The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Phishing in 2025: How Stolen Data Hits Telegram and the Dark Web Faster Than Ever
In early-to-mid 2025, a broad wave of phishing campaigns leveraged sophisticated data harvesting tools—including Telegram bots and automated admin panels—to exfiltrate user credentials and personal data from victims worldwide. Attackers collected credentials through fraudulent pages, relayed them instantly over secure messaging apps or specialized dashboards, and then swiftly funneled the stolen information into darknet marketplaces. Stolen data ranged from email logins and banking details to scans of personal documents, which were sorted, validated, and commoditized for direct fraud, resale, or subsequent targeted attacks on individuals and organizations. This incident highlights the acceleration of phishing-as-a-service ecosystems driven by real-time, evasive data exfiltration via commodity tools. The commodification of personal and corporate credentials intensifies regulatory and reputational risks, as stolen data is increasingly recycled for follow-on attacks—including identity theft and business email compromise—months or years after the initial breach.
8 months ago
Kill Chain
Critical React Server Components Flaws in 2025 Enable DoS and Code Leaks
In December 2025, several critical vulnerabilities were discovered in React Server Components (RSC), affecting core packages such as react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. Identified as CVE-2025-55184, CVE-2025-67779, and CVE-2025-55183, these flaws were exploited by attackers to perform pre-authentication denial-of-service (DoS) attacks and, in some cases, access sensitive server-side source code. Exploitation was enabled through unsafe deserialization of HTTP payloads, leading to server hangs, or via crafted requests that exposed function source code. The vulnerabilities impacted RSC versions 19.0.0 through 19.2.2 and were identified following active investigation by security researchers in the wake of CVE-2025-55182 exploitation in the wild. This incident underscores the growing trend of adversaries targeting server-side JavaScript frameworks through exploitation chains and rapid patch circumvention. Organizations relying on React for server-side rendering must remain vigilant, as repeated disclosures highlight both the software supply chain's fragility and the need for rigorous update cycles to fend off evolving threats.
8 months ago
Kill Chain
2025 Advanced Phishing Kits Exploit AI and MFA Bypass to Steal Credentials at Scale
In August 2025, cybersecurity firms identified four sophisticated phishing kits—BlackForce, GhostFrame, InboxPrime AI, and Spiderman—leveraging advanced AI and multi-factor authentication (MFA) bypass tactics to automate credential theft at massive scale. These kits use capabilities like Man-in-the-Browser (MitB) attacks to capture one-time passwords, impersonate legitimate brands, evade detection, and target both enterprise and individual platforms. Attackers deploy these toolkits to orchestrate widespread phishing campaigns, resulting in unauthorized account access, data loss, and potential downstream breaches for affected organizations. This incident illustrates a significant escalation in the complexity of phishing operations, combining AI-powered evasion with real-time MFA bypass. The rise of such modular, scalable phishing kits demonstrates the evolving challenge for organizations to safeguard user credentials and the urgent need for adaptive defenses.
8 months ago
Kill Chain
CISA Adds Google Chromium CVE-2025-14174 to Exploited Vulnerabilities List
In December 2025, CISA added CVE-2025-14174—a Google Chromium out-of-bounds memory access vulnerability—to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation. This vulnerability enables threat actors to execute arbitrary code or potentially escalate privileges via unauthorized memory access within affected Chromium browser instances. Attackers exploited this flaw as an entry vector for malware and credential theft, increasing risks for both federal agencies and organizations relying on Chromium-based browsers. Federal Civilian Executive Branch agencies were directed, under BOD 22-01, to remediate this vulnerability by a strict deadline to mitigate ongoing risks. The rapid inclusion of CVE-2025-14174 in the KEV Catalog highlights persistent challenges posed by zero-day and n-day browser vulnerabilities. Recent increases in browser-based exploitation and strict regulatory mandates underscore the growing urgency to address software supply chain threats and prioritize swift vulnerability management across all industry sectors.
8 months ago
Kill Chain
FBI Delivers 630 Million Compromised Passwords to HIBP: 2024 Credential Exposure
In June 2024, the FBI provided Have I Been Pwned (HIBP) with approximately 630 million compromised passwords uncovered during multiple cybercrime investigations. The credentials were amassed from seized devices linked to a criminal suspect and sourced from the open web, Tor-based marketplaces, Telegram channels, and infostealer malware logs. Notably, about 46 million of these passwords were new to HIBP's repository, enabling organizations and individuals to proactively block use of these widely circulated credentials and bolster account security. The addition further expands the scale and utility of accessible credential hygiene tools worldwide. This incident underscores the ongoing and massive prevalence of credential compromise in the cybercrime landscape, as password data continually proliferates across threat actors and dark markets. It highlights the urgent need for organizations to adopt robust password exposure monitoring and zero trust authentication policies.
8 months ago
Kill Chain
Critical Gogs Zero-Day Exploited in Ongoing Supply-Chain Attacks
In early 2024, security researchers revealed that attackers had actively exploited a zero-day vulnerability in Gogs, a popular self-hosted Git service, for several months. The flaw, which allowed remote code execution (RCE), bypassed a previously disclosed patch, enabling unauthorized actors to compromise software supply chains by injecting code and potentially exfiltrating sensitive repositories. This sustained exploitation remained undetected until a disclosure by Wiz, highlighting that a patch was still unavailable at the time of reporting, therefore leaving many self-hosted Gogs deployments exposed and at risk. This incident underscores the increasingly sophisticated nature of supply-chain attacks and the challenges organizations face in managing security across open-source dependencies. With the rapid rise in software supply-chain exploits targeting CI/CD platforms, organizations are under mounting pressure to adopt stringent internal controls and layered defenses.
8 months ago
Kill Chain
2025 Surge in Supply Chain Attacks Hits GitHub Actions: What Every DevSecOps Leader Must Know
In 2025, a surge in supply chain attacks targeted GitHub Actions, leveraging insecure workflows and misconfigured secrets to inject malicious code into the software development pipeline. Attackers exploited open source dependencies and automation gaps, enabling lateral movement and data theft across multiple organizations using compromised CI/CD environments. The incident, revealed through coordinated research at Black Hat Europe, highlighted how adversaries can escalate privileges and bypass traditional defenses by targeting both public and private repositories, resulting in widespread risk for organizations with weak DevSecOps controls. This incident underscores a pronounced trend: attackers are increasingly focusing on automated development environments and supply chains, not just production workloads. With more organizations adopting GitHub Actions and similar platforms, visibility, zero trust segmentation, and secure automation practices are now critical to thwart sophisticated threat actors targeting the software supply chain.
8 months ago
Kill Chain
How Salt Typhoon Infiltrated US Telecoms: Lessons from the 2024 Nation-State Attack
In early 2024, multiple major US telecommunications providers were targeted in a sophisticated nation-state attack attributed to Salt Typhoon, a Chinese-affiliated APT group. The attackers exploited unencrypted and east-west traffic flows within provider networks, bypassing conventional perimeter defenses to gain persistent access to sensitive infrastructure and intercept data in transit. Salt Typhoon leveraged advanced lateral movement and covert exfiltration techniques, enabling them to collect confidential communications and network architecture details. The incident led to significant operational risks, regulatory scrutiny, and concern within the telecom and national security sectors. This breach highlights a surge in highly targeted attacks on critical infrastructure, as nation-state actors exploit unencrypted traffic and insufficient internal segmentation. Current attacks reflect a broader strategic trend, with organizations facing pressure to modernize controls to address evolving threat vectors and international cyber-risk dynamics.
8 months ago
Kill Chain
Malware’s New Trick: Abusing the DLL EntryPoint in Windows (2024)
In December 2024, security researchers identified a Windows malware technique that leverages the DLL entry point (DllMain) to execute malicious code automatically upon DLL loading, even if no exported function is invoked. By embedding harmful operations—such as launching other processes—directly within DllMain, threat actors can evade typical detection methods that focus primarily on analyzing exported functions. This technique often harnesses trusted Windows utilities, like rundll32.exe or regsvr32.exe, as the initial execution vectors, making attacks stealthy and difficult to detect. The result is an elevated risk for lateral movement within environments and increased potential for undetected code execution. This method highlights a broader trend in which attackers abuse overlooked aspects of Windows internals to persist and evade controls. As adversaries continue to evolve, the need for better anomaly detection, code inspection, and zero trust segmentation becomes ever more critical for organizations defending against sophisticated malware delivery approaches.
8 months ago
Kill Chain
LockBit Ransomware: Why Reputation Now Drives RaaS Attacks and Ransom Payments (2025 Analysis)
In early 2025, research into the LockBit ransomware-as-a-service (RaaS) gang revealed the pivotal role of reputation in both attacker and victim circles. At its peak, LockBit utilized a vast network of nearly 200 affiliates to gain initial access, exfiltrate sensitive data, and negotiate ransoms, with over half achieving payout settlements after system encryption and data theft. The incident highlights the attackers’ emphasis on trust during ransom negotiations and the widespread operational and financial disruptions suffered by targeted organizations, including critical recovery costs, business downtime, and severe reputational impact stemming from media coverage. The increasing maturity and professionalization of RaaS operations, typified by LockBit, have made sophisticated extortion tactics more common. As law enforcement and insurers adapt, companies face heightened risk not just from technical compromise, but from strategic reconnaissance that monetizes cyber insurance intelligence, further escalating the urgency for advanced protection and segmentation of sensitive data.
8 months ago
Kill Chain
AI-Powered Attacks Break Smart Contracts: A 2025 Blockchain Breach Analysis
In late 2025, advanced AI models including Anthropic's Claude Opus 4.5, Claude Sonnet 4.5, and OpenAI's GPT-5 autonomously exploited vulnerabilities across a new smart contract benchmark (SCONE-bench) comprising 405 blockchain contracts. These AIs collectively discovered and weaponized vulnerabilities leading to $4.6 million in simulated or actual economic loss, proving AI-driven cyber capabilities have reached critical new thresholds. Further, simulations against nearly 2,850 newly deployed smart contracts with no previously known vulnerabilities resulted in successful zero-day discoveries and profitable exploits, despite only modest operational costs for the threat actors. This fundamentally changed the risk calculus for decentralized finance and blockchain-based businesses. These findings underscore a turning point, where the integration of conversational and agentic AI with offensive security tools directly translates to scalable, profitable cyberattacks. The incident highlights an urgent risk landscape: AI-driven exploitation is no longer theoretical, driving increased pressure for automated AI defensive strategies and regulatory focus in sectors reliant on smart contracts.
8 months ago
Kill Chain
Eighth Chrome Zero-Day of 2025: Google Issues Emergency Patch Amid Active Exploitation
In early 2025, Google addressed its eighth actively exploited zero-day vulnerability in Chrome within the year, releasing an emergency update after threat actors leveraged the flaw to bypass browser security and execute malicious code. Attackers exploited a use-after-free bug to achieve remote code execution, targeting Chrome users worldwide. Quick detection and response by Google limited the potential damage, but the repeated appearance of critical zero-days raised new concerns among IT teams and users regarding browser safety and patch timeliness. The frequency and sophistication of recent browser-based zero-days reflect an upward trend in targeted attacks against mainstream software. As Chrome remains the dominant browser for consumers and enterprises alike, effective patch management and browser security have become business-critical to defend against rapid exploit deployment and reduce organizational risk.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports