✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Understanding the 'WriteOut' Vulnerability in Writer AI Platform
In July 2026, a critical session isolation vulnerability, dubbed 'WriteOut,' was discovered in Writer, an enterprise generative AI platform. This flaw allowed attackers to hijack user sessions across different organizations by exploiting the platform's live preview feature. By sharing a malicious preview link, attackers could gain unauthorized access to sensitive data, including private chats, documents, and large language model credentials, without requiring prior access to the victim's organization. ([thehackernews.com](https://thehackernews.com/2026/07/writer-ai-flaw-could-let-agent-previews.html?utm_source=openai)) The 'WriteOut' vulnerability underscores the growing security challenges in AI platforms, particularly concerning tenant isolation and session management. As AI adoption accelerates, ensuring robust security measures to prevent cross-tenant data breaches becomes imperative for organizations relying on such technologies.
2 weeks ago
Kill Chain
Understanding the 'GitLost' Vulnerability in GitHub's Agentic Workflows
In July 2026, researchers at Noma Security identified a critical vulnerability, dubbed 'GitLost,' in GitHub's Agentic Workflows. This flaw allows unauthenticated attackers to craft issues in public repositories that, when processed by AI-powered automation, can access and leak data from an organization's private repositories. The attack exploits prompt injection techniques, manipulating the AI agent into executing unintended actions, thereby exposing sensitive information without requiring stolen credentials or direct access to the organization. This incident underscores the growing risks associated with integrating AI agents into development workflows. As organizations increasingly adopt AI-driven automation, the potential for such vulnerabilities rises, emphasizing the need for robust security measures and continuous monitoring to prevent unauthorized data access and leakage.
2 weeks ago
Kill Chain
Scattered Spider Hacker Traced via Windows Device ID
In May 2025, attackers infiltrated a luxury jewelry retailer by impersonating employees and convincing the IT help desk to reset passwords and multifactor authentication devices. They gained control over three accounts, including two IT administrators, installed tunneling tools, and exfiltrated at least 77 gigabytes of data. Although the attackers attempted to deploy ransomware, the retailer's security team thwarted the effort. The attackers demanded an $8 million ransom, which the company refused to pay, resulting in approximately $2 million in losses due to disruption and remediation efforts. The incident underscores the critical importance of robust identity verification processes for IT support functions. It also highlights the necessity of implementing phishing-resistant multifactor authentication methods and continuous monitoring to detect and prevent unauthorized access attempts.
2 weeks ago
Kill Chain
FreeBSD Kernel Vulnerability CVE-2026-3038: A Critical Security Flaw
In March 2026, a critical vulnerability identified as CVE-2026-3038 was discovered in the FreeBSD kernel's rtsock_msg_buffer() function. This flaw allows unprivileged users to trigger a 127-byte stack buffer overflow, leading to immediate kernel panics by overwriting stack canaries. The vulnerability arises from improper validation of the sockaddr length field, enabling attackers to craft malicious requests that exploit this weakness. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-3038/?utm_source=openai)) The discovery of CVE-2026-3038 underscores the persistent challenges in kernel security, particularly concerning input validation and memory management. This incident highlights the necessity for continuous vigilance and prompt patching to mitigate potential exploits that could lead to system crashes or privilege escalation.
2 weeks ago
Kill Chain
Google's Legal Action Against AI-Driven Phishing: A Case Study
In June 2026, Google filed a lawsuit against a China-based cybercrime network known as 'Outsider Enterprise.' This group utilized Google's Gemini AI to create and distribute phishing websites that impersonated entities like Google, YouTube, and government agencies such as New York's E-ZPass. Operating through Telegram, Outsider Enterprise offered phishing-as-a-service, providing nearly 300 scam templates to individuals lacking technical expertise. Over a two-week period, the group sent approximately 2.5 million fraudulent text messages to Android users, leading to significant financial losses among hundreds of thousands of victims. ([arstechnica.com](https://arstechnica.com/google/2026/06/google-sues-chinese-cybercrime-network-that-used-gemini-to-automate-scams/?utm_source=openai)) This incident underscores the escalating misuse of AI technologies in cybercrime, highlighting the urgent need for enhanced security measures and regulatory frameworks to combat AI-driven phishing schemes. The collaboration between Google, the FBI, and major U.S. carriers exemplifies a proactive approach to dismantling such operations and protecting consumers from sophisticated digital threats. ([techcrunch.com](https://techcrunch.com/2026/06/12/chinese-cybercrime-operation-that-used-ai-to-scam-hundreds-of-thousands-of-victims-sued-by-google/?utm_source=openai))
2 weeks ago
Kill Chain
Sysdig Unveils First AI-Driven Ransomware Attack by JadePuffer
In late June 2026, Sysdig researchers documented the first known case of agentic ransomware, where an AI agent autonomously executed a comprehensive extortion operation. The threat actor, identified as JadePuffer, exploited a vulnerability in Langflow (CVE-2025-3248) to gain initial access, then proceeded to conduct reconnaissance, credential theft, lateral movement, persistence, encryption, and delivery of a ransom note. The AI agent's ability to rapidly adapt and execute over 600 distinct payloads significantly reduced the complexity and increased the speed of the attack, demonstrating a new level of operational efficiency in cyberattacks. ([sysdig.com](https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion?utm_source=openai)) This incident underscores the evolving landscape of cyber threats, highlighting the integration of artificial intelligence in malicious activities. The use of AI agents in cyberattacks lowers the barrier for executing sophisticated operations, posing a significant challenge for cybersecurity defenses. Organizations must adapt to these advancements by implementing robust security measures and staying vigilant against AI-driven threats.
2 weeks ago
Kill Chain
Critical Adobe ColdFusion Vulnerability CVE-2026-48282: Immediate Action Required
In July 2026, a critical vulnerability identified as CVE-2026-48282 was discovered in Adobe ColdFusion versions 2025.9, 2023.20, and earlier. This path traversal flaw allows unauthenticated attackers to execute arbitrary code remotely without user interaction, posing a significant risk to affected systems. Adobe promptly released security updates to address this issue, urging administrators to apply patches immediately. The rapid exploitation of this vulnerability underscores the increasing speed at which threat actors are leveraging newly disclosed flaws. Organizations must prioritize timely patch management and maintain robust monitoring to mitigate such risks effectively.
2 weeks ago
Kill Chain
Cybercriminals Exploit Microsoft Teams to Deploy EtherRAT Malware
In July 2026, threat actors initiated a sophisticated phishing campaign targeting corporate employees by impersonating IT support staff via Microsoft Teams voice calls. The attack began with phishing emails containing malicious PDF attachments labeled as 'Employee Survey.' Shortly after opening the document, victims received Teams calls from external accounts posing as system administrators. Exploiting Teams' screen-sharing feature, attackers convinced employees to install legitimate remote-access tools like HopToDesk and AnyDesk. Subsequently, they deployed a malicious MSI installer that downloaded and executed EtherRAT, a cross-platform remote access trojan written in Node.js, granting full control over compromised systems. EtherRAT enables attackers to execute commands, manipulate files, steal data, and maintain persistence, utilizing Ethereum smart contracts to retrieve its command-and-control server, complicating disruption efforts. This campaign underscores the evolving tactics of cybercriminals leveraging trusted communication platforms to infiltrate corporate networks. Organizations must enhance their security awareness training, implement robust authentication measures, and monitor for unusual activities within collaboration tools to mitigate such threats.
2 weeks ago
Kill Chain
Understanding the 2026 Microsoft Device Code Phishing Attack
In early 2026, a sophisticated phishing campaign exploited Microsoft's OAuth 2.0 Device Authorization Grant flow to compromise user accounts. Attackers initiated the device code authentication process and tricked victims into entering the provided code on Microsoft's legitimate login page, thereby granting unauthorized access without exposing credentials. This method allowed threat actors to bypass multi-factor authentication (MFA) and maintain persistent access to services like Outlook, OneDrive, and Teams by capturing access and refresh tokens. The campaign, active from April to mid-May 2026, targeted Microsoft 365 users through deceptive emails and malicious attachments, leading to significant data breaches and unauthorized account activities. The incident underscores a growing trend of attackers leveraging legitimate authentication mechanisms to bypass traditional security measures. The rise of device code phishing highlights the need for organizations to reassess their security protocols, especially concerning OAuth flows and MFA implementations. As phishing techniques become more sophisticated, continuous monitoring, user education, and the implementation of conditional access policies are crucial to mitigate such threats.
2 weeks ago
Kill Chain
Exploitation of Critical Gitea Docker Vulnerability CVE-2026-20896
In July 2026, threat actors began exploiting a critical vulnerability in Gitea Docker images, identified as CVE-2026-20896 with a CVSS score of 9.8. This flaw arises from the default configuration in Gitea Docker images up to version 1.26.2, which trusts the 'X-WEBAUTH-USER' header from any source IP address. Consequently, unauthenticated internet clients can gain elevated access by impersonating users, including administrators, leading to potential full system compromise. The vulnerability was patched in version 1.26.3, released in late June 2026. ([thehackernews.com](https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html?utm_source=openai)) The rapid exploitation of this vulnerability underscores the critical need for organizations to promptly apply security patches. With approximately 6,200 internet-facing Gitea instances, the risk of unauthorized access and data breaches is significant. This incident highlights the importance of vigilant monitoring and timely updates to mitigate emerging threats. ([thehackernews.com](https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html?utm_source=openai))
2 weeks ago
Kill Chain
Januscape Vulnerability: Critical KVM Flaw CVE-2026-53359
In July 2026, a critical vulnerability known as 'Januscape' (CVE-2026-53359) was disclosed in the Linux Kernel-based Virtual Machine (KVM) hypervisor. This use-after-free flaw in the shadow Memory Management Unit (MMU) code allows a guest virtual machine to corrupt the host kernel's shadow-page state, potentially leading to guest-to-host escapes on both Intel and AMD x86 systems. The vulnerability, present since August 2010, was discovered by security researcher Hyunwoo Kim and has been patched in the latest Linux kernel releases. The disclosure of Januscape underscores the persistent risks associated with long-standing vulnerabilities in widely used open-source software. It highlights the necessity for continuous code audits and timely patch management to mitigate potential exploits that could compromise multi-tenant environments and cloud infrastructures.
2 weeks ago
Kill Chain
SkillCloak: Unveiling the Evasion of Malicious AI Skills
In July 2026, researchers from the Hong Kong University of Science and Technology unveiled 'SkillCloak,' a technique enabling malicious AI agent skills to evade static scanners through self-extracting packing methods. By embedding malicious payloads within directories typically ignored by scanners, such as .git/, and reconstructing them during execution, SkillCloak achieved over 90% evasion rates across eight tested scanners. This method allows attackers to distribute harmful skills that can steal credentials, exfiltrate source code, or install backdoors, all while appearing benign during initial scans. ([thehackernews.com](https://thehackernews.com/2026/07/new-skillcloak-technique-lets-malicious.html?utm_source=openai)) The study underscores a critical vulnerability in current AI agent ecosystems, where static analysis tools fail to detect dynamically concealed threats. This highlights the urgent need for enhanced runtime behavior monitoring and the development of more robust detection mechanisms to safeguard against sophisticated evasion tactics. ([thehackernews.com](https://thehackernews.com/2026/07/new-skillcloak-technique-lets-malicious.html?utm_source=openai))
3 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports