✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
2024 DOGE Insider Threat: Massive Data Privacy Risk at U.S. Agencies
In June 2024, the Department of Government Efficiency (DOGE), created by Elon Musk, was found to be operating outside federal law, compromising cybersecurity and privacy protocols at three major U.S. agencies: the General Services Administration (GSA), Office of Personnel Management (OPM), and Social Security Administration (SSA). According to a Senate Homeland Security and Governmental Affairs Committee report, DOGE staffers allegedly uploaded sensitive personal data—such as the SSA's Numident database—into inadequately protected environments. This exposed millions of Americans to potential identity theft and data misuse, circumventing standard cybersecurity and regulatory controls by leveraging unauthorized cloud resources and private satellite networks, notably Starlink, to evade agency oversight. The incident underscores an urgent shift in the threat landscape, whereby insider threats and shadow IT initiatives create unprecedented systemic risk within critical public sector organizations. Amid regulatory scrutiny, this breach highlights the critical need for robust monitoring, segmentation, and compliance enforcement against complex, evolving insider vulnerabilities.
6 months ago
Kill Chain
Nation-State Zero-Day Attacks Breach Cisco Firewalls in 2024
In mid-2024, an advanced nation-state threat group—tracked as UAT4356 (Talos) and Storm-1849 (Microsoft)—launched a widespread espionage campaign exploiting newly discovered zero-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) in Cisco Adaptive Security Appliance (ASA) firewalls. These attackers gained persistent, full-device control by chaining zero-days, disabling logging, evading defenses, and implanting custom malware on federal networks, achieving potential data exfiltration and establishing long-term persistence beyond standard remediation steps. The Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive mandating immediate federal agency response, including mandatory patching or device disconnection. This attack underscores the evolving sophistication and urgency of supply chain and perimeter device threats. As zero-day exploitation targeting network infrastructure escalates and aligns with global power competition, organizations must prioritize detection, segmented defense, and rapid vulnerability management to safeguard high-value assets and comply with emerging federal cyber mandates.
6 months ago
Kill Chain
Cisco Zero-Day Exploitation: Federal Agencies Targeted in Prolonged Nation-State Attack
In 2024, a series of sophisticated attacks leveraging zero-day vulnerabilities in Cisco firewalls targeted U.S. federal agencies and critical infrastructure. Initial reconnaissance began in November 2023, with attackers exploiting unknown flaws at the network edge to gain persistent, low-profile access—including read-only memory modifications. The breach remained undetected for months as Cisco and federal authorities investigated, coordinated patches, and ultimately prompted an emergency CISA directive. Despite working closely with vendors on remediation, the scope required urgent government intervention, with potential exposure impacting hundreds of Cisco firewalls across key sectors. These attacks underscore growing nation-state interest in exploiting core network devices for stealthy espionage. With similar tactics on the rise, the breach brings renewed urgency for rapid threat detection, zero-trust policy enforcement, and timely vulnerability disclosures across government and industry.
6 months ago
Kill Chain
Forta GoAnywhere 2025: Zero-Day Supply Chain Breach Raises Compliance Alarms
In September 2025, Forta's GoAnywhere MFT file-transfer service was found to contain a critical deserialization vulnerability (CVE-2025-10035) which could enable attackers to execute arbitrary code remotely. Although Forta initially stopped short of confirming exploitation, credible evidence from threat researchers surfaced showing active in-the-wild attacks dating back to at least September 10. The exploit relies on the attacker’s ability to sign Java objects with a stolen or leaked private key, raising concerns over supply chain security and key management. Enterprises using GoAnywhere MFT face risks of data exfiltration and operational disruption. The incident highlights ongoing challenges in vendor transparency and the risks associated with critical third-party software. It underscores the urgent need for enhanced monitoring, timely vendor disclosures, strict key management, and robust segmentation strategies, as similar exploitation patterns have escalated across the supply chain attack landscape.
6 months ago
Kill Chain
Teen Hacker, Scattered Spider, and the 2023 Vegas Casino Ransomware Crisis
In late summer and early fall 2023, Las Vegas casinos MGM Resorts and Caesars Entertainment suffered major cyberattacks conducted by the Scattered Spider threat group, including at least one 17-year-old suspect. Attackers gained network access via social engineering and lateral movement, ultimately deploying BlackCat/ALPHV ransomware. The incidents led to severe operational disruption, significant financial losses exceeding $100 million for MGM, a $15 million ransom paid by Caesars, and exposure of sensitive customer and employee data. Law enforcement identified and apprehended one teenage perpetrator, who was later released to parental custody pending trial. This high-profile case highlights the growing trend of sophisticated, identity-driven ransomware attacks launched by younger, tech-savvy threat actors and hacking collectives. It underscores the urgent need for organizations to close internal security gaps, improve zero trust posture, and address the challenges of compliance amid increasingly aggressive and disruptive ransomware campaigns.
6 months ago
Kill Chain
Malicious Rust Crates on Crates.io Compromise Developer Crypto Wallets in 2025
In September 2025, security researchers uncovered two malicious Rust packages, 'faster_log' and 'async_println', uploaded to the official Crates.io repository. These packages, downloaded nearly 8,500 times, masqueraded as legitimate logging libraries but secretly scanned developers' machines for cryptocurrency wallet private keys and other sensitive secrets. The attackers used cloned documentation and authentic functionality to evade suspicion, while an embedded payload exfiltrated discovered secrets to a hardcoded Cloudflare Worker endpoint controlled by the threat actors. Upon discovery, Crates.io removed the packages and banned the associated users, mitigating the immediate threat. This incident demonstrates the persistent risk posed by supply chain attacks targeting open-source repositories and the increasing focus of cybercriminals on cryptocurrency theft. It underscores the need for rigorous vetting, enhanced code scanning, and heightened awareness among developers regarding open-source dependencies.
6 months ago
Kill Chain
Cisco ASA Firewall Zero-Day Attacks 2025: Immediate Remediation Required
In September 2025, Cisco revealed that two zero-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) affecting ASA Firewall and FTD software were exploited in active campaigns. One flaw allowed authenticated remote code execution, while the other exposed restricted URL endpoints without authentication. Attackers leveraged these security gaps to potentially gain unauthorized access and control over vulnerable network infrastructure. Security advisories emphasized the need for immediate patching, with involvement from global cybersecurity agencies such as ACSC, CCCS, NCSC, and CISA in threat investigation and response. This breach highlights a surge in zero-day exploitations against critical network appliances and underscores the evolving sophistication of attacker reconnaissance and exploitation cycles. The incident reflects an ongoing trend of targeting edge devices as organizations increase reliance on remote and hybrid work models.
6 months ago
Kill Chain
APT Campaign Exploits Cisco ASA Zero-Days: Persistent Threats to Government Devices in 2025
In September 2025, U.S. federal agencies were ordered by CISA to urgently patch Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices after two critical zero-day vulnerabilities (CVE-2025-20333, CVE-2025-20362) were exploited by the APT group UAT4356 (STORM-1849). Attackers achieved unauthenticated remote code execution and persistent control by manipulating device ROMMON, deploying malware such as LINE VIPER and the RayInitiator bootkit to facilitate malware implants, command execution, and possible data exfiltration. The campaign, linked to the larger ArcaneDoor operation, threatened essential government and global infrastructure by allowing full device compromise, evasion of detection, and resistance to conventional remediation steps. This incident highlights an escalating trend in sophisticated, state-linked attacks targeting edge infrastructure, often leveraging supply-chain weaknesses and persistent malware able to survive reboots and firmware updates. It also underscores renewed regulatory pressure for timely vulnerability mitigation and increased focus on Zero Trust architectures for critical sectors.
6 months ago
Kill Chain
Inside the 2025 Co-op Scattered Spider Cyberattack: Lessons and Impact
In April 2025, the Co-operative Group (Co-op), a major UK member-owned retailer, experienced a sophisticated cyberattack attributed to Scattered Spider affiliates linked to the DragonForce ransomware operation. The attack targeted Co-op’s IT infrastructure, forcing the group to shut down critical systems, causing major disruptions to back-office and call-center operations, and necessitating rapid manual workarounds. Although Co-op's incident response prevented data encryption, attackers stole sensitive personal information of all 6.5 million current and past members, including names and contact details. The breach resulted in significant operational outages, with £80 million ($107 million USD) in immediate financial losses and longer-term revenue reduction due to impacted retail operations and customer trust. This incident highlights the evolving threat of identity-driven ransomware attacks and the increasing willingness of threat actors to disrupt critical infrastructure for financial gain. The scale and impact of the Co-op breach underscore the need for advanced security controls and segmented, resilient architectures to counter modern ransomware groups.
6 months ago
Kill Chain
Unofficial Postmark MCP npm Package: 2024 Supply Chain Breach Exposes Email Data
In February 2024, the unofficial 'postmark-mcp' npm package—a clone of the genuine Postmark MCP email handler—was discovered to have maliciously exfiltrated users' email data. With a single line of code added in its latest update, the package silently sent every processed email to an external domain controlled by the attacker. This supply chain compromise exploited developer trust in open-source libraries, resulting in unintentional leakage of confidential user communications and putting affected organizations and their customers at risk of data exposure or further attacks. This incident underscores the growing frequency and sophistication of supply chain attacks targeting software ecosystems like npm. Organizations face heightened regulatory and reputational risks as attackers leverage trusted distribution platforms to propagate malicious code, making robust dependency monitoring and vendor validation more critical than ever.
6 months ago
Kill Chain
Microsoft Warns: XCSSET macOS Malware Evolves to Target Xcode Devs in 2025
In September 2025, Microsoft Threat Intelligence identified a new, advanced variant of the XCSSET macOS malware targeting Xcode developers. This infostealer propagates by infecting Xcode projects—widely shared among software engineers—allowing it to execute malicious code each time a compromised project is built. The updated malware features enhanced browser data theft (including Firefox), clipboard hijacking to steal cryptocurrency via address swapping, and improved persistence mechanisms. Though observed only in limited, targeted attacks so far, XCSSET poses a significant risk to both assets and sensitive developer tooling. This incident is especially relevant today as targeting the software supply chain and developer toolchains is becoming a favored method for threat actors seeking high-privilege access. The sophistication of XCSSET’s mechanisms mirrors broader trends in stealthy, data-focused attacks against development environments, pressing organizations to reassess internal controls and software sharing practices.
6 months ago
Kill Chain
Massive npm Supply Chain Attack: Shai-Hulud Worm Infects Hundreds of Packages
In September 2025, a major supply chain compromise hit the npm ecosystem with the discovery of the Shai-Hulud worm. Attackers leveraged malicious npm packages to propagate self-replicating malware, which spread by abusing developer credentials and update permissions across over 500 packages—including widely used libraries from organizations such as CrowdStrike. Malicious code executed on install harvested secrets, exfiltrated sensitive GitHub and cloud data, and published infected releases to additional packages, resulting in widespread risk of source code leaks, credential theft, and downstream infections. This incident typifies the escalating trend of highly automated supply chain attacks targeting open-source repositories. Such events highlight the vulnerabilities of complex dependency networks and reinforce the necessity for robust controls, automated monitoring, and zero trust policies for development and CI/CD ecosystems.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports