✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Microsoft Addresses Critical Zero-Day Vulnerabilities: YellowKey, GreenPlasma, and MiniPlasma
In June 2026, Microsoft addressed three critical zero-day vulnerabilities—YellowKey, GreenPlasma, and MiniPlasma—disclosed by the researcher 'Nightmare Eclipse.' YellowKey (CVE-2026-45585) allowed attackers with physical access to bypass BitLocker encryption via the Windows Recovery Environment. GreenPlasma (CVE-2026-45586) and MiniPlasma (CVE-2020-17103) were privilege escalation flaws in the Collaborative Translation Framework and Cloud Files Mini Filter Driver, respectively, enabling local attackers to gain SYSTEM privileges on fully patched Windows systems. These vulnerabilities were patched in Microsoft's June 2026 Patch Tuesday updates. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-yellowkey-greenplasma-miniplasma-zero-days/?utm_source=openai)) The disclosure of these vulnerabilities highlights ongoing challenges in vulnerability management and coordinated disclosure practices. The public release of proof-of-concept exploits prior to patches underscores the need for robust security measures and prompt patch management to mitigate potential threats.
1 month ago
Kill Chain
Critical Vulnerabilities in Ivanti Sentry: CVE-2026-10520 and CVE-2026-10523
In June 2026, Ivanti disclosed two critical vulnerabilities in its Sentry secure mobile gateway: CVE-2026-10520, an OS command injection flaw allowing unauthenticated remote code execution with root privileges, and CVE-2026-10523, an authentication bypass enabling attackers to create administrative accounts. Both vulnerabilities were patched in Sentry versions R10.5.2, R10.6.2, and R10.7.1. These vulnerabilities underscore the persistent targeting of Ivanti products by threat actors, highlighting the necessity for organizations to promptly apply security patches to mitigate potential exploitation risks.
1 month ago
Kill Chain
Microsoft Exchange Server CVE-2026-42897 Zero-Day Exploited in Attacks
In May 2026, Microsoft disclosed a high-severity cross-site scripting (XSS) vulnerability, CVE-2026-42897, affecting on-premises Exchange Server versions 2016, 2019, and Subscription Edition. This flaw allows remote attackers to execute arbitrary JavaScript in the context of a user's browser by sending specially crafted emails, which, when opened in Outlook Web Access (OWA), trigger the exploit. The vulnerability was actively exploited in the wild, prompting Microsoft to release security updates in June 2026 to address the issue. Organizations were advised to apply these updates promptly and maintain existing mitigations to ensure comprehensive protection. The exploitation of CVE-2026-42897 underscores the persistent targeting of email infrastructure by threat actors, highlighting the critical need for organizations to prioritize the security of their communication platforms. This incident serves as a reminder of the importance of timely patch management and the implementation of robust security measures to defend against evolving cyber threats.
1 month ago
Kill Chain
ShinyHunters' Exploitation of Oracle PeopleSoft: A Wake-Up Call for ERP Security
In June 2026, the ShinyHunters cybercriminal group launched a series of data theft attacks targeting Oracle PeopleSoft servers across more than 100 organizations, predominantly within the education sector. By exploiting a combination of known and zero-day vulnerabilities, they successfully exfiltrated sensitive data from approximately 300 instances. The University of Nottingham was among the affected institutions, with its data subsequently published on ShinyHunters' data leak site. These incidents underscore the critical need for organizations to promptly apply security patches and conduct thorough system configurations to mitigate potential vulnerabilities. This attack highlights a concerning trend of cybercriminals increasingly targeting enterprise resource planning (ERP) systems, which are integral to organizational operations. The exploitation of both known and unknown vulnerabilities in such systems emphasizes the importance of proactive cybersecurity measures, including regular system audits, timely patch management, and comprehensive incident response planning to safeguard sensitive data and maintain operational integrity.
1 month ago
Kill Chain
GitHub's npm v12: Strengthening Security Against Supply-Chain Attacks
In June 2026, GitHub announced significant security enhancements for npm version 12, aimed at mitigating supply-chain attacks. Key changes include requiring explicit approval for running preinstall, install, or postinstall scripts from dependencies, and restricting automatic fetching of dependencies from Git repositories and remote URLs unless explicitly permitted. These measures are designed to prevent unauthorized code execution during package installations, thereby enhancing the security of the npm ecosystem. This initiative addresses vulnerabilities exploited in recent supply-chain attacks, such as the Shai-Hulud campaign, which compromised numerous npm packages to steal developer credentials. By implementing these changes, GitHub aims to fortify the software supply chain against emerging threats and protect developers from potential security breaches.
1 month ago
Kill Chain
Critical Langflow Vulnerability CVE-2026-5027 Exploited in the Wild
In early 2026, a critical path traversal vulnerability, CVE-2026-5027, was discovered in Langflow, an open-source AI development platform. This flaw allowed unauthenticated attackers to write arbitrary files to exposed servers by exploiting the 'POST /api/v2/files' endpoint, which failed to properly sanitize user-supplied filenames. The vulnerability was publicly disclosed on March 27, 2026, after initial reports to the Langflow team went unanswered. Exploitation of this flaw has been observed in the wild, with attackers dropping test files on vulnerable instances. Langflow users are urged to upgrade to version 1.10.0 to mitigate this risk. This incident underscores the critical importance of timely vulnerability management and the risks associated with default configurations that allow unauthenticated access. Organizations must prioritize patching known vulnerabilities and reassess default settings to prevent unauthorized exploitation.
1 month ago
Kill Chain
JDY Botnet's Rapid Expansion: A Wake-Up Call for Cybersecurity
In June 2026, cybersecurity researchers reported a significant expansion of the JDY botnet, a covert network linked to Chinese state-sponsored actors. The botnet has grown from 650 to over 1,500 compromised small office and home office (SOHO) routers and IoT devices. This network is utilized for large-scale reconnaissance, enabling rapid identification and mapping of exposed services within hours of new vulnerability disclosures. The JDY botnet's resilience and adaptability underscore the persistent threat posed by state-sponsored cyber activities targeting critical infrastructure. The rapid expansion of the JDY botnet highlights the increasing sophistication of state-sponsored cyber operations. Organizations must prioritize timely patching of edge devices, enforce strong authentication measures, and monitor for indicators of compromise to mitigate the risks associated with such covert networks.
1 month ago
Kill Chain
Miasma Worm Source Code Leaked on GitHub: Implications for Open-Source Security
In June 2026, the Miasma worm, an evolution of the Shai-Hulud malware, was deliberately leaked on GitHub by threat actors. This credential-stealing framework targets developers by infecting their machines, harvesting build environment and cloud credentials, and propagating itself by compromising legitimate repositories and packages. Notably, Miasma has been linked to significant supply chain attacks, including the compromise of 73 Microsoft GitHub repositories and Red Hat npm packages. The worm's autonomous propagation mechanism poses a substantial risk to the open-source ecosystem, enabling rapid and widespread distribution of malicious code. The deliberate release of Miasma's source code is expected to facilitate further adaptations by malicious actors, potentially leading to an increase in sophisticated supply chain attacks. This incident underscores the critical need for enhanced security measures within the open-source community to mitigate the risks associated with such self-propagating malware.
1 month ago
Kill Chain
Microsoft's June 2026 Patch Tuesday: Addressing 206 Vulnerabilities, Including Three Zero-Days
In June 2026, Microsoft released its largest-ever Patch Tuesday update, addressing 206 vulnerabilities across its product suite, including Windows, Office, Azure, and more. Notably, this update included fixes for three zero-day vulnerabilities: CVE-2026-49160, a denial of service flaw in web servers; CVE-2026-45586, an elevation of privilege issue in the Windows Collaborative Translation Framework; and CVE-2026-50507, a BitLocker vulnerability allowing unauthorized data access. These zero-days were publicly disclosed by a researcher known as 'Nightmare Eclipse,' leading to heightened tensions between the researcher and Microsoft. The rapid disclosure and exploitation of these vulnerabilities underscore the evolving threat landscape and the critical need for timely patch management. Organizations are urged to prioritize the deployment of these updates to mitigate potential risks associated with these vulnerabilities.
1 month ago
Kill Chain
The Gentlemen Ransomware Group: A Rising Threat in 2026
The Gentlemen ransomware group, emerging in mid-2025, has rapidly become the second most active ransomware-as-a-service (RaaS) operation, claiming over 330 victims by mid-2026. Offering affiliates a 90% revenue share, the group attracts experienced operators who exploit internet-facing devices like VPNs and firewalls to gain initial access, swiftly encrypting entire networks within hours. Their cross-platform ransomware, written in Go, targets Windows, Linux, and ESXi environments, employing advanced techniques such as lateral movement, defense evasion, and data exfiltration to maximize impact. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor/?utm_source=openai))The rapid ascent of The Gentlemen underscores the evolving sophistication of ransomware operations, highlighting the urgent need for organizations to bolster their cybersecurity defenses. The group's aggressive recruitment and advanced tactics exemplify the growing threat posed by RaaS platforms, emphasizing the importance of proactive threat intelligence and robust security measures to mitigate such risks. ([computerweekly.com](https://www.computerweekly.com/news/366643511/The-Gentlemen-emerging-as-key-ransomware-player?utm_source=openai))
1 month ago
Kill Chain
Proto6 Vulnerabilities in protobuf.js: A Threat to Node.js Applications
In June 2026, cybersecurity researchers identified six critical vulnerabilities, collectively termed 'Proto6,' in protobuf.js—a widely used JavaScript and TypeScript implementation of Google's Protocol Buffers. These flaws, including CVE-2026-44291 and CVE-2026-44295, could lead to remote code execution (RCE) and denial-of-service (DoS) attacks if exploited. The vulnerabilities affect Node.js applications utilizing protobuf.js, Google Cloud client libraries, messaging frameworks like Baileys, and CI/CD pipelines. Attackers can exploit these issues by introducing malicious protobuf schemas, potentially compromising sensitive data and system integrity. The discovery underscores the growing risks in software supply chains, especially within data and AI ecosystems that frequently exchange schemas and configurations. Organizations are urged to update to protobuf.js versions 7.5.6 or 8.0.2 to mitigate these threats.
1 month ago
Kill Chain
Miasma Worm's 2026 Attack on Microsoft: A Wake-Up Call for Supply Chain Security
In June 2026, Microsoft faced a significant supply chain attack when the Miasma worm compromised 73 of its GitHub repositories across four organizations: Azure, Azure-Samples, Microsoft, and MicrosoftDocs. The attackers utilized previously stolen credentials to inject malicious code into these repositories, leading to widespread disruptions in continuous integration and deployment (CI/CD) workflows globally. This incident underscores the escalating threat of self-replicating malware targeting trusted software supply chains. The Miasma worm's ability to exploit AI coding tools and integrated development environments (IDEs) highlights a concerning evolution in attack vectors, emphasizing the need for enhanced security measures in development environments to prevent similar breaches in the future.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports