Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
ChatGPT Prompt Injection Flaw Exposed Gmail Data Through Hidden Cross-Account Channels
In September 2026, Check Point Research disclosed a critical vulnerability in OpenAI's ChatGPT that allowed attackers to inject malicious prompts that could silently exfiltrate user data from connected applications like Gmail. The attack exploited a shared internal JFrog Artifactory service used by ChatGPT's isolated containers, creating an unauthorized communication channel between different user accounts. Attackers could plant instructions through shared conversations, custom GPTs, or user-pasted prompts that would execute hidden data theft operations while displaying normal responses to victims. OpenAI confirmed the vulnerability and took the internal service offline after disclosure. This incident highlights the emerging risks of AI systems as attack vectors, particularly as organizations increasingly integrate AI tools with sensitive business applications and data sources, making prompt injection attacks a critical new threat category requiring immediate security attention.
1 week ago
Kill Chain
WeChat Zero-Click Worm: How 1.4 Billion Users Were at Risk from Incoming Calls
In July 2026, security researchers at Calif discovered a critical zero-click vulnerability in WeChat that allowed attackers to take complete control of user accounts through incoming calls without any user interaction. The exploit worked by leveraging WeChat's contact trust system, enabling worm-like propagation where compromised accounts could automatically infect other contacts. Affecting WeChat's 1.4 billion user base across iPhone and Android platforms, the vulnerability granted attackers full access to messages, payments, and WeChat's extensive ecosystem of mini-programs and services. Tencent patched the flaw in August 2026 versions 8.0.77 for Android and 8.0.76 for iOS. This incident highlights the growing sophistication of mobile application attacks and the critical importance of securing communication platforms that serve as digital wallets and business ecosystems, particularly as zero-click exploits become increasingly weaponized against high-value messaging applications.
1 week ago
Kill Chain
AI Reasoning Traces Theft: The 2026 Vulnerability That Exposed AI's Hidden Thoughts
In 2026, security researchers discovered a critical vulnerability affecting major AI providers including OpenAI, Anthropic, and Google, where encrypted reasoning traces from large language models could be stolen and decoded. The attack exploited the interchangeable nature of encrypted reasoning blocks across different sessions and models, allowing adversaries to inject traces into weaker models to extract proprietary reasoning in plaintext. This vulnerability enabled four distinct attack vectors: circumventing anti-distillation mechanisms, large-scale private data extraction, revealing hidden hazardous information, and executing invisible prompt injections. Researchers successfully extracted 367 PII artifacts and 182 credentials from 315,320 reasoning blocks scraped from public repositories, demonstrating the significant privacy and security implications. This incident highlights the emerging risks in AI security as organizations increasingly deploy autonomous AI agents and rely on cloud-based AI services, making AI-specific vulnerabilities a critical new attack surface that traditional security measures may not adequately address.
1 week ago
Kill Chain
N-able N-central CVE-2026-86218: When RMM Platforms Become Attack Vectors
N-able released an emergency hotfix for CVE-2026-86218, a maximum-severity remote code execution vulnerability in its N-central remote monitoring and management platform used by IT departments and MSPs. The flaw allows unprivileged attackers to execute malicious code on exposed N-central instances through low-complexity attacks. With nearly 1,500 N-central servers exposed online and evidence of active exploitation flagged by Huntress cybersecurity, the company urged immediate patching to N-central 2026.3 Hotfix 4. This incident highlights the persistent targeting of remote management platforms that provide privileged access to client networks and infrastructure. RMM platforms continue to be attractive targets as they offer attackers potential access to multiple downstream organizations through a single compromise, making them critical components in supply chain attack scenarios.
1 week ago
Kill Chain
ConnectWise Issues Emergency Alert for Unpatched ScreenConnect Vulnerability
In September 2026, ConnectWise disclosed a critical file transfer vulnerability in ScreenConnect Remote Access that affects both cloud and on-premises deployments. The flaw, which has not yet received a CVE identifier, impacts file transfer behavior in ScreenConnect support and access sessions. ConnectWise released temporary mitigation measures requiring administrators to disable TransferFiles permissions while a permanent patch is developed. With nearly 6,000 ScreenConnect instances exposed online according to Shadowserver, this vulnerability poses significant risk to managed service providers and IT departments. This incident highlights the ongoing targeting of remote access tools by threat actors, particularly as organizations increasingly rely on cloud-hosted management platforms. ScreenConnect has been repeatedly exploited by ransomware groups and state-sponsored attackers, making this unpatched vulnerability a critical concern for enterprise security teams.
1 week ago
Kill Chain
Trezor Breach Exposes 81,000 Customers: Third-Party Risk Management Failures
In August 2026, cryptocurrency hardware wallet maker Trezor disclosed a significant data breach at its third-party shipping provider ShipMonk, initially affecting 14,000 customers across multiple countries. The breach expanded dramatically when it was revealed that ShipMonk had failed to delete historical customer data as contractually required, ultimately exposing personal information of 81,000 customers including names, addresses, email addresses, and phone numbers. The attack exploited a critical SQL injection zero-day vulnerability in the Metabase analytics platform, with the ShinyHunters extortion gang later claiming responsibility and sending extortion demands to ShipMonk. This incident highlights the persistent vulnerability of third-party supply chains and the critical importance of data retention policies in an era where cryptocurrency adoption is accelerating and regulatory scrutiny is intensifying. The breach demonstrates how a single compromised analytics platform can cascade across multiple organizations, affecting everything from hardware manufacturers to online service providers.
1 week ago
Kill Chain
How BigBear Phishing Service Defeated MFA at 258 Organizations
In September 2026, the BigBear 2.0 phishing-as-a-service platform successfully compromised 258 organizations by bypassing multi-factor authentication on Microsoft 365 accounts. Using an Evilginx2-based adversary-in-the-middle framework across 42 VPS nodes, the operation captured over 5,000 credentials including 474 complete MFA bypasses, 1,032 plaintext passwords, and 4,148 session cookies. The service employed custom JavaScript to disable FIDO2/WebAuthn authentication and used geo-matched residential proxies across 69 countries to evade detection by Microsoft's security systems. This incident highlights the evolving sophistication of phishing-as-a-service platforms that can defeat traditional MFA implementations, demonstrating the urgent need for phishing-resistant authentication methods and comprehensive identity security strategies as threat actors increasingly commercialize advanced bypass techniques.
1 week ago
Kill Chain
PEEP Malware Transforms Chrome and Edge Into Persistent Backdoors
In September 2026, cybersecurity researchers disclosed PEEP, a sophisticated post-exploitation toolkit that transforms Chrome and Edge browsers into persistent backdoors. The malware, derived from the open-source RedExt framework, masquerades as a Smart Bookmarks extension and bypasses browser security by manipulating Chromium's Secure Preferences integrity values. Once deployed on compromised systems, PEEP establishes command-and-control communications via plaintext HTTP, exfiltrates browsing data and credentials, and enables remote command execution through a native messaging host. The toolkit demonstrates advanced persistence techniques and represents a significant evolution in browser-based post-compromise frameworks. This incident highlights the growing sophistication of browser-based attack vectors as threat actors increasingly leverage trusted applications to maintain persistence and evade detection in enterprise environments.
1 week ago
Kill Chain
StyleSmuggler Zero-Day: How Advanced Backdoors Bypass E-Commerce Security
On September 4, 2026, threat actors began exploiting a zero-day vulnerability dubbed 'StyleSmuggler' affecting all versions of Magento and Adobe Commerce platforms. The attackers leveraged PHP code injection through Magento's template system to generate fake payment failure emails, triggering code execution that deployed a sophisticated Rust-based Linux backdoor. The malware disguises itself as legitimate system processes and establishes persistent command-and-control communication using NTP traffic mimicry to evade detection. With over 160,000 Magento installations worldwide, including 14,000 high-traffic sites, this incident represents a significant supply chain risk. This attack highlights the growing trend of threat actors targeting e-commerce platforms through zero-day exploits, coinciding with increased regulatory scrutiny on supply chain security and the rising sophistication of malware that mimics legitimate network protocols to bypass traditional security controls.
1 week ago
Kill Chain
JSCeal Malware: Advanced Session Hijacking Bypasses Google Authentication
JSCeal, a sophisticated compiled V8 JavaScript malware, has been actively targeting cryptocurrency traders since late 2024 through malvertising campaigns on Facebook and Google. The malware uses fake TradingView installers distributed via counterfeit trading sites to harvest credentials, steal browser data, and conduct session replay attacks that bypass Google authentication using stolen cookies. Check Point Research revealed that JSCeal employs advanced obfuscation techniques including RC4-protected strings and control-flow flattening, while maintaining surveillance capabilities through keylogging and screenshot capture. The threat actors behind JSCeal, linked to WEEVILPROXY and MeadowLocust clusters, have expanded their operations across 12 countries in 25 languages, primarily targeting Asia Pacific and Latin America regions. This incident highlights the growing sophistication of browser-based malware campaigns that exploit legitimate advertising platforms to distribute advanced credential harvesting tools, representing a significant escalation in session hijacking techniques that can bypass modern authentication mechanisms.
1 week ago
Kill Chain
N-able Issues Critical Fourth Hotfix: CVE-2026-86218 RCE Vulnerability Exposes MSP Infrastructure
N-able released its fourth critical hotfix in five weeks for the N-central remote monitoring and management platform, addressing CVE-2026-86218, a maximum-severity unauthenticated remote code execution vulnerability with a CVSS 4.0 score of 10.0. The flaw affects all on-premises N-central builds before 2026.3.1.14, with conflicting reports from N-able regarding whether the vulnerability has been exploited in the wild. This incident follows a pattern of critical vulnerabilities in the platform, including previous authentication bypasses that enabled attackers to gain administrative access and pivot to managed endpoints through Cloudflare tunnels. The vulnerability has prompted immediate patching requirements for all on-premises customers and demonstrates the ongoing targeting of managed service provider infrastructure by threat actors seeking to compromise multiple organizations through a single entry point.
1 week ago
Kill Chain
Telerik UI Padding Oracle Exploit: CVE-2026-13181 RCE Chain Puts Web Apps at Risk
In July 2026, Progress Software patched a critical vulnerability chain in Telerik UI for ASP.NET AJAX (CVE-2026-13181) that allows unauthenticated remote code execution. Security firm TantoSec released a working exploit in September 2026, demonstrating how attackers can chain a padding oracle vulnerability with unguarded type resolution to achieve code execution on vulnerable web applications. The attack requires specific non-default configurations including custom encryption keys, affecting versions 2010.1.309 through 2026.2.519. While no confirmed exploitation has been reported for these specific CVEs, the Telerik component has a history of being targeted by ransomware groups and nation-state actors through previous vulnerabilities. This incident highlights the persistent risks in web application components and the importance of timely patching, especially given Telerik's history as a favored target for sophisticated threat actors seeking initial access to enterprise networks.
1 week ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports