✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Fake AI Coding Assistant Delivers Malware via VS Code Marketplace in 2026 Supply-Chain Attack
In January 2026, cybersecurity researchers discovered a malicious Visual Studio Code extension masquerading as "ClawdBot Agent - AI Coding Assistant" in the official VS Code Marketplace. The extension claimed to offer AI-assisted coding functionality but instead delivered a concealed malware payload to users who installed it. The attack leveraged the supply chain vector—abusing trust in a popular development marketplace—and could compromise the local development environment, providing the threat actor with unauthorized access and control over the affected system. This incident highlights the expanding risk of supply-chain attacks in developer ecosystems and raises concerns about the integrity of widely used software distribution platforms. This case underscores a rising trend of threat actors exploiting trusted software repositories to launch targeted malware campaigns. As AI coding assistants and marketplace extensions surge in popularity, organizations face mounting pressure to implement rigorous vetting and monitoring to protect software supply chains from increasingly sophisticated threats.
6 months ago
Kill Chain
SafePay 2025: Ransomware Double-Extortion Escalates Against SMBs
In late 2024 and throughout 2025, the SafePay ransomware group rapidly escalated its operations, launching a string of highly targeted double-extortion attacks against small and mid-sized businesses (SMBs), particularly in highly regulated markets such as the US and Germany. SafePay affiliates compromised victim networks via common attack vectors, exfiltrated sensitive data, and deployed ransomware to encrypt crucial assets. Victims predominantly included service-based companies lacking the resilience to handle operational downtime or public exposure. Attackers leveraged leak sites and aggressive negotiation tactics, threatening regulatory action, legal liability, and reputational damage to compel payment, creating severe business, legal, and financial impacts. This incident exemplifies a broader trend in ransomware: extortion is no longer just about encrypting files, but about exploiting regulatory frameworks and psychological leverage. The rise of fragmented ransomware ecosystems and pressure-centric extortion highlights the need for organizations to move beyond classic recovery strategies and address emerging risks such as data exposure, legal repercussions, and reputational harm.
6 months ago
Kill Chain
Stanley Malware: Chrome Web Store Defense Bypassed for Phishing – 2026 Breach Analysis
In January 2026, security researchers uncovered 'Stanley', a Malware-as-a-Service (MaaS) operation specializing in the distribution of phishing Chrome extensions designed to bypass Google’s official Chrome Web Store review process. Marketed on underground forums, Stanley provides subscribers with malicious browser extensions capable of injecting full-page phishing iframes, silently installing on Chrome, Edge, and Brave, and maintaining persistent command-and-control communication. The malware enables attackers to manipulate users’ browsing sessions while masking the true origin, collect sensitive credentials, and target victims based on IP and geography. This poses a significant risk of data theft and compromise within organizations that rely on browser-based workflows. This incident underscores the growing trend of abusing trusted extension platforms to deliver targeted phishing and credential theft at scale. The ability for criminal actors to bypass established security vetting processes presents urgent challenges for enterprise security teams and highlights the broader concern over supply chain weakness in browser ecosystems.
6 months ago
Kill Chain
Over 6,000 SmarterMail Servers Hijacked via Critical Authentication Bypass (2026)
In January 2026, over 6,000 SmarterMail servers were found exposed online and vulnerable due to a critical authentication bypass vulnerability (CVE-2026-23760). This flaw in the password reset API allowed unauthenticated attackers to reset administrator passwords, granting them full administrative access and enabling remote code execution on affected servers. Reports of in-the-wild exploitation emerged within days of public disclosure, prompting both mass, automated hijacking attacks and urgent guidance from governmental agencies. The vulnerability impacted organizations globally, particularly across North America and Asia, and posed significant risk to business continuity, privacy, and service integrity. This incident underlines rapid attacker adoption of zero-day vulnerabilities and the risks of delayed patching for internet-exposed business systems. With threat actors leveraging automation and targeting widely-used administrative interfaces, organizations must adopt faster patch cycles and stronger access controls to reduce exposure to similar authentication bypass attacks.
6 months ago
Kill Chain
US ATM Jackpotting: Tren de Aragua's Ploutus Malware Heist Exposed
In late 2025 and early 2026, US law enforcement charged 31 additional suspects in a major campaign of ATM jackpotting attacks attributed to the Venezuelan criminal gang Tren de Aragua. The attackers breached numerous ATMs across the United States, installing Ploutus malware by physically accessing internal components and deploying malware to force the machines to dispense large quantities of cash. The sophisticated attacks leveraged swapped hard drives or infected USB devices and allowed the perpetrators to launder stolen funds internationally, inflicting millions of dollars in losses on banks and credit unions. To date, over 87 individuals have been charged in this transnational criminal scheme. This incident highlights the evolving tactics of financially motivated threat groups combining physical access and technical expertise. The designation of Tren de Aragua as a Foreign Terrorist Organization underscores law enforcement’s recognition of cyber-enabled financial crime as a national security threat and signals intensified global scrutiny on such operations.
6 months ago
Kill Chain
HoneyMyte 2025 Cyberespionage Hits: Updated CoolClient and Credential Theft Campaigns
Between 2024 and 2025, the advanced persistent threat group HoneyMyte (aka Mustang Panda, Bronze President) orchestrated advanced espionage campaigns targeting government entities across Southeast Asia, Mongolia, Malaysia, Myanmar, and Europe. Using updated CoolClient backdoors, custom browser credential stealers, and sophisticated prying scripts, HoneyMyte achieved persistent access, broad network infiltration, and the theft of sensitive documents, credentials, and operational intelligence. Attackers exploited signed DLL sideloading, launched post-exploitation scripts, and used public file-sharing services for covert exfiltration, successfully bypassing traditional defense layers and maintaining long-term surveillance on official targets. This incident highlights the evolving techniques of APT campaigns with growing reliance on multi-stage malware, encrypted traffic, and cloud-based exfiltration channels. The sophistication and persistence demonstrated by HoneyMyte reflect a broader rise in state-sponsored cyber espionage, posing continuing challenges for organizations' detection and regulatory compliance efforts in 2025.
6 months ago
Kill Chain
2026 Fortinet Zero-Day SSO Breach: How Authentication Bypass Exposed Critical Devices
In January 2026, Fortinet disclosed a critical zero-day vulnerability (CVE-2026-24858) in its FortiCloud SSO authentication mechanism that allowed attackers to bypass security controls and gain unauthorized administrative access to FortiOS, FortiManager, and FortiAnalyzer devices. By leveraging rogue FortiCloud accounts, threat actors exploited an alternate authentication path—even on fully patched systems—to create new local admin and VPN-enabled accounts, exfiltrating firewall configuration data from customer environments within seconds. Fortinet mitigated active attacks by disabling vulnerable FortiCloud SSO connections and initiating global blocks before a patch was available, but over 25,000 devices were at risk during the attack window. This incident is highly relevant due to the growing sophistication and automation of supply chain and SSO-based attacks, with adversaries increasingly targeting trusted cloud management platforms. The event underscores the need for stricter access controls, rapid incident response capabilities, and heightened vigilance around identity infrastructure, especially as SAML and SSO adoption expands in modern enterprises.
6 months ago
Kill Chain
Cellbreak: Critical Grist-Core Vulnerability Enables Remote Code Execution
In January 2026, a critical vulnerability (CVE-2026-24002, codename Cellbreak, CVSS 9.1) was disclosed in Grist-Core, an open-source spreadsheet-database platform. The flaw enabled attackers to leverage malicious spreadsheet formulas for remote code execution (RCE) on self-hosted Grist-Core servers. This vulnerability could grant adversaries full foothold on affected systems, leading to potential data exfiltration, lateral movement, and operational disruption for organizations running vulnerable deployments. Security researchers at Cyera Research Labs made the discovery public after coordinated disclosure and a patch release by Grist developers. The incident is particularly relevant due to the sharp increase in attacks targeting spreadsheet and application logic vulnerabilities—especially in open-source business tools. As attackers pivot toward supply chain and SaaS entry points, control weaknesses involving user-supplied formulas and embedded code in collaborative apps persist as a high-risk vector.
6 months ago
Kill Chain
Microsoft Office 2026 Zero-Day Forces Emergency Patch After Widespread Exploitation
In January 2026, Microsoft urgently released an out-of-band security update to address a high-severity zero-day vulnerability, CVE-2026-21509, in Microsoft Office. This security feature bypass flaw allowed attackers to exploit untrusted inputs, enabling unauthorized code execution through manipulated Office documents. The active exploitation of this vulnerability led to significant exposure for organizations relying on Office, making endpoints susceptible to malware deployment and data compromise. Microsoft’s swift emergency patch was in response to in-the-wild attacks observed by security researchers and incident response teams. This incident underscores the persistent threat of zero-day exploits targeting widely used productivity platforms. Attacker tactics are evolving to bypass conventional controls, driving urgency around proactive patch management and advanced threat detection to mitigate business disruption and data loss.
6 months ago
Kill Chain
CISA Flags Five Actively Exploited Vulnerabilities in 2026 KEV Catalog Update
In January 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added five high-risk vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation. These include flaws in the Linux Kernel, SmarterTools SmarterMail, Microsoft Office, and GNU InetUtils. Threat actors exploited these vulnerabilities through methods such as authentication bypass, unrestricted file upload, security feature bypass, and argument injection, targeting both federal and private sector networks. Rapid exploitation can lead to unauthorized access, data exfiltration, or further compromise of organizational systems if not promptly remediated. This evolving threat landscape highlights an ongoing wave of opportunistic and targeted attacks leveraging widely used enterprise, email, and infrastructure software. The addition of these CVEs to the KEV Catalog underscores regulatory pressure and the increased urgency for organizations of all sizes to prioritize patch management and mitigate exposure to active threats.
6 months ago
Kill Chain
How 2024 Romance Scams Use WhatsApp Social Engineering: An Inside Look
In early 2024, security researchers investigated the initial phases of romance scams conducted over WhatsApp, where attackers use social engineering tactics to engage targets. Scammers made initial contact using 'wrong number' messages, then rapidly built rapport through flattering responses and fabricated personal stories. Over the span of several weeks, operators established credibility by sharing career details, transitioning conversations to new phone numbers, and sharing lifestyle photos to lay groundwork for future financial scams. The observed campaigns were early-stage but designed to emotionally manipulate victims for eventual financial exploitation. This incident spotlights the refined playbooks, multi-operator approaches, and psychological grooming now typical in romance scams. With surges in digital-first communication and persistent threat actor innovation, such social engineering exploits pose a significant and evolving risk to individuals and businesses alike.
6 months ago
Kill Chain
VMware vCenter RCE Flaw Actively Exploited: What Security Teams Need to Know
In January 2026, a critical vulnerability (CVE-2024-37079) in VMware vCenter Server was confirmed as actively exploited in the wild. This heap overflow flaw within the DCERPC protocol implementation enables unauthenticated remote attackers with network access to execute arbitrary code on vulnerable vCenter Server systems. The compromise does not require user interaction or elevated privileges, making attacks relatively low-effort and high-impact. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a directive mandating all federal agencies to remediate the issue within three weeks, underscoring its urgency and operational risk. No temporary mitigations exist, leaving patching as the sole defense for affected environments. This incident highlights a continued trend of attackers targeting management and orchestration layers in hybrid-cloud and virtualized infrastructures. The lack of workarounds, combined with rapid weaponization, points to increasing risks for organizations who delay patching and underlines regulatory pressure on timely remediation for critical zero-day vulnerabilities.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports