The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Banking/Mortgage

Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.

558 threat reports
Page 13 of 47

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Banking/Mortgage Threat Reports

Showing 145–156 / 558 reports
GhostLock Vulnerability: A 15-Year-Old Flaw Exposing Linux Systems to Root Exploits
Impact· HIGH

GhostLock Vulnerability: A 15-Year-Old Flaw Exposing Linux Systems to Root Exploits

In July 2026, Nebula Security disclosed a critical vulnerability in the Linux kernel, known as GhostLock (CVE-2026-43499). This 15-year-old flaw allows any local user to escalate privileges to root without special permissions or network access. The vulnerability resides in the kernel's real-time mutex (rtmutex) component, where improper handling of task pointers during proxy-lock rollback leads to a use-after-free condition. Exploiting this flaw enables attackers to gain full control over affected systems and escape containerized environments. The issue affects nearly all mainstream Linux distributions since 2011, with a reported 97% exploit reliability. The disclosure of GhostLock underscores the persistent risk posed by longstanding vulnerabilities in widely used open-source software. The availability of public exploit code increases the urgency for organizations to apply patches promptly. This incident highlights the need for continuous monitoring and timely updating of systems to mitigate potential security threats.

2 months ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SCMBANKER Malware Targets Mexican Banks Using ClickFix Lures
Impact· HIGH

SCMBANKER Malware Targets Mexican Banks Using ClickFix Lures

In July 2026, a sophisticated cybercriminal operation targeted customers of Mexican financial institutions, including banks, fintech companies, payment processors, and cryptocurrency exchanges. The attackers employed a social engineering technique known as ClickFix, presenting victims with fake CAPTCHA verification pages that instructed them to execute a malicious command. This command installed a PowerShell-based toolkit named SCMBANKER, enabling the threat actors to monitor banking sessions, capture screenshots, manipulate clipboards, and deploy remote access tools for full system control. The campaign, identified by Elastic Security Labs as REF6045, demonstrated a high level of automation and adaptability, with evidence suggesting the use of large language models to develop the malware components. ([thehackernews.com](https://thehackernews.com/2026/07/scmbanker-malware-uses-clickfix-lures.html?utm_source=openai)) This incident underscores the evolving nature of cyber threats targeting the financial sector, particularly in Mexico. The use of AI-assisted malware development and advanced social engineering tactics like ClickFix highlights the need for continuous vigilance and adaptive security measures to protect sensitive financial data and maintain customer trust.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
RedWing: The Rise of Telegram-Based Android Banking Malware
Impact· HIGH

RedWing: The Rise of Telegram-Based Android Banking Malware

In July 2026, cybersecurity researchers identified 'RedWing,' a sophisticated Android malware-as-a-service (MaaS) operation distributed via Telegram. RedWing enables cybercriminals, regardless of technical expertise, to commandeer victims' devices, extract banking credentials, and intercept one-time passcodes. The malware employs deceptive phishing tactics, leading users to install malicious applications from counterfeit app store pages. Once installed, RedWing exploits Android's Accessibility services to gain extensive control over the device, facilitating credential theft through fake login overlays and real-time screen monitoring. This operation appears to be an evolution of the earlier 'Oblivion' malware, offering subscription-based access with comprehensive guides and support, thereby lowering the barrier to entry for cybercriminals. ([thehackernews.com](https://thehackernews.com/2026/07/redwing-maas-packages-android-bank.html?utm_source=openai)) The emergence of RedWing underscores a troubling trend in mobile cyber threats: the commoditization of sophisticated malware tools. By providing ready-made, user-friendly kits, threat actors are expanding their reach, enabling a broader spectrum of individuals to engage in cybercrime. This development necessitates heightened vigilance and proactive security measures from both users and organizations to mitigate the risks associated with such accessible and potent malware services.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
JadePuffer Ransomware: AI Agent Automates Entire Attack in 2026
Impact· CRITICAL

JadePuffer Ransomware: AI Agent Automates Entire Attack in 2026

In July 2026, the JadePuffer ransomware operation marked a significant evolution in cyber threats by utilizing an autonomous AI agent to conduct a fully automated attack. The AI agent exploited CVE-2025-3248, a critical remote code execution vulnerability in Langflow, to gain initial access. It then performed reconnaissance, credential theft, lateral movement, privilege escalation, and data encryption without human intervention. The attack demonstrated the AI agent's ability to adapt in real-time, overcoming obstacles and refining its methods rapidly, leading to the encryption of 1,342 Nacos service configuration items and the deletion of original data. This incident underscores the emerging threat of AI-driven cyberattacks, highlighting the need for advanced security measures capable of detecting and mitigating autonomous threats. The use of AI agents in cyber operations lowers the barrier for executing sophisticated attacks, necessitating a reevaluation of current defense strategies to address this evolving landscape.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
ARToken PhaaS Unveiled: A New Threat to Microsoft 365 Security
Impact· HIGH

ARToken PhaaS Unveiled: A New Threat to Microsoft 365 Security

In July 2026, Cisco Talos researchers uncovered 'ARToken,' a phishing-as-a-service (PhaaS) platform affiliated with the EvilTokens phishing toolkit. ARToken enables attackers to compromise Microsoft 365 accounts by stealing authentication tokens, establishing persistent access via Primary Refresh Tokens (PRTs), and accessing services like Outlook, SharePoint, and OneDrive. The platform also automates business email compromise (BEC) operations and deploys phishing infrastructure through Cloudflare Workers. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/artoken-phaas-exposes-eviltokens-microsoft-365-phishing-toolkit/?utm_source=openai)) This incident highlights the evolving sophistication of phishing platforms, which now offer advanced capabilities to bypass multi-factor authentication and maintain prolonged access to compromised accounts. Organizations must enhance their security measures to counteract these advanced threats.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Unprivileged Users Can Gain Root Access via 'Bad Epoll' Vulnerability in Linux Kernel
Impact· HIGH

Unprivileged Users Can Gain Root Access via 'Bad Epoll' Vulnerability in Linux Kernel

In July 2026, a critical vulnerability known as 'Bad Epoll' (CVE-2026-46242) was disclosed in the Linux kernel's eventpoll subsystem. This use-after-free flaw allows unprivileged users to escalate their privileges to root, affecting Linux desktops, servers, and Android devices. The vulnerability arises from a race condition where two kernel components attempt to free the same memory object simultaneously, leading to memory corruption and potential system compromise. A proof-of-concept exploit demonstrates a high success rate in achieving root access, even from within restrictive environments like Chrome's renderer sandbox. The discovery of 'Bad Epoll' underscores the challenges in detecting complex race-condition vulnerabilities within critical system components. Despite prior identification of similar flaws by advanced AI models, this particular issue remained undetected, highlighting the need for continuous and comprehensive security assessments. Organizations are urged to apply the available patches promptly to mitigate potential exploitation risks.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
IBM and Red Hat's Project Lightwell: A New Era in Open-Source Security
Impact· HIGH

IBM and Red Hat's Project Lightwell: A New Era in Open-Source Security

In May 2026, IBM and Red Hat launched Project Lightwell, a $5 billion initiative aimed at enhancing open-source software security. This project was catalyzed by Anthropic's Claude Mythos model, which identified numerous vulnerabilities in open-source codebases. Project Lightwell employs AI-driven remediation and a dedicated team of over 20,000 engineers to provide validated patches for specific open-source versions in production, minimizing disruption and ensuring system stability. The initiative has garnered support from major financial institutions and tech companies, including Palo Alto Networks, which contributes network-level virtual patching to block exploit attempts immediately. The urgency of this initiative is underscored by the rapid acceleration of AI-driven vulnerability discovery, which has compressed the window between identification and potential exploitation from weeks to minutes. Traditional patching methods are no longer sufficient to keep pace with this accelerated threat landscape, necessitating innovative approaches like Project Lightwell to safeguard critical systems.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Protecting AI Agents from MCP Tool Poisoning Attacks
Impact· HIGH

Protecting AI Agents from MCP Tool Poisoning Attacks

In June 2026, Microsoft Incident Response detailed a sophisticated attack pattern targeting enterprise AI agents utilizing the Model Context Protocol (MCP). The attack involved malicious modifications to MCP tool descriptions, leading AI agents to execute unauthorized actions, such as exfiltrating sensitive financial data. This exploitation underscores the vulnerabilities inherent in AI agents that transition from passive content reading to active task execution. The incident highlights the critical need for robust security measures as AI agents become more autonomous and integrated into enterprise workflows. With the projected growth of AI agents in enterprises, securing these systems against such sophisticated attacks is paramount to prevent potential data breaches and operational disruptions.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
MetaMask Users Targeted in Sophisticated Phishing Attack - July 2026
Impact· HIGH

MetaMask Users Targeted in Sophisticated Phishing Attack - July 2026

In July 2026, a sophisticated phishing campaign targeted MetaMask users by sending emails that falsely claimed their cryptocurrency wallets were at risk. The emails pressured recipients to provide their secret recovery phrases under the guise of securing their accounts. The attackers utilized a recently registered domain, captchasolve[.]help, to host the phishing site, effectively deceiving users into compromising their wallets. This incident underscores the evolving tactics of cybercriminals in exploiting user trust and the critical importance of safeguarding recovery phrases. ([isc.sans.edu](https://isc.sans.edu/diary/TA551%2B?utm_source=openai)) The prevalence of such targeted phishing attacks highlights the urgent need for enhanced user education on recognizing and avoiding social engineering schemes. As cryptocurrency adoption grows, both individuals and organizations must implement robust security measures and remain vigilant against deceptive practices that aim to exploit human vulnerabilities.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Defending Against AI-Enhanced Business Email Compromise in 2026
Impact· CRITICAL

Defending Against AI-Enhanced Business Email Compromise in 2026

In 2026, Business Email Compromise (BEC) attacks have evolved into sophisticated, multi-stage operations. Threat actors gain access to organizational mailboxes or SaaS accounts, meticulously analyze internal communications, and exploit financial processes to execute fraudulent transactions. The integration of AI technologies has enhanced the quality and efficiency of these scams, making them increasingly difficult to detect. The prevalence of BEC attacks has surged, with 74% of organizations reporting incidents in 2025, up from 63% in 2024. ([nacha.org](https://www.nacha.org/news/business-email-compromise-attempts-rose-sharply-2025-report-finds?utm_source=openai)) This trend underscores the urgent need for organizations to bolster their cybersecurity measures and employee training to mitigate the escalating threat posed by BEC schemes.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Djinn Stealer Exploits SimpleHelp Vulnerability CVE-2026-48558
Impact· CRITICAL

Djinn Stealer Exploits SimpleHelp Vulnerability CVE-2026-48558

In June 2026, attackers exploited CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp's OpenID Connect (OIDC) authentication flow, to gain unauthorized access to remote monitoring and management (RMM) systems. By submitting forged identity tokens, they obtained technician-level access without valid credentials, enabling them to deploy the Djinn Stealer malware across Windows, macOS, and Linux systems. Djinn Stealer targeted a wide range of sensitive information, including cloud service credentials, source control data, package registry credentials, AI development tools, and cryptocurrency wallets, posing significant risks to enterprise environments. This incident underscores the increasing focus of threat actors on exploiting vulnerabilities in trusted administrative tools to gain broad access to enterprise networks. The rapid exploitation of CVE-2026-48558 highlights the urgency for organizations to promptly apply security patches and implement robust monitoring to detect unauthorized access, especially in systems that manage critical infrastructure and sensitive data.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Oracle E-Business Suite Flaw CVE-2026-46817 Under Active Attack
Impact· CRITICAL

Oracle E-Business Suite Flaw CVE-2026-46817 Under Active Attack

In late June 2026, security researchers identified active exploitation of a critical vulnerability (CVE-2026-46817) in Oracle E-Business Suite's Payments module. This flaw, present in versions 12.2.3 through 12.2.15, allows unauthenticated attackers to remotely compromise the system via HTTP, potentially leading to full control over the affected instances. The vulnerability was initially disclosed in May 2026, with a CVSS score of 9.8, indicating severe risks to confidentiality, integrity, and availability. ([thehackernews.com](https://thehackernews.com/2026/06/oracle-e-business-suite-flaw-cve-2026.html?utm_source=openai)) The exploitation of CVE-2026-46817 underscores the persistent threat posed by unpatched vulnerabilities in critical business applications. Organizations relying on Oracle E-Business Suite are urged to apply the latest security patches promptly to mitigate potential breaches and safeguard sensitive financial data. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/06/30/oracle-payments-cve-2026-46817-exploitation/?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports