The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

4339 threat reports
Page 1 of 362

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Financial Services Threat Reports

Showing 1–12 / 4339 reports
GitLab Email Addresses Weaponized in 2026 Supply Chain Attacks
Impact· HIGH

GitLab Email Addresses Weaponized in 2026 Supply Chain Attacks

In September 2026, Aikido Security researchers discovered that GitLab's incoming email addresses contain non-expiring access tokens that grant broad privileges across an organization's public and private projects. These automatically assigned email addresses, designed for creating issues via email, can be weaponized by attackers who obtain them to push malicious code, bypass IP restrictions, and execute CI/CD jobs without direct account access. The vulnerability affects the entire GitLab ecosystem, with researchers finding exposed addresses for popular open-source projects during a brief internet scan. This incident highlights the growing sophistication of supply chain attacks targeting developer platforms and the hidden security implications of seemingly benign productivity features. As organizations increasingly rely on DevOps platforms for critical infrastructure, attackers are exploiting overlooked authentication mechanisms to compromise software supply chains at scale.

5 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Process Parameter Poisoning: The EDR Evasion Technique That's Rewriting Endpoint Security Rules
Impact· MEDIUM

Process Parameter Poisoning: The EDR Evasion Technique That's Rewriting Endpoint Security Rules

In September 2026, cybersecurity researchers at Flashpoint validated a sophisticated EDR evasion technique called 'process parameter poisoning,' originally discovered by Max Hirschberger and Ogulcan Ugur in July 2026. This technique allows attackers to inject malicious code into Windows process initialization structures without using traditional Windows APIs that EDR tools monitor, such as VirtualAllocEx() and WriteProcessMemory(). When combined with additional evasion methods like DLL unhooking and non-Microsoft DLL blocking policies, the technique successfully bypassed multiple market-leading EDR solutions without generating any security alerts. This discovery represents a significant shift in the cybersecurity landscape as threat actors increasingly develop advanced techniques to circumvent endpoint detection systems. The research highlights the growing sophistication of EDR evasion methods and the need for security teams to monitor actual process behavior rather than relying solely on traditional API monitoring approaches.

5 hours ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
$4B Manus AI Platform Exploited Through Prompt Injection Vulnerability
Impact· HIGH

$4B Manus AI Platform Exploited Through Prompt Injection Vulnerability

In September 2026, security researchers at Salt Labs discovered a critical prompt injection vulnerability in Manus, a $4 billion valuation agentic AI platform. The vulnerability allowed attackers to execute remote code through indirect prompt injection via email, bypassing security filters using JSFuck obfuscation techniques. Researchers demonstrated the ability to establish reverse shells and extract credentials for connected third-party services including Gmail, Dropbox, and GitHub. The vulnerability was reported through Meta's bug bounty program during an attempted acquisition and was subsequently patched. This incident highlights the growing security risks in the rapidly expanding agentic AI ecosystem, where AI agents with extensive third-party integrations present attractive targets for credential harvesting and supply chain attacks.

5 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Ghost Service Accounts: The Hidden Threat in Your M365 Environment
Impact· HIGH

Ghost Service Accounts: The Hidden Threat in Your M365 Environment

In July 2026, threat actor UNK_CondorFiltration successfully compromised a major Chilean retailer's Microsoft 365 environment using the open-source TeamFiltration toolkit. After failing to breach employee accounts at multiple Chilean financial institutions, the attacker pivoted to exploit forgotten service accounts with default credentials and no multi-factor authentication. Within seven minutes, six of seven targeted service accounts were compromised, enabling the exfiltration of emails, chat conversations, and files from Outlook, Teams, and OneDrive. The attacker also probed the company's VPN and accessed both M365 and Azure management portals. This incident highlights the growing threat of identity-based attacks targeting non-human accounts in cloud environments. As organizations strengthen human account security, attackers increasingly focus on overlooked service accounts that lack proper lifecycle management, creating critical security gaps in zero trust implementations.

6 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
TeamFiltration Campaign Exploits Forgotten Service Accounts in Chilean Organizations
Impact· HIGH

TeamFiltration Campaign Exploits Forgotten Service Accounts in Chilean Organizations

In July-August 2026, the UNK_CondorFiltration campaign leveraged the TeamFiltration framework to target over 5,700 Microsoft 365 accounts across 28 tenants, primarily focusing on Chilean retail and financial institutions. Operating from 1,487 unique AWS EC2 IP addresses, attackers successfully compromised 7 unmanaged service accounts using default passwords and no multi-factor authentication. The campaign unfolded in three waves, with threat actors gaining access to Microsoft Office, OneDrive, and Teams within minutes of compromise, then pivoting through German VPN nodes to access corporate infrastructure and initiate data exfiltration activities. This incident highlights the growing trend of attackers targeting forgotten service accounts and leveraging legitimate penetration testing tools for malicious purposes, reflecting broader shifts toward identity-based attacks that exploit basic hygiene gaps rather than sophisticated exploits.

6 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
ClickFix Campaign Weaponizes 17,000 URLs in Massive Social Engineering Operation
Impact· HIGH

ClickFix Campaign Weaponizes 17,000 URLs in Massive Social Engineering Operation

ClickFix has emerged as the dominant initial access technique in enterprise breaches, with Microsoft attributing 47% of Defender Experts cases in 2025 to this social engineering method. The attack compromises legitimate websites to display fake error pages that trick users into copying and pasting malicious commands into trusted system interfaces like PowerShell or Terminal. CTM360's analysis revealed over 17,000 infected URLs using blockchain-based infrastructure to evade takedown attempts, with the technique delivering Vidar Stealer through legitimate Microsoft processes via DLL side-loading. This represents a fundamental shift in attack methodology that bypasses traditional security controls by exploiting human trust rather than technical vulnerabilities. The technique's evolution from novelty in late 2023 to a subscription service with state-sponsored adoption demonstrates the cybercrime ecosystem's rapid adaptation to defensive measures.

6 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
How Attackers Exploit URL Parser Differences in Advanced Phishing Campaigns
Impact· LOW

How Attackers Exploit URL Parser Differences in Advanced Phishing Campaigns

Security researchers at SANS Internet Storm Center documented a sophisticated phishing campaign exploiting URL parser differences to evade detection systems. The attack utilized three distinct techniques: RFC 3986 userinfo fields with tracking tokens, malformed hostnames with hyphens that bypass strict validators, and victim email addresses in URL paths that confuse parsing logic. These methods created URLs that appeared as legitimate email addresses or trusted domains to security filters while directing browsers to attacker-controlled phishing sites. The campaign demonstrated how attackers exploit discrepancies between different URL parsing implementations rather than traditional vulnerabilities. This incident highlights the growing sophistication of phishing campaigns that exploit fundamental protocol ambiguities and parser inconsistencies. As organizations implement zero-trust architectures and advanced email security, attackers are adapting with techniques that manipulate how different systems interpret the same URL string.

7 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Sophisticated Malicious npm Packages Bypass Security Defenses in 2026 Supply Chain Attack
Impact· MEDIUM

Sophisticated Malicious npm Packages Bypass Security Defenses in 2026 Supply Chain Attack

In September 2026, cybersecurity researchers discovered sophisticated malicious npm packages capable of evading standard install script defenses through runtime execution techniques. The malware demonstrates advanced evasion capabilities by bypassing traditional package scanning mechanisms and executing malicious code only after successful installation. Security expert Bruce Schneier characterized the sophistication as potentially nation-state level, though no direct attribution has been established. The attack compromises JavaScript supply chains by targeting the npm ecosystem, affecting downstream applications and potentially exposing sensitive development environments and production systems. This incident highlights the escalating sophistication of supply chain attacks targeting developer ecosystems, coinciding with increased nation-state activity in software supply chain infiltration and the growing dependency on open-source package managers across enterprise environments.

7 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical F5 BIG-IP APM Zero-Day Under Active Attack: What Organizations Need to Know
Impact· CRITICAL

Critical F5 BIG-IP APM Zero-Day Under Active Attack: What Organizations Need to Know

F5 disclosed CVE-2026-94127, a critical zero-day vulnerability in BIG-IP APM (Access Policy Manager) being actively exploited for remote code execution attacks in September 2026. The flaw affects instances configured as OAuth Authorization Servers and has prompted emergency patching advisories from both F5 and CISA, which added it to the Known Exploited Vulnerabilities catalog. With over 14,700 exposed BIG-IP APM instances detected by Shadowserver, the vulnerability poses significant risks to enterprise networks and critical infrastructure. This incident underscores the escalating threat to network access management solutions as attackers increasingly target authentication and authorization infrastructure to gain privileged network access and establish persistent footholds in enterprise environments.

23 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Ryuk Ransomware Architect Sentenced: Lessons for Modern Enterprise Security
Impact· HIGH

Ryuk Ransomware Architect Sentenced: Lessons for Modern Enterprise Security

Karen Serobovich Vardanyan, a 35-year-old Armenian national known online as 'Maneeken' or 'Karl Lagerfeld,' was sentenced to 24 months in prison for his role in Ryuk ransomware attacks between March 2019 and June 2020. Vardanyan specialized in gaining initial access to corporate networks, helping his cybercriminal group breach multiple U.S. organizations including companies in Michigan, Texas, and Oregon. The group collected over $15 million in ransom payments, with one Michigan company alone paying 200 BTC worth over $1.1 million. Vardanyan was extradited from Ukraine in 2025 and pleaded guilty in July 2026. This sentencing highlights the ongoing global law enforcement efforts to prosecute ransomware operators, even years after attacks occurred. As ransomware groups continue to evolve and fragment into smaller units, the Ryuk-to-Conti evolution demonstrates how cybercriminal organizations adapt and rebrand while maintaining similar attack methodologies.

23 hours ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Zero-Day in Arista VeloCloud Orchestrator Exposes SD-WAN Infrastructure Risk
Impact· CRITICAL

Critical Zero-Day in Arista VeloCloud Orchestrator Exposes SD-WAN Infrastructure Risk

In September 2026, Arista Networks disclosed CVE-2026-93952, a maximum-severity zero-day vulnerability in VeloCloud Orchestrator (VCO) On-Prem deployments that was being actively exploited. The flaw stems from improper input validation in certificate-based authentication, allowing remote attackers to access privileged internal VCO host functionality without requiring system privileges or user interaction. The U.S. CISA immediately added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated federal agencies secure their networks within 48 hours. This incident highlights the escalating threat to SD-WAN infrastructure as organizations increasingly rely on hybrid connectivity solutions. With Arista being a Fortune 500 company serving over 10,000 customers worldwide, this zero-day demonstrates how critical network infrastructure remains a high-value target for sophisticated threat actors seeking to compromise enterprise connectivity and potentially pivot to broader network access.

23 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How One Kubernetes YAML File Can Compromise Your Entire Google Cloud Organization
Impact· CRITICAL

How One Kubernetes YAML File Can Compromise Your Entire Google Cloud Organization

A critical security vulnerability in Google Kubernetes Config Connector (KCC) allows attackers with limited Kubernetes namespace access to escalate privileges and gain complete control over entire Google Cloud organizations. The attack, dubbed ConfigConfusion, exploits a confused deputy problem where KCC's organization-level service account executes IAM changes requested by users who lack corresponding Google Cloud permissions. Attackers can submit a single YAML IAMPolicyMember resource to grant themselves roles/owner privileges across the entire organization, effectively bypassing all authentication controls without ever possessing Google Cloud credentials. This vulnerability highlights the growing risks of infrastructure-as-code systems where authorization gaps between Kubernetes RBAC and cloud provider IAM create unprecedented privilege escalation pathways, particularly as organizations increasingly adopt GitOps workflows and multi-cloud architectures.

23 hours ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports