✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Agentjacking: Exploiting AI Coding Agents via Sentry Vulnerability
In June 2026, Tenet Security identified a novel attack method termed 'Agentjacking,' which exploits AI coding agents by injecting malicious code through manipulated error reports in Sentry, an open-source error-tracking platform. Attackers can send crafted error events to Sentry using publicly accessible Data Source Names (DSNs), embedding commands that AI agents interpret and execute as legitimate diagnostic steps. This technique allows unauthorized code execution on developer machines, potentially exposing sensitive data such as environment variables, Git credentials, and private repository URLs. The Agentjacking attack underscores the growing security risks associated with integrating AI coding agents into development workflows. As these agents gain broader access to codebases and tools, they become attractive targets for exploitation. This incident highlights the urgent need for robust security measures and governance frameworks to manage the deployment and operation of AI agents, ensuring they do not inadvertently become vectors for cyberattacks.
1 month ago
Kill Chain
CompleteFTP 'Short-Sleeve' RSA and DSA Key Vulnerability Exposed
In June 2026, researchers identified a vulnerability in RSA and DSA key generation within the CompleteFTP software, leading to the creation of 'short-sleeve' keys with predictable zero-bit patterns. This flaw, stemming from a type mismatch in big-integer code, resulted in the generation of weak cryptographic keys that could be easily factored, compromising the security of encrypted communications. The issue affected CompleteFTP versions 10.0.0 through 23.0.4, spanning from December 2016 to December 2023. EnterpriseDT, the developers of CompleteFTP, promptly released version 26.1.0 on May 8, 2026, which includes a tool to detect and regenerate vulnerable keys. ([enterprisedt.jp](https://www.enterprisedt.jp/doc23/html/howtoserverkeys.html?utm_source=openai)) This incident underscores the critical importance of rigorous code review and adherence to cryptographic standards in software development. It also highlights the necessity for organizations to regularly audit their cryptographic implementations to identify and mitigate potential vulnerabilities that could be exploited by attackers.
1 month ago
Kill Chain
Urgent: Ivanti Sentry Vulnerability Exploited – Immediate Action Required
In June 2026, a critical OS command injection vulnerability (CVE-2026-10520) was discovered in Ivanti Sentry, formerly known as MobileIron Sentry. This flaw allows remote, unauthenticated attackers to execute arbitrary commands with root privileges on affected devices. Ivanti released patches on June 9, 2026, addressing the issue in versions R10.5.2, R10.6.2, and R10.7.1. However, within 24 hours, reports emerged of active exploitation, with attackers backdooring exposed Sentry gateways. The Shadowserver Foundation identified multiple compromised instances, indicating widespread exploitation. Organizations using Ivanti Sentry are urged to apply the patches immediately to mitigate the risk of unauthorized access and potential data breaches. This incident underscores the critical importance of timely patch management and proactive vulnerability assessments to safeguard enterprise networks against rapidly evolving threats.
1 month ago
Kill Chain
Coupang Data Breach 2025: A Wake-Up Call for E-Commerce Security
In June 2025, Coupang, South Korea's leading e-commerce platform, experienced a significant data breach that went undetected until November 2025. The breach compromised personal information of approximately 37.55 million customers, including names, email addresses, phone numbers, delivery addresses, and order histories. Investigations revealed that the breach resulted from inadequate security practices, such as poor authentication key management and insufficient access controls. This incident underscores the critical importance of robust cybersecurity measures in protecting sensitive customer data. The substantial fine imposed by South Korean authorities highlights the growing regulatory focus on data protection and the severe consequences of security lapses for organizations handling large volumes of personal information.
1 month ago
Kill Chain
International Authorities Dismantle 'AudiA6' Cryptocurrency Laundering Service
In June 2026, an international law enforcement operation dismantled 'AudiA6,' a cryptocurrency laundering service that allegedly processed over $389 million in illicit funds between 2022 and 2025. The service facilitated the laundering of proceeds from ransomware attacks and other cybercrimes by obfuscating transaction origins through complex routes, returning 'cleaned' funds to users for a commission. The operation led to the arrest of two individuals in Georgia, the seizure of 25 domains, 80 vehicles and properties, and the freezing of approximately $897,000 in cryptocurrency assets. This takedown underscores the growing global collaboration in combating cyber-enabled financial crimes and highlights the increasing scrutiny on cryptocurrency platforms used for illicit activities. Organizations are urged to enhance their monitoring of cryptocurrency transactions and implement robust compliance measures to detect and prevent money laundering activities.
1 month ago
Kill Chain
ShinyHunters Exploit Oracle PeopleSoft CVE-2026-35273 in 2026 Data Breaches
In June 2026, Oracle disclosed a critical vulnerability (CVE-2026-35273) in PeopleSoft PeopleTools versions 8.61 and 8.62, which allows unauthenticated remote code execution. The ShinyHunters cybercriminal group exploited this zero-day flaw to breach over 100 organizations, primarily in the education sector, leading to significant data theft and extortion attempts. Oracle has released emergency mitigations and is preparing a patch to address this vulnerability. This incident underscores the increasing targeting of enterprise resource planning (ERP) systems by cybercriminals, highlighting the necessity for organizations to promptly apply security updates and implement robust monitoring to detect unauthorized access attempts.
1 month ago
Kill Chain
GreatXML Exploit: A New Threat to Windows BitLocker Encryption
In June 2026, security researcher Chaotic Eclipse disclosed a zero-day vulnerability named 'GreatXML' that allows attackers to bypass Windows BitLocker encryption. The exploit leverages artifacts left by Microsoft Defender's offline scan to gain SYSTEM-level access during Recovery Mode, effectively rendering BitLocker protections ineffective. Systems that have run an offline scan are particularly vulnerable, as the exploit involves placing specific XML files in the recovery partition and rebooting into the Windows Recovery Environment. This vulnerability poses a significant risk to data security, especially for devices that have utilized Defender's offline scanning feature. ([securityweek.com](https://www.securityweek.com/greatxml-zero-day-exploit-bypasses-bitlocker/?utm_source=openai)) The disclosure of GreatXML underscores the ongoing challenges in securing endpoint devices against sophisticated attacks. It highlights the need for organizations to reassess their reliance on built-in encryption tools and to implement additional layers of security to protect sensitive data. The incident also raises concerns about the effectiveness of current vulnerability disclosure practices and the timeliness of patches for critical security flaws.
1 month ago
Kill Chain
ShinyHunters Exploit Oracle PeopleSoft Vulnerability CVE-2026-35273 in 2026
Between May 27 and June 9, 2026, the cybercriminal group ShinyHunters exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools versions 8.61 and 8.62. This critical flaw allowed unauthenticated remote code execution, leading to unauthorized access and data exfiltration from over 100 organizations, predominantly universities. The University of Nottingham confirmed a breach affecting approximately 500,000 current and former students' personal and academic records. Oracle released a security advisory on June 10, 2026, acknowledging the vulnerability and urging immediate mitigation measures. This incident underscores the escalating threat posed by sophisticated cybercriminal groups targeting enterprise software vulnerabilities, particularly in the education sector. The exploitation of zero-day vulnerabilities for large-scale data breaches highlights the urgent need for organizations to implement proactive security measures, including timely patch management and comprehensive monitoring of critical systems.
1 month ago
Kill Chain
Critical Security Flaws Discovered in OpenClaw AI Agent
In June 2026, security researchers from Imperva and Varonis identified critical vulnerabilities in OpenClaw, a widely used self-hosted AI agent. Imperva demonstrated that attackers could embed malicious instructions within shared contacts, vCards, and location pins, leading the agent to execute unauthorized code without user awareness. Varonis revealed that OpenClaw could be manipulated through standard emails to exfiltrate sensitive data, such as AWS keys and customer information, to external addresses. These findings underscore the agent's susceptibility to prompt injection attacks and its overreliance on unverified inputs, posing significant security risks to users. The rapid adoption of AI agents like OpenClaw has outpaced the development of robust security measures, highlighting the urgent need for comprehensive governance frameworks. Organizations must reassess their deployment strategies, implement stringent access controls, and ensure continuous monitoring to mitigate the risks associated with autonomous AI systems operating within their environments.
1 month ago
Kill Chain
Unveiling Cyber-Enabled Maritime Sanctions Evasion Tactics in 2026
In 2026, Iranian and Russian shadow fleet vessels, along with multiple sanctions evasion networks (SENs), utilized over 36 inauthentic websites to impersonate maritime authorities and organizations. These fraudulent sites facilitated the generation of false documents and certificates, effectively replicating key layers of the maritime compliance stack. This cyber-enabled infrastructure allowed sanctioned entities to circumvent international sanctions by creating credible but fraudulent maritime organizations, increasing the risk of due diligence failures and regulatory exposure. The emergence of such sophisticated cyber-enabled sanctions evasion tactics underscores the evolving nature of maritime compliance challenges. Organizations in the maritime and shipping sectors must integrate independent verification and cyber threat intelligence into compliance workflows to proactively identify and mitigate fraudulent online infrastructure.
1 month ago
Kill Chain
CISA's BOD 26-04: A New Era in Federal Vulnerability Management
On June 10, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive (BOD) 26-04, mandating federal agencies to adopt a risk-based approach to vulnerability remediation. This directive requires agencies to prioritize vulnerabilities based on four criteria: inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog, public exposure of the asset, potential for automated exploitation, and the level of control an attacker could gain upon successful exploitation. Vulnerabilities meeting all four criteria must be remediated within three days, while others have extended timelines or can be deferred. ([darkreading.com](https://www.darkreading.com/cyber-risk/cisa-rewrites-federal-patching-requirements-ai-threat-era?utm_source=openai))The directive reflects growing concerns about AI-driven threats accelerating the discovery and exploitation of vulnerabilities, necessitating faster remediation processes. This shift underscores the need for agencies to enhance their vulnerability management practices to keep pace with evolving cyber threats. ([darkreading.com](https://www.darkreading.com/cyber-risk/cisa-rewrites-federal-patching-requirements-ai-threat-era?utm_source=openai))
1 month ago
Kill Chain
Escalating Cyber Threats from North Korea and China Target Asia-Pacific Financial Institutions
In 2025, cyber threat groups linked to North Korea and China intensified their attacks on financial institutions and cryptocurrency assets in the Asia-Pacific region. North Korean adversaries, notably PRESSURE CHOLLIMA, executed the largest financial theft to date, stealing $1.46 billion in cryptocurrency through a supply chain compromise. Concurrently, Chinese threat actors like HOLLOW PANDA targeted financial institutions across multiple countries, including the Philippines, Indonesia, and Brazil. These operations leveraged advanced techniques, including AI-generated identities and sophisticated social engineering tactics, to infiltrate organizations and exfiltrate sensitive data. ([crowdstrike.com](https://www.crowdstrike.com/en-us/press-releases/crowdstrike-2026-financial-services-threat-landscape-report/?utm_source=openai)) The escalation of these cyber activities underscores a growing trend of state-sponsored cybercrime aimed at financial gain and intelligence collection. The increasing sophistication and frequency of these attacks highlight the urgent need for enhanced cybersecurity measures and international collaboration to protect financial infrastructures from such persistent threats.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports