The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Critical Vulnerability in Grandstream GXP1600 VoIP Phones: CVE-2026-2329
In February 2026, a critical vulnerability (CVE-2026-2329) was discovered in Grandstream's GXP1600 series VoIP phones, affecting models GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630. This unauthenticated stack-based buffer overflow in the HTTP API endpoint "/cgi-bin/api.values.get" allows remote attackers to execute arbitrary code with root privileges. Exploitation could lead to unauthorized access, interception of VoIP communications, and potential eavesdropping on sensitive conversations. ([rapid7.com](https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/?utm_source=openai)) The incident underscores the importance of promptly applying security patches and monitoring VoIP infrastructure for vulnerabilities. Organizations using these devices should update to firmware version 1.0.7.81 to mitigate the risk. ([rapid7.com](https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/?utm_source=openai))
7 months ago
Kill Chain
KongTuke's CrashFix Campaign: Exploiting DNS to Deliver ModeloRAT
In early 2026, the threat actor known as KongTuke launched an evolved ClickFix campaign, dubbed 'CrashFix,' targeting corporate environments. The attack began with users installing a malicious Chrome extension named NexShield, masquerading as a legitimate ad blocker. After a delay, the extension deliberately crashed the browser, displaying a fake 'CrashFix' security warning. This prompt instructed users to run a command that executed a custom DNS lookup, leading to the download and execution of ModeloRAT, a Python-based remote access trojan. This sophisticated social engineering tactic exploited user trust and system utilities to gain unauthorized access to corporate systems. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/02/05/clickfix-variant-crashfix-deploying-python-rat-trojan/?utm_source=openai)) This incident underscores a growing trend of attackers leveraging social engineering combined with native system tools to bypass traditional security measures. The use of DNS queries for payload delivery highlights the need for enhanced monitoring of network traffic and user education to recognize and resist such deceptive tactics.
7 months ago
Kill Chain
The Rise of RMM Tool Exploitation in Cyber Attacks
In early 2025, cybersecurity researchers observed a significant increase in cyberattacks leveraging legitimate Remote Monitoring and Management (RMM) tools such as AnyDesk, ScreenConnect, and SimpleHelp. Threat actors exploited these tools to gain unauthorized access to systems, maintain persistence, and execute malicious activities without deploying traditional malware. This method allowed attackers to blend seamlessly into normal IT operations, making detection challenging. The impact was widespread, affecting various sectors including healthcare, finance, and education, leading to data breaches, financial losses, and operational disruptions. This trend underscores a shift in cybercriminal tactics towards 'Living-off-the-Land' techniques, where adversaries misuse trusted tools to evade detection. The rise in RMM abuse highlights the need for organizations to enhance monitoring of legitimate software usage and implement stringent access controls to mitigate such threats.
7 months ago
Kill Chain
Microsoft Office Equation Editor Exploit: A 2026 Malware Campaign
In February 2026, a sophisticated malware campaign exploited the Microsoft Office Equation Editor vulnerability (CVE-2017-11882) to deliver malicious payloads. Attackers distributed emails with attachments that, when opened, triggered the exploit, leading to the download and execution of harmful scripts and DLLs. Notably, the campaign reused a JPEG image embedding the final payload, a technique observed in previous attacks, indicating a pattern of leveraging known vulnerabilities and methods. This incident underscores the persistent threat posed by unpatched vulnerabilities and the reuse of attack techniques. Organizations must prioritize timely patching and remain vigilant against evolving malware delivery methods to mitigate such risks.
7 months ago
Kill Chain
Critical Vulnerability in Cryptographic Libraries Exposes Sensitive Data
In February 2026, a critical vulnerability was identified in widely-used JavaScript and Python cryptographic libraries, aes-js and pyaes, respectively. These libraries defaulted to a static initialization vector (IV) in AES-CTR mode, leading to predictable encryption patterns. This flaw exposed numerous applications to potential data breaches, as attackers could exploit the deterministic IV to decrypt sensitive information. The issue was notably present in strongMan VPN Manager, which utilized pyaes for encrypting private keys and certificates, thereby compromising user credentials and network security. This incident underscores the importance of secure cryptographic practices, particularly the necessity of using unique, random IVs for each encryption operation. The widespread adoption of these libraries amplifies the risk, highlighting the need for developers to audit and update their cryptographic implementations to prevent similar vulnerabilities.
7 months ago
Kill Chain
Anthropic's Git MCP Server Vulnerabilities: A Wake-Up Call for AI Security
In January 2026, Anthropic addressed critical vulnerabilities in its Git MCP server, a key component of the Model Context Protocol enabling AI tools to interact with code repositories. Security researchers identified three significant flaws: a path validation bypass (CVE-2025-68145), an unrestricted git_init issue (CVE-2025-68143), and an argument injection flaw in git_diff (CVE-2025-68144). These vulnerabilities, particularly when combined with the Filesystem MCP server, could allow remote code execution or file tampering via prompt injection. Reported in June 2025, these issues were patched by Anthropic in December 2025 with version 2025.12.18. While no active exploitation has been confirmed, this incident highlights the growing risks associated with integrating complex AI systems, where safe components may become vulnerable when used together. The event also references a prior incident from November 2025, where Anthropic's Claude AI was manipulated in a cyberespionage campaign targeting major global entities, underscoring the broader cybersecurity challenges linked to rapid AI adoption.
7 months ago
Kill Chain
AI Discovers Critical OpenSSL Vulnerabilities in 2026
In January 2026, the AI-assisted cybersecurity firm Aisle identified twelve previously undisclosed vulnerabilities in OpenSSL, a widely used cryptographic library essential for secure internet communications. These vulnerabilities, some dating back to 1998, included critical issues like CVE-2025-15467, a stack buffer overflow in CMS message parsing that could lead to remote code execution. OpenSSL rated this vulnerability as HIGH severity, with a CVSS v3 score of 9.8 out of 10. The discovery underscores the potential of AI in enhancing cybersecurity measures by identifying complex vulnerabilities that have eluded traditional detection methods. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/ai-assisted-cybersecurity-team-discovers-12-openssl-vulnerabilities-claims-humans-are-the-limiting-factor-some-vulnerabilities-have-been-around-for-decades?utm_source=openai)) The findings highlight the evolving landscape of cybersecurity, where AI tools are becoming instrumental in proactively identifying and mitigating risks. This shift emphasizes the need for organizations to integrate AI-driven solutions into their security protocols to stay ahead of sophisticated cyber threats.
7 months ago
Kill Chain
Chinese APT UNC6201 Exploits Dell RecoverPoint Zero-Day Vulnerability
In mid-2024, the Chinese state-sponsored threat group UNC6201 exploited a critical zero-day vulnerability (CVE-2026-22769) in Dell's RecoverPoint for Virtual Machines. This flaw, stemming from hardcoded administrator credentials in Apache Tomcat, allowed unauthenticated remote attackers to gain full system access and establish root-level persistence. The attackers deployed malware such as Brickstorm and later Grimbolt, facilitating long-term espionage and data exfiltration. ([cyberscoop.com](https://cyberscoop.com/china-brickstorm-grimbolt-dell-zero-day/?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors targeting critical infrastructure. The prolonged undetected exploitation highlights the necessity for robust vulnerability management and continuous monitoring to detect and mitigate such sophisticated attacks. ([cyberscoop.com](https://cyberscoop.com/china-brickstorm-grimbolt-dell-zero-day/?utm_source=openai))
7 months ago
Kill Chain
Poland's Crackdown on Phobos Ransomware: A 2026 Update
In February 2026, Polish authorities arrested a 47-year-old man in the Małopolska region, suspected of affiliating with the Phobos ransomware group. The arrest was part of 'Operation Aether,' an international effort coordinated by Europol targeting Phobos ransomware infrastructure and affiliates. During the operation, law enforcement seized computers and mobile phones containing stolen credentials, credit card numbers, and server access data, which could be used to facilitate ransomware attacks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/poland-arrests-suspect-linked-to-phobos-ransomware-operation/?utm_source=openai)) This arrest underscores the ongoing global efforts to dismantle ransomware operations and highlights the persistent threat posed by groups like Phobos. Organizations are reminded to bolster their cybersecurity defenses, particularly around Remote Desktop Protocol (RDP) configurations, to mitigate the risk of such attacks.
7 months ago
Kill Chain
Intruder 2026: Unveiling Exposed Secrets in JavaScript Bundles
In December 2025, Intruder's research team conducted a comprehensive scan of 5 million applications, uncovering over 42,000 exposed tokens hidden within JavaScript bundles. These tokens included sensitive credentials such as code repository access tokens and project management API keys, many of which were active and provided unauthorized access to critical systems. The exposure was attributed to limitations in traditional security tools, which often fail to detect secrets embedded in front-end code, particularly within single-page applications. This incident underscores the urgent need for enhanced secrets detection methods that can effectively identify and mitigate such vulnerabilities in modern web applications.
7 months ago
Kill Chain
Chinese Hackers Exploit Dell Zero-Day Vulnerability in 2024
In mid-2024, the Chinese state-sponsored hacking group UNC6201 began exploiting a critical vulnerability (CVE-2026-22769) in Dell's RecoverPoint for Virtual Machines, a solution integral to VMware virtual machine backup and recovery. This hardcoded credential flaw allowed unauthenticated remote attackers to gain unauthorized access to the underlying operating system, achieving root-level persistence. Once inside, UNC6201 deployed advanced malware, including the Grimbolt backdoor, and utilized novel techniques like creating hidden network interfaces ('Ghost NICs') on VMware ESXi servers to move stealthily across networks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/chinese-hackers-exploiting-dell-zero-day-flaw-since-mid-2024/?utm_source=openai))This incident underscores the persistent threat posed by state-sponsored actors targeting critical infrastructure through zero-day vulnerabilities. The exploitation of such flaws highlights the necessity for organizations to maintain rigorous patch management and continuous monitoring to detect and mitigate sophisticated cyber threats.
7 months ago
Kill Chain
Critical Vulnerabilities in Popular VSCode Extensions Expose Developers to Attacks
In February 2026, critical vulnerabilities were discovered in several widely-used Visual Studio Code (VSCode) extensions, including Live Server, Code Runner, Markdown Preview Enhanced, and Microsoft Live Preview. These extensions, collectively downloaded over 128 million times, contained flaws that could be exploited to steal local files and execute remote code. The vulnerabilities were identified by Ox Security, which attempted disclosure since June 2025 without receiving responses from the maintainers. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/?utm_source=openai)) This incident underscores the escalating risks associated with third-party development tools and the necessity for rigorous security assessments of IDE extensions. The widespread adoption of these vulnerable extensions highlights the potential for significant supply chain attacks targeting developers and organizations.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports