The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Urgent: CISA Reports Active Exploitation of SolarWinds Serv-U Vulnerability CVE-2026-28318
In June 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) reported active exploitation of a high-severity vulnerability in SolarWinds Serv-U software, identified as CVE-2026-28318. This flaw allows unauthenticated remote attackers to crash the Serv-U service by sending specially crafted POST requests with the 'Content-Encoding: deflate' header. SolarWinds released Serv-U 15.5.4 Hotfix 1 to address this issue, advising immediate patching or, if not feasible, implementing mitigations such as restricting access to known addresses and blocking POST requests containing 'content-encoding'. The exploitation of CVE-2026-28318 underscores the persistent targeting of file transfer services by threat actors to disrupt operations. Organizations are urged to prioritize patching and enhance monitoring of their file transfer infrastructures to prevent potential service disruptions and data breaches.
3 months ago
Kill Chain
Dark Web Vendor Sentenced to Over 26 Years for Drug Trafficking
In June 2026, Darren Hughes, a 39-year-old from San Jose, California, was sentenced to over 26 years in federal prison for trafficking fentanyl and methamphetamine via the dark web platform Nemesis Market. Hughes operated a vendor store on Nemesis Market, offering free samples of methamphetamine to attract clients. Between 2023 and 2024, he sold methamphetamine and fentanyl pills to undercover law enforcement agents on five occasions, accepting cryptocurrency as payment. His arrest in June 2024 led to the seizure of approximately 672 grams of methamphetamine and a loaded 9mm 'ghost gun' without a serial number. This case underscores the persistent threat posed by dark web marketplaces in facilitating the global distribution of illegal narcotics. Despite the takedown of Nemesis Market in March 2024, similar platforms continue to emerge, highlighting the ongoing challenges law enforcement faces in combating online drug trafficking.
3 months ago
Kill Chain
IronWorm and Miasma Worm Supply Chain Attacks on npm - June 2026
In early June 2026, the npm ecosystem faced significant supply chain attacks involving the IronWorm and a new variant of the Miasma worm. Threat actors compromised over 50 legitimate npm packages to distribute a Rust-based information stealer and a self-propagating worm. The IronWorm malware, concealed by an eBPF kernel rootkit, harvested sensitive data from developers' machines and propagated by injecting malicious code into GitHub repositories. Concurrently, the Miasma worm variant targeted 57 npm packages, deploying credential-stealing payloads that executed during package installation, compromising cloud credentials and CI/CD secrets. These attacks underscore the escalating threats to software supply chains, emphasizing the need for robust security measures in package management and development workflows. The rapid propagation and sophisticated techniques employed highlight the urgency for organizations to enhance their defenses against such evolving threats.
3 months ago
Kill Chain
Gartner Highlights Four Critical Cybersecurity Threats for 2026
In June 2026, Gartner analysts highlighted four critical cybersecurity threats where attackers currently have the upper hand: deepfakes, software supply chain risks, prompt injections, and AI application compromises. These threats exploit vulnerabilities in enterprise defenses, leading to significant security breaches and operational disruptions. Organizations are urged to enhance their security postures by implementing additional controls and stronger policies to mitigate these emerging risks. The urgency to address these threats is underscored by the rapid evolution of attack techniques and the increasing sophistication of threat actors. Enterprises must proactively adapt their security strategies to counteract these advanced threats and protect their assets effectively.
3 months ago
Kill Chain
Critical Authentication Bypass Vulnerability in Palo Alto Networks PAN-OS (CVE-2026-0257)
In May 2026, a critical authentication bypass vulnerability (CVE-2026-0257) was discovered in Palo Alto Networks' PAN-OS software, specifically affecting the GlobalProtect portal and gateway components. This flaw allowed remote, unauthenticated attackers to establish unauthorized VPN connections, potentially exposing internal networks to malicious access. Rapid7's Managed Detection and Response team observed active exploitation of this vulnerability starting on May 17, 2026, leading to its inclusion in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog. Palo Alto Networks released security patches beginning May 15, 2026, urging immediate updates to mitigate the risk. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0257?utm_source=openai)) The exploitation of CVE-2026-0257 underscores the critical importance of timely vulnerability management and patch application. Organizations relying on PAN-OS for secure remote access must ensure their systems are updated to prevent unauthorized access and potential data breaches. This incident highlights the ongoing challenges in securing network infrastructure against rapidly evolving threats.
3 months ago
Kill Chain
TA4922's Global Cybercrime Expansion in 2026
In early 2026, the Chinese-speaking cybercrime group TA4922 significantly expanded its operations beyond East Asia, targeting organizations in Europe and Africa. Utilizing sophisticated social engineering tactics, TA4922 employed localized phishing campaigns impersonating tax authorities and financial departments to distribute malware such as Atlas RAT, RomulusLoader, and SilentRunLoader. These campaigns aimed to gain unauthorized access to systems for data theft, fraud, and resale of access. The group's rapid operational tempo and diverse malware arsenal have made detection and defense increasingly challenging. ([proofpoint.com](https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global?utm_source=openai)) This expansion underscores a broader trend of cybercriminal groups diversifying their targets and techniques, highlighting the need for organizations worldwide to enhance their cybersecurity measures and remain vigilant against evolving threats.
3 months ago
Kill Chain
Adaptive, Agentic AI Worms: A New Era of Cyber Threats
In June 2026, researchers from the University of Toronto, the Vector Institute, and the University of Cambridge developed a proof-of-concept AI-driven worm capable of autonomously analyzing and exploiting vulnerabilities across diverse systems. Unlike traditional worms that rely on predefined exploits, this AI worm utilizes open-weight large language models to adapt its attack strategies in real-time, enabling it to propagate through networks by identifying and leveraging unpatched vulnerabilities and misconfigurations. The worm demonstrated the ability to compromise a simulated enterprise network spanning Linux, Windows, and IoT devices, highlighting a significant evolution in malware capabilities. ([arxiv.org](https://arxiv.org/abs/2606.03811?utm_source=openai)) This development underscores the urgent need for organizations to enhance their cybersecurity defenses against adaptive, AI-powered threats. The emergence of such autonomous malware presents a destabilizing economic asymmetry between attackers and defenders, as the worm's propagation incurs minimal cost to the attacker while posing substantial risks to enterprise networks. ([arxiv.org](https://arxiv.org/abs/2606.03811?utm_source=openai))
3 months ago
Kill Chain
PCPJack's Covert SMTP Relay Network: A Wake-Up Call for Cloud Security
In May 2026, the threat actor known as PCPJack hijacked 230 cloud servers across Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to establish a covert SMTP email relay network. The compromised servers, located in the U.S., Europe, and Asia, were transformed into SMTP proxies, verified for mail relay capabilities, and synchronized to a downstream consumer every five minutes. This operation enabled the threat actor to send large volumes of emails while concealing their origin, potentially facilitating spam campaigns, phishing attacks, or other malicious activities. This incident underscores the increasing sophistication of cloud-based attacks and the critical need for robust security measures in cloud environments. Organizations must implement stringent access controls, regularly monitor for unauthorized activities, and ensure that all cloud services are properly configured to prevent exploitation by threat actors.
3 months ago
Kill Chain
Microsoft AI Red Team Enhances AI Security with Updated Failure Mode Taxonomy
In June 2026, the Microsoft AI Red Team released an updated taxonomy of failure modes in agentic AI systems, building upon their initial April 2025 publication. This revision introduces seven new failure mode categories, expands mitigation strategies, and incorporates insights from a year of red team engagements. Key developments prompting this update include the rapid mainstream adoption of open-source agentic frameworks like OpenClaw, which, upon its January 2026 launch, revealed significant vulnerabilities such as CVE-2026-25253—a critical WebSocket hijacking flaw. Additionally, the maturation of the Model Context Protocol (MCP) ecosystem has led to an increase in vulnerabilities, with 99 CVEs reported in 2025 alone. The transition of computer-use agents from research to production has further exposed novel attack surfaces, necessitating a comprehensive reevaluation of existing security frameworks. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/06/04/updating-taxonomy-failure-modes-agentic-ai-systems-year-red-teaming-taught-us/?utm_source=openai)) This update is particularly relevant as agentic AI systems become more integrated into critical domains, amplifying the potential impact of their failure modes. The introduction of new categories like Agentic Supply Chain Compromise and Goal Hijacking underscores the evolving threat landscape. Organizations must proactively adapt their security measures to address these emerging risks, ensuring the safe deployment and operation of agentic AI systems in increasingly complex environments.
3 months ago
Kill Chain
WeTransfer Phishing Campaign Delivers Multi-Stage Malware via Trusted Services
In June 2026, a sophisticated phishing campaign was identified, leveraging legitimate WeTransfer links to distribute malicious JavaScript files. The attack began with an email containing a WeTransfer link to a file named "Remittance Advice.js," which, upon execution, initiated a multi-stage infection chain. This chain involved decoding and executing PowerShell commands to download and run additional payloads, including a modified .NET DLL disguised within an MSI-branded JPEG image. The attackers utilized trusted cloud services like Cloudflare Workers and R2 to host these malicious payloads, enhancing the campaign's credibility and evading detection mechanisms. This incident underscores the increasing trend of cybercriminals exploiting legitimate platforms to deliver malware, making it imperative for organizations to scrutinize even seemingly trustworthy sources. The use of steganography to conceal malicious code within image files further complicates detection efforts, highlighting the need for advanced threat detection capabilities and continuous monitoring of network traffic to identify and mitigate such sophisticated attacks.
3 months ago
Kill Chain
Active Exploitation of PAN-OS CVE-2026-0257
In May 2026, Palo Alto Networks disclosed an authentication bypass vulnerability, CVE-2026-0257, in its PAN-OS software affecting GlobalProtect portals and gateways. This flaw allows unauthenticated attackers to establish unauthorized VPN connections, potentially exposing internal networks to external threats. The vulnerability has been actively exploited in the wild, leading to its inclusion in CISA's Known Exploited Vulnerabilities catalog on May 29, 2026. Organizations are urged to review their systems for indicators of compromise and apply the recommended mitigations or updates promptly. The active exploitation of CVE-2026-0257 underscores the critical need for organizations to maintain up-to-date security patches and monitor for unauthorized access attempts. This incident highlights the evolving tactics of threat actors targeting network infrastructure vulnerabilities to gain unauthorized access.
3 months ago
Kill Chain
OP-512: New Threat Cluster Targets Microsoft IIS Servers with Custom Web Shells
In June 2026, cybersecurity researchers identified a new threat cluster named OP-512, which targets Microsoft Internet Information Services (IIS) servers to deploy a custom web shell framework. This activity is assessed with moderate to high confidence to be linked to China and is focused on espionage. The attackers utilize a bespoke framework consisting of three web shells that provide remote access while evading detection through techniques like timestomping, which manipulates file timestamps to complicate forensic analysis. The compromised servers automatically report back to the attackers, facilitating centralized management at scale. This incident underscores a growing trend of sophisticated cyber-espionage campaigns targeting critical infrastructure. The use of custom web shells and advanced evasion techniques highlights the evolving tactics of nation-state actors, emphasizing the need for organizations to enhance their security measures to detect and mitigate such threats.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports