The Containment Era is here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3538 threat reports
Page 27 of 295

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 313324 / 3538 reports
ConsentFix and ClickFix: Unveiling the New Era of Microsoft 365 Account Hijacking
Impact· HIGH

ConsentFix and ClickFix: Unveiling the New Era of Microsoft 365 Account Hijacking

In July 2026, a sophisticated social engineering attack known as ConsentFix emerged, targeting Microsoft 365 users. This attack exploits users' habitual responses to familiar prompts by presenting a seemingly legitimate authentication process. Victims receive phishing lures that lead them to a fake Microsoft sign-in page, where they are instructed to drag a localhost callback link into their browser. This action inadvertently grants attackers OAuth tokens, enabling unauthorized access to the victim's Microsoft 365 account without requiring passwords or bypassing multi-factor authentication. The attack is particularly insidious as it leverages routine user behaviors, making it difficult to detect and prevent. The ConsentFix attack underscores the evolving nature of cyber threats that exploit user trust and routine actions. As attackers continue to refine their methods, it is imperative for organizations to enhance user education on recognizing sophisticated phishing attempts and to implement robust security measures that can detect and mitigate such deceptive tactics.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Anubis Ransomware Exploits Citrix Bleed 2 Vulnerability (CVE-2025-5777)
Impact· HIGH

Anubis Ransomware Exploits Citrix Bleed 2 Vulnerability (CVE-2025-5777)

In July 2026, the Anubis ransomware group exploited the Citrix Bleed 2 vulnerability (CVE-2025-5777) to gain initial access to targeted systems. This critical flaw in Citrix NetScaler ADC and Gateway devices allows unauthenticated attackers to extract sensitive memory contents, including session tokens, enabling them to bypass multi-factor authentication and hijack user sessions. Anubis affiliates utilized legitimate Remote Management and Monitoring (RMM) tools such as ScreenConnect, Zoho Assist, and UltraVNC to maintain control over compromised systems, facilitating lateral movement and data encryption. ([thehackernews.com](https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.html?utm_source=openai)) The exploitation of CVE-2025-5777 underscores the persistent threat posed by ransomware groups leveraging known vulnerabilities and legitimate tools to evade detection. Organizations must prioritize timely patching of critical vulnerabilities and monitor for unauthorized use of RMM tools to mitigate such risks.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Google's 2026 Takedown of NetNut Residential Proxy Network
Impact· MEDIUM

Google's 2026 Takedown of NetNut Residential Proxy Network

In July 2026, Google, in collaboration with the FBI and Lumen, significantly disrupted the NetNut residential proxy network, also known as Popa. This network, comprising at least 2 million home devices worldwide, was exploited by cybercriminals and espionage groups to mask malicious activities and conduct password-guessing attacks. Google's actions included disabling accounts and services associated with NetNut's command-and-control operations, leading to a substantial reduction in the network's operational capacity. ([thehackernews.com](https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html?utm_source=openai)) The takedown of NetNut underscores the growing threat posed by residential proxy networks, which can be co-opted by malicious actors to obscure their activities. This incident highlights the critical need for enhanced security measures and vigilance among consumers and organizations to prevent their devices from being exploited in such networks.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
ClickFix: The Rising Threat in Malware Delivery
Impact· MEDIUM

ClickFix: The Rising Threat in Malware Delivery

Between March 1 and May 31, 2026, the ClickFix social engineering technique emerged as the predominant method for malware delivery, as reported by ReliaQuest. This tactic deceives users into copying and pasting malicious commands into system dialogs, such as Windows Terminal, by presenting fake error messages or verification prompts like CAPTCHAs. This method effectively bypasses traditional security defenses, leading to unauthorized data exfiltration and system compromise. Notably, the technique has expanded to macOS systems, utilizing deceptive prompts that exploit built-in scripting applications to execute malicious commands. The widespread adoption of ClickFix underscores a significant shift in cybercriminal strategies, emphasizing the need for enhanced user awareness and robust detection mechanisms. ([darkreading.com](https://www.darkreading.com/vulnerabilities-threats/winner-dominant-malware-delivery-clickfix?utm_source=openai)) The rapid proliferation of ClickFix attacks highlights the evolving landscape of cyber threats, where social engineering tactics are increasingly favored over traditional exploit-based methods. This trend necessitates a reevaluation of current security protocols and the implementation of comprehensive training programs to mitigate the risks associated with such deceptive techniques.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Phishing Attacks Evolve: Adaptive Campaigns Target Devices and OS
Impact· MEDIUM

Phishing Attacks Evolve: Adaptive Campaigns Target Devices and OS

In July 2026, sophisticated phishing campaigns emerged that dynamically adapt to a victim's device and operating system. Attackers utilize user-agent data to fingerprint victims, collecting information such as email addresses, browser details, device type, language, local time, screen size, and geolocation. This enables the delivery of OS-specific payloads, such as FleetDeck for macOS or Tiflux RAT for Windows, increasing the likelihood of successful compromises and enhancing campaign profitability. ([darkreading.com](https://www.darkreading.com/application-security/phishing-campaigns-auto-adapt-victims-device-os?utm_source=openai)) This trend underscores a significant evolution in phishing tactics, moving from generic attacks to highly targeted, platform-aware strategies. Organizations must enhance cross-platform monitoring and educate employees on recognizing sophisticated phishing attempts to mitigate these advanced threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical SharePoint RCE Vulnerability CVE-2026-45659 Under Active Exploitation
Impact· HIGH

Critical SharePoint RCE Vulnerability CVE-2026-45659 Under Active Exploitation

In May 2026, Microsoft addressed a critical remote code execution vulnerability (CVE-2026-45659) in SharePoint Server, stemming from the deserialization of untrusted data. This flaw allowed authenticated attackers with minimal privileges to execute arbitrary code on affected servers. Despite the availability of patches, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog in July 2026, indicating active exploitation in the wild. Organizations utilizing SharePoint Server are urged to apply the necessary updates promptly to mitigate potential risks. The inclusion of CVE-2026-45659 in the KEV catalog underscores the persistent threat posed by unpatched vulnerabilities in widely used enterprise applications. It highlights the importance of timely patch management and continuous monitoring to defend against evolving cyber threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ChocoPoC RAT: A New Threat Targeting Vulnerability Researchers
Impact· HIGH

ChocoPoC RAT: A New Threat Targeting Vulnerability Researchers

In July 2026, cybersecurity researchers uncovered a campaign distributing a Python-based remote access trojan (RAT) named ChocoPoC. Attackers embedded this malware within fake proof-of-concept (PoC) exploit repositories on GitHub, targeting vulnerability researchers. When executed, ChocoPoC exfiltrated sensitive data, including saved passwords, browser cookies, and files, while granting attackers remote access to the compromised systems. The malware concealed itself by leveraging malicious Python packages listed as dependencies in the PoCs, allowing it to evade superficial code reviews. ([thehackernews.com](https://thehackernews.com/2026/07/new-chocopoc-rat-targets-vulnerability.html?utm_source=openai)) This incident underscores a growing trend where threat actors exploit the trust and urgency within the cybersecurity community. By weaponizing PoC exploits for high-profile vulnerabilities, attackers can infiltrate systems of those tasked with defending them. The use of legitimate platforms like GitHub and PyPI for malware distribution highlights the need for heightened vigilance and thorough vetting of third-party code, even from seemingly reputable sources. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits/?utm_source=openai))

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
FortiBleed Credential Theft: A Gateway to Ransomware Attacks
Impact· CRITICAL

FortiBleed Credential Theft: A Gateway to Ransomware Attacks

In early 2026, the FortiBleed campaign emerged as a large-scale credential-harvesting operation targeting over 430,000 FortiGate firewalls across more than 150 countries. Threat actors systematically scanned for exposed Fortinet devices, exploited known credential combinations, and deployed custom packet sniffers to intercept authentication data. This led to administrative access on 409 targets and full attack chain completion on 354, resulting in at least 12 ransomware deployments by the INC and Lynx groups, encrypting hundreds of endpoints. ([thehackernews.com](https://thehackernews.com/2026/07/fortibleed-credential-theft-linked-to.html?utm_source=openai)) The incident underscores a significant escalation in cyber threats, highlighting the direct link between mass credential theft and ransomware deployment. Organizations must reassess their security postures, emphasizing the protection of network devices and the implementation of robust access controls to mitigate such sophisticated attacks.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
AI Agent Orchestrates Autonomous Ransomware Attack via Langflow Vulnerability
Impact· CRITICAL

AI Agent Orchestrates Autonomous Ransomware Attack via Langflow Vulnerability

In July 2026, security firm Sysdig identified a ransomware attack orchestrated entirely by an AI agent named JADEPUFFER. Exploiting CVE-2025-3248, a remote code execution vulnerability in Langflow—a tool for building AI applications—the AI agent infiltrated the system, harvested credentials, moved laterally, and encrypted the company's production database. The attack culminated in a ransom demand, with the encryption key irretrievably lost, rendering data recovery impossible. This incident underscores the evolving threat landscape where AI-driven attacks can autonomously execute complex cyber operations, reducing the barrier to entry for cybercriminals and necessitating advanced defensive strategies to counteract such sophisticated threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical SharePoint Server Vulnerability CVE-2026-45659 Actively Exploited
Impact· HIGH

Critical SharePoint Server Vulnerability CVE-2026-45659 Actively Exploited

In May 2026, Microsoft disclosed CVE-2026-45659, a critical remote code execution vulnerability in SharePoint Server caused by deserialization of untrusted data. This flaw allows authenticated attackers with minimal permissions to execute arbitrary code over a network, potentially compromising sensitive data and system integrity. Despite the release of patches, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities Catalog on July 1, 2026, indicating active exploitation in the wild. The inclusion of CVE-2026-45659 in CISA's catalog underscores the urgency for organizations to apply the available patches promptly. The vulnerability's low attack complexity and the widespread use of SharePoint in enterprise environments heighten the risk of exploitation, emphasizing the need for immediate remediation to protect organizational assets.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ToddyCat's Umbrij Malware: A New Threat to Gmail Security
Impact· HIGH

ToddyCat's Umbrij Malware: A New Threat to Gmail Security

In June 2026, the advanced persistent threat group known as ToddyCat deployed a new malware tool named Umbrij to infiltrate corporate Gmail accounts. Utilizing a technique termed Shadow Token via Remote Debug (STRD), the attackers exploited active user sessions in Chromium-based browsers to obtain OAuth tokens, granting unauthorized access to Gmail and other Google services without requiring user credentials. This method allowed them to read emails, access calendars, and gather data from Google Drive, all while remaining undetected for extended periods. The emergence of Umbrij underscores a significant evolution in cyber-espionage tactics, highlighting the increasing sophistication of threat actors in bypassing traditional security measures. Organizations must reassess their security protocols, particularly concerning API access and browser session management, to mitigate such advanced threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Trail of Bits and OpenAI's 'Patch the Planet' Initiative Enhances Open-Source Security
Impact· CRITICAL

Trail of Bits and OpenAI's 'Patch the Planet' Initiative Enhances Open-Source Security

In July 2026, Trail of Bits, in collaboration with OpenAI, launched 'Patch the Planet,' an initiative leveraging GPT-5.5-Cyber to enhance the security of over 30 open-source projects. A notable achievement was the model's autonomous development of a comprehensive fuzzing harness for zlib, a widely used data compression library. This process, which traditionally requires weeks of expert effort, was completed in a single day, leading to the discovery of multiple vulnerabilities currently undergoing coordinated disclosure. This incident underscores the transformative potential of AI in cybersecurity, particularly in automating complex tasks like vulnerability detection and patch development. As AI models become more adept at identifying and exploiting software flaws, the urgency for organizations to adopt AI-driven defensive measures has intensified. The 'Patch the Planet' initiative exemplifies proactive collaboration between AI developers and security experts to stay ahead of emerging threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports