Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
August 2026 Cybersecurity Incidents: City-Forum Campaign, ShipMonk Data Breach, and Cursor CLI Vulnerability
In August 2026, multiple cybersecurity incidents emerged, including the 'City-Forum' campaign targeting unauthenticated guest user access in Salesforce Experience Cloud and ServiceNow Service Portals, leading to significant data exfiltration. Additionally, ShipMonk, a shipping provider for Trezor, suffered a data breach exposing sensitive customer information. Furthermore, Cursor's CLI coding agent was found to execute untrusted repository code without user consent, posing a significant security risk. These incidents underscore the evolving threat landscape, highlighting the need for robust security measures and vigilance against sophisticated attack vectors.
1 month ago
Kill Chain
Jewelbug's Exploitation of XG-Web: A Dual Threat to Governments and Cryptocurrency Users
In August 2026, the China-linked threat actor known as Jewelbug was identified conducting cyber espionage operations targeting governments and militaries, alongside engaging in cryptocurrency fraud. Utilizing a sophisticated tool named XG-Web, Jewelbug transformed victims' browsers into remote-control channels, enabling deep infiltration into host systems and internal networks. This dual-purpose framework facilitated both espionage against governmental entities across the Middle East, Southeast Asia, and South Asia, and financially motivated cryptocurrency fraud aimed at Chinese-speaking users. The group's operations were marked by the development of multiple generations of command-and-control code and a suite of implants affecting browsers, Windows endpoints, Linux servers, and network devices, all feeding into a centralized victim database. The significance of this incident lies in the convergence of state-sponsored cyber espionage and cybercrime within a single operational framework. Jewelbug's activities underscore the evolving landscape where nation-state actors increasingly blur the lines between political objectives and financial gain. This trend highlights the urgent need for organizations to adopt comprehensive cybersecurity measures that address both traditional espionage tactics and emerging cybercriminal methodologies.
1 month ago
Kill Chain
U.S. Private Sector Empowered to Combat Foreign Cybercriminals
On August 12, 2026, President Donald Trump signed a memorandum instructing the National Coordination Center (NCC) to establish a program enabling vetted U.S. private sector companies to conduct cyber operations against foreign Transnational Criminal Organizations (TCOs). This initiative allows authorized firms to perform cyber surveillance and cyber effects operations, including accessing sensitive data and disrupting information systems, under federal oversight. The program aims to counter cyber-enabled crimes such as ransomware, phishing, and financial fraud targeting American citizens. This policy marks a significant expansion of the private sector's role in offensive cyber operations, raising legal and security considerations. Existing U.S. laws prohibit private entities from conducting cyber attacks without court authorization, and this development parallels international trends, such as Germany's recent legislation granting its intelligence agencies broader cyber capabilities.
1 month ago
Kill Chain
CTM360's 'RecruitTrap' Campaign Unveils Sophisticated Phishing Tactics
In August 2026, CTM360 uncovered a large-scale phishing campaign named 'RecruitTrap,' involving over 3,000 malicious URLs designed to steal Google and Facebook credentials. The attackers impersonated recruiters from more than 50 organizations across 14 sectors, primarily targeting marketing professionals. Victims received unsolicited emails or meeting invitations leading to counterfeit interview scheduling pages. These pages employed Browser-in-the-Browser (BitB) techniques to display fake authentication pop-ups, tricking users into entering their credentials and multi-factor authentication codes, which were then relayed to the attackers in real time. This incident highlights the increasing sophistication of phishing attacks, particularly those leveraging BitB techniques to bypass traditional security measures. The focus on marketing professionals underscores the strategic targeting of roles with access to sensitive corporate resources, emphasizing the need for heightened vigilance and advanced security protocols to protect against such evolving threats.
1 month ago
Kill Chain
Exploiting Chrome DevTools Protocol: A New Vector for Session Hijacking in Windows Browsers
In August 2026, cybersecurity researchers disclosed a post-exploitation technique that leverages the Chrome DevTools Protocol (CDP) within active Google Chrome or Microsoft Edge processes on Windows systems. This method allows attackers with existing code execution capabilities to access cookies, saved data, and authenticated browser sessions without exploiting any specific browser vulnerabilities. The technique involves injecting code into running browser processes to activate the CDP, thereby exposing the browser's current context over a specified port. This approach builds upon prior research and tools, such as the CDP-Enable-BOF developed by SpecterOps, which facilitates the activation of the debugging server from within an existing browser process. The method requires a running browser process and is limited to x64 systems. The significance of this technique lies in its ability to bypass traditional security measures by operating within the authenticated context of the browser. This development underscores the evolving nature of post-exploitation strategies and highlights the need for robust detection mechanisms to identify unauthorized process injections and anomalous activities within browser processes.
1 month ago
Kill Chain
macOS Screen Sharing Vulnerability Leads to Unauthorized Monero Mining
In August 2026, a critical vulnerability identified as CVE-2026-65400 was discovered in Apple macOS's Screen Sharing component. This flaw allowed attackers to bypass authentication and gain remote root access to systems with port 5900 exposed to the internet. Exploiting this vulnerability, attackers installed Monero cryptocurrency mining software on compromised machines. Apple promptly released emergency patches for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 to address this issue. The incident underscores the importance of timely software updates and the risks associated with exposing remote access services to the internet. Organizations are advised to apply security patches promptly and review network configurations to minimize exposure to such vulnerabilities.
1 month ago
Kill Chain
Cybercriminals Invest Millions in Expired Domains for Malicious Activities
In the first half of 2026, cybercriminals have increasingly exploited expired domains, known as 'dropcatch' domains, to conduct large-scale scams and malware distribution. By re-registering these domains, threat actors inherit their previous reputation and traffic, enabling them to evade detection and effectively target victims. Notably, the group 'Sable Squirrel' invested over $7 million to acquire more than 10,000 such domains, which they utilized for illegal streaming, online gambling, and as command-and-control servers for various malware families, including Quasar RAT and AsyncRAT. This trend underscores a significant shift in cybercriminal tactics, leveraging the residual trust of expired domains to facilitate malicious activities. The prevalence of this method highlights the urgent need for organizations to monitor and manage their domain portfolios proactively, ensuring that expired domains are not left vulnerable to exploitation. Additionally, it emphasizes the importance of enhancing detection mechanisms to identify and mitigate threats originating from re-registered domains.
1 month ago
Kill Chain
Immediate Action Required: SAP Commerce Cloud CVE-2026-58231 Exploited Days After Patch Release
In August 2026, SAP Commerce Cloud was found to have a critical vulnerability, CVE-2026-58231, rated 10.0 on the CVSS scale. This flaw allows unauthenticated attackers to exploit default authentication clients and submit specially crafted inputs to functions lacking sufficient validation, potentially leading to arbitrary code execution and compromising internal components. Exploitation attempts were detected just three days after the patch release, indicating rapid targeting by threat actors. The swift exploitation of CVE-2026-58231 underscores the increasing speed at which cyber adversaries are capitalizing on newly disclosed vulnerabilities. Organizations must prioritize timely patching and implement robust security measures to mitigate risks associated with such critical flaws.
1 month ago
Kill Chain
Wireshark 4.6.8: Enhancing Network Security with Critical Fixes
In August 2026, Wireshark released version 4.6.8, addressing 28 vulnerabilities and 25 bugs. Notable fixes include the ROHC protocol dissector crash (wnpa-sec-2026-51) and the IEEE 802.11 protocol dissector crash (wnpa-sec-2026-57). These vulnerabilities could lead to denial of service, impacting network analysis capabilities. ([wireshark.org](https://www.wireshark.org/security/?utm_source=openai)) The release underscores the importance of timely software updates to mitigate security risks. Organizations relying on Wireshark for network monitoring should upgrade to version 4.6.8 to ensure system integrity and operational continuity.
1 month ago
Kill Chain
China-Nexus APT Exploits VMware vCenter Vulnerability to Deploy Ransomware
In August 2026, a suspected China-nexus advanced persistent threat (APT) exploited CVE-2026-59310, a critical directory-traversal vulnerability in VMware vCenter Server, to execute arbitrary code. This campaign compromised 361 unique IP addresses across 47 countries, including Germany, the U.S., Turkey, Iran, and France. The attackers deployed Babuk-derived ransomware on ESXi hosts, encrypting files with the ".babyk" extension, potentially as a smokescreen to distract defenders and hinder forensic analysis. This incident underscores the urgency for organizations to promptly apply security patches, especially for critical vulnerabilities in widely used infrastructure. The rapid exploitation following public disclosure highlights the need for proactive vulnerability management and robust incident response strategies to mitigate the risks posed by sophisticated threat actors.
1 month ago
Kill Chain
Suspected China-Nexus APT Exploits VMware vCenter Vulnerability CVE-2026-59310
In August 2026, a suspected China-nexus Advanced Persistent Threat (APT) group exploited CVE-2026-59310, a critical directory-traversal vulnerability in VMware vCenter Server, to execute arbitrary code remotely. This exploitation led to the deployment of a backdoor and a reverse SSH binary, culminating in the installation of Babuk-derived ransomware. The ransomware deployment appeared to serve as a diversion, complicating forensic analysis and potentially masking the primary objectives of the intrusion. This incident underscores the persistent threat posed by state-sponsored actors targeting critical infrastructure through known vulnerabilities. It highlights the necessity for organizations to promptly apply security patches and maintain vigilant monitoring to detect and mitigate such sophisticated attacks.
1 month ago
Kill Chain
Urgent: macOS Screen Sharing Vulnerability (CVE-2026-65400) Exploited in the Wild
In August 2026, a critical vulnerability (CVE-2026-65400) was discovered in macOS's Screen Sharing feature, allowing remote attackers to bypass authentication and gain root access to systems exposed via port 5900. Exploiting this flaw, attackers installed Monero cryptocurrency miners on compromised machines. Apple released out-of-band patches on August 6, 2026, for macOS versions Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 to address this issue. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/macos-screen-sharing-flaw-exploited-to-root-macs-and-plant-monero-miners?utm_source=openai)) This incident underscores the importance of promptly applying security updates and reassessing the exposure of remote access services. The active exploitation of this vulnerability highlights the ongoing risks associated with unpatched systems and the necessity for robust security practices.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports