The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Microsoft 2026 OAuth Redirection Abuse: A New Phishing Threat
In early March 2026, Microsoft identified a sophisticated phishing campaign targeting government and public-sector organizations. Attackers exploited the OAuth 2.0 redirection mechanism to bypass traditional email and browser defenses, redirecting users from legitimate authentication pages to malicious sites. This technique involved crafting OAuth authorization requests with parameters designed to trigger authentication errors, leading to redirects that facilitated malware delivery or credential harvesting. The campaign underscores the evolving tactics of threat actors in leveraging trusted authentication flows to compromise user accounts and deliver malicious payloads. This incident highlights a growing trend in the abuse of OAuth mechanisms for phishing and malware distribution. Organizations must remain vigilant, as attackers continue to refine their methods to exploit authentication protocols, emphasizing the need for robust security measures and user education to mitigate such threats.
6 months ago
Kill Chain
SloppyLemming's Dual Malware Assault on South Asian Governments
Between January 2025 and January 2026, the threat actor known as SloppyLemming executed a series of cyber-espionage attacks targeting government entities and critical infrastructure in Pakistan and Bangladesh. Utilizing spear-phishing emails with malicious PDF and Excel attachments, the group deployed two distinct malware strains: BurrowShell, a backdoor facilitating file manipulation and network tunneling, and a Rust-based keylogger designed for information theft and network reconnaissance. These sophisticated attacks underscore the evolving tactics of nation-state actors in the region. The campaign's reliance on advanced techniques, such as disguising command-and-control traffic as legitimate Windows Update communications and exploiting Cloudflare Workers infrastructure, highlights the increasing complexity of cyber threats facing South Asian nations. This incident serves as a critical reminder for organizations to bolster their cybersecurity defenses against state-sponsored attacks.
6 months ago
Kill Chain
Android 2026 Security Update: Addressing CVE-2026-21385 in Qualcomm Components
In March 2026, Google released a security update addressing 129 vulnerabilities in Android devices, notably CVE-2026-21385—a high-severity flaw in Qualcomm's display component. This vulnerability, an integer overflow leading to memory corruption, was reported by Google's Android Security team on December 18, 2025, and has been confirmed to be under limited, targeted exploitation in the wild. The flaw affects 234 Qualcomm chipsets, spanning a wide range of devices. ([cyberscoop.com](https://cyberscoop.com/android-security-update-march-2026/?utm_source=openai)) The active exploitation of CVE-2026-21385 underscores the critical need for timely security updates. Organizations and individuals using affected devices should prioritize applying the March 2026 security patch to mitigate potential risks associated with this vulnerability. ([cyberscoop.com](https://cyberscoop.com/android-security-update-march-2026/?utm_source=openai))
6 months ago
Kill Chain
Microsoft Warns of OAuth Redirect Abuse Delivering Malware to Government Targets
In March 2026, Microsoft identified phishing campaigns exploiting OAuth's standard redirection mechanisms to deliver malware to government and public-sector organizations. Attackers created malicious applications with redirect URLs pointing to rogue domains hosting malware. They distributed OAuth phishing links prompting recipients to authenticate via these applications using intentionally invalid scopes. This process redirected users to attacker-controlled pages, leading to inadvertent malware downloads. The payloads, often in ZIP archives, executed PowerShell commands upon opening, resulting in host reconnaissance, DLL side-loading, and connections to external command-and-control servers. Phishing emails employed lures such as e-signature requests, Teams recordings, and financial themes, sent through mass-sending tools and custom solutions developed in Python and Node.js. Microsoft has since removed several malicious OAuth applications and advises organizations to limit user consent, periodically review application permissions, and remove unused or overprivileged apps. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/?utm_source=openai))
6 months ago
Kill Chain
AI-Assisted FortiGate Breach 2026: A Wake-Up Call for Network Security
Between January 11 and February 18, 2026, a Russian-speaking, financially motivated threat actor utilized multiple commercial generative AI services to compromise over 600 Fortinet FortiGate firewalls across more than 55 countries. The attacker exploited exposed management interfaces and weak credentials lacking multi-factor authentication, without leveraging any known FortiGate vulnerabilities. This campaign underscores the growing trend of cybercriminals employing AI tools to automate and scale attacks, significantly reducing the technical expertise required to execute large-scale intrusions. The incident highlights the urgent need for organizations to secure management interfaces, enforce strong authentication mechanisms, and stay vigilant against AI-assisted cyber threats.
6 months ago
Kill Chain
Cybercriminals Exploit Fake Tech Support to Deploy Havoc C2 Framework
In February 2026, a sophisticated cyberattack campaign was identified targeting multiple organizations. Threat actors impersonated IT support personnel, initiating contact through spam emails followed by phone calls. They convinced victims to grant remote access via tools like AnyDesk, leading to the deployment of a customized version of the Havoc command-and-control (C2) framework. This allowed rapid lateral movement within networks, with the attackers compromising multiple endpoints within hours, indicating objectives of data exfiltration or ransomware deployment. This incident underscores the evolving tactics of cybercriminals, combining social engineering with advanced malware to infiltrate organizations. The use of open-source C2 frameworks like Havoc, customized to evade detection, highlights the need for enhanced vigilance and updated security protocols to counter such multifaceted threats.
6 months ago
Kill Chain
Project Compass: Unveiling the Arrests in 'The Com' Cybercrime Network
In January 2025, Europol initiated Project Compass, a coordinated international operation targeting 'The Com,' a decentralized cybercriminal collective known for engaging in ransomware attacks, financial extortion, and the exploitation of minors. Over the course of the year, the operation led to the arrest of 30 individuals and the identification of 179 additional suspects across 28 countries. Investigators also identified 62 victims, with four being directly safeguarded from further harm. 'The Com' primarily consists of English-speaking individuals aged 16 to 25, who utilize social media platforms, messaging applications, and online gaming environments to recruit and exploit young people. The group's decentralized structure and use of various online platforms have made it particularly challenging for law enforcement to disrupt their activities. The success of Project Compass underscores the importance of international collaboration in combating cybercrime and highlights the ongoing threat posed by such decentralized networks. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/27/europol-the-com-network-arrests/?utm_source=openai)) The significance of this operation is underscored by the increasing prevalence of cybercriminal groups targeting vulnerable populations through online platforms. The arrest of key members of 'The Com' serves as a critical reminder of the need for continuous vigilance and proactive measures to protect minors from online exploitation. Additionally, the operation highlights the evolving tactics of cybercriminals, who are increasingly leveraging decentralized networks and social engineering techniques to perpetrate their crimes. ([darkreading.com](https://www.darkreading.com/threat-intelligence/30-alleged-members-the-com-arrested-project-compass/?utm_source=openai))
6 months ago
Kill Chain
OpenClaw Vulnerability Highlights AI Agent Security Risks
In February 2026, a critical vulnerability (CVE-2026-25253) was discovered in OpenClaw, an open-source AI agent platform, allowing attackers to execute arbitrary code on users' systems via malicious web pages. This flaw exposed over 42,000 instances globally, leading to unauthorized access, data exfiltration, and potential system compromise. The vulnerability was promptly patched in version 2026.1.29, but the incident highlighted significant security concerns inherent in AI agent architectures. ([taoapex.com](https://taoapex.com/en/guides/deploy-personal-ai-assistant-openclaw/?utm_source=openai)) The rapid adoption of AI agents like OpenClaw has outpaced the development of robust security measures, making them attractive targets for cybercriminals. This incident underscores the urgent need for comprehensive security frameworks and best practices to mitigate risks associated with autonomous AI systems.
6 months ago
Kill Chain
Pro-Iranian Cyberattacks 2026: Unveiling the Threat to Critical Infrastructure
In early 2026, amid escalating geopolitical tensions, pro-Iranian cyber actors launched a series of coordinated cyberattacks targeting critical infrastructure in the United States and allied nations. These attacks aimed to disrupt essential services, including utilities and transportation systems, and were characterized by sophisticated techniques such as ransomware deployment and data exfiltration. The cyber offensive resulted in significant operational disruptions and financial losses, highlighting the evolving threat landscape posed by nation-state-sponsored cyber activities. This incident underscores the persistent and adaptive nature of cyber threats from nation-state actors, particularly in the context of geopolitical conflicts. Organizations are urged to enhance their cybersecurity posture by implementing robust defense mechanisms, conducting regular threat assessments, and fostering information-sharing partnerships to mitigate the risks associated with such sophisticated cyberattacks.
6 months ago
Kill Chain
Understanding OAuth Redirection Abuse in Phishing Attacks
In March 2026, Microsoft identified a sophisticated phishing campaign exploiting OAuth's redirection mechanisms to deliver malware. Attackers crafted URLs using legitimate identity providers like Microsoft Entra ID and Google Workspace, embedding them in phishing emails with themes such as e-signature requests and financial documents. When recipients clicked these links, they were redirected through trusted domains to attacker-controlled sites, leading to malware downloads. This method effectively bypassed traditional email and browser security defenses, resulting in significant compromises across government and public-sector organizations. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/?utm_source=openai)) This incident underscores a growing trend where threat actors leverage legitimate protocol features to conduct malicious activities. The abuse of OAuth redirection highlights the need for organizations to enhance monitoring of authentication flows and implement stricter controls over third-party application permissions to mitigate such evolving threats.
6 months ago
Kill Chain
IBM Bob's 2026 Prompt Injection Vulnerability Exposes AI Security Risks
In January 2026, security researchers at Prompt Armor identified a critical vulnerability in IBM's generative AI tool, Bob, which was in its beta phase. The flaw allowed for indirect prompt injection attacks, enabling malicious actors to embed hidden commands within emails or calendar entries. When Bob processed these inputs, it could be manipulated to perform unauthorized actions such as data exfiltration, malware execution, or establishing persistent system access. This vulnerability was particularly concerning due to Bob's integration capabilities with other applications, amplifying the potential attack surface. The incident underscores the inherent risks associated with AI systems that process untrusted data sources. As AI tools become more integrated into business workflows, the potential for such vulnerabilities increases, highlighting the need for robust security measures. Organizations must prioritize the development and implementation of safeguards to prevent prompt injection attacks and ensure the secure deployment of AI technologies.
6 months ago
Kill Chain
CrushFTP 2025 Brute-Force Attack Highlights Credential Vulnerabilities
In March 2025, CrushFTP servers were targeted by brute-force attacks exploiting default or weak credentials, particularly the 'crushadmin' account with the password 'crushadmin'. These attacks originated from IP address 5.189.139.225, a French IP with a history of exploit attempts targeting simple vulnerabilities. The attackers aimed to gain unauthorized administrative access, potentially leading to data exfiltration and system compromise. This incident underscores the critical importance of enforcing strong password policies and regularly updating default credentials to prevent unauthorized access. Organizations are advised to review their authentication mechanisms and implement multi-factor authentication where possible to mitigate such risks.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports