✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Major Supply Chain Attacks Target Nx Console and GitHub Repositories in 2026
In May 2026, two significant supply chain attacks targeted the developer ecosystem. The first involved a compromised version of the Nx Console Visual Studio Code extension (v18.95.0), which was live for approximately 18 minutes on May 18, 2026. This malicious extension exfiltrated credentials from developer machines, leading to unauthorized access and exfiltration of approximately 3,800 internal GitHub repositories. The second attack, dubbed 'Megalodon,' occurred on the same day and compromised over 5,500 GitHub repositories by injecting malicious GitHub Actions workflows designed to harvest CI/CD secrets and cloud credentials. These incidents underscore the escalating threat landscape targeting software development pipelines and the critical need for robust security measures in CI/CD environments. The rapid execution and widespread impact of these attacks highlight the urgency for organizations to implement stringent supply chain security practices and continuous monitoring to detect and mitigate such threats promptly.
2 months ago
Kill Chain
The Hidden Dangers of AI-Generated Applications: A 2026 Security Analysis
In May 2026, cybersecurity firm RedAccess identified over 380,000 publicly accessible web assets created using AI-driven development platforms, commonly referred to as 'vibe coding' tools. Among these, approximately 5,000 assets appeared to be corporate-related, with more than 2,000 containing sensitive corporate, operational, or personal data. These applications were often deployed without basic access controls, granting administrative access to anyone who accessed the URL. This widespread exposure underscores the significant security risks associated with the rapid adoption of AI-generated code without proper oversight. The incident highlights the urgent need for organizations to implement robust security measures and governance frameworks to manage the risks posed by unauthorized AI-generated applications. As AI-driven development becomes more prevalent, ensuring the security and integrity of these applications is paramount to prevent data breaches and maintain compliance with regulatory standards.
2 months ago
Kill Chain
Malicious Sicoob NuGet Package Compromises Banking Credentials
In May 2026, cybersecurity researchers discovered a malicious NuGet package named 'Sicoob.Sdk' that impersonated a C# software development kit for Sicoob, one of Brazil's largest cooperative financial systems. Versions 2.0.0 through 2.0.4 of this package were found to exfiltrate sensitive information, including client IDs and PFX certificates, which are crucial for secure communications. This incident underscores the growing trend of supply chain attacks targeting software development ecosystems to steal sensitive data. The discovery of 'Sicoob.Sdk' aligns with a series of recent supply chain attacks where malicious packages infiltrate trusted repositories. For instance, the 'TrapDoor' campaign targeted npm, PyPI, and Crates.io ecosystems to distribute credential-stealing malware. These incidents highlight the urgent need for enhanced vigilance and security measures within software supply chains to protect against such threats.
2 months ago
Kill Chain
AI Agents Exploit Marimo Vulnerability CVE-2026-39987
In May 2026, an unidentified threat actor exploited a critical vulnerability (CVE-2026-39987) in Marimo, an open-source Python notebook platform, to gain unauthorized access to a publicly accessible Marimo instance. Utilizing a large language model (LLM) agent, the attacker extracted cloud credentials, retrieved an SSH private key from AWS Secrets Manager, and conducted multiple SSH sessions to exfiltrate the schema and full contents of an internal PostgreSQL database within a short timeframe. This incident underscores the rapid weaponization of AI-driven tools in cyberattacks, enabling sophisticated post-exploitation activities with minimal prior knowledge of the target environment. Organizations must prioritize patching known vulnerabilities and enhance monitoring to detect and mitigate such advanced threats promptly.
2 months ago
Kill Chain
Typosquatted npm Packages Lead to Cloud and CI/CD Credential Theft
In May 2026, a threat actor using the alias 'vpmdhaj' published 14 malicious npm packages that mimicked popular OpenSearch and ElasticSearch libraries. These packages, once installed, executed scripts to harvest sensitive credentials, including AWS keys, HashiCorp Vault tokens, and CI/CD pipeline secrets, from the host environment. The attack leveraged typosquatting and spoofed metadata to appear legitimate, facilitating unauthorized access and potential lateral movement within cloud infrastructures. This incident underscores the escalating threat of supply chain attacks targeting open-source ecosystems. Organizations must remain vigilant, as such attacks can lead to significant data breaches and operational disruptions. Implementing stringent package validation processes and monitoring for anomalous activities are crucial to mitigating these risks.
2 months ago
Kill Chain
Canon Printer Vulnerability Exposes Credentials - 2026
In April 2026, a critical vulnerability (CVE-2026-1789) was discovered in Canon's browser-based remote management interface for certain production printers and office multifunction printers. This flaw allowed attackers with administrative access to extract sensitive information, including plaintext credentials, by manipulating client-side encryption parameters during configuration exports. Exploiting this vulnerability enabled lateral movement within networks, potentially leading to complete domain compromise. This incident underscores the persistent risks associated with default credentials and inadequate security measures in networked devices. It highlights the necessity for organizations to enforce robust password policies, regularly update firmware, and implement stringent network segmentation to mitigate such vulnerabilities.
2 months ago
Kill Chain
Harnessing AI: LLMs in EDR Evasion Techniques
In May 2026, Praetorian published a blog post titled 'Adversarial Oracles: LLM-Guided EDR Signature Reduction,' detailing the use of Large Language Models (LLMs) to automate the evasion of Endpoint Detection and Response (EDR) signatures. The post describes a methodology where LLMs analyze detection patterns from services like VirusTotal, identify specific triggers in offensive security tools, and suggest code modifications to reduce detection rates. This approach was applied to tools like 'goffloader,' resulting in a significant decrease in antivirus detections without altering the tools' core functionalities. This development is significant as it highlights the evolving arms race between offensive and defensive cybersecurity measures. The use of AI to circumvent EDR systems underscores the need for adaptive defense strategies and raises ethical considerations regarding the deployment of AI in cybersecurity.
2 months ago
Kill Chain
Google Engineer Arrested for Insider Trading on Polymarket
In May 2026, Michele Spagnuolo, a 36-year-old Google security engineer, was arrested in New York for allegedly using confidential internal data to profit on the Polymarket prediction platform. Spagnuolo accessed nonpublic 'Year in Search' data to place bets on the most searched individuals of 2025, resulting in over $1.2 million in gains. He faces charges including commodities fraud, wire fraud, and money laundering, with potential sentences totaling up to 50 years in prison. This incident underscores the growing scrutiny of insider trading within emerging financial platforms like prediction markets. It highlights the critical need for robust internal controls and monitoring to prevent the misuse of proprietary information, especially as digital platforms become increasingly integrated into financial activities.
2 months ago
Kill Chain
Romanian Hacker Sentenced for Breaching Oregon Government Network
In June 2021, Catalin Dragomir, a Romanian national operating under the alias "inthematrixl," unlawfully accessed the Oregon Department of Emergency Management's network. He extracted personally identifiable information, including names, email addresses, dates of birth, and passport numbers, and sold this data alongside unauthorized network access to potential buyers. Dragomir extended his cybercriminal activities by compromising nearly a dozen other U.S. networks, resulting in cumulative losses exceeding $250,000. Following his arrest in Romania in November 2024 and subsequent extradition to the United States in January 2025, Dragomir pleaded guilty to charges of aggravated identity theft and obtaining information from a protected computer. In May 2026, he was sentenced to 56 months in federal prison and ordered to forfeit approximately 23 Monero (XMR) cryptocurrency, valued at roughly $8,500. This case underscores the persistent threat posed by cybercriminals targeting government infrastructures and the critical need for robust cybersecurity measures to protect sensitive data. The incident also highlights the importance of international cooperation in apprehending and prosecuting cyber offenders.
2 months ago
Kill Chain
Critical Gogs Zero-Day Vulnerability Exposes Code Repositories to Remote Code Execution
In May 2026, a critical zero-day vulnerability was discovered in Gogs, a self-hosted Git service. This argument injection flaw allows authenticated users to execute arbitrary code on servers running Gogs versions 0.14.2 and 0.15.0+dev. Exploitation involves creating a pull request with a malicious branch name that injects the --exec flag into git rebase during the 'Rebase before merging' operation. This vulnerability enables attackers to compromise the server, access all repositories, extract credentials, and potentially pivot to other systems. The incident underscores the persistent risks associated with self-hosted code repositories, especially those with default configurations that permit open registration. Organizations relying on Gogs should assess their exposure, apply available patches promptly, and consider implementing stricter access controls to mitigate similar threats.
2 months ago
Kill Chain
FortiClient EMS Vulnerability Leads to EKZ Infostealer Deployment
In May 2026, threat actors exploited a critical authentication bypass vulnerability (CVE-2026-35616) in Fortinet's FortiClient Enterprise Management Server (EMS) versions 7.4.5 and 7.4.6. This flaw allowed unauthenticated remote attackers to execute arbitrary code via specially crafted requests. Leveraging this vulnerability, attackers delivered the EKZ infostealer malware, disguised as a legitimate Fortinet endpoint update, through FortiClient-managed VPN scripting workflows. The malware targeted credentials and sensitive data stored in web browsers, exfiltrating them to attacker-controlled servers. Fortinet released emergency patches to address this issue, and organizations were urged to apply them promptly to mitigate the risk of compromise. This incident underscores the critical importance of timely patch management and vigilance against sophisticated social engineering tactics. The exploitation of trusted security infrastructure highlights the evolving strategies of threat actors, emphasizing the need for organizations to adopt a proactive and layered security approach to protect against such vulnerabilities.
2 months ago
Kill Chain
FBI Issues Warning on Fake FIFA Websites Targeting 2026 World Cup Fans
In May 2026, the FBI issued a warning about cybercriminals creating fake websites impersonating FIFA ahead of the 2026 World Cup. These fraudulent sites, often with minor spelling variations or alternative top-level domains, aim to steal personal and financial information, sell counterfeit tickets, and perpetrate other scams. The threat actors employ techniques like typo squatting to deceive users into believing they are interacting with legitimate FIFA platforms. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260527?utm_source=openai)) This incident underscores the increasing sophistication of phishing and social engineering attacks targeting major global events. As the World Cup approaches, the prevalence of such scams is expected to rise, highlighting the need for heightened vigilance and robust cybersecurity measures among fans and organizations involved. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/fbi-warns-of-fake-fifa-websites-running-world-cup-fraud-schemes/amp/?utm_source=openai))
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports