✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Amazon Bedrock AgentCore 2026 DNS Exfiltration Vulnerability
In March 2026, cybersecurity researchers identified a vulnerability in Amazon Bedrock AgentCore's Code Interpreter, allowing attackers to exfiltrate sensitive data via DNS queries. The flaw permitted outbound DNS requests from the sandbox environment, enabling unauthorized data transmission. This vulnerability underscores the critical need for robust security measures in AI code execution platforms to prevent data breaches. Organizations utilizing AI agents must implement stringent controls to mitigate such risks.
4 months ago
Kill Chain
GlassWorm Malware: A 2026 Supply Chain Attack on Developer Ecosystems
In early 2026, the GlassWorm malware resurfaced, compromising the Open VSX Registry by infiltrating trusted developer accounts. Attackers published malicious updates to widely used VS Code extensions, embedding loaders that executed encrypted payloads to steal sensitive information, including developer credentials and cryptocurrency wallets. The malware employed advanced evasion techniques, such as using invisible Unicode characters and leveraging the Solana blockchain for command-and-control communication, making detection and mitigation challenging. This incident underscores the escalating sophistication of supply chain attacks targeting developer ecosystems. The use of decentralized infrastructures and obfuscation methods highlights the need for enhanced vigilance and security measures within software development communities to prevent similar breaches.
4 months ago
Kill Chain
Wing FTP Server 2025 Information Disclosure Vulnerability: What You Need to Know
In July 2025, a medium-severity information disclosure vulnerability, identified as CVE-2025-47813, was discovered in Wing FTP Server versions 7.4.3 and earlier. This flaw allowed unauthenticated attackers to obtain sensitive information about the server's local file system by exploiting the 'loginok.html' page with a specially crafted UID cookie. The vulnerability was addressed in version 7.4.4, released on May 14, 2025. Despite the availability of a patch, many systems remained unpatched, leaving them susceptible to potential exploitation. The incident underscores the critical importance of timely software updates and robust vulnerability management practices. Organizations are urged to prioritize the remediation of known vulnerabilities to mitigate the risk of unauthorized access and data breaches.
4 months ago
Kill Chain
Iranian Cyber Threat Evolution: Exploiting MDM Platforms in 2026
In March 2026, Iranian state-sponsored cyber actors executed a large-scale attack by compromising privileged identities within cloud-based Mobile Device Management (MDM) platforms. This allowed them to issue legitimate remote-wipe commands, resulting in the simultaneous erasure of data from over 200,000 devices globally. The attack exploited administrative tools to bypass traditional endpoint detection systems, leading to significant operational disruptions across multiple organizations. This incident underscores a strategic shift in Iranian cyber operations from deploying custom malware to leveraging existing administrative infrastructures for destructive purposes. The use of legitimate management tools for widescale data destruction highlights the evolving threat landscape and the need for organizations to enhance identity and access management protocols to mitigate such risks.
4 months ago
Kill Chain
Introducing Augustus: Praetorian's Open-Source LLM Vulnerability Scanner
In February 2026, Praetorian released Augustus, an open-source vulnerability scanner designed to test Large Language Models (LLMs) against a comprehensive suite of adversarial attacks. Augustus automates over 210 distinct attack vectors, including prompt injections and jailbreaks, across 28 LLM providers. This tool addresses the growing need for robust security testing as enterprises rapidly integrate generative AI into their products. By providing a portable, single-binary solution, Augustus facilitates seamless integration into continuous integration/continuous deployment (CI/CD) pipelines, enabling security teams to identify and mitigate vulnerabilities efficiently. The release of Augustus underscores the escalating threats targeting LLMs, as adversaries increasingly exploit these models for malicious purposes. The tool's comprehensive testing capabilities highlight the necessity for organizations to proactively assess and fortify their AI systems against evolving attack methodologies.
4 months ago
Kill Chain
South Korea's NTS Security Lapse Results in $4.8M Crypto Theft
In February 2026, South Korea's National Tax Service (NTS) conducted raids on 124 high-value tax evaders, seizing digital assets worth approximately $5.6 million. During a press release showcasing the operation, the NTS inadvertently published images displaying a Ledger hardware wallet alongside a handwritten note containing the wallet's mnemonic recovery phrase. This exposure allowed an unauthorized individual to access and transfer 4 million Pre-Retogeum (PRTG) tokens, valued at about $4.8 million, from the confiscated wallet. The NTS has since apologized for the oversight and initiated measures to prevent similar incidents in the future. ([koreajoongangdaily.joins.com](https://koreajoongangdaily.joins.com/news/2026-03-01/national/socialAffairs/Police-probing-unauthorized-crypto-transfer-after-NTS-inadvertently-shared-wallet-recovery-phrase/2534349?utm_source=openai)) This incident underscores the critical importance of secure handling and storage of digital assets, especially by governmental agencies. As cryptocurrency adoption grows, ensuring robust security protocols and staff training is essential to prevent such costly errors and maintain public trust.
4 months ago
Kill Chain
Kwamaine Jerell Ford's 2026 Phishing Scheme Targets Professional Athletes
In March 2026, Kwamaine Jerell Ford, a 34-year-old from Georgia, was indicted for orchestrating a sophisticated phishing scheme targeting professional NBA and NFL athletes. While incarcerated for a similar offense, Ford allegedly impersonated an adult film star to deceive athletes into providing their iCloud credentials and multifactor authentication codes. This access enabled him to steal sensitive personal and financial information, leading to unauthorized transactions exceeding 2,000 instances between November 2020 and September 2024. The scheme also involved coercing an OnlyFans model into recording commercial sex acts with athletes without their consent, further complicating the legal ramifications. This incident underscores the persistent threat of social engineering attacks, even from individuals previously convicted of similar crimes. It highlights the critical need for continuous vigilance, robust cybersecurity measures, and comprehensive education on recognizing and mitigating phishing attempts, especially for high-profile individuals who are frequent targets.
4 months ago
Kill Chain
UK's Companies House Security Flaw Exposes Business Data - 2026
In March 2026, the UK's Companies House disclosed a significant security vulnerability in its WebFiling service, which had been present since October 2025. This flaw allowed authenticated users to access and potentially modify sensitive information of any registered company by exploiting a back-navigation loophole. The exposed data included directors' residential addresses, email addresses, and dates of birth. The agency has since rectified the issue, notified affected parties, and reported the incident to the Information Commissioner's Office (ICO) and the National Cyber Security Centre (NCSC). This incident underscores the critical importance of rigorous security testing and prompt response to vulnerabilities in public sector digital services. The exposure of personal data over an extended period raises concerns about potential misuse and the necessity for enhanced monitoring and compliance measures to protect sensitive information.
4 months ago
Kill Chain
GoPIX Banking Trojan: A New Threat to Brazil's PIX Payment System
In December 2022, the GoPIX banking Trojan emerged, targeting users of Brazil's PIX instant payment system. Disguised as a WhatsApp Web installer, it spread through malicious ads, leading victims to download malware that intercepts and manipulates PIX transactions. GoPIX employs sophisticated techniques, including IP Quality Score's anti-fraud tools, to evade detection and ensure successful infections. ([usa.kaspersky.com](https://usa.kaspersky.com/about/press-releases/kaspersky-crimeware-report-reveals-new-rhysida-ransomware-lumar-stealer-and-gopix-banking-malware?utm_source=openai)) The rise of GoPIX underscores a growing trend of cybercriminals exploiting popular payment systems in Latin America. Its advanced evasion methods and focus on real-time transaction manipulation highlight the need for enhanced security measures and user awareness to combat such evolving threats. ([usa.kaspersky.com](https://usa.kaspersky.com/about/press-releases/kaspersky-crimeware-report-reveals-new-rhysida-ransomware-lumar-stealer-and-gopix-banking-malware?utm_source=openai))
4 months ago
Kill Chain
ClickFix Campaigns Exploit AI Tool Installers to Deploy MacSync Infostealer
In late 2025 and early 2026, multiple ClickFix campaigns emerged, targeting macOS users with the MacSync infostealer. These campaigns utilized malicious Google Ads and AI-generated content to lure users into executing terminal commands that installed the malware. The MacSync infostealer is capable of exfiltrating credentials, browser data, and cryptocurrency wallet information. ([cybernews.com](https://cybernews.com/security/hackers-spread-mac-infostealer-using-google-ads/?utm_source=openai)) This incident underscores a growing trend of sophisticated social engineering attacks that exploit user trust in AI tools and search engine results. The increasing prevalence of such tactics highlights the need for heightened vigilance and user education to prevent similar breaches. ([techmonk.economictimes.indiatimes.com](https://techmonk.economictimes.indiatimes.com/news/security-alert/security-alert-clickfix-campaign-abuses-claude-artifacts-and-google-ads-to-drop-macos-infostealer/128334810?utm_source=openai))
4 months ago
Kill Chain
GlassWorm Attack 2026: A Wake-Up Call for Open-Source Security
In early 2026, the GlassWorm malware campaign exploited stolen GitHub tokens to inject malicious code into numerous Python repositories. Attackers targeted projects such as Django applications, machine learning research code, Streamlit dashboards, and PyPI packages by appending obfuscated code to files like setup.py, main.py, and app.py. This code, often concealed using invisible Unicode characters, enabled the exfiltration of sensitive data, including SSH keys, cloud credentials, and cryptocurrency wallet information. The malware's command-and-control infrastructure leveraged the Solana blockchain, complicating detection and mitigation efforts. The resurgence of GlassWorm highlights the persistent vulnerabilities within software supply chains, emphasizing the need for robust security measures in open-source ecosystems. The attack underscores the importance of vigilant monitoring and the implementation of stringent access controls to prevent unauthorized code modifications and protect sensitive information.
4 months ago
Kill Chain
Critical Chrome Zero-Day Vulnerability CVE-2026-2441 Patched
In February 2026, Google identified and patched a high-severity zero-day vulnerability in its Chrome browser, designated as CVE-2026-2441. This use-after-free flaw in the CSS component allowed attackers to execute arbitrary code by enticing users to visit maliciously crafted HTML pages. The vulnerability was actively exploited in the wild, prompting Google to release an emergency update to mitigate the risk. Users were urged to update their browsers immediately to versions 145.0.7632.75/76 for Windows and macOS, and 144.0.7559.75 for Linux. ([securityweek.com](https://www.securityweek.com/google-patches-first-actively-exploited-chrome-zero-day-of-2026/?utm_source=openai)) The exploitation of CVE-2026-2441 underscores the persistent threat posed by zero-day vulnerabilities and the importance of timely software updates. This incident highlights the need for organizations and individuals to maintain vigilant cybersecurity practices, including regular patching and monitoring for emerging threats.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports