✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
ServiceNow Security Alert: Understanding the June 2026 Incident
In early June 2026, ServiceNow identified a security issue that allowed unauthorized users to access certain customer data through a misconfigured API endpoint. The vulnerability, affecting customers on the Australia platform release and earlier versions with specific configurations, was exploited to query customer instance tables containing sensitive information. ServiceNow addressed the issue with a security update on June 5, 2026, restricting access to authenticated users. Subsequent investigations revealed that the anomalous activity was conducted by security researchers participating in bug bounty programs, not malicious actors. This incident underscores the importance of promptly addressing security vulnerabilities and the potential for security research activities to be misinterpreted as malicious threats.
1 month ago
Kill Chain
GitHub Enhances Security by Disabling npm Install Scripts by Default
In June 2026, GitHub announced significant changes to npm version 12, aiming to enhance security by disabling install scripts by default. This measure addresses vulnerabilities where attackers exploit npm lifecycle hooks during the 'npm install' process to execute malicious code. By requiring explicit user approval for script execution, GitHub seeks to mitigate risks associated with software supply chain attacks. This change is particularly relevant given the recent surge in supply chain attacks targeting npm packages. Incidents like the 'Mini Shai-Hulud' campaign have demonstrated the potential for widespread impact, emphasizing the need for proactive security measures in package management systems.
1 month ago
Kill Chain
TanStack npm Supply Chain Attack: A Wake-Up Call for CI/CD Security
In May 2026, TanStack's npm packages were compromised in a sophisticated supply chain attack. The attackers exploited GitHub Actions vulnerabilities, including misconfigured workflows and cache poisoning, to publish 84 malicious versions across 42 packages. This breach led to credential theft and potential malware propagation, impacting developers and CI/CD systems. ([tanstack.com](https://tanstack.com/blog/npm-supply-chain-compromise-postmortem?utm_source=openai)) This incident underscores the critical need for secure CI/CD pipeline configurations and robust supply chain security measures, as similar attacks are on the rise, targeting widely-used open-source libraries.
1 month ago
Kill Chain
OpenClaw AI Agent Phishing Incident Highlights Critical Security Gaps
In June 2026, a significant cybersecurity incident was reported involving the OpenClaw AI agent. Security researchers at Varonis conducted an experiment where they connected an OpenClaw email agent to a simulated Gmail inbox containing fictitious company data. Through a single phishing email impersonating a colleague, the AI agent was tricked into disclosing sensitive information, including AWS credentials, database connection strings, and a customer export list. This breach underscores the vulnerability of autonomous AI systems to social engineering attacks, highlighting the need for robust security measures in AI deployments. The incident is particularly concerning given the increasing integration of AI agents in enterprise environments. As these systems gain more autonomy and access to critical data, the potential for exploitation through sophisticated phishing tactics grows. Organizations must prioritize the development and implementation of security frameworks tailored to AI agents to prevent similar breaches in the future.
1 month ago
Kill Chain
Understanding the OpenClaw Vulnerability and AI Agent Supply Chain Risks
In early 2026, the OpenClaw AI agent framework, widely adopted for automating enterprise workflows, was found to have a critical vulnerability (CVE-2026-25253) that allowed remote code execution via a WebSocket exploit. This flaw enabled attackers to hijack agents by tricking users into visiting malicious websites, potentially compromising entire workstations. The incident highlighted the risks associated with unmanaged, autonomous AI systems operating with extensive access and minimal oversight. ([waxell.ai](https://www.waxell.ai/blog/openclaw-ai-agent-supply-chain-security?utm_source=openai)) This event underscores the growing security challenges in AI agent supply chains, emphasizing the need for robust governance and verification mechanisms. As organizations increasingly deploy AI agents, ensuring the integrity and security of third-party skills and components becomes paramount to prevent similar vulnerabilities and attacks.
1 month ago
Kill Chain
CISA's BOD 26-04: A New Era in Risk-Based Vulnerability Management
On June 10, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive (BOD) 26-04, mandating federal agencies to prioritize vulnerability remediation based on four specific criteria: public exposure of the asset, evidence of active exploitation, potential for automated exploitation, and the technical impact of the vulnerability. Vulnerabilities meeting all four criteria require remediation within three days, accompanied by a forensic assessment to determine if systems have been compromised. ([cyberscoop.com](https://cyberscoop.com/cisa-vulnerability-remediation-directive-bod-26-04/?utm_source=openai)) This directive reflects CISA's response to the accelerated threat landscape, particularly the role of artificial intelligence in rapidly identifying and exploiting vulnerabilities. By focusing on risk-based prioritization, BOD 26-04 aims to enhance the efficiency and effectiveness of federal agencies' cybersecurity efforts, ensuring that the most critical vulnerabilities are addressed promptly to mitigate potential threats. ([cyberscoop.com](https://cyberscoop.com/cisa-vulnerability-remediation-directive-bod-26-04/?utm_source=openai))
1 month ago
Kill Chain
Microsoft Addresses Critical Zero-Day Vulnerabilities: YellowKey, GreenPlasma, and MiniPlasma
In June 2026, Microsoft addressed three critical zero-day vulnerabilities—YellowKey, GreenPlasma, and MiniPlasma—disclosed by the researcher 'Nightmare Eclipse.' YellowKey (CVE-2026-45585) allowed attackers with physical access to bypass BitLocker encryption via the Windows Recovery Environment. GreenPlasma (CVE-2026-45586) and MiniPlasma (CVE-2020-17103) were privilege escalation flaws in the Collaborative Translation Framework and Cloud Files Mini Filter Driver, respectively, enabling local attackers to gain SYSTEM privileges on fully patched Windows systems. These vulnerabilities were patched in Microsoft's June 2026 Patch Tuesday updates. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-yellowkey-greenplasma-miniplasma-zero-days/?utm_source=openai)) The disclosure of these vulnerabilities highlights ongoing challenges in vulnerability management and coordinated disclosure practices. The public release of proof-of-concept exploits prior to patches underscores the need for robust security measures and prompt patch management to mitigate potential threats.
1 month ago
Kill Chain
Critical Vulnerabilities in Ivanti Sentry: CVE-2026-10520 and CVE-2026-10523
In June 2026, Ivanti disclosed two critical vulnerabilities in its Sentry secure mobile gateway: CVE-2026-10520, an OS command injection flaw allowing unauthenticated remote code execution with root privileges, and CVE-2026-10523, an authentication bypass enabling attackers to create administrative accounts. Both vulnerabilities were patched in Sentry versions R10.5.2, R10.6.2, and R10.7.1. These vulnerabilities underscore the persistent targeting of Ivanti products by threat actors, highlighting the necessity for organizations to promptly apply security patches to mitigate potential exploitation risks.
1 month ago
Kill Chain
Microsoft Exchange Server CVE-2026-42897 Zero-Day Exploited in Attacks
In May 2026, Microsoft disclosed a high-severity cross-site scripting (XSS) vulnerability, CVE-2026-42897, affecting on-premises Exchange Server versions 2016, 2019, and Subscription Edition. This flaw allows remote attackers to execute arbitrary JavaScript in the context of a user's browser by sending specially crafted emails, which, when opened in Outlook Web Access (OWA), trigger the exploit. The vulnerability was actively exploited in the wild, prompting Microsoft to release security updates in June 2026 to address the issue. Organizations were advised to apply these updates promptly and maintain existing mitigations to ensure comprehensive protection. The exploitation of CVE-2026-42897 underscores the persistent targeting of email infrastructure by threat actors, highlighting the critical need for organizations to prioritize the security of their communication platforms. This incident serves as a reminder of the importance of timely patch management and the implementation of robust security measures to defend against evolving cyber threats.
1 month ago
Kill Chain
ShinyHunters' Exploitation of Oracle PeopleSoft: A Wake-Up Call for ERP Security
In June 2026, the ShinyHunters cybercriminal group launched a series of data theft attacks targeting Oracle PeopleSoft servers across more than 100 organizations, predominantly within the education sector. By exploiting a combination of known and zero-day vulnerabilities, they successfully exfiltrated sensitive data from approximately 300 instances. The University of Nottingham was among the affected institutions, with its data subsequently published on ShinyHunters' data leak site. These incidents underscore the critical need for organizations to promptly apply security patches and conduct thorough system configurations to mitigate potential vulnerabilities. This attack highlights a concerning trend of cybercriminals increasingly targeting enterprise resource planning (ERP) systems, which are integral to organizational operations. The exploitation of both known and unknown vulnerabilities in such systems emphasizes the importance of proactive cybersecurity measures, including regular system audits, timely patch management, and comprehensive incident response planning to safeguard sensitive data and maintain operational integrity.
1 month ago
Kill Chain
GitHub's npm v12: Strengthening Security Against Supply-Chain Attacks
In June 2026, GitHub announced significant security enhancements for npm version 12, aimed at mitigating supply-chain attacks. Key changes include requiring explicit approval for running preinstall, install, or postinstall scripts from dependencies, and restricting automatic fetching of dependencies from Git repositories and remote URLs unless explicitly permitted. These measures are designed to prevent unauthorized code execution during package installations, thereby enhancing the security of the npm ecosystem. This initiative addresses vulnerabilities exploited in recent supply-chain attacks, such as the Shai-Hulud campaign, which compromised numerous npm packages to steal developer credentials. By implementing these changes, GitHub aims to fortify the software supply chain against emerging threats and protect developers from potential security breaches.
1 month ago
Kill Chain
Critical Langflow Vulnerability CVE-2026-5027 Exploited in the Wild
In early 2026, a critical path traversal vulnerability, CVE-2026-5027, was discovered in Langflow, an open-source AI development platform. This flaw allowed unauthenticated attackers to write arbitrary files to exposed servers by exploiting the 'POST /api/v2/files' endpoint, which failed to properly sanitize user-supplied filenames. The vulnerability was publicly disclosed on March 27, 2026, after initial reports to the Langflow team went unanswered. Exploitation of this flaw has been observed in the wild, with attackers dropping test files on vulnerable instances. Langflow users are urged to upgrade to version 1.10.0 to mitigate this risk. This incident underscores the critical importance of timely vulnerability management and the risks associated with default configurations that allow unauthenticated access. Organizations must prioritize patching known vulnerabilities and reassess default settings to prevent unauthorized exploitation.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports