The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Shai-Hulud 2.0: Unveiling the 2025 npm Supply Chain Attack
In November 2025, the Shai-Hulud 2.0 supply chain attack emerged as a significant threat to the npm ecosystem. Attackers compromised hundreds of npm packages by injecting malicious preinstall scripts that executed before installation completion. These scripts harvested sensitive data, including credentials and configuration secrets, from developer environments and CI/CD pipelines, exfiltrating them to attacker-controlled repositories. The malware exhibited worm-like behavior, autonomously spreading by publishing malicious versions of accessible packages, thereby propagating across the npm ecosystem. Major projects such as Zapier, Ethereum Name Service (ENS), PostHog, and Postman were affected, with over 25,000 repositories compromised within a few hours. ([blog.checkpoint.com](https://blog.checkpoint.com/research/shai-hulud-2-0-inside-the-second-coming-the-most-aggressive-npm-supply-chain-attack-of-2025/?utm_source=openai)) This incident underscores the escalating sophistication of supply chain attacks targeting open-source ecosystems. The rapid propagation and automation observed in Shai-Hulud 2.0 highlight the urgent need for enhanced security measures in software development pipelines. Organizations must prioritize securing their development environments, implement robust monitoring, and adopt best practices to mitigate the risks associated with such pervasive threats.
3 months ago
Kill Chain
CERT-In's 12-Hour Patching Mandate: A Response to AI-Driven Cyber Threats
In May 2026, the Indian Computer Emergency Response Team (CERT-In) issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of identification. This directive aims to mitigate threats from adversaries leveraging artificial intelligence (AI) tools and large language models (LLMs) to automate vulnerability discovery and exploitation, thereby accelerating the scale and speed of cyber attacks. CERT-In emphasized that AI-assisted cyber exploitation reduces the time required for adversaries to identify, weaponize, and exploit vulnerabilities, exposed services, weak identities, insecure APIs, and misconfigured systems. As organizations become increasingly dependent on interconnected digital infrastructure, cloud ecosystems, software supply chains, operational technologies, and AI-enabled platforms, the potential impact of AI-enabled cyber threats continues to increase across sectors. ([thehackernews.com](https://thehackernews.com/2026/05/cert-in-mandates-12-hour-patching-for.html?utm_source=openai)) This development underscores the evolving cyber threat landscape, where AI technologies are being harnessed to compress attack timelines and bypass traditional security controls. Organizations are urged to adopt proactive cybersecurity measures, including continuous threat assessment, proactive exposure reduction, and operational preparedness, to effectively counter these AI-assisted threats.
3 months ago
Kill Chain
Understanding and Mitigating MFA Prompt Bombing Attacks in 2026
In May 2026, a significant cybersecurity threat emerged involving Multi-Factor Authentication (MFA) prompt bombing attacks. Cybercriminals exploited push-based MFA systems by repeatedly sending authentication requests to users, aiming to induce fatigue and prompt them to approve unauthorized access. This method effectively bypassed traditional MFA protections, leading to unauthorized access to sensitive systems and data. The attacks primarily targeted organizations utilizing push-based MFA for services like Microsoft 365, VPNs, and other cloud applications, resulting in compromised accounts and potential data breaches. The prevalence of MFA prompt bombing underscores the evolving tactics of threat actors who leverage social engineering to circumvent security measures. This trend highlights the necessity for organizations to adopt more resilient authentication methods, such as number-matching codes or hardware tokens, and to implement comprehensive user education programs to recognize and resist such attacks.
3 months ago
Kill Chain
Microsoft Releases Critical Patch for SharePoint RCE Vulnerability CVE-2026-45659
In May 2026, Microsoft addressed a critical remote code execution vulnerability, CVE-2026-45659, in SharePoint Server versions 2016, 2019, and Subscription Edition. This flaw arises from the deserialization of untrusted data, allowing authenticated attackers with minimal permissions to execute arbitrary code remotely without user interaction. The vulnerability has a CVSS score of 8.8, indicating high severity. ([thehackernews.com](https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html?utm_source=openai)) The prompt release of patches underscores the importance of timely updates, especially given SharePoint's role in storing sensitive corporate data. Organizations are urged to apply these updates promptly to mitigate potential exploitation risks. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/26/sharepoint-vulnerability-cve-2026-45659/?utm_source=openai))
3 months ago
Kill Chain
Cybercriminals Exploit Claude AI Popularity to Distribute Malware
In early 2026, cybercriminals launched a sophisticated campaign targeting users seeking to download Anthropic's Claude AI tool. By creating fraudulent websites that closely mimicked the official Claude download pages, attackers distributed trojanized installers. These malicious installers appeared legitimate but secretly deployed malware, such as PlugX and ACR Stealer, granting attackers remote access to victims' systems and enabling the theft of sensitive information, including credentials and financial data. The campaign exploited users' trust in search engine results and official-looking websites, leading to widespread infections across both Windows and macOS platforms. This incident underscores a growing trend where threat actors leverage the popularity of AI tools to execute social engineering attacks. The use of fake installation guides and malicious advertisements highlights the need for heightened vigilance among users and organizations. As AI tools become more integrated into daily operations, ensuring the authenticity of download sources and implementing robust cybersecurity measures are imperative to prevent similar attacks.
3 months ago
Kill Chain
Anthropic's Claude Mythos: Revolutionizing Cybersecurity with AI
In April 2026, Anthropic introduced 'Claude Mythos,' an advanced AI model with exceptional capabilities in identifying and exploiting software vulnerabilities. The model demonstrated the ability to autonomously develop sophisticated cyberattacks, raising significant concerns about its potential misuse. To mitigate these risks, Anthropic restricted public access to Mythos, collaborating with select partners through Project Glasswing to enhance cybersecurity defenses. ([euronews.com](https://www.euronews.com/next/2026/04/08/why-anthropics-most-powerful-ai-model-mythos-preview-is-too-dangerous-for-public-release?utm_source=openai)) The emergence of AI models like Claude Mythos signifies a paradigm shift in cybersecurity, where AI can both uncover and exploit vulnerabilities at unprecedented speeds. This development underscores the urgent need for robust security measures and proactive strategies to address the dual-use nature of such technologies. ([cfr.org](https://www.cfr.org/articles/six-reasons-claude-mythos-is-an-inflection-point-for-ai-and-global-security?utm_source=openai))
4 months ago
Kill Chain
FBI Issues Warning on Kali365 Phishing Service Exploiting Microsoft 365 Accounts
In April 2026, the FBI identified 'Kali365,' a Phishing-as-a-Service (PhaaS) platform distributed via Telegram, enabling cybercriminals to hijack Microsoft 365 accounts. By exploiting Microsoft's OAuth 2.0 Device Authorization grant flow, attackers trick users into entering device codes on legitimate Microsoft pages, granting unauthorized access to services like Outlook, Teams, and OneDrive. This method bypasses multi-factor authentication (MFA) and does not require stealing user credentials. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/fbi-warns-of-kali365-phishing-service-targeting-microsoft-365-accounts/?utm_source=openai)) The emergence of Kali365 underscores a significant shift in cyber threats, where sophisticated phishing tools are now accessible to less-skilled attackers. This trend highlights the urgent need for organizations to reassess and strengthen their authentication protocols and user education to mitigate evolving phishing tactics. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260521?utm_source=openai))
4 months ago
Kill Chain
Dutch Authorities Dismantle Cyberattack Infrastructure Linked to Russian Operations
In May 2026, Dutch authorities arrested two individuals, aged 57 and 39, for allegedly providing IT infrastructure used by Russian entities to conduct cyberattacks and disinformation campaigns within the European Union. The arrests followed investigations into Stark Industries Solutions, a hosting provider sanctioned by the EU in 2025 for facilitating Russian cyber operations. The suspects, associated with MIRhosting and WorkTitans BV, were charged with violating sanctions laws by making economic resources available to sanctioned entities. During the operation, over 800 servers were seized from data centers in Dronten and Schiphol-Rijk. ([krebsonsecurity.com](https://krebsonsecurity.com/2026/05/netherlands-seizes-800-servers-arrests-2-for-aiding-cyberattacks/?utm_source=openai)) This incident underscores the persistent challenges in enforcing sanctions against entities that support state-sponsored cyber activities. Despite previous sanctions, the rebranding and asset transfers by Stark Industries highlight the adaptability of such organizations in evading regulatory measures. The case emphasizes the need for continuous monitoring and robust enforcement mechanisms to prevent the circumvention of international sanctions.
4 months ago
Kill Chain
TrapDoor Supply Chain Attack Compromises npm, PyPI, and Crates.io Ecosystems
In May 2026, a coordinated supply chain attack named 'TrapDoor' targeted the npm, PyPI, and Crates.io ecosystems, distributing credential-stealing malware through over 34 malicious packages across more than 384 versions. The campaign began on May 22, 2026, with attackers publishing these packages in rapid succession. The malware specifically aimed at developers in the cryptocurrency, DeFi, Solana, and AI sectors, seeking to exfiltrate sensitive information such as crypto wallets, SSH keys, cloud credentials, browser data, and environment variables. The attack employed various methods, including postinstall hooks, remote JavaScript payloads executed during package imports, and malicious build.rs scripts, to infiltrate developer environments and establish persistence. ([thehackernews.com](https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks within open-source ecosystems, highlighting the need for enhanced vigilance and security measures among developers and organizations. The sophisticated techniques used in the TrapDoor campaign reflect a broader trend of attackers exploiting trusted software repositories to distribute malware, emphasizing the importance of robust supply chain security practices.
4 months ago
Kill Chain
Lazarus Group's RemotePE: A New Memory-Only Threat to Financial Institutions
In May 2026, cybersecurity researchers uncovered a sophisticated attack campaign by the North Korean state-sponsored Lazarus Group targeting financial and cryptocurrency organizations. The group deployed a cross-platform, memory-only Remote Access Trojan (RAT) named RemotePE, which operates entirely in memory, leaving no artifacts on the filesystem. The attack chain involves two loaders: DPAPILoader, which decrypts and loads RemotePELoader using the Windows Data Protection API, and RemotePELoader, which contacts a command-and-control server to fetch and execute RemotePE in memory. This multi-stage approach allows the malware to evade traditional detection mechanisms and maintain persistent access to compromised systems. ([thehackernews.com](https://thehackernews.com/2026/05/lazarus-deploys-remotepe-memory-only.html?utm_source=openai)) The discovery of RemotePE highlights the Lazarus Group's continued evolution in cyber-attack methodologies, emphasizing the need for organizations to adopt advanced threat detection and response strategies. The use of memory-only malware underscores the importance of monitoring in-memory activities and implementing robust endpoint detection and response (EDR) solutions to detect and mitigate such sophisticated threats.
4 months ago
Kill Chain
TeamPCP's Supply Chain Attack: A Wake-Up Call for Software Security
In May 2026, the cybercriminal group TeamPCP executed a sophisticated supply chain attack targeting multiple software ecosystems. The campaign involved compromising the Nx Console VS Code extension, leading to the exfiltration of approximately 3,800 internal GitHub repositories. Additionally, TeamPCP trojanized Microsoft's durabletask Python SDK on PyPI and injected malicious code into 639 versions of 323 npm packages within the @antv ecosystem. These attacks resulted in significant credential theft and potential data loss across affected organizations. This incident underscores the escalating threat posed by supply chain attacks, particularly those targeting widely used development tools and libraries. The rapid succession and scale of these compromises highlight the need for enhanced vigilance and security measures within software development and deployment pipelines.
4 months ago
Kill Chain
Ghost CMS Vulnerability Exploited in Widespread ClickFix Campaign
In May 2026, a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS versions 3.24.0 through 6.19.0 was exploited in a large-scale campaign known as ClickFix. Threat actors leveraged this flaw to gain unauthorized access to over 700 domains, including prominent institutions like Harvard University, Oxford University, and DuckDuckGo. By extracting admin API keys, attackers injected malicious JavaScript into website articles, leading to further exploitation and potential data exfiltration. This incident underscores the persistent threat posed by unpatched vulnerabilities in widely used content management systems. The exploitation of CVE-2026-26980 highlights the importance of timely software updates and robust security practices to prevent unauthorized access and maintain the integrity of web platforms.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports