The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
FBI's 2025 Cybercrime Report: A 26% Surge to $21 Billion in Losses
In 2025, the FBI's Internet Crime Complaint Center (IC3) reported that Americans lost nearly $21 billion to cyber-enabled crimes, marking a 26% increase from the previous year. The most prevalent incidents included phishing attacks, extortion, and investment scams, with cryptocurrency-related fraud accounting for over $11 billion in losses. Notably, individuals over the age of 60 were disproportionately affected, reporting $7.7 billion in losses, a 37% rise from 2024. Additionally, the FBI highlighted the emergence of AI-driven scams, which resulted in 22,300 complaints and $893 million in losses, involving tactics such as voice cloning and deepfake videos. This surge underscores the evolving sophistication of cybercriminals, who are increasingly leveraging advanced technologies like artificial intelligence to enhance the effectiveness of their schemes. The significant financial impact on older adults highlights the urgent need for targeted education and robust cybersecurity measures to protect vulnerable populations from these emerging threats.
5 months ago
Kill Chain
GPUBreach: Unveiling the 2026 NVIDIA GDDR6 RowHammer Vulnerability
In April 2026, researchers from the University of Toronto unveiled 'GPUBreach,' a sophisticated RowHammer attack targeting NVIDIA GPUs equipped with GDDR6 memory. This attack exploits bit-flips in GPU memory to corrupt page tables, granting an unprivileged process arbitrary read/write access to GPU memory. By leveraging vulnerabilities in the NVIDIA driver, attackers can escalate privileges to gain full control over the host system, even with IOMMU protections enabled. The implications are severe, particularly for cloud AI infrastructures and multi-tenant GPU deployments, as GPUBreach enables attackers to compromise entire systems without physical access. This development underscores the evolving nature of hardware-based attacks and the necessity for robust security measures in GPU environments. ([thehackernews.com](https://thehackernews.com/2026/04/new-gpubreach-attack-enables-full-cpu.html?utm_source=openai))
5 months ago
Kill Chain
Critical Docker Authorization Bypass Vulnerability (CVE-2026-34040) Discovered
In March 2026, a high-severity vulnerability (CVE-2026-34040) was identified in Docker Engine, allowing attackers to bypass authorization plugins (AuthZ) by sending oversized HTTP request bodies. This flaw enables unauthorized users to perform privileged container operations, potentially leading to full host system compromise. The issue affects Docker Engine versions prior to 29.3.1 and is a result of an incomplete fix for a previous vulnerability (CVE-2024-41110) addressed in July 2024. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-34040/?utm_source=openai)) The discovery of this vulnerability underscores the persistent risks associated with authorization bypass flaws in critical infrastructure. Organizations relying on Docker for container management must promptly update to version 29.3.1 or later to mitigate this threat. ([cyera.com](https://www.cyera.com/blog/cyera-research-discovers-docker-authorization-bypass-that-silently-disables-security-policies?utm_source=openai))
5 months ago
Kill Chain
APT28's 2025 DNS Hijacking Campaign: A Wake-Up Call for Network Security
In 2025, the Russian state-sponsored cyber group APT28, also known as Fancy Bear, exploited vulnerabilities in MikroTik and TP-Link routers to conduct a large-scale DNS hijacking campaign. By compromising these routers, APT28 redirected internet traffic through attacker-controlled servers, enabling adversary-in-the-middle attacks that harvested credentials from web and email services. This operation targeted a broad range of victims, including organizations linked to the UK Ministry of Defence and NATO logistics contractors, posing significant risks of credential theft, data manipulation, and broader network compromise. ([ncsc.gov.uk](https://www.ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dns-hijacking-operations?utm_source=openai)) This incident underscores the critical importance of securing network infrastructure against sophisticated state-sponsored threats. The exploitation of widely used routers highlights the need for organizations to implement robust security measures, including regular firmware updates, strong authentication protocols, and continuous monitoring to detect and mitigate such attacks.
5 months ago
Kill Chain
AI-Driven Supply Chain Attack Compromises GitHub Repositories
In March 2026, a threat actor utilized AI-assisted automation to execute over 450 exploit attempts against open-source repositories on GitHub. The campaign, identified as 'prt-scan,' specifically targeted repositories misconfigured with the 'pull_request_target' workflow trigger. While less than 10% of these attempts were successful, the attacker managed to compromise at least two NPM packages, leading to the exposure of ephemeral GitHub credentials. This incident underscores the growing trend of AI-enhanced supply chain attacks, where adversaries leverage automation to scale their operations and exploit common misconfigurations. Organizations are urged to review and secure their CI/CD pipelines to mitigate such risks.
5 months ago
Kill Chain
Fortinet's 2026 Unauthenticated API Access Bypass: A Critical Security Alert
In April 2026, Fortinet disclosed a critical vulnerability (CVE-2026-35616) in its FortiClient Endpoint Management Server (EMS) versions 7.4.5 and 7.4.6. This improper access control flaw allowed unauthenticated attackers to execute unauthorized code or commands via crafted API requests. The vulnerability was actively exploited in the wild, prompting Fortinet to release emergency hotfixes and advise customers to apply them immediately. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/?utm_source=openai)) The incident underscores the persistent targeting of Fortinet products by threat actors, highlighting the importance of timely patch management and vigilant monitoring of security advisories to mitigate risks associated with zero-day vulnerabilities. ([tenable.com](https://www.tenable.com/blog/cve-2026-35616-fortinet-forticlientems-improper-access-control-vulnerability-exploited-in-the?utm_source=openai))
5 months ago
Kill Chain
UNC1069's Social Engineering Compromise of Axios: A 2026 Supply Chain Attack
In late March 2026, the popular JavaScript HTTP client library Axios, with over 100 million weekly downloads, was compromised through a sophisticated social engineering attack. The North Korean state-sponsored group UNC1069 targeted lead maintainer Jason Saayman, gaining access to his npm account. The attackers published two malicious versions of Axios (1.14.1 and 0.30.4) that included a trojanized dependency, 'plain-crypto-js@4.2.1', which executed a post-install script to deploy a cross-platform Remote Access Trojan (RAT) upon installation. The malicious packages were available for approximately two to three hours before being removed, but the potential impact was significant due to Axios's widespread use. This incident underscores the increasing industrialization of social engineering attacks targeting open-source maintainers, highlighting the need for enhanced security measures within the software supply chain. The rapid detection and removal of the compromised packages prevented a more extensive breach, but the event serves as a critical reminder of the vulnerabilities inherent in widely used open-source projects.
5 months ago
Kill Chain
Storm-1175's Rapid Exploitation of Web Vulnerabilities in 2026
In early 2026, the financially motivated cybercriminal group Storm-1175 executed high-velocity ransomware campaigns by exploiting recently disclosed vulnerabilities in web-facing systems. The group rapidly transitioned from initial access to data exfiltration and deployment of Medusa ransomware, often within 24 hours. These attacks significantly impacted healthcare, education, professional services, and finance sectors across Australia, the United Kingdom, and the United States. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/?utm_source=openai)) This incident underscores the critical need for organizations to promptly apply security patches and enhance monitoring of web-facing assets. The rapid exploitation of vulnerabilities by threat actors like Storm-1175 highlights the importance of proactive defense measures to mitigate the risk of ransomware attacks.
5 months ago
Kill Chain
Fortinet FortiClientEMS 2026 Improper Access Control Vulnerability
In April 2026, Fortinet disclosed a critical improper access control vulnerability (CVE-2026-35616) in FortiClient Endpoint Management Server (EMS) versions 7.4.5 and 7.4.6. This flaw allows unauthenticated attackers to execute unauthorized code or commands via crafted requests, leading to potential remote code execution and privilege escalation. The vulnerability has been actively exploited in the wild, prompting Fortinet to release emergency hotfixes and advise immediate patching to mitigate the risk. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/?utm_source=openai)) The exploitation of CVE-2026-35616 underscores the persistent targeting of Fortinet products by threat actors. Organizations are urged to apply the provided hotfixes promptly and monitor their systems for any signs of compromise to maintain robust security postures. ([tenable.com](https://www.tenable.com/blog/cve-2026-35616-fortinet-forticlientems-improper-access-control-vulnerability-exploited-in-the?utm_source=openai))
5 months ago
Kill Chain
Fortinet's FortiClient EMS Zero-Day Vulnerability Exploited in 2026
In early April 2026, Fortinet disclosed a critical zero-day vulnerability (CVE-2026-35616) in its FortiClient Endpoint Management Server (EMS), which was actively exploited in the wild. This improper access control flaw allowed unauthenticated attackers to execute unauthorized code or commands via crafted requests. Fortinet released an emergency hotfix for versions 7.4.5 and 7.4.6, with plans for a comprehensive patch in version 7.4.7. The vulnerability was added to CISA's known exploited vulnerability catalog, highlighting its severity and widespread impact. The rapid exploitation of CVE-2026-35616 underscores a growing trend of attackers targeting zero-day vulnerabilities in widely used security solutions. Organizations must remain vigilant, ensuring timely application of patches and hotfixes to mitigate such threats. This incident also emphasizes the importance of robust access controls and continuous monitoring to detect and respond to unauthorized activities promptly.
5 months ago
Kill Chain
GrafanaGhost: Unveiling the Critical AI Prompt Injection Vulnerability in Grafana
In April 2026, security researchers at Noma Security disclosed a critical vulnerability in Grafana, termed 'GrafanaGhost.' This exploit enables attackers to silently exfiltrate sensitive data by circumventing Grafana's AI defenses through prompt injection techniques. The attack does not require user interaction or authentication; it leverages crafted URLs to inject hidden instructions that Grafana's AI processes, leading to unauthorized data transmission to attacker-controlled servers. The vulnerability affects Grafana instances widely used for monitoring real-time financial metrics, infrastructure health data, and customer records, posing significant risks to enterprise data security. This incident underscores the escalating threat of AI prompt injection attacks, where adversaries manipulate AI systems to perform unintended actions. As AI integration in enterprise environments grows, such vulnerabilities highlight the urgent need for robust AI-specific security measures to prevent data breaches and maintain system integrity.
5 months ago
Kill Chain
Fortinet EMS Vulnerability CVE-2026-35616: Immediate Action Required
In April 2026, a critical vulnerability (CVE-2026-35616) was discovered in Fortinet's FortiClient Enterprise Management Server (EMS). This flaw allowed unauthenticated attackers to bypass authentication controls and execute arbitrary code via specially crafted requests. Fortinet released emergency hotfixes to address the issue, urging immediate application to prevent exploitation. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) mandated federal agencies to patch affected systems by April 9, 2026, highlighting the significant risk posed by this vulnerability. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-fortinet-flaw-exploited-in-attacks-by-friday/?utm_source=openai)) The exploitation of CVE-2026-35616 underscores the persistent threat of zero-day vulnerabilities in widely used enterprise solutions. Organizations are reminded of the critical importance of timely patch management and proactive security measures to mitigate such risks.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports