The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Banking/Mortgage

Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.

556 threat reports
Page 1 of 47

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Banking/Mortgage Threat Reports

Showing 1–12 / 556 reports
Critical WSO2 and Adobe Commerce Vulnerabilities Under Active Attack Added to CISA KEV
Impact· MEDIUM

Critical WSO2 and Adobe Commerce Vulnerabilities Under Active Attack Added to CISA KEV

CISA added two critical vulnerabilities to its Known Exploited Vulnerabilities catalog in September 2026: CVE-2026-5430 affecting WSO2 products and CVE-2026-71362 impacting Adobe Commerce and Magento. CVE-2026-5430 is a path traversal flaw allowing unrestricted file upload and remote code execution, while CVE-2026-71362 enables unauthorized account access through session switching. Security researchers observed active exploitation attempts against honeypots starting September 13, 2026, with attackers using forged JWT tokens and targeting customer account takeovers. Federal agencies must patch by September 27, 2026. These incidents highlight the accelerating timeline between vulnerability disclosure and active exploitation, with attackers moving within days rather than weeks to weaponize critical flaws against high-value enterprise platforms.

5 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
North Korean Hackers Steal $351.6M from Bitget in Sophisticated Backend Compromise
Impact· CRITICAL

North Korean Hackers Steal $351.6M from Bitget in Sophisticated Backend Compromise

On September 24, 2026, cryptocurrency exchange Bitget suffered a massive security breach resulting in the theft of $351.6 million from hot and warm wallets. Suspected North Korean threat actors compromised a critical backend system within Bitget's wallet infrastructure, used it to spoof transaction data, and triggered the authorization process to move funds out. The attack affected multiple cryptocurrency assets including ETH, XRP, BNB, AVAX, USDT, and USDC across seven different blockchain networks. While customer account balances remained accurate and trading continued normally, withdrawals were temporarily suspended as a precautionary measure during the ongoing investigation. This incident highlights the continued escalation of North Korean state-sponsored cryptocurrency theft operations, representing one of the largest single exchange compromises in 2026. The sophisticated backend compromise demonstrates evolving attack techniques that bypass traditional security controls, emphasizing the urgent need for enhanced infrastructure protection and transaction authorization mechanisms in the rapidly growing digital asset sector.

5 hours ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
PamStealer Malware Evolution: Live C2 Decryption Challenges macOS Security
Impact· HIGH

PamStealer Malware Evolution: Live C2 Decryption Challenges macOS Security

In September 2026, cybersecurity researchers discovered an evolved version of PamStealer macOS malware that implements sophisticated live command-and-control payload decryption and multi-layer persistence mechanisms. The new variant distributes through a fake cryptocurrency wallet website called "Wavel" and uses server-side X25519 key exchange to prevent static analysis of encrypted payloads. The malware establishes four redundant persistence methods including LaunchAgent installations, repair scripts, and Git hook injections, while stealing credentials from over a dozen browsers, keychain items, and system passwords through fake crash dialogs. This incident highlights the growing sophistication of macOS-targeted information stealers as threat actors invest heavily in anti-analysis techniques and delivery infrastructure, making traditional signature-based detection and static malware analysis significantly more challenging for security teams.

5 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical TEE-MPC Security Flaws Expose Cryptographic Vulnerabilities in Confidential Computing
Impact· LOW

Critical TEE-MPC Security Flaws Expose Cryptographic Vulnerabilities in Confidential Computing

Trail of Bits research revealed critical security vulnerabilities when combining Trusted Execution Environments (TEEs) with Multi-Party Computation (MPC) protocols, particularly in threshold signature schemes. The research demonstrates how malicious hosts can exploit rollback attacks against TEE-protected MPC implementations, causing nonce reuse that leads to private key disclosure. The vulnerabilities stem from the fundamental trust model clash between MPC's distributed security approach and TEEs' centralized manufacturer trust, creating new attack surfaces including filesystem rollbacks, incomplete attestation measurements, and side-channel exploits. Organizations deploying TEE-MPC hybrid systems face significant risks from implementation flaws that can compromise cryptographic security guarantees despite appearing to provide defense-in-depth protection. This research gains critical relevance as organizations increasingly adopt zero-trust architectures and confidential computing solutions to protect sensitive workloads. With the rise of AI workloads requiring secure multi-party computation and the growing deployment of TEE-enabled cloud services, understanding these interaction vulnerabilities becomes essential for preventing catastrophic cryptographic failures in production systems.

5 hours ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical .NET MAUI Vulnerabilities Expose Cross-Platform Mobile Security Risks
Impact· MEDIUM

Critical .NET MAUI Vulnerabilities Expose Cross-Platform Mobile Security Risks

Security researchers at Bishop Fox have demonstrated critical vulnerabilities in Microsoft's .NET Multi-platform App UI (MAUI) framework, revealing how cross-platform development creates unified security risks across iOS and Android applications. The analysis shows that MAUI's shared C# codebase architecture allows attackers to reverse-engineer a single assembly and apply findings to both platform versions simultaneously. Using their published mauidlltool, researchers can extract readable assemblies from both Android APKs and iOS IPAs, exposing hardcoded secrets, weak encryption implementations, and authorization flaws that affect millions of users across both app stores. This research highlights the growing security challenges of cross-platform mobile development frameworks as organizations prioritize development efficiency over security isolation. With MAUI applications increasingly deployed in enterprise environments handling sensitive data, the single-point-of-failure risk becomes particularly concerning for compliance and data protection.

5 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Multi-Vector Campaign Targets AI Systems and Banking: RemControl Trojan and Search Poisoning Analysis
Impact· HIGH

Multi-Vector Campaign Targets AI Systems and Banking: RemControl Trojan and Search Poisoning Analysis

In September 2026, cybersecurity researchers identified a coordinated multi-vector campaign targeting AI systems, banking applications, and enterprise development environments. The campaign featured the RemControl Android banking trojan targeting Western Europe and Canada through fake Google Play Store pages, a massive AI disinformation attack poisoning ChatGPT and Google AI Overviews with fraudulent information, and supply chain compromises affecting WordPress plugins and AI coding tools. Threat actors leveraged social engineering tactics, exploited trusted platforms, and manipulated AI training data to execute credential theft, financial fraud, and code repository exfiltration across multiple industries. This incident highlights the rapidly evolving threat landscape where attackers are increasingly targeting AI systems and trusted development tools, representing a fundamental shift toward exploiting automation and machine learning platforms that organizations rely on for daily operations.

22 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
MacSync Malware Evolution: From AppleScript to Advanced Swift/Objective-C Threats
Impact· HIGH

MacSync Malware Evolution: From AppleScript to Advanced Swift/Objective-C Threats

MacSync, a macOS cryptocurrency and information stealer first advertised in 2025, has undergone significant evolution in 2026 with new variants discovered by Kaspersky researchers. The malware family has transitioned from AppleScript-based implementations to sophisticated binary droppers written in Swift and Objective-C, featuring complex multi-stage infection chains that leverage Apple's iCloud infrastructure for payload delivery. The stealer targets developers and cryptocurrency enthusiasts through fake applications like the non-existent Toria crypto wallet, employing social engineering and masquerading as cracked software to gain initial access. This incident demonstrates the rapid evolution of macOS malware families and their increasing sophistication in targeting high-value users in the cryptocurrency and development communities, highlighting the growing threat to supply chain security through compromised developer workstations.

22 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical OnePlus Privilege Escalation Flaws Leave Millions of Devices Vulnerable to Root Access
Impact· HIGH

Critical OnePlus Privilege Escalation Flaws Leave Millions of Devices Vulnerable to Root Access

In September 2026, security researcher Rasmus Moorats disclosed two unpatched vulnerabilities in OnePlus devices that allow malicious Android applications to gain root access without requesting any permissions. The attack chains two flaws: one in OnePlus's AtlasService debugging component that accepts unchecked calls from any app, and another in the olc2 hardware helper service that executes arbitrary shell commands. The vulnerabilities affect OnePlus 15, OnePlus 12 Pro, and potentially all devices running OxygenOS 16, as well as OPPO devices due to shared codebase. OnePlus acknowledged the flaws in May 2026 but threatened legal action against disclosure and has not released patches as of the researcher's September publication. This incident highlights the growing trend of privilege escalation vulnerabilities in Android OEM customizations, following similar discoveries across Samsung, Xiaomi, and other manufacturers in 2026, demonstrating systemic security gaps in vendor-modified Android implementations.

22 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Ghost Service Accounts: The Hidden Threat in Your M365 Environment
Impact· HIGH

Ghost Service Accounts: The Hidden Threat in Your M365 Environment

In July 2026, threat actor UNK_CondorFiltration successfully compromised a major Chilean retailer's Microsoft 365 environment using the open-source TeamFiltration toolkit. After failing to breach employee accounts at multiple Chilean financial institutions, the attacker pivoted to exploit forgotten service accounts with default credentials and no multi-factor authentication. Within seven minutes, six of seven targeted service accounts were compromised, enabling the exfiltration of emails, chat conversations, and files from Outlook, Teams, and OneDrive. The attacker also probed the company's VPN and accessed both M365 and Azure management portals. This incident highlights the growing threat of identity-based attacks targeting non-human accounts in cloud environments. As organizations strengthen human account security, attackers increasingly focus on overlooked service accounts that lack proper lifecycle management, creating critical security gaps in zero trust implementations.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
How Attackers Exploit URL Parser Differences in Advanced Phishing Campaigns
Impact· LOW

How Attackers Exploit URL Parser Differences in Advanced Phishing Campaigns

Security researchers at SANS Internet Storm Center documented a sophisticated phishing campaign exploiting URL parser differences to evade detection systems. The attack utilized three distinct techniques: RFC 3986 userinfo fields with tracking tokens, malformed hostnames with hyphens that bypass strict validators, and victim email addresses in URL paths that confuse parsing logic. These methods created URLs that appeared as legitimate email addresses or trusted domains to security filters while directing browsers to attacker-controlled phishing sites. The campaign demonstrated how attackers exploit discrepancies between different URL parsing implementations rather than traditional vulnerabilities. This incident highlights the growing sophistication of phishing campaigns that exploit fundamental protocol ambiguities and parser inconsistencies. As organizations implement zero-trust architectures and advanced email security, attackers are adapting with techniques that manipulate how different systems interpret the same URL string.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
RemControl Android Banking Malware: New MaaS Platform Targets Europe and Canada
Impact· HIGH

RemControl Android Banking Malware: New MaaS Platform Targets Europe and Canada

In September 2026, cybersecurity researchers discovered RemControl, a new Android malware-as-a-service (MaaS) platform targeting banking users across Europe and Canada through sophisticated phishing campaigns. The malware impersonates the popular TVTap IPTV application via fake Google Play pages and malvertising campaigns, deploying over 30 banking overlays to steal credentials from financial institutions across Italy, France, Spain, Poland, Portugal, and Canada. RemControl employs advanced evasion techniques including VPN services to block Google Play Protect scans, accessibility service abuse for remote device control, and dynamic C2 infrastructure rotation via Telegram channels. This incident highlights the continued evolution of mobile banking trojans, particularly the integration of AI-assisted development and sophisticated anti-detection mechanisms. The malware's ability to dynamically receive new targets and perform real-time device manipulation represents a significant escalation in mobile banking threats, coinciding with increased regulatory focus on mobile security frameworks.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
ClickFix Attack Analysis: When Your Logo Becomes the Weapon
Impact· MEDIUM

ClickFix Attack Analysis: When Your Logo Becomes the Weapon

ClickFix represents a sophisticated social engineering technique that leverages trusted brand logos and familiar verification prompts to deceive victims into executing malicious commands on their own systems. Unlike traditional malware campaigns, ClickFix attacks require no code injection or exploit delivery - instead, they manipulate users into becoming the attack vector themselves by mimicking legitimate CAPTCHA screens, brand verification pages, and system prompts. These campaigns adapt dynamically to victim operating systems, delivering tailored instructions for Windows or macOS environments, making detection through traditional signature-based methods ineffective. This attack method exemplifies the current shift toward human-centric attack vectors that bypass traditional security controls by exploiting psychological manipulation rather than technical vulnerabilities. As organizations increasingly deploy sophisticated endpoint protection and network security tools, threat actors are pivoting to techniques that leverage the weakest link in most security architectures - human trust and recognition patterns.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports