✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Google Gemini AI AI Vulnerability Enables Stealth Phishing Across Google Products
In early 2024, a significant vulnerability was uncovered in Google’s Gemini AI assistant, exposing users across Google platforms to sophisticated prompt injection attacks. Adversaries leveraged this flaw to craft invisible, malicious prompts that disguised themselves as legitimate Google Security alerts, tricking users and facilitating vishing and phishing attacks. The flaw allowed threat actors to bypass visible UI cues, broadening attack reach across Google applications and potentially compromising internal data and account integrity. Google was notified and began remediation efforts, but the proof-of-concept highlighted how large-scale AI platforms present new attack surfaces. This incident reflects an emerging trend where AI-driven tools are being targeted through prompt injection and model manipulation, creating challenging attack vectors for even the largest technology firms. The Gemini vulnerability underscores the importance of advanced security testing for generative AI and the urgent need for zero trust controls within AI ecosystems.
7 months ago
Kill Chain
2025’s Multichannel Phishing Surge: How Attackers Bypassed MFA and Hijacked Sessions
In early 2025, a wave of sophisticated phishing attacks exploited new multichannel vectors, including social media platforms, malicious search advertisements, and browser-based manipulation, to bypass multi-factor authentication and steal user sessions. Threat actors rapidly adapted to defensive advances, leveraging session hijacking and advanced social engineering to deceive users, often eclipsing legacy email-based phishing. Organizations reported credential compromise, unauthorized access to sensitive resources, and downstream data breaches as a result of these evolving techniques. The relevance of this incident is underscored by the acceleration of identity-based attacks, targeting hybrid and cloud environments and challenging traditional security controls. Regulatory focus on data privacy and authentication heightens the need for organizations to reassess their phishing defenses, user awareness, and session protection strategies.
7 months ago
Kill Chain
Malicious Implants in AI Supply Chains: 2024’s Stealth Attack Surface
In early 2024, security researchers uncovered evidence that malicious implants are increasingly targeting AI components and applications through vulnerabilities in the supply chain. Threat actors leveraged weaknesses in popular AI frameworks and third-party dependencies to introduce stealthy backdoors and implants, enabling them to evade modern security tools. The attackers often exploited insufficient validation of AI model inputs, compromised third-party code, or leveraged misconfigurations to achieve persistent access and lateral movement within enterprise environments, resulting in sensitive data exposure and operational risk for organizations deploying AI-driven solutions. This incident underlines an emerging trend where cybercriminals and nation-state actors prioritize supply-chain vectors to subvert the rapidly expanding AI ecosystem. As AI adoption accelerates and digital trust becomes paramount, organizations face increased regulatory scrutiny and pressure to implement robust controls around software provenance and supply chain integrity.
7 months ago
Kill Chain
GhostPoster: Malicious Firefox Add-ons Drive 2025 Supply-Chain Breach
In late 2025, security researchers at Koi Security uncovered a widespread supply-chain malware campaign named "GhostPoster." This campaign weaponized 17 Mozilla Firefox browser add-ons, leveraging benign logo files to conceal malicious JavaScript that hijacked affiliate links, injected tracking codes, and orchestrated click and ad fraud operations. The compromised extensions had garnered over 50,000 downloads before Mozilla intervened to remove them from its add-on repository, but users were already exposed to extensive privacy intrusions and potential data exfiltration. The GhostPoster incident underscores a growing trend of exploiting trusted browser extension ecosystems for mass infection and financial fraud. With attackers increasingly targeting supply-chain vectors and browser add-ons, organizations and individuals must reevaluate extension vetting processes amid surging regulatory scrutiny and evolving adversary techniques.
7 months ago
Kill Chain
WhatsApp GhostPairing: 2024 Account Takeover Campaign Exploits Device Linking
In June 2024, cyber attackers launched widespread account takeover campaigns targeting WhatsApp users by exploiting the platform’s legitimate device-linking feature. This method, known as 'GhostPairing,' allows threat actors to hijack user accounts without requiring the victim’s credentials or multi-factor authentication codes. By intercepting or tricking users into sharing device-linking codes, attackers can remotely pair new devices to victims’ WhatsApp accounts, thus gaining complete access to conversations, contacts, and stored media. The campaign appears automated and has affected users globally, sparking concerns over the resilience of messaging platform identity controls. This incident highlights rising abuse of legitimate features and growing sophistication of social engineering tactics to bypass traditional security controls. Similar account compromise techniques are increasingly observed across the industry, prompting urgent calls for strengthened identity verification and robust monitoring of device association activities.
7 months ago
Kill Chain
Chinese APT Exploits Cisco AsyncOS Zero-Day in 2025: What You Need to Know
In December 2025, Cisco disclosed an unpatched, maximum-severity zero-day vulnerability (CVE-2025-20393) affecting AsyncOS running on Cisco Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances with exposed Spam Quarantine features. Leveraging this zero-day, the Chinese-nexus APT group UAT-9686 exploited systems by executing commands as root, deploying persistent backdoors (AquaShell), reverse SSH tunnels (AquaTunnel, Chisel), and evasion tools (AquaPurge). The campaign was active from late November 2025, with intrusions traced to sophisticated nation-state tooling and lateral movement, potentially compromising sensitive email infrastructure and enabling persistent access. This incident underscores ongoing risks from zero-day exploitation by advanced threat actors, especially those leveraging public-facing management interfaces and unpatched systems for initial access. The active exploitation by a Chinese APT mirrors broader trends in targeted cyberespionage against enterprise collaboration tools and highlights the urgency of proactive exposure management and segmentation.
7 months ago
Kill Chain
State-Backed Attackers Breach SonicWall SMA1000 Devices via Zero-Day Chain in 2025
In December 2025, SonicWall urgently advised customers to patch a newly identified zero-day vulnerability (CVE-2025-40602) in its SMA1000 Appliance Management Console after attackers exploited it in the wild. The attack chain combined this medium-severity local privilege escalation flaw with a critical pre-authentication deserialization vulnerability (CVE-2025-23006), allowing remote unauthenticated threat actors to execute arbitrary OS commands with root privileges on vulnerable appliances. These appliances serve as secure remote access gateways for large enterprises and critical infrastructure, amplifying the risk of broad organizational compromise and lateral movement within protected networks. The incident follows prior breaches and repeated targeting of SonicWall solutions by sophisticated, potentially state-backed actors, with over 950 SMA1000 devices found internet-exposed. Immediate remediation was urged to prevent further exploitation amidst evidence of active, targeted attacks. The SonicWall SMA1000 incident underscores a persistent trend of advanced actors leveraging zero-day exploits in network infrastructure appliances, fueling urgency around patch management and segmentation. This breach highlights the evolving complexity of attack chains targeting foundational remote access technologies and the critical need for proactive defense-in-depth and threat visibility measures.
7 months ago
Kill Chain
How Weaxor Ransomware Leveraged the React2Shell Vulnerability in 2025
In December 2025, cybercriminals exploited the critical React2Shell vulnerability (CVE-2025-55182) in React Server Components and Next.js to gain unauthorized access to a corporate endpoint. Within seconds, attackers deployed the Weaxor ransomware strain, rapidly encrypting files and appending a '.WEAX' extension, while dropping ransom notes named 'RECOVERY INFORMATION.txt' in each directory. The attack began by delivering an obfuscated PowerShell command, installing a Cobalt Strike beacon for command-and-control, disabling Windows Defender, wiping shadow copies, and clearing logs to evade detection and hinder forensic analysis. Researchers confirmed there was no lateral movement or data exfiltration prior to encryption, and the targeted machine was subsequently compromised by additional threat actors. This incident highlights the widespread exploitation of recently disclosed vulnerabilities by both ransomware gangs and nation-state actors. With opportunistic attacks increasing in speed and automation, organizations must improve patch velocity and advanced monitoring to defend against emerging, rapidly weaponized threats.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports