Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
ReliaQuest Breach Exposes Critical Identity Security Gaps in Social Engineering Defense
In August 2026, cybersecurity firm ReliaQuest fell victim to a sophisticated social engineering attack orchestrated by the ShinyHunters extortion group. Attackers impersonated ReliaQuest security team members via phone calls, directing employees to a fraudulent SSO page hosted on the lookalike domain reliaquest.claims. One employee was successfully deceived into entering credentials and approving an MFA push notification, granting attackers temporary view-only access to ReliaQuest's Okta identity dashboard. However, device-trust controls successfully prevented access to applications and systems, limiting the breach's scope to credential exposure only. This incident highlights the evolving sophistication of social engineering attacks targeting identity systems, particularly as threat actors increasingly combine vishing techniques with credential harvesting. The attack demonstrates how even cybersecurity companies with robust controls can be vulnerable to human-focused attack vectors, emphasizing the critical need for comprehensive identity protection beyond traditional MFA implementations.
3 weeks ago
Kill Chain
The AI Vulnerability Gap: When Discovery Outpaces Defense in 2026
The cybersecurity landscape faces a critical vulnerability gap where AI-powered discovery tools can identify security flaws in hours while human-driven remediation still takes weeks or months. In 2025-2026, advanced AI models began producing vulnerability reports at unprecedented speed, with one in four malicious breaches being AI-enabled, costing organizations an average of $6 million—$1 million more than traditional breaches. This acceleration has created a dangerous imbalance where threat actors leverage AI agents to exploit vulnerabilities faster than defenders can patch them, particularly affecting open source software maintainers who are overwhelmed by uncoordinated disclosure reports. The convergence of AI-accelerated discovery with the EU Cyber Resilience Act's strict disclosure timelines has created unprecedented pressure on organizations to fundamentally transform their vulnerability management processes from reactive patching to proactive engineering disciplines.
4 weeks ago
Kill Chain
SynkLoader Malware: The Multitool Threat Preparing Networks for Ransomware
SynkLoader, a sophisticated multilingual malware family first discovered in August 2026, represents an advanced threat that combines traditional malware techniques with novel social engineering tactics. The malware uses a combination of Python scripts, malicious DLLs, and a unique screen-locking phishing module called 'PhishLocker' to steal credentials and establish persistent access to corporate networks. Initial deployment vectors include convincing phishing emails impersonating Microsoft IT services, with attackers registering legitimate Microsoft 365 tenants and hosting malicious payloads on Azure infrastructure to increase credibility. This incident highlights the evolution of ransomware precursor attacks and initial access broker tactics, particularly the resurgence of screen-locking techniques for credential theft in modern SSO-integrated environments. The malware's system profiling capabilities specifically target network size assessment, suggesting preparation for ransomware deployment or sale to ransomware operators.
4 weeks ago
Kill Chain
ToxicPanda 2.0: When Banking Trojans Become Enterprise Identity Threats
ToxicPanda 2.0, an evolved Android banking Trojan, has expanded from targeting 16 financial institutions to 349 banking, e-wallet, and cryptocurrency applications across 16 countries. The malware leverages Android's Wireless Debugging and ADB capabilities to achieve shell-level access and persistent device compromise. Beyond traditional banking fraud, the Trojan now captures lock-screen credentials and establishes enterprise-grade persistence, creating risks for corporate identity systems and authentication frameworks. This incident highlights the maturation of mobile banking Trojans from simple financial theft tools to comprehensive enterprise threats capable of compromising corporate identity anchors and multi-factor authentication systems.
4 weeks ago
Kill Chain
The Outsized Shadow: How 5% of AI Users Create Enterprise-Wide Security Risks
Akamai's 2026 Enterprise AI Usage Risk Report reveals that the top 5% of enterprise AI power users interact with AI models at 12 times the rate of typical employees, creating disproportionate security risks through shadow AI adoption. These super-adopters are embedding unvetted AI tools into critical business operations, with 47% of enterprise AI conversations occurring through personal identities rather than corporate-managed accounts. The research highlights emerging attack vectors including vibe hacking, cursor jacking, and comet jacking that specifically target AI-enabled workflows and bypass traditional security controls. Organizations face significant data leakage risks as employees use corporate email addresses for personal AI subscriptions, with 14.4% of conversations occurring via freemium accounts that may use sensitive data for model training. The expanding landscape of AI browser extensions poses additional vulnerabilities, with 16.31% containing known CVE exploits compared to 10.8% of standard extensions. This research underscores the urgent need for enterprises to shift from preventing AI adoption to governing AI integration, as traditional security frameworks struggle to address the unique risks posed by autonomous AI agents operating within corporate environments.
4 weeks ago
Kill Chain
Critical Keycloak Authentication Bypass Threatens Enterprise Identity Security
In August 2026, Red Hat and the Keycloak project disclosed CVE-2026-18963, a critical authentication bypass vulnerability rated 9.1 on CVSS. The flaw in Keycloak's password reset mechanism allows unauthenticated remote attackers to take over any user account, including administrative accounts, by exploiting improper state validation in the reset-credentials authentication flow. Attackers can send specially crafted requests to bypass email verification tokens and directly access the password update phase, achieving complete account compromise without user interaction. This vulnerability highlights the growing threat to identity and access management systems, which have become primary targets as organizations adopt zero-trust architectures. With IAM systems serving as the foundational layer for enterprise security, compromises at this level provide attackers with unprecedented access to downstream applications and sensitive data.
4 weeks ago
Kill Chain
WordlistLoader and SynkLoader Campaigns Exploit ClickFix and Microsoft Teams for Credential Theft
In August 2026, cybersecurity researchers identified two new malware families - WordlistLoader and SynkLoader - being used to deliver sophisticated payloads and potentially sell access to ransomware groups. WordlistLoader delivers Amatera Stealer through ClearFake campaigns using ClickFix social engineering techniques that trick victims into executing malicious commands disguised as CAPTCHA verification. The malware uses advanced evasion techniques including EtherHiding blockchain storage and WebDAV-based delivery, while SynkLoader is distributed via Microsoft Teams phishing campaigns to capture Windows credentials through fake lock screens. This incident highlights the evolving sophistication of infostealer campaigns that increasingly abuse legitimate infrastructure like CDNs, cloud storage, and collaboration platforms. The use of blockchain-based payload storage and hardware-breakpoint ETW bypasses demonstrates how threat actors are adapting to modern security controls, making traditional signature-based detection less effective.
4 weeks ago
Kill Chain
AI-Powered Cyber Attacks Target Critical Infrastructure PLCs
In August 2026, U.S. government agencies warned of active threat actors using AI to generate exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) across critical infrastructure sectors including water, energy, and manufacturing. Attackers leverage legitimate scanning services like Censys and ZoomEye to identify vulnerable PLCs, then deploy AI-generated scripts masquerading as monitoring tools to find exploits. The threat actors are systematically testing exploitation techniques against specific PLC models and using read access to understand target environments in preparation for future write operations that could cause operational disruption, safety incidents, equipment damage, and compliance violations. This incident marks a significant escalation in AI-enabled cyber threats against operational technology, demonstrating how artificial intelligence is lowering the barrier for sophisticated industrial control system attacks and compressing the timeline from vulnerability discovery to weaponization.
4 weeks ago
Kill Chain
DOUBLECUP Malware: When PNG Files Become PowerShell Delivery Vehicles
DOUBLECUP malware represents a novel approach to payload delivery by appending PowerShell scripts directly to PNG image files rather than using traditional steganographic techniques. Discovered in August 2024, this malware cleverly leverages Windows' FINDSTR command to extract and execute malicious PowerShell code that is concatenated to legitimate image files. The technique bypasses traditional detection methods by disguising malicious payloads as image files while avoiding complex steganographic encoding that might trigger security tools. The malware uses carriage return and newline characters to facilitate payload extraction, demonstrating attackers' continued innovation in file-based attack vectors. This incident highlights the evolving sophistication of malware delivery mechanisms as threat actors seek new ways to evade detection systems that rely on traditional file analysis and steganographic detection tools.
4 weeks ago
Kill Chain
ToxicPanda 2.0: The Android Banking Trojan That Hijacks VPN Permissions
ToxicPanda 2.0 Android malware emerged in August 2026 with sophisticated capabilities targeting 349 banking and financial applications across 16 countries. The malware exploits VPN service permissions to create local network interfaces that block Google Play communications, preventing security updates and Play Protect interference. It leverages Accessibility Services to automatically enable Wireless ADB debugging, gaining shell-level access to execute high-privilege commands and bypass Android security restrictions. The malware supports 167 remote commands and includes invisible phishing overlays that capture credentials and device PINs while maintaining persistence across major Android device manufacturers. Mobile banking trojans are experiencing a resurgence in 2026, with threat actors increasingly targeting VPN permissions and ADB abuse techniques to circumvent Google's enhanced security measures and maintain persistent access to compromised devices.
4 weeks ago
Kill Chain
Windows Named Pipes Under Attack: Critical Privilege Escalation Vulnerability Analysis
Windows named pipes, a critical interprocess communication mechanism, have become a significant attack vector for privilege escalation vulnerabilities in 2024. Security researchers have identified multiple instances where attackers exploit weak access controls on named pipes to gain elevated privileges and move laterally within Windows environments. These attacks leverage improperly configured pipe permissions, allowing untrusted processes to communicate with privileged services, ultimately leading to system compromise. The exploitation typically involves identifying accessible named pipes, crafting malicious requests, and leveraging inadequate input validation to execute code with elevated privileges. This attack vector has gained prominence as organizations increasingly adopt zero-trust architectures and attackers shift focus to Windows-specific interprocess communication flaws. The rise in named pipe exploitation coincides with growing ransomware campaigns targeting enterprise Windows infrastructure and sophisticated APT groups leveraging these techniques for persistent access.
4 weeks ago
Kill Chain
Critical Zimbra Vulnerability Added to CISA's KEV Catalog Following Active Exploitation
CISA has added CVE-2026-73570, a critical OS command injection vulnerability in Zimbra Collaboration Suite, to its Known Exploited Vulnerabilities Catalog following evidence of active exploitation in the wild. This vulnerability allows attackers to execute arbitrary operating system commands on compromised Zimbra servers, potentially leading to complete system takeover. The addition coincides with CISA's new Binding Operational Directive (BOD) 26-04, which requires federal agencies to prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets that grant total control post-exploitation. This development highlights the continued targeting of enterprise collaboration platforms by threat actors seeking to establish persistent footholds in corporate networks. As hybrid work environments increasingly rely on email and collaboration infrastructure, vulnerabilities in platforms like Zimbra represent high-value targets for initial access brokers and advanced persistent threat groups.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports