Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
CISA Raises Red Flag: Sudo Vulnerability Opens Door to Linux & Unix Attacks
In September 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) urgently flagged a critical vulnerability, CVE-2025-32463, in the Sudo command-line utility that affects most Linux and Unix-like systems. Attackers have actively exploited this flaw to gain unauthorized root-level privileges, bypassing standard user restrictions. The vulnerability lies in how Sudo handles certain inputs, allowing threat actors to escalate privileges after breaching an account or exploiting a weak service. Exploitation has already been observed in the wild, impacting organizations globally and raising significant concerns about data integrity and lateral movement within enterprise environments. This incident underscores the increasing sophistication of privilege escalation attacks targeting essential open-source utilities. It also highlights an urgent need for organizations to strengthen patch management and bolster monitoring, as these vulnerabilities are being rapidly weaponized by both criminal and nation-state actors.
8 months ago
Kill Chain
Datzbro Android Trojan Exploits Elderly via Facebook Travel Event Scams in 2025
In August 2025, cybersecurity researchers discovered a sophisticated Android banking trojan named Datzbro targeting elderly users in Australia. The malware spread through AI-generated Facebook groups promoting travel events for seniors, tricking victims into installing a malicious app under the guise of exclusive event details. Once installed, Datzbro enabled full device takeover, allowing threat actors to intercept credentials, manipulate transactions, and conduct fraudulent activities undetected, resulting in significant financial losses for victims and the potential compromise of sensitive personal data. This incident highlights the growing exploitation of AI-driven social engineering techniques and the increasing focus on vulnerable demographics like the elderly. The convergence of advanced mobile malware and tailored deception campaigns presents escalating risks for global financial institutions and their customer bases.
8 months ago
Kill Chain
UNC5174 Exploits VMware Zero-Day in Cloud Foundation: 2024 Breach Analysis
In October 2024, China-linked threat actor UNC5174 actively exploited an undisclosed zero-day vulnerability (CVE-2025-41244) in Broadcom VMware Tools and VMware Aria Operations, primarily impacting VMware Cloud Foundation 4.x and 5.x. This local privilege escalation flaw allowed attackers to gain elevated access on affected systems, facilitating potential lateral movement across enterprise networks. The exploitation campaign remained undetected for several months until NVISO Labs and security researchers documented the sophisticated tactics, techniques, and persistence of UNC5174. This incident highlights the growing risks associated with zero-day vulnerabilities in widely deployed virtualization platforms, especially as advanced persistent threats increasingly target cloud and hybrid infrastructure. The attack underscores the urgent need for robust patch management and east-west security controls amid a surge in sophisticated nation-state cyber activity.
8 months ago
Kill Chain
Google Gemini AI 2025: Prompt Injection and Cloud Exploit Flaws Revealed
In September 2025, cybersecurity researchers disclosed three critical, now-patched vulnerabilities in Google’s Gemini AI assistant platform. Attackers were able to exploit prompt injection and log-to-prompt injection flaws within Gemini’s Search Personalization Model and Cloud deployment, risking unauthorized data access, privacy compromise, and potential theft of sensitive information. The exploited vulnerabilities allowed crafted prompts or manipulated logs to execute unintended commands, bypass safeguards, and potentially leak user data, highlighting major security gaps in generative AI-driven workflows before emergency updates were deployed by Google. This incident underscores the growing risk of prompt injection and supply-chain-type threats in the AI/ML ecosystem. The attack reflects a surge in adversarial tactics targeting large language models and cloud-based AI assistants, drawing regulatory attention and prompting security leaders to reassess AI deployment controls in enterprise environments.
8 months ago
Kill Chain
Palo Alto GlobalProtect VPN Vulnerability (CVE-2024-3400): Global Exploitation in 2024
In September 2024, cybersecurity observers detected a surge in malicious internet scans targeting Palo Alto Networks GlobalProtect gateways vulnerable to CVE-2024-3400. Threat actors exploited an authentication validation flaw, enabling unauthenticated attackers to manipulate session IDs and upload arbitrary files to the server. Initial activity was observed from IP 141.98.82.26, executing file upload and retrieval attempts against honeypots. While early-stage attacks focused on validating exploitability, successful exploitation of this flaw could lead to remote code execution, exposing enterprise networks protected by GlobalProtect to compromise, lateral movement, and potential data breaches. This incident is significant as CVE-2024-3400 rapidly attracted widespread exploitation attempts, with proof-of-concept code and automated scanning observed in the wild. The event underscores the criticality of timely appliance patching and the inherent risk posed by remotely accessible VPN infrastructure in enterprise environments.
8 months ago
Kill Chain
Battering RAM: $50 Hardware Attack Breaks Intel & AMD Cloud Defenses
In October 2025, researchers from KU Leuven and the University of Birmingham unveiled a significant vulnerability dubbed "Battering RAM" affecting both Intel and AMD cloud processor architectures. By inserting a $50 hardware interposer into the memory bus, attackers demonstrated the ability to bypass state-of-the-art cloud security mechanisms. This approach allowed them to intercept, manipulate, and extract both encrypted and unencrypted in-memory data flows intended to remain protected by hardware and virtualization-layer defenses. The attack's stealth and low cost highlight the practical risk to multi-tenant and cloud environments relying on trusted chipset-based security. The Battering RAM disclosure comes amid growing concerns around hardware-level threats capable of undermining software-managed frameworks, especially in multi-cloud and highly regulated sectors. This incident underscores the need for enhanced hardware threat modeling, rapid detection capabilities, and updated compliance guidance tailored to physical vector risks.
8 months ago
Kill Chain
Apple Rushes Security Fix for Critical FontParser Vulnerability (CVE-2025-43400)
In September 2025, Apple released urgent security updates for iOS, iPadOS, macOS, and visionOS to address CVE-2025-43400—a vulnerability in the FontParser component allowing maliciously crafted fonts to trigger app termination or corrupt process memory. This flaw affects recent and some older OS versions, with Apple pushing out rapid patches to prevent potential exploitation. As of release, there is no evidence of active attacks or remote code execution stemming from this bug, but the vulnerability represents a serious risk due to the widespread use of affected products and the low-complexity of font-based exploits. This incident highlights how even routine OS updates can carry vital security fixes against emerging threats. With font parsing bugs being favored by both criminals and spyware operators in recent years, broad and proactive patching remains essential, especially as quick-moving threat actors seek early exploit opportunities.
8 months ago
Kill Chain
Akira Ransomware Launches Mass Attack on SonicWall VPNs in 2025
In mid-2025, Akira ransomware operators launched a widespread campaign targeting organizations using SonicWall VPN appliances, exploiting a critical vulnerability (CVE-2024-40766) in SonicOS firmware. Attackers achieved initial access through malicious SSL VPN logins, sometimes even bypassing one-time password (OTP) multi-factor authentication controls. Following a successful breach, the attackers conducted rapid port scanning and lateral movement via Impacket SMB activity before deploying Akira ransomware, impacting organizations across various sectors. Despite firmware updates and password resets, compromised credentials persisted, leaving several devices exposed, and the campaign has continued to escalate into late September 2025. This incident illustrates the ongoing evolution and sophistication of ransomware campaigns exploiting network infrastructure vulnerabilities and underscores the urgency of proactive credential management, privileged access monitoring, and swift patch adoption. It exemplifies growing attacks abusing VPNs and MFA, requiring organizations to revisit zero trust and layered defense measures.
8 months ago
Kill Chain
Malicious MCP Server Abuses AI Email Automation for Covert Secrets Exfiltration
In June 2024, researchers uncovered a supply-chain attack involving a malicious Managed Communication Platform (MCP) AI server deployed by enterprises for automating routine email tasks, such as password resets, account confirmations, and invoicing. Threat actors subverted the platform to silently exfiltrate sensitive information by routing copies of key emails via BCC fields to attacker-controlled addresses. This tactic enabled attackers to capture credentials, personally identifiable information (PII), and financial data from authentic business processes, making detection extremely challenging and extending the risk across multiple organizations leveraging the affected platform. The incident highlights a growing trend of attackers abusing trusted third-party SaaS and AI service integrations to conduct covert exfiltration at scale. As supply-chain vectors proliferate, organizations face increased pressure to monitor internal communication workflows and enforce egress controls on platform-generated messaging.
8 months ago
Kill Chain
AI Voice Cloning Ushers in the Next Wave of Real-Time Vishing Attacks
In mid-2024, cybersecurity researchers from NCC Group demonstrated that AI-powered voice cloning now enables highly convincing, real-time vishing (voice phishing) attacks. By training voice models with just a few minutes of publicly available recordings, attackers were able to conduct live phone calls, impersonate executives or IT staff, and successfully extract sensitive information from organizations and individuals. Notably, real organizations were targeted in proof-of-concept scams that bypassed prior limitations such as latency or unnatural responses, blurring the line between real and synthetic voices and exposing significant new avenues for social engineering that traditional defenses may not stop. This incident highlights the rapid escalation in the capabilities of cybercriminals leveraging generative AI for social engineering. Security leaders are now facing an urgent need to adapt defenses, reconsider trust in voice authentication, and train employees about increasingly undetectable scams as vishing becomes more automated, scalable, and effective using minimal resources and AI frameworks.
8 months ago
Kill Chain
Google Gemini AI Model Vulnerabilities: The 2024 Security Wake-Up Call
In early 2024, significant security and privacy vulnerabilities were discovered across multiple Google Gemini AI models, exposing users and enterprises to attack vectors that could have led to data leakage, privilege escalation, and AI-assisted exploitation. Researchers identified a 'trifecta' of flaws enabling prompt injection, sensitive data exposure, and circumvention of embedded safety controls, highlighting weaknesses in current generative AI guardrails. While no widespread attacker exploitation was confirmed, proof-of-concept attacks demonstrated how these flaws could weaponize Gemini models as an attack surface and vehicle for secondary threats. The disclosure prompted urgent reviews of AI usage and mitigations for enterprise consumers. This incident underscores escalating risks as generative AI platforms become embedded across business workflows. It illustrates the urgent challenge of securing large language models (LLMs) against novel exploitation methods and the rapidly intensifying focus by both attackers and regulators on AI/ML supply chain security.
8 months ago
Kill Chain
Phantom Taurus: Inside the 2025 Chinese APT NET-STAR Espionage Breach
In early 2025, security researchers uncovered a sophisticated espionage campaign attributed to a newly recognized Chinese nation-state actor, Phantom Taurus. Operating since at least late 2022, the group prioritized stealth and advanced tactics, primarily targeting government and telecommunications entities across Africa, the Middle East, and Asia. Attackers leveraged a novel, highly covert malware suite—NET-STAR—capable of remaining fileless within IIS web servers and facilitating persistent, encrypted exfiltration of sensitive diplomatic, military, and geopolitical data. The operation exploited custom-developed tools to move from email theft to direct database compromise, employing in-memory web backdoors and evasion techniques like timestomping and security mechanism bypasses to avoid detection and maintain long-term access. The exposure of Phantom Taurus and the NET-STAR suite highlights an escalating trend of targeted, stealthy cyber espionage campaigns against critical infrastructure by advanced persistent threat (APT) actors. This incident underscores the urgent need for organizations to strengthen east-west security visibility, enforce zero trust principles, and regularly review controls against constantly evolving attacker tradecraft.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports