The Containment Era is here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3554 threat reports
Page 49 of 297

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 577588 / 3554 reports
Agentjacking: Exploiting AI Coding Agents via Sentry Vulnerability
Impact· HIGH

Agentjacking: Exploiting AI Coding Agents via Sentry Vulnerability

In June 2026, Tenet Security identified a novel attack method termed 'Agentjacking,' which exploits AI coding agents by injecting malicious code through manipulated error reports in Sentry, an open-source error-tracking platform. Attackers can send crafted error events to Sentry using publicly accessible Data Source Names (DSNs), embedding commands that AI agents interpret and execute as legitimate diagnostic steps. This technique allows unauthorized code execution on developer machines, potentially exposing sensitive data such as environment variables, Git credentials, and private repository URLs. The Agentjacking attack underscores the growing security risks associated with integrating AI coding agents into development workflows. As these agents gain broader access to codebases and tools, they become attractive targets for exploitation. This incident highlights the urgent need for robust security measures and governance frameworks to manage the deployment and operation of AI agents, ensuring they do not inadvertently become vectors for cyberattacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CompleteFTP 'Short-Sleeve' RSA and DSA Key Vulnerability Exposed
Impact· CRITICAL

CompleteFTP 'Short-Sleeve' RSA and DSA Key Vulnerability Exposed

In June 2026, researchers identified a vulnerability in RSA and DSA key generation within the CompleteFTP software, leading to the creation of 'short-sleeve' keys with predictable zero-bit patterns. This flaw, stemming from a type mismatch in big-integer code, resulted in the generation of weak cryptographic keys that could be easily factored, compromising the security of encrypted communications. The issue affected CompleteFTP versions 10.0.0 through 23.0.4, spanning from December 2016 to December 2023. EnterpriseDT, the developers of CompleteFTP, promptly released version 26.1.0 on May 8, 2026, which includes a tool to detect and regenerate vulnerable keys. ([enterprisedt.jp](https://www.enterprisedt.jp/doc23/html/howtoserverkeys.html?utm_source=openai)) This incident underscores the critical importance of rigorous code review and adherence to cryptographic standards in software development. It also highlights the necessity for organizations to regularly audit their cryptographic implementations to identify and mitigate potential vulnerabilities that could be exploited by attackers.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Urgent: Ivanti Sentry Vulnerability Exploited – Immediate Action Required
Impact· CRITICAL

Urgent: Ivanti Sentry Vulnerability Exploited – Immediate Action Required

In June 2026, a critical OS command injection vulnerability (CVE-2026-10520) was discovered in Ivanti Sentry, formerly known as MobileIron Sentry. This flaw allows remote, unauthenticated attackers to execute arbitrary commands with root privileges on affected devices. Ivanti released patches on June 9, 2026, addressing the issue in versions R10.5.2, R10.6.2, and R10.7.1. However, within 24 hours, reports emerged of active exploitation, with attackers backdooring exposed Sentry gateways. The Shadowserver Foundation identified multiple compromised instances, indicating widespread exploitation. Organizations using Ivanti Sentry are urged to apply the patches immediately to mitigate the risk of unauthorized access and potential data breaches. This incident underscores the critical importance of timely patch management and proactive vulnerability assessments to safeguard enterprise networks against rapidly evolving threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Coupang Data Breach 2025: A Wake-Up Call for E-Commerce Security
Impact· CRITICAL

Coupang Data Breach 2025: A Wake-Up Call for E-Commerce Security

In June 2025, Coupang, South Korea's leading e-commerce platform, experienced a significant data breach that went undetected until November 2025. The breach compromised personal information of approximately 37.55 million customers, including names, email addresses, phone numbers, delivery addresses, and order histories. Investigations revealed that the breach resulted from inadequate security practices, such as poor authentication key management and insufficient access controls. This incident underscores the critical importance of robust cybersecurity measures in protecting sensitive customer data. The substantial fine imposed by South Korean authorities highlights the growing regulatory focus on data protection and the severe consequences of security lapses for organizations handling large volumes of personal information.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
International Authorities Dismantle 'AudiA6' Cryptocurrency Laundering Service
Impact· HIGH

International Authorities Dismantle 'AudiA6' Cryptocurrency Laundering Service

In June 2026, an international law enforcement operation dismantled 'AudiA6,' a cryptocurrency laundering service that allegedly processed over $389 million in illicit funds between 2022 and 2025. The service facilitated the laundering of proceeds from ransomware attacks and other cybercrimes by obfuscating transaction origins through complex routes, returning 'cleaned' funds to users for a commission. The operation led to the arrest of two individuals in Georgia, the seizure of 25 domains, 80 vehicles and properties, and the freezing of approximately $897,000 in cryptocurrency assets. This takedown underscores the growing global collaboration in combating cyber-enabled financial crimes and highlights the increasing scrutiny on cryptocurrency platforms used for illicit activities. Organizations are urged to enhance their monitoring of cryptocurrency transactions and implement robust compliance measures to detect and prevent money laundering activities.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
ShinyHunters Exploit Oracle PeopleSoft CVE-2026-35273 in 2026 Data Breaches
Impact· CRITICAL

ShinyHunters Exploit Oracle PeopleSoft CVE-2026-35273 in 2026 Data Breaches

In June 2026, Oracle disclosed a critical vulnerability (CVE-2026-35273) in PeopleSoft PeopleTools versions 8.61 and 8.62, which allows unauthenticated remote code execution. The ShinyHunters cybercriminal group exploited this zero-day flaw to breach over 100 organizations, primarily in the education sector, leading to significant data theft and extortion attempts. Oracle has released emergency mitigations and is preparing a patch to address this vulnerability. This incident underscores the increasing targeting of enterprise resource planning (ERP) systems by cybercriminals, highlighting the necessity for organizations to promptly apply security updates and implement robust monitoring to detect unauthorized access attempts.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
GreatXML Exploit: A New Threat to Windows BitLocker Encryption
Impact· MEDIUM

GreatXML Exploit: A New Threat to Windows BitLocker Encryption

In June 2026, security researcher Chaotic Eclipse disclosed a zero-day vulnerability named 'GreatXML' that allows attackers to bypass Windows BitLocker encryption. The exploit leverages artifacts left by Microsoft Defender's offline scan to gain SYSTEM-level access during Recovery Mode, effectively rendering BitLocker protections ineffective. Systems that have run an offline scan are particularly vulnerable, as the exploit involves placing specific XML files in the recovery partition and rebooting into the Windows Recovery Environment. This vulnerability poses a significant risk to data security, especially for devices that have utilized Defender's offline scanning feature. ([securityweek.com](https://www.securityweek.com/greatxml-zero-day-exploit-bypasses-bitlocker/?utm_source=openai)) The disclosure of GreatXML underscores the ongoing challenges in securing endpoint devices against sophisticated attacks. It highlights the need for organizations to reassess their reliance on built-in encryption tools and to implement additional layers of security to protect sensitive data. The incident also raises concerns about the effectiveness of current vulnerability disclosure practices and the timeliness of patches for critical security flaws.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ShinyHunters Exploit Oracle PeopleSoft Vulnerability CVE-2026-35273 in 2026
Impact· CRITICAL

ShinyHunters Exploit Oracle PeopleSoft Vulnerability CVE-2026-35273 in 2026

Between May 27 and June 9, 2026, the cybercriminal group ShinyHunters exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools versions 8.61 and 8.62. This critical flaw allowed unauthenticated remote code execution, leading to unauthorized access and data exfiltration from over 100 organizations, predominantly universities. The University of Nottingham confirmed a breach affecting approximately 500,000 current and former students' personal and academic records. Oracle released a security advisory on June 10, 2026, acknowledging the vulnerability and urging immediate mitigation measures. This incident underscores the escalating threat posed by sophisticated cybercriminal groups targeting enterprise software vulnerabilities, particularly in the education sector. The exploitation of zero-day vulnerabilities for large-scale data breaches highlights the urgent need for organizations to implement proactive security measures, including timely patch management and comprehensive monitoring of critical systems.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Security Flaws Discovered in OpenClaw AI Agent
Impact· HIGH

Critical Security Flaws Discovered in OpenClaw AI Agent

In June 2026, security researchers from Imperva and Varonis identified critical vulnerabilities in OpenClaw, a widely used self-hosted AI agent. Imperva demonstrated that attackers could embed malicious instructions within shared contacts, vCards, and location pins, leading the agent to execute unauthorized code without user awareness. Varonis revealed that OpenClaw could be manipulated through standard emails to exfiltrate sensitive data, such as AWS keys and customer information, to external addresses. These findings underscore the agent's susceptibility to prompt injection attacks and its overreliance on unverified inputs, posing significant security risks to users. The rapid adoption of AI agents like OpenClaw has outpaced the development of robust security measures, highlighting the urgent need for comprehensive governance frameworks. Organizations must reassess their deployment strategies, implement stringent access controls, and ensure continuous monitoring to mitigate the risks associated with autonomous AI systems operating within their environments.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Unveiling Cyber-Enabled Maritime Sanctions Evasion Tactics in 2026
Impact· HIGH

Unveiling Cyber-Enabled Maritime Sanctions Evasion Tactics in 2026

In 2026, Iranian and Russian shadow fleet vessels, along with multiple sanctions evasion networks (SENs), utilized over 36 inauthentic websites to impersonate maritime authorities and organizations. These fraudulent sites facilitated the generation of false documents and certificates, effectively replicating key layers of the maritime compliance stack. This cyber-enabled infrastructure allowed sanctioned entities to circumvent international sanctions by creating credible but fraudulent maritime organizations, increasing the risk of due diligence failures and regulatory exposure. The emergence of such sophisticated cyber-enabled sanctions evasion tactics underscores the evolving nature of maritime compliance challenges. Organizations in the maritime and shipping sectors must integrate independent verification and cyber threat intelligence into compliance workflows to proactively identify and mitigate fraudulent online infrastructure.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA's BOD 26-04: A New Era in Federal Vulnerability Management
Impact· LOW

CISA's BOD 26-04: A New Era in Federal Vulnerability Management

On June 10, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive (BOD) 26-04, mandating federal agencies to adopt a risk-based approach to vulnerability remediation. This directive requires agencies to prioritize vulnerabilities based on four criteria: inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog, public exposure of the asset, potential for automated exploitation, and the level of control an attacker could gain upon successful exploitation. Vulnerabilities meeting all four criteria must be remediated within three days, while others have extended timelines or can be deferred. ([darkreading.com](https://www.darkreading.com/cyber-risk/cisa-rewrites-federal-patching-requirements-ai-threat-era?utm_source=openai))The directive reflects growing concerns about AI-driven threats accelerating the discovery and exploitation of vulnerabilities, necessitating faster remediation processes. This shift underscores the need for agencies to enhance their vulnerability management practices to keep pace with evolving cyber threats. ([darkreading.com](https://www.darkreading.com/cyber-risk/cisa-rewrites-federal-patching-requirements-ai-threat-era?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Escalating Cyber Threats from North Korea and China Target Asia-Pacific Financial Institutions
Impact· CRITICAL

Escalating Cyber Threats from North Korea and China Target Asia-Pacific Financial Institutions

In 2025, cyber threat groups linked to North Korea and China intensified their attacks on financial institutions and cryptocurrency assets in the Asia-Pacific region. North Korean adversaries, notably PRESSURE CHOLLIMA, executed the largest financial theft to date, stealing $1.46 billion in cryptocurrency through a supply chain compromise. Concurrently, Chinese threat actors like HOLLOW PANDA targeted financial institutions across multiple countries, including the Philippines, Indonesia, and Brazil. These operations leveraged advanced techniques, including AI-generated identities and sophisticated social engineering tactics, to infiltrate organizations and exfiltrate sensitive data. ([crowdstrike.com](https://www.crowdstrike.com/en-us/press-releases/crowdstrike-2026-financial-services-threat-landscape-report/?utm_source=openai)) The escalation of these cyber activities underscores a growing trend of state-sponsored cybercrime aimed at financial gain and intelligence collection. The increasing sophistication and frequency of these attacks highlight the urgent need for enhanced cybersecurity measures and international collaboration to protect financial infrastructures from such persistent threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports