The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
Critical WSO2 and Adobe Commerce Vulnerabilities Under Active Attack Added to CISA KEV
CISA added two critical vulnerabilities to its Known Exploited Vulnerabilities catalog in September 2026: CVE-2026-5430 affecting WSO2 products and CVE-2026-71362 impacting Adobe Commerce and Magento. CVE-2026-5430 is a path traversal flaw allowing unrestricted file upload and remote code execution, while CVE-2026-71362 enables unauthorized account access through session switching. Security researchers observed active exploitation attempts against honeypots starting September 13, 2026, with attackers using forged JWT tokens and targeting customer account takeovers. Federal agencies must patch by September 27, 2026. These incidents highlight the accelerating timeline between vulnerability disclosure and active exploitation, with attackers moving within days rather than weeks to weaponize critical flaws against high-value enterprise platforms.
5 hours ago
Kill Chain
North Korean Hackers Steal $351.6M from Bitget in Sophisticated Backend Compromise
On September 24, 2026, cryptocurrency exchange Bitget suffered a massive security breach resulting in the theft of $351.6 million from hot and warm wallets. Suspected North Korean threat actors compromised a critical backend system within Bitget's wallet infrastructure, used it to spoof transaction data, and triggered the authorization process to move funds out. The attack affected multiple cryptocurrency assets including ETH, XRP, BNB, AVAX, USDT, and USDC across seven different blockchain networks. While customer account balances remained accurate and trading continued normally, withdrawals were temporarily suspended as a precautionary measure during the ongoing investigation. This incident highlights the continued escalation of North Korean state-sponsored cryptocurrency theft operations, representing one of the largest single exchange compromises in 2026. The sophisticated backend compromise demonstrates evolving attack techniques that bypass traditional security controls, emphasizing the urgent need for enhanced infrastructure protection and transaction authorization mechanisms in the rapidly growing digital asset sector.
5 hours ago
Kill Chain
PamStealer Malware Evolution: Live C2 Decryption Challenges macOS Security
In September 2026, cybersecurity researchers discovered an evolved version of PamStealer macOS malware that implements sophisticated live command-and-control payload decryption and multi-layer persistence mechanisms. The new variant distributes through a fake cryptocurrency wallet website called "Wavel" and uses server-side X25519 key exchange to prevent static analysis of encrypted payloads. The malware establishes four redundant persistence methods including LaunchAgent installations, repair scripts, and Git hook injections, while stealing credentials from over a dozen browsers, keychain items, and system passwords through fake crash dialogs. This incident highlights the growing sophistication of macOS-targeted information stealers as threat actors invest heavily in anti-analysis techniques and delivery infrastructure, making traditional signature-based detection and static malware analysis significantly more challenging for security teams.
5 hours ago
Kill Chain
Critical TEE-MPC Security Flaws Expose Cryptographic Vulnerabilities in Confidential Computing
Trail of Bits research revealed critical security vulnerabilities when combining Trusted Execution Environments (TEEs) with Multi-Party Computation (MPC) protocols, particularly in threshold signature schemes. The research demonstrates how malicious hosts can exploit rollback attacks against TEE-protected MPC implementations, causing nonce reuse that leads to private key disclosure. The vulnerabilities stem from the fundamental trust model clash between MPC's distributed security approach and TEEs' centralized manufacturer trust, creating new attack surfaces including filesystem rollbacks, incomplete attestation measurements, and side-channel exploits. Organizations deploying TEE-MPC hybrid systems face significant risks from implementation flaws that can compromise cryptographic security guarantees despite appearing to provide defense-in-depth protection. This research gains critical relevance as organizations increasingly adopt zero-trust architectures and confidential computing solutions to protect sensitive workloads. With the rise of AI workloads requiring secure multi-party computation and the growing deployment of TEE-enabled cloud services, understanding these interaction vulnerabilities becomes essential for preventing catastrophic cryptographic failures in production systems.
5 hours ago
Kill Chain
Critical .NET MAUI Vulnerabilities Expose Cross-Platform Mobile Security Risks
Security researchers at Bishop Fox have demonstrated critical vulnerabilities in Microsoft's .NET Multi-platform App UI (MAUI) framework, revealing how cross-platform development creates unified security risks across iOS and Android applications. The analysis shows that MAUI's shared C# codebase architecture allows attackers to reverse-engineer a single assembly and apply findings to both platform versions simultaneously. Using their published mauidlltool, researchers can extract readable assemblies from both Android APKs and iOS IPAs, exposing hardcoded secrets, weak encryption implementations, and authorization flaws that affect millions of users across both app stores. This research highlights the growing security challenges of cross-platform mobile development frameworks as organizations prioritize development efficiency over security isolation. With MAUI applications increasingly deployed in enterprise environments handling sensitive data, the single-point-of-failure risk becomes particularly concerning for compliance and data protection.
5 hours ago
Kill Chain
Multi-Vector Campaign Targets AI Systems and Banking: RemControl Trojan and Search Poisoning Analysis
In September 2026, cybersecurity researchers identified a coordinated multi-vector campaign targeting AI systems, banking applications, and enterprise development environments. The campaign featured the RemControl Android banking trojan targeting Western Europe and Canada through fake Google Play Store pages, a massive AI disinformation attack poisoning ChatGPT and Google AI Overviews with fraudulent information, and supply chain compromises affecting WordPress plugins and AI coding tools. Threat actors leveraged social engineering tactics, exploited trusted platforms, and manipulated AI training data to execute credential theft, financial fraud, and code repository exfiltration across multiple industries. This incident highlights the rapidly evolving threat landscape where attackers are increasingly targeting AI systems and trusted development tools, representing a fundamental shift toward exploiting automation and machine learning platforms that organizations rely on for daily operations.
22 hours ago
Kill Chain
MacSync Malware Evolution: From AppleScript to Advanced Swift/Objective-C Threats
MacSync, a macOS cryptocurrency and information stealer first advertised in 2025, has undergone significant evolution in 2026 with new variants discovered by Kaspersky researchers. The malware family has transitioned from AppleScript-based implementations to sophisticated binary droppers written in Swift and Objective-C, featuring complex multi-stage infection chains that leverage Apple's iCloud infrastructure for payload delivery. The stealer targets developers and cryptocurrency enthusiasts through fake applications like the non-existent Toria crypto wallet, employing social engineering and masquerading as cracked software to gain initial access. This incident demonstrates the rapid evolution of macOS malware families and their increasing sophistication in targeting high-value users in the cryptocurrency and development communities, highlighting the growing threat to supply chain security through compromised developer workstations.
22 hours ago
Kill Chain
Critical OnePlus Privilege Escalation Flaws Leave Millions of Devices Vulnerable to Root Access
In September 2026, security researcher Rasmus Moorats disclosed two unpatched vulnerabilities in OnePlus devices that allow malicious Android applications to gain root access without requesting any permissions. The attack chains two flaws: one in OnePlus's AtlasService debugging component that accepts unchecked calls from any app, and another in the olc2 hardware helper service that executes arbitrary shell commands. The vulnerabilities affect OnePlus 15, OnePlus 12 Pro, and potentially all devices running OxygenOS 16, as well as OPPO devices due to shared codebase. OnePlus acknowledged the flaws in May 2026 but threatened legal action against disclosure and has not released patches as of the researcher's September publication. This incident highlights the growing trend of privilege escalation vulnerabilities in Android OEM customizations, following similar discoveries across Samsung, Xiaomi, and other manufacturers in 2026, demonstrating systemic security gaps in vendor-modified Android implementations.
22 hours ago
Kill Chain
Ghost Service Accounts: The Hidden Threat in Your M365 Environment
In July 2026, threat actor UNK_CondorFiltration successfully compromised a major Chilean retailer's Microsoft 365 environment using the open-source TeamFiltration toolkit. After failing to breach employee accounts at multiple Chilean financial institutions, the attacker pivoted to exploit forgotten service accounts with default credentials and no multi-factor authentication. Within seven minutes, six of seven targeted service accounts were compromised, enabling the exfiltration of emails, chat conversations, and files from Outlook, Teams, and OneDrive. The attacker also probed the company's VPN and accessed both M365 and Azure management portals. This incident highlights the growing threat of identity-based attacks targeting non-human accounts in cloud environments. As organizations strengthen human account security, attackers increasingly focus on overlooked service accounts that lack proper lifecycle management, creating critical security gaps in zero trust implementations.
1 day ago
Kill Chain
How Attackers Exploit URL Parser Differences in Advanced Phishing Campaigns
Security researchers at SANS Internet Storm Center documented a sophisticated phishing campaign exploiting URL parser differences to evade detection systems. The attack utilized three distinct techniques: RFC 3986 userinfo fields with tracking tokens, malformed hostnames with hyphens that bypass strict validators, and victim email addresses in URL paths that confuse parsing logic. These methods created URLs that appeared as legitimate email addresses or trusted domains to security filters while directing browsers to attacker-controlled phishing sites. The campaign demonstrated how attackers exploit discrepancies between different URL parsing implementations rather than traditional vulnerabilities. This incident highlights the growing sophistication of phishing campaigns that exploit fundamental protocol ambiguities and parser inconsistencies. As organizations implement zero-trust architectures and advanced email security, attackers are adapting with techniques that manipulate how different systems interpret the same URL string.
1 day ago
Kill Chain
RemControl Android Banking Malware: New MaaS Platform Targets Europe and Canada
In September 2026, cybersecurity researchers discovered RemControl, a new Android malware-as-a-service (MaaS) platform targeting banking users across Europe and Canada through sophisticated phishing campaigns. The malware impersonates the popular TVTap IPTV application via fake Google Play pages and malvertising campaigns, deploying over 30 banking overlays to steal credentials from financial institutions across Italy, France, Spain, Poland, Portugal, and Canada. RemControl employs advanced evasion techniques including VPN services to block Google Play Protect scans, accessibility service abuse for remote device control, and dynamic C2 infrastructure rotation via Telegram channels. This incident highlights the continued evolution of mobile banking trojans, particularly the integration of AI-assisted development and sophisticated anti-detection mechanisms. The malware's ability to dynamically receive new targets and perform real-time device manipulation represents a significant escalation in mobile banking threats, coinciding with increased regulatory focus on mobile security frameworks.
1 day ago
Kill Chain
ClickFix Attack Analysis: When Your Logo Becomes the Weapon
ClickFix represents a sophisticated social engineering technique that leverages trusted brand logos and familiar verification prompts to deceive victims into executing malicious commands on their own systems. Unlike traditional malware campaigns, ClickFix attacks require no code injection or exploit delivery - instead, they manipulate users into becoming the attack vector themselves by mimicking legitimate CAPTCHA screens, brand verification pages, and system prompts. These campaigns adapt dynamically to victim operating systems, delivering tailored instructions for Windows or macOS environments, making detection through traditional signature-based methods ineffective. This attack method exemplifies the current shift toward human-centric attack vectors that bypass traditional security controls by exploiting psychological manipulation rather than technical vulnerabilities. As organizations increasingly deploy sophisticated endpoint protection and network security tools, threat actors are pivoting to techniques that leverage the weakest link in most security architectures - human trust and recognition patterns.
1 day ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports