Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Fortinet FortiWeb WAF Zero-Day Breach: 2024 Vulnerability Exposes Perimeter Defenses
In early June 2024, Fortinet disclosed a critical remote code execution (RCE) vulnerability in its FortiWeb Web Application Firewall (WAF). Identified as CVE-2024-21762, this zero-day bug enables unauthenticated attackers to remotely execute administrative commands on affected WAF devices via specially crafted HTTP requests. Threat actors were observed actively exploiting the flaw in the wild before the vendor released patches, allowing them to potentially compromise sensitive networks, bypass perimeter defenses, and gain high-privilege access to protected applications. Burdened by the high privilege level of administrative access, compromised systems are exposed to data theft, operational disruption, or lateral movement within enterprise networks. The incident highlights an ongoing surge in zero-day exploitation of critical infrastructure solutions, particularly targeting network perimeter and cloud security devices. Preliminary evidence suggests opportunistic attackers and advanced persistent threats are both involved, driving renewed urgency for timely patching, actionable threat detection, and Zero Trust strategies across enterprise and cloud environments.
8 months ago
Kill Chain
Cursor Vulnerability: AI Code Assistant Supply-Chain Flaw Exposes Credentials
In early 2024, security researchers uncovered a significant supply-chain vulnerability affecting Cursor, an AI-powered coding assistant, enabling attackers to hijack Cursor's internal application browser via a malicious MCP (Model Control Protocol) server. Exploiting this weakness, threat actors could inject malicious code through the compromised server, control the tool’s browser processes, and steal sensitive user credentials, potentially jeopardizing developer environments and broader organizational security. The vulnerability allows attackers to manipulate trusted workspace sessions, escalating the risk of lateral movement within corporate infrastructure. This incident highlights the increasing risks associated with AI-driven developer tools and the broader supply chain, reflecting a growing attacker focus on abusing trust relationships within cloud-native and collaborative software platforms. Organizations must revisit supply-chain security and adopt robust detection and response strategies for AI-enabled environments.
8 months ago
Kill Chain
US Citizens Busted for Aiding North Korean IT Worker Supply-Chain Fraud in 2024
In 2024, four United States citizens pleaded guilty to helping North Korean nationals surreptitiously secure IT positions at American companies by misrepresenting the workers’ identities and providing remote access to corporate assets. This insider-assisted scheme enabled foreign IT professionals to bypass typical background checks and compliance controls, giving them potential access to sensitive information and intellectual property. The activities ran over a sustained period and leveraged supply-chain weaknesses in remote workforce onboarding and equipment provisioning, ultimately exposing numerous U.S. firms to regulatory and operational risk. This incident underscores a worrying trend in which threat actors exploit remote work arrangements, weak identity verification protocols, and gaps in third-party management—highlighting increased regulatory scrutiny on supply-chain and insider vulnerabilities, especially amid ongoing geopolitical tensions involving North Korea.
8 months ago
Kill Chain
Jaguar Land Rover 2023 Ransomware Attack: $220 Million in Damages
In Q3 2023, Jaguar Land Rover (JLR) suffered a disruptive ransomware attack that severely impacted its global operations. The company reported in its financial results that the cyber incident, which occurred between July and September 2023, incurred costs amounting to £196 million ($220 million). Attackers leveraged ransomware to compromise JLR systems, reportedly targeting critical IT infrastructure essential for production and distribution. While business continuity was maintained post-incident, the supply chain faced significant disruptions, and the company responded promptly by activating its incident response protocols and collaborating with cybersecurity authorities. This incident is emblematic of the rising financial and operational toll ransomware inflicts on the automotive sector and large manufacturers globally. Increasingly sophisticated cybercriminals are actively targeting organizations with complex supply chains, amplifying the need for robust east-west security, visibility, and segmentation to protect critical assets in line with emerging compliance and regulatory expectations.
8 months ago
Kill Chain
The 2024 Finger Protocol ClickFix Malware Attack: Legacy Protocols Reused for Command and Control
In early 2024, security researchers uncovered that threat actors were actively abusing the decades-old 'finger' protocol—a remote access and user lookup protocol seldom used in modern networks—as a covert command and control (C2) channel for deploying ClickFix malware on Windows devices. Attackers leveraged the unencrypted and often overlooked finger service to quietly retrieve remote commands, allowing compromise of endpoints and escalation of persistent access across targeted corporate environments. The attacks often evaded traditional security controls, highlighting a resurgence of legacy protocol exploitation as a lateral movement and control method that bypasses common detection. This incident demonstrates the increased ingenuity of malware authors in repurposing overlooked network protocols to evade security controls. As threat actors broaden their toolkits to exploit legacy services, organizations with insufficient east-west segmentation, network visibility, or outdated protocol restrictions remain at risk of similar covert command and control attacks.
8 months ago
Kill Chain
Google Lawsuit Disrupts Lighthouse: Major Blow to Smishing Operations in 2024
In early 2024, Google initiated legal action against the operators behind Lighthouse, an SMS phishing (smishing) platform used to impersonate legitimate services and lure victims into fraudulent payment schemes, such as fake unpaid road tolls. The suspected operators, commonly referred to as the Smishing Triad and believed to be based in China, leveraged the Lighthouse kit and Telegram groups to execute widespread phishing campaigns. Following Google's lawsuit in the Southern District of New York, Lighthouse's infrastructure, Telegram channels, and several associated domains were taken offline, significantly disrupting the group's activities and signaling a major blow to organized SMS phishing at scale. This incident underscores the growing role of civil litigation and collaboration between technology giants and threat intelligence firms in disrupting cybercriminal ecosystems. As smishing attacks rise in sophistication and frequency worldwide, organizations must ensure layered defenses and readiness for increasingly advanced social engineering threats.
8 months ago
Kill Chain
ClickFix: How Attackers Exploited finger.exe for Stealthy Network Access in 2023
In November 2023, organizations reported a wave of Living-off-the-Land (LotL) attacks known as ClickFix, in which adversaries abused the legacy finger.exe utility on Windows systems. Attackers exploited finger.exe to retrieve and execute malicious scripts by leveraging the finger protocol over TCP port 79, bypassing endpoint security tools that are often tuned for more common protocols. The technique allowed attackers to maintain stealthy communications and initial access, exposing corporate environments where outbound traffic controls were inadequate. No major ransomware group claimed responsibility, but the campaign highlighted increasing sophistication in LotL exploitation, putting enterprises at risk of lateral movement and data exfiltration. This incident is highly relevant given the resurgence of attackers abusing built-in OS utilities to evade detection, as well as increased regulatory scrutiny over encrypted and segmented internal network traffic. Organizations must reevaluate their defenses against legacy protocol abuse.
8 months ago
Kill Chain
150,000 Malicious Packages Flood NPM in Record-Breaking Token Farming Attack
In early June 2024, attackers unleashed a self-replicating campaign on the NPM package registry, flooding it with over 150,000 malicious packages. The attack targeted user authentication tokens linked to the tea.xyz protocol, leveraging automation to exploit repository weaknesses and propagate at scale. The malicious packages were largely automated, making detection and removal challenging. The attackers’ actions threatened to undermine trust in the open-source JavaScript ecosystem, potentially exposing developers and end users integrating these packages into their applications to credential theft and further compromise. This incident underscores the escalating risks in software supply chains, where open-source dependencies serve as fertile ground for large-scale token harvesting and distributed attacks. It highlights a concerning rise in automation-driven supply chain exploits and the urgent need for enhanced package repository security and vetting processes.
8 months ago
Kill Chain
Five US Citizens Plead Guilty: North Korean IT Worker Sanctions Evasion Exposed
In 2025, the U.S. Department of Justice announced that five U.S. citizens pleaded guilty to aiding North Korean nationals in infiltrating over 130 companies by posing as IT workers. The individuals—Audricus Phagnasay, Jason Salazar, Alexander Paul Travis, Oleksandr Didenko, and Erick—operated a fraudulent scheme that enabled North Korea to evade international sanctions. Using sophisticated tactics, the group helped launder the proceeds from illegal IT contracts with U.S. and global firms, providing North Korea with critical revenue streams to support prohibited activities, including weapons development. This incident highlights the growing trend of nation-state actors exploiting legitimate IT contracting channels to bypass international sanctions. Widespread remote work, talent shortages, and lax vendor verification have increased organizational exposure to similar fraud, raising urgent compliance and geopolitical risk for businesses worldwide.
8 months ago
Kill Chain
Akira Ransomware Hits Nutanix VMs, Exposing Threats to Critical Sectors
In early 2024, the Akira ransomware-as-a-service (RaaS) operation expanded its attack capabilities by targeting Nutanix virtual machines, allowing it to compromise both Windows and Linux workloads within critical infrastructure and enterprise environments. Attackers exploited new vulnerabilities and lateral movement techniques to rapidly deploy ransomware, encrypting data at scale and causing significant business disruption among targeted organizations. Notably, Akira’s evolving tooling enabled them to bypass certain traditional detection measures and exfiltrate sensitive information to pressure victims into ransom payment. This campaign highlights the increasing sophistication of ransomware operators and the growing risk posed to hybrid and multicloud environments. The success of the Akira group against high-value sectors underscores the urgent need for advanced east-west traffic security, visibility, and robust segmentation strategies.
8 months ago
Kill Chain
FortiWeb CVE-2025-64446: Honeypot Reveals Automated Web App Exploits
In November 2025, researchers observed active exploit attempts targeting FortiWeb appliances via CVE-2025-64446. Attackers sent specially crafted POST requests to FortiWeb's administration interface, leveraging the vulnerability to create privileged admin accounts remotely. The attack, first detected in internet-facing honeypots, allowed adversaries potential unauthorized control over victim devices and lateral access to connected environments. Organizations using vulnerable firmware versions face the risk of compromise if patches are not applied. This incident highlights the rapid adoption and automation of new web application exploits by threat actors. With FortiWeb appliances deployed widely across critical infrastructure, mass exploitation attempts have increased urgency for organizations to implement robust patch management and web application security controls.
8 months ago
Kill Chain
Digital Doppelgangers: How Gh0st RAT Impersonation Attacks Are Evolving in 2024
In early 2024, sophisticated cyber attackers launched a series of impersonation campaigns targeting Chinese-speaking users with the distribution of the notorious Gh0st RAT malware. By mimicking trusted brands and official services, the threat actors exploited social engineering techniques to trick victims into opening malicious documents. Once activated, Gh0st RAT enabled remote access to infected systems, allowing attackers to exfiltrate sensitive data, monitor user activity, and potentially move laterally within organizational networks. The campaigns demonstrated a deep understanding of the target population's online behaviors, leveraging regional platforms and culturally relevant lures to increase infection success rates. This incident highlights a growing trend of language- and culture-specific impersonation attacks, particularly those using well-established remote access trojans. As organizations expand their digital presence in diverse markets, the risk of highly targeted social engineering and malware campaigns increases, demanding enhanced east-west traffic controls and proactive detection strategies.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports