The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Banking/Mortgage

Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.

556 threat reports
Page 5 of 47

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Banking/Mortgage Threat Reports

Showing 49–60 / 556 reports
Chrome V8 Zero-Day CVE-2026-85046: Critical Browser Security Incident Analysis
Impact· CRITICAL

Chrome V8 Zero-Day CVE-2026-85046: Critical Browser Security Incident Analysis

Google patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome's V8 JavaScript engine, actively exploited in the wild. The zero-day flaw allowed remote attackers to execute arbitrary code through crafted HTML pages, representing the sixth Chrome zero-day addressed by Google in 2026. Security researcher Salvatore Gulizia discovered the bug in V8's compilers that led to array element type confusion, enabling arbitrary read/write operations on the JavaScript heap. This incident highlights the continued targeting of browser engines by threat actors seeking code execution capabilities through web-based attack vectors, emphasizing the critical importance of rapid patch deployment for client-side security vulnerabilities.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
PostgreSQL's 12-Year Security Blind Spot: CVE-2026-6471 Exposes Critical Database Infrastructure Risks
Impact· HIGH

PostgreSQL's 12-Year Security Blind Spot: CVE-2026-6471 Exposes Critical Database Infrastructure Risks

PostgreSQL disclosed CVE-2026-6471, a critical 12-year-old vulnerability in logical decoding that allows accounts with REPLICATION privileges to execute arbitrary code as the database server's operating system user. The flaw, present since PostgreSQL 9.4 in 2014, enables attackers to bypass existing security restrictions by loading malicious libraries through the CREATE_REPLICATION_SLOT command. Exploitation requires a replication account and wal_level=logical configuration, commonly found in backup tools, standby servers, and CDC pipelines. The vulnerability affects versions before 18.6, 17.11, 16.15, 15.19, and 14.24, with fixes introducing the output_plugin_libraries parameter to whitelist approved plugins. This incident highlights the growing threat to database infrastructure as organizations increasingly rely on distributed data architectures and replication mechanisms. With PostgreSQL powering critical applications across industries, this vulnerability exposes the risks of privilege escalation through seemingly low-privilege backup credentials, emphasizing the need for comprehensive database security controls and regular privilege audits.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Massive Unicode Phishing Campaign Evades Email Filters Using Invisible Characters
Impact· HIGH

Massive Unicode Phishing Campaign Evades Email Filters Using Invisible Characters

A sophisticated phishing campaign identified by Microsoft in 2026 leveraged invisible Unicode tag characters to bypass email security filters while targeting millions of recipients with financial lures. The campaign, which peaked between February and May 2026, sent up to 2.37 million messages daily using AI-generated content distributed through the legitimate ActiveCampaign marketing platform. Attackers inserted invisible Unicode characters into financial keywords like 'funding' to evade detection while appearing normal to human recipients, demonstrating how AI-era evasion techniques are being adapted for traditional phishing campaigns. This incident highlights the evolving sophistication of email-based attacks in the AI era, where threat actors are exploiting legitimate marketing platforms and advanced obfuscation techniques to scale phishing operations at unprecedented volumes while evading traditional security controls.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
BraZetsu Malware Transforms Compromised Networks Into Criminal Marketplace Assets
Impact· HIGH

BraZetsu Malware Transforms Compromised Networks Into Criminal Marketplace Assets

In February 2026, cybersecurity researchers discovered BraZetsu, a sophisticated Python-based malware framework developed by the Exilware threat group targeting Latin American organizations. The malware transforms compromised Windows hosts into commercial assets sold through the 'Infected Marketplace' for initial access brokerage operations. BraZetsu employs AI-enhanced reconnaissance capabilities to scan victim networks, extract financial data including Brazilian CNAB banking files, and maintain persistent command and control through WebSocket protocols. The framework represents a significant evolution in Initial Access Broker (IAB) operations, demonstrating how cybercriminals are leveraging artificial intelligence to automate target prioritization and commercialize network access at scale. This incident highlights the growing sophistication of IAB operations and the increasing use of AI in cybercrime, representing a critical shift in how threat actors monetize initial network access and scale their operations across regional markets.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Breeze Comet Cybercrime Group: Direct Manipulation of Global Financial Payment Systems
Impact· HIGH

Breeze Comet Cybercrime Group: Direct Manipulation of Global Financial Payment Systems

Breeze Comet (formerly UNC5669) represents Brazil's most sophisticated cybercrime group, systematically infiltrating financial institutions across Brazil and expanding globally since 2024. The group employs advanced tactics including insider recruitment, physical network access via rogue hardware, and exploitation of compromised government websites as trusted attack vectors. Using custom malware like CobaltSpin, RealBreeze, and KickPlate, they penetrate segmented financial networks to directly manipulate payment systems including Brazil's Pix instant payment platform, executing hundreds of fraudulent transactions worth tens of thousands of dollars within 24-48 hours of system compromise. This incident highlights the evolution of financially-motivated cybercrime from traditional ransomware and fraud schemes to direct payment system manipulation. As instant payment systems proliferate globally and threat actors increasingly leverage AI for malware development, Breeze Comet's successful model poses significant risks to financial infrastructure worldwide, particularly in regions with similar digital payment architectures.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Global Law Enforcement Dismantles 20-Year Sality Botnet in Coordinated Takedown
Impact· MEDIUM

Global Law Enforcement Dismantles 20-Year Sality Botnet in Coordinated Takedown

In September 2026, international law enforcement agencies including the FBI, DOJ, and European authorities successfully dismantled the Sality botnet infrastructure in a coordinated global operation. The peer-to-peer botnet, active for over two decades and controlled by the Russian cybercriminal group SALTY SPIDER, had infected more than 15,000 devices since 2003. The takedown involved seizing command and control domains across the US and Europe, while CrowdStrike's Counter Adversary Operations team executed a sinkhole operation to isolate infected machines and disrupt the botnet's communication backbone. This takedown reflects the growing effectiveness of international cybercrime cooperation and highlights the persistent threat of long-running botnets that adapt their payloads over time, most recently focusing on cryptocurrency clipjacking attacks through EggJagger malware.

3 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Inside the Sality Botnet Takedown: How Authorities Turned P2P Architecture Against Itself
Impact· MEDIUM

Inside the Sality Botnet Takedown: How Authorities Turned P2P Architecture Against Itself

In August 2026, the U.S. Department of Justice led a coordinated international operation to disrupt the Sality botnet, a peer-to-peer malware network operating since 2003. Law enforcement from the U.S., Bulgaria, Hungary, and Romania, working with CrowdStrike and Shadowserver Foundation, executed a sophisticated sinkhole operation that turned Sality's decentralized architecture against itself. The botnet, operated by the Russian threat group Salty Spider from Bashkortostan, had infected over 15,000 machines worldwide and generated at least $150,000 through cryptocurrency theft via clipboard hijacking malware. The operation demonstrates evolving law enforcement capabilities against resilient P2P botnets that traditionally evade conventional takedown methods. This disruption highlights the increasing sophistication of international cybercrime enforcement and the vulnerability of even decentralized criminal infrastructure to coordinated technical and legal action, particularly relevant as threat actors increasingly adopt P2P architectures to avoid single points of failure.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Meta Ads Campaign Delivers StreamRat Android Banking Trojan to 570K+ Users
Impact· HIGH

Meta Ads Campaign Delivers StreamRat Android Banking Trojan to 570K+ Users

Between June and July 2026, cybercriminals leveraged Meta advertising platforms to distribute StreamRat, a sophisticated Android banking trojan targeting Spanish-speaking users through fake television streaming campaigns. The malvertising operation reached approximately 570,950 Meta accounts across the European Union, directing victims to download malicious APK files that granted attackers near-complete device control. Once installed, StreamRat could capture keystrokes, steal credentials through overlay attacks, take screenshots, and remotely control infected devices by exploiting Android's Accessibility services and VPN capabilities. This incident highlights the growing threat of malvertising on major social platforms and the evolution of mobile banking trojans that abuse legitimate Android features for malicious purposes, demonstrating how attackers increasingly target mobile users through trusted advertising channels.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Venezuelan ATM Jackpotting Ring Exposed: When Physical Access Beats Network Security
Impact· HIGH

Venezuelan ATM Jackpotting Ring Exposed: When Physical Access Beats Network Security

Five Venezuelan nationals pleaded guilty to conspiracy to commit bank larceny through ATM jackpotting attacks in Kansas during December 2025. The attackers attempted to install malware on ATMs in Wamego and Manhattan to force cash dispensers to empty their storage cassettes, but failed in both attempts and were arrested within days after surveillance cameras captured their activities. This case is part of a broader crackdown on the Tren de Aragua Venezuelan criminal organization, with the Justice Department charging 87 members in connection with ATM malware schemes that stole over $20 million in 2025. ATM jackpotting attacks represent a growing physical-digital threat where criminals bypass traditional network security by gaining direct hardware access to financial infrastructure, highlighting the critical need for comprehensive security that extends beyond network perimeters to protect physical endpoints and embedded systems.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Breeze Comet's Sophisticated Attack on Brazilian Payment Systems Exposes Critical Infrastructure Vulnerabilities
Impact· HIGH

Breeze Comet's Sophisticated Attack on Brazilian Payment Systems Exposes Critical Infrastructure Vulnerabilities

Since 2024, the financially motivated threat actor Breeze Comet (formerly UNC5669) has targeted Brazilian financial services, retail, and e-commerce organizations through sophisticated payment system manipulation attacks. The group gains initial access via password spraying and social engineering calls impersonating IT support to install remote access tools like AnyDesk, then deploys custom malware including COBALTSPIN, LIGHTPAINT, and MILDFROST to maintain persistence and lateral movement. Successfully executing hundreds of fraudulent transactions worth tens of thousands of dollars, the group specifically targets entities with access to Brazil's National Financial System Network and payment platforms like Pix, STR, and Boleto. This campaign represents a significant evolution in Latin American cybercrime from opportunistic retail fraud to direct targeting of core financial infrastructure. The threat actor's use of AI-assisted malware development and expansion into other Latin American and African countries signals a new model for financially motivated attacks that defenders must prepare for as interconnected payment ecosystems become increasingly vulnerable.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Guildma (Astaroth) Malware Evolves with Advanced Geofencing and Evasion Techniques
Impact· MEDIUM

Guildma (Astaroth) Malware Evolves with Advanced Geofencing and Evasion Techniques

In August 2026, a sophisticated Guildma (Astaroth) malware campaign targeted Brazilian users through geofenced phishing emails written in Brazilian Portuguese. The attack required victims to access malicious links from Brazil-based IP addresses with Brazilian Portuguese language and regional settings, demonstrating advanced evasion techniques. The malware was delivered via a zip archive containing a Windows shortcut that utilized alternate data streams to deploy a 64-bit DLL, which subsequently installed an AutoIt-compiled Guildma payload for credential theft and information stealing. This campaign represents the continued evolution of Brazilian-origin banking trojans that have expanded globally, leveraging sophisticated geofencing and language-based targeting to evade detection and analysis. The use of legitimate cloud infrastructure like Azure websites and advanced evasion techniques demonstrates how threat actors are adapting to modern security controls while maintaining persistence through alternate data streams and AutoIt compilation.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Cronos Blockchain Halts After $74M Tectonic Protocol Exploit
Impact· HIGH

Cronos Blockchain Halts After $74M Tectonic Protocol Exploit

In August 2026, the Cronos blockchain network experienced a devastating $74 million exploit targeting the Tectonic DeFi lending protocol. Attackers artificially inflated the price of Tectonic's TONIC token by 100 times within 20 minutes, then used it as collateral to borrow legitimate assets. While the total exploit value reached $74 million, attackers only managed to extract approximately $6 million in Ethereum before Cronos validators executed an emergency consensus halt, freezing the blockchain to prevent further damage. The incident reduced Tectonic's total value locked from $122 million to under $3 million. This incident highlights the growing sophistication of DeFi price manipulation attacks and demonstrates how attackers are exploiting oracle vulnerabilities and lending protocol weaknesses to execute large-scale thefts. The rapid response by blockchain validators represents an evolution in DeFi incident response capabilities, though it raises questions about decentralization versus security trade-offs.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports