Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
AI-Powered Malware & Hyper-V Exploits: The 2025 Multi-Vector Attack Recap
In early November 2025, a series of sophisticated cyberattacks targeted enterprise and consumer systems worldwide, exploiting vulnerabilities in Hyper-V virtual machines, RDP protocols, and leveraging malicious AI bots. Attackers deployed stealthy malware within virtualized environments to evade detection, while advanced spyware campaigns targeted Android devices using side-channel techniques to capture sensitive AI chat data. Additionally, high-profile service disruptions, including a mass WhatsApp account lockdown, affected millions of users and raised concerns about systemic vulnerabilities and cross-platform exploitation. The threat actors behind these incidents demonstrated new levels of coordination and adaptability, with alliances between major cybercrime groups amplifying the scope and impact of the campaigns. This incident underscores an accelerating trend toward multi-vector, AI-enabled cybercrime and highlights the convergence of ransomware, lateral movement, and novel attack methods across cloud and hybrid infrastructures. Security leaders should anticipate further escalation in both the sophistication and frequency of such attacks through 2025, heightening urgency for layered defenses and zero trust strategies.
8 months ago
Kill Chain
Triofox Flaw Exploited: How CVE-2025-12480 Enabled Remote Access Tool Attacks
In June 2025, cybersecurity researchers at Google's Mandiant Threat Defense uncovered active exploitation of a critical authentication bypass vulnerability (CVE-2025-12480, CVSS 9.1) affecting Gladinet's Triofox file-sharing and remote access platform. Attackers leveraged this n-day vulnerability—now patched—to gain unauthorized access to Triofox administrative configuration panels. With authentication circumvented, they uploaded and executed malicious payloads, specifically deploying remote access tools via the platform’s integrated antivirus feature. This enabled adversaries to establish persistent footholds, move laterally, and potentially exfiltrate sensitive corporate data and credentials. The incident underscores the ongoing urgency of patch management and monitoring, as threat actors continue to weaponize critical vulnerabilities within widely used collaboration and remote access tools. Industry experts warn of increasing attacks exploiting n-day vulnerabilities before patch adoption, reflecting a broader trend toward highly targeted lateral movement and remote tool deployment campaigns.
8 months ago
Kill Chain
CISA Flags Samsung Mobile Devices for Critical Exploited Vulnerability (CVE-2025-21042)
In November 2025, CISA added CVE-2025-21042, an out-of-bounds write vulnerability affecting Samsung Mobile Devices, to its Known Exploited Vulnerabilities (KEV) Catalog following active exploitation in the wild. Threat actors have leveraged this flaw to gain unauthorized control over affected devices, potentially allowing them to execute arbitrary code, escalate privileges, and compromise sensitive user data. The vulnerability poses significant risks to both federal agencies and commercial enterprises, prompting CISA to mandate remediation by federal civilian agencies under Binding Operational Directive (BOD) 22-01. Failure to remediate exposes organizations to data breaches and operational disruption. This incident highlights a broader wave of targeted exploits against widely used mobile platforms, illustrating attackers’ ongoing shift toward mobile devices as primary entry vectors. With regulatory attention intensifying, the urgency for rapid vulnerability management and proactive defense measures is escalated for all sectors.
8 months ago
Kill Chain
ClickFix Hospitality Breach: Infostealer Attack Impacts Hotels and Their Customers
In early 2024, a cybercrime campaign known as "ClickFix" targeted hospitality providers globally using infostealer and remote access trojan (RAT) malware. Threat actors gained initial access via spear phishing and malicious links, compromising hotel systems to harvest sensitive booking data and customer contact information. Attackers leveraged this stolen data to conduct highly convincing secondary phishing attacks directed at hotel customers via both email and WhatsApp channels, exposing guests to social engineering, fraud, and further credential theft. This cascading impact emphasized the attacker's focus on exploiting trusted relationships across business and customer environments. The incident is notable for its dual-target strategy, harnessing a single breach to fuel broader downstream attacks and demonstrating attackers' sophisticated use of layered social engineering. As infostealer activity surges across the hospitality and service sectors, defenders must adapt to increasingly persistent, multi-stage campaigns that pose risks for both enterprise operations and their customers.
8 months ago
Kill Chain
TEE.fail: 2025 Hardware Attack Cracks Latest Secure Enclaves
In November 2025, researchers disclosed a critical hardware attack known as TEE.fail, which compromised secure enclaves (trusted execution environments or TEEs) across Intel, AMD, and ARM chips. By placing a small hardware device between a DDR5 memory chip and the motherboard, and leveraging kernel-level privileges, attackers were able to bypass the most advanced TEE protections including Confidential Compute, SEV-SNP, and TDX/SDX. Once exploited, these secure enclaves could no longer be trusted to protect sensitive data in-use, raising major concerns for cloud providers, enterprises, and users reliant on confidential computing. The attack’s low cost, simplicity, and applicability to modern hardware make it a significant development, reflecting growing sophistication in hardware-level threats. Regulatory scrutiny and industry attention have intensified as organizations reevaluate their trust assumptions and risk models for sensitive workloads.
8 months ago
Kill Chain
runC Vulnerabilities Threaten Container Security: Docker and Kubernetes Breach 2024
In June 2024, critical vulnerabilities (CVE-2024-21626, CVE-2024-21627, and CVE-2024-21628) were disclosed in the runC container runtime, which underpins Docker, Kubernetes, and many modern container platforms. These flaws could be exploited by attackers to break out of a container, bypassing isolation controls and gaining unauthorized access to the underlying host system. A successful exploit would allow lateral movement and potentially compromise entire cloud or on-premises environments. Prompt patching and risk assessment are essential, as proof-of-concept exploits have already been published in the wild. This incident underscores the increasing sophistication and focus of attackers on supply chain and containerization technologies, as organizations accelerate cloud and DevOps adoption. As regulatory expectations around zero trust and runtime controls intensify, keeping pace with container threat vectors is now mission-critical for enterprise security teams.
8 months ago
Kill Chain
GlassWorm Supply Chain Attack: Malicious VSCode Extensions Threaten Open Source Ecosystem
In June 2024, the GlassWorm malware resurfaced in a significant supply chain attack on the OpenVSX and Visual Studio Code (VSCode) extension marketplaces. Threat actors uploaded three malicious extensions, which were collectively downloaded over 10,000 times before detection and removal. These extensions were designed to compromise developer environments by deploying malware capable of exfiltrating credentials and enabling persistent access. The attack leveraged trusted open-source ecosystems, making it difficult for end users and organizations to detect the compromise until indicators of compromise (IoCs) were published, potentially exposing sensitive data and intellectual property. This event underscores a broader rise in supply chain attacks targeting developer tools and open-source package ecosystems. The campaign highlights the urgent need for rigorous code vetting, extension auditing, and enhanced supply chain security controls as attackers increasingly exploit automated trust in widely used development platforms.
8 months ago
Kill Chain
Microsoft's 'Whisper Leak' Side-Channel Attack Bypasses Encryption for AI Traffic
In late 2025, Microsoft researchers uncovered the 'Whisper Leak' side-channel attack, a novel method allowing passive adversaries to deduce the topics of conversations with streaming AI language models despite the use of encrypted, high-performance network protocols. Attackers exploited traffic analysis techniques, observing packet timing and size patterns, to infer sensitive discussion details traversing enterprise VPNs and encrypted links. Although private circuit encryption such as MACsec and IPsec was in place, the attack effectively bypassed traditional data-in-transit security controls, raising concerns for sectors leveraging AI in sensitive communications. This incident is significant as it highlights an emerging risk where encrypted cloud AI traffic can be compromised via sophisticated traffic analysis, just as generative AI adoption is surging across regulated industries. It illustrates evolving attacker sophistication beyond classical exploits, prompting urgent review of AI data security and zero trust segmentation strategies.
8 months ago
Kill Chain
'Ransomvibing' Supply Chain Attack Strikes Visual Studio Extension Marketplace
In early 2024, a malicious Visual Studio Code extension named 'Ransomvibing' was discovered on the Visual Studio Marketplace. The extension used AI-generated code to encrypt and exfiltrate sensitive project data from developer environments, leveraging encrypted outbound traffic to evade traditional detection methods. Despite containing telltale signs of automation and suspicious behavior, the extension bypassed security controls and was downloaded before being taken down, exposing users to significant intellectual property and operational risks associated with a compromised development supply chain. This incident highlights growing risks in open-source and extension marketplaces, as attackers increasingly exploit trusted software ecosystems with novel supply-chain techniques. Organizations should prioritize continuous monitoring of third-party integrations and reinforce their zero trust controls in response to evolving adversary methods.
8 months ago
Kill Chain
Landfall Malware: Covert Mobile Surveillance Hits Samsung Galaxy in 2024
In early 2024, cybersecurity researchers uncovered a sophisticated mobile surveillance campaign targeting Samsung Galaxy users through a malware strain dubbed 'Landfall.' Delivered primarily via malicious apps and phishing schemes, Landfall granted attackers covert access to device microphones, cameras, geolocation, and sensitive stored data. The threat actors capitalized on advanced evasion tactics to remain undetected, enabling them to record conversations, track user locations, collect photos, and exfiltrate contacts without the victims’ knowledge. The incident highlights the growing complexity of targeted mobile threats and the operational risks facing organizations with a mobile workforce. With the rise of mobile malware like Landfall exploiting modern smartphones’ vast attack surface, security teams must reassess their controls for device management, east-west traffic monitoring, and policy enforcement. This case underscores the urgency for enterprises to adopt zero trust defenses and adapt to evolving mobile threat tactics.
8 months ago
Kill Chain
APT Groups Exploit Hybrid & Multicloud Gaps: Insights from ESET Q2–Q3 2025 Activity Report
In Q2 and Q3 of 2025, ESET Research identified a surge in advanced persistent threat (APT) activity, with multiple sophisticated threat actors targeting organizations across various industries and geographies. These groups leveraged techniques such as east-west lateral movement within hybrid and multicloud environments, encrypted traffic tunneling, and exploitation of zero trust segmentation gaps. Attackers infiltrated networks via phishing campaigns, supply chain vulnerabilities, and exploitation of unpatched cloud workloads, achieving persistent access and data exfiltration. The business impacts included service disruptions, data breaches, and regulatory scrutiny for affected organizations. This incident underscores the increasing complexity of APT operations in cloud-centric architectures and highlights the urgency of implementing comprehensive east-west visibility, zero trust controls, and robust anomaly detection. The trends reported by ESET indicate a continued escalation of multicloud security risks and a persistent threat landscape adapting to modern enterprise environments.
8 months ago
Kill Chain
How State-Sponsored APTs Bypassed Multi-Cloud Defenses in 2025
Between Q2 and Q3 2025, ESET researchers identified a significant rise in sophisticated Advanced Persistent Threat (APT) attacks spanning multiple regions and industry verticals. State-sponsored actors leveraged encrypted communications and advanced lateral movement tactics to compromise organizations’ east-west cloud traffic, successfully bypassing conventional perimeter defenses. These campaigns exploited unmonitored internal traffic and insufficient network segmentation, leading to the exfiltration of sensitive data and critical infrastructure disruptions. The attackers demonstrated thorough knowledge of multi-cloud environments, combining zero-day exploits with stolen credentials to maintain persistent access and evade detection for weeks. This incident is emblematic of a broader trend—APT groups are accelerating the use of sophisticated, stealthy methods in hybrid cloud contexts. Modern enterprises must recognize the increased risk to east-west workloads, stay vigilant to evolving TTPs, and augment internal defenses in the face of rising geopolitical tensions and regulatory enforcement.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports