The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Chinese APT Exploits Cisco Zero-Day in Secure Email Gateways (2024)
In late 2024, Cisco disclosed that a Chinese state-sponsored advanced persistent threat (APT) group, tracked as UAT-9686, exploited a critical zero-day vulnerability (CVE-2025-20393, CVSS 10) in Cisco AsyncOS software for Secure Email Gateway and Web Manager. Attackers gained unrestricted command execution by abusing non-standard, publicly exposed configurations of the spam quarantine feature, allowing them to implant persistent backdoors and fully compromise targeted environments. The campaign has been active since at least November 2024 and prompted rapid advisories following detection in early December. While the vulnerability remains unpatched, Cisco urged immediate risk mitigation steps for potentially affected customers. This incident highlights ongoing targeting of network appliances and email infrastructure by sophisticated Chinese APTs, leveraging zero-days and configuration weaknesses. It underscores the urgent need for better threat visibility, segmentation, and rapid incident response, especially as attackers increasingly weaponize supply chain and cloud service vulnerabilities.
8 months ago
Kill Chain
HPE OneView 2025: Critical Remote Code Execution Flaw Places Global Enterprises at Risk
In December 2025, Hewlett Packard Enterprise (HPE) disclosed a maximum-severity security vulnerability (CVE-2025-37164) in its HPE OneView infrastructure management software. The flaw enabled unauthenticated remote attackers to execute arbitrary code on affected systems through low-complexity code injection, threatening widespread compromise of connected server, storage, and networking infrastructure. Reported by security researcher Nguyen Quoc Khanh, the vulnerability affected all OneView versions prior to v11.00, with no workarounds or mitigations available aside from applying vendor patches or hotfixes. As of publication, there were no confirmed reports of exploitation in the wild, but the risk to global HPE customers—including many Fortune 500 companies—was considered severe. The incident highlights the ongoing risks posed by critical remote code execution vulnerabilities in widely-used infrastructure management tools. With attackers regularly scanning for vulnerable systems and exploiting them in supply chain and ransomware campaigns, organizations must prioritize rapid patching and holistic vulnerability management to stay resilient.
8 months ago
Kill Chain
Cisco Email Security Breach 2025: 0-Day Exploited by China-Linked APT
In December 2025, Cisco issued an urgent warning about active exploitation of a critical zero-day vulnerability in its AsyncOS software, which powers Cisco Secure Email Gateway and Secure Email and Web Manager appliances. A sophisticated, China-linked Advanced Persistent Threat (APT) group tracked as UAT-9686 successfully bypassed security controls to gain unauthorized access to unpatched devices. The exploitation enabled attackers to intercept, manipulate, or exfiltrate sensitive business communications, putting enterprise and government clients at significant risk. The vulnerability was disclosed following observed intrusions, prompting emergency advisories and a scramble among organizations to patch affected systems and review their email security postures. This incident highlights an ongoing trend of state-sponsored groups targeting core enterprise email systems via unknown or unpatched flaws. As attackers increasingly adapt to evolving defenses and zero-day vulnerabilities, organizations must prioritize rapid patch management and enhance segmentation and monitoring strategies against persistent, sophisticated threats.
8 months ago
Kill Chain
E-Note Crypto Exchange Seized: $70M Ransomware Laundering Operation Disrupted
In December 2025, U.S. law enforcement agencies, in collaboration with Finnish and German authorities, seized the E-Note cryptocurrency exchange after investigating its role in facilitating ransomware-related money laundering. The FBI identified that over $70 million in proceeds from ransomware attacks and account takeover operations were funneled through E-Note since 2017, relying on a broad, international money mule network. The operation involved confiscating E-Note’s domains, mobile applications, servers, and transaction databases, severely disrupting a key enabling service for cybercriminals and potentially exposing a wide array of threat actors utilizing the platform. The alleged operator, Mykhalio Petrovich Chudnovets, has been indicted for money laundering and faces significant penalties. The takedown of E-Note highlights growing law enforcement action against illicit cryptocurrency infrastructure used by ransomware operators and cybercriminal ecosystems. The incident exemplifies an intensifying focus on disrupting financial channels that allow attackers to monetize stolen data and ransom payments, signaling increasing risk for enablers and users of such services.
8 months ago
Kill Chain
Automated Credential Attacks Storm Cisco & Palo Alto Networks VPNs
In December 2025, automated credential attacks targeted enterprise VPN gateways from Cisco and Palo Alto Networks. Threat monitoring platforms such as GreyNoise observed a surge of password spraying attempts, with 1.7 million login probes against Palo Alto GlobalProtect portals within 16 hours, and coordinated activity later targeting Cisco SSL VPNs. The attacks originated from over 10,000 unique IPs, predominantly routed through the 3xK GmbH cloud provider in Germany. Attackers employed scripted credential stuffing—leveraging common username and password combinations—to probe for weak authentication endpoints, with no evidence of software vulnerabilities being exploited. This campaign highlights the ongoing evolution and scale of credential-based attacks targeting critical remote access infrastructure. As password spraying and automated reconnaissance increase, robust authentication and monitoring remain pivotal to defending against perimeter breaches, especially as threat actors exploit enterprise weaknesses during periods of heightened cyber activity.
8 months ago
Kill Chain
Clop Ransomware Hits Gladinet CentreStack: 2025 Data Theft Alert
In December 2025, the Clop ransomware gang initiated a widespread extortion campaign by exploiting internet-facing Gladinet CentreStack file servers. Gladinet CentreStack, used by thousands of businesses worldwide, enables remote file sharing without VPNs. The attackers scanned for accessible servers, exploited a yet-undetermined (potentially zero-day or unpatched) vulnerability, and exfiltrated sensitive business data, leaving ransom notes for victims. The breaches escalated concerns after Clop’s history with major file transfer solutions, such as MOVEit and Oracle EBS, resulting in significant data leaks and operational disruption for affected organizations. This attack underscores the persistent risk posed by sophisticated ransomware groups exploiting file transfer and sharing platforms. With attackers rapidly leveraging unknown or unpatched security flaws, enterprises must prioritize robust vulnerability management for all internet-exposed assets and monitor threat actor trends targeting remote-access file servers.
8 months ago
Kill Chain
HPE OneView 2025: CVE-2025-37164 Remote Code Execution Threat
In June 2025, Hewlett Packard Enterprise (HPE) patched a critical vulnerability (CVE-2025-37164) in its OneView infrastructure management software, allowing unauthenticated remote code execution via network exposure. Rated CVSS 10.0, the flaw enabled threat actors to gain full control over affected systems by exploiting improper input validation in OneView’s remote management interfaces. This vulnerability posed immediate risk to critical infrastructure across industries relying on OneView for centralized management, potentially resulting in disruption, unauthorized access, or lateral movement within enterprise environments. The discovery highlights ongoing concerns around enterprise software supply chain security and the elevated threats facing privileged IT management tools. Increasingly, sophisticated threat actors target such infrastructure software to bypass traditional security controls, emphasizing the urgency for timely patching and advanced east-west traffic controls.
8 months ago
Kill Chain
North Korea’s $2 Billion Crypto Heist: 2025’s Largest Nation-State Cyber Attack
In 2025, threat actors closely tied to North Korea orchestrated a record-breaking $2.02 billion in cryptocurrency thefts, representing over half of the global digital asset losses for the year. These attackers leveraged sophisticated intrusion techniques, advanced persistent threat (APT) operations, and exploited vulnerabilities in decentralized finance (DeFi) platforms and exchanges from January through early December. High-value thefts were often facilitated by exploiting weak internal controls, compromised credentials, and security gaps in cross-chain bridges, resulting in severe financial losses for both exchanges and their clients. This incident marks a significant escalation in nation-state cybercrime and highlights evolving attacker sophistication in targeting cryptocurrency infrastructure. It underscores escalating regulatory scrutiny and the necessity for organizations to bolster east-west traffic controls, threat detection, and zero trust architectures in response to persistent, financially-motivated adversaries.
8 months ago
Kill Chain
2025 Multi-Vector Breach: WhatsApp Hijacks, MCP Leaks & AI Threats Signal New Era of Cyber Attacks
In December 2025, adversaries leveraged multiple cyberattack vectors—including WhatsApp account hijacking, major control plane (MCP) data leaks, generative AI reconnaissance, and the React2Shell exploit—to target organizations worldwide. Attackers combined social engineering, exploitation of unpatched vulnerabilities, and east-west traffic movement for lateral compromise. The orchestration of these tactics led to large-scale credential theft, successful ransomware deployment, and significant data exfiltration across cloud and on-premise environments. Notably, sophisticated evasion and automation tools hindered early detection and response, increasing operational disruption and risk exposure for affected enterprises. This incident exemplifies how weaponized AI, hybrid cloud vulnerabilities, and multi-vector attacks are converging. Organizations face growing urgency for zero trust segmentation, improved encrypted traffic controls, and comprehensive threat detection as attackers exploit interconnected infrastructure weaknesses and automation gaps.
8 months ago
Kill Chain
Sha1-Hulud 2025: The Multi-Vector Threat Campaign that Redefined Cloud Security
In December 2025, security researchers observed a sophisticated multi-vector attack campaign, dubbed 'Sha1-Hulud,' targeting organizations across North America, Europe, and Asia. The campaign leveraged vulnerabilities in remote management tools such as ScreenConnect and MacSync to gain initial access, then proceeded laterally using encrypted traffic, zero trust segmentation evasion, and cloud-native pivoting. Attackers deployed covert remote access tools and exploited gaps in cloud firewall and egress controls to move data out, leaving organizations grappling with data theft, systems downtime, and regulatory exposure. This incident is notable for its integration of advanced encryption bypass, multicloud movement, and the blending of traditional and cloud-native evasion tactics. The convergence of infrastructure and cloud threats highlights the need for ubiquitous visibility, modern segmentation, and coordinated policy enforcement in response to increasingly diverse and distributed attacks.
8 months ago
Kill Chain
React2Shell 2025: When AI-Generated Exploits Complicate Supply Chain Defense
In December 2025, the cybersecurity community was rocked by mass exploitation efforts targeting "React2Shell," a critical vulnerability in the popular React UI framework. Threat actors, including China-linked groups, quickly launched attacks just hours after the initial public advisory. Amid the chaos, researchers and automated AI tools published over a hundred proof-of-concept (PoC) exploits—many of which were either nonfunctional or misrepresented the true risk, leading to widespread confusion. This "AI slop" polluted vulnerability feeds and caused defenders to waste valuable time, potentially resulting in underestimating the urgency to patch real flaws. The incident exposed significant weaknesses in open-source supply chain security, the peer-review process for public PoCs, and how security teams triage emerging threats. The React2Shell event is emblematic of the growing challenges defenders face as AI-generated code and public exploit sharing accelerate the pace and volume of security noise. With enterprises relying on automated detection and research, this incident highlights systemic risks posed by false negatives, delayed remediation, and rushed patch management in the face of incomplete or misleading information.
8 months ago
Kill Chain
Cellik RAT’s Google Play Store Infiltration Exposes Mobile Security Gaps
In June 2024, cybersecurity researchers uncovered that the Cellik Android Remote Access Trojan (RAT) was being distributed through malicious applications on the official Google Play Store. The Cellik RAT allows attackers to remotely control infected Android devices, harvest sensitive credentials, and exfiltrate private data without the user’s knowledge. Threat actors used advanced evasion tactics, including app generation within Play Store guidelines and encrypted communications, to bypass traditional defenses. The incident highlights weaknesses in mobile app review processes and demonstrates the continued use of popular app stores as distribution vectors for sophisticated malware campaigns. This breach is especially notable as attackers continue to exploit trusted platforms like the Google Play Store, elevating risk for both individuals and enterprises. The emergence of Cellik marks an uptick in mobile RAT sophistication and underscores the urgent need for stronger app vetting and threat detection on mainstream digital ecosystems.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports