Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3611 threat reports
Page 151 of 301

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 18011812 / 3611 reports
Critical SQL Injection Vulnerability in FortiClient EMS 7.4.4
Impact· CRITICAL

Critical SQL Injection Vulnerability in FortiClient EMS 7.4.4

In February 2026, a critical SQL injection vulnerability (CVE-2026-21643) was discovered in Fortinet's FortiClient Endpoint Management Server (EMS) version 7.4.4. This flaw allows unauthenticated attackers to execute arbitrary code or commands via specially crafted HTTP requests, potentially leading to full system compromise. Fortinet promptly released version 7.4.5 to address this issue, urging all users to upgrade immediately. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-21643?utm_source=openai)) This incident underscores the persistent threat posed by SQL injection vulnerabilities, especially in widely used enterprise security solutions. Organizations are reminded of the importance of timely patch management and vigilant monitoring to mitigate such risks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AdvJudge-Zero: Unveiling Critical Vulnerabilities in AI Judge Systems
Impact· MEDIUM

AdvJudge-Zero: Unveiling Critical Vulnerabilities in AI Judge Systems

In March 2026, Palo Alto Networks' Unit 42 researchers unveiled a critical vulnerability in AI 'judge' systems, which are large language models (LLMs) employed to enforce security policies and evaluate outputs. Utilizing a tool named AdvJudge-Zero, the researchers demonstrated that these AI judges could be manipulated through stealthy input sequences, a form of prompt injection, to bypass security controls. The attack exploits the models' decision-making processes, allowing unauthorized actions without detection. This vulnerability underscores the need for robust defenses against adversarial manipulations in AI systems. The discovery highlights the growing sophistication of prompt injection attacks, emphasizing the urgency for organizations to reassess and fortify their AI security measures. As AI integration deepens across industries, understanding and mitigating such vulnerabilities becomes paramount to maintaining trust and operational integrity.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ShinyHunters' 2026 Exploitation of Salesforce Aura: A Wake-Up Call for Cloud Security
Impact· HIGH

ShinyHunters' 2026 Exploitation of Salesforce Aura: A Wake-Up Call for Cloud Security

In March 2026, the cybercriminal group ShinyHunters initiated a series of data theft attacks targeting misconfigured Salesforce Experience Cloud instances. By exploiting excessive permissions granted to guest user profiles, the attackers accessed sensitive data without authentication. Utilizing a modified version of the AuraInspector tool, they identified and exploited these vulnerabilities, compromising approximately 300 to 400 organizations, many within the cybersecurity sector. The breaches led to unauthorized access to vast amounts of customer and corporate data, raising significant concerns about data security and privacy. This incident underscores the critical importance of proper configuration and access control in cloud platforms. Organizations are urged to audit guest user permissions, adhere to the principle of least privilege, and monitor for unusual access patterns to mitigate such risks. The event highlights the evolving tactics of threat actors and the necessity for continuous vigilance in cybersecurity practices.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Google Cloud 2026: Surge in Vulnerability Exploitation
Impact· CRITICAL

Google Cloud 2026: Surge in Vulnerability Exploitation

In the latter half of 2025, Google observed a significant shift in cloud attack vectors, with 44.5% of intrusions exploiting newly disclosed vulnerabilities in third-party software, while attacks leveraging weak credentials decreased to 27%. Notably, remote code execution flaws like React2Shell (CVE-2025-55182) and the XWiki vulnerability (CVE-2025-24893) were frequently targeted, with attackers deploying cryptominers within 48 hours of vulnerability disclosure. This trend underscores the urgency for organizations to promptly patch vulnerabilities and enhance their security posture to mitigate rapid exploitation risks. The accelerated exploitation of software vulnerabilities highlights the evolving tactics of threat actors and the necessity for organizations to adopt proactive vulnerability management and robust security measures to safeguard cloud environments against emerging threats.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Chrome Extensions Compromised Post-Ownership Transfer: A 2026 Case Study
Impact· HIGH

Chrome Extensions Compromised Post-Ownership Transfer: A 2026 Case Study

In February 2026, two Google Chrome extensions, QuickLens and ShotBird, were compromised following ownership transfers. The new owners introduced malicious updates that stripped security headers from HTTP responses, enabling code injection and data theft. These updates allowed attackers to execute arbitrary JavaScript, leading to the exfiltration of sensitive user data, including credentials and browsing history. The incident underscores the risks associated with browser extension supply chains and the potential for legitimate tools to become vectors for malware distribution. This event highlights the growing trend of attackers exploiting trusted browser extensions to infiltrate systems, emphasizing the need for vigilant monitoring of software supply chains and the implementation of robust security measures to detect and prevent such compromises.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Malicious npm Package Poses as OpenClaw Installer, Deploys RAT on macOS
Impact· MEDIUM

Malicious npm Package Poses as OpenClaw Installer, Deploys RAT on macOS

In early March 2026, a malicious npm package named '@openclaw-ai/openclawai' was discovered posing as an installer for OpenClaw. Uploaded on March 3, 2026, by a user named 'openclaw-ai', the package was downloaded 178 times before detection. Upon installation, it executed a postinstall script that deployed a remote access trojan (RAT) capable of stealing sensitive data, including system credentials, browser data, cryptocurrency wallets, SSH keys, Apple Keychain databases, and iMessage history. The malware also established persistence, allowing continuous remote access and data exfiltration. This incident underscores the growing trend of supply chain attacks targeting open-source ecosystems, exploiting the trust developers place in widely-used package managers like npm. The sophistication of the attack, including social engineering tactics and advanced persistence mechanisms, highlights the urgent need for enhanced security measures in software development pipelines.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
UNC4899's $1.5 Billion Cryptocurrency Heist: Lessons for the Industry
Impact· HIGH

UNC4899's $1.5 Billion Cryptocurrency Heist: Lessons for the Industry

In February 2025, the North Korean state-sponsored hacking group UNC4899, also known as TraderTraitor, orchestrated a sophisticated cyberattack resulting in the theft of approximately $1.5 billion from the cryptocurrency exchange Bybit. The attackers compromised a developer's macOS workstation at Safe{Wallet}, a multisignature wallet platform, by deploying a malicious Docker project. This initial breach allowed them to hijack AWS session tokens, bypass multi-factor authentication, and inject malicious JavaScript into Safe{Wallet}'s application. Consequently, they manipulated a routine Ethereum transfer from Bybit's cold wallet to its hot wallet, redirecting the funds to addresses under their control. ([blog.it-expert.net](https://blog.it-expert.net/summaries/The-Feed_2025-03-10.html?utm_source=openai)) This incident underscores the escalating threat posed by state-sponsored cyber actors targeting the cryptocurrency sector. The use of advanced social engineering tactics, exploitation of cloud infrastructure vulnerabilities, and sophisticated supply chain attacks highlight the need for enhanced security measures and vigilance within the industry. ([thehackernews.com](https://thehackernews.com/2025/07/n-korean-hackers-used-job-lures-cloud.html?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
OpenClaw 2026 Supply Chain Attack: Lessons in AI Security
Impact· CRITICAL

OpenClaw 2026 Supply Chain Attack: Lessons in AI Security

In early 2026, OpenClaw, a widely adopted open-source AI assistant, became the target of a sophisticated supply chain attack. Cybercriminals infiltrated ClawHub, OpenClaw's marketplace for third-party skills, embedding 341 malicious skills among legitimate offerings. These malicious skills, often disguised as tools for crypto traders and finance professionals, were designed to steal user credentials and deploy malware upon installation. The attack exploited the trust users placed in ClawHub's ecosystem, leading to unauthorized access and data breaches. ([tech.yahoo.com](https://tech.yahoo.com/cybersecurity/articles/hackers-poison-popular-ai-assistant-171427799.html?utm_source=openai)) This incident underscores the escalating risks associated with AI assistants and their extensible platforms. As organizations increasingly integrate AI agents into their workflows, the potential for supply chain attacks grows, emphasizing the need for rigorous security assessments of third-party integrations and heightened vigilance against emerging threats.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
AirSnitch: Unveiling the 2026 Wi-Fi Vulnerability
Impact· HIGH

AirSnitch: Unveiling the 2026 Wi-Fi Vulnerability

In February 2026, researchers from the University of California, Riverside, and KU Leuven's DistriNet lab unveiled 'AirSnitch,' a novel attack that exploits fundamental flaws in Wi-Fi client isolation mechanisms. By leveraging cross-layer identity desynchronization, AirSnitch enables attackers to perform full bidirectional man-in-the-middle (MitM) attacks, allowing them to intercept and modify data between clients on the same network. This vulnerability affects a wide range of devices, including consumer routers from Netgear, Tenda, D-Link, TP-Link, and Asus, as well as enterprise hardware from Ubiquiti and Cisco. The attack is particularly concerning as it bypasses existing Wi-Fi encryption protocols without the need to crack them, posing significant risks to both home and enterprise networks. ([arstechnica.com](https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/?utm_source=openai)) The discovery of AirSnitch underscores the urgent need for standardized and robust client isolation implementations in Wi-Fi networks. As the attack exploits architectural weaknesses rather than specific software flaws, addressing this vulnerability requires coordinated efforts from hardware manufacturers, software developers, and standards organizations to enhance the security of wireless communications. ([cyberkendra.com](https://www.cyberkendra.com/2026/02/new-airsnitch-attack-bypasses-wpa2-and.html?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Cybercriminals Exploit .arpa Domains and IPv6 to Bypass Phishing Defenses
Impact· MEDIUM

Cybercriminals Exploit .arpa Domains and IPv6 to Bypass Phishing Defenses

In March 2026, cybersecurity researchers identified a sophisticated phishing campaign exploiting the .arpa top-level domain (TLD) and IPv6 reverse DNS to bypass traditional security measures. Attackers acquired IPv6 address blocks and manipulated reverse DNS zones to create deceptive subdomains under the ip6.arpa domain. These subdomains hosted phishing sites that impersonated legitimate brands, luring victims through emails promising rewards or account notifications. The use of .arpa domains, typically reserved for internet infrastructure, allowed these malicious sites to evade detection by standard domain reputation checks and email security gateways. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hackers-abuse-arpa-dns-and-ipv6-to-evade-phishing-defenses/?utm_source=openai)) This incident underscores a growing trend where threat actors exploit lesser-known internet protocols and infrastructure to conduct attacks. The abuse of reserved domains like .arpa highlights the need for enhanced monitoring and security measures that encompass all facets of the DNS ecosystem. Organizations must adapt to these evolving tactics to protect against increasingly sophisticated phishing schemes. ([infoblox.com](https://www.infoblox.com/blog/threat-intelligence/abusing-arpa-the-tld-that-isnt-supposed-to-host-anything/?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Velvet Tempest's Use of 'ClickFix' in Recent Cyber Intrusion
Impact· HIGH

Velvet Tempest's Use of 'ClickFix' in Recent Cyber Intrusion

Between February 3 and 16, 2026, the threat group Velvet Tempest (also known as DEV-0504) conducted a sophisticated cyber intrusion targeting a U.S. non-profit organization with over 3,000 endpoints and 2,500 users. Utilizing a malvertising campaign, they employed the 'ClickFix' technique, deceiving victims into executing obfuscated commands via the Windows Run dialog. This led to the deployment of DonutLoader and the CastleRAT backdoor, facilitating credential harvesting and extensive reconnaissance. Notably, while Velvet Tempest is known for deploying various ransomware strains, including Ryuk, REvil, and Conti, the Termite ransomware was not executed in this particular incident. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/termite-ransomware-breaches-linked-to-clickfix-castlerat-attacks/?utm_source=openai)) This incident underscores the evolving tactics of ransomware affiliates, highlighting the use of social engineering techniques like 'ClickFix' to gain initial access. The absence of immediate ransomware deployment suggests a strategic shift towards prolonged network infiltration and data exfiltration, posing significant challenges for detection and mitigation.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft Reports Surge in AI-Powered Cyberattacks in 2026
Impact· HIGH

Microsoft Reports Surge in AI-Powered Cyberattacks in 2026

In March 2026, Microsoft reported a significant increase in cyberattacks leveraging artificial intelligence (AI) across all stages of the attack lifecycle. Threat actors utilized generative AI tools for tasks such as reconnaissance, phishing, infrastructure development, malware creation, and post-compromise activities. Notably, North Korean groups like Jasper Sleet (Storm-0287) and Coral Sleet (Storm-1877) employed AI to craft realistic digital personas, enabling them to infiltrate Western organizations under the guise of remote IT workers. This strategic use of AI allowed attackers to accelerate operations, scale malicious activities, and lower technical barriers, resulting in more sophisticated and efficient cyberattacks. The current relevance of this incident lies in the escalating trend of AI-powered cyber threats. As AI technologies become more accessible, both state-sponsored and financially motivated actors are increasingly integrating AI into their operations. This evolution necessitates that organizations enhance their cybersecurity measures to detect and mitigate AI-driven attacks effectively.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports