The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
Typosquatting Supply Chain Attack 2026: A New Era of Cyber Threats
In December 2025, attackers exploited typosquatting techniques to embed AI-generated lookalike domains within legitimate third-party scripts running on web properties. This method allowed malicious code to execute in users' browsers without requiring mistyped URLs or server breaches, leading to significant data exfiltration and financial losses. The Trust Wallet incident exemplifies this trend, where a trojanized Chrome extension resulted in the theft of $8.5 million from 2,500 wallets within 48 hours. This incident underscores a critical shift in cyber threats, highlighting the vulnerability of supply chains to typosquatting attacks. The rapid generation of convincing domain variants by AI tools has outpaced traditional security measures, necessitating enhanced detection capabilities and vigilance in monitoring third-party scripts.
4 months ago
Kill Chain
Mini Shai-Hulud 2026: Unveiling TeamPCP's npm Supply Chain Attack
In May 2026, the self-replicating malware campaign known as Mini Shai-Hulud resurfaced, compromising hundreds of npm packages. The threat actor, TeamPCP, utilized this campaign to autonomously spread malware, install persistent OS-level backdoors, and harvest sensitive credentials such as GitHub tokens, npm tokens, SSH keys, and cloud provider credentials. The malware executed upon package installation, affecting both local development environments and CI/CD pipelines, and propagated by republishing infected packages under legitimate maintainers' names. ([cyberscoop.com](https://cyberscoop.com/mini-shai-hulud-malware-npm-packages-compromised-again/?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting open-source ecosystems. The ability of such malware to persist beyond standard remediation efforts, like package removal, highlights the need for comprehensive security measures, including thorough auditing of developer tools and CI/CD environments, to prevent unauthorized access and data exfiltration.
4 months ago
Kill Chain
AI-Driven Vulnerability Discovery: Transforming Cybersecurity in 2026
In April 2026, Anthropic's AI model, Mythos, identified thousands of previously unknown vulnerabilities across major operating systems and web browsers, including a 27-year-old flaw in OpenBSD. This unprecedented discovery underscores the transformative impact of AI in cybersecurity, enabling rapid identification of critical vulnerabilities that had remained undetected for decades. ([ibm.com](https://www.ibm.com/think/insights/the-mythos-moment-when-discovery-outpaces-defense?utm_source=openai)) The rapid pace of AI-driven vulnerability discovery has compressed the timeline between identification and potential exploitation, necessitating immediate and robust defensive measures. Organizations must adapt to this accelerated threat landscape by integrating AI-powered tools into their security protocols to effectively manage and mitigate emerging risks. ([sans.org](https://www.sans.org/press/announcements/emergency-strategy-briefing-ai-driven-vulnerability-discovery-compresses-exploit-timelines?utm_source=openai))
4 months ago
Kill Chain
INTERPOL's Operation Ramz: A Landmark Cybercrime Crackdown in the MENA Region
Between October 2025 and February 2026, INTERPOL coordinated Operation Ramz, a large-scale cybercrime crackdown across 13 Middle East and North African countries. This operation led to 201 arrests, the identification of 382 additional suspects, and the seizure of 53 servers. Authorities disrupted various cybercrime activities, including phishing services, malware distribution, and financial scams, affecting nearly 4,000 victims. Notably, in Jordan, police uncovered a human trafficking scheme linked to financial fraud scams, rescuing 15 victims coerced into criminal activities. ([interpol.int](https://www.interpol.int/News-and-Events/News/2026/201-arrests-in-first-of-its-kind-cybercrime-operation-in-MENA-region?utm_source=openai)) This operation underscores the escalating threat of cybercrime in the MENA region and highlights the effectiveness of international collaboration in combating such activities. The involvement of private sector partners like Group-IB, Kaspersky, and Team Cymru provided critical threat intelligence, facilitating the identification and dismantling of malicious infrastructures. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/kaspersky-supports-interpols-operation-ramz-in-mena-region-resulting-in-over-200-arrests?utm_source=openai))
4 months ago
Kill Chain
INTERPOL's Operation Ramz: A Major Cybercrime Crackdown in the MENA Region
Between October 2025 and February 2026, INTERPOL coordinated Operation Ramz, a large-scale cybercrime crackdown across 13 Middle Eastern and North African countries. The operation led to the arrest of 201 individuals and the identification of 382 additional suspects involved in phishing, malware distribution, and online fraud. Authorities seized 53 servers and identified 3,867 victims, disrupting significant malicious infrastructure and preventing further cyber threats. ([interpol.int](https://www.interpol.int/News-and-Events/News/2026/201-arrests-in-first-of-its-kind-cybercrime-operation-in-MENA-region?utm_source=openai)) This operation underscores the escalating threat of cybercrime in the MENA region and highlights the effectiveness of international collaboration in combating such activities. The involvement of private cybersecurity firms like Kaspersky and Group-IB demonstrates the critical role of public-private partnerships in enhancing global cybersecurity efforts. ([kaspersky.co.za](https://www.kaspersky.co.za/about/press-releases/kaspersky-supports-interpols-operation-ramz-in-mena-region-resulting-in-over-200-arrests?utm_source=openai))
4 months ago
Kill Chain
INTERPOL's Operation Ramz: A Landmark Cybercrime Crackdown in MENA
Between October 2025 and February 2026, INTERPOL coordinated Operation Ramz, a significant cybercrime crackdown across 13 Middle East and North Africa (MENA) countries. This operation led to the arrest of 201 individuals and the identification of 382 additional suspects involved in various cybercrimes, including phishing, malware distribution, and financial fraud. Authorities seized 53 servers and identified 3,867 victims, highlighting the extensive impact of these cybercriminal activities. ([interpol.int](https://www.interpol.int/News-and-Events/News/2026/201-arrests-in-first-of-its-kind-cybercrime-operation-in-MENA-region?utm_source=openai)) The success of Operation Ramz underscores the effectiveness of international collaboration in combating cybercrime. As cyber threats continue to evolve and proliferate, such coordinated efforts are crucial in disrupting malicious networks and protecting potential victims from emerging cyber scams and attacks.
4 months ago
Kill Chain
Mamont Banking Trojan: A Rising Threat in Q1 2026
In Q1 2026, the Mamont banking Trojan emerged as a significant threat to Android users, accounting for 73.5% of banking Trojan detections. This malware family, including variants like Mamont.jo and Mamont.jx, primarily targets users' financial credentials by masquerading as legitimate applications. The surge in Mamont-related incidents underscores the evolving tactics of cybercriminals in exploiting mobile platforms for financial gain. The proliferation of Mamont banking Trojans highlights the critical need for enhanced mobile security measures. As cyber threats become more sophisticated, users and organizations must adopt proactive strategies to safeguard sensitive financial information from such pervasive malware.
4 months ago
Kill Chain
MiniPlasma Zero-Day: A Critical Threat to Windows 11 Security
In May 2026, security researcher Chaotic Eclipse disclosed a critical zero-day vulnerability in Microsoft Windows, codenamed MiniPlasma. This flaw affects the Windows Cloud Files Mini Filter Driver (cldflt.sys) and allows attackers to escalate privileges to SYSTEM level on fully patched Windows 11 systems. The vulnerability was initially reported to Microsoft in September 2020 and was believed to have been patched in December 2020 as CVE-2020-17103. However, recent findings indicate that the issue remains unpatched, posing significant security risks. The public release of the MiniPlasma exploit underscores ongoing challenges in Windows security, particularly concerning privilege escalation vulnerabilities. Organizations must reassess their security postures and implement additional measures to mitigate the risks associated with this unpatched flaw.
4 months ago
Kill Chain
Mini Shai-Hulud Attack: A Wake-Up Call for Developer Ecosystem Security
Between April 29 and May 1, 2026, a coordinated supply chain attack known as "Mini Shai-Hulud" targeted multiple developer ecosystems, including npm, PyPI, and Docker Hub. The threat actor group TeamPCP injected malicious code into widely used packages such as SAP's Cloud Application Programming Model, PyTorch Lightning, and Intercom's npm package. This malware harvested sensitive credentials from developer environments and CI/CD pipelines, including GitHub tokens, cloud API keys, and SSH keys, by exfiltrating them to attacker-controlled repositories. The attack compromised over 170 packages, affecting millions of developers and organizations worldwide. ([labs.cloudsecurityalliance.org](https://labs.cloudsecurityalliance.org/research/csa-research-note-mini-shai-hulud-supply-chain-20260503-csa/?utm_source=openai)) This incident underscores the evolving nature of supply chain attacks, which now focus on developer workstations as entry points. The integration of malicious code into trusted packages highlights the need for enhanced security measures in the software development lifecycle, particularly in dependency management and CI/CD processes. Organizations must adopt comprehensive strategies to protect against such sophisticated threats.
4 months ago
Kill Chain
Windows 'MiniPlasma' Zero-Day Exploit Grants SYSTEM Access
On May 17, 2026, cybersecurity researcher Chaotic Eclipse released a proof-of-concept exploit named 'MiniPlasma' that enables attackers to gain SYSTEM privileges on fully patched Windows systems. This exploit targets a vulnerability in the 'cldflt.sys' Cloud Filter driver, specifically the 'HsmOsBlockPlaceholderAccess' routine, which was initially reported in 2020 as CVE-2020-17103 and believed to have been patched in December 2020. However, the researcher discovered that the vulnerability remains exploitable, allowing for privilege escalation attacks. The release of this exploit underscores the critical importance of thorough patch validation and continuous security assessments. Organizations must remain vigilant, as previously addressed vulnerabilities can resurface, posing significant security risks. This incident highlights the necessity for robust vulnerability management practices to ensure the effectiveness of security patches.
4 months ago
Kill Chain
Alleged Dream Market Administrator Indicted for Money Laundering
In May 2026, Owe Martin Andresen, the alleged main administrator of the defunct darknet marketplace Dream Market, was indicted in the United States on multiple counts of money laundering. Andresen, known by the alias "Speedstepper," is accused of accessing dormant cryptocurrency wallets containing millions of dollars in commission payments from Dream Market, which operated from 2013 until its shutdown in 2019. He allegedly transferred these funds into new cryptocurrency wallets and converted them into gold bars, directing shipments to his residence in Germany. German authorities arrested Andresen on May 7, 2026, under separate charges of concealment money laundering. ([justice.gov](https://www.justice.gov/usao-ndga/pr/german-citizen-charged-laundering-funds-linked-prominent-darknet-marketplace-dream?utm_source=openai)) This case underscores the persistent challenges law enforcement faces in tracking and prosecuting cybercriminals who exploit digital currencies and anonymized platforms to launder illicit proceeds. The indictment highlights the importance of international cooperation in addressing cybercrime and the evolving tactics used by threat actors to obfuscate their activities.
4 months ago
Kill Chain
Understanding the Risks: AI Integration and Cloud Security
In 2025, the enterprise risk landscape experienced a paradigm shift: the adoption of AI and LLMs officially becoming the primary driver of cloud risk. Today, almost 88% of organizations now leverage AI in at least one business function. With this level of integration, the risk of AI is now outpacing traditional security guardrails, culminating in a highly complex and interconnected attack surface. SentinelOne’s new AI and Cloud Verified Exploit Paths and Secrets Scanning Report examines this evolving threatscape and draws on telemetry from over 11,000 anonymized customer environments to offer deeper visibility into how threat actors are actively exploiting modern cloud and AI infrastructures. A primary finding of the 2026 report is the rising proliferation of AI-specific credentials. The data indicates that AI-related secrets — such as OpenAI API Keys, Azure OpenAI API Keys, and others — increased by approximately 140% in a span of one year. This growth correlates directly with the rapid embedding of AI technologies into customer support systems, internal tooling, financial platforms, and product experiences. Ubiquitous deployment has generated a widespread organizational pattern known as 'shadow AI' – the unsanctioned use of AI tools in an environment without formal IT approval or security oversight. In practice, this occurs when developers or internal teams utilize unmanaged or personal LLM keys to process corporate data outside of sanctioned IT or security channels. Since these AI integrations span numerous internal applications, the same API keys are frequently duplicated and stored within code repositories, SaaS configurations, and development scripts. Compounding this, these credentials are often implemented without proper access controls or routine rotation schedules. The sprawl of these credentials renders them difficult to track via standard secrets management protocols, establishing a requirement for more centralized governance over how AI keys are issued and utilized.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports