The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Hades Campaign: A New Threat to PyPI Security
In June 2026, a sophisticated supply chain attack targeted the Python Package Index (PyPI), compromising 37 wheels across 19 packages. The attackers, adopting a 'Hades' naming convention, deployed a variant of the Shai-Hulud worm, which is known for its self-propagating and information-stealing capabilities. This malware infects software components, utilizes the access to publish malicious versions, and harvests repository accounts of downstream users. The attack chain's cross-runtime design involved the installation of Bun—a JavaScript runtime—as a heavily obfuscated JavaScript stealer before executing the payload. This incident underscores the persistent and evolving nature of software supply chain threats. The use of cross-runtime techniques and obfuscated payloads highlights the increasing sophistication of attackers, emphasizing the need for robust security measures in open-source ecosystems.
3 months ago
Kill Chain
UNC3753's 2026 Data Theft Campaign: A Blend of Vishing and Physical Intrusions
Between January and May 2026, the threat actor UNC3753, also known as Chatty Spider, Luna Moth, and Silent Ransom Group (SRG), targeted numerous U.S. organizations in the professional, legal, and financial sectors. Utilizing voice phishing (vishing) and social engineering tactics, they impersonated IT support to gain remote access via screen-sharing sessions and remote monitoring tools. In some cases, attackers physically infiltrated offices, posing as IT technicians to exfiltrate data using USB devices. Stolen information included proprietary legal agreements, personally identifiable information (PII), and financial records. The group rapidly demanded ransoms, threatening to publish the stolen data if payments were not made promptly. This incident underscores the evolving tactics of cybercriminals, combining traditional social engineering with physical intrusion methods. The rapid execution of these attacks, often completed within a single business day, highlights the need for organizations to enhance their security awareness training and implement robust verification processes for IT support interactions.
3 months ago
Kill Chain
Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
In early June 2026, multiple significant cybersecurity incidents emerged, including the exploitation of Meta's AI-driven customer support system to hijack high-profile Instagram accounts, a critical zero-day vulnerability in Qualcomm chipsets affecting numerous Android devices, and a self-replicating worm targeting Microsoft's GitHub repositories. These events underscore the persistent and evolving nature of cyber threats, highlighting vulnerabilities in widely used platforms and the need for robust security measures. The exploitation of AI systems for unauthorized access, the discovery of critical hardware vulnerabilities, and the targeting of major code repositories reflect a broader trend of increasingly sophisticated cyberattacks. Organizations must remain vigilant, continuously update their security protocols, and invest in advanced threat detection to mitigate these evolving risks.
3 months ago
Kill Chain
Red Hat npm Packages Compromised in June 2026 Supply Chain Attack
In June 2026, a sophisticated supply chain attack was identified, involving the compromise of Red Hat's npm packages. Attackers infiltrated a Red Hat employee's GitHub account, injecting malware into numerous npm packages under the Red Hat Cloud Services namespace. This breach led to over 80,000 downloads of compromised packages within a week, targeting sensitive data such as GitHub Actions secrets, npm tokens, SSH keys, and cloud credentials. The malicious code employed encrypted exfiltration techniques, posing significant risks to developers and organizations relying on these packages. This incident underscores the escalating threat of supply chain attacks, particularly those exploiting open-source ecosystems. The attackers' use of advanced techniques, including encrypted exfiltration and targeting cloud identities, highlights the need for enhanced vigilance and robust security measures in software development and distribution processes.
3 months ago
Kill Chain
Critical Check Point VPN Flaw Exploited: CVE-2026-50751
In early June 2026, Check Point Software Technologies disclosed active exploitation of a critical vulnerability, CVE-2026-50751, affecting their Remote Access VPN and Mobile Access products configured with the deprecated IKEv1 key exchange protocol. This flaw allows unauthenticated remote attackers to bypass user authentication and establish unauthorized VPN connections. Exploitation has been observed since at least May 7, 2026, with increased activity in early June, including incidents linked to a Qilin ransomware affiliate. ([blog.checkpoint.com](https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/amp/?utm_source=openai)) The incident underscores the risks associated with using outdated protocols like IKEv1, which, despite being deprecated, remain in use for legacy compatibility. Organizations are urged to disable IKEv1 and apply security updates to mitigate this vulnerability. ([blog.checkpoint.com](https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/amp/?utm_source=openai))
3 months ago
Kill Chain
AI-Generated Phishing Attacks Overwhelm SOCs in 2026
In early 2026, organizations experienced a surge in AI-generated phishing attacks, leading to an overwhelming increase in security alerts. These sophisticated campaigns utilized generative AI to craft convincing emails and evade traditional detection methods, significantly burdening Security Operations Centers (SOCs). As a result, SOCs faced challenges in effectively triaging and responding to the high volume of alerts, with only 37% of daily security alerts being investigated. This escalation in alert volume not only strained resources but also increased the risk of overlooking genuine threats, thereby elevating the overall cost and complexity of cybersecurity operations. ([prnewswire.com](https://www.prnewswire.com/news-releases/new-research-reveals-enterprises-investigate-just-37-of-daily-security-alerts-as-ai-expands-in-the-soc-302717184.html?utm_source=openai)) The proliferation of AI-driven phishing attacks underscores the urgent need for organizations to adapt their cybersecurity strategies. Traditional defense mechanisms are proving inadequate against the scale and sophistication of these threats. Implementing advanced AI-powered defenses and enhancing SOC capabilities are critical to effectively manage and mitigate the risks associated with AI-generated phishing campaigns.
3 months ago
Kill Chain
C0XMO Botnet's 2026 Exploitation of DD-WRT Router Vulnerability
In June 2026, the C0XMO botnet, a sophisticated variant of the Gafgyt malware, exploited a buffer overflow vulnerability (CVE-2021-27137) in DD-WRT router firmware to compromise devices across multiple CPU architectures, including ARM, MIPS, and x86. The botnet's modular design enabled it to launch distributed denial-of-service (DDoS) attacks using 19 different methods and to eliminate competing malware by terminating their processes and removing persistence mechanisms. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/?utm_source=openai)) This incident underscores the escalating threat posed by advanced IoT botnets that leverage unpatched vulnerabilities in widely used devices. Organizations must prioritize timely firmware updates, enforce strong authentication practices, and disable unnecessary remote access to mitigate such risks.
3 months ago
Kill Chain
Silent Ransom Group Exploits Law Firms with Sophisticated Social Engineering Attacks
In early 2026, the Silent Ransom Group (SRG), also known as Luna Moth and Chatty Spider, targeted U.S. law firms and professional services organizations through sophisticated social engineering attacks. The group initiated contact via invoice-themed phishing emails, followed by phone calls impersonating corporate IT staff. They convinced employees to join remote support sessions, leading to the installation of remote monitoring tools like AnyDesk and Zoho Assist, granting attackers access to sensitive legal and financial documents. Data exfiltration was conducted using tools such as WinSCP and Rclone, with ransom demands issued within 30 minutes of the attackers' departure. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/silent-ransom-group-targets-law-firms-with-fake-it-support-calls/?utm_source=openai)) This incident underscores a concerning trend of cybercriminals employing direct social engineering tactics, including in-person impersonation, to infiltrate organizations. The rapid escalation from initial contact to data theft and extortion highlights the need for enhanced employee training and robust verification procedures to counter such evolving threats. ([techcrunch.com](https://techcrunch.com/2026/06/05/google-and-fbi-warn-of-ransomware-group-that-sends-fake-it-workers-to-hack-victims-in-person/?utm_source=openai))
3 months ago
Kill Chain
Miasma Worm Infiltrates 73 Microsoft GitHub Repositories in Major 2026 Supply Chain Attack
In June 2026, Microsoft faced a significant supply chain attack when the self-replicating Miasma worm compromised 73 of its GitHub repositories across organizations such as Azure, Azure-Samples, Microsoft, and MicrosoftDocs. The worm embedded malicious code that activated upon developers cloning and opening the affected repositories in AI coding agents, leading to the harvesting of credentials for platforms including AWS, Azure, GCP, Kubernetes, npm, and GitHub. This incident underscores the evolving nature of supply chain attacks, particularly targeting AI-assisted development tools. The Miasma worm, a variant of the Mini Shai-Hulud worm, exploits the inherent trust in authenticated maintainers and signed packages, highlighting the need for enhanced security measures in software development and distribution processes.
3 months ago
Kill Chain
CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog
In early June 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a high-severity vulnerability, CVE-2026-28318, affecting SolarWinds Serv-U, to its Known Exploited Vulnerabilities (KEV) catalog. This denial-of-service (DoS) flaw allows unauthenticated attackers to crash the Serv-U service by sending specially crafted POST requests with the 'Content-Encoding: deflate' header. The vulnerability has a CVSS score of 7.5 and is actively being exploited in the wild. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-28318?utm_source=openai)) The inclusion of this vulnerability in the KEV catalog underscores the critical need for organizations to promptly apply security patches. Unpatched systems remain susceptible to service disruptions, which can have significant operational and financial impacts. ([scworld.com](https://www.scworld.com/brief/hackers-actively-exploit-solarwinds-serv-u-flaw-to-crash-servers-cisa-warns?utm_source=openai))
3 months ago
Kill Chain
Critical SolarWinds Serv-U Vulnerability (CVE-2026-28318) Under Active Exploitation
In early June 2026, a critical vulnerability identified as CVE-2026-28318 was discovered in SolarWinds Serv-U software. This flaw allows unauthenticated attackers to send specially crafted POST requests with 'Content-Encoding: deflate' headers, leading to uncontrolled resource consumption and subsequent service crashes. The vulnerability has been actively exploited in the wild, prompting the Cybersecurity and Infrastructure Security Agency (CISA) to add it to their Known Exploited Vulnerabilities (KEV) catalog. Organizations utilizing affected versions of Serv-U are at significant risk of service disruptions and potential data loss. The inclusion of CVE-2026-28318 in CISA's KEV catalog underscores the urgency for organizations to address this vulnerability promptly. With active exploitation observed, it is imperative for entities using SolarWinds Serv-U to apply the recommended patches or mitigations to prevent potential service outages and safeguard sensitive information.
3 months ago
Kill Chain
Cisco SD-WAN Vulnerability CVE-2026-20245: Root Privilege Escalation Risk
In June 2026, Cisco disclosed a high-severity vulnerability (CVE-2026-20245) in its Catalyst SD-WAN Manager, formerly known as SD-WAN vManage. This flaw arises from insufficient validation of user-supplied input, allowing authenticated local attackers with netadmin privileges to execute arbitrary commands as the root user by uploading crafted files. Exploitation of this vulnerability has been observed in limited cases, leading to unauthorized configuration changes pushed to edge devices. The ongoing exploitation of this zero-day vulnerability underscores the persistent targeting of network management systems by threat actors. Organizations utilizing Cisco's SD-WAN solutions should prioritize reviewing their systems for indicators of compromise and apply recommended mitigations promptly to prevent potential breaches and maintain network integrity.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports