✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
New Rowhammer Attacks Compromise NVIDIA GPUs, Leading to Full System Control
In April 2026, independent research teams unveiled novel Rowhammer attacks targeting NVIDIA's Ampere-generation GPUs, specifically the RTX 3060 and RTX 6000 models. These attacks, named GDDRHammer and GeForge, exploit vulnerabilities in GDDR6 memory to induce bit flips, granting attackers arbitrary read/write access to CPU memory and leading to full system compromise. The attacks are particularly effective when IOMMU memory management is disabled, a common default in BIOS settings. ([arstechnica.com](https://arstechnica.com/security/2026/04/new-rowhammer-attacks-give-complete-control-of-machines-running-nvidia-gpus/?utm_source=openai)) The emergence of these GPU-focused Rowhammer attacks signifies a critical evolution in hardware-based vulnerabilities, extending beyond traditional CPU memory exploits. This development underscores the urgent need for enhanced security measures in GPU architectures, especially as GPUs play pivotal roles in cloud computing and AI applications. Organizations must reassess their hardware security protocols to mitigate these advanced threats.
2 months ago
Kill Chain
Latvian National Sentenced for Ransomware Attacks by Former Conti Leaders
In May 2026, Latvian national Deniss Zolotarjovs was sentenced to 102 months in prison for his role in a series of ransomware attacks orchestrated by former leaders of the Conti ransomware group. Between June 2021 and August 2023, Zolotarjovs and his co-conspirators extorted nearly $16 million from over 54 companies, employing multiple aliases such as Conti, Karakurt, Royal, TommyLeaks, SchoolBoys Ransomware, and Akira. Notably, Zolotarjovs pressured victims by threatening to leak sensitive data, including children's health records, to coerce ransom payments. ([cyberscoop.com](https://cyberscoop.com/latvian-russia-ransomware-conti-sentenced/?utm_source=openai)) This case underscores the persistent threat posed by rebranded ransomware groups and highlights the importance of robust cybersecurity measures. Organizations must remain vigilant against evolving tactics employed by cybercriminals, especially those targeting sensitive data to maximize leverage.
2 months ago
Kill Chain
ScarCruft's Supply Chain Attack Delivers BirdCall Malware to Android Users
In May 2026, the North Korean state-sponsored hacking group ScarCruft (APT37) executed a supply chain attack by compromising the sqgame[.]net gaming platform, which serves the Yanbian region in China. The attackers trojanized Android game APKs available on the platform, embedding a new variant of their BirdCall backdoor malware. This Android version of BirdCall is capable of extracting geolocation data, collecting contacts, call logs, SMS messages, device information, and exfiltrating files of interest. Additionally, it can take periodic screenshots and record audio during specific time frames. The campaign appears to target ethnic Koreans in the Yanbian region, a known crossing point for North Korean defectors and refugees. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/scarcruft-hackers-push-birdcall-android-malware-via-game-platform/?utm_source=openai)) This incident underscores the evolving tactics of state-sponsored threat actors, particularly their expansion into mobile platforms through supply chain compromises. The development of Android-specific malware variants like BirdCall highlights the increasing risk to mobile device users, emphasizing the need for heightened vigilance and robust security measures when downloading applications, especially from third-party sources.
2 months ago
Kill Chain
Karakurt Extortion Gang Member Sentenced to 8.5 Years in Prison
In May 2026, Deniss Zolotarjovs, a Latvian national and member of the Russian Karakurt ransomware group, was sentenced to 8.5 years in prison in the United States. Operating under the alias "Sforza_cesarini," Zolotarjovs specialized in "cold case" negotiations, re-engaging with victims who had ceased communication without paying ransoms. Between August 2021 and November 2023, he was linked to at least six extortion cases against American organizations, contributing to over $56 million in losses, including approximately $2.8 million in ransom payments. His tactics included leveraging stolen personal and health information to intensify pressure on victims. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/karakurt-extortion-gang-negotiator-sentenced-to-85-years-in-prison/?utm_source=openai)) This sentencing marks the first conviction of a Karakurt member in the U.S., potentially paving the way for further prosecutions within the group. The case underscores the persistent threat posed by ransomware and extortion groups, highlighting the necessity for robust cybersecurity measures and international cooperation in combating cybercrime. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/karakurt-extortion-gang-negotiator-sentenced-to-85-years-in-prison/?utm_source=openai))
2 months ago
Kill Chain
CloudZ Malware Exploits Microsoft Phone Link to Steal SMS and OTPs
In May 2026, cybersecurity researchers identified a new variant of the CloudZ remote access tool (RAT) that employs a malicious plugin named Pheno to exploit Microsoft's Phone Link application. This malware monitors active Phone Link sessions on Windows 10 and 11 systems, accessing the application's local SQLite database to intercept SMS messages and one-time passwords (OTPs) without compromising the associated mobile device. The attack chain begins with a fake ScreenConnect update, leading to the deployment of a Rust-based loader, followed by a .NET loader that installs CloudZ RAT and establishes persistence via a scheduled task. The .NET loader includes anti-analysis checks to evade detection. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cloudz-malware-abuses-microsoft-phone-link-to-steal-sms-and-otps/?utm_source=openai)) This incident underscores the evolving tactics of threat actors who are increasingly targeting desktop applications that bridge connections to mobile devices. By compromising the Phone Link application, attackers can bypass traditional mobile security measures and directly access sensitive authentication codes, highlighting the need for enhanced security protocols in cross-device applications. ([csoonline.com](https://www.csoonline.com/article/4167092/stealthy-malware-abuses-microsoft-phone-link-to-siphon-sms-otps-from-enterprise-pcs.html?utm_source=openai))
2 months ago
Kill Chain
Critical Spring Security Vulnerability CVE-2026-22732: What You Need to Know
In March 2026, a critical vulnerability identified as CVE-2026-22732 was discovered in Spring Security versions 5.7.0 through 7.0.3. This flaw causes HTTP response headers specified for servlet applications to be omitted, potentially exposing applications to attacks such as Cross-Site Scripting (XSS) and clickjacking. The vulnerability affects applications using the default lazy writing of HTTP headers, leading to the absence of essential security headers in responses. ([spring.io](https://spring.io/security/cve-2026-22732?utm_source=openai)) The omission of these headers undermines client-side protections, increasing the risk of sensitive data exposure and other security breaches. Organizations utilizing affected versions of Spring Security are urged to upgrade to the latest patched versions or apply recommended workarounds to mitigate this risk. ([spring.io](https://spring.io/security/cve-2026-22732?utm_source=openai))
2 months ago
Kill Chain
DAEMON Tools Supply Chain Attack: A Wake-Up Call for Software Security
In April 2026, a sophisticated supply chain attack compromised the official installers of DAEMON Tools, a widely used virtual drive emulation software. Attackers injected malicious code into the software's installers, which were distributed from the legitimate DAEMON Tools website and signed with valid digital certificates. This allowed the malware to execute arbitrary commands and remotely control infected devices. The compromised versions, ranging from 12.5.0.2421 to 12.5.0.2434, have been in circulation since April 8, 2026. The attack has affected users in over 100 countries, with significant impacts in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China. Approximately 10% of the affected systems belong to businesses and organizations, exposing enterprise networks to severe risks. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/kaspersky-identifies-ongoing-supply-chain-attack-on-official-daemon-tools-website-distributing-backdoor-malware?utm_source=openai)) This incident underscores the growing threat of supply chain attacks, where trusted software is exploited to distribute malware. The DAEMON Tools compromise highlights the need for organizations to implement stringent software procurement protocols, conduct regular security audits, and enforce strict administrative privileges to mitigate such risks. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/kaspersky-identifies-ongoing-supply-chain-attack-on-official-daemon-tools-website-distributing-backdoor-malware?utm_source=openai))
2 months ago
Kill Chain
Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
In May 2026, the Apache Software Foundation disclosed a critical vulnerability (CVE-2026-23918) in Apache HTTP Server version 2.4.66, involving a double-free error in the HTTP/2 protocol handling. This flaw allows attackers to execute denial-of-service attacks and potentially achieve remote code execution by sending specific HTTP/2 frames. The issue was identified by researchers Bartlomiej Dmitruk and Stanislaw Strzalkowski and has been addressed in version 2.4.67. Organizations using affected versions are urged to upgrade immediately to mitigate the risk. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-23918?utm_source=openai)) The widespread adoption of HTTP/2 and the default inclusion of mod_http2 in many deployments amplify the urgency of this vulnerability. Exploitation could lead to significant service disruptions and unauthorized access, underscoring the importance of prompt patching and vigilant monitoring of server configurations.
2 months ago
Kill Chain
Urgent: cPanel Vulnerability CVE-2026-41940 Under Active Exploitation
In late April 2026, a critical authentication bypass vulnerability, CVE-2026-41940, was disclosed in cPanel and WHM software, affecting versions after 11.40. This flaw allows unauthenticated remote attackers to gain administrative access to servers, posing a significant risk to millions of websites. Within 24 hours of disclosure, multiple threat actors began exploiting the vulnerability, leading to server compromises, website defacements, and ransomware deployments. Notably, the "sorry" ransomware encrypts files and appends a ".sorry" extension, with over 7,000 cPanel instances identified as compromised. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/04/multiple-threat-actors-actively-exploit-cpanel-vulnerability-cve-2026-41940/?utm_source=openai)) The rapid exploitation of CVE-2026-41940 underscores the critical need for organizations to promptly apply security patches and implement robust monitoring systems. The incident highlights the increasing speed at which threat actors exploit newly disclosed vulnerabilities, emphasizing the importance of proactive cybersecurity measures.
2 months ago
Kill Chain
VENOMOUS#HELPER: Phishing Campaign Leveraging RMM Tools Targets 80+ Organizations
Since April 2025, the VENOMOUS#HELPER phishing campaign has targeted over 80 organizations, primarily in the United States, by exploiting legitimate Remote Monitoring and Management (RMM) tools—SimpleHelp and ScreenConnect—to establish persistent remote access. Attackers initiate the campaign with phishing emails impersonating the U.S. Social Security Administration, leading victims to download malicious executables that install these RMM tools, thereby bypassing traditional security defenses. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/rmm-tools-stealthy-phishing-campaign?utm_source=openai)) This incident underscores a growing trend of cybercriminals leveraging trusted software to evade detection, highlighting the need for organizations to scrutinize the use of legitimate tools within their networks and enhance employee awareness to recognize sophisticated phishing attempts. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/rmm-tools-stealthy-phishing-campaign?utm_source=openai))
2 months ago
Kill Chain
Microsoft Edge's Cleartext Password Storage: A Security Wake-Up Call
In May 2026, security researcher Tom Jøran Sønstebyseter Rønning disclosed that Microsoft Edge decrypts and stores all saved user passwords in cleartext within process memory upon browser launch, retaining them throughout the session. This design allows attackers with administrative privileges to access these credentials, posing significant risks in shared and enterprise environments. Microsoft confirmed this behavior is intentional, stating it is 'by design.' This incident underscores the critical need for organizations to reassess their reliance on browser-based password storage solutions. The exposure of credentials in memory highlights vulnerabilities that can be exploited, emphasizing the importance of adopting dedicated password management tools and implementing robust security policies to mitigate such risks.
2 months ago
Kill Chain
Microsoft Phishing Campaign April 2026: A Deep Dive into AiTM Credential Theft
In April 2026, Microsoft identified a sophisticated phishing campaign that targeted over 35,000 users across 13,000 organizations in 26 countries, with 92% of the targets located in the United States. The attackers employed code of conduct-themed lures, using polished HTML templates and legitimate email services to enhance credibility. Victims were directed through multiple CAPTCHA and intermediate pages, culminating in adversary-in-the-middle (AiTM) phishing tactics that harvested Microsoft credentials and authentication tokens, effectively bypassing multi-factor authentication (MFA). The campaign primarily targeted sectors such as healthcare, financial services, professional services, and technology. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/?utm_source=openai)) This incident underscores the evolving sophistication of phishing attacks, highlighting the need for organizations to enhance their security measures. The use of legitimate services and advanced techniques like AiTM phishing to bypass MFA indicates a significant escalation in threat actor capabilities, necessitating continuous vigilance and adaptation of security protocols. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/?utm_source=openai))
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports