✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
Anthropic's Claude Mythos AI: A Game-Changer in Cybersecurity
In March 2026, Anthropic's AI model, Claude Mythos, identified thousands of zero-day vulnerabilities across major operating systems and web browsers. This unprecedented discovery included a 27-year-old bug in OpenBSD and a critical flaw in FFmpeg. Due to the model's potential for misuse, Anthropic restricted access to select organizations under Project Glasswing to facilitate responsible vulnerability remediation. ([techcrunch.com](https://techcrunch.com/2026/04/07/anthropic-mythos-ai-model-preview-security/?utm_source=openai)) The incident underscores the dual-use nature of advanced AI in cybersecurity, highlighting the need for stringent access controls and collaborative efforts to mitigate risks associated with powerful AI tools.
3 months ago
Kill Chain
Navigating Financial Cyberthreats: Insights from 2025 and Projections for 2026
In 2025, the financial sector faced a rapidly evolving cyber landscape characterized by the proliferation of infostealers, AI-assisted attacks, and supply chain compromises. Notably, there was a significant increase in mobile financial threats, with a 102% rise in users affected globally compared to 2023. Additionally, 12.8% of B2B finance sector companies encountered ransomware attacks, marking a 35.7% increase from the previous year. These developments underscore the growing sophistication and diversification of cyber threats targeting financial institutions. ([me-en.kaspersky.com](https://me-en.kaspersky.com/about/press-releases/financial-sector-faced-ai-blockchain-and-organized-crime-threats-in-2025-kaspersky-reports?utm_source=openai)) Looking ahead to 2026, the financial sector is expected to confront even more complex challenges, including the emergence of quantum-proof ransomware and the continued advancement of mobile financial cyberthreats. Organizations must proactively adapt their cybersecurity strategies to address these evolving threats, emphasizing the importance of real-time monitoring, cross-channel threat intelligence, and robust identity protection measures. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/kaspersky-predicts-quantum-proof-ransomware-and-advancements-in-mobile-financial-cyberthreats-in-2025?utm_source=openai))
3 months ago
Kill Chain
Latin American Banks Confront 155% Surge in Social Engineering Scams in 2025
In 2025, Latin American financial institutions experienced a 155% increase in social engineering scams, with fraud attempts utilizing remote-access tools surging fivefold and malware attacks rising by 225%. This escalation underscores a shift in fraudsters' tactics, moving from basic phishing to sophisticated methods that exploit human behavior and technological vulnerabilities. The surge in fraud cases highlights the urgent need for enhanced security measures and collaborative efforts among financial institutions to combat evolving threats.
3 months ago
Kill Chain
Snowflake Data Breach 2026: Lessons in Third-Party Integration Security
In April 2026, over a dozen companies experienced data theft attacks following a breach at a SaaS integration provider, leading to the theft of authentication tokens. The majority of these attacks targeted Snowflake, a cloud-based data platform. Snowflake detected unusual activity in a small number of customer accounts linked to a specific third-party integration and promptly initiated an investigation, securing the affected accounts and notifying impacted customers. The attacks did not involve any vulnerability or compromise of Snowflake's systems. The ShinyHunters extortion group claimed responsibility for the attacks, stating they had stolen data from dozens of companies and were demanding ransom payments to prevent the release of the stolen data. The group also attempted to steal data from Salesforce but were thwarted by AI detection mechanisms. This incident underscores the critical importance of securing third-party integrations and the growing threat posed by sophisticated cybercriminal groups like ShinyHunters.
3 months ago
Kill Chain
Phishing Campaigns Exploit Open Redirects in 2026
In early 2026, multiple phishing campaigns exploited open redirect vulnerabilities in trusted domains to deceive users into visiting malicious websites. Attackers crafted URLs that appeared legitimate by leveraging open redirects in services like Google Meet and Microsoft OAuth, effectively bypassing traditional email and browser security measures. This technique led to increased instances of credential theft and malware distribution, particularly targeting government and public-sector organizations. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/?utm_source=openai)) The prevalence of these attacks underscores the critical need for organizations to identify and remediate open redirect vulnerabilities within their web applications. As threat actors continue to refine their methods, maintaining robust security protocols and user awareness is essential to mitigate the risks associated with such sophisticated phishing tactics.
3 months ago
Kill Chain
New SparkCat Variant Targets iOS and Android Users, Stealing Crypto Wallet Recovery Phrases
In April 2026, cybersecurity researchers identified a new variant of the SparkCat malware infiltrating both the Apple App Store and Google Play Store. This sophisticated malware masquerades as legitimate applications, such as enterprise messengers and food delivery services, to gain access to users' photo galleries. Once installed, it employs optical character recognition (OCR) technology to scan images for cryptocurrency wallet recovery phrases, subsequently exfiltrating this sensitive information to attacker-controlled servers. The malware's advanced obfuscation techniques and cross-platform capabilities underscore the evolving threat landscape targeting mobile users. The resurgence of SparkCat highlights a concerning trend in mobile malware development, emphasizing the need for heightened vigilance among users and app store operators. The ability of such malware to bypass official app store security measures and target sensitive financial information calls for enhanced detection mechanisms and user education to mitigate potential risks.
3 months ago
Kill Chain
Drift Protocol's $280 Million Admin Takeover Exploit in 2026
In April 2026, Drift Protocol, a Solana-based decentralized finance (DeFi) platform, suffered a significant security breach resulting in the loss of approximately $280 million. The attacker employed a sophisticated strategy involving durable nonce accounts and pre-signed transactions to gain unauthorized administrative control over Drift's Security Council. This method allowed the execution of malicious transactions at a predetermined time, leading to the rapid transfer of administrative powers and subsequent draining of funds. Notably, the breach did not exploit any vulnerabilities in Drift's smart contracts or programs, and there was no compromise of seed phrases. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/drift-loses-280-million-as-hackers-seize-security-council-powers/?utm_source=openai)) This incident underscores the evolving nature of cyber threats targeting DeFi platforms, highlighting the need for enhanced security measures beyond traditional smart contract audits. The use of advanced techniques such as durable nonces and social engineering to manipulate governance structures presents a new challenge for the industry, emphasizing the importance of robust administrative controls and vigilant monitoring to prevent similar exploits.
3 months ago
Kill Chain
Casbaneiro Banking Trojan's 2026 Campaign: A Wake-Up Call for Financial Cybersecurity
In early 2026, the Brazilian cybercrime group known as Augmented Marauder launched a sophisticated phishing campaign targeting Spanish-speaking users across Latin America and Europe. Utilizing the Horabot malware, they distributed the Casbaneiro banking trojan through deceptive emails containing password-protected PDFs. Once executed, Casbaneiro monitored victims' online banking activities, capturing credentials and facilitating unauthorized financial transactions. The campaign's worm-like propagation via compromised email accounts significantly amplified its reach and impact. This incident underscores the evolving tactics of cybercriminals in deploying banking trojans, highlighting the need for enhanced email security measures and user awareness. The use of dynamic PDF lures and self-propagating malware reflects a broader trend of increasingly sophisticated phishing techniques aimed at financial institutions and their customers.
3 months ago
Kill Chain
Google Chrome's Dawn WebGPU Zero-Day Vulnerability in 2026
In March 2026, Google identified and patched a critical zero-day vulnerability (CVE-2026-5281) in its Chrome browser, marking the fourth such exploit addressed that year. This flaw resided in Dawn, Chrome's implementation of the WebGPU standard, and was actively exploited in the wild. Attackers leveraged this use-after-free vulnerability to cause browser crashes, data corruption, and potentially execute arbitrary code by enticing users to visit maliciously crafted web content. Google promptly released emergency updates for Windows, macOS, and Linux platforms to mitigate the risk. The recurrence of multiple zero-day vulnerabilities within a short timeframe underscores the persistent targeting of widely-used browsers by threat actors. Organizations and individual users are urged to maintain vigilance by promptly applying security updates and adopting robust cybersecurity practices to mitigate the risks associated with such exploits.
3 months ago
Kill Chain
NoVoice Malware: A Wake-Up Call for Android Security
In early 2026, a sophisticated Android malware campaign named 'NoVoice' infiltrated over 50 applications on Google Play, amassing at least 2.3 million downloads. Disguised as legitimate utilities like cleaners, games, and image galleries, these apps functioned as advertised, concealing their malicious intent. Upon installation, the malware exploited known Android vulnerabilities to gain root access, enabling it to inject code into other applications and exfiltrate sensitive data, notably targeting WhatsApp sessions. The malware's persistence mechanisms allowed it to survive standard factory resets, posing a significant threat to user privacy and device integrity. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/novoice-android-malware-on-google-play-infected-23-million-devices/?utm_source=openai)) This incident underscores the evolving sophistication of mobile malware and the critical importance of maintaining up-to-date device security. It highlights the necessity for users to exercise caution when downloading apps, even from trusted sources like Google Play, and for developers to adhere to stringent security practices to prevent such infiltrations.
3 months ago
Kill Chain
Casbaneiro Phishing Campaign Targets Latin America and Europe
In March 2026, a sophisticated phishing campaign orchestrated by the Brazilian cybercrime group Augmented Marauder targeted Spanish-speaking users across Latin America and Europe. The attackers distributed emails with court summons-themed messages containing password-protected PDF attachments. These PDFs directed recipients to malicious links, initiating a multi-stage infection chain that deployed the Horabot malware, which subsequently delivered the Casbaneiro banking trojan. This campaign leveraged dynamic PDF generation and exploited both email and WhatsApp platforms to propagate the malware, resulting in significant financial and data losses for affected organizations. This incident underscores the evolving tactics of cybercriminals who are increasingly using multi-pronged attack vectors and dynamic content to bypass traditional security measures. The use of legitimate communication channels like WhatsApp for malware distribution highlights the need for organizations to implement comprehensive security strategies that address both email and messaging platforms.
3 months ago
Kill Chain
Chrome 2026 Dawn Use-After-Free Vulnerability
In April 2026, Google identified and patched a high-severity zero-day vulnerability, CVE-2026-5281, in its Chrome browser. This use-after-free flaw in Dawn, Chrome's implementation of the WebGPU standard, allowed remote attackers to execute arbitrary code via crafted HTML pages. The vulnerability was actively exploited in the wild, prompting Google to release an emergency update to versions 146.0.7680.177/178 for Windows and macOS, and 146.0.7680.177 for Linux. ([thehackernews.com](https://thehackernews.com/2026/04/new-chrome-zero-day-cve-2026-5281-under.html?utm_source=openai)) This incident underscores the increasing frequency of zero-day vulnerabilities targeting widely used software. It highlights the critical need for organizations to maintain up-to-date systems and implement robust security measures to mitigate the risks associated with such exploits.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports