✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Akira Ransomware: MFA-Protected SonicWall VPNs Breached in 2024
In early 2024, the Akira ransomware group escalated its campaign by successfully breaching organizations through SonicWall SSL VPN appliances, even when multi-factor authentication (MFA) was enabled. Security researchers determined that Akira actors appeared to bypass one-time password (OTP) protections, potentially by leveraging previously obtained OTP seed information or exploiting weaknesses in authentication management. Following the VPN compromise, attackers moved laterally, exfiltrated data, and encrypted systems to demand substantial ransom payments. This attack vector enabled access to privileged internal resources, resulting in business disruption, data exposure, and financial losses for affected organizations. The incident underscores how ransomware operators are adapting to bypass commonly deployed defenses, specifically targeting VPN and MFA solutions. Such tactics highlight the urgent need for organizations to reassess remote access controls, authentication infrastructure, and visibility gaps, as similar techniques are increasingly observed in the wild.
6 months ago
Kill Chain
Fake Microsoft Teams Installers Spread Oyster Malware via Malvertising
In September 2025, cybercriminals exploited search engine advertisements and SEO poisoning to promote fake Microsoft Teams installers, which covertly delivered the Oyster backdoor (also known as Broomstick or CleanUpLoader) onto Windows devices. By luring users—often IT administrators—to download malicious 'MSTeamsSetup.exe' files from deceptive sites like teams-install[.]top, attackers established remote control over compromised systems. The malware facilitated persistent access by installing a scheduled task and enabled command execution, lateral movement, deployment of additional payloads, and file exfiltration, posing considerable risks to corporate environments. Organizations relying on user trust in branded software searches became targets for subsequent attacks, including potential ransomware deployment. This incident underscores a growing threat: attackers increasingly abuse mainstream search engines and brand impersonation to achieve initial corporate access. As malvertising and SEO poisoning campaigns surge, organizations must prioritize user security awareness, robust endpoint threat detection, and zero trust controls to defend against evolving infostealer delivery mechanisms.
6 months ago
Kill Chain
Threat Insights: Nation-State Exploitation of Cisco ASA Zero-Days (ArcaneDoor 2025)
In September 2025, Cisco disclosed that a sophisticated nation-state threat actor, linked to the ArcaneDoor campaign, exploited multiple zero-day vulnerabilities in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. These attackers targeted government networks and critical infrastructure globally, leveraging CVE-2025-20333 and CVE-2025-20362, which enabled remote code execution, persistent malware installation, and data exfiltration. Advanced evasion tactics allowed the attackers to disrupt device logging and remain undetected for extended periods, while the deployment of custom malware such as RayInitiator and LINE VIPER provided long-term backdoor access to compromised environments. This case highlights growing trends in state-sponsored exploitation of perimeter devices and demonstrates how quickly nation-state TTPs can proliferate to broader criminal groups. The campaign triggered urgent mandates from CISA and NCSC for organizations—especially in the public sector—to patch and monitor edge infrastructure, emphasizing the escalating risk from zero-day vulnerabilities and the increasing sophistication of attacker methods.
6 months ago
Kill Chain
GoAnywhere MFT Zero-Day (CVE-2025-10035): Anatomy of a 2025 Enterprise Breach
In September 2025, a maximum severity zero-day vulnerability (CVE-2025-10035) in Fortra’s GoAnywhere Managed File Transfer (MFT) platform was actively exploited in the wild. Attackers remotely injected commands via a deserialization flaw in the License Servlet, requiring only a forged license response signature to achieve pre-authentication remote code execution. The breach timeline reveals attackers gained access at least a week before public disclosure, establishing persistence via a backdoor admin account and deploying secondary payloads like SimpleHelp for ongoing access, with evidence of lateral movement reconnaissance. The incident underscores the increasing sophistication and rapid weaponization of zero-day exploits targeting widely used enterprise file transfer solutions. With high-profile breaches tied to vulnerabilities in GoAnywhere, pressure is mounting for organizations to reassess their exposure and incident response practices amid a sharp uptick in exploit automation and data exfiltration attacks.
6 months ago
Kill Chain
Cisco Firewall Zero-Day Incident: RayInitiator & LINE VIPER Malware Exposed
In September 2025, Cisco ASA firewalls faced a severe cybersecurity incident when threat actors leveraged recently disclosed zero-day vulnerabilities to secretly infiltrate network perimeters. The attackers exploited these flaws to deploy two newly discovered malware strains, RayInitiator and LINE VIPER, allowing them to bypass existing defenses, maintain persistence, and exfiltrate sensitive data from affected enterprises. This highly sophisticated campaign showcased advanced persistent threat (APT) tradecraft, utilizing encrypted command-and-control traffic and lateral movement within east-west network segments, impacting organizations across multiple sectors and creating significant operational and reputational risks. This incident underscores an emergent pattern of targeting network infrastructure devices with custom malware, reflecting broader shifts in attacker strategy. As attackers increasingly refine zero-day exploitation and expand their arsenal, organizations must adapt security postures to detect and respond to threats traversing both perimeter and internal network boundaries.
6 months ago
Kill Chain
New XCSSET Variant Hits macOS: Browser Credential Theft and Clipper Risk for Developers
In September 2025, researchers identified a sophisticated new variant of the macOS XCSSET malware, targeting Apple devices with an updated focus on browser credential theft, clipboard hijacking (clipper), and improved persistence. Initially delivered through tainted Xcode projects, the malware leveraged encrypted and obfuscated code to avoid detection, and incorporated a persistence module for sustained access. Key changes included deeper targeting of browsers like Firefox, allowing attackers to intercept credentials, exfiltrate sensitive data, and potentially escalate attacks to other platforms or accounts. The XCSSET variant’s rise mirrors broader trends in information-stealing malware exploiting developer platforms and macOS. This incident highlights growing attacker interest in macOS ecosystems, the sophistication of obfuscation techniques, and the urgent need for endpoint monitoring and microsegmentation across development environments.
6 months ago
Kill Chain
Fortra GoAnywhere Zero-Day CVSS 10 Exploited Before Disclosure in 2025
In September 2025, a critical zero-day vulnerability (CVSS 10.0) in Fortra GoAnywhere Managed File Transfer software was actively exploited for at least a week before its public disclosure. Attackers leveraged the flaw to gain unauthorized access and potentially exfiltrate sensitive data from organizations using the platform, which is widely adopted in regulated sectors. The attack vector was weaponized rapidly by sophisticated threat groups and ransomware actors, highlighting systemic risks in third-party file transfer applications. The incident resulted in significant business disruption, data exposure, and triggered urgent patching activities across affected enterprises. This breach reflects a broader trend of adversaries increasingly targeting secure file transfer solutions via 0-day vulnerabilities, often achieving lateral movement and persistent footholds. It underscores the pressing need for proactive vulnerability management, real-time threat detection, and strong compliance practices amid rising regulatory scrutiny around data handling and supply chain exposures.
6 months ago
Kill Chain
SSL.com Certificate Abuse: Iranian APTs Sign Malware with Trusted Keys in 2024
In early 2024, multiple Iranian state-linked threat groups, including the Charming Kitten offshoot Subtle Snail, leveraged code-signing certificates issued by Houston-based SSL.com to digitally sign malware campaigns targeting organizations worldwide. Researchers discovered that the threat actors abused trusted certificates to bypass security controls and distribute malicious payloads, with their primary focus on espionage and data exfiltration. This compromised trust in legitimate software distribution channels and posed significant detection challenges for defenders, underscoring the evolving sophistication of APT campaigns tied to Iran. The incident highlights an uptick in supply chain and abuse-of-trust techniques among state-sponsored groups. Attackers are increasingly capitalizing on trusted processes—such as code signing—to slip past endpoint protection platforms, raising the regulatory and operational urgency for organizations dependent on digital certificate trust.
6 months ago
Kill Chain
COLDRIVER’s 2025 ClickFix Malware Campaign: Modular APT Tactics Evolve
In September 2025, the Russian APT group COLDRIVER launched a multi-stage cyber campaign using newly identified malicious tools, BAITSWITCH and SIMPLEFIX, delivered through ClickFix-style phishing attacks. Zscaler ThreatLabz observed that COLDRIVER targeted Russian-speaking entities with sophisticated social engineering and credential phishing tactics, ultimately compromising victims by deploying lightweight downloaders that enable remote access and further malware deployment. Impacted organizations faced stealthed data exfiltration risks and the threat actor's evolving persistence mechanisms, signifying a leap in their operational security evasion. This incident reflects an accelerating trend of APT actors developing nimble, modular malware to bypass traditional defenses and exploit collaboration platforms. Continued adaptation in attacker tradecraft underscores the growing urgency for zero trust controls, east-west visibility, and anomaly detection across hybrid environments.
6 months ago
Kill Chain
Targeted SVG Phishing Hits Ukrainian Agencies with CountLoader, PureRAT
In September 2025, cybersecurity researchers uncovered a targeted phishing campaign impersonating Ukrainian government agencies. Attackers distributed emails containing malicious SVG file attachments, crafted to deliver the CountLoader malware. Upon execution, CountLoader dropped secondary payloads—Amatera Stealer and PureMiner—allowing cybercriminals to steal sensitive information and deploy cryptomining operations on victim systems. The attacks leveraged sophisticated social engineering and file formats to evade detection, threatening both public sector and affiliated organizations. This incident highlights a surge in phishing operations leveraging advanced loaders and novel file types, such as SVG. As more attackers exploit government-themed lures and multi-tool chains, organizations face an elevated risk of data exfiltration, credential theft, and operational disruption, demanding robust, adaptive security controls.
6 months ago
Kill Chain
Salesforce Agentforce 2024: ForcedLeak AI Prompt Injection Breach Exposes CRM Data
In June 2024, researchers at Noma Security identified a severe vulnerability in Salesforce's Agentforce AI agents, termed 'ForcedLeak'. By exploiting prompt injection via web-to-lead forms, attackers were able to manipulate Agentforce into exfiltrating sensitive CRM data, including PII, corporate secrets, and transactional details, to unauthorized locations. The vulnerability hinged on whitelist misconfigurations of trusted domains and the agent’s overly broad prompt interpretation, leading to an attacker-controlled data leak chain. Salesforce addressed data exfiltration by patching URL restrictions and acquiring an expired trusted domain but ongoing risks persist with agentic AI’s prompt processing logic. The incident underscores the growing challenges as mainstream SaaS platforms rapidly integrate autonomous GenAI features, often lacking robust input validation and security boundaries. High CVSS-scored issues like ForcedLeak exemplify the urgent need for zero trust guardrails and more resilient AI security frameworks given the increasing velocity and sophistication of prompt injection attacks.
6 months ago
Kill Chain
Nation-State Attackers Exploit Cisco Zero-Day Bugs in 2024: What You Need to Know
In early 2024, Cisco disclosed four actively exploited zero-day vulnerabilities impacting its firewalls and IOS software, affecting millions of devices globally. At least three of these flaws were exploited by a sophisticated nation-state threat actor behind the ArcaneDoor campaign. Attackers leveraged the zero-days to gain unauthorized access to networks, facilitating lateral movement, data interception, and potentially persistent backdoors in affected systems. The campaign specifically targeted high-value government and critical infrastructure entities, prompting urgent patching initiatives. This incident underscores a growing trend of state-backed actors aggressively targeting network infrastructure with zero-day exploits. As attackers focus on networking gear as an entry point, organizations must reevaluate perimeter defenses and accelerate patch management to remain resilient against such advanced threats.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports