✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Oracle E-Business Suite 2025: Critical SSRF Exploit Exposed and Analyzed
In October 2025, Oracle E-Business Suite was found to be vulnerable to an actively exploited server-side request forgery (SSRF) vulnerability, tracked as CVE-2025-61882. Threat actors leveraged a publicly available exploit script to manipulate the product’s servlet endpoints, extracting CSRF tokens and delivering a crafted payload capable of executing arbitrary commands via XSLT and Java reflection. The attack enabled remote code execution and potential lateral movement within affected enterprise environments, with indicators of compromise made public shortly after discovery. Oracle’s rapid response included a critical patch and threat intelligence advisory. This incident highlights an ongoing surge in advanced web exploitation techniques, particularly SSRF combined with deserialization and XSLT-based attacks. It underscores the urgent need for timely patching, defense-in-depth, and continuous anomaly detection, as well as the growing focus of attackers on business-critical ERP platforms.
6 months ago
Kill Chain
Salesloft Drift Supply Chain Breach: How Okta and Zscaler Responded in 2023
In August 2023, a sophisticated supply chain attack targeting Salesloft and Drift exposed the vulnerabilities of OAuth token management in SaaS integrations. Threat actor group UNC6395 compromised Salesloft's GitHub and later leveraged compromised OAuth tokens from the Drift platform, affecting over 700 customers—including security leaders Okta and Zscaler. While Okta’s proactive use of IP restrictions blocked malicious API requests and prevented data loss, Zscaler experienced a significant breach, exposing both customer and internal data. The campaign unfolded rapidly, relying on automated scripts for widespread data extraction via legitimate channels before defenses were activated. This incident underscores the growing pipeline threat of API- and token-driven attacks across integrated SaaS ecosystems. As organizations increasingly rely on third-party applications, traditional security mechanisms and risk due diligence are proving insufficient against lateral supply-chain intrusion tactics and the automated exploitation of tokenized access.
6 months ago
Kill Chain
ParkMobile 2021 Data Breach: Lessons from a 22 Million User Exposure
In March 2021, ParkMobile, a widely used parking payment platform, suffered a significant data breach that exposed sensitive information of nearly 22 million users. Threat actors exploited a vulnerability in the company’s third-party software, exfiltrating a 4.5 GB dataset containing names, email addresses, phone numbers, license plate data, mailing addresses, usernames, bcrypt-hashed passwords, and vehicle information. The full database was later leaked on a popular hacking forum, fueling risks of identity theft and fraud. Legal proceedings culminated in late 2024, with ParkMobile settling a class action lawsuit by offering $1 in-app credits per user. The breach highlights persistent challenges around protecting personal data, enforcing regulatory standards, and responding to data leaks in the mobility and payments sector. It emphasizes the urgent need for encrypted communications, strong segmentation, and robust threat detection as organizations confront increasingly sophisticated attack methods and legal repercussions.
6 months ago
Kill Chain
How Attackers Exploited a Zimbra Zero-Day via iCalendar Files in 2024
In early 2024, attackers exploited a previously unknown zero-day vulnerability in Zimbra Collaboration Suite (ZCS), targeting organizations via specially crafted .ICS (iCalendar) attachments. The vulnerability allowed threat actors to execute code by delivering malicious calendar files through email, bypassing traditional security filters. Incident responders observed attackers using this method for initial access, resulting in potential data theft, lateral movement, and disruption of email communications for affected businesses. The exploitation remained undetected for a significant period, amplifying operational and reputational risks for impacted entities. This incident highlights a growing trend of attackers leveraging supply chain and collaboration software vulnerabilities for sophisticated phishing and malware campaigns, often exploiting zero-days before vendors can respond. Organizations relying on common email and collaboration platforms face increased exposure to targeted file-type exploits and require improved visibility and rapid patching capabilities.
6 months ago
Kill Chain
Discord 2024 Breach: Third-Party Support Attack Exposes User Data
In early March 2024, Discord disclosed a data breach after threat actors compromised a third-party customer service provider’s systems. Attackers gained access to customer support tickets, exposing partial payment information, names, email addresses, and government-issued IDs of Discord users who had interacted with support. The breach occurred through unauthorized access to the provider’s internal systems, allowing exfiltration of sensitive, personally identifiable information linked to support requests. Discord promptly investigated, notified affected users, and terminated the third party’s access to its systems. This incident highlights the increasing risks associated with third-party vendors handling sensitive data, especially as social engineering and supply chain attacks become more common. Growing scrutiny from regulators and customers underscores the need for robust supply chain security and continuous monitoring of vendor access.
6 months ago
Kill Chain
Palo Alto Networks Faces Massive Surge in Login Portal Recon Scans
In early October 2025, cybersecurity firm GreyNoise detected a sharp 500% spike in reconnaissance scans targeting Palo Alto Networks GlobalProtect and PAN-OS login portals. Over 1,285 unique suspicious IP addresses, predominantly from the U.S., but also from the UK, Canada, the Netherlands, and Russia, launched automated probes against these authentication portals. The campaign appeared targeted, leveraging data from public scanning platforms like Shodan and Censys. No verified exploit or compromise has been confirmed, with Palo Alto Networks asserting their systems remain secure and attributing much of the observed activity to external fingerprinting, not internal breach. This incident highlights a broader escalation in focused reconnaissance tactics against major infrastructure platforms, often preceding attempts to weaponize new vulnerabilities. Organizations should remain vigilant about emerging threats, monitor authentication endpoints, and proactively patch known and zero-day-related risks.
6 months ago
Kill Chain
Palo Alto Networks Portals Targeted by 500% Surge in Reconnaissance Scanning
On October 3, 2025, cybersecurity researchers at GreyNoise detected an unprecedented 500% spike in scanning activity targeting Palo Alto Networks login portals, marking the highest volume observed over a three-month period. The scanning involved a surge of IP addresses systematically probing these portals, suggesting highly targeted reconnaissance efforts by unknown threat actors. While no direct exploitation or breach was reported, such coordinated scanning is often the precursor to exploitation attempts against potential vulnerabilities in security infrastructure, especially as targeted technologies are foundational for enterprise security postures. This incident exemplifies the growing trend of automated reconnaissance on high-value network assets as adversaries aim to map attack surfaces for later campaigns. Organizations relying on exposed management interfaces must bolster detection, segmentation, and access controls to address these evolving reconnaissance tactics.
6 months ago
Kill Chain
CometJacking: How a Single Click Turned Perplexity's Comet AI Browser into a Data Thief
In October 2025, cybersecurity researchers uncovered a significant prompt injection attack targeting Perplexity's Comet AI browser. Dubbed "CometJacking," this incident involved adversaries embedding malicious prompts in links, which—when clicked by users—triggered unauthorized data siphoning through the browser's agentic AI capabilities. Sensitive information, including from connected services like email and calendars, was exposed, demonstrating how AI-driven interfaces can be subverted via crafted input. The attack exploited trust in browser automation and the deep integration of third-party services, raising concerns about the security of AI-powered productivity tools. This incident is highly relevant as prompt injection attacks are rapidly emerging as a primary risk vector for generative AI environments. The growth in agentic AI and interconnected browser-based workflows has exposed new attack surfaces, prompting urgent calls for improved input validation, isolation of automation agents, and strengthened compliance for AI SaaS applications.
6 months ago
Kill Chain
Salesforce Breach 2024: Scattered Lapsus$ Hunters' Massive Data Extortion Campaign
In October 2024, the cybercriminal collective Scattered Lapsus$ Hunters resurfaced with a dedicated leak site, threatening to publish stolen data related to Salesforce customers if their extortion demands were not met. This group, an alliance of threat actors including Scattered Spider, Lapsus$, and ShinyHunters, allegedly compromised Salesforce environments through social engineering—specifically vishing IT support personnel to obtain credentials and, in parallel campaigns, exploiting OAuth token theft. The attackers claimed to possess approximately one billion records from 39 prominent organizations, including sensitive personally identifiable information (PII) like Social Security and driver’s license numbers. This incident underscores the increased targeting of SaaS platforms via identity and access manipulation, as well as the growing sophistication of multinational threat actor collaborations. It signals elevated risk for organizations relying on cloud applications and highlights the necessity of enforcing multi-factor authentication and vigilant third-party access controls.
6 months ago
Kill Chain
Oracle EBS Exploited in Clop Ransomware Extortion Campaign (2025)
In September 2025, Oracle confirmed that customers running E-Business Suite (EBS) were targeted by extortion emails attributed to the Clop ransomware gang, following exploitation of security vulnerabilities addressed in the July 2025 Critical Patch Update. Multiple executives at affected companies received emails demanding ransom, with Clop claiming to have exfiltrated confidential data from unpatched Oracle EBS instances. While Oracle has not formally verified the data theft, the vulnerabilities—three of which were remotely exploitable without authentication—enabled attackers to potentially access sensitive business documents and threaten public disclosure if ransoms were not paid. This incident highlights a continued and escalating trend of ransomware groups leveraging zero-day and freshly patched vulnerabilities to target critical enterprise software. Organizations dependent on ERP and business process applications are increasingly at risk, underscoring the urgent need for rapid patching and advanced network-layer security controls.
6 months ago
Kill Chain
CometJacking Attack: How Prompt Injection Exposed Comet AI Browser Users in 2025
In October 2025, security researchers from LayerX uncovered a novel 'CometJacking' attack affecting Perplexity's Comet AI browser. This prompt injection attack leverages URL parameters to deliver hidden instructions that compel the browser to access and exfiltrate sensitive data—such as Gmail messages and Google Calendar information—from connected services, without any need for user credentials or interaction. The technique exploits the 'collection' URL parameter to insert malicious prompts, instructing the AI agent to gather and encode user data (e.g., using base64) before surreptitiously transmitting it to attacker-controlled endpoints. Despite being informed, Perplexity dismissed the security risk, highlighting concerns about unmitigated AI agent behaviors.This incident surfaces amid growing adoption of agentic AI browsers and illustrates the ease with which prompt injection tactics can sidestep controls, particularly in tools integrated with sensitive personal or enterprise accounts. The attack underscores the increasing threat from adversarial prompt engineering as AI agent usage expands rapidly.
6 months ago
Kill Chain
ShinyHunters Extorts 39 Firms in Salesforce OAuth Supply Chain Breach
In October 2025, the extortion group known as 'Scattered Lapsus$ Hunters'—a coalition including ShinyHunters, Scattered Spider, and Lapsus$—launched a data leak site to extort 39 companies after a coordinated campaign exploiting Salesforce OAuth integrations. The attackers used sophisticated voice phishing to trick employees into connecting malicious OAuth apps to corporate Salesforce instances, enabling unauthorized database access. Stolen data included sensitive customer records from major global brands such as FedEx, Disney, Google, and Marriott, with threat actors demanding ransom to prevent broader public disclosure. Salesforce stated there was no compromise of its platform, but investigations continue. This incident highlights the rising threat of supply chain and identity-based attacks targeting SaaS platforms, exploiting user trust and third-party integrations. With the growing adoption of SaaS solutions and increasing regulatory focus (e.g., GDPR), enterprises face mounting pressure to implement robust identity, access governance, and monitoring controls to defend against mass-scale data exfiltration and extortion.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports