✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Azure AD Credential Exposure: Public Config File Leak Spotlights Cloud Risks
In early 2024, a significant security incident was discovered involving the inadvertent exposure of Azure Active Directory credentials via a misconfigured JSON configuration file. The public accessibility of this file enabled malicious actors to directly authenticate against Microsoft’s OAuth 2.0 endpoints, bypassing traditional security controls and potentially infiltrating cloud environments. Attackers leveraged this cloud misconfiguration to escalate cloud access, risking business-critical Azure resources, data loss, and lateral movement inside affected organizations. Detection came after researchers observed unusual authentication patterns linked to public file sharing, prompting rapid investigation and remediation efforts. The incident underscores how easily overlooked misconfigurations can undermine enterprise cloud security and compliance obligations. The breach highlights ongoing challenges as organizations migrate sensitive workflows to the cloud. Public file exposure, credential leakage, and abuse of identity platforms like Azure Active Directory remain top attack vectors. This incident amplifies recent regulatory scrutiny, reinforces the need for cloud visibility and zero trust practices, and signals rising attacker sophistication in exploiting misconfigured storage and identity controls.
7 months ago
Kill Chain
Phishing Empire Unmasked: How Cloud Phishing-as-a-Service Campaigns Evade Detection
In 2024, a sophisticated phishing-as-a-service (PhaaS) operation leveraged Google and Cloudflare infrastructure to host undetectable phishing sites for over three years. By employing advanced cloaking techniques and encrypted traffic, threat actors were able to evade detection by security platforms and browsers, targeting users globally and harvesting credentials at scale. The persistent campaign highlights the effectiveness of public cloud abuse for malicious operations and the operational difficulties organizations face in detecting and mitigating such well-cloaked threats. This incident underscores a growing trend: cybercriminals turning to public cloud providers for reliable infrastructure and exploiting their reputation to bypass security controls. It also signals the adaptability of phishing campaigns and the need for enhanced monitoring and zero trust strategies in response to evolving attacker TTPs.
7 months ago
Kill Chain
APT28 Exploits Microsoft Outlook: Inside the 2024 NotDoor Backdoor Attack
In 2024, the Russian state-sponsored group APT28 (also known as Fancy Bear) leveraged a new backdoor called "NotDoor" to infiltrate targeted organizations via Microsoft Outlook. Researchers from Lab52 revealed that attackers delivered NotDoor using DLL sideloading through OneDrive.exe, enabling them to bypass Outlook's macro security and gain persistent access. Once deployed, NotDoor monitored incoming Outlook emails for specific trigger words, allowing APT28 to exfiltrate sensitive data, upload malicious files, and execute remote commands without detection. Outlook's native functions were abused to provide covert communications and stealthy data transfers, making detection difficult. This incident illustrates the continued evolution of state-sponsored attack methods, especially the abuse of ubiquitous business software like Microsoft Outlook for stealthy, command-and-control operations. Organizations face mounting pressure to address advanced persistent threats exploiting native application behaviors and to enhance email and endpoint security in response to these sophisticated tactics.
7 months ago
Kill Chain
European Crypto Fraud Ring Dismantled After €100 Million Theft
In September 2025, European law enforcement agencies coordinated by Eurojust and Europol dismantled a cryptocurrency investment fraud ring, arresting five suspects linked to more than €100 million ($118 million) in stolen funds. The operation, spanning several countries including Spain, Portugal, Bulgaria, Italy, Lithuania, and Romania, targeted a sophisticated group that lured victims with promises of high returns through professional online platforms. Funds from over 100 victims across 23 countries were diverted into controlled accounts, masked by additional recovery fees and subsequent website takedowns, resulting in substantial losses and significant reputational damage. This incident underscores the growing scale and sophistication of crypto-based financial fraud targeting both individuals and organizations globally. The case highlights the necessity for robust fraud prevention, regulatory vigilance, and proactive threat detection in the rapidly evolving crypto investment landscape.
7 months ago
Kill Chain
FDN3’s Massive Brute-Force Attacks Target VPN & RDP Devices Globally (2025)
Between June and July 2025, Ukrainian autonomous system FDN3 (AS211736) orchestrated large-scale brute-force and password spraying attacks targeting SSL VPN and Remote Desktop Protocol (RDP) devices across multiple regions. The campaign, identified and attributed by French cybersecurity firm Intrinsec, involved distributed login attempts to compromise organizations’ remote access infrastructure using stolen or weak credentials. This led to unauthorized system access, at-risk sensitive data, and the potential for further lateral movement inside target environments. The attack underscored the critical vulnerabilities that arise when VPNs and RDP servers are exposed without adequate security controls. This incident is emblematic of the growing trend of threat actors exploiting internet-facing authentication portals with automated credential attacks. As organizations continue to rely on remote access solutions, adversaries are increasingly targeting SSL VPN and RDP endpoints to gain initial entry—a method further complicated by the prevalence of weak password policies, limited anomaly detection, and insufficient segmentation.
7 months ago
Kill Chain
Nx npm Supply Chain Breach 2025: AI Stealer Exposes Over 1,000 Developer Secrets
In late August 2025, a highly automated supply chain attack compromised the popular Nx build system on npm, enabling unidentified attackers to infect more than 1,000 JavaScript developers within just four hours. Malicious packages, leveraging artificial intelligence through CLI integrations, actively scanned victim environments for GitHub tokens, npm credentials, SSH keys, cloud secrets, and cryptocurrency wallets—exfiltrating roughly 20,000 sensitive files. Instead of using traditional command and control servers, the attackers published victims’ stolen data into public GitHub repositories, complicating detection and enabling rapid collection by threat actors. This incident marks a significant escalation in software supply chain threats by demonstrating the abuse of AI-driven reconnaissance and novel exfiltration via legitimate platforms. The swift, large-scale impact underscores rising attacker sophistication and amplified operational risk, especially as AI and developer tooling become more deeply embedded in build pipelines and cloud-native workflows.
7 months ago
Kill Chain
Amazon Disrupts APT29 Credential Theft Leveraging Cloudflare and Device Code Abuse
In early 2024, Amazon identified and disrupted a credential theft campaign orchestrated by the Russian-linked threat actor APT29 (also known as Cozy Bear or Midnight Blizzard). Attackers redirected targeted users to fraudulent Cloudflare verification pages and abused Microsoft's device code authentication flow to harvest credentials. This sophisticated phishing operation targeted employees with access to sensitive resources and leveraged social engineering along with technical exploits to bypass multi-factor authentication controls. Amazon’s security team coordinated rapid takedown efforts, mitigating potential compromise before widespread damage or data loss could occur. This incident exemplifies the increasing sophistication of nation-state actors, particularly in leveraging supply chain services and authentication protocols. The widespread adoption of identity and device-based authentication has introduced new attack surfaces, highlighting the urgent need for adaptive security measures and ongoing user vigilance in credential management.
7 months ago
Kill Chain
How a Zero-Click Exploit Unleashed AI Agent Mayhem Across Enterprises
In July 2025, researchers disclosed a critical vulnerability affecting generative AI agents deployed widely across enterprises. This exploit, requiring no user interaction (zero-click), enabled remote attackers to commandeer AI agents and gain broad, unauthorized access to sensitive business data and interdependent cloud applications. By leveraging the AI agents’ elevated privileges and extensive network reach, attackers could move laterally across organizational boundaries, exposing data in transit, triggering egress to attacker-controlled infrastructure, and bypassing traditional segmentation and policy enforcement. The incident resulted in heightened risk for data exfiltration, business interruption, and regulatory scrutiny as organizations scrambled to assess and mitigate exposure. This breach highlights the growing risks of autonomous AI behavior and the challenges of applying conventional network and application security frameworks to evolving AI-driven architectures. The attack underscores the urgent need for robust segmentation, encrypted traffic, and continuous threat monitoring in AI/ML environments, as both threat actors and defenders rapidly adapt to the rise of agentic AI.
7 months ago
Kill Chain
Federal Agency Breached via GeoServer RCE Exploit in 2024
In July 2024, a U.S. federal civilian executive branch agency suffered a significant security breach when attackers exploited a critical remote code execution (RCE) vulnerability (CVE-2024-36401) in an unpatched GeoServer instance. Threat actors gained initial access by leveraging proof-of-concept exploits that had been made public after the vulnerability's disclosure. They moved laterally across the agency’s internal network, breaching additional web and SQL servers, deploying web shells like China Chopper, escalating privileges, and maintaining persistence. The attackers remained undetected for three weeks, only triggering detection when the agency’s EDR tool flagged suspicious malware activity. This breach underscores the growing risk posed by rapid weaponization of new vulnerabilities, particularly those affecting widely used open-source platforms. The incident follows a trend of increased attacks exploiting unpatched systems and weak internal segmentation, emphasizing the urgent need for proactive vulnerability management and robust East-West traffic controls.
7 months ago
Kill Chain
Nearly 2,000 MCP Servers Left Exposed by Authentication Misconfiguration in 2024
In early 2024, security researchers discovered that nearly 2,000 MCP (Management Control Plane) servers worldwide were left completely unsecured due to disabled or unconfigured authentication settings. This cloud misconfiguration meant that anyone with internet access could gain full administrative control, potentially allowing unauthorized parties to manipulate workloads, exfiltrate sensitive data, or deploy malicious software at will. The lack of basic security controls exposed organizations leveraging agentic AI services to severe operational risks, compliance violations, and potential breaches of critical business infrastructure. This incident underscores a troubling pattern of cloud misconfiguration, particularly as organizations rapidly adopt AI and cloud-native platforms. As threat actors increasingly target exposed management interfaces and identity systems, the urgent need for robust authentication and continuous configuration monitoring has never been greater.
7 months ago
Kill Chain
Amazon ECS Privilege Escalation Flaw Exposes Critical IAM Risks in 2024
In early 2024, an independent security researcher uncovered a privilege escalation vulnerability in Amazon Elastic Container Service (ECS) that allowed attackers to abuse an undocumented protocol to gain IAM permissions well beyond their original access. By exploiting a misconfiguration in ECS’s internal handling of credentials, a malicious user could escalate from container-level privileges to full IAM role hijacking, enabling lateral movement across cloud environments and access to sensitive AWS resources. Amazon responded quickly and patched the issue after disclosure, but the flaw potentially exposed numerous customer environments to risk. This incident underscores the growing risk of cloud misconfigurations and privileged identity attacks, as well as the need for real-time monitoring of cloud service behaviors. Security teams should recognize the increasing creativity of threat actors targeting identity and access weaknesses within major cloud providers.
7 months ago
Kill Chain
Cloud Misconfig Leaves 2,000 MCP Servers Wide Open to Attack
In June 2024, security researchers uncovered that nearly 2,000 MCP (Managed Cloud Platform) servers were left exposed to the public internet without any authentication required. Attackers could readily gain unfettered administrative access, enabling full server control, lateral movement within environments, and potential exfiltration or disruption of sensitive workloads. The breach was a direct result of critical cloud misconfigurations, specifically the omission of basic authentication on systems underpinning key business and AI operations. While no single threat actor has been publicly attributed, the sheer scale exposes businesses globally to automated attacks, data theft, and business disruption. This incident highlights the persistent danger of insecure cloud defaults, particularly as organizations accelerate adoption of agentic AI and cloud-native architectures. With threat actors increasingly scanning for misconfigured cloud assets and attacker dwell time decreasing, timely secure configuration and visibility are more essential than ever.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports