The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
React2Shell: China-Nexus Groups Target Supply Chains with Critical React Vulnerability
In early 2024, a critical zero-day vulnerability in the widely used React JavaScript library—dubbed React2Shell—was actively exploited in the wild by sophisticated China-nexus threat actors. Attackers leveraged compromised software supply chains to infiltrate organizations during regular package updates, gaining access via vulnerable dependency injection into production environments. Once inside, adversaries orchestrated lateral movement to exfiltrate sensitive data and disrupt business operations across sectors, leveraging encrypted communication channels and advanced stealth techniques. The incident has underscored the significant risk posed by supply-chain weaknesses in core developer tools and frameworks, amplifying concerns among enterprises and regulators alike. This breach reflects a surge in supply-chain attacks targeting popular open-source components, exposing systemic vulnerabilities beyond traditional perimeter defenses. The rapid weaponization of techniques by nation-state actors highlights the urgent need for zero trust segmentation, proactive patching, and real-time threat visibility within software development ecosystems.
8 months ago
Kill Chain
Critical RCE in React Server Components Exposes Applications Worldwide (CVE-2025-55182)
In December 2025, a critical remote code execution (RCE) vulnerability—CVE-2025-55182—was discovered in the Flight protocol used by React Server Components. Rated CVSS 10.0, this flaw enabled unauthenticated attackers to craft malicious requests, resulting in the compromise of application servers running affected versions. Security researchers observed exploitation in the wild, with threat actors leveraging the flaw for lateral movement and potential data exfiltration. Organizations using Next.js and other frameworks integrating the vulnerable protocol faced heightened risk until urgent patches were issued. Immediate remediation efforts, threat monitoring, and network segmentation were necessary to mitigate the rapid spread. This incident underscores the increasing threat posed by supply chain vulnerabilities in widely adopted developer ecosystems. The exploitation of core component flaws in popular open-source projects amplifies business risk, as attackers accelerate adoption of frontline vulnerabilities for larger-scale impact.
8 months ago
Kill Chain
Meta React Server Components 2025: Critical RCE Vulnerability Added to CISA KEV
In December 2025, a critical remote code execution (RCE) vulnerability (CVE-2025-55182) was discovered and actively exploited in Meta's React Server Components framework. Threat actors leveraged this flaw in internet-exposed REACT instances, enabling them to execute arbitrary code remotely and potentially gain unauthorized access to internal systems. This vulnerability was significant enough to be added to CISA's Known Exploited Vulnerabilities (KEV) Catalog, prompting urgent remediation efforts across public and private organizations. Federal agencies were mandated to act by Binding Operational Directive 22-01, while industry peers were strongly advised to prioritize patching to limit exposure and prevent compromise. The exploit highlights an ongoing trend of attackers targeting widely adopted development frameworks like React, demonstrating how software supply chain and third-party vulnerabilities remain a high-risk vector. Its addition to the KEV Catalog underlines the persistent challenge organizations face in quickly identifying and mitigating critical threats across their infrastructure.
8 months ago
Kill Chain
Predator Spyware 2024: Zero-Click Ad Delivery Redefines Stealth Attacks
Between late 2023 and early 2024, the Predator spyware—developed by surveillance tech company Intellexa—was deployed via a novel zero-click attack vector known as "Aladdin." This technique exploited malicious ads to automatically compromise targeted devices as soon as they displayed the booby-trapped advertisement, without requiring any user interaction. Elite threat actors leveraged this method to implant sophisticated spyware capable of exfiltrating sensitive data and monitoring victim activity. The campaign’s covert nature enabled infections to go undetected, raising the risk for organizations and individuals exposed to this advanced surveillance toolset. This incident highlights the rapid evolution of zero-click infection strategies, especially those exploiting web advertising ecosystems. Security teams must double down on threat detection, anomaly response, and zero trust frameworks to counter increasingly stealthy surveillance tools used by both commercial operators and nation-state clients.
8 months ago
Kill Chain
Critical React2Shell Flaw in React & Next.js Puts Web Servers at Risk
In June 2024, a critical vulnerability known as 'React2Shell' was discovered in the React Server Components (RSC) 'Flight' protocol, impacting React and Next.js applications worldwide. This flaw enables unauthenticated remote code execution (RCE), allowing attackers to execute arbitrary JavaScript code on affected web servers. Security researchers observed that threat actors could exploit the protocol by sending crafted requests, potentially leading to a full compromise of application environments and exposure of sensitive data or further lateral movement within networks. This incident underscores heightened risk in modern web application supply chains and the urgent need for timely patching within frameworks. Growing attacks on open-source packages and widespread usage of React/Next.js frameworks amplify the incident's relevance, especially as application-layer vulnerabilities facilitate high-impact breaches at scale.
8 months ago
Kill Chain
ArrayOS AG VPN Vulnerability Exploited: Threat Actors Plant Webshells via Command Injection (2024)
In early June 2024, threat actors began actively exploiting a command injection vulnerability in Array Networks AG Series VPN devices, targeting organizations and critical infrastructure globally. Attackers leveraged the flaw to plant malicious webshells and create rogue administrative users, gaining persistent access to internal networks. The observed attacks allowed adversaries to bypass normal authentication and move laterally, posing significant operational risks by exposing sensitive internal systems and enabling further exploitation. The breach heightened concerns about the security of perimeter VPN appliances and the need for urgent patching. This incident is especially significant as attackers rapidly weaponize new vulnerabilities in edge infrastructure, reflecting a persistent trend of chaining VPN flaws to compromise enterprise environments. Heightened regulatory scrutiny and rising sophistication in attacks on remote access solutions underscore the urgent need for enhanced security controls and vigilant vulnerability management.
8 months ago
Kill Chain
CISA Warns of Chinese 'BrickStorm' Malware on VMware Servers: What Enterprises Must Know
In mid-2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that Chinese state-sponsored hackers deployed the 'BrickStorm' malware to backdoor vulnerable VMware vSphere servers across multiple U.S. critical infrastructure sectors. Attackers exploited unpatched or insecurely configured vSphere environments to gain initial access, install persistent web shells, and enable lateral movement within networks. The campaign featured advanced evasion tactics, strong operational security, and targeted high-value assets, risking confidential data exposure, business disruption, and regulatory non-compliance for affected organizations. This attack exemplifies a rising trend of sophisticated supply-chain and infrastructure attacks leveraging known vulnerabilities in virtualized server environments. With ongoing exploitation by nation-state actors and renewed regulatory focus on asset protection, organizations must reevaluate their segmentation, patching, and east-west visibility controls to mitigate similar threats.
8 months ago
Kill Chain
2025’s Multi-Vector Supply Chain Attacks: How AI and Automation Redefined Web Security
In 2025, a coordinated wave of sophisticated attacks exploited web supply chain vulnerabilities, impacting over 180,000 websites globally. Threat actors leveraged multi-vector tactics, combining AI-driven injection methods, automated credential stuffing, and lateral movement across cloud and hybrid environments. The adversaries compromised legitimate third-party libraries and embedded malicious code into trusted web assets, bypassing traditional security controls and causing data breaches, unauthorized financial transfers, and reputation damage for thousands of organizations. Rapid east-west propagation enabled attackers to escalate privileges and exfiltrate sensitive customer data before detection. This incident signals a shift in the threat landscape, with attackers increasingly using AI and automation to exploit supply chain trust, targeting hybrid and multi-cloud infrastructures. Organizations face unprecedented pressure to modernize web security, prioritizing zero trust, real-time threat monitoring, and proactive segmentation to defend against rapidly evolving, multi-pronged attack campaigns.
8 months ago
Kill Chain
Cloudflare Defeats Record 29.7 Tbps DDoS Attack Attributable to AISURU Botnet
In December 2025, Cloudflare successfully detected and mitigated the largest recorded distributed denial-of-service (DDoS) attack, peaking at 29.7 terabits per second. The attack was orchestrated by the AISURU botnet, leveraging up to four million infected hosts to launch a hyper-volumetric assault. The malicious traffic targeted Cloudflare’s infrastructure, testing the limits of web security and putting critical online services at risk of disruption during the 69-second onslaught. This incident illustrates the increasing scale and sophistication of botnet-driven DDoS attacks, forcing organizations to reassess their mitigation strategies. The AISURU attack underscores a troubling trend in the growth of for-hire botnets and record-breaking DDoS volumes seen in 2025. These evolving threats continue to challenge traditional perimeter defenses, making advanced detection, automated response, and robust network segmentation more critical than ever.
8 months ago
Kill Chain
GoldFactory Trojan Infects 11,000+ Mobile Users in Southeast Asia through Fake Banking Apps
Between October and December 2024, a financially motivated threat group known as GoldFactory orchestrated an extensive campaign targeting mobile users across Indonesia, Thailand, and Vietnam. By impersonating trusted government services, the attackers distributed modified Android banking apps laced with malware, resulting in over 11,000 infections. Once installed, these malicious applications harvested sensitive financial data and enabled unauthorized transactions, posing significant financial risks to individual users and undermining trust in mobile banking channels. The campaign used phishing techniques and social engineering, making detection challenging for average users. This incident illustrates the growing trend of cybercriminals leveraging mobile channels and government impersonation to amplify reach and lower the barrier for monetization in emerging markets. It also highlights the urgent need for stronger mobile security controls, user education, and regulatory vigilance to mitigate evolving threats targeting digital financial services.
8 months ago
Kill Chain
How the yETH DeFi Platform Lost $9 Million in a Flash Loan Exploit (2025)
In December 2025, an unknown threat actor successfully exploited a critical vulnerability in the yETH DeFi platform's smart contract infrastructure, using advanced flash loan manipulation tactics to drain approximately $9 million in funds. The attack was executed within minutes, bypassing protocol controls and effectively emptying several liquidity pools. Investigators reveal that the breach exploited flawed logic in the contract that allowed multiple reentrancies and circumvented rate checks, leading to rapid unauthorized fund transfers. Remediation steps included pausing affected smart contracts and collaborating with exchanges to freeze stolen assets. This incident highlights the rapidly evolving threat landscape targeting decentralized finance (DeFi) ecosystems, where complex protocols and smart contract bugs can be weaponized for mass financial theft. Continued increases in such exploits have intensified regulatory and investor scrutiny while prompting the DeFi sector to emphasize real-time security visibility, automated incident response, and proactive contract auditing.
8 months ago
Kill Chain
Silver Fox Mimics Russian Tactics: Fake Teams Installer Pushes ValleyRAT in 2025 China Cyber Attack
In December 2025, the threat actor known as Silver Fox executed a targeted cyber campaign in China, distributing the ValleyRAT remote access trojan through a fake Microsoft Teams installer. By leveraging SEO-poisoned websites, attackers lured victims searching for legitimate collaboration apps into downloading malicious files disguised as authentic installers. Once executed, the malware provided the attackers with covert access and enabled data theft, surveillance, and potential lateral movement within targeted organizations. The campaign mimicked Russian threat actor behaviors as a false flag, complicating attribution and response. This incident highlights the increasing sophistication and frequency of social engineering attacks using trusted business tools as lures. The rise of targeted SEO poisoning, deceptive software installers, and identity obfuscation poses heightened risks for organizations handling sensitive data or operating in sensitive regions.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports