The Containment Era is here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3554 threat reports
Page 48 of 297

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 565576 / 3554 reports
Arch Linux AUR Compromise 2026: A Wake-Up Call for Open-Source Security
Impact· HIGH

Arch Linux AUR Compromise 2026: A Wake-Up Call for Open-Source Security

In June 2026, over 400 packages in the Arch User Repository (AUR) were compromised to distribute a Linux rootkit and infostealer malware. Attackers spoofed trusted publishers to inject malicious preinstall scripts that downloaded and executed the 'atomic-lockfile' npm package. This malware targeted sensitive information, including credentials and access tokens, and utilized eBPF rootkit capabilities to conceal its presence. The incident underscores the vulnerabilities inherent in community-maintained repositories and the critical need for stringent package verification processes. This breach highlights the escalating threat of supply chain attacks, particularly within open-source ecosystems. Organizations must enhance their security postures by implementing robust monitoring and validation mechanisms to detect and prevent such infiltrations.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Massive Compromise of Arch Linux AUR Packages Leads to Deployment of Infostealer and eBPF Rootkit
Impact· HIGH

Massive Compromise of Arch Linux AUR Packages Leads to Deployment of Infostealer and eBPF Rootkit

In June 2026, attackers compromised over 400 packages in the Arch User Repository (AUR), modifying their build scripts to deploy a Rust-based credential stealer. This malware targeted developer secrets, including browser cookies, SSH keys, and API tokens. When executed with root privileges, it could also install an eBPF rootkit to conceal its presence. The attack exploited the trust model of the AUR by adopting orphaned packages and altering their build instructions, while the package names and histories remained unchanged. This incident underscores the vulnerabilities inherent in community-maintained repositories and highlights the need for rigorous package vetting processes. The use of eBPF rootkits represents an evolution in malware techniques, emphasizing the importance of advanced detection mechanisms to identify and mitigate such sophisticated threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(low)
Read Report
China-Linked Hackers Backdoor Linux Login Systems for Nearly a Decade
Impact· MEDIUM

China-Linked Hackers Backdoor Linux Login Systems for Nearly a Decade

In June 2026, cybersecurity firm Sygnia uncovered that the China-linked threat group known as Velvet Ant had infiltrated Linux systems by backdooring the Pluggable Authentication Modules (PAM) and OpenSSH components, enabling unauthorized access and credential harvesting. This sophisticated attack, which began as early as 2016, involved replacing trusted login programs with malicious versions, allowing the attackers to maintain persistent access and evade detection. The incident underscores the evolving tactics of nation-state actors targeting critical infrastructure components that are often overlooked, highlighting the need for organizations to implement rigorous integrity checks and continuous monitoring of authentication systems to detect and mitigate such stealthy intrusions.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Google's Legal Battle Against AI-Driven Smishing Attacks
Impact· HIGH

Google's Legal Battle Against AI-Driven Smishing Attacks

In June 2026, Google initiated legal action against a Chinese cybercrime network known as 'Outsider Enterprise.' This group utilized Google's Gemini AI to create and distribute phishing-as-a-service (PhaaS) kits, enabling the generation of fraudulent websites and the dispatch of massive SMS phishing ('smishing') campaigns. These campaigns impersonated reputable brands, deceiving recipients into providing personal and financial information. The operation involved over 9,000 fake websites and more than 1 million fraudulent web domains, leading to financial losses estimated in the millions and affecting hundreds of thousands of victims. ([techcrunch.com](https://techcrunch.com/2026/06/12/google-sues-alleged-chinese-cybercrime-operation-that-used-ai-to-send-scam-texts/?utm_source=openai)) This incident underscores the escalating threat posed by cybercriminals leveraging advanced AI technologies to conduct large-scale, sophisticated phishing attacks. The use of AI in such malicious activities highlights the urgent need for enhanced security measures and regulatory frameworks to combat AI-driven cyber threats effectively.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Miasma Worm's 2026 Attack on Microsoft GitHub: A Wake-Up Call for Developers
Impact· HIGH

Miasma Worm's 2026 Attack on Microsoft GitHub: A Wake-Up Call for Developers

In June 2026, Microsoft faced a significant supply chain attack when the Miasma worm infiltrated 73 of its GitHub repositories, including those under Azure, Azure-Samples, Microsoft, and MicrosoftDocs. The attackers utilized previously compromised contributor credentials to push malicious commits, introducing configuration files that executed credential-harvesting payloads upon opening in AI coding tools or IDEs. This breach led to the temporary disabling of the affected repositories, disrupting critical workflows and CI/CD pipelines. ([computing.co.uk](https://www.computing.co.uk/news/2026/security/microsoft-s-github-repositories-taken-offline-amid-miasma-supply-chain-attack?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting trusted development environments. The Miasma worm's ability to exploit AI coding tools highlights the need for enhanced security measures in software development processes to prevent similar breaches in the future.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in Ivanti Sentry: CVE-2026-10520
Impact· CRITICAL

Critical Vulnerability in Ivanti Sentry: CVE-2026-10520

In June 2026, a critical OS command injection vulnerability, CVE-2026-10520, was identified in Ivanti Sentry versions prior to R10.5.2, R10.6.2, and R10.7.1. This flaw allows remote, unauthenticated attackers to execute arbitrary code with root privileges. Within 24 hours of disclosure, attackers exploited this vulnerability to backdoor exposed Ivanti Sentry appliances, compromising enterprise mobile gateways. ([techtimes.com](https://www.techtimes.com/articles/318221/20260611/ivanti-sentry-actively-exploited-cvss-100-flaw-backdoors-enterprise-mobile-gateways.htm?utm_source=openai)) The rapid exploitation underscores the urgency for organizations to promptly apply security patches. The availability of a public proof-of-concept exploit increases the risk of widespread attacks, emphasizing the need for immediate remediation. ([noise.getoto.net](https://noise.getoto.net/2026/06/10/cve-2026-10520-cve-2026-10523-multiple-critical-vulnerabilities-affecting-ivanti-sentry/?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Anthropic's Claude Fable 5: Balancing Advanced AI Capabilities with Security
Impact· LOW

Anthropic's Claude Fable 5: Balancing Advanced AI Capabilities with Security

In June 2026, Anthropic released Claude Fable 5, a public version of its advanced AI model, Claude Mythos 5, which was previously restricted due to security concerns. Fable 5 is designed to perform complex tasks autonomously, including software development and research. To mitigate potential misuse in sensitive areas like cybersecurity and biology, Anthropic implemented safeguards that redirect high-risk queries to a less capable model, Claude Opus 4.8. This approach aims to balance the model's powerful capabilities with safety considerations. The release of Claude Fable 5 underscores the ongoing challenge of deploying advanced AI systems responsibly. As AI models become more capable, ensuring they are used ethically and securely remains a critical concern for developers and users alike.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Phishing Attacks Decline 20% in 2026, But AI Enhances Threats
Impact· HIGH

Phishing Attacks Decline 20% in 2026, But AI Enhances Threats

In 2026, phishing attack volumes decreased by 20% for the second consecutive year. However, the sophistication and effectiveness of these attacks have significantly increased, largely due to the integration of artificial intelligence (AI) by cybercriminals. AI tools enable attackers to craft highly convincing phishing lures and automate the creation of fraudulent websites, leading to more targeted and successful campaigns. ([zscaler.com](https://www.zscaler.com/blogs/security-research/one-click-compromise-threatlabz-2026-phishing-and-initial-access-report?utm_source=openai)) This trend underscores a shift in cybercriminal strategies from mass, indiscriminate attacks to focused, high-yield operations. Organizations must recognize that while the quantity of phishing attempts has declined, the quality and potential impact of these attacks have escalated, necessitating enhanced vigilance and advanced security measures.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Europol Dismantles 'AudiA6' Crypto Laundering Service Used by Ransomware Gangs
Impact· MEDIUM

Europol Dismantles 'AudiA6' Crypto Laundering Service Used by Ransomware Gangs

In June 2026, an international law enforcement operation led by Europol dismantled 'AudiA6,' a cryptocurrency laundering service that processed over €336 million for ransomware gangs and cybercriminal networks between 2022 and 2025. The operation resulted in the arrest of two alleged administrators in Georgia, the seizure of more than 30 servers, 25 domains, over 80 vehicles, multiple properties, and the freezing of approximately €692,000 in cryptocurrency assets. 'AudiA6' was linked to over 15 international cybercrime investigations and was also associated with the dark web forum 'Dark2Web,' which facilitated illicit services and connections among cybercriminals. ([fdicoig.gov](https://www.fdicoig.gov/news/investigations-press-releases/ransomware-gangs-cut-eur-336-million-audia6-crypto-laundering?utm_source=openai)) This takedown underscores the growing industrialization of cryptocurrency laundering services that support the global cybercrime economy. The operation highlights the increasing reliance of ransomware groups on sophisticated laundering platforms to obscure illicit proceeds, emphasizing the need for enhanced international cooperation and advanced forensic capabilities to combat such threats. ([dig.watch](https://dig.watch/updates/europol-audia6-crypto-laundering-network?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical RCE Vulnerability in LangGraph: Immediate Action Required
Impact· HIGH

Critical RCE Vulnerability in LangGraph: Immediate Action Required

In February 2026, a critical remote code execution (RCE) vulnerability, identified as CVE-2026-27794, was discovered in LangGraph's caching layer. This flaw allowed attackers with write access to the cache backend to inject malicious serialized objects, leading to arbitrary code execution upon deserialization by the LangGraph process. The vulnerability affected versions of langgraph-checkpoint prior to 4.0.0 and was particularly concerning for applications utilizing cache backends inheriting from BaseCache with nodes opted into caching via CachePolicy. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-27794/?utm_source=openai)) This incident underscores the persistent risks associated with deserialization of untrusted data, especially in AI frameworks. Organizations leveraging LangGraph for AI agent orchestration must ensure they have updated to version 4.0.0 or later to mitigate this vulnerability. The event highlights the critical need for secure coding practices and regular security assessments in AI development environments.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Adds CVE-2026-10520 to Known Exploited Vulnerabilities Catalog
Impact· CRITICAL

CISA Adds CVE-2026-10520 to Known Exploited Vulnerabilities Catalog

In June 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-10520 to its Known Exploited Vulnerabilities (KEV) Catalog. This critical OS Command Injection vulnerability in Ivanti Sentry versions prior to R10.5.2, R10.6.2, and R10.7.1 allows remote unauthenticated attackers to execute code with root privileges. The flaw poses significant risks to federal enterprises and has been actively exploited in the wild. Organizations are urged to update to the patched versions immediately to mitigate potential threats. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-10520?utm_source=openai)) The inclusion of CVE-2026-10520 in the KEV Catalog underscores the ongoing threat posed by command injection vulnerabilities. This incident highlights the importance of timely patch management and proactive vulnerability assessments to prevent unauthorized access and potential data breaches.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Security Flaws Discovered in Brickcom Cameras
Impact· HIGH

Critical Security Flaws Discovered in Brickcom Cameras

In June 2026, critical vulnerabilities were identified in Brickcom cameras, specifically models Cube, Dome, Bullet, and Box version 3.2.3.5.6. These flaws, cataloged as CVE-2026-50245 and CVE-2026-50005, allow unauthenticated remote attackers to access live video feeds and still images via the /ONVIF endpoint without requiring authentication. Additionally, the use of default credentials enables silent access to camera feeds, compromising sensitive visual information and potentially granting administrative control over the devices. The exploitation of these vulnerabilities poses significant risks to sectors such as Commercial Facilities, Critical Manufacturing, Financial Services, and Healthcare, where surveillance systems are integral to security operations. The absence of authentication mechanisms in these cameras underscores the critical need for robust access controls and regular security assessments to prevent unauthorized access and data breaches.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports