Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

4282 threat reports
Page 43 of 357

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Financial Services Threat Reports

Showing 505516 / 4282 reports
Unveiling 'ShieldBreak': A New Zero-Day Threat in Microsoft Defender
Impact· HIGH

Unveiling 'ShieldBreak': A New Zero-Day Threat in Microsoft Defender

In August 2026, security researcher Nightmare Eclipse disclosed a zero-day vulnerability named 'ShieldBreak' in Microsoft Defender, allowing attackers to escalate privileges to SYSTEM level on fully patched Windows 10, Windows 11, and Windows Server systems. This exploit leverages a user-mode callback hook during a Defender cloud-hydration scan via the Cloud Filter API (cfapi), effectively bypassing the previous 'RoguePlanet' patch (CVE-2026-50656). The proof-of-concept demonstrated a 100% success rate on tested systems. This incident underscores the persistent challenges in securing endpoint protection platforms and highlights the need for continuous vigilance and rapid response to emerging threats. Organizations must reassess their security postures, especially concerning privilege escalation vulnerabilities, to mitigate potential risks associated with such exploits.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Urgent: Microsoft SharePoint CVE-2026-55040 Exploited in the Wild
Impact· CRITICAL

Urgent: Microsoft SharePoint CVE-2026-55040 Exploited in the Wild

In July 2026, a critical vulnerability identified as CVE-2026-55040 was discovered in Microsoft SharePoint's JWT token validation pipeline. This flaw allowed unauthenticated attackers to impersonate any SharePoint user, including administrators, by bypassing authentication mechanisms. Microsoft addressed this issue in their July 2026 Patch Tuesday updates, urging organizations using SharePoint Enterprise Server 2016 and SharePoint Server 2019 to apply the patches promptly. The urgency of this patch was underscored when, shortly after its release, proof-of-concept exploit code became publicly available and was actively used in attacks targeting unpatched SharePoint servers. This rapid weaponization highlights the critical need for organizations to maintain up-to-date security measures and promptly apply patches to mitigate emerging threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Unmasking the Threat: North Korean IT Worker Impersonation in 2026
Impact· HIGH

Unmasking the Threat: North Korean IT Worker Impersonation in 2026

In July 2026, the U.S. Department of State issued an alert regarding North Korean IT workers impersonating foreign nationals to secure remote employment with U.S. companies. These operatives utilized falsified identities, AI-generated profiles, and deepfake technologies to bypass standard hiring processes. Once employed, they exfiltrated sensitive data, including source code and proprietary information, and funneled salaries back to North Korea, thereby circumventing international sanctions and funding the regime's activities. This incident underscores the evolving sophistication of social engineering tactics in cyber threats. The integration of AI and deepfake technologies into these schemes highlights the urgent need for organizations to enhance their identity verification and remote hiring protocols to prevent similar infiltrations.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Hundreds of Fake Chrome VPN Extensions Compromise User Security
Impact· MEDIUM

Hundreds of Fake Chrome VPN Extensions Compromise User Security

In August 2026, researchers uncovered a campaign involving over 737 malicious Chrome browser extensions that impersonated reputable VPN services such as Proton VPN, NordVPN, and ExpressVPN. These extensions, downloaded nearly 75,000 times primarily by Russian users, rerouted all browser traffic through SOCKS5 proxies controlled by a single operator. This setup allowed the threat actor to monitor users' browsing activities, including destination URLs and any unencrypted data transmitted over HTTP. The extensions employed deceptive tactics, including advertising non-existent premium server locations and using misleading disclosures to evade detection. Despite Google's removal of over 200 of these extensions, more than 500 remained available in the Chrome Web Store at the time of discovery. This incident underscores the persistent threat posed by malicious browser extensions and highlights the need for vigilant scrutiny of browser add-ons. Users are advised to verify the authenticity of extensions before installation and to regularly review and manage their browser's proxy settings to prevent unauthorized data interception.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Understanding the 'Plug and Pwn' Attack: A New Threat to Windows Systems
Impact· HIGH

Understanding the 'Plug and Pwn' Attack: A New Threat to Windows Systems

In August 2026, security researchers unveiled the 'Plug and Pwn' attack, exploiting Windows' Plug and Play feature to gain SYSTEM privileges by emulating USB devices. By presenting fake USB hardware, attackers could trigger Windows to install vulnerable vendor software automatically, leading to unauthorized access. Notably, some attack vectors required no user interaction or physical device connection, utilizing Remote Desktop Protocol (RDP) to achieve the same outcome. This method underscores significant vulnerabilities in Windows' device installation processes, potentially allowing attackers to execute arbitrary code with elevated privileges. The 'Plug and Pwn' attack highlights the evolving sophistication of hardware-based exploits and the critical need for organizations to reassess endpoint security measures. As attackers increasingly leverage legitimate system functionalities for malicious purposes, it becomes imperative to implement stringent device installation policies and monitor for anomalous hardware behaviors to mitigate such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Android Malware Exploits NFC to Commit Financial Fraud
Impact· HIGH

Android Malware Exploits NFC to Commit Financial Fraud

In August 2026, cybersecurity firm Group-IB uncovered a sophisticated Android malware campaign combining the SpyNote Remote Administration Tool (RAT) and WindRelay NFC relay malware. Attackers impersonated bank employees, convincing victims to install a malicious app granting remote access. Utilizing SpyNote, they installed WindRelay, transforming the device into a fraudulent contactless reader to capture and relay credit card data, enabling unauthorized transactions. This operation, executed within a 13-minute phone call, resulted in unauthorized loans and financial losses for victims. This incident underscores a significant escalation in mobile malware sophistication, particularly in exploiting NFC technology for financial fraud. The seamless integration of remote access tools with NFC relay capabilities highlights the evolving tactics of cybercriminals, emphasizing the need for heightened vigilance and advanced security measures to protect against such multifaceted threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
City-Forum Data Theft Attacks: A Wake-Up Call for SaaS Security
Impact· HIGH

City-Forum Data Theft Attacks: A Wake-Up Call for SaaS Security

In August 2026, a data theft campaign named 'City-Forum' was identified, targeting misconfigured Salesforce Experience Cloud and ServiceNow customer portals. The attackers exploited overly permissive sharing rules and portal configurations, allowing unauthorized access to sensitive data through anonymous guest accounts. The campaign, traced to the IP address 158.220.87.79 associated with the domain city-forum.com, has been active since at least March 2025, affecting various sectors including telecommunications, finance, enterprise software, and public services. The 'City-Forum' attacks underscore the critical importance of securing SaaS platforms against unauthorized access. Organizations must review and tighten guest-user permissions and sharing settings to prevent data exposure. This incident highlights a growing trend of cybercriminals exploiting misconfigurations in widely used platforms, emphasizing the need for continuous monitoring and proactive security measures.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft's August 2026 Patch Tuesday: Addressing 398 Security Vulnerabilities
Impact· HIGH

Microsoft's August 2026 Patch Tuesday: Addressing 398 Security Vulnerabilities

In August 2026, Microsoft released patches for 398 security vulnerabilities across its Windows operating systems and supported software. Among these, CVE-2026-68820, a privilege escalation flaw in the afd.sys component, was actively exploited. This vulnerability allows attackers to elevate privileges by exploiting race conditions in the Windows socket driver. Additionally, two other vulnerabilities, CVE-2026-62832 and CVE-2026-72971, were publicly disclosed prior to the patch release, highlighting the critical need for timely updates. The increasing volume of vulnerabilities, attributed to AI-driven discovery methods, underscores the necessity for organizations to enhance their patch management processes. The active exploitation of CVE-2026-68820 emphasizes the urgency of applying these patches promptly to mitigate potential security breaches.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Gunra Ransomware's 2026 Exploitation of Fortinet Vulnerabilities: A Wake-Up Call for Cybersecurity
Impact· CRITICAL

Gunra Ransomware's 2026 Exploitation of Fortinet Vulnerabilities: A Wake-Up Call for Cybersecurity

In early 2026, the Gunra ransomware group, a Ransomware-as-a-Service (RaaS) operation, exploited known vulnerabilities in Fortinet products, notably CVE-2026-24858, to bypass multi-factor authentication (MFA) and gain unauthorized access to critical infrastructure and government organizations worldwide. Utilizing the leaked Conti ransomware code, Gunra executed double-extortion attacks, encrypting data and threatening to publish stolen information unless ransoms were paid. The group's operations expanded through a structured affiliate program, targeting sectors such as healthcare, finance, manufacturing, transportation, and government services. ([shellcodex.com](https://shellcodex.com/ransomware/group/gunra?utm_source=openai)) This incident underscores the persistent threat posed by ransomware groups leveraging known vulnerabilities and the importance of timely patching and robust security measures. The exploitation of Fortinet flaws highlights the need for organizations to prioritize vulnerability management and implement comprehensive security protocols to mitigate such risks. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-22572/?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Cisco ASA and FTD Vulnerability (CVE-2026-20349) Exploited in the Wild
Impact· HIGH

Critical Cisco ASA and FTD Vulnerability (CVE-2026-20349) Exploited in the Wild

In August 2026, Cisco disclosed a high-severity vulnerability (CVE-2026-20349) in its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. This flaw allows unauthenticated remote attackers to trigger a denial-of-service (DoS) condition by sending crafted HTTP requests to the Remote Access SSL VPN service on affected devices. Exploitation results in device reloads, causing service disruptions. The vulnerability affects devices with specific configurations, including IKEv2 Remote Access VPN, SSL-VPN, and Zero Trust Network Access2. Cisco has released software updates to address this issue, as no workarounds are available. The active exploitation of CVE-2026-20349 underscores the critical need for organizations to promptly apply security patches to network infrastructure devices. Delayed responses to such vulnerabilities can lead to significant operational disruptions and potential security breaches. This incident highlights the importance of maintaining up-to-date systems and monitoring for emerging threats to ensure network resilience.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
ShieldBreak Zero-Day PoC Exposes Microsoft Defender Patch Bypass
Impact· HIGH

ShieldBreak Zero-Day PoC Exposes Microsoft Defender Patch Bypass

In August 2026, security researcher Chaotic Eclipse released a proof-of-concept (PoC) for a new Microsoft zero-day vulnerability named ShieldBreak. This vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656, also known as RoguePlanet. RoguePlanet is a race condition that, if exploited, allows an attacker to spawn a shell with SYSTEM-level privileges, enabling the execution of arbitrary code or unauthorized actions. Despite Microsoft's release of a patch in July 2026 to address RoguePlanet, the ShieldBreak PoC indicates that the patch is ineffective, as it can be fully bypassed, maintaining a 100% success rate in tests on Windows 11 25H2 and Windows Server 2025. The release of ShieldBreak underscores the persistent challenges in effectively patching critical vulnerabilities. It highlights the need for organizations to adopt comprehensive security measures beyond relying solely on vendor patches. This incident also emphasizes the importance of continuous monitoring and rapid response strategies to mitigate potential exploits that can arise even after patches are applied.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Vulnerability in SAP Commerce Cloud: CVE-2026-58231
Impact· CRITICAL

Critical Vulnerability in SAP Commerce Cloud: CVE-2026-58231

In August 2026, SAP released patches to address a critical vulnerability (CVE-2026-58231) in SAP Commerce Cloud's Data Hub Adapter. This flaw, rated 10.0 on the CVSS scale, allows unauthenticated attackers to exploit default authentication clients and submit specially crafted inputs to functions lacking sufficient validation. Successful exploitation could lead to arbitrary code execution, compromising the confidentiality, integrity, and availability of the application. This incident underscores the ongoing risks associated with insufficient authorization checks and input validation in enterprise applications. Organizations must prioritize timely patch management and implement robust security measures to mitigate such vulnerabilities.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports