The Containment Era is here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3529 threat reports
Page 3 of 295

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 2536 / 3529 reports
Critical Authentication Bypass in Check Point SmartConsole Exploited (CVE-2026-16232)
Impact· CRITICAL

Critical Authentication Bypass in Check Point SmartConsole Exploited (CVE-2026-16232)

In July 2026, Check Point Software identified and patched a critical authentication bypass vulnerability (CVE-2026-16232) in its SmartConsole GUI admin panel. This flaw allowed unauthenticated remote attackers to obtain an application login token, granting full administrative privileges to Security Management Servers or Multi-Domain Security Management Servers. Exploitation required the management server to be exposed to the internet without IP restrictions on Trusted Clients. Successful attacks enabled adversaries to modify security configurations and policies, posing significant risks to affected organizations. The active exploitation of this vulnerability underscores the critical importance of securing management interfaces and adhering to best practices for access control. Organizations are urged to apply the provided patches promptly and implement recommended mitigations to prevent unauthorized access and potential compromise of security infrastructure.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Chaos Ransomware's msaRAT: Concealing C2 Traffic Through Browsers
Impact· HIGH

Chaos Ransomware's msaRAT: Concealing C2 Traffic Through Browsers

In July 2026, the Chaos ransomware group deployed a new Rust-based remote access trojan (RAT) named msaRAT, which leverages Chrome and Edge browsers to conceal command-and-control (C2) communications. By initiating a headless browser session and utilizing the Chrome DevTools Protocol (CDP), msaRAT routes its C2 traffic through the browser, effectively evading traditional network detection mechanisms. This method allows the malware to execute commands and exfiltrate data without direct network connections, significantly reducing the likelihood of detection. The emergence of msaRAT underscores a growing trend among threat actors to exploit legitimate applications and protocols to mask malicious activities. This technique highlights the need for enhanced behavioral analysis and anomaly detection capabilities within cybersecurity defenses to identify and mitigate such sophisticated threats.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
RefluXFS Vulnerability: Critical Linux Kernel Flaw Grants Root Access
Impact· HIGH

RefluXFS Vulnerability: Critical Linux Kernel Flaw Grants Root Access

In July 2026, a critical vulnerability known as RefluXFS (CVE-2026-64600) was disclosed in the Linux kernel's XFS filesystem. This nine-year-old race condition allows local attackers to overwrite protected files, such as /etc/passwd or SUID-root binaries, thereby gaining root privileges. The flaw affects systems running Linux kernel version 4.11 or later with XFS filesystems where reflink is enabled—a default setting in major enterprise Linux distributions. Exploitation is highly reliable, leaves no kernel log output, and the on-disk modifications persist across reboots. ([blog.qualys.com](https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600?utm_source=openai)) The discovery of RefluXFS underscores the persistent risk posed by longstanding vulnerabilities in widely used systems. Its exploitation bypasses standard security mechanisms, highlighting the need for continuous vigilance and prompt patching in the face of evolving threats. ([blog.qualys.com](https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600?utm_source=openai))

3 days ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fake Claude App via Bing Ads Delivers SectopRAT Malware
Impact· HIGH

Fake Claude App via Bing Ads Delivers SectopRAT Malware

In July 2026, a sophisticated malvertising campaign named 'FakeAgent' exploited Bing advertisements to distribute the SectopRAT malware. Attackers created a fake Claude desktop application installer, hosted on a legitimate Claude.ai domain, which was promoted through Bing ads. Unsuspecting users searching for the Claude desktop app were redirected to this malicious installer, leading to the compromise of at least 29 organizations over a two-day period. The malware, SectopRAT, is a remote access trojan with information-stealing capabilities, allowing attackers to exfiltrate sensitive data and maintain persistent access to infected systems. This incident underscores the evolving tactics of cybercriminals who leverage legitimate platforms and advertising services to disseminate malware. The use of authentic domains and sophisticated social engineering techniques highlights the need for heightened vigilance among users and organizations. It also emphasizes the importance of downloading software exclusively from official and verified sources to mitigate the risk of such deceptive attacks.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Dolphin X Malware: AI-Powered Threat Targeting High-Value Victims
Impact· HIGH

Dolphin X Malware: AI-Powered Threat Targeting High-Value Victims

In July 2026, cybersecurity researchers identified 'Dolphin X,' a sophisticated Windows-based remote access trojan (RAT) and infostealer. This malware targets over 300 applications, including browsers, cryptocurrency wallets, password managers, and cloud command-line tools. Notably, Dolphin X incorporates an AI-powered profiling system that analyzes infected systems' application usage, browsing history, and installed software to assign risk scores. These scores enable attackers to prioritize high-value targets, such as developers with access to sensitive cloud production environments. The malware is marketed on cybercrime forums under a malware-as-a-service model, with subscription tiers offering varying levels of obfuscation and feature sets. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-dolphin-x-malware-uses-ai-to-rank-high-value-targets/?utm_source=openai)) The emergence of Dolphin X underscores a concerning trend: the integration of artificial intelligence into cybercriminal tools to enhance operational efficiency and target selection. This development highlights the need for organizations to bolster their cybersecurity defenses, particularly in protecting developer workstations and sensitive credentials, to mitigate the risks posed by such advanced threats.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Russian Espionage Group Exploits Zimbra Zero-Day Vulnerability
Impact· MEDIUM

Russian Espionage Group Exploits Zimbra Zero-Day Vulnerability

In July 2025, the Russian state-sponsored threat group known as Laundry Bear initiated a sophisticated cyber-espionage campaign targeting Western government and commercial organizations. By exploiting a zero-day vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite's webmail client, the attackers deployed a 'view-based exploit' that activated upon merely viewing a malicious email. This allowed them to exfiltrate sensitive data, including recent emails, entire email directories, browser-saved passwords, and two-factor authentication recovery codes. The vulnerability was patched in November 2025, but unpatched systems remain at risk. ([nsa.gov](https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4553352/nsa-and-partners-alert-zimbra-collaboration-suite-users-of-a-russian-state-supp/?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors exploiting zero-day vulnerabilities. The use of 'zero-click' exploits, which require no user interaction beyond viewing an email, highlights the evolving sophistication of cyber threats and the critical need for timely patch management and robust cybersecurity measures. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/russian-hackers-zimbra-zero-day-us-ukraine-targets?utm_source=openai))

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Origin Energy Data Breach: A Wake-Up Call for Critical Infrastructure Security
Impact· HIGH

Origin Energy Data Breach: A Wake-Up Call for Critical Infrastructure Security

In July 2026, Origin Energy, Australia's largest energy retailer, confirmed a data breach involving unauthorized access to customer information. The compromised data includes names, addresses, dates of birth, contact numbers, account details, and partial financial information (last four digits of credit cards or last three digits of bank accounts). The company is working to determine the total number of affected customers and has engaged with the Australian Cyber Security Centre, the Australian Federal Police, and the Office of the Australian Information Commissioner to investigate the incident. ([originenergy.com.au](https://www.originenergy.com.au/about/investors-media/update-on-data-security-incident/?utm_source=openai)) This breach underscores the escalating threat of cyberattacks targeting critical infrastructure sectors. The exposure of personal information increases the risk of identity theft and sophisticated phishing scams, particularly with the rise of AI-driven cybercrime. Organizations must enhance their cybersecurity measures to protect sensitive customer data and maintain public trust. ([abc.net.au](https://www.abc.net.au/news/2026-07-24/origin-breach-could-fuel-wave-of-ai-powered-scams/106951588?utm_source=openai))

3 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
TAG-195's Modular Malware: A New Era in Cyber Threats
Impact· MEDIUM

TAG-195's Modular Malware: A New Era in Cyber Threats

In July 2026, Insikt Group identified four new malware families—TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and ChromEggscalator—developed by TAG-195, also known as "Golden Chickens" or "Venom Spider." These developments signify a strategic shift towards modular, operator-driven tools within the TAG-195 malware-as-a-service (MaaS) ecosystem. The modularized ChonkyChicken variant employs a controller-and-plugin architecture, allowing the base implant to dynamically load specific capability modules from attacker-controlled infrastructure, thereby reducing its static detection footprint. All four malware families exhibit consistent command-and-control mechanisms, shared persistence methods, string obfuscation, and execution via legitimate Windows binaries. This evolution underscores TAG-195's commitment to enhancing the adaptability and stealth of its offerings, catering to a diverse range of operational requirements. The emergence of these advanced, modular malware families highlights the ongoing sophistication of MaaS providers and the necessity for organizations to bolster their detection and response strategies against such evolving threats.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
LummaStealer's 2026 Resurgence: The Role of CastleLoader and ClickFix Techniques
Impact· LOW

LummaStealer's 2026 Resurgence: The Role of CastleLoader and ClickFix Techniques

Between December 2025 and January 2026, cybersecurity researchers observed a significant resurgence of LummaStealer infections, facilitated by the deployment of CastleLoader malware through sophisticated ClickFix social engineering techniques. Attackers lured victims to malicious websites mimicking legitimate services, where fake CAPTCHA verifications tricked users into executing malicious PowerShell commands. These commands installed CastleLoader, which subsequently delivered LummaStealer, an infostealer targeting sensitive data such as credentials, cryptocurrency wallets, and session cookies. This campaign marked a notable evolution in malware delivery methods, combining advanced loaders with deceptive social engineering tactics to bypass traditional security measures. The resurgence of LummaStealer, despite previous law enforcement disruptions, underscores the adaptability and persistence of cybercriminals. The use of CastleLoader and ClickFix techniques highlights a trend towards more sophisticated and deceptive attack vectors, emphasizing the need for continuous vigilance and advanced security protocols to protect sensitive information.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
SANDWORM_MODE: Unveiling the npm Supply Chain Attack on AI Development Tools
Impact· HIGH

SANDWORM_MODE: Unveiling the npm Supply Chain Attack on AI Development Tools

In February 2026, the SANDWORM_MODE malware campaign targeted the npm ecosystem by distributing 19 typosquatted packages under aliases 'official334' and 'javaorg'. Upon installation, these packages executed a multi-stage attack: initially harvesting developer credentials and environment variables, followed by deploying a malicious MCP server to compromise AI coding assistants. The malware propagated by injecting itself into GitHub repositories and CI/CD pipelines, exfiltrating sensitive data, and, if thwarted, activating a destructive fallback to erase user files. ([crowdstrike.com](https://www.crowdstrike.com/en-us/blog/denying-the-worm-sandworm-mode-and-ai-toolchain-supply-chain-attacks/?utm_source=openai)) This incident underscores the escalating sophistication of supply chain attacks, particularly those exploiting AI development tools. Organizations must enhance their security measures to detect and prevent such multi-faceted threats that blend into legitimate development workflows.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Flaws in Microsoft's Passkey Implementation Uncovered
Impact· MEDIUM

Critical Flaws in Microsoft's Passkey Implementation Uncovered

In July 2026, security researchers identified critical vulnerabilities in Microsoft's passkey implementation within Windows 11 and Microsoft Entra ID. These flaws allowed attackers to exploit weaknesses reminiscent of traditional password attacks, enabling them to impersonate privileged users and bypass phishing-resistant multifactor authentication. The vulnerabilities were disclosed to Microsoft, which subsequently released patches to address the issues. This incident underscores the importance of thorough implementation and validation of security protocols, even when adopting advanced authentication methods like passkeys. Organizations must remain vigilant, ensuring that new technologies are deployed securely to prevent exploitation by threat actors.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Lampion Banking Trojan Resurfaces in Portugal: A 2026 Threat Analysis
Impact· MEDIUM

Lampion Banking Trojan Resurfaces in Portugal: A 2026 Threat Analysis

In July 2026, the Brazilian banking Trojan known as Lampion was identified in an active campaign targeting Portuguese users. The malware is disseminated through phishing emails that masquerade as financial and administrative communications, leading recipients to download malicious ZIP files. Once executed, Lampion establishes persistence, connects to a remote command-and-control server, and can inject overlays into banking websites to steal credentials. This campaign has resulted in significant data breaches and financial losses for affected individuals and organizations. The resurgence of Lampion underscores the persistent threat posed by banking Trojans, especially those leveraging social engineering tactics. Organizations must remain vigilant, as attackers continue to exploit language and cultural similarities to enhance the effectiveness of their campaigns.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports