The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Ransomware Reimagined: Attackers Deploy Their Own QEMU VM for Stealth and Persistence
In early 2025, a sophisticated ransomware incident was revealed by Red Canary Intelligence when an adversary launched a coordinated attack combining email bombing, social engineering, and abuse of legitimate remote access tools. Initially, victims endured email inundation designed to cause confusion and open the door to a convincing technical support ruse. Leveraging remote assistance software, attackers deployed a custom QEMU virtual machine (VM) into the compromised environment—a novel method for persistent access. Within this VM, tools such as Sliver C2, QDoor backdoor, and ScreenConnect enabled internal reconnaissance, lateral movement, and external command and control, all while evading conventional endpoint security controls. This incident is noteworthy for both its multi-layered attack chain and the adversary’s use of their own pre-configured VM for persistence, representing a shift toward virtualization-based evasion and resilience. The detection highlights a rise in blended attacks using social engineering, legitimate tools, and bespoke infrastructure, stressing the importance of defense-in-depth and advanced anomaly detection capabilities.
8 months ago
Kill Chain
SAP’s December 2023 Patch: Three Critical Vulnerabilities Explained
In December 2023, SAP released security updates that addressed 14 vulnerabilities across several of its products, three of which were rated as critical. The most severe flaws affected fundamental SAP systems such as ABAP and NetWeaver, with CVSS scores as high as 9.9, potentially allowing attackers to execute unauthorized actions, access sensitive data, or disrupt business operations. The vulnerabilities could be exploited remotely, and patching delays threatened core business processes of organizations running SAP in enterprise and cloud environments. No active exploitation was publicly reported at disclosure, but SAP strongly urged immediate patching to mitigate risk. This incident highlights the persistent risks associated with complex enterprise application platforms widely used across industries. With attackers increasingly targeting software supply chains and critical business infrastructure, timely patch management and continuous vulnerability monitoring in environments like SAP remain essential to maintaining regulatory compliance and business continuity.
8 months ago
Kill Chain
CISA Flags New High-Risk Vulnerabilities in 2025 KEV Catalog
In December 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added two actively exploited vulnerabilities—CVE-2025-6218 (RARLAB WinRAR Path Traversal) and CVE-2025-62221 (Microsoft Windows Use After Free)—to its Known Exploited Vulnerabilities (KEV) Catalog. These critical flaws are utilized by cyber attackers to gain unauthorized access, facilitate lateral movement, and potentially execute arbitrary code within federal and enterprise environments. CISA’s directive mandates that all Federal Civilian Executive Branch (FCEB) agencies remediate these vulnerabilities by specified dates to mitigate significant risk, reinforcing the growing threat from rapid exploitation of newly discovered CVEs. This incident illustrates the ongoing challenges faced by organizations, as adversaries increasingly exploit widely used software at scale. The timely identification and remediation of KEV Catalog vulnerabilities are vital for maintaining strong security postures amid an uptick in exploitation and regulatory pressure to close known gaps.
8 months ago
Kill Chain
US Treasury Highlights $4.5B in Ransomware Payments: 2024 Threat Landscape
In February 2024, the US Treasury’s Financial Crimes Enforcement Network (FinCEN) reported that ransomware attacks have resulted in over $4.5 billion in ransom payments since 2013, underscoring a dramatic surge in both scale and sophistication. Attackers typically infiltrated organizations through phishing campaigns, exploitation of unpatched vulnerabilities, and compromised remote desktop protocols, deploying ransomware variants to encrypt data and demand payment. These incidents disrupted critical business operations across sectors, forced enterprises to halt services, and left many struggling with reputational and financial damage. This report is especially relevant as ransomware strains evolve, facilitating large-scale attacks on enterprises, healthcare, and infrastructure. Heightened regulatory scrutiny, such as OFAC and FinCEN advisories, means organizations face intensified pressure to monitor, report, and prevent ransomware-related activities.
8 months ago
Kill Chain
React2Shell: Exploitation Surge Hits Businesses in 2025
In June 2025, attackers began widespread exploitation of CVE-2025-55182, a critical vulnerability known as React2Shell, shortly after it was publicly disclosed. Threat actors rapidly leveraged the unauthenticated remote code execution flaw to gain access to vulnerable web servers running the React2Shell component, allowing lateral movement, data exfiltration, and in some cases, ransomware deployment. The initial wave targeted a range of businesses, exploiting the window between disclosure and patch adoption, thus exposing organizations to operational disruption and compliance risks. The surge in React2Shell exploitation underscores an ongoing trend: cybercriminals are taking advantage of zero-day and recently publicized vulnerabilities with renewed speed and sophistication. Security teams must deal with shrinking patch windows, automated exploit tools, and increasing pressure from regulators to secure internet-facing applications.
8 months ago
Kill Chain
Apache Tika’s Critical Patch Flaw: 2024 Supply-Chain Wake-Up Call
In June 2024, The Apache Software Foundation disclosed that its initial patch for a critical vulnerability (CVE-2024-29945) in Apache Tika was incomplete, leaving systems exposed to remote code execution risks. Tika, widely used for content detection and extraction, is embedded in many enterprise and cloud-native applications, amplifying the scale of exposure through the software supply chain. Attackers who exploit this flaw can execute arbitrary code on affected servers, potentially enabling data breaches or lateral movement across environments. The revised advisory and updated CVE has prompted urgent action to remediate the unresolved security gap. This incident highlights persistent challenges around open-source supply chain risks, insufficient patch validation, and the rapid exploitation of incomplete fixes. Organizations must evaluate their dependency chains, continuously monitor vendor advisories, and implement layered security controls as supply-chain vulnerabilities become increasingly frequent and business-critical.
8 months ago
Kill Chain
Gemini Enterprise No-Click Vulnerability: A Wake-Up Call for AI/ML Security
In early 2024, Google addressed a severe vulnerability in its Gemini Enterprise AI platform that allowed attackers to craft common business documents containing malicious prompt injections. These attacks did not require any user interaction; simply opening or syncing affected documents enabled adversaries to exfiltrate sensitive organizational data, bypassing usual security controls. The flaw exploited Gemini’s integration with widely used Google Workspace applications. Attackers leveraged this vulnerability to gain unintended access to confidential files, customer data, and internal communications, posing material risks to business operations and reputation. This vulnerability exemplifies emerging no-click threats in AI-integrated enterprise ecosystems, where conventional perimeter defenses and user-awareness controls are ineffective. The incident underscores the urgency for organizations to review AI/ML security posture as attackers rapidly adapt to take advantage of new AI-powered workflows.
8 months ago
Kill Chain
UK Cyber Agency Issues Stark Warning: Prompt Injection in LLMs is Here to Stay
In June 2024, the UK’s National Cyber Security Centre (NCSC) publicly warned that large language models (LLMs), including popular AI tools such as ChatGPT and Claude, possess a fundamental and persistent vulnerability known as prompt injection. This flaw arises because LLMs are architecturally incapable of reliably distinguishing between trusted and untrusted input within prompts. Despite repeated industry efforts to implement guardrails, researchers routinely bypass these safeguards, allowing malicious actors to manipulate LLM behavior, potentially leading to harmful outputs or the execution of unauthorized actions in real-world applications that integrate LLMs. This alert is especially significant as LLM-driven automations are rapidly proliferating in software development, browser agents, and enterprise workflows. The NCSC’s assessment signals an urgent need for organizations to shift their risk models, as AI prompt injection represents a persistent, unfixable attack vector with serious implications for data security, business integrity, and regulatory compliance.
8 months ago
Kill Chain
Nation-State Cyber Espionage: Iran’s Shahid Shushtari Unit and the $10M Bounty
In late 2024, security authorities announced a $10 million reward for information regarding the whereabouts of Mohammad Bagher Shirinkar and Fatemeh Sedighian Kashi, key leaders of Shahid Shushtari — a cyber unit operating under Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command. Known by threat intelligence analysts as UNC5866, Cotton Sandstorm, and Haywire Kitten, the group targets critical infrastructure sectors, including news, shipping, travel, energy, financial services, and telecom across the U.S., Europe, and the Middle East. Their operations span spear-phishing, malware campaign delivery, and cyberespionage, with significant disruptions and financial damages reported. Notably, the group attempted to influence the 2020 U.S. presidential election and continues its multi-pronged attacks using evolving techniques and new tradecraft. This incident underscores the persistent and evolving threat posed by nation-state actors targeting both public and private institutions globally. Increased vigilance, timely intelligence sharing, and robust controls around east-west network traffic and encrypted communications are now critical countermeasures as similar attacks escalate.
8 months ago
Kill Chain
Malicious VSCode Extensions Breach Puts Developer Supply Chains at Risk
In December 2025, two malicious Visual Studio Code extensions—Bitcoin Black and Codo AI—were uncovered on Microsoft’s official VSCode Marketplace, executing a supply chain attack that targeted developers. Published by an entity named 'BigBlack', these extensions installed information-stealing malware by abusing extension privileges. The malware leveraged DLL hijacking and covert batch scripts to steal credentials, browser session cookies, cryptocurrency wallet data, and system information from infected developer machines, storing exfiltrated data for later retrieval. The incident highlights how even widely trusted software platforms can host weaponized add-ons capable of compromising sensitive environments. This breach exemplifies the growing risks posed by open-source and third-party software supply chain compromises, especially targeting developer tools. The ease with which unvetted code can be distributed through official registries underscores the need for rigorous extension security and policy enforcement in enterprise environments.
8 months ago
Kill Chain
Ransomware: FinCEN Reports Over $2.1B Paid to Gangs (2022–2024)
Between 2022 and early 2024, ransomware gangs operating globally extorted over $2.1 billion from victims, according to an official report by the Financial Crimes Enforcement Network (FinCEN). Activity surged markedly in 2023, driven by large-scale campaigns from prolific threat groups such as ALPHV/BlackCat and LockBit. Attackers commonly gained initial access through phishing, vulnerable VPNs, or exposed remote services, rapidly leveraging lateral movement and data exfiltration before deploying file-encrypting malware to maximize leverage. As a result, numerous organizations across multiple sectors experienced severe operational disruption, financial losses, reputational damage, and in some cases, regulatory scrutiny. This incident underscores the growing reach and impact of organized ransomware, even as some law enforcement takedowns in late 2023 and 2024 caused temporary disruption to top gangs. The pattern highlights evolving attacker strategies, heightened regulatory attention, and the need for proactive cyber defense and comprehensive incident response preparedness.
8 months ago
Kill Chain
2025 Cyberattack Wave: USB Malware, React2Shell & AI Tool Exploits Expose Security Gaps
In December 2025, organizations worldwide faced a surge of multi-vector cyberattacks exploiting recent vulnerabilities in USB devices, popular developer frameworks like React (notably the React2Shell bug), and emerging AI-powered coding environments. Attackers leveraged unpatched software, social engineering, and compromised USB devices to distribute malware and establish lateral movement within networks. The campaign capitalized on the rapid deployment of new technologies and lagging security controls, resulting in data breaches, financial theft via sophisticated WhatsApp worms, and the infiltration of development pipelines. This spate of incidents underscores the escalating convergence of traditional malware vectors and AI-driven exploits, exposing significant gaps in current security postures. As organizations accelerate digital transformation and adopt generative AI tools, adversaries are rapidly evolving, testing defenses across cloud, hybrid, and on-premises ecosystems.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports