Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3618 threat reports
Page 175 of 302

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 20892100 / 3618 reports
XWorm Malware Resurgence in 2025: Advanced Threats Unveiled
Impact· HIGH

XWorm Malware Resurgence in 2025: Advanced Threats Unveiled

In mid-2025, cybersecurity researchers identified a resurgence of the XWorm Remote Access Trojan (RAT), notably with the release of version 6.0. This variant introduced advanced plugins, enhanced persistence mechanisms, and a ransomware module, significantly increasing its threat level. Attackers distributed XWorm V6 through sophisticated phishing campaigns, utilizing malicious JavaScript droppers that executed PowerShell scripts to deliver injector DLLs. The malware's modular design allowed for extensive data theft, system control, and file encryption, posing substantial risks to organizations across various sectors. The re-emergence of XWorm underscores the evolving nature of cyber threats, highlighting the necessity for organizations to adopt proactive and adaptive cybersecurity measures. The malware's advanced evasion techniques and modular capabilities reflect a broader trend of increasingly sophisticated attack vectors, emphasizing the importance of continuous monitoring, employee training, and robust security protocols to mitigate such threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
The Rising Threat of AI-Enhanced Phishing Attacks in 2025
Impact· HIGH

The Rising Threat of AI-Enhanced Phishing Attacks in 2025

In 2025, phishing attacks surged dramatically, with over 1.35 million incidents reported between May and July alone. ([cybercrimeinfocenter.org](https://www.cybercrimeinfocenter.org/phishing-activity-quarter-over-quarter-numbers-may-july-2025?utm_source=openai)) Cybercriminals increasingly leveraged AI technologies to craft sophisticated and personalized phishing campaigns, leading to a 160% rise in credential theft. ([itpro.com](https://www.itpro.com/security/cyber-attacks/credential-theft-has-surged-160-percent-in-2025?utm_source=openai)) These attacks often exploited psychological tactics such as urgency, fear, and authority to deceive even the most vigilant individuals. The financial impact was substantial, with phishing-related breaches costing organizations an average of $4.88 million per incident. ([deepstrike.io](https://deepstrike.io/blog/Phishing-Statistics-2025?utm_source=openai)) The escalating sophistication of phishing attacks underscores the critical need for organizations to enhance their cybersecurity measures. Implementing AI-driven detection systems, conducting continuous employee training, and adopting phishing-resistant multi-factor authentication are essential steps to mitigate these evolving threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Zero-Day Vulnerabilities in Ivanti EPMM Exploited: Immediate Action Required
Impact· CRITICAL

Critical Zero-Day Vulnerabilities in Ivanti EPMM Exploited: Immediate Action Required

In January 2026, Ivanti disclosed two critical zero-day vulnerabilities, CVE-2026-1281 and CVE-2026-1340, in its Endpoint Manager Mobile (EPMM) software. Both vulnerabilities, with a CVSS score of 9.8, allow unauthenticated remote code execution. Prior to disclosure, a limited number of customers were exploited, enabling attackers to execute arbitrary commands, access sensitive data, and potentially establish persistence through web shells. Ivanti released interim patches and plans a permanent fix in version 12.8.0.0. Organizations are urged to apply patches promptly and review logs for signs of compromise. ([cyberscoop.com](https://cyberscoop.com/ivanti-endpoint-manager-mobile-zero-day-vulnerabilities-exploit/?utm_source=openai)) This incident underscores the persistent targeting of network edge devices by threat actors, highlighting the critical need for timely patch management and vigilant monitoring of security advisories to mitigate risks associated with zero-day vulnerabilities.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical React Native Metro Vulnerability Exploited in 2025
Impact· CRITICAL

Critical React Native Metro Vulnerability Exploited in 2025

In late 2025, a critical vulnerability (CVE-2025-11953) was discovered in the Metro Development Server used by React Native. This flaw allowed unauthenticated attackers to execute arbitrary OS commands on developer systems via a POST request to the server's /open-url endpoint. The vulnerability affected versions 4.8.0 through 20.0.0-alpha.2 of the @react-native-community/cli-server-api package and was patched in version 20.0.0. Exploitation was observed in December 2025 and January 2026, with attackers delivering advanced payloads on both Windows and Linux platforms, leading to potential system compromise and data exfiltration. This incident underscores the critical importance of securing development environments and promptly applying patches to known vulnerabilities. The ease of exploitation and the widespread use of React Native in the development community highlight the need for vigilant security practices to prevent similar supply-chain attacks in the future.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SolarWinds 2026 Unauthenticated RCE Vulnerability: Immediate Action Required
Impact· CRITICAL

SolarWinds 2026 Unauthenticated RCE Vulnerability: Immediate Action Required

In January 2026, a critical vulnerability (CVE-2025-40551) was discovered in SolarWinds Web Help Desk, allowing unauthenticated remote code execution due to untrusted data deserialization. This flaw enables attackers to execute arbitrary commands on affected systems without authentication, posing significant risks to organizations using this software. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-flags-critical-solarwinds-rce-flaw-as-actively-exploited/?utm_source=openai)) The exploitation of this vulnerability underscores the persistent threat posed by unpatched software vulnerabilities, emphasizing the need for organizations to maintain rigorous patch management practices to safeguard against such attacks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Notepad++ Supply Chain Attack: Lessons Learned from the 2025 Breach
Impact· HIGH

Notepad++ Supply Chain Attack: Lessons Learned from the 2025 Breach

Between June and December 2025, the Notepad++ text editor's update infrastructure was compromised by the Chinese state-sponsored hacking group Lotus Blossom. The attackers exploited vulnerabilities at the hosting provider level, redirecting update requests from targeted users to malicious servers. This allowed them to deliver a custom backdoor named Chrysalis, enabling unauthorized access to users' systems. The breach was addressed in December 2025 with the release of Notepad++ version 8.8.9, which enhanced update verification processes. ([thehackernews.com](https://thehackernews.com/2026/02/notepad-hosting-breach-attributed-to.html?utm_source=openai)) This incident underscores the growing threat of supply chain attacks, where trusted software updates are manipulated to distribute malware. Organizations must prioritize securing their software supply chains and implement robust verification mechanisms to prevent similar breaches.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Citrix NetScaler Reconnaissance Campaign Highlights Evolving Attacker Tactics
Impact· CRITICAL

Citrix NetScaler Reconnaissance Campaign Highlights Evolving Attacker Tactics

Between January 28 and February 2, 2026, a coordinated reconnaissance campaign targeted Citrix NetScaler infrastructure, utilizing over 63,000 distinct IP addresses to conduct more than 111,000 scanning sessions. Approximately 64% of this traffic originated from residential proxies, allowing attackers to masquerade as legitimate users and evade traditional security measures. The primary focus was on identifying exposed Citrix login panels and enumerating product versions, indicating a systematic effort to map vulnerable systems for potential exploitation. This incident underscores a growing trend where attackers leverage residential proxies to conduct large-scale reconnaissance, complicating detection efforts. The specific targeting of Citrix NetScaler devices suggests a heightened interest in exploiting known vulnerabilities within these systems, emphasizing the need for organizations to implement robust monitoring and timely patching strategies to mitigate such threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Step Finance's $40M Crypto Theft: A Wake-Up Call for Endpoint Security
Impact· CRITICAL

Step Finance's $40M Crypto Theft: A Wake-Up Call for Endpoint Security

In late January 2026, Step Finance, a prominent Solana-based DeFi platform, suffered a significant security breach resulting in the theft of approximately $40 million worth of digital assets. The attackers gained unauthorized access to the company's treasury wallets by compromising devices belonging to its executive team. This breach led to the unauthorized transfer of 261,854 SOL tokens, valued at around $29 million at the time, and caused the platform's native STEP token to plummet over 80% within 24 hours. ([ainvest.com](https://www.ainvest.com/news/step-finance-treasury-theft-27m-sol-outflow-step-token-collapse-2602/?utm_source=openai)) This incident underscores the critical importance of robust endpoint security measures, especially for individuals with access to substantial organizational assets. The breach highlights the growing trend of targeting high-level personnel through device compromises, emphasizing the need for comprehensive security protocols and regular audits to safeguard against such sophisticated attacks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
APT28's Operation Neusploit: Exploiting Microsoft Office Vulnerability CVE-2026-21509
Impact· HIGH

APT28's Operation Neusploit: Exploiting Microsoft Office Vulnerability CVE-2026-21509

In January 2026, the Russian state-sponsored threat actor APT28 launched 'Operation Neusploit,' targeting users in Ukraine, Slovakia, and Romania. The group exploited CVE-2026-21509, a zero-day vulnerability in Microsoft Office, by distributing malicious RTF documents via phishing emails. These documents, when opened, executed a multi-stage infection chain deploying backdoors like MiniDoor and PixyNetLoader, enabling email theft and persistent access to compromised systems. Microsoft released an emergency patch on January 26, 2026, but exploitation continued until at least January 29. This incident underscores the rapid weaponization of newly disclosed vulnerabilities by sophisticated threat actors, emphasizing the need for immediate patching and heightened vigilance against phishing campaigns.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Notepad++ 2025 Supply Chain Attack: A Wake-Up Call for Software Security
Impact· HIGH

Notepad++ 2025 Supply Chain Attack: A Wake-Up Call for Software Security

Between June and December 2025, state-sponsored attackers compromised the update infrastructure of Notepad++, a widely used text editor, by infiltrating its hosting provider. This allowed them to intercept and redirect update requests, delivering malicious executables to selectively targeted users. The attackers employed multiple infection chains, frequently altering their command-and-control infrastructure and payloads, which included reconnaissance tools and backdoors. The campaign primarily targeted organizations in East and Southeast Asia, including government and financial institutions, as well as IT service providers. The compromise was discovered in early 2026, leading to a public disclosure on February 2, 2026. In response, Notepad++ migrated to a new hosting provider and enhanced its update verification mechanisms to prevent similar attacks in the future. This incident underscores the growing sophistication of supply chain attacks, where adversaries exploit trusted software distribution channels to infiltrate targeted systems. Organizations are urged to scrutinize their software supply chains and implement robust verification processes to mitigate such risks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical RCE Vulnerability in React Native CLI Exposes Developers to Attacks
Impact· CRITICAL

Critical RCE Vulnerability in React Native CLI Exposes Developers to Attacks

In November 2025, a critical remote code execution (RCE) vulnerability, designated as CVE-2025-11953 and dubbed 'Metro4Shell,' was discovered in the '@react-native-community/cli' npm package. This package, integral to React Native development, had versions 4.8.0 through 20.0.0-alpha.2 affected. The flaw allowed unauthenticated attackers to execute arbitrary operating system commands on machines running the Metro Development Server, which binds to external interfaces by default. Exploitation was achieved by sending specially crafted POST requests to the '/open-url' endpoint, leading to potential full system compromise. The vulnerability was patched in version 20.0.0 released in October 2025. ([github.com](https://github.com/advisories/GHSA-399j-vxmf-hjvr?utm_source=openai)) The 'Metro4Shell' incident underscores the critical importance of securing development environments and the potential risks posed by exposed development servers. It highlights the necessity for developers to regularly update dependencies, configure development tools securely, and implement network access controls to prevent unauthorized access. ([csa.gov.sg](https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-104/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
DockerDash Vulnerability: A Wake-Up Call for AI Security in Development Tools
Impact· HIGH

DockerDash Vulnerability: A Wake-Up Call for AI Security in Development Tools

In November 2025, Docker addressed a critical vulnerability, dubbed 'DockerDash,' in its AI assistant, Ask Gordon. This flaw allowed attackers to embed malicious instructions within Docker image metadata, leading to remote code execution (RCE) in cloud and CLI environments, and data exfiltration in Docker Desktop setups. The attack exploited the AI's inability to distinguish between benign metadata and executable commands, enabling unauthorized actions without user consent. The incident underscores the emerging risks associated with integrating AI agents into development workflows, highlighting the need for stringent validation mechanisms to prevent similar vulnerabilities. Organizations are urged to update to Docker Desktop version 4.50.0 to mitigate this threat.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports