The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Critical Denial of Service Vulnerability in F5 BIG-IP APM: CVE-2025-53521
In October 2025, a critical vulnerability identified as CVE-2025-53521 was discovered in F5 BIG-IP Access Policy Manager (APM). This flaw allows unauthenticated attackers to remotely trigger a denial of service (DoS) by sending specially crafted traffic to a virtual server configured with an APM access policy. Exploitation results in the termination and restart of the Traffic Management Microkernel (TMM) process, causing temporary disruption of all traffic handled by the BIG-IP device. Affected versions include BIG-IP APM 17.5.0 through 17.5.1, 17.1.0 through 17.1.2, 16.1.0 through 16.1.5, and 15.1.0 through 15.1.10. F5 has released patches in versions 17.5.1.3, 17.1.3, 16.1.6.1, and 15.1.10.8 to address this issue. The inclusion of CVE-2025-53521 in CISA's Known Exploited Vulnerabilities (KEV) catalog underscores the active exploitation of this vulnerability in the wild. Organizations utilizing affected versions of F5 BIG-IP APM are urged to apply the recommended patches promptly to mitigate potential service disruptions and maintain the integrity of their network infrastructure.
5 months ago
Kill Chain
TA446's Deployment of DarkSword iOS Exploit Kit in 2026
In March 2026, the Russian state-sponsored threat group TA446, also known as Callisto Group, SEABORGIUM, and COLDRIVER, launched a targeted spear-phishing campaign deploying the DarkSword iOS exploit kit. This sophisticated exploit chain targeted iPhones running iOS versions 18.4 through 18.7, enabling full device compromise and exfiltration of sensitive data, including credentials and cryptocurrency wallets. The campaign primarily targeted individuals and organizations in Ukraine, aligning with Russian strategic interests. ([thehackernews.com](https://thehackernews.com/2026/03/darksword-ios-exploit-kit-uses-6-flaws.html?utm_source=openai)) The public release of the DarkSword exploit kit has significantly increased the risk to iOS users worldwide. Multiple threat actors, including commercial spyware vendors and other state-sponsored groups, have adopted the exploit, leading to a surge in attacks. This incident underscores the critical importance of timely software updates and robust cybersecurity measures to protect against rapidly evolving threats. ([lookout.com](https://www.lookout.com/news-release/lookout-uncovers-darksword-ios-exploit-chain?utm_source=openai))
5 months ago
Kill Chain
Infinity Stealer: A New Threat to macOS Users
In March 2026, a new macOS-targeted malware named Infinity Stealer emerged, utilizing the ClickFix technique to deceive users into executing malicious code. The malware is delivered through fake CAPTCHA prompts that mimic Cloudflare's human verification, instructing users to paste a base64-obfuscated curl command into the macOS Terminal. This command downloads and executes a Python payload compiled with Nuitka, resulting in a native binary that is more resistant to static analysis. Once executed, Infinity Stealer performs anti-analysis checks and proceeds to exfiltrate sensitive data, including browser credentials, Keychain entries, cryptocurrency wallets, and plaintext secrets from developer files, via HTTP POST requests to a command-and-control server. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/02/02/infostealers-without-borders-macos-python-stealers-and-platform-abuse/?utm_source=openai)) The emergence of Infinity Stealer highlights a growing trend of sophisticated malware targeting macOS systems, leveraging advanced social engineering techniques and cross-platform development tools. This incident underscores the importance of user vigilance and the need for robust security measures to protect against evolving threats.
5 months ago
Kill Chain
Citrix NetScaler 2025 Memory Overread Vulnerability: Immediate Action Required
In June 2025, Citrix disclosed a critical vulnerability (CVE-2025-5777) in NetScaler ADC and NetScaler Gateway, characterized by insufficient input validation leading to memory overread. This flaw allows unauthenticated attackers to remotely access sensitive memory contents, including session tokens and credentials, when the devices are configured as a Gateway or AAA virtual server. The vulnerability affects versions 14.1 before 14.1-43.56 and 13.1 before 13.1-58.32. Citrix released patches on June 17, 2025, urging immediate updates to mitigate potential exploitation. ([support.citrix.com](https://support.citrix.com/external/article/CTX693420/netscaler-adc-and-netscaler-gateway-secu.html?utm_source=openai)) The urgency of addressing this vulnerability is underscored by its active exploitation in the wild, as reported by security agencies and researchers. Organizations are advised to apply the provided patches promptly to prevent unauthorized access and potential data breaches. ([techradar.com](https://www.techradar.com/pro/security/cisa-warns-hackers-are-actively-exploiting-critical-citrixbleed-2?utm_source=openai))
5 months ago
Kill Chain
F5 BIG-IP 2025 Remote Code Execution Vulnerability
In October 2025, a critical vulnerability identified as CVE-2025-53521 was discovered in F5 Networks' BIG-IP Access Policy Manager (APM). This flaw allows specific, undisclosed traffic to cause the Traffic Management Microkernel (TMM) to terminate unexpectedly, leading to a denial-of-service (DoS) condition. The vulnerability affects multiple versions of BIG-IP, including 17.5.0, 17.1.0, 16.1.0, and 15.1.0, and has been assigned a CVSS v3.1 score of 7.5, indicating high severity. ([wiz.io](https://www.wiz.io/vulnerability-database/cve/cve-2025-53521?utm_source=openai)) The exploitation of this vulnerability can disrupt critical services relying on BIG-IP systems, posing significant risks to organizations. Given the widespread deployment of BIG-IP devices in enterprise environments, timely remediation is essential to prevent potential service outages and maintain operational continuity.
5 months ago
Kill Chain
Silver Fox Exploits Japan's Tax Season in 2025 Phishing Campaign
In early 2025, the Chinese state-aligned threat actor known as Silver Fox launched a sophisticated phishing campaign targeting Japanese organizations during the tax season. By impersonating official entities such as the National Taxation Bureau, Silver Fox distributed emails containing malicious attachments and links, leading recipients to download trojanized versions of legitimate software. Once installed, these malicious programs deployed remote access trojans (RATs) like ValleyRAT and Winos 4.0, enabling unauthorized access, data exfiltration, and potential financial fraud. The campaign's timing exploited the heightened activity and urgency associated with tax season, increasing the likelihood of successful infiltration. ([trustwave.com](https://www.trustwave.com/en-us/resources/blogs/trustwave-blog/inside-silver-foxs-den-trustwave-spiderlabs-unmasks-a-global-threat-actor/?utm_source=openai)) This incident underscores a growing trend where state-sponsored threat actors blend espionage with financially motivated cybercrime. Silver Fox's operations highlight the evolving landscape of cyber threats, where attackers leverage seasonal events and trusted software to enhance the effectiveness of their campaigns. Organizations must remain vigilant, especially during periods of increased administrative activity, to mitigate the risks posed by such multifaceted threats. ([darkreading.com](https://www.darkreading.com/threat-intelligence/silver-fox-apt-espionage-cybercrime?utm_source=openai))
5 months ago
Kill Chain
Understanding the 2026 TeamPCP Supply Chain Attack
In March 2026, the cybercriminal group TeamPCP executed a sophisticated supply chain attack targeting multiple software packages and cloud services. The campaign began on March 19, 2026, with successive compromises of tools like Trivy, CanisterWorm, Checkmarx, LiteLLM, and Telnyx, occurring every 1-3 days. These attacks involved injecting malicious code into widely used software packages, enabling unauthorized access and data exfiltration from numerous downstream users. The rapid succession of these breaches highlighted the group's aggressive operational tempo and their focus on exploiting trusted software supply chains. As of March 28, 2026, a notable shift in TeamPCP's strategy was observed, with no new compromises reported in the preceding 48 hours. This pause suggests a transition from expanding their foothold to monetizing the vast trove of stolen credentials and data. The group's explicit intent to maintain a prolonged presence indicates that future supply chain attacks remain a significant threat. Organizations are advised to remain vigilant, conduct thorough security assessments, and implement robust monitoring to detect and mitigate potential breaches stemming from this campaign.
5 months ago
Kill Chain
AI-Enhanced Cyber Threats Surge in 2026
In 2026, the cybersecurity landscape witnessed a significant surge in AI-enhanced cyber threats. Malicious actors leveraged artificial intelligence to automate and accelerate attacks, leading to a 72% increase in AI-powered cyber incidents compared to the previous year. These sophisticated attacks utilized generative AI tools to craft convincing phishing emails, deepfakes, and automated exploit development, drastically reducing the time required to breach systems and exfiltrate data. Organizations across various sectors faced unprecedented challenges in defending against these rapidly evolving threats. This escalation underscores the urgent need for organizations to adopt AI-driven defense mechanisms. Traditional security measures are increasingly inadequate against AI-powered attacks, necessitating the integration of advanced AI-based threat detection and response systems to effectively mitigate these emerging risks.
5 months ago
Kill Chain
Telnyx PyPI Supply Chain Attack: A 2026 Case Study
In March 2026, the Telnyx Python package on the Python Package Index (PyPI) was compromised by the threat actor TeamPCP. Malicious versions 4.87.1 and 4.87.2 were uploaded, embedding malware that exfiltrated sensitive data such as SSH keys, cloud tokens, and cryptocurrency wallets. The attack utilized steganography, hiding the payload within WAV audio files, and affected both Linux/macOS and Windows systems. This incident underscores the escalating threat of supply chain attacks targeting widely used open-source packages, emphasizing the need for enhanced security measures in software development pipelines.
5 months ago
Kill Chain
Fake VS Code Alerts on GitHub Distribute Malware to Developers
In March 2026, a large-scale campaign targeted developers on GitHub by posting fake Visual Studio Code (VS Code) security alerts in the Discussions sections of various projects. These deceptive posts, crafted as vulnerability advisories with titles like 'Severe Vulnerability - Immediate Update Required,' included fake CVE IDs and urgent language. Attackers impersonated real code maintainers or researchers to enhance credibility. The posts contained links to purportedly patched versions of VS Code extensions hosted on external services such as Google Drive. Clicking these links led to a redirection chain that executed a JavaScript reconnaissance script, collecting victims' system information and sending it to the attackers' command-and-control server. This campaign highlights the increasing sophistication of social engineering attacks targeting developers through trusted platforms. Similar tactics have been observed in previous incidents, such as the March 2025 phishing campaign that targeted 12,000 GitHub repositories with fake security alerts, leading to unauthorized access to developers' accounts and repositories. The recurrence of such attacks underscores the need for heightened vigilance and robust security practices within the developer community.
5 months ago
Kill Chain
Critical Security Vulnerabilities in LangChain and LangGraph: Immediate Action Required
In early 2026, multiple security vulnerabilities were identified in LangChain and LangGraph, two widely used open-source frameworks for building applications powered by Large Language Models (LLMs). These vulnerabilities include Server-Side Request Forgery (SSRF) in LangChain versions prior to 1.2.11, Regular Expression Denial-of-Service (ReDoS) in versions up to 0.3.1, and a critical Remote Code Execution (RCE) flaw in LangGraph's caching layer before version 4.0.0. Exploitation of these vulnerabilities could lead to unauthorized access to sensitive data, execution of arbitrary code, and potential system compromise. ([stack.watch](https://stack.watch/product/langchain-ai/langchain/?utm_source=openai)) The discovery of these vulnerabilities underscores the importance of rigorous security practices in the development and maintenance of AI frameworks. As LLM-powered applications become increasingly prevalent, ensuring the security of underlying frameworks is crucial to prevent potential exploitation by malicious actors.
5 months ago
Kill Chain
Open VSX Registry's 2026 GlassWorm Supply Chain Attack: A Wake-Up Call for Extension Security
In January 2026, the Open VSX Registry, a vendor-neutral extension marketplace for Visual Studio Code, experienced a significant supply chain attack. Threat actors compromised a legitimate publisher's account to distribute malicious updates to four popular extensions, collectively downloaded over 22,000 times. These updates deployed the GlassWorm malware, specifically targeting macOS users by exfiltrating sensitive data such as browser cookies, cryptocurrency wallets, and developer credentials. The malware utilized sophisticated evasion techniques, including locale checks and blockchain-based command-and-control mechanisms, to avoid detection and dynamically manage its infrastructure. ([securityweek.com](https://www.securityweek.com/open-vsx-publisher-account-hijacked-in-fresh-glassworm-attack/?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks within open-source ecosystems, highlighting the critical need for robust security measures in extension marketplaces. In response, the Eclipse Foundation, which maintains the Open VSX Registry, has announced plans to implement pre-publication security checks to proactively identify and mitigate malicious extensions before they reach users. ([thehackernews.com](https://thehackernews.com/2026/02/eclipse-foundation-mandates-pre-publish.html?utm_source=openai))
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports