The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
Microsoft's KB5099539 Update: A Critical Security Release for Windows 10
On July 14, 2026, Microsoft released the Windows 10 KB5099539 extended security update, addressing 570 vulnerabilities, including two zero-day flaws actively exploited in the wild. This update is part of Microsoft's Extended Security Updates (ESU) program, which was recently extended to provide free security updates until October 12, 2027. The update includes fixes for issues such as OLE Automation compatibility, File Explorer's OneDrive shortcut malfunction, and Recycle Bin confirmation dialog errors. Additionally, it introduces security hardening changes like enforcing TDI transport registration requirements and enhancing Secure Boot certificate management. The release of KB5099539 underscores the critical importance of timely patch management, especially in light of the record-breaking number of vulnerabilities addressed. Organizations must prioritize the deployment of this update to mitigate potential security risks and ensure compliance with industry standards. The extension of the ESU program provides additional time for organizations to transition to newer operating systems while maintaining security posture.
2 months ago
Kill Chain
Spanish Authorities Dismantle €140 Million Cyber Fraud Network
In July 2026, Spanish authorities dismantled a cybercrime and money-laundering network responsible for defrauding €140 million through investment fraud and Business Email Compromise (BEC) schemes. The operation led to the arrest of four individuals across Spain, Portugal, and Panama. The criminals managed over 800 bank accounts, utilizing sophisticated social engineering tactics such as impersonating executives and issuing false invoices to divert funds into accounts they controlled. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/spanish-police-take-down-140-million-cyber-fraud-ring-arrest-four/?utm_source=openai)) This incident underscores the escalating threat of BEC attacks, which exploit organizational trust and email communications to execute financial fraud. The substantial financial impact highlights the necessity for organizations to implement robust email security measures, employee training, and stringent verification processes to mitigate such risks.
2 months ago
Kill Chain
UK Authorities Charge Five in Russian Coms Caller ID Spoofing Case
In July 2026, UK authorities charged five individuals in connection with Russian Coms, a caller ID spoofing platform implicated in over 1.8 million scam calls since its inception in 2020. The platform enabled criminals to impersonate trusted entities, leading to financial losses estimated in the tens of millions and affecting approximately 170,000 victims. The National Crime Agency (NCA) had previously dismantled Russian Coms in March 2024, arresting key figures believed to be its developers and administrators. The recent charges underscore the ongoing efforts to hold accountable those involved in facilitating large-scale fraud operations. This incident highlights the persistent threat posed by sophisticated social engineering tactics and the critical need for robust cybersecurity measures to protect individuals and organizations from such fraudulent schemes.
2 months ago
Kill Chain
CrashStealer: New macOS Malware Impersonates Apple CrashReporter
In early July 2026, security researchers identified 'CrashStealer,' a sophisticated macOS infostealer malware that masquerades as Apple's CrashReporter tool. Delivered through a signed and notarized installer named 'Werkbit Setup,' CrashStealer bypasses macOS's Gatekeeper protections. Once executed, it prompts users with a fake system password request to gain access to the Keychain, subsequently exfiltrating sensitive data including browser credentials, cookies, and cryptocurrency wallet information. The malware employs advanced techniques such as client-side AES-256-GCM encryption for data exfiltration and re-signing its binary to evade detection. This incident underscores a growing trend of macOS-targeted malware leveraging social engineering and legitimate-looking applications to infiltrate systems. Organizations must enhance their security posture by implementing robust endpoint protection, user education on phishing tactics, and continuous monitoring to detect and mitigate such threats.
2 months ago
Kill Chain
GigaWiper: A New Era of Modular Malware Threats
In October 2025, Microsoft identified GigaWiper, a sophisticated Golang-based backdoor that integrates multiple destructive capabilities, including disk wiping, fake ransomware, and system-level sabotage. This modular malware combines elements from various malware families, allowing attackers to execute a range of destructive actions on compromised Windows systems. GigaWiper's design enables threat actors to maintain control over infected systems, conduct surveillance, and deploy destructive payloads on demand, significantly increasing the potential impact of cyberattacks. ([csoonline.com](https://www.csoonline.com/article/4195470/microsoft-uncovers-gigawiper-a-backdoor-designed-for-destruction-on-demand.html?utm_source=openai)) The emergence of GigaWiper highlights a concerning trend towards more versatile and destructive malware, emphasizing the need for organizations to enhance their cybersecurity measures. The ability of such malware to perform both espionage and destruction underscores the importance of robust detection and response strategies to mitigate potential threats.
2 months ago
Kill Chain
ScamBuster: Revolutionizing Phishing Defense with AI
In July 2026, cybersecurity researcher Laurent Giovannoni introduced ScamBuster, an AI-driven system designed to counteract phishing attacks by engaging scammers with human-like personas. By simulating potential victims, ScamBuster collects critical data on cybercriminal operations, including financial details and infrastructure insights, which can be utilized by organizations and law enforcement to disrupt fraudulent activities. This proactive approach not only wastes scammers' time but also provides valuable intelligence to prevent future attacks. The emergence of ScamBuster highlights a significant shift towards offensive cybersecurity measures, leveraging artificial intelligence to turn the tables on cybercriminals. As phishing tactics become increasingly sophisticated, tools like ScamBuster offer a novel method to gather actionable intelligence, emphasizing the importance of adaptive and proactive defense strategies in the evolving threat landscape.
2 months ago
Kill Chain
RedHook Android Malware Exploits Wireless ADB for Unauthorized Access
In July 2026, cybersecurity researchers identified a new variant of the RedHook Android malware that exploits the Wireless Android Debug Bridge (ADB) feature to gain shell-level access without a computer connection. By deceiving users into granting Accessibility permissions, RedHook enables Developer Options and activates Wireless Debugging, allowing it to connect to the device's ADB service via the loopback interface. This grants the malware elevated privileges, enabling it to stream screens, intercept keystrokes, automate UI interactions, and steal credentials. The attack does not require device rooting, making it effective across all Android devices where users approve the Accessibility Service request. This incident underscores the evolving sophistication of mobile malware, highlighting the need for heightened vigilance among Android users. The exploitation of legitimate features like Wireless ADB for malicious purposes reflects a broader trend of attackers leveraging built-in functionalities to bypass security measures, emphasizing the importance of cautious permission granting and regular security updates.
2 months ago
Kill Chain
jscrambler npm Package Compromise: A Wake-Up Call for Developer Security
On July 11, 2026, the jscrambler npm package version 8.14.0 was compromised, introducing a preinstall hook that deployed a Rust-based infostealer upon installation. This malicious code targeted developer environments across Windows, macOS, and Linux platforms, exfiltrating sensitive data such as cloud credentials, cryptocurrency wallets, password manager vaults, and session tokens for various applications. The attack was identified within minutes of the release, but the exact number of affected systems remains undetermined. This incident underscores the escalating threat of supply chain attacks within the software development ecosystem. The rapid detection highlights the importance of vigilant monitoring and swift response mechanisms. Organizations must prioritize securing their development pipelines and implement robust verification processes to mitigate the risks associated with third-party dependencies.
2 months ago
Kill Chain
Injective Labs GitHub Compromise Exposes Supply Chain Vulnerabilities
In July 2026, threat actors compromised the GitHub repository of Injective Labs' SDK project, leading to the publication of a malicious npm package, @injectivelabs/sdk-ts@1.20.21. This package contained code designed to exfiltrate cryptocurrency wallet private keys and mnemonic seed phrases by embedding fake telemetry functionality. The malicious version was released on July 8, 2026, and remained available for download until its deprecation. The attackers utilized a developer's GitHub account with a history of contributions to introduce the malicious code, which was then propagated across 17 additional @injectivelabs scoped packages, affecting numerous downstream users. This incident underscores the escalating threat of supply chain attacks targeting open-source repositories. The sophisticated nature of the attack, involving legitimate contributor accounts and widespread package dependencies, highlights the urgent need for enhanced security measures in software development pipelines to prevent similar breaches.
2 months ago
Kill Chain
Critical ATM Software Vulnerabilities Uncovered
In July 2026, security researcher Matt Burch identified nine vulnerabilities in CryptWare's CryptoPro Secure Disk, a full-disk encryption and pre-boot authentication solution for Windows. These flaws could potentially allow attackers with physical access to ATMs to execute arbitrary code, bypass encryption, and steal cash. The vulnerabilities include integrity validation bypasses and improper storage of key materials, raising significant security concerns for organizations utilizing this software. This discovery underscores the critical need for robust physical and software security measures in ATMs, especially as 'jackpotting' attacks have been on the rise, with over 700 incidents reported in 2025, resulting in more than $20 million stolen. ([techcrunch.com](https://techcrunch.com/2026/02/19/fbi-says-atm-jackpotting-attacks-are-on-the-rise-and-netting-hackers-millions-in-stolen-cash/?utm_source=openai))
2 months ago
Kill Chain
Navigating the Security Landscape of AI Coding Tools
In July 2026, a comprehensive analysis revealed that while AI coding tools have significantly enhanced developer productivity, they also introduce substantial security vulnerabilities. Studies indicated that a significant portion of AI-generated code contained critical flaws, including injection vulnerabilities and hardcoded secrets. Additionally, incidents such as the 'GhostApproval' vulnerability in major AI coding assistants highlighted the potential for remote code execution and data exfiltration. These findings underscore the necessity for organizations to balance the productivity benefits of AI coding tools with rigorous security assessments and mitigation strategies. The current relevance of this issue is underscored by the rapid adoption of AI coding tools across industries, coupled with an increasing number of documented security incidents. As organizations integrate these tools into their development workflows, the potential for widespread security breaches grows, emphasizing the urgent need for enhanced security protocols and continuous monitoring.
2 months ago
Kill Chain
INTERPOL's Operation First Light 2026: A Major Blow to Global Fraud Networks
Between January 15 and April 30, 2026, INTERPOL coordinated 'Operation First Light 2026,' a global initiative targeting social engineering fraud and money laundering across 97 countries. The operation resulted in the arrest of 5,811 suspects, the seizure of $293 million in illicit assets, and the identification of over 142,000 victims. Authorities also blocked 31,014 bank accounts and analyzed 152,808 cases, highlighting the extensive reach of these fraudulent activities. This operation underscores the escalating threat of transnational social engineering scams, which have become increasingly sophisticated and widespread. The significant number of victims and the substantial financial impact emphasize the urgent need for enhanced international cooperation and proactive measures to combat such fraud.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports