✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Scattered Spider's 2025 Voice Phishing Attacks: A New Era of Social Engineering
In 2025, the cybercriminal group Scattered Spider executed a series of sophisticated voice phishing attacks targeting major corporations, including technology firms and critical infrastructure providers. By impersonating employees and IT staff over the phone, they manipulated help desks into resetting credentials, granting them unauthorized access to sensitive systems. This method led to significant data breaches, operational disruptions, and financial losses for the affected organizations. The rise of such interactive phishing techniques underscores a shift in cyberattack strategies, emphasizing the exploitation of human vulnerabilities over technical exploits. As traditional phishing methods decline, the increasing prevalence of voice-based social engineering attacks highlights the need for enhanced security awareness and robust verification processes within organizations.
4 months ago
Kill Chain
VoidStealer Malware Exploits Debugger Trick to Bypass Chrome's Encryption
In March 2026, the VoidStealer malware emerged, employing a novel technique to bypass Google Chrome's Application-Bound Encryption (ABE). By utilizing hardware breakpoints, VoidStealer extracts the v20_master_key directly from the browser's memory during decryption operations, allowing it to access sensitive data such as cookies and stored passwords without requiring privilege escalation or code injection. This method represents a significant advancement in infostealer capabilities, as it circumvents security measures introduced in Chrome 127 to protect user data. The emergence of VoidStealer underscores the continuous evolution of malware tactics in response to browser security enhancements. Organizations must remain vigilant, as threat actors rapidly adapt to new defenses, developing sophisticated methods to access protected information. This incident highlights the importance of implementing comprehensive security strategies that go beyond relying solely on browser-based protections.
4 months ago
Kill Chain
Trivy Supply Chain Attack: A Wake-Up Call for Open-Source Security
In March 2026, the Trivy vulnerability scanner, a widely used open-source security tool, was compromised in a sophisticated supply chain attack orchestrated by the threat actor group known as TeamPCP. The attackers infiltrated Trivy's GitHub repository, replacing legitimate code with malicious versions in the v0.69.4 release and associated GitHub Actions. This breach led to the distribution of credential-stealing malware, which harvested sensitive information from developers' environments, including SSH keys, cloud service credentials, and database passwords. The malicious code was active for approximately three hours, during which it exfiltrated data to attacker-controlled servers. Organizations utilizing the affected versions were advised to treat their environments as fully compromised, necessitating immediate rotation of all secrets and thorough system analysis for additional breaches. This incident underscores the escalating threat posed by supply chain attacks targeting open-source ecosystems. The exploitation of trusted development tools to distribute malware highlights the critical need for enhanced security measures within software supply chains. As attackers increasingly focus on compromising widely adopted tools, organizations must implement rigorous code review processes, continuous monitoring, and robust incident response strategies to mitigate the risks associated with such attacks.
4 months ago
Kill Chain
Exploitation of Microsoft Azure Monitor in Sophisticated Phishing Attack
In March 2026, cybercriminals exploited Microsoft Azure Monitor to send phishing emails that appeared as legitimate security alerts from Microsoft. These emails, originating from azure-noreply@microsoft.com, warned recipients of unauthorized charges and urged them to call a provided phone number. By leveraging Azure Monitor's legitimate alerting system, attackers bypassed standard email security checks, making the phishing attempts more convincing. This method highlights a sophisticated abuse of trusted cloud services to execute social engineering attacks. The incident underscores the evolving tactics of threat actors who manipulate legitimate platforms to enhance the credibility of their phishing campaigns. Organizations must remain vigilant, as such techniques can lead to credential theft, financial fraud, or unauthorized access to sensitive systems.
4 months ago
Kill Chain
Trivy Supply Chain Attack Leads to CanisterWorm Infection in 47 npm Packages
In March 2026, a sophisticated supply chain attack targeted the Trivy vulnerability scanner, leading to the compromise of 47 npm packages through a self-propagating worm named CanisterWorm. The attackers infiltrated Trivy's codebase, embedding malicious code that, upon execution, harvested developer credentials and propagated itself by injecting into other npm packages. This resulted in widespread exposure of sensitive information and potential unauthorized access to numerous development environments. This incident underscores the escalating threat of supply chain attacks within the open-source ecosystem. The use of self-replicating malware like CanisterWorm highlights the need for enhanced security measures, including rigorous code audits, robust access controls, and continuous monitoring of software dependencies to mitigate the risk of similar attacks in the future.
4 months ago
Kill Chain
CISA Flags Critical Vulnerabilities in Apple, Craft CMS, and Laravel Livewire
In March 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added multiple vulnerabilities affecting Apple products, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities (KEV) catalog. Notably, CVE-2025-31277, a memory corruption issue in Apple's WebKit, was exploited by the 'DarkSword' malware, impacting over 220 million iPhones running iOS versions 18.4 through 18.7. Additionally, CVE-2025-23209, a code injection vulnerability in Craft CMS, allowed remote code execution in installations with compromised security keys. CISA mandated federal agencies to patch these vulnerabilities by April 3, 2026. The inclusion of these vulnerabilities in the KEV catalog underscores the increasing sophistication of cyber threats targeting widely-used platforms. Organizations are urged to prioritize patching to mitigate potential exploits and protect sensitive data from unauthorized access.
4 months ago
Kill Chain
Critical Unauthenticated RCE Vulnerability in Oracle Identity Manager (CVE-2025-61757)
In October 2025, Oracle disclosed a critical vulnerability (CVE-2025-61757) in Oracle Identity Manager, a key component of Oracle Fusion Middleware. This flaw, with a CVSS score of 9.8, allows unauthenticated remote code execution via HTTP, enabling attackers to fully compromise affected systems. The vulnerability arises from missing authentication checks in the REST WebServices component, permitting unauthorized access and control over the Identity Manager. ([hipaajournal.com](https://www.hipaajournal.com/critical-flaw-oracle-identity-manager-nov-2025/?utm_source=openai)) The exploitation of this vulnerability has been observed in the wild, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities catalog and mandate federal agencies to apply patches by December 12, 2025. Organizations using Oracle Identity Manager versions 12.2.1.4.0 and 14.1.2.1.0 are urged to apply the October 2025 Critical Patch Update immediately to mitigate potential risks. ([securityweek.com](https://www.securityweek.com/cisa-confirms-exploitation-of-recent-oracle-identity-manager-vulnerability/?utm_source=openai))
4 months ago
Kill Chain
Russian Hackers Exploit Signal and WhatsApp in Sophisticated Phishing Campaign
In March 2026, Dutch intelligence agencies reported a large-scale global cyber campaign by Russian state-sponsored hackers targeting Signal and WhatsApp accounts of dignitaries, military personnel, and journalists. The attackers employed social engineering techniques, such as impersonating support chatbots, to deceive users into revealing security verification codes and PINs. This allowed unauthorized access to individual accounts, enabling the interception of sensitive communications. Notably, the campaign did not exploit technical vulnerabilities within the messaging platforms themselves but rather manipulated legitimate security features through phishing tactics. ([english.aivd.nl](https://english.aivd.nl/latest/news/2026/03/09/russia-targets-signal-and-whatsapp-accounts-in-cyber-campaign?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors utilizing sophisticated social engineering methods to compromise secure communication channels. The focus on widely used encrypted messaging applications highlights the need for heightened vigilance and robust security practices among high-profile individuals and organizations to safeguard sensitive information.
4 months ago
Kill Chain
Oracle Fusion Middleware 2026 Critical RCE Vulnerability
In January 2026, Oracle disclosed a critical remote code execution (RCE) vulnerability, CVE-2026-21962, affecting Oracle Fusion Middleware components, including Oracle HTTP Server and WebLogic Server Proxy Plug-ins. This flaw allows unauthenticated attackers with network access via HTTP to compromise affected servers, potentially leading to unauthorized creation, deletion, or modification of critical data. The vulnerability impacts versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 of the affected components. Oracle released patches as part of their January 2026 Critical Patch Update to address this issue. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-21962?utm_source=openai)) The exploitation of this vulnerability underscores the persistent threat posed by unauthenticated RCE flaws in widely used enterprise software. Organizations are urged to apply the provided patches promptly to mitigate potential risks associated with this vulnerability.
4 months ago
Kill Chain
Surge in Agentic AI-Driven Retail Fraud in 2026
In early 2026, the retail industry witnessed a significant surge in AI-enabled fraud, particularly through the exploitation of agentic AI systems. Cybercriminals leveraged autonomous AI agents to conduct sophisticated scams, including deepfake customer service interactions and unauthorized transactions, leading to substantial financial losses and operational disruptions for retailers. This escalation highlighted the vulnerabilities inherent in integrating AI agents into e-commerce platforms without robust security measures. The incident underscores the urgent need for retailers to implement comprehensive AI security protocols, as the adoption of agentic AI continues to rise. With projections indicating that AI agents could handle up to 25% of e-commerce transactions by 2030, the potential for AI-driven fraud poses a growing threat to the retail sector's integrity and consumer trust.
4 months ago
Kill Chain
Ubiquiti UniFi Access Vulnerability: Unauthenticated API Exposure
In October 2025, Ubiquiti's UniFi Access Application was found to have a critical vulnerability (CVE-2025-52665) that exposed a management API without proper authentication. This flaw, present in versions 3.3.22 through 3.4.31, allowed attackers with access to the management network to gain unauthorized control over door access systems, posing significant risks to physical security. Ubiquiti addressed the issue by releasing version 4.0.21, which rectified the misconfiguration. This incident underscores the importance of promptly updating software to mitigate security vulnerabilities. Organizations are advised to review their access control systems and ensure that all applications are updated to the latest secure versions to prevent unauthorized access and potential breaches.
4 months ago
Kill Chain
North Korean IT Worker Scheme 2026: Unveiling the Insider Threat
Between September 2019 and November 2022, three U.S. nationals—Audricus Phagnasay, Jason Salazar, and Alexander Paul Travis—facilitated a scheme enabling North Korean IT workers to secure remote positions at U.S. companies. By hosting company-provided laptops and installing remote-access software, they allowed these operatives to masquerade as domestic employees. This operation led to approximately $1.28 million in salaries being funneled to North Korea, violating U.S. sanctions and compromising corporate security. ([cyberscoop.com](https://cyberscoop.com/doj-north-korea-it-worker-scheme-cases-crypto-seized/?utm_source=openai)) This incident underscores the evolving tactics of state-sponsored cyber operations, highlighting the critical need for robust identity verification and remote work security protocols to prevent similar breaches.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports