The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Apple Issues Urgent Update for 'DarkSword' Exploit in 2026
In March 2026, Apple issued urgent lock screen notifications to users of older iPhone and iPad models, warning them of active web-based exploits targeting outdated iOS versions. The 'DarkSword' exploit, which had been used by surveillance groups, became widely accessible after its code was leaked online, enabling attackers to exfiltrate sensitive data from devices running iOS versions 18.4 to 18.7. Apple responded by releasing security updates for iOS versions 15 through 26 and advised users on older systems to upgrade immediately to mitigate the risk. ([tomsguide.com](https://www.tomsguide.com/phones/iphones/darksword-exploit-just-went-global-millions-of-iphones-now-wide-open-to-hackers?utm_source=openai)) This incident underscores the critical importance of keeping devices updated to the latest software versions. The public availability of the 'DarkSword' exploit highlights the rapid dissemination of vulnerabilities and the necessity for users to remain vigilant against emerging threats. ([techradar.com](https://www.techradar.com/phones/update-your-iphone-now-apple-issues-a-rare-warning-to-ios-users-as-a-new-hacker-threat-is-discovered?utm_source=openai))
5 months ago
Kill Chain
TeamPCP's Malicious 'telnyx' PyPI Attack Exposes Supply Chain Vulnerabilities
In March 2026, the threat actor group TeamPCP executed a supply chain attack by uploading two malicious versions (4.87.1 and 4.87.2) of the 'telnyx' Python package to the Python Package Index (PyPI). These versions concealed credential-stealing malware within .WAV files, enabling the exfiltration of sensitive data from compromised systems. The attack underscores the vulnerability of open-source repositories to sophisticated supply chain compromises. This incident highlights the escalating trend of attackers targeting widely used open-source packages to distribute malware, emphasizing the need for enhanced vigilance and security measures in software supply chains.
5 months ago
Kill Chain
Coruna Exploit Kit: A Case Study in the Commercialization of Nation-State Cyber Tools
In February 2025, Google's Threat Intelligence Group (GTIG) identified 'Coruna,' a sophisticated iOS exploit kit comprising 23 vulnerabilities across five exploit chains, targeting devices running iOS 13 through 17.2.1. Initially deployed by a surveillance vendor for government clients, Coruna was later utilized by Russian state actors in espionage campaigns against Ukrainian users. By December 2025, the exploit kit had proliferated to financially motivated Chinese cybercriminals, who employed it to steal cryptocurrency from over 42,000 iOS devices via malicious websites. This rapid transition from state-sponsored espionage to widespread financial crime underscores the growing commercialization and accessibility of nation-state-level cyber tools. The Coruna incident highlights the urgent need for organizations to stay vigilant against advanced threats, as sophisticated exploit kits once exclusive to government entities are increasingly available to cybercriminals, posing significant risks to both individuals and enterprises.
5 months ago
Kill Chain
Coruna iOS Exploit Framework: Evolution from Espionage to Cybercrime
In 2025, the Coruna exploit kit emerged as a sophisticated tool targeting iPhones running iOS versions 13.0 through 17.2.1. Initially observed in February 2025, it was used by a surveillance vendor's client, later appearing in attacks by Russian espionage groups against Ukrainian users, and subsequently by financially motivated Chinese hackers. Coruna comprises five full iOS exploit chains leveraging 23 vulnerabilities, including CVE-2023-32434 and CVE-2023-38606, previously exploited in Operation Triangulation. The kit's evolution suggests a continuous development from earlier frameworks, now capable of compromising modern hardware, including Apple's A17 and M3 chips. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/03/03/coruna-ios-exploit-kit/?utm_source=openai)) The proliferation of Coruna underscores the escalating risk of advanced exploit kits transitioning from state-sponsored espionage to widespread cybercrime. This trend highlights the urgent need for organizations to implement robust security measures, including timely software updates and advanced threat detection systems, to mitigate the risks posed by such sophisticated tools.
5 months ago
Kill Chain
International Operation Dismantles LeakBase Cybercrime Forum in 2026
In early March 2026, an international law enforcement operation led by the FBI and Europol dismantled LeakBase, one of the world's largest cybercrime forums. Established in 2021, LeakBase had over 142,000 members and facilitated the trade of stolen data, including account credentials and financial information. The coordinated effort spanned 14 countries, resulting in the seizure of the forum's domains and databases, as well as multiple arrests and searches targeting the platform's most active users. This operation underscores the growing global collaboration in combating cybercrime and highlights the increasing focus on dismantling platforms that facilitate the sale of stolen data. The takedown of LeakBase serves as a significant deterrent to cybercriminals and emphasizes the importance of international cooperation in addressing the evolving cyber threat landscape.
5 months ago
Kill Chain
Unveiling the March 2026 Fraud Attack: Bot Signups and Account Takeovers
In March 2026, a sophisticated fraud campaign was identified, leveraging automated bots to create large volumes of fake accounts using compromised emails and residential proxies. These accounts, appearing legitimate, were later exploited for account takeovers through credential stuffing and phishing, leading to unauthorized transactions and data breaches. The attackers' use of automation and human-driven sessions allowed them to bypass traditional security measures, resulting in significant financial losses and reputational damage for affected organizations. This incident underscores the evolving nature of cyber threats, highlighting the need for multi-layered security approaches that integrate behavioral analytics, device fingerprinting, and real-time threat intelligence to detect and prevent such complex fraud schemes.
5 months ago
Kill Chain
Critical Langflow RCE Vulnerability (CVE-2026-33017) Exploited in the Wild
In March 2026, a critical remote code execution (RCE) vulnerability, identified as CVE-2026-33017, was discovered in Langflow, an open-source framework for building AI workflows. This flaw allows unauthenticated attackers to execute arbitrary Python code on affected servers by sending crafted HTTP requests to the unsandboxed flow execution endpoint. The vulnerability affects Langflow versions 1.8.1 and earlier, potentially leading to full system compromise, data theft, and unauthorized access to sensitive information. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-27966/?utm_source=openai)) The rapid exploitation of this vulnerability underscores the increasing targeting of AI development tools by threat actors. Organizations utilizing Langflow are urged to upgrade to version 1.9.0 or later, which addresses this security issue. Additionally, it is recommended to disable or restrict access to the vulnerable endpoint, monitor for suspicious activity, and rotate API keys and credentials to mitigate potential risks. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-27966/?utm_source=openai))
5 months ago
Kill Chain
UK Sanctions Xinbi Marketplace Linked to Asian Scam Centers
In March 2026, the United Kingdom's Foreign, Commonwealth and Development Office (FCDO) imposed sanctions on Xinbi, a Chinese-language online marketplace operating via Telegram. Xinbi has been implicated in facilitating the sale of stolen data and satellite internet equipment to scam networks across Southeast Asia. Additionally, the platform is believed to have assisted North Korean threat actors in laundering cryptocurrency obtained from significant cyber heists targeting global companies and individuals. Between 2021 and 2025, Xinbi processed over $19.9 billion, engaging in activities ranging from unlicensed over-the-counter trades and money laundering to the distribution of stolen personal databases. The UK's sanctions aim to sever Xinbi's connections to the legitimate cryptocurrency ecosystem, thereby disrupting its operations and preventing further illicit activities. This action underscores the growing international efforts to combat cybercrime infrastructures that enable large-scale financial fraud and data breaches. The sanctions against Xinbi highlight the necessity for organizations to enhance their cybersecurity measures and remain vigilant against platforms that facilitate cybercriminal activities.
5 months ago
Kill Chain
WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites
In March 2026, cybersecurity researchers identified a novel web skimming attack targeting e-commerce platforms. This attack leverages WebRTC data channels to exfiltrate payment information, effectively bypassing traditional security measures such as Content Security Policy (CSP) controls. The skimmer, implemented in JavaScript, establishes a direct, encrypted communication channel with a command-and-control server, facilitating the stealthy transmission of stolen credit card data. This method allows attackers to circumvent standard detection mechanisms, posing a significant threat to online retailers and their customers. The emergence of this WebRTC-based skimming technique underscores the evolving sophistication of cyber threats in the e-commerce sector. As attackers develop more advanced methods to exploit web technologies, it is imperative for organizations to enhance their security protocols and monitoring systems to detect and mitigate such innovative attack vectors.
5 months ago
Kill Chain
LiteLLM Supply Chain Attack: A Wake-Up Call for Open-Source Security
In March 2026, the widely used Python library LiteLLM was compromised in a supply chain attack. Threat actors, identified as TeamPCP, gained access to the LiteLLM account and released malicious versions 1.82.7 and 1.82.8 on the PyPI repository. These versions contained backdoors that harvested sensitive data, including SSH keys, cloud tokens, Kubernetes secrets, and crypto wallets. The malware also attempted lateral movement across Kubernetes clusters by deploying privileged pods and established persistence via systemd backdoors. ([techradar.com](https://www.techradar.com/pro/security/top-llm-pypl-package-compromised-to-steal-user-details-heres-what-we-know?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting open-source software repositories. The compromise of LiteLLM, a tool integral to AI model management, highlights the critical need for enhanced security measures in software development pipelines to prevent similar breaches.
5 months ago
Kill Chain
Coruna Exploit Kit: A Cautionary Tale of Advanced Hacking Tools in Cybercriminal Hands
In 2025, the Coruna exploit kit emerged as a sophisticated tool targeting iPhones running iOS versions 13.0 through 17.2.1. Initially deployed by a surveillance vendor for government clients, Coruna was later utilized by Russian espionage groups in attacks against Ukrainian users and by financially motivated hackers in China. The kit comprises five exploit chains and 23 vulnerabilities, including CVE-2023-32434 and CVE-2023-38606, previously exploited in Operation Triangulation. These vulnerabilities enable remote code execution and privilege escalation, granting attackers full control over affected devices. ([techcrunch.com](https://techcrunch.com/2026/03/03/a-suite-of-government-hacking-tools-targeting-iphones-is-now-being-used-by-cybercriminals/?utm_source=openai)) The proliferation of Coruna underscores the risks associated with the leakage of government-grade hacking tools into the broader cybercriminal ecosystem. This incident highlights the urgent need for organizations to implement robust security measures, promptly apply software updates, and monitor for emerging threats to protect sensitive data and maintain operational integrity. ([techcrunch.com](https://techcrunch.com/2026/03/03/a-suite-of-government-hacking-tools-targeting-iphones-is-now-being-used-by-cybercriminals/?utm_source=openai))
5 months ago
Kill Chain
Understanding the Coruna iOS Exploit Kit: A 2026 Security Threat
In early 2026, the Coruna iOS exploit kit emerged as a significant threat, targeting iPhones running iOS versions 13.0 through 17.2.1. This sophisticated toolkit comprises 23 exploits, including zero-day vulnerabilities, enabling attackers to execute zero-click attacks via iMessage. Initially developed for government surveillance, Coruna has since been adopted by cybercriminal groups, leading to widespread data breaches and financial losses. The kit's capabilities allow for full device compromise, granting unauthorized access to sensitive information and enabling remote control of infected devices. The proliferation of Coruna underscores the evolving landscape of mobile threats and the critical need for robust security measures to protect against advanced exploit kits. Organizations and individuals must prioritize timely software updates, implement comprehensive security protocols, and remain vigilant against emerging threats to safeguard their digital assets.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports