The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
DarkSword Malware: A New Threat to iOS Devices
In March 2026, Google's Threat Intelligence Group (GTIG) identified 'DarkSword,' a sophisticated iOS exploit chain targeting devices running iOS versions 18.4 through 18.7. This exploit leverages six vulnerabilities to achieve full device compromise, deploying malware families such as GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER. Initially observed in November 2025, DarkSword has been utilized by multiple threat actors, including state-sponsored groups like UNC6353, to target users in countries such as Saudi Arabia, Turkey, Malaysia, and Ukraine. The exploit is delivered through malicious or compromised websites, enabling attackers to steal sensitive data and execute unauthorized code on affected devices. ([malwarebytes.com](https://www.malwarebytes.com/blog/mobile/2026/03/a-darksword-hangs-over-unpatched-iphones?utm_source=openai)) The widespread adoption of DarkSword by various threat actors underscores a significant shift in the cyber threat landscape, highlighting the increasing accessibility and deployment of advanced mobile exploits. This incident emphasizes the critical importance of timely software updates and robust security practices to mitigate emerging threats. ([labs.cloudsecurityalliance.org](https://labs.cloudsecurityalliance.org/research/csa-research-note-darksword-ios-fullchain-zeroday-multiactor/?utm_source=openai))
4 months ago
Kill Chain
CISA Alerts on Active Exploitation of 'Copy Fail' Linux Vulnerability (CVE-2026-31431)
In late April 2026, a critical vulnerability known as 'Copy Fail' (CVE-2026-31431) was disclosed, affecting Linux kernels released since 2017. This flaw resides in the algif_aead cryptographic interface, allowing unprivileged local users to escalate privileges to root by writing controlled bytes to the page cache of any readable file. Theori researchers released a proof-of-concept exploit demonstrating the vulnerability's reliability across major distributions, including Ubuntu, Amazon Linux, RHEL, and SUSE. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, urging immediate patching to mitigate active exploitation risks. The rapid public disclosure and availability of a reliable exploit underscore the urgency for organizations to update their systems promptly. Given the widespread use of affected Linux distributions in enterprise and cloud environments, unpatched systems are at significant risk of compromise, potentially leading to unauthorized access and control over critical infrastructure.
4 months ago
Kill Chain
Critical Authentication Bypass Vulnerability in MOVEit Automation: CVE-2026-4670
In April 2026, Progress Software disclosed a critical authentication bypass vulnerability (CVE-2026-4670) in its MOVEit Automation managed file transfer application. This flaw allows unauthenticated remote attackers to gain unauthorized access to affected systems without user interaction. The vulnerability impacts MOVEit Automation versions prior to 2025.1.5, 2025.0.9, and 2024.1.8. Exploitation could lead to unauthorized access, administrative control, and potential data exposure. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/04/critical-moveit-automation-auth-bypass-vulnerability-fixed-cve-2026-4670/?utm_source=openai)) Given the widespread use of MOVEit Automation in enterprise environments, this vulnerability poses a significant risk. Organizations are urged to upgrade to the latest patched versions immediately to mitigate potential exploitation. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/04/critical-moveit-automation-auth-bypass-vulnerability-fixed-cve-2026-4670/?utm_source=openai))
4 months ago
Kill Chain
PyTorch Lightning Supply Chain Attack: A Wake-Up Call for Developers
In April 2026, versions 2.6.2 and 2.6.3 of the PyTorch Lightning package were compromised and published on the Python Package Index (PyPI). These versions contained malicious code that, upon import, initiated a background process to download and execute an obfuscated JavaScript payload. This payload targeted sensitive information, including environment files, API keys, GitHub tokens, and credentials stored in browsers such as Chrome, Firefox, and Brave. Additionally, it interacted with cloud service APIs (AWS, Azure, GCP) to exfiltrate credentials and had the capability to execute arbitrary system commands. This incident underscores the escalating threat of supply chain attacks in the software development ecosystem. The compromise of widely-used packages like PyTorch Lightning highlights the need for enhanced vigilance and robust security measures in managing software dependencies to prevent unauthorized access and data breaches.
4 months ago
Kill Chain
Fraudsters Exploit Credit Union Verification Processes in 2026
In May 2026, cybersecurity researchers uncovered a sophisticated fraud scheme targeting small to mid-sized credit unions. Threat actors utilized stolen personal data to impersonate legitimate borrowers, navigating through credit checks and identity verification processes without triggering security alerts. This methodical approach exploited perceived weaknesses in the verification systems of smaller financial institutions, leading to unauthorized loan approvals and significant financial losses. This incident underscores a growing trend where cybercriminals focus on process exploitation rather than technical vulnerabilities. The increasing availability of personal data on underground forums, combined with advanced social engineering tactics, poses a heightened risk to financial institutions, especially those with limited fraud prevention resources.
4 months ago
Kill Chain
Weaver E-cology CVE-2026-22679 Exploitation: A Critical Security Alert
In mid-March 2026, attackers began exploiting CVE-2026-22679, a critical unauthenticated remote code execution vulnerability in Weaver E-cology 10.0, an enterprise office automation platform. The flaw resides in an exposed debug API endpoint that allows user-supplied parameters to reach backend Remote Procedure Call (RPC) functionality without authentication or input validation. This enables attackers to execute arbitrary system commands on the server. The attacks commenced five days after the vendor released a security update on March 12, 2026, and two weeks before the vulnerability was publicly disclosed. The exploitation involved multiple phases, including initial reconnaissance through ping commands, attempts to deploy PowerShell-based payloads, and the use of obfuscated, fileless PowerShell scripts to fetch remote scripts. Despite these efforts, the attackers did not establish a persistent session on the targeted hosts.
4 months ago
Kill Chain
Rising Threat: Amazon SES Phishing Abuse in 2026
In May 2026, cybersecurity researchers identified a significant increase in phishing campaigns exploiting Amazon Simple Email Service (SES). Attackers leveraged exposed AWS Identity and Access Management (IAM) access keys, often found in public GitHub repositories, .ENV files, Docker images, and publicly accessible S3 buckets, to send convincing phishing emails that bypass standard security filters. These emails, appearing to originate from trusted sources, included fake document-signing notifications and sophisticated business email compromise (BEC) attacks, leading to unauthorized access and financial losses. This trend underscores the critical need for organizations to implement stringent security measures, such as enforcing least-privilege IAM policies, enabling multi-factor authentication, regularly rotating access keys, and applying IP-based access restrictions. The rise in such attacks highlights the evolving tactics of cybercriminals and the importance of proactive defense strategies to protect sensitive information and maintain trust.
4 months ago
Kill Chain
Progress Software Patches Critical MOVEit Automation Vulnerabilities
In April 2026, Progress Software identified and patched two critical vulnerabilities in MOVEit Automation, a managed file transfer solution widely used in enterprise environments. The most severe, CVE-2026-4670, is an authentication bypass flaw with a CVSS score of 9.8, allowing unauthenticated remote attackers to gain unauthorized access. The second, CVE-2026-5174, involves improper input validation that could lead to privilege escalation. Exploitation of these vulnerabilities could result in unauthorized access, administrative control, and potential data exposure. ([thehackernews.com](https://thehackernews.com/2026/05/progress-patches-critical-moveit.html?utm_source=openai)) This incident underscores the persistent threat posed by vulnerabilities in widely deployed enterprise software. Organizations are reminded of the importance of timely patch management and vigilant monitoring to mitigate risks associated with such critical flaws.
4 months ago
Kill Chain
VENOMOUS#HELPER Phishing Campaign: A Wake-Up Call for RMM Tool Security
Since April 2025, a sophisticated phishing campaign named VENOMOUS#HELPER has targeted over 80 organizations, primarily in the U.S. Attackers impersonated the U.S. Social Security Administration, sending emails that directed recipients to download malicious executables disguised as official documents. These executables installed legitimate Remote Monitoring and Management (RMM) tools—SimpleHelp and ScreenConnect—on victims' systems, granting attackers persistent remote access. The use of these legitimate tools allowed the attackers to evade detection by standard security measures. ([thehackernews.com](https://thehackernews.com/2026/05/phishing-campaign-hits-80-orgs-using.html?utm_source=openai)) This incident underscores a growing trend where cybercriminals exploit trusted software to maintain undetected access within networks. The dual deployment of RMM tools highlights the need for organizations to scrutinize the use of such software and implement robust monitoring to detect unauthorized installations. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/rmm-tools-stealthy-phishing-campaign?utm_source=openai))
4 months ago
Kill Chain
Exploitation of Amazon SES in Phishing and BEC Attacks: A 2026 Analysis
In early 2026, cybercriminals exploited Amazon Simple Email Service (SES) to conduct sophisticated phishing and Business Email Compromise (BEC) attacks. By leveraging exposed AWS Identity and Access Management (IAM) access keys, attackers sent large volumes of phishing emails that passed standard authentication checks, such as SPF, DKIM, and DMARC. These emails often impersonated trusted services like DocuSign, leading recipients to malicious sites designed to harvest sensitive information. The abuse of Amazon's legitimate infrastructure allowed these phishing campaigns to evade traditional email security measures, resulting in significant data breaches and financial losses for targeted organizations. This incident underscores a growing trend where attackers exploit trusted cloud services to enhance the credibility and effectiveness of their phishing campaigns. The increasing sophistication of such attacks highlights the urgent need for organizations to implement robust security measures, including strict IAM policies, regular key rotation, and comprehensive employee training to recognize and respond to phishing attempts.
4 months ago
Kill Chain
Silver Fox's Tax-Themed Phishing Campaign Unveils New ABCDoor Malware
In December 2025, the China-backed threat group Silver Fox initiated a phishing campaign targeting organizations in India and Russia. The attackers sent emails impersonating tax authorities, prompting recipients to download archives purportedly containing lists of tax violations. These archives contained a modified Rust-based loader that deployed the known ValleyRAT backdoor and a previously undocumented Python-based backdoor named ABCDoor. Between early January and early February 2026, over 1,600 such malicious emails were recorded, affecting sectors including industrial, consulting, retail, and transportation. ([darkreading.com](https://www.darkreading.com/endpoint-security/silver-fox-tax-themed-attacks-india-russia?utm_source=openai)) This incident underscores the evolving tactics of APT groups, particularly their use of sophisticated social engineering techniques and novel malware to infiltrate organizations. The discovery of ABCDoor highlights the continuous development of custom tools by threat actors to evade detection and maintain persistence. ([darkreading.com](https://www.darkreading.com/endpoint-security/silver-fox-tax-themed-attacks-india-russia?utm_source=openai))
4 months ago
Kill Chain
Global Crackdown Dismantles Major Crypto Scam Network
In April 2026, a coordinated international operation led by Dubai Police, in collaboration with the U.S. FBI and the Chinese Ministry of Public Security, resulted in the arrest of at least 276 individuals and the dismantling of nine scam centers involved in cryptocurrency investment fraud targeting American citizens. The operation uncovered that these centers employed 'pig butchering' schemes, where scammers built trust with victims through fake relationships before persuading them to invest in fraudulent cryptocurrency platforms, leading to millions of dollars in losses. Notably, the scams were linked to human trafficking, with individuals coerced into operating the fraudulent schemes under exploitative conditions. ([justice.gov](https://www.justice.gov/opa/pr/coordinated-takedown-scam-centers-leads-least-276-arrests-alleged-managers-and-recruiters?utm_source=openai)) This incident underscores the growing sophistication and international reach of cryptocurrency fraud schemes, highlighting the urgent need for enhanced global cooperation in combating such cybercrimes. The successful operation demonstrates the effectiveness of cross-border law enforcement collaboration in addressing complex financial frauds that exploit emerging technologies.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports