Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Federal Agency Breached via GeoServer RCE Exploit in 2024
In July 2024, a U.S. federal civilian executive branch agency suffered a significant security breach when attackers exploited a critical remote code execution (RCE) vulnerability (CVE-2024-36401) in an unpatched GeoServer instance. Threat actors gained initial access by leveraging proof-of-concept exploits that had been made public after the vulnerability's disclosure. They moved laterally across the agency’s internal network, breaching additional web and SQL servers, deploying web shells like China Chopper, escalating privileges, and maintaining persistence. The attackers remained undetected for three weeks, only triggering detection when the agency’s EDR tool flagged suspicious malware activity. This breach underscores the growing risk posed by rapid weaponization of new vulnerabilities, particularly those affecting widely used open-source platforms. The incident follows a trend of increased attacks exploiting unpatched systems and weak internal segmentation, emphasizing the urgent need for proactive vulnerability management and robust East-West traffic controls.
8 months ago
Kill Chain
Nearly 2,000 MCP Servers Left Exposed by Authentication Misconfiguration in 2024
In early 2024, security researchers discovered that nearly 2,000 MCP (Management Control Plane) servers worldwide were left completely unsecured due to disabled or unconfigured authentication settings. This cloud misconfiguration meant that anyone with internet access could gain full administrative control, potentially allowing unauthorized parties to manipulate workloads, exfiltrate sensitive data, or deploy malicious software at will. The lack of basic security controls exposed organizations leveraging agentic AI services to severe operational risks, compliance violations, and potential breaches of critical business infrastructure. This incident underscores a troubling pattern of cloud misconfiguration, particularly as organizations rapidly adopt AI and cloud-native platforms. As threat actors increasingly target exposed management interfaces and identity systems, the urgent need for robust authentication and continuous configuration monitoring has never been greater.
8 months ago
Kill Chain
Amazon ECS Privilege Escalation Flaw Exposes Critical IAM Risks in 2024
In early 2024, an independent security researcher uncovered a privilege escalation vulnerability in Amazon Elastic Container Service (ECS) that allowed attackers to abuse an undocumented protocol to gain IAM permissions well beyond their original access. By exploiting a misconfiguration in ECS’s internal handling of credentials, a malicious user could escalate from container-level privileges to full IAM role hijacking, enabling lateral movement across cloud environments and access to sensitive AWS resources. Amazon responded quickly and patched the issue after disclosure, but the flaw potentially exposed numerous customer environments to risk. This incident underscores the growing risk of cloud misconfigurations and privileged identity attacks, as well as the need for real-time monitoring of cloud service behaviors. Security teams should recognize the increasing creativity of threat actors targeting identity and access weaknesses within major cloud providers.
8 months ago
Kill Chain
Cloud Misconfig Leaves 2,000 MCP Servers Wide Open to Attack
In June 2024, security researchers uncovered that nearly 2,000 MCP (Managed Cloud Platform) servers were left exposed to the public internet without any authentication required. Attackers could readily gain unfettered administrative access, enabling full server control, lateral movement within environments, and potential exfiltration or disruption of sensitive workloads. The breach was a direct result of critical cloud misconfigurations, specifically the omission of basic authentication on systems underpinning key business and AI operations. While no single threat actor has been publicly attributed, the sheer scale exposes businesses globally to automated attacks, data theft, and business disruption. This incident highlights the persistent danger of insecure cloud defaults, particularly as organizations accelerate adoption of agentic AI and cloud-native architectures. With threat actors increasingly scanning for misconfigured cloud assets and attacker dwell time decreasing, timely secure configuration and visibility are more essential than ever.
8 months ago
Kill Chain
Google Gemini AI AI Vulnerability Enables Stealth Phishing Across Google Products
In early 2024, a significant vulnerability was uncovered in Google’s Gemini AI assistant, exposing users across Google platforms to sophisticated prompt injection attacks. Adversaries leveraged this flaw to craft invisible, malicious prompts that disguised themselves as legitimate Google Security alerts, tricking users and facilitating vishing and phishing attacks. The flaw allowed threat actors to bypass visible UI cues, broadening attack reach across Google applications and potentially compromising internal data and account integrity. Google was notified and began remediation efforts, but the proof-of-concept highlighted how large-scale AI platforms present new attack surfaces. This incident reflects an emerging trend where AI-driven tools are being targeted through prompt injection and model manipulation, creating challenging attack vectors for even the largest technology firms. The Gemini vulnerability underscores the importance of advanced security testing for generative AI and the urgent need for zero trust controls within AI ecosystems.
8 months ago
Kill Chain
2025’s Multichannel Phishing Surge: How Attackers Bypassed MFA and Hijacked Sessions
In early 2025, a wave of sophisticated phishing attacks exploited new multichannel vectors, including social media platforms, malicious search advertisements, and browser-based manipulation, to bypass multi-factor authentication and steal user sessions. Threat actors rapidly adapted to defensive advances, leveraging session hijacking and advanced social engineering to deceive users, often eclipsing legacy email-based phishing. Organizations reported credential compromise, unauthorized access to sensitive resources, and downstream data breaches as a result of these evolving techniques. The relevance of this incident is underscored by the acceleration of identity-based attacks, targeting hybrid and cloud environments and challenging traditional security controls. Regulatory focus on data privacy and authentication heightens the need for organizations to reassess their phishing defenses, user awareness, and session protection strategies.
8 months ago
Kill Chain
Malicious Implants in AI Supply Chains: 2024’s Stealth Attack Surface
In early 2024, security researchers uncovered evidence that malicious implants are increasingly targeting AI components and applications through vulnerabilities in the supply chain. Threat actors leveraged weaknesses in popular AI frameworks and third-party dependencies to introduce stealthy backdoors and implants, enabling them to evade modern security tools. The attackers often exploited insufficient validation of AI model inputs, compromised third-party code, or leveraged misconfigurations to achieve persistent access and lateral movement within enterprise environments, resulting in sensitive data exposure and operational risk for organizations deploying AI-driven solutions. This incident underlines an emerging trend where cybercriminals and nation-state actors prioritize supply-chain vectors to subvert the rapidly expanding AI ecosystem. As AI adoption accelerates and digital trust becomes paramount, organizations face increased regulatory scrutiny and pressure to implement robust controls around software provenance and supply chain integrity.
8 months ago
Kill Chain
GhostPoster: Malicious Firefox Add-ons Drive 2025 Supply-Chain Breach
In late 2025, security researchers at Koi Security uncovered a widespread supply-chain malware campaign named "GhostPoster." This campaign weaponized 17 Mozilla Firefox browser add-ons, leveraging benign logo files to conceal malicious JavaScript that hijacked affiliate links, injected tracking codes, and orchestrated click and ad fraud operations. The compromised extensions had garnered over 50,000 downloads before Mozilla intervened to remove them from its add-on repository, but users were already exposed to extensive privacy intrusions and potential data exfiltration. The GhostPoster incident underscores a growing trend of exploiting trusted browser extension ecosystems for mass infection and financial fraud. With attackers increasingly targeting supply-chain vectors and browser add-ons, organizations and individuals must reevaluate extension vetting processes amid surging regulatory scrutiny and evolving adversary techniques.
9 months ago
Kill Chain
WhatsApp GhostPairing: 2024 Account Takeover Campaign Exploits Device Linking
In June 2024, cyber attackers launched widespread account takeover campaigns targeting WhatsApp users by exploiting the platform’s legitimate device-linking feature. This method, known as 'GhostPairing,' allows threat actors to hijack user accounts without requiring the victim’s credentials or multi-factor authentication codes. By intercepting or tricking users into sharing device-linking codes, attackers can remotely pair new devices to victims’ WhatsApp accounts, thus gaining complete access to conversations, contacts, and stored media. The campaign appears automated and has affected users globally, sparking concerns over the resilience of messaging platform identity controls. This incident highlights rising abuse of legitimate features and growing sophistication of social engineering tactics to bypass traditional security controls. Similar account compromise techniques are increasingly observed across the industry, prompting urgent calls for strengthened identity verification and robust monitoring of device association activities.
9 months ago
Kill Chain
Chinese APT Exploits Cisco AsyncOS Zero-Day in 2025: What You Need to Know
In December 2025, Cisco disclosed an unpatched, maximum-severity zero-day vulnerability (CVE-2025-20393) affecting AsyncOS running on Cisco Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances with exposed Spam Quarantine features. Leveraging this zero-day, the Chinese-nexus APT group UAT-9686 exploited systems by executing commands as root, deploying persistent backdoors (AquaShell), reverse SSH tunnels (AquaTunnel, Chisel), and evasion tools (AquaPurge). The campaign was active from late November 2025, with intrusions traced to sophisticated nation-state tooling and lateral movement, potentially compromising sensitive email infrastructure and enabling persistent access. This incident underscores ongoing risks from zero-day exploitation by advanced threat actors, especially those leveraging public-facing management interfaces and unpatched systems for initial access. The active exploitation by a Chinese APT mirrors broader trends in targeted cyberespionage against enterprise collaboration tools and highlights the urgency of proactive exposure management and segmentation.
9 months ago
Kill Chain
State-Backed Attackers Breach SonicWall SMA1000 Devices via Zero-Day Chain in 2025
In December 2025, SonicWall urgently advised customers to patch a newly identified zero-day vulnerability (CVE-2025-40602) in its SMA1000 Appliance Management Console after attackers exploited it in the wild. The attack chain combined this medium-severity local privilege escalation flaw with a critical pre-authentication deserialization vulnerability (CVE-2025-23006), allowing remote unauthenticated threat actors to execute arbitrary OS commands with root privileges on vulnerable appliances. These appliances serve as secure remote access gateways for large enterprises and critical infrastructure, amplifying the risk of broad organizational compromise and lateral movement within protected networks. The incident follows prior breaches and repeated targeting of SonicWall solutions by sophisticated, potentially state-backed actors, with over 950 SMA1000 devices found internet-exposed. Immediate remediation was urged to prevent further exploitation amidst evidence of active, targeted attacks. The SonicWall SMA1000 incident underscores a persistent trend of advanced actors leveraging zero-day exploits in network infrastructure appliances, fueling urgency around patch management and segmentation. This breach highlights the evolving complexity of attack chains targeting foundational remote access technologies and the critical need for proactive defense-in-depth and threat visibility measures.
9 months ago
Kill Chain
How Weaxor Ransomware Leveraged the React2Shell Vulnerability in 2025
In December 2025, cybercriminals exploited the critical React2Shell vulnerability (CVE-2025-55182) in React Server Components and Next.js to gain unauthorized access to a corporate endpoint. Within seconds, attackers deployed the Weaxor ransomware strain, rapidly encrypting files and appending a '.WEAX' extension, while dropping ransom notes named 'RECOVERY INFORMATION.txt' in each directory. The attack began by delivering an obfuscated PowerShell command, installing a Cobalt Strike beacon for command-and-control, disabling Windows Defender, wiping shadow copies, and clearing logs to evade detection and hinder forensic analysis. Researchers confirmed there was no lateral movement or data exfiltration prior to encryption, and the targeted machine was subsequently compromised by additional threat actors. This incident highlights the widespread exploitation of recently disclosed vulnerabilities by both ransomware gangs and nation-state actors. With opportunistic attacks increasing in speed and automation, organizations must improve patch velocity and advanced monitoring to defend against emerging, rapidly weaponized threats.
9 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports