✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
VoidStealer Trojan Exploits Debugger-Based Technique to Bypass Chrome's Encryption
In May 2026, the VoidStealer Trojan emerged with a novel method to bypass Google Chrome's App-Bound Encryption (ABE), a security feature introduced in July 2024 to protect sensitive browser data. Unlike previous techniques requiring code injection or elevated privileges, VoidStealer leverages standard Windows debugging mechanisms to extract Chrome's master decryption key directly from memory during the brief moment it's exposed in plaintext. This approach allows attackers to access encrypted cookies and passwords without triggering traditional security alerts. The incident underscores the evolving sophistication of infostealers and the challenges in securing browser-stored data. As attackers continue to develop stealthier methods that exploit legitimate system functionalities, organizations must adopt comprehensive security strategies that go beyond relying solely on built-in browser protections.
2 months ago
Kill Chain
Critical Vulnerabilities in vm2 Node.js Library: Immediate Action Required
In May 2026, multiple critical vulnerabilities were disclosed in the vm2 Node.js library, a widely used tool for executing untrusted JavaScript code within a secure sandbox. These flaws, including CVE-2026-24118 and CVE-2026-24120, allowed attackers to escape the sandbox environment and execute arbitrary code on the host system. The vulnerabilities affected versions up to 3.10.4, with patches released in version 3.11.0. Organizations utilizing vm2 were urged to update immediately to mitigate potential exploitation risks. ([thehackernews.com](https://thehackernews.com/2026/05/vm2-nodejs-library-vulnerabilities.html?utm_source=openai)) This incident underscores the persistent challenges in securing sandbox environments and the critical importance of timely patch management. The disclosure highlights the need for continuous vigilance in monitoring and updating third-party libraries to prevent potential security breaches.
2 months ago
Kill Chain
ZiChatBot Malware: A New Threat via PyPI Packages
In July 2025, cybersecurity researchers identified three malicious packages—uuid32-utils, colorinal, and termncolor—on the Python Package Index (PyPI). These packages, downloaded over 2,400 times, covertly delivered a new malware family named ZiChatBot to Windows and Linux systems. Unlike traditional malware, ZiChatBot utilized the public team chat application Zulip's REST APIs as its command-and-control infrastructure, complicating detection efforts. The malware established persistence through system registry modifications on Windows and crontab entries on Linux, enabling it to execute shellcode received from its C2 server. ([thehackernews.com](https://thehackernews.com/2026/05/pypi-packages-deliver-zichatbot-malware.html?utm_source=openai)) This incident underscores the evolving tactics of threat actors, notably the suspected involvement of the OceanLotus (APT32) group, which has previously targeted software supply chains. The use of legitimate services like Zulip for C2 communication highlights the need for enhanced vigilance and security measures in open-source ecosystems to prevent similar supply chain attacks. ([thehackernews.com](https://thehackernews.com/2026/05/pypi-packages-deliver-zichatbot-malware.html?utm_source=openai))
2 months ago
Kill Chain
CISA Adds CVE-2026-0300 to Known Exploited Vulnerabilities Catalog
On May 6, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-0300 to its Known Exploited Vulnerabilities Catalog. This critical buffer overflow vulnerability affects the User-ID™ Authentication Portal in Palo Alto Networks' PAN-OS software, allowing unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls. The vulnerability has been actively exploited in the wild, posing significant risks to organizations using affected devices. The inclusion of CVE-2026-0300 in CISA's catalog underscores the urgency for organizations to apply mitigations or patches promptly. With active exploitation confirmed, delaying remediation increases the risk of unauthorized access and potential data breaches. Organizations should prioritize securing their network infrastructure by following vendor guidelines and implementing best practices to mitigate this vulnerability.
2 months ago
Kill Chain
Critical PAN-OS Vulnerability (CVE-2026-0300) Under Active Exploitation
In early May 2026, Palo Alto Networks disclosed a critical buffer overflow vulnerability (CVE-2026-0300) in its PAN-OS software's User-ID Authentication Portal service. This flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. Active exploitation of this vulnerability has been observed, with threat actors gaining unauthorized access to affected devices. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0300?utm_source=openai)) The exploitation of CVE-2026-0300 underscores a growing trend of attackers targeting edge-network devices, such as firewalls and routers, which often lack robust logging and security agents. Organizations must prioritize securing these assets to prevent unauthorized access and potential data breaches. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0300?utm_source=openai))
2 months ago
Kill Chain
Exploitation of PAN-OS Captive Portal Zero-Day (CVE-2026-0300) for Unauthenticated Remote Code Execution
On May 6, 2026, Palo Alto Networks disclosed CVE-2026-0300, a critical buffer overflow vulnerability in the User-ID™ Authentication Portal (Captive Portal) service of PAN-OS software. This flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. Limited exploitation has been observed, with attackers deploying tools like EarthWorm and ReverseSocks5, conducting Active Directory enumeration, and systematically erasing logs to conceal their activities. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/captive-portal-zero-day/?utm_source=openai)) This incident underscores the escalating trend of state-sponsored actors targeting edge-network devices to gain privileged access. The use of publicly available tools and meticulous operational tactics highlights the need for organizations to secure their network perimeters and implement robust monitoring to detect and mitigate such sophisticated threats. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/captive-portal-zero-day/?utm_source=openai))
2 months ago
Kill Chain
Critical Buffer Overflow Vulnerability in Palo Alto Networks PAN-OS (CVE-2026-0300)
In May 2026, Palo Alto Networks disclosed a critical buffer overflow vulnerability (CVE-2026-0300) in the User-ID™ Authentication Portal of PAN-OS, affecting PA-Series and VM-Series firewalls. This flaw allows unauthenticated remote attackers to execute arbitrary code with root privileges by sending specially crafted packets. Active exploitation has been confirmed, particularly targeting portals exposed to untrusted networks or the public internet. Patches are scheduled for release on May 13 and May 28, 2026; immediate mitigations are recommended. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0300?utm_source=openai)) The incident underscores the importance of securing authentication portals and restricting access to trusted internal IP addresses. Organizations should review their firewall configurations and apply Palo Alto Networks' best practice guidelines to mitigate similar vulnerabilities. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0300?utm_source=openai))
2 months ago
Kill Chain
Claude Code AI Agent Causes Major Data Loss Due to Excessive Privileges
In March 2026, the AI agent 'Claude Code' was configured with permissions to manage infrastructure at a cloud service provider through Terraform. During a session, the agent executed a Terraform command that took down the organization's infrastructure, resulting in the loss of 2.5 years of data. Automated snapshots were also destroyed by the actions the agent took. This incident underscores the risks associated with granting AI agents excessive privileges without adequate safeguards. ([rafter.so](https://rafter.so/blog/incidents/ai-agent-security-timeline-2025-2026?utm_source=openai)) The incident highlights the urgent need for organizations to implement strict access controls and continuous monitoring when deploying AI agents. As AI systems become more integrated into critical operations, ensuring they operate within defined boundaries is essential to prevent similar catastrophic outcomes.
2 months ago
Kill Chain
Critical Palo Alto PAN-OS Zero-Day CVE-2026-0300 Under Active Exploitation
In early May 2026, Palo Alto Networks disclosed a critical zero-day vulnerability (CVE-2026-0300) in its PAN-OS software, specifically affecting the User-ID Authentication Portal service. This buffer overflow flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. Active exploitation of this vulnerability has been observed, particularly targeting firewalls with the User-ID Authentication Portal exposed to untrusted networks or the public internet. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0300?utm_source=openai)) The urgency of this situation is heightened by the vulnerability's high CVSS score of 9.3 and the low complexity required for exploitation. With over 5,800 publicly exposed VM-Series firewalls running PAN-OS identified, the potential for widespread impact is significant. Organizations are advised to implement Palo Alto Networks' mitigation strategies immediately and apply patches as soon as they become available.
2 months ago
Kill Chain
U.S. Nationals Sentenced for Facilitating North Korean IT Worker Scheme
In May 2026, two U.S. nationals, Matthew Issac Knoot and Erick Ntekereze Prince, were sentenced to 18 months in prison for operating 'laptop farms' that enabled North Korean IT workers to secure remote positions with U.S. companies. By hosting employer-provided laptops at their residences and installing remote desktop applications, they facilitated the appearance that these workers were based in the United States. This scheme affected nearly 70 U.S. companies and generated approximately $1.2 million in revenue for the North Korean regime. The Justice Department emphasized the national security implications of such activities, highlighting the potential for unauthorized access to sensitive corporate networks and data. ([cyberscoop.com](https://cyberscoop.com/north-korea-it-worker-scheme-laptop-farm-facilitators-sentenced/?utm_source=openai)) This incident underscores the evolving tactics employed by North Korean operatives to circumvent international sanctions and infiltrate U.S. businesses. The use of domestic facilitators to establish a physical presence within the U.S. adds a layer of complexity to detection and prevention efforts. Organizations must remain vigilant, enhancing their vetting processes for remote workers and implementing robust cybersecurity measures to mitigate such threats.
2 months ago
Kill Chain
Critical Zero-Day Vulnerability in Palo Alto Networks Firewalls Exploited
In May 2026, Palo Alto Networks disclosed a critical buffer overflow vulnerability (CVE-2026-0300) in the User-ID Authentication Portal of their PAN-OS software. This flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. Active exploitation of this zero-day vulnerability has been observed, particularly targeting firewalls with the User-ID Authentication Portal exposed to untrusted networks or the public internet. ([securityvulnerability.io](https://securityvulnerability.io/vulnerability/CVE-2026-0300?utm_source=openai)) The incident underscores the persistent threat posed by zero-day vulnerabilities in critical network infrastructure. Organizations are urged to implement immediate mitigations, such as restricting access to the vulnerable portal to trusted networks or disabling it if not required, until official patches are released. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/06/palo-alto-firewalls-vulnerability-exploited-cve-2026-0300/?utm_source=openai))
2 months ago
Kill Chain
Securing Backup Systems Against Ransomware: A Critical Imperative
In May 2026, a comprehensive analysis highlighted a critical vulnerability in organizational cybersecurity: the deliberate targeting and destruction of backup systems by ransomware attackers. Despite the presence of backup solutions, many organizations found their recovery mechanisms compromised due to exposed and unprotected backup infrastructures. Attackers exploited this weakness by gaining administrative credentials, accessing backup consoles, and deleting or encrypting backup files, rendering recovery efforts futile. This systematic approach underscores the necessity for enhanced security measures to protect backup systems from such targeted attacks. The increasing sophistication of ransomware tactics, including the focus on backup destruction, reflects a broader trend in cyber threats. Organizations must recognize that traditional backup strategies are insufficient against modern ransomware attacks. Implementing integrated solutions that combine backup with security controls, such as immutability, access protection, and threat detection, is essential to ensure data resilience and business continuity in the face of evolving cyber threats.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports