed writeups emerged before Adobe issued a patch in August. Attackers were able to exploit the misconfiguration to gain complete control over unpatched systems, endangering both public and private sector organizations. This incident underscores the increasing threat posed by delayed patching and public disclosure of unpatched zero-days. It highlights the importance of rapid vulnerability management, particularly for federal agencies under BOD 22-01, and serves as a warning for organizations to prioritize patching high-impact application flaws to protect critical business operations.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports