✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
APT28's 2025 SOHO Router DNS Hijacking: A Wake-Up Call for Network Security
In August 2025, the Russian state-sponsored group APT28 (also known as Forest Blizzard) initiated a large-scale cyber-espionage campaign targeting small office/home office (SOHO) routers, primarily from TP-Link and MikroTik. By exploiting known vulnerabilities, such as CVE-2023-50224, the attackers gained unauthorized access to these routers and modified their DNS settings to redirect traffic through malicious servers under their control. This allowed them to intercept and steal credentials for web and email services, including Microsoft Outlook, from over 200 organizations and 5,000 consumer devices across more than 120 countries. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/07/soho-router-compromise-leads-to-dns-hijacking-and-adversary-in-the-middle-attacks/?utm_source=openai)) The campaign, which peaked in December 2025, underscores the critical need for securing network infrastructure, especially SOHO devices that may lack robust security measures. The U.S. Department of Justice, in collaboration with the FBI and international partners, conducted Operation Masquerade to disrupt this malicious network, highlighting the ongoing threat posed by state-sponsored cyber activities and the importance of proactive defense strategies. ([justice.gov](https://www.justice.gov/opa/pr/justice-department-conducts-court-authorized-disruption-dns-hijacking-network-controlled?utm_source=openai))
3 months ago
Kill Chain
DISGOMOJI Malware: A New Era of Emoji-Based Cyber Attacks
In 2024, the Pakistan-based Advanced Persistent Threat (APT) group UTA0137 launched a cyber-espionage campaign targeting Indian government entities. The group deployed a sophisticated malware named DISGOMOJI, written in Golang and designed for Linux systems. DISGOMOJI uniquely utilized Discord for command-and-control (C2) communications, employing emojis to execute commands such as taking screenshots, exfiltrating files, and terminating processes. The malware was delivered via spear-phishing emails containing a ZIP archive with a Golang ELF binary. Upon execution, the binary downloaded a lure file and the DISGOMOJI payload, establishing a dedicated Discord channel for each infected system, allowing individualized interaction with each victim. This campaign underscores the evolving tactics of state-sponsored threat actors in leveraging unconventional methods to evade detection and maintain persistent access to targeted systems. The use of emojis in C2 communications highlights a broader trend of adversaries adopting more visual and adaptive forms of interaction to obfuscate their activities and complicate monitoring efforts.
3 months ago
Kill Chain
Critical Vulnerability in Ivanti EPMM: CVE-2026-1340
In January 2026, a critical code injection vulnerability, CVE-2026-1340, was discovered in Ivanti Endpoint Manager Mobile (EPMM). This flaw allows unauthenticated remote code execution, enabling attackers to execute arbitrary code on affected systems without authentication. The vulnerability affects EPMM versions up to and including 12.7.0.0. Exploitation of this vulnerability can lead to complete system compromise, data theft, and potential lateral movement within enterprise networks. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-1340/?utm_source=openai)) The inclusion of CVE-2026-1340 in CISA's Known Exploited Vulnerabilities Catalog underscores the urgency for organizations to address this issue promptly. ([datacomm.com](https://www.datacomm.com/feed-post/cve-2026-1281-cve-2026-1340-ivanti-endpoint-manager-mobile-epmm-zero-day-vulnerabilities-exploited-2/?utm_source=openai))
3 months ago
Kill Chain
Cisco's 2026 Trivy Supply Chain Breach: A Wake-Up Call for Development Security
In March 2026, Cisco's internal development environment was breached through a sophisticated supply chain attack involving the Trivy vulnerability scanner. Threat actors, identified as TeamPCP, compromised Trivy's GitHub Actions pipeline, injecting credential-stealing malware into official releases. This allowed them to harvest credentials from organizations using Trivy, including Cisco. Leveraging these stolen credentials, the attackers infiltrated Cisco's build systems and developer workstations, exfiltrating over 300 private GitHub repositories containing source code for AI-powered products and unreleased items. Additionally, customer repositories belonging to banks, business process outsourcing firms, and U.S. government agencies were among those exfiltrated. AWS keys were also stolen and used for unauthorized activities across Cisco's cloud accounts. Cisco has since isolated affected systems, initiated reimaging, and is performing wide-scale credential rotation to contain the breach. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/?utm_source=openai)) This incident underscores the escalating threat posed by supply chain attacks, where compromising a widely-used tool can have cascading effects across multiple organizations. The breach highlights the critical need for organizations to scrutinize the security of third-party tools integrated into their development pipelines and to implement robust monitoring and incident response strategies to detect and mitigate such sophisticated attacks.
3 months ago
Kill Chain
EngageLab SDK Vulnerability: A Wake-Up Call for Android Developers
In April 2025, a critical intent redirection vulnerability was discovered in the EngageLab SDK, a widely used third-party Android library for managing messaging and push notifications. This flaw allowed malicious applications to exploit the SDK's exported activity, MTCommonActivity, to gain unauthorized access to private data by bypassing Android's security mechanisms. The vulnerability affected numerous applications, including cryptocurrency wallets, with over 30 million installations, exposing sensitive user information to potential risk. EngageLab addressed the issue by releasing version 5.2.1 on November 3, 2025, which set the vulnerable activity to non-exported, mitigating the risk. This incident underscores the significant security implications of vulnerabilities in third-party SDKs, especially in high-value sectors like digital asset management. It highlights the necessity for developers to rigorously review and monitor third-party components integrated into their applications to prevent similar security breaches.
3 months ago
Kill Chain
Storm-2755: Unveiling the 2026 Payroll Pirate AiTM Attack in Canada
In April 2026, a financially motivated threat actor identified as Storm-2755 targeted Canadian employees through a sophisticated 'payroll pirate' campaign. Utilizing adversary-in-the-middle (AiTM) phishing techniques, the attackers intercepted authentication sessions to gain unauthorized access to employee profiles on HR platforms. This access enabled them to divert salary payments to accounts under their control, resulting in direct financial losses for both individuals and organizations. The campaign was notable for its use of malvertising and search engine optimization (SEO) poisoning to lure victims to malicious sites, effectively bypassing traditional multi-factor authentication (MFA) methods. This incident underscores the evolving nature of cyber threats, particularly the increasing prevalence of AiTM attacks that can circumvent standard MFA protections. Organizations must recognize the limitations of traditional security measures and adopt more robust, phishing-resistant authentication methods to safeguard against such sophisticated attacks.
3 months ago
Kill Chain
AWS AgentCore IAM God Mode Vulnerability Exposes Critical Security Risks
In April 2026, a security analysis revealed that the Amazon Bedrock AgentCore Starter Toolkit's default IAM roles granted overly permissive access, allowing AI agents to perform actions across all resources within an AWS account. This misconfiguration enabled potential attackers to exfiltrate proprietary ECR images, access other agents' memories, invoke code interpreters, and extract sensitive data. The issue stemmed from the toolkit's auto-create logic, which favored deployment ease over the principle of least privilege. Following disclosure, AWS updated its documentation to warn users that the default roles are intended for development and testing purposes only and are not recommended for production deployments. This incident underscores the critical importance of adhering to the principle of least privilege in IAM configurations, especially as organizations increasingly deploy AI agents in cloud environments. Overly permissive roles can lead to significant security risks, including data breaches and unauthorized access to sensitive resources.
3 months ago
Kill Chain
Critical RCE Vulnerability Discovered in Apache ActiveMQ Classic
In April 2026, a critical remote code execution (RCE) vulnerability, CVE-2026-34197, was discovered in Apache ActiveMQ Classic, a widely used open-source message broker. This flaw, present for over 13 years, allows authenticated attackers to execute arbitrary commands on the broker's Java Virtual Machine (JVM) by exploiting the Jolokia JMX-HTTP bridge. The vulnerability affects versions before 5.19.4 and from 6.0.0 up to 6.2.3. Exploitation involves sending a crafted request that forces the broker to load a remote Spring XML file, leading to command execution during its initialization. The discovery underscores the importance of proactive vulnerability management and the potential of AI tools in identifying complex security flaws. Organizations using affected ActiveMQ versions are urged to upgrade to versions 5.19.5 or 6.2.3 to mitigate this risk. ([ubuntu.com](https://ubuntu.com/security/CVE-2026-34197?utm_source=openai))
3 months ago
Kill Chain
New macOS Malware Campaign Exploits Script Editor in ClickFix Attack
In April 2026, a new macOS malware campaign emerged, leveraging the Script Editor application to deliver the Atomic Stealer (AMOS) malware. Attackers employed a variation of the ClickFix technique, directing users to malicious websites that prompted them to open Script Editor via the 'applescript://' URL scheme. This method executed obfuscated commands to download and run AMOS, which exfiltrated sensitive data including Keychain information, browser credentials, and cryptocurrency wallets. This incident underscores the evolving tactics of threat actors targeting macOS systems, particularly through trusted applications like Script Editor. The shift from Terminal-based to Script Editor-based ClickFix attacks highlights the need for continuous vigilance and user education to recognize and avoid such sophisticated social engineering schemes.
3 months ago
Kill Chain
Navigating Financial Cyberthreats: Insights from 2025 and Projections for 2026
In 2025, the financial sector faced a rapidly evolving cyber landscape characterized by the proliferation of infostealers, AI-assisted attacks, and supply chain compromises. Notably, there was a significant increase in mobile financial threats, with a 102% rise in users affected globally compared to 2023. Additionally, 12.8% of B2B finance sector companies encountered ransomware attacks, marking a 35.7% increase from the previous year. These developments underscore the growing sophistication and diversification of cyber threats targeting financial institutions. ([me-en.kaspersky.com](https://me-en.kaspersky.com/about/press-releases/financial-sector-faced-ai-blockchain-and-organized-crime-threats-in-2025-kaspersky-reports?utm_source=openai)) Looking ahead to 2026, the financial sector is expected to confront even more complex challenges, including the emergence of quantum-proof ransomware and the continued advancement of mobile financial cyberthreats. Organizations must proactively adapt their cybersecurity strategies to address these evolving threats, emphasizing the importance of real-time monitoring, cross-channel threat intelligence, and robust identity protection measures. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/kaspersky-predicts-quantum-proof-ransomware-and-advancements-in-mobile-financial-cyberthreats-in-2025?utm_source=openai))
3 months ago
Kill Chain
North Korean Hackers Deploy 1,700 Malicious Packages in Unprecedented Supply Chain Attack
In early April 2026, North Korean state-sponsored hackers, identified as the Contagious Interview group, executed a sophisticated supply chain attack by publishing over 1,700 malicious packages across multiple open-source ecosystems, including npm, PyPI, Go, Rust, and PHP. These packages impersonated legitimate developer tools but functioned as malware loaders, deploying platform-specific payloads capable of data theft and remote access. The attack underscores the persistent threat to software supply chains and the need for vigilant security practices among developers and organizations. ([thehackernews.com](https://thehackernews.com/2026/04/n-korean-hackers-spread-1700-malicious.html?utm_source=openai)) This incident highlights a concerning trend of state-sponsored actors targeting open-source ecosystems to infiltrate developer environments. The scale and coordination of this attack demonstrate the evolving tactics of threat actors and the critical importance of securing software supply chains to prevent widespread compromise.
3 months ago
Kill Chain
Anthropic's Claude Mythos AI Model Uncovers Critical Software Vulnerabilities
In April 2026, Anthropic unveiled its advanced AI model, Claude Mythos, which autonomously identified thousands of high-severity vulnerabilities across major operating systems and web browsers. This unprecedented capability led to the launch of Project Glasswing, a collaborative initiative with tech giants like Amazon, Apple, and Microsoft, aiming to address these security flaws before potential exploitation. The discovery of such extensive vulnerabilities underscores the critical need for proactive cybersecurity measures in the face of rapidly advancing AI technologies. As AI models become more sophisticated, they present both opportunities for enhancing security and risks of being weaponized by malicious actors. Organizations must stay vigilant and adapt their defenses to counteract these evolving threats.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports