✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
PyPI Phishing Attack Exposes Open-Source Supply Chain in 2025
In September 2025, the Python Package Index (PyPI) suffered a targeted supply-chain phishing campaign, where threat actors impersonated PyPI via convincing emails and domain lookalikes (such as pypi-mirror.org). Attackers sent phishing emails to PyPI maintainers, warning of account suspension and requesting email verification. Unsuspecting victims who followed malicious links and entered credentials risked account compromise, enabling attackers to breach legitimate developer accounts. The likely aim was to either infect existing packages with malware or introduce new malicious packages into trusted software repositories, potentially impacting the broader Python ecosystem. This incident underscores the growing sophistication of software supply-chain threats, especially as open-source repositories face sustained phishing campaigns and credential harvesting tactics. As phishing campaigns increasingly target developers and critical infrastructure, strong phishing-resistant authentication and vigilant domain monitoring are now essential industry-wide defenses.
7 months ago
Kill Chain
Obscura Ransomware 2025: What Enterprises Must Learn About Active Directory Attacks
In late August 2025, a newly discovered ransomware variant named Obscura was identified executing across several hosts within an enterprise network. The attack leveraged the organization's Active Directory infrastructure, using the NETLOGON share to automatically deploy a Go-based ransomware binary across all domain controllers and affected endpoints. The attackers created malicious scheduled tasks for persistent execution and attempted to enable remote desktop for potential lateral movement. The ransomware also attempted to disable endpoint recovery options, and the ransom note indicated both data encryption and exfiltration of sensitive company information. Limited security agent coverage hampered detection and response, amplifying the operational disruption and risk of sensitive data exposure. This incident underscores the evolving sophistication of ransomware actors in targeting critical authentication infrastructure and automated deployment mechanisms. As attackers increasingly combine data theft with operational disruption and target identity systems, organizations face heightened regulatory, financial, and reputational risks, warranting renewed focus on segmentation, visibility, and endpoint security.
7 months ago
Kill Chain
Interpol's 2024 Crackdown: $439 Million Seized from Global Cybercrime Networks
In 2024, Interpol coordinated a global operation targeting cybercrime rings responsible for large-scale financial crimes. Over a period of five months, law enforcement agencies from 61 countries worked together to investigate and disrupt online scams that included business email compromise (BEC), investment fraud, romance scams, and e-commerce fraud. The operation resulted in the seizure of more than $439 million in cash and cryptocurrency, exposing elaborate money laundering networks and identifying approximately 1,300 suspects linked to cyber-enabled financial crime groups. Thousands of victims worldwide were impacted by these schemes. This incident highlights the growing sophistication and international reach of financially motivated cybercrime, as well as the increasingly effective law enforcement collaborations to disrupt illicit networks. The operation reflects a heightened urgency for organizations to strengthen controls against online fraud and cyber-enabled theft, as attackers continually evolve their tactics.
7 months ago
Kill Chain
Unpatched SMS Flaw in OnePlus Phones Leaves User Messages Exposed
In September 2025, a critical, still-unpatched vulnerability (CVE-2025-10184) was publicly disclosed in OnePlus smartphones running OxygenOS 12 through 15. Discovered by Rapid7, the flaw enables any installed app—without explicit permissions or user input—to access and exfiltrate SMS content and metadata on affected devices. This exposure was caused by insecurely exported content providers in the custom Android Telephony package, allowing SQL injection-style inference attacks. Despite multiple disclosure attempts, OnePlus did not respond for over four months; the details, including a proof of concept, were disclosed publicly to accelerate a fix. The case underscores rising risks from insecure mobile customizations and vendor slow response, especially as attackers increasingly exploit flaws in widely deployed consumer devices. With the proliferation of mobile-centric attacks and regulatory scrutiny on data privacy, this breach highlights the urgent need for robust patch management and proactive mobile security.
7 months ago
Kill Chain
Cisco's 2025 SNMP Zero-Day: Credential Compromise Drives Network Device Exploit Surge
In September 2025, Cisco disclosed a high-severity zero-day vulnerability (CVE-2025-20352) affecting IOS and IOS XE network infrastructure devices. The flaw, a stack-based buffer overflow in the SNMP subsystem, allowed remote, authenticated attackers with low privileges to cause denial-of-service and, in some cases, permitted high-privileged attackers to fully compromise devices. Exploitation was detected after local administrator credentials were stolen, enabling threat actors to send malicious SNMP packets over IPv4/IPv6, impacting unpatched devices globally. Immediate patching was recommended as no workarounds existed except tightly restricting SNMP access. This incident underscores the criticality of timely patching and robust identity and network access controls, as attackers increasingly target network infrastructure via both credential compromise and protocol-level vulnerabilities. Industry-wide, it marks an escalating trend of high-impact, infrastructure-level exploits requiring urgent coordinated response.
7 months ago
Kill Chain
Attackers Leverage Pandoc SSRF Vulnerability CVE-2025-51591 to Breach AWS IMDS
In September 2025, threat actors exploited a newly disclosed Server-Side Request Forgery (SSRF) vulnerability in the open-source Linux utility Pandoc (CVE-2025-51591), targeting Amazon Web Services (AWS) cloud environments. The attackers leveraged the flaw to send unauthorized requests to the AWS Instance Metadata Service (IMDS), allowing them to obtain EC2 role credentials and elevate cloud permissions. Security researchers, including Wiz, observed active exploitation in the wild, leading to unauthorized access and potential data exfiltration from affected AWS infrastructure. Organizations relying on Pandoc as part of their cloud automation workflows face heightened risk of credential compromise and lateral movement across accounts. This incident underscores a fast-evolving cloud threat landscape, where attackers exploit supply-chain and open-source vulnerabilities to traverse trusted infrastructure and target sensitive identity and metadata services. The rapid weaponization of CVE-2025-51591 mirrors the broader trend of SSRF attacks on cloud metadata, driving urgent calls for proactive detection, segmentation, and credential management in multi-cloud environments.
7 months ago
Kill Chain
State-Sponsored Actors Breach Libraesva ESG via Command Injection Vulnerability
In September 2025, Libraesva disclosed a command injection vulnerability (CVE-2025-59689, CVSS 6.1) affecting its Email Security Gateway (ESG) platform, which was actively exploited by state-sponsored threat actors. Attackers leveraged maliciously-crafted email payloads to trigger remote command execution, bypassing ESG protections and potentially gaining persistent access to targeted networks. The intrusion method allowed attackers to move laterally and exfiltrate sensitive data, underscoring the risks posed by the exploitation of security appliances themselves. Libraesva released emergency patches and urged customers to upgrade immediately, as evidence emerged of ongoing targeted campaigns against critical sectors. This incident highlights the increasing use of email gateway exploits by sophisticated adversaries, aligning with a wider trend of targeting security infrastructure for initial access. With command injection flaws on the rise and ransomware operators adopting similar approaches, organizations face escalating pressure to rapidly patch vulnerabilities and reinforce segmentation and anomaly detection across their environments.
7 months ago
Kill Chain
YiBackdoor: A Sophisticated Backdoor Malware Campaign Bridging IcedID and Latrodectus
In June 2025, researchers discovered YiBackdoor, a novel malware family exhibiting significant source code overlaps with the notorious IcedID and Latrodectus strains. Campaigns leveraging YiBackdoor execute advanced backdoor techniques that establish remote access, command execution, and data exfiltration within compromised environments. YiBackdoor is typically deployed as part of a multi-stage attack campaign, using phishing or malicious attachments as its primary entry vector. Its detection signaled the emergence of new collaborative threats between criminal malware groups, raising concerns over increased code sharing and tool evolution. This incident highlights growing technical sophistication and cross-pollination between established malware actors. The use of YiBackdoor in conjunction with IcedID and Latrodectus demonstrates adversary agility and the accelerated pace of malware innovation, elevating the threat to enterprises reliant on traditional detection models.
7 months ago
Kill Chain
Iframe Security Exposed: The 2025 Rise of Payment Skimmer Attacks
In September 2025, a widespread web application attack exploited payment iframes across major online retailers to deploy advanced payment skimmer malware. Attackers leveraged vulnerabilities in embedded iframe components on e-commerce checkout pages, bypassing client-side security controls and web isolation policies to secretly harvest customer credit card data. The campaign remained undetected for weeks, affecting thousands of transactions globally and prompting emergency mitigation efforts, reputational impact, and regulatory scrutiny for affected organizations. This incident highlights the urgent need for stronger web application and iframe security, as payment skimming through novel overlay techniques continues to surge. Organizations are under increased regulatory pressure to harden PCI compliance and prevent supply chain-driven client-side attacks.
7 months ago
Kill Chain
Critical Wondershare RepairIt Vulnerabilities in 2025 Expose User Data and AI Models
In September 2025, security researchers from Trend Micro uncovered two critical vulnerabilities in Wondershare RepairIt, a leading file repair software. Identified as CVE-2025-10643 (authentication bypass, CVSS 9.1) and a second AI model tampering flaw, these vulnerabilities allowed unauthorized attackers to access sensitive user information and potentially manipulate embedded AI models. Exploitation could be achieved over unencrypted traffic routes, making lateral movement and data exfiltration easier for adversaries. The flaws highlighted the growing risks associated with AI-driven software and the increased attack surface presented by supply chain exposures. This incident underscores the urgency of securing both traditional application logic and the growing use of embedded AI models. Adversaries are increasingly targeting AI supply chains and exploiting weak east-west segmentation controls, a pattern observed in several recent breaches. Regulatory scrutiny and customer expectations around data protection continue to mount.
7 months ago
Kill Chain
How a Single Weak Password Caused the Collapse of KNP Logistics
In August 2023, KNP Logistics Group—one of the UK’s oldest haulage companies—fell victim to a catastrophic ransomware attack after cybercriminals exploited a weak, reused password to gain initial access. The attackers leveraged this compromised credential to breach internal systems, move laterally, and deploy ransomware, severely encrypting business-critical data. Operations halted, hundreds of employees were affected, and the incident ultimately forced the 158-year-old business into administration, marking a rare instance where a cyberattack directly led to company collapse. This breach exemplifies a growing wave of highly disruptive ransomware attacks exploiting basic identity and password hygiene gaps. As threat actors increasingly target legacy industries and critical infrastructure with credential-based intrusions, the risk to business continuity is escalating—pressing organizations to reevaluate access controls and cyber resilience.
7 months ago
Kill Chain
Steganography Strikes: npm Supply Chain Breach Hides Malware in JavaScript Package (2024)
In June 2024, a malicious npm JavaScript package was discovered masquerading as a utility library while covertly deploying a credential-stealing malware. Attackers cleverly embedded the malicious payload using steganography by hiding harmful code within QR code images bundled in the package. Once installed by developers, the malware extracted sensitive credentials and communicated with attacker-controlled infrastructure, posing a significant risk to any organization that unknowingly integrated the tainted dependency in its software supply chain. This incident underscores the mounting threat posed by highly obfuscated, supply chain attacks leveraging trusted open-source platforms. The attack highlights the emergence of sophisticated malware delivery via unconventional vectors such as steganographic encoding within common file formats. With broad software ecosystem dependencies and rapid code adoption, organizations face increasing urgency to vet third-party packages and enforce robust supply chain security controls.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports