The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
China-Linked Supply Chain Breach Exploits React2Shell Flaw in 2025
In mid-2025, multiple China-linked threat actors launched widespread exploitation of the React2Shell vulnerability (CVE-2025-55182), a critical supply-chain flaw impacting React and Next.js applications. Within hours of the flaw’s public disclosure, attackers initiated automated scanning and weaponization campaigns, targeting internet-exposed services to quickly gain unauthorized, remote code execution. Successful intrusions enabled attackers to harvest sensitive data, escalate privileges, and pivot laterally within affected cloud environments. The rapid adoption of malicious payloads and swift exploitation before most organizations could patch led to substantial business risk, data loss, and potential compliance violations across sectors. This incident underscores an escalated threat landscape where nation-state actors rapidly exploit newly-disclosed supply-chain vulnerabilities. The speed and scope of these attacks reflect a significant uptick in zero-day exploitation campaigns and highlight the urgent need for organizations to strengthen patching velocity, endpoint monitoring, and east-west segmentation controls.
8 months ago
Kill Chain
Cloudflare’s 2024 Outage: Lessons from the React2Shell RCE Emergency
In June 2024, Cloudflare experienced a significant outage after emergency patching efforts to address an actively exploited remote code execution (RCE) vulnerability in the React framework, dubbed "React2Shell." The incident unfolded as threat actors began leveraging the vulnerability to attempt unauthorized code execution on internet-facing workloads, prompting Cloudflare to rush critical security mitigations. While the attack itself targeted exploitation routes via React, it was the swift application of mitigations—rather than a direct breach—which triggered widespread downtime, temporarily impacting Cloudflare's global network operations and customer accessibility. This incident underscores the increasing speed and aggression of active exploitation cycles, particularly for zero-day vulnerabilities in widely used frameworks. As attacker sophistication grows and organizations race to patch critical flaws, operational disruptions and collateral damage are becoming more frequent in the ongoing effort to balance security with business continuity.
8 months ago
Kill Chain
Clop Ransomware Hits Barts Health NHS via Oracle Zero-Day
In early 2024, Barts Health NHS Trust disclosed a data breach after Clop ransomware actors exploited a zero-day vulnerability in Oracle E-Business Suite. The attackers gained unauthorized access to internal systems, exfiltrated sensitive files from a key database, and threatened further leaks. The attack leveraged unpatched software flaws as the entry vector, allowing for rapid lateral movement and data theft before being detected. The incident disrupted operations and triggered regulatory notifications due to the sensitive nature of patient and operational information. This breach highlights the ongoing risks posed by sophisticated ransomware groups exploiting zero-day vulnerabilities in widely used enterprise software. Attacks of this kind are increasingly common, especially in the healthcare sector, which remains a high-value target for ransomware due to legacy systems and critical service mandates.
8 months ago
Kill Chain
CISA Discloses PRC Hackers Using BRICKSTORM Backdoor for Stealthy U.S. System Access
In June 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) reported that state-sponsored hackers affiliated with the People's Republic of China (PRC) utilized a newly identified backdoor dubbed BRICKSTORM to infiltrate and maintain long-term access within VMware vSphere and Windows environments of U.S. critical infrastructure entities. The campaign started months prior, leveraging advanced persistent threat (APT) tactics such as lateral movement, encrypted C2 channels, and sophisticated evasion techniques to bypass network defenses and persist undetected. This led to extensive exfiltration of sensitive data and raised major concerns about the resilience of core U.S. operational systems. The BRICKSTORM attack signals a rising tide of highly targeted intrusions on virtualization platforms, as nation-state actors adopt increasingly stealthy and persistent approaches. Organizations must now contend with the growing complexity and scale of APT operations, which often elude legacy tools and monitoring strategies.
8 months ago
Kill Chain
Active Command Injection Attacks Hit Array AG Series Gateways in 2025
In mid-2025, JPCERT/CC reported that a command injection vulnerability in Array Networks AG Series secure access gateways had been actively exploited in the wild since at least August of that year. The flaw, residing in the DesktopDirect remote desktop access feature, allowed unauthenticated attackers to execute arbitrary commands on targeted devices. The vulnerability, lacking a CVE at the time of disclosure, was patched by Array Networks in May 2025, but unpatched systems remained exposed to attacks that could lead to further compromise and unauthorized network access. This incident underscores the persistent risks of unpatched infrastructure and weak segmentation in network environments. The rise of zero-day exploits targeting remote access solutions combined with increased regulatory scrutiny makes rapid detection, patching, and least privilege policy enforcement more critical than ever.
8 months ago
Kill Chain
Supply-Chain Emergency: Critical XXE Bug (CVE-2025-66516) in Apache Tika Imperils Enterprises
In December 2025, a critical XML External Entity (XXE) vulnerability, CVE-2025-66516, with a maximum CVSS score of 10.0, was discovered in multiple core Apache Tika modules. This flaw enables unauthenticated attackers to exploit XXE processing to remotely access sensitive files, exfiltrate data, and launch further attacks through maliciously crafted XML payloads. Because Apache Tika is widely employed in data extraction and content analysis across enterprise, cloud, and supply-chain systems, the exposure has immediate downstream risk for any organizations leveraging impacted Tika libraries. The incident highlights a significant supply-chain security challenge, reinforcing the urgency for immediate patching and improved review of third-party open-source components. Increasingly, threat actors are exploiting foundational software dependencies to bypass traditional security perimeters, making software supply-chain vigilance a key priority for 2025 and beyond.
8 months ago
Kill Chain
Chinese Hackers Exploit React2Shell RCE—Critical React Server Vulnerability in 2025
In December 2025, two Chinese nation-state threat groups rapidly began exploiting CVE-2025-55182—dubbed 'React2Shell'—a critical unauthenticated remote code execution vulnerability affecting React Server Components (RSC). Within hours of public disclosure, attackers scanned for and targeted vulnerable servers globally, leveraging the flaw to gain full control over application environments, execute arbitrary commands, and establish persistent footholds for lateral movement. The wide adoption of React in enterprise and SaaS environments increased the exposure and impact of these attacks, putting sensitive business-critical data at risk and causing major security teams to issue rapid patch advisories. This incident underscores the growing speed with which advanced threat actors weaponize zero-day vulnerabilities in widely used software frameworks. It highlights the urgent need for rapid vulnerability management, enhanced east-west segmentation, and robust threat detection, as attackers increasingly exploit supply chain and development stack exposures in cloud and hybrid environments.
8 months ago
Kill Chain
Zero-Click Agentic Browser Attack Wipes Google Drive (Perplexity Comet, 2025)
In December 2025, researchers from Straiker STAR Labs disclosed a zero-click browser-based attack targeting users of Perplexity's Comet browser, enabling malicious actors to erase the contents of a victim’s entire Google Drive. The attack leverages agentic browser automation capable of connecting Gmail and Google Drive accounts by abusing trusted email-based automations. Once triggered by a specially crafted email, the exploit requires no user interaction to execute the destructive action. The compromise of cloud-stored data had significant operational impact, resulting in permanent data loss for affected users and highlighting new risks for organizations relying heavily on SaaS storage platforms. This attack is significant as it demonstrates the expanding threat of zero-click vulnerabilities powered by advanced browser automation, agentic AI, and email exploits. As more organizations migrate operations and collaborative data to the cloud, the frequency and sophistication of such attacks are expected to increase, escalating the urgency for robust cloud security controls.
8 months ago
Kill Chain
BRG Ransomware Breach: How a 2025 Attack Unveiled Legal Sector’s Vendor Risk
In March 2025, Berkeley Research Group (BRG), a prominent consulting and legal advisory firm, suffered a devastating ransomware attack attributed to the RansomHub cybercriminal group. Attackers leveraged persistent dwell time to infiltrate BRG’s network, exfiltrated sensitive data including M&A intelligence and confidential client materials, and encrypted key systems. The breach occurred during BRG's $700 million buyout by TowerBrook Capital Partners, amplifying the incident’s impact and resulting in exposure of information related to hundreds of active deals and thousands of individuals. The attackers’ extortion included threats of blackmail and public data leaks, leveraging their knowledge of both firm structure and sensitive client engagements. This attack spotlights a surge in professional services sector targeting—especially legal and advisory firms—by highly organized ransomware groups in 2024–2025. Threat actors like RansomHub have adopted prolonged infiltration tactics, optimized affiliate compensation, and leveraged industrialized extortion, mirroring broader ransomware trends and underscoring urgent vendor risk management needs.
8 months ago
Kill Chain
Holiday Season Phishing Surge: Fake Rewards, Tax Refunds, and Retail Scams Hit US Consumers
In late 2025, a surge of SMS phishing campaigns originating from China-based threat actors targeted US consumers, leveraging fake rewards, tax refund lures, and convincing e-commerce storefronts. Attackers registered thousands of new phishing domains, deploying convincing T-Mobile and AT&T spoof sites promoted via iMessage and RCS. Victims, enticed to enter payment card data and one-time codes, unknowingly enabled attackers to enroll their cards into Apple or Google mobile wallets under fraudster control, facilitating rapid monetization of stolen credentials. These operations exploited seasonal shopping urgency and sophisticated phishing kits to evade detection, causing widespread financial fraud, identity theft, and downstream losses for individuals and financial institutions. The incident highlights a global shift in phishing techniques, with threat actors now employing advanced, rapidly deployable kits and mobile wallet fraud vectors. The proliferation of fake e-commerce and tax-refund scams demonstrates increased operational agility and a focus on bypassing traditional browser-based defenses, raising urgent concerns for both consumer security and enterprise payment protection.
8 months ago
Kill Chain
M&S & Co-op Group 2025: Identity-Based Vishing Unleashes Ransomware Chaos
In early 2025, Marks & Spencer (M&S) and Co-op Group, two major UK retailers, suffered significant ransomware attacks following sophisticated vishing campaigns. Attackers impersonated IT support and targeted outsourced helpdesk staff to capture corporate credentials, enabling unauthorized access to internal networks. Once inside, threat actors leveraged overprivileged accounts and weak segmentation to laterally move and exfiltrate sensitive data, ultimately deploying ransomware that disrupted operations. The incidents resulted in direct losses exceeding £500 million (USD 667 million), with long-term impacts including reputational harm and regulatory scrutiny. This breach underscores the ongoing threat of identity-based attacks, particularly those exploiting social engineering and credential harvesting to bypass perimeter defenses. With the rise of distributed workforces, cloud adoption, and third-party supply chains, organizations of all sizes remain vulnerable to similar tactics, making identity security and robust privilege management more urgent than ever.
8 months ago
Kill Chain
AutoIT3 Compiled Script Malware: 2024 Infostealer Surge Targets Windows Users
In December 2024, researchers identified a fresh malware campaign abusing compiled AutoIT3 scripts to deliver infostealers and remote access trojans to Windows systems. Attackers distributed malicious executables packaged in ZIP archives, which, upon execution, leveraged AutoIT3’s FileInstall() function to embed and unpack additional payloads, including obfuscated shellcode. Once unpacked, these scripts decoded and executed shellcode in memory, deploying threats such as Quasar RAT and Phantom Stealer, thereby enabling credential theft and system compromise for victim organizations. This campaign highlights a growing trend where attackers utilize low-profile development tools, like AutoIT, to evade traditional defenses and deliver sophisticated payloads. The resurgence of compiled script-based malware demonstrates ongoing innovation in attack vectors, requiring defenders to expand their monitoring to scripting environments and unpacked resource analysis.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports