The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Banking/Mortgage

Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.

558 threat reports
Page 25 of 47

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Banking/Mortgage Threat Reports

Showing 289–300 / 558 reports
Google Chrome's Dawn WebGPU Zero-Day Vulnerability in 2026
Impact· HIGH

Google Chrome's Dawn WebGPU Zero-Day Vulnerability in 2026

In March 2026, Google identified and patched a critical zero-day vulnerability (CVE-2026-5281) in its Chrome browser, marking the fourth such exploit addressed that year. This flaw resided in Dawn, Chrome's implementation of the WebGPU standard, and was actively exploited in the wild. Attackers leveraged this use-after-free vulnerability to cause browser crashes, data corruption, and potentially execute arbitrary code by enticing users to visit maliciously crafted web content. Google promptly released emergency updates for Windows, macOS, and Linux platforms to mitigate the risk. The recurrence of multiple zero-day vulnerabilities within a short timeframe underscores the persistent targeting of widely-used browsers by threat actors. Organizations and individual users are urged to maintain vigilance by promptly applying security updates and adopting robust cybersecurity practices to mitigate the risks associated with such exploits.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
NoVoice Malware: A Wake-Up Call for Android Security
Impact· CRITICAL

NoVoice Malware: A Wake-Up Call for Android Security

In early 2026, a sophisticated Android malware campaign named 'NoVoice' infiltrated over 50 applications on Google Play, amassing at least 2.3 million downloads. Disguised as legitimate utilities like cleaners, games, and image galleries, these apps functioned as advertised, concealing their malicious intent. Upon installation, the malware exploited known Android vulnerabilities to gain root access, enabling it to inject code into other applications and exfiltrate sensitive data, notably targeting WhatsApp sessions. The malware's persistence mechanisms allowed it to survive standard factory resets, posing a significant threat to user privacy and device integrity. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/novoice-android-malware-on-google-play-infected-23-million-devices/?utm_source=openai)) This incident underscores the evolving sophistication of mobile malware and the critical importance of maintaining up-to-date device security. It highlights the necessity for users to exercise caution when downloading apps, even from trusted sources like Google Play, and for developers to adhere to stringent security practices to prevent such infiltrations.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Casbaneiro Phishing Campaign Targets Latin America and Europe
Impact· HIGH

Casbaneiro Phishing Campaign Targets Latin America and Europe

In March 2026, a sophisticated phishing campaign orchestrated by the Brazilian cybercrime group Augmented Marauder targeted Spanish-speaking users across Latin America and Europe. The attackers distributed emails with court summons-themed messages containing password-protected PDF attachments. These PDFs directed recipients to malicious links, initiating a multi-stage infection chain that deployed the Horabot malware, which subsequently delivered the Casbaneiro banking trojan. This campaign leveraged dynamic PDF generation and exploited both email and WhatsApp platforms to propagate the malware, resulting in significant financial and data losses for affected organizations. This incident underscores the evolving tactics of cybercriminals who are increasingly using multi-pronged attack vectors and dynamic content to bypass traditional security measures. The use of legitimate communication channels like WhatsApp for malware distribution highlights the need for organizations to implement comprehensive security strategies that address both email and messaging platforms.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Chrome 2026 Dawn Use-After-Free Vulnerability
Impact· HIGH

Chrome 2026 Dawn Use-After-Free Vulnerability

In April 2026, Google identified and patched a high-severity zero-day vulnerability, CVE-2026-5281, in its Chrome browser. This use-after-free flaw in Dawn, Chrome's implementation of the WebGPU standard, allowed remote attackers to execute arbitrary code via crafted HTML pages. The vulnerability was actively exploited in the wild, prompting Google to release an emergency update to versions 146.0.7680.177/178 for Windows and macOS, and 146.0.7680.177 for Linux. ([thehackernews.com](https://thehackernews.com/2026/04/new-chrome-zero-day-cve-2026-5281-under.html?utm_source=openai)) This incident underscores the increasing frequency of zero-day vulnerabilities targeting widely used software. It highlights the critical need for organizations to maintain up-to-date systems and implement robust security measures to mitigate the risks associated with such exploits.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Magecart E-Skimmer Infections Reach Record Highs in 2025
Impact· CRITICAL

Magecart E-Skimmer Infections Reach Record Highs in 2025

In 2025, Magecart e-skimming attacks surged, compromising over 23 million online transactions across more than 10,500 unique infections. These attacks involved injecting malicious JavaScript into e-commerce checkout pages to steal payment data. The proliferation of full-stack e-skimmer kits and Malware-as-a-Service offerings enabled less technically skilled threat actors to execute large-scale compromises, significantly impacting the security of online merchants and consumers. ([recordedfuture.com](https://www.recordedfuture.com/resources/guides/annual-payment-fraud-intelligence-report-2025?utm_source=openai)) The industrialization of the fraud ecosystem, characterized by standardized attack tools and services, has lowered the barrier to entry for cybercriminals. This trend underscores the urgent need for financial institutions and e-commerce platforms to adopt proactive, intelligence-driven defenses to mitigate the escalating threat of payment fraud. ([recordedfuture.com](https://www.recordedfuture.com/resources/guides/annual-payment-fraud-intelligence-report-2025?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Venom Stealer: The New Frontier in Automated ClickFix Attacks
Impact· HIGH

Venom Stealer: The New Frontier in Automated ClickFix Attacks

In April 2026, a new malware-as-a-service (MaaS) platform named Venom Stealer emerged, automating the creation of persistent information-stealing attacks through ClickFix social engineering techniques. Developed by an individual known as 'VenomStealer,' this platform enables attackers to establish a continuous exfiltration pipeline, harvesting credentials, session cookies, and cryptocurrency wallets from victims. Unlike traditional infostealers, Venom Stealer remains active post-infection, continuously monitoring and exfiltrating new data, thereby undermining standard incident response measures. The commoditization of such advanced attack methods signifies a concerning evolution in cyber threats, making sophisticated social engineering tactics more accessible to a broader range of cybercriminals. Organizations must enhance their security awareness training and implement robust monitoring of outbound traffic to detect and prevent data exfiltration activities associated with these attacks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Dutch Finance Ministry Cyberattack: A 2026 Case Study
Impact· MEDIUM

Dutch Finance Ministry Cyberattack: A 2026 Case Study

In March 2026, the Dutch Ministry of Finance detected unauthorized access to its internal systems, specifically targeting primary processes within the policy department. The breach, identified on March 19, led to the temporary shutdown of affected systems by March 23, impacting some employees' access. Notably, services related to tax collection, customs, and benefits remained operational, ensuring that citizen and business services were unaffected. The ministry has not disclosed the extent of data accessed or the number of employees impacted, and no threat actor has claimed responsibility for the attack. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/dutch-ministry-of-finance-discloses-breach-affecting-employees/?utm_source=openai)) This incident underscores the persistent threat to governmental institutions and the critical importance of robust cybersecurity measures. The breach highlights the necessity for continuous monitoring, rapid response protocols, and comprehensive security frameworks to protect sensitive governmental data and maintain public trust.

5 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Cisco's 2026 Trivy Supply Chain Attack: A Wake-Up Call for CI/CD Security
Impact· HIGH

Cisco's 2026 Trivy Supply Chain Attack: A Wake-Up Call for CI/CD Security

In March 2026, Cisco experienced a significant security breach when attackers exploited compromised credentials from the Trivy supply chain attack to infiltrate its internal development environment. This intrusion led to the theft of source code from over 300 GitHub repositories, including proprietary AI-powered products and sensitive customer data from sectors such as banking and U.S. government agencies. The attackers utilized a malicious GitHub Action plugin to exfiltrate credentials and data, affecting numerous developer and lab workstations. In response, Cisco isolated impacted systems, initiated reimaging procedures, and commenced a comprehensive credential rotation to mitigate further unauthorized access. This incident underscores the escalating threat posed by supply chain attacks, where vulnerabilities in widely-used tools can have cascading effects on major organizations. The breach highlights the critical need for robust security measures in CI/CD pipelines and the importance of prompt credential management to prevent unauthorized access and data exfiltration.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
DeepLoad Malware: AI-Powered Threat Exploiting ClickFix Social Engineering
Impact· HIGH

DeepLoad Malware: AI-Powered Threat Exploiting ClickFix Social Engineering

In March 2026, researchers identified 'DeepLoad,' a sophisticated malware strain that employs AI-generated code to steal credentials and evade detection. Delivered through the 'ClickFix' social engineering technique, DeepLoad tricks users into executing malicious commands under the guise of resolving fake errors. Once executed, it captures stored browser passwords and real-time keystrokes via a standalone stealer and a malicious browser extension. The malware's extensive use of junk code, likely generated by AI, obfuscates its true functionality, making it challenging for security tools to detect. Additionally, DeepLoad establishes persistence mechanisms that allow it to re-execute even after apparent removal, posing a significant threat to enterprise environments. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/ai-powered-deepload-steals-credentials-evades-detection/?utm_source=openai)) The emergence of DeepLoad underscores the evolving landscape of cyber threats, where attackers leverage AI to enhance malware capabilities and employ advanced social engineering tactics like ClickFix. This incident highlights the urgent need for organizations to bolster their defenses against AI-driven threats and to educate users about sophisticated phishing techniques that exploit human trust and technical familiarity.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Bypassing Application Control: A New Data Exfiltration Technique Unveiled
Impact· MEDIUM

Bypassing Application Control: A New Data Exfiltration Technique Unveiled

In March 2026, a security assessment revealed that data exfiltration could bypass application control mechanisms in next-generation firewalls. The assessment demonstrated that by transmitting data in small chunks (approximately 3KB each), an attacker could evade detection thresholds, allowing unauthorized data transfer without triggering security alerts. This method exploits the time and data volume required by firewalls to accurately classify and block malicious traffic. This incident underscores the evolving tactics of cyber adversaries who continuously adapt to circumvent security measures. Organizations must recognize that traditional firewall configurations may be insufficient against such sophisticated exfiltration techniques, necessitating enhanced monitoring and adaptive security strategies.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Addressing API Authorization Vulnerabilities in the Age of AI
Impact· CRITICAL

Addressing API Authorization Vulnerabilities in the Age of AI

In 2026, API authorization vulnerabilities have emerged as a critical security concern, with Broken Object Level Authorization (BOLA) and Broken Function Level Authorization (BFLA) being the most prevalent issues. These flaws allow attackers to access or manipulate resources without proper permissions, leading to unauthorized data exposure and potential system compromise. The rapid proliferation of APIs, coupled with inadequate access controls, has significantly increased the attack surface for organizations. ([42crunch.com](https://42crunch.com/state-of-api-security-2026-report/?utm_source=openai)) The urgency to address these vulnerabilities is heightened by the integration of AI and automation technologies, which rely heavily on APIs. As AI systems become more prevalent, the potential for exploitation through insecure APIs grows, emphasizing the need for robust authorization mechanisms and continuous security assessments. ([tfir.io](https://tfir.io/ai-security-api-security-wallarm-2026/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Bearlyfy's 2025 Ransomware Campaign Against Russian Companies
Impact· HIGH

Bearlyfy's 2025 Ransomware Campaign Against Russian Companies

In early 2025, the pro-Ukrainian cyber group Bearlyfy initiated a series of over 70 ransomware attacks targeting Russian companies. Employing custom strains like GenieLocker, Bearlyfy exploited vulnerabilities in public-facing applications to gain initial access, subsequently encrypting critical data and demanding ransoms. The group's operations have caused significant disruptions across various sectors in Russia. This incident underscores a growing trend of politically motivated cyberattacks, where hacktivist groups leverage ransomware to inflict economic damage. The Bearlyfy attacks highlight the evolving landscape of cyber threats, emphasizing the need for robust security measures to protect against both financially and ideologically driven adversaries.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports