✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
GoBruteforcer Botnet Hits Crypto Projects via AI-Configured Default Credentials
In January 2026, a significant wave of GoBruteforcer botnet attacks targeted cryptocurrency and blockchain projects by exploiting misconfigured, internet-facing servers. Attackers leveraged weak default credentials in commonly used XAMPP, MySQL, PostgreSQL, FTP, and phpMyAdmin deployments—many set up using AI-generated configuration examples. After brute-forcing access, threat actors deployed web shells and specialized utilities to scan for vulnerable cryptocurrency wallets, aiming to exfiltrate crypto assets from compromised infrastructure. Over 50,000 servers were estimated at risk, with threat actors automating large-scale scans and credential spraying campaigns over public IP space. This campaign highlights a critical trend: the proliferation of weak security settings driven by widespread adoption of AI-generated setup scripts, as well as persistent use of outdated, insecure server stacks. The convergence of automation, botnet-scale brute-forcing, and blockchain-targeted payloads marks an evolution in how cybercriminals exploit configuration drift and endpoint exposure in modern DevOps environments.
6 months ago
Kill Chain
Misconfigured Email Routing Enables Sophisticated Internal Domain Phishing Attacks
In early 2026, Microsoft disclosed that threat actors exploited misconfigured email routing and insufficient spoof protections to impersonate internal organizational domains. Attackers leveraged these configuration flaws to bypass domain authentication controls, distributing phishing emails that appeared to originate from trusted internal addresses. Tactics included the use of phishing-as-a-service (PhaaS) platforms like Tycoon 2FA, resulting in credential theft and increased risk of lateral movement within affected organizations. The incident underscored systemic weaknesses in email routing setups and the importance of enforcing secure communication protocols. This attack highlights a growing trend of adversaries abusing overlooked, internal cloud and email infrastructure weaknesses to evade legacy defenses. The prevalence of PhaaS platforms has lowered the barrier for conducting sophisticated phishing campaigns, emphasizing the urgency for organizations to audit and remediate their email and domain configurations against evolving social engineering tactics.
6 months ago
Kill Chain
D-Link Legacy Routers Under Siege: CVE-2026-0625 RCE Flaw Exploited in Active Campaigns
In late 2025 and early 2026, a critical security vulnerability (CVE-2026-0625, CVSS 9.3) in legacy D-Link DSL routers was actively exploited, enabling unauthenticated remote code execution. The flaw arises from insufficient input sanitization on the dnscfg.cgi endpoint, allowing attackers to inject arbitrary shell commands and modify DNS settings remotely. As reported by VulnCheck and observed by the Shadowserver Foundation, exploitation affected end-of-life models including DSL-2740R, DSL-2640B, DSL-2780B, and DSL-526B, leading to large-scale DNS hijacking, persistent traffic redirection, and compromised user privacy and security for any device behind these routers. This incident highlights the ongoing risk posed by end-of-life and unsupported network hardware, which remains prevalent in many organizations. The swift weaponization of unauthenticated RCE vulnerabilities in edge devices—especially those lacking patch support—underscores the need for proactive infrastructure lifecycle management, supply chain visibility, and robust segmentation to defend against fast-evolving infrastructure-targeted threats.
6 months ago
Kill Chain
Veeam Backup & Replication 2026: Critical RCE Flaws and Enterprise Risk
In January 2026, Veeam disclosed and patched four critical vulnerabilities in its Backup & Replication software, with the most severe (CVE-2025-59470, CVSS 9.0) enabling remote code execution as the postgres user by authorized Backup or Tape Operators. Additional flaws allowed for RCE as root and arbitrary file writes, impacting Veeam Backup & Replication 13.0.1.180 and prior. While exploitation requires highly privileged roles, prior incidents have shown that threat actors rapidly exploit vulnerable backup platforms, risking backup integrity, ransomware proliferation, and data exfiltration. Immediate patching is essential to prevent lateral movement and data loss, per Veeam's and industry guidance. The incident underscores the ongoing risk of privilege abuse and the critical importance of timely vulnerability management in backup infrastructures, especially as threat actors increasingly target backup systems to disable recovery and amplify ransomware impacts.
6 months ago
Kill Chain
Critical 2026 n8n Vulnerability Lets Attackers Remotely Execute Code Without Credentials
In early January 2026, security researchers disclosed CVE-2026-21858 ("Ni8mare"), a critical (CVSS 10.0) vulnerability in the n8n workflow automation platform. Affecting versions up to 1.65.0, the flaw allows unauthenticated remote attackers to exploit the application's "Content-Type" processing logic, enabling arbitrary file reads and ultimately granting full system takeover by escalating to remote code execution (RCE). Attackers can leverage exposed n8n instances, retrieve sensitive admin credentials, forge session tokens, and create malicious workflows to execute system commands. Globally, over 26,000 systems were identified as potentially exposed at disclosure time, many internet-accessible, posing grave risk to organizations running n8n. This incident underscores a growing trend in supply chain and automation-tool attacks, where threat actors exploit complex integrations and insufficient access controls. The prevalence of automation platforms as central hubs for organizational secrets intensifies the impact radius. The urgent need to patch, limit internet exposure, and apply zero trust controls remains critical to prevent similar high-impact breaches.
6 months ago
Kill Chain
Critical RCE in n8n Workflow Platform Exposes Cloud & Self-Hosted Users (2026)
In January 2026, open-source workflow automation platform n8n disclosed a critical vulnerability (CVE-2026-21877) affecting both its self-hosted and cloud environments. The flaw, rated CVSS 10.0, allows authenticated users to execute arbitrary code remotely under specific conditions, potentially leading to the full compromise of affected instances. The vulnerability impacts versions >=0.123.0 and <1.121.3, and was responsibly disclosed by security researcher Théo Lelasseux. Immediate mitigation includes upgrading to version 1.121.3 or higher, and temporarily disabling certain nodes for additional protection. This incident underscores the persistent risks associated with supply chain and automation software, which are increasingly targeted due to their ubiquity and privileged access. The n8n case also reflects a trend of continuous discovery of critical flaws in widely used DevOps tooling, making timely patching and access control more important than ever.
6 months ago
Kill Chain
Black Cat SEO Poisoning Campaign Unleashes Mass Infostealer Outbreak Across China
Between December 7 and 20, 2025, the cybercrime gang Black Cat orchestrated a large-scale SEO poisoning campaign targeting Chinese users searching for popular software via Microsoft Bing and similar engines. By pushing fraudulent lookalike websites (e.g., mimicking Notepad++, Google Chrome, QQ International, iTools) to the top of search results, Black Cat tricked users into downloading compromised installers. When executed, these installers side-loaded backdoor trojans that exfiltrated sensitive information, such as browser data, keystrokes, and clipboard contents, back to attacker-controlled infrastructure. At least 277,800 hosts were infected in less than two weeks, with daily compromise rates peaking above 62,000 machines. This campaign marks a significant escalation in the use of SEO poisoning for initial malware access, reflecting a trend in highly targeted, financially motivated infostealer operations. As search engines become the go-to for software discovery, this incident strongly highlights the risks of relying on unverified download sources and demonstrates attackers' growing sophistication in exploiting user trust.
6 months ago
Kill Chain
CISA Flags New Code Injection Threats in 2026: HPE OneView & Microsoft Office Under Attack
On January 7, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation of two critical code injection vulnerabilities: CVE-2009-0556 in Microsoft Office PowerPoint and CVE-2025-37164 affecting HPE OneView. Attackers leveraged these vulnerabilities to gain unauthorized code execution, potentially enabling lateral movement and data compromise within federal and enterprise environments. The exploitation highlighted weaknesses in outdated software and emphasized the urgency for immediate remediation to safeguard sensitive systems and data across government agencies and broader sectors. The rapid addition of these vulnerabilities to CISA's KEV Catalog reflects a broader industry trend of threat actors targeting lingering, unpatched software with advanced code injection techniques. Increasing regulatory pressure and new threat intelligence underscore the need for timely vulnerability management as attackers adapt to bypass existing defenses.
6 months ago
Kill Chain
How NoName057(16) Used DDoSia to Drive Hacktivist DDoS Attacks in 2024
In early 2024, the pro-Russian hacktivist group NoName057(16) leveraged their custom DDoS tool, DDoSia, to orchestrate large-scale distributed denial-of-service attacks targeting government, media, and institutional websites in Ukraine and Western countries. By mobilizing a network of volunteer participants through its affiliate model, NoName057(16) was able to coordinate and intensify attacks, resulting in substantial website downtime and service disruptions for organizations with links to Ukraine and the West. The campaign highlighted the effectiveness of modern hacktivist crowd-sourcing tactics and the increasing difficulty of defending against well-organized, politically motivated DDoS operations. This incident is particularly relevant in 2024 as DDoS-as-a-service tools and volunteer-driven hacktivist campaigns are on the rise, blurring the lines between state-driven threats and amateur activism. Organizations should review their DDoS mitigation and incident response defenses amid heightened geopolitical tensions and expanding threat capabilities among hacktivist collectives.
6 months ago
Kill Chain
Inside the Scattered Lapsus$ Honeypot: How Researchers Turned the Tables in 2024
In early 2024, cybersecurity researchers staged a sophisticated deception operation targeting Scattered Lapsus$, also known as ShinyHunters, by deploying a realistic but fake dataset as a honeypot. The operation was designed to lure threat actors with what appeared to be sensitive credentials and data, allowing security experts to monitor the attackers' methods and behaviors in real time. Once engaged, Scattered Lapsus$ actors attempted lateral movement and data exfiltration using various covert tools and techniques, but their actions were closely tracked and documented. This resulted in a rare glimpse into the group's tactics, techniques, and procedures, as well as validation of multiple defensive controls. This incident is particularly noteworthy as it demonstrates the growing effectiveness of proactive threat intelligence gathering through deception and honeypots. With threat groups like Lapsus$ and ShinyHunters targeting high-value data across industries, similar methods are being adopted by defenders to preemptively understand and disrupt sophisticated adversaries.
6 months ago
Kill Chain
Zestix Credential Heist: 2024 Cloud Infostealer Campaign Exposes MFA Weaknesses
In early 2024, a novel threat actor known as "Zestix" orchestrated a widespread credential theft campaign targeting enterprise file-sharing environments across multiple sectors. Using advanced infostealer malware, Zestix harvested cloud credentials at scale, exploiting organizations that had not enforced multi-factor authentication (MFA). The attackers subsequently gained unauthorized access to sensitive files and regulated business data from approximately 50 companies, causing both data exfiltration and operational disruptions. The breach underlines significant weaknesses in authentication and access controls within cloud ecosystems, with impacts ranging from compromised intellectual property to potential compliance violations. The incident underscores the urgent need for robust access controls and MFA as essential defenses in today’s cloud-first environments. With identity-driven breaches rising and attackers automating large-scale infostealer campaigns, organizations face increasing regulatory and reputational pressure to modernize and enforce cloud security policies.
6 months ago
Kill Chain
Innovative Phishing Campaign Evades Detection with HTML Table-Based QR Codes
In late December 2023, a novel phishing campaign was observed in which attackers delivered emails containing QR codes crafted not from traditional images, but rendered using HTML tables. The campaign targeted end users with messages between December 22nd and December 26th, embedding visually normal but technically 'imageless' QR codes. When scanned, these QR codes redirected victims to phishing domains customized per recipient, aiming to harvest credentials. By sidestepping standard image-based security controls, these emails successfully bypassed common email security gateways designed to detect embedded malicious QR codes. This incident highlights adversary innovation in evading current email security technologies by exploiting overlooked content formats. It underscores ongoing risks as attackers adapt tactics to defeat both legacy and modern defensive controls. As sophisticated phishing methods proliferate, organizations must focus on layered defenses and continuous user education.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports