✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
BTMOB: The No-Code Android Malware Service Empowering Cybercriminals
In May 2026, cybersecurity researchers identified BTMOB, an Android remote access trojan (RAT) offered as a malware-as-a-service (MaaS) platform. BTMOB provides cybercriminals with a no-code APK builder, enabling the creation of customized phishing payloads without programming expertise. The malware grants attackers extensive control over infected devices, including data exfiltration, financial transaction interception, screenshot capture, and remote operation. Distributed primarily through phishing websites impersonating legitimate services, BTMOB has been notably active in Brazil and Latin America. Its accessibility and comprehensive feature set pose a significant threat to Android users globally. The emergence of BTMOB underscores a concerning trend in the cyber threat landscape: the commoditization of sophisticated malware through MaaS platforms. This development lowers the barrier to entry for cybercriminals, facilitating the rapid proliferation of advanced threats. Organizations must remain vigilant, as the ease of deploying such malware increases the risk of widespread attacks targeting mobile devices.
2 months ago
Kill Chain
Exploitation of FortiClient EMS Vulnerability Leads to Credential Theft
In May 2026, threat actors exploited a critical vulnerability (CVE-2026-35616) in Fortinet's FortiClient Endpoint Management Server (EMS) to deploy credential-stealing malware across managed endpoints. By abusing the trusted endpoint management infrastructure, attackers disguised the malicious payload as a legitimate Fortinet update, executing it via PowerShell. This allowed them to harvest sensitive data, including passwords and autofill details from web browsers, and exfiltrate the information to attacker-controlled servers. The exploitation of this vulnerability underscores the risks associated with unpatched management systems and the potential for widespread compromise through centralized infrastructure. Organizations are urged to apply the latest patches and review endpoint management configurations to mitigate such threats.
2 months ago
Kill Chain
Critical Gogs RCE Vulnerability Discovered in 2026
In May 2026, a critical remote code execution (RCE) vulnerability was identified in Gogs, an open-source self-hosted Git service. This flaw allows authenticated users to execute arbitrary code on the server by creating a pull request with a malicious branch name that injects the --exec flag into git rebase during the 'Rebase before merging' operation. The vulnerability, rated 9.4 on the CVSS scale, does not require administrative privileges or interaction with other users, making exploitation straightforward for any registered user. ([thehackernews.com](https://thehackernews.com/2026/05/critical-gogs-rce-vulnerability-lets.html?utm_source=openai)) The discovery of this vulnerability underscores the ongoing risks associated with self-hosted development tools. Organizations relying on Gogs should promptly implement recommended mitigations, such as restricting user registration and repository creation, to prevent potential exploitation. ([thehackernews.com](https://thehackernews.com/2026/05/critical-gogs-rce-vulnerability-lets.html?utm_source=openai))
2 months ago
Kill Chain
Silent Ransom Group's In-Person Data Theft Tactics Target Law Firms
In May 2026, the FBI issued a warning about the Silent Ransom Group (SRG), a Russia-linked extortion gang targeting U.S. law firms. SRG employs sophisticated social engineering tactics, including impersonating IT support staff via phone calls and phishing emails to gain remote access. When these methods fail, they escalate to in-person visits, where operatives physically infiltrate offices, connect external storage devices to computers, and exfiltrate sensitive client data. This data is then used to extort firms, with threats to publish or sell the information if ransoms are not paid. ([techtimes.com](https://www.techtimes.com/articles/317293/20260527/silent-ransom-group-sends-operatives-law-firm-offices-38-firms-already-leaked.htm?utm_source=openai)) This incident underscores a concerning evolution in cybercriminal tactics, blending traditional cyber attacks with physical intrusion. The legal sector's sensitive data makes it a prime target, highlighting the urgent need for robust security protocols, employee training, and vigilance against both digital and physical social engineering threats.
2 months ago
Kill Chain
BTMOB RAT: A New Android Malware-as-a-Service Threat
In May 2026, cybersecurity researchers identified BTMOB, an Android Remote Access Trojan (RAT), actively targeting users in Brazil and Latin America. Distributed through phishing campaigns that mimic legitimate services, BTMOB is sold as a malware-as-a-service (MaaS), allowing attackers to create malicious apps without coding expertise. Once installed, it exploits Android's Accessibility Services to gain elevated permissions, enabling data exfiltration, screen capture, and full remote control of infected devices. This comprehensive access poses significant risks, including financial theft and privacy breaches. The emergence of BTMOB underscores a growing trend in the commoditization of sophisticated malware, lowering the barrier for cybercriminals and expanding the threat landscape. Its MaaS model facilitates rapid adaptation and distribution, making it a formidable challenge for cybersecurity defenses worldwide.
2 months ago
Kill Chain
JINX-0164's Sophisticated Attack on Cryptocurrency Firms
In mid-2025, a previously unidentified threat actor, JINX-0164, initiated a campaign targeting cryptocurrency organizations. Utilizing sophisticated social engineering tactics, the attackers posed as recruiters on LinkedIn, inviting victims to virtual meetings on counterfeit domains resembling legitimate teleconference services. During these meetings, victims were deceived into downloading a malicious file disguised as a meeting client, leading to the installation of a Python-based macOS malware named AUDIOFIX. This malware harvested sensitive data, including credentials from password managers, web browsers, and cryptocurrency wallet extensions, and facilitated lateral movement within the organizations' development infrastructure. ([thehackernews.com](https://thehackernews.com/2026/05/jinx-0164-targets-cryptocurrency-firms.html?utm_source=openai)) The campaign's relevance persists due to the increasing sophistication of social engineering attacks targeting the cryptocurrency sector. The use of custom macOS malware and the focus on compromising development pipelines underscore the evolving tactics of financially motivated threat actors. Organizations must remain vigilant against such multifaceted attacks to safeguard their digital assets. ([thehackernews.com](https://thehackernews.com/2026/05/jinx-0164-targets-cryptocurrency-firms.html?utm_source=openai))
2 months ago
Kill Chain
Microsoft Addresses Risks of Uncoordinated Zero-Day Disclosures
In May 2026, security researcher Chaotic Eclipse publicly disclosed multiple zero-day vulnerabilities affecting Windows components such as Defender and BitLocker. These disclosures were made without prior notification to Microsoft, leading to active exploitation of vulnerabilities like BlueHammer (CVE-2026-33825), RedSun (CVE-2026-41091), and UnDefend (CVE-2026-45498). Microsoft criticized this uncoordinated approach, emphasizing the risks posed to customers and advocating for Coordinated Vulnerability Disclosure (CVD) to allow vendors time to address issues before public release. This incident underscores the ongoing tension between independent security researchers and software vendors regarding disclosure practices. The rapid exploitation of these vulnerabilities highlights the critical need for timely and coordinated communication to mitigate risks and protect end-users effectively.
2 months ago
Kill Chain
Akira Ransomware 2026 Attack: Lessons for Mid-Sized Organizations
In May 2026, a mid-sized organization fell victim to an Akira ransomware attack. The intrusion began with the exploitation of a forgotten local VPN account lacking multi-factor authentication, allowing attackers to gain initial access. Subsequently, they conducted network reconnaissance, escalated privileges, and moved laterally across systems. The attackers exfiltrated sensitive data before deploying ransomware to encrypt files, culminating in a ransom demand. This incident underscores the critical need for robust access controls and vigilant monitoring of network activities to prevent such breaches. The Akira ransomware group has demonstrated a rapid escalation in attack sophistication and frequency, particularly targeting organizations with vulnerable VPN configurations. Their ability to swiftly transition from initial access to full data encryption within hours highlights the urgency for organizations to implement comprehensive cybersecurity measures, including timely patching, multi-factor authentication, and continuous network monitoring.
2 months ago
Kill Chain
Zapier Vulnerabilities Exposed: Potential Account Takeover Risks
In May 2026, security researchers from Token Security identified a chain of five vulnerabilities within Zapier, a widely-used workflow automation service. Exploiting these flaws required only a free Zapier account and could have allowed attackers to impersonate any signed-in user, potentially accessing millions of user accounts and their connected applications. The attack vector involved manipulating user-generated code, retrieving discarded login credentials, and accessing internal storage systems containing private software images. One such image included a publishing key for code running in every logged-in user's browser, enabling attackers to create or alter automations and interact with connected services as legitimate users. ([cyberscoop.com](https://cyberscoop.com/zapier-bug-chain-account-takeover-patched/?utm_source=openai)) This incident underscores the critical importance of securing automation platforms, especially as they gain increased authority to act on behalf of users across multiple services. The vulnerabilities were promptly reported and patched, with no evidence of exploitation. However, organizations are advised to review their automation logs for unauthorized activities and reauthorize connections to sensitive systems to mitigate potential risks. ([cyberscoop.com](https://cyberscoop.com/zapier-bug-chain-account-takeover-patched/?utm_source=openai))
2 months ago
Kill Chain
CISA Mandates Urgent Patching of LiteSpeed cPanel Plugin Vulnerability CVE-2026-48172
In May 2026, a critical privilege escalation vulnerability, CVE-2026-48172, was discovered in the LiteSpeed User-End cPanel Plugin versions 2.3 through 2.4.4. This flaw allows unauthenticated remote attackers to execute arbitrary scripts with root privileges by exploiting the 'lsws.redisAble' function, which mishandles Redis enable/disable features. The vulnerability has been actively exploited in the wild, leading to full system compromises on affected servers. LiteSpeed released urgent security updates to address the issue, urging users to update to version 2.4.5 or later. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-48172/?utm_source=openai)) The exploitation of CVE-2026-48172 underscores the critical importance of timely patch management and the need for robust privilege assignment mechanisms in web hosting environments. The incident highlights the potential risks associated with shared hosting platforms, where a single compromised account can lead to server-wide breaches. Organizations are advised to prioritize the implementation of security patches and to conduct thorough audits of their systems to prevent similar vulnerabilities from being exploited.
2 months ago
Kill Chain
FBI Issues Warning on Silent Ransom Group's In-Person Data Theft Tactics
In May 2026, the FBI issued a warning about the Silent Ransom Group (SRG), an extortion gang targeting U.S. law firms through sophisticated social engineering tactics. SRG actors impersonate IT support personnel via phone calls and phishing emails to gain remote access to victim computers. If these attempts fail, they escalate their efforts by sending individuals in person to the victim's location to physically access computers and exfiltrate sensitive data using external storage devices. The stolen data is then used to extort victims, with threats to sell or publicly disclose the information if ransom demands are not met. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/fbi-warns-of-silent-ransom-group-in-person-data-theft-attacks/?utm_source=openai)) This incident underscores a concerning evolution in cybercriminal tactics, blending traditional phishing with physical infiltration to bypass digital defenses. The legal sector, known for handling highly sensitive information, is particularly vulnerable to such targeted attacks. Organizations must enhance their security protocols, including employee training on social engineering, strict access controls, and monitoring for unauthorized physical access, to mitigate the risks posed by such multifaceted threats.
2 months ago
Kill Chain
Glassworm Botnet Disrupted After Resilient C2 Infrastructure Takedown
In May 2026, a coordinated operation by CrowdStrike, Google, and The Shadowserver Foundation successfully disrupted the Glassworm botnet, which had been targeting software developers through the open-source supply chain since October 2025. The botnet employed resilient command-and-control (C2) infrastructure utilizing Solana blockchain transactions, BitTorrent Distributed Hash Table (DHT), Google Calendar events, and traditional virtual private servers (VPS). This sophisticated architecture enabled Glassworm to persistently deliver malicious payloads, compromising over 300 GitHub repositories and numerous npm packages, thereby posing significant risks to software supply chains. The takedown underscores a critical shift in cyber threats, with adversaries increasingly focusing on developers to infiltrate and compromise software supply chains. This incident highlights the necessity for enhanced security measures within development environments and the importance of safeguarding open-source ecosystems against such sophisticated attacks.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports