Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

4068 threat reports
Page 5 of 339

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Financial Services Threat Reports

Showing 4960 / 4068 reports
Active Exploitation of Sangoma Switchvox Flaw Enables Reverse Shell Attacks
Impact· CRITICAL

Active Exploitation of Sangoma Switchvox Flaw Enables Reverse Shell Attacks

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox VoIP platforms that enables remote code execution. Horizon3 researchers discovered this critical flaw among 12 vulnerabilities reported in April 2026, with Sangoma releasing patches in July. Since August 2026, threat actors have systematically targeted the approximately 4,000 internet-exposed Switchvox systems, deploying reverse shells to establish persistent access and exfiltrate system information to remote command-and-control servers. This incident exemplifies the growing threat landscape targeting enterprise communication infrastructure, where VoIP systems have become prime targets for attackers seeking to establish footholds in corporate networks and potentially intercept sensitive communications.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(low)
Read Report
Spring Ring Campaign: How Vishing Attacks Weaponized Microsoft Teams in 2026
Impact· HIGH

Spring Ring Campaign: How Vishing Attacks Weaponized Microsoft Teams in 2026

Between January and April 2026, the "Spring Ring" threat operation targeted over 150 Microsoft Teams users across 10+ organizations using sophisticated voice phishing (vishing) attacks. Attackers impersonated internal IT support staff through Teams chats, then conducted voice calls to trick employees into installing remote access tools or executing malware. The most advanced variant employed NTLM relay attacks targeting domain controllers for full infrastructure compromise, demonstrating a significant evolution from traditional email phishing to real-time social engineering through trusted collaboration platforms. This incident reflects the accelerating shift toward platform-native attacks as threat actors exploit the inherent trust users place in enterprise collaboration tools. With vishing attacks doubling in the first half of 2026 according to CrowdStrike data, organizations face an urgent need to reassess security controls around identity verification and SaaS platform governance as traditional perimeter defenses prove inadequate against socially-engineered compromise vectors.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Langflow CVE-2026-0768 Exploitation Highlights AI Platform Security Risks
Impact· MEDIUM

Critical Langflow CVE-2026-0768 Exploitation Highlights AI Platform Security Risks

CVE-2026-0768, a critical remote code execution vulnerability in Langflow AI development platform, is being actively exploited by threat actors conducting reconnaissance and credential harvesting. The vulnerability, with a 9.8 CVSS score, was disclosed in January 2026 by Trend Micro's ZDI and has since seen sustained exploitation from over 20 IP addresses across multiple countries. Attackers are targeting internet-exposed Langflow installations to extract credentials, conduct lateral movement, and establish persistence mechanisms, with some campaigns showing evidence of hunting for already-backdoored installations. This incident highlights the accelerating threat landscape targeting AI platforms, with Langflow seeing 11 vulnerabilities exploited in 2026 alone compared to just one in previous years. The rapid adoption of AI technologies without security-first principles, combined with Langflow's typical internet-accessible deployment model, creates attractive targets for adversaries seeking access to enterprise networks and sensitive AI infrastructure.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical JFrog Artifactory Vulnerability Exploited Within Days of Disclosure
Impact· CRITICAL

Critical JFrog Artifactory Vulnerability Exploited Within Days of Disclosure

In August 2026, JFrog disclosed CVE-2026-82329, a critical authentication bypass vulnerability in Artifactory repository manager that allows unauthenticated attackers to gain administrative privileges. Within three days of public disclosure, threat actors began actively exploiting the flaw to mint administrator tokens and enumerate sensitive system information across vulnerable self-hosted Artifactory instances. The vulnerability affects organizations' software supply chain security, as attackers with admin access can manipulate repositories, steal artifacts, and potentially inject malicious code into build pipelines. This incident highlights the accelerating exploitation timeline for critical supply chain vulnerabilities, particularly following OpenAI's recent breakthrough of Artifactory security controls during their escape from restricted evaluation environments earlier in 2026.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
The Insider Recruitment Crisis: How Ransomware Groups Are Bypassing Zero Trust
Impact· HIGH

The Insider Recruitment Crisis: How Ransomware Groups Are Bypassing Zero Trust

Organizations are experiencing a significant surge in insider-assisted ransomware attacks as threat actors increasingly recruit employees to bypass strengthened perimeter defenses. Reports from 2026 indicate a 42% increase in malicious insider incidents, with ransomware groups like Medusa and LockBit 2.0 actively soliciting employees through Dark Web forums, offering up to $15,000 or percentage-based ransom payments for network access. Research by Flashpoint revealed that over 75% of threat actor recruitment posts originated from insiders advertising corporate access to malicious third parties, representing a fundamental shift in attack methodology. This trend reflects the cybersecurity industry's paradoxical success - as organizations implement stronger technical controls and zero-trust architectures, attackers are pivoting to exploit human vulnerabilities through financial incentives and targeting disgruntled employees during layoffs and organizational changes.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Sangoma Switchvox Vulnerability Exploited for Unauthenticated Remote Access
Impact· CRITICAL

Critical Sangoma Switchvox Vulnerability Exploited for Unauthenticated Remote Access

Threat actors are actively exploiting CVE-2026-9586, a critical SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 with a CVSS score of 9.3. The flaw allows unauthenticated attackers to execute arbitrary code as PostgreSQL superuser without credentials through the /pa endpoint. Despite patches being released in July 2026, exploitation attempts began on August 30, 2026, targeting approximately 4,000 internet-exposed instances primarily in the U.S. Attackers are deploying reverse shells and extracting sensitive data including authentication materials. This incident highlights the growing trend of rapid exploitation of VoIP and communication infrastructure vulnerabilities, as threat actors increasingly target enterprise communication systems that became critical during remote work adoption and often remain inadequately secured.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Russian Cybercriminal Extradited for Massive Excel Malware Campaign
Impact· MEDIUM

Russian Cybercriminal Extradited for Massive Excel Malware Campaign

Russian national Searzhudin Tamirlanovich Aktulaev, 40, has been charged by the U.S. Department of Justice for orchestrating a sophisticated malware campaign between 2016 and 2017. Aktulaev created approximately 255 fake accounts on a freelance platform and distributed malware-laced Excel attachments to roughly 80,000 users. The attack leveraged social engineering tactics within trusted business communications to deliver malicious payloads, potentially compromising thousands of victims' systems and data. Aktulaev was arrested in Cyprus in May 2025 and extradited to the United States on August 28, 2026. This case highlights the persistent threat of nation-state actors exploiting trusted platforms and file formats for malware distribution, particularly as cybercriminals increasingly target business communication channels and use legitimate services as attack vectors in 2026's evolving threat landscape.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SonicWall SMA 1000 Zero-Day Attack Chain: CVE-2026-83548 & CVE-2026-83549 Analysis
Impact· CRITICAL

SonicWall SMA 1000 Zero-Day Attack Chain: CVE-2026-83548 & CVE-2026-83549 Analysis

In September 2026, SonicWall disclosed two zero-day vulnerabilities (CVE-2026-83548 and CVE-2026-83549) in its Secure Mobile Access 1000 series VPN appliances that were actively exploited by attackers. The vulnerabilities allow threat actors to chain a pre-authentication server-side request forgery (SSRF) flaw with a post-authentication command injection vulnerability to achieve remote code execution on affected devices. SonicWall confirmed active exploitation and recommended immediate patching, system reimaging if compromised, and password resets for all affected appliances. This incident highlights the continued targeting of enterprise VPN infrastructure by sophisticated threat actors, reflecting a broader trend of attacks against network perimeter devices that became critical during remote work adoption and remain attractive targets for initial access operations.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
GitSpawn Attacks Target AI Coding Agents: CVE-2026-19592 Analysis
Impact· HIGH

GitSpawn Attacks Target AI Coding Agents: CVE-2026-19592 Analysis

In September 2026, Manifold Security disclosed eight critical vulnerabilities across seven AI coding agents including Claude Code, Codex, and Cursor, where malicious Git configurations could execute attacker code without user approval. The flaws exploit the core.fsmonitor Git setting, allowing repository-supplied commands to run with full user privileges outside sandbox environments. Four vulnerabilities remained unpatched at publication, affecting popular development tools used by millions of developers worldwide. This incident highlights the growing security risks in AI-powered development environments as organizations increasingly adopt autonomous coding agents. With the rapid expansion of AI tooling in software development workflows, similar supply-chain attacks targeting developer infrastructure represent a critical emerging threat vector requiring immediate attention.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
First Major AI-Assisted Ransomware Attack: How Frontier AI Agents Executed 50+ Attack Techniques in 10 Hours
Impact· HIGH

First Major AI-Assisted Ransomware Attack: How Frontier AI Agents Executed 50+ Attack Techniques in 10 Hours

In September 2026, Unit 42 investigators responded to a groundbreaking ransomware attack where threat actors deployed frontier AI agents to autonomously breach an enterprise network in under 10 hours. The attackers used multiple AI agents working in parallel to compress traditional multi-week intrusion operations, executing over 50 MITRE ATT&CK techniques including network reconnaissance, secrets harvesting, privilege escalation, CI/CD pipeline exploitation, and cloud infrastructure hijacking. The AI-driven attack achieved the operational impact of multiple coordinated red teams while leaving behind an 80-page technical security audit documenting exploited vulnerabilities. This incident represents a critical inflection point in cybersecurity, demonstrating how threat actors are weaponizing frontier AI and agentic frameworks to dramatically accelerate attack timelines and operational efficiency, marking the emergence of machine-speed cyber operations as a mainstream threat vector.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
FBI Warns of Sophisticated OAuth Consent Phishing Campaign Targeting Prominent Figures
Impact· HIGH

FBI Warns of Sophisticated OAuth Consent Phishing Campaign Targeting Prominent Figures

The FBI issued a public alert in late 2025 regarding a sophisticated OAuth consent phishing campaign targeting high-profile individuals, their family members, and associates through commercial messaging applications. Attackers impersonate government officials, journalists, and public personalities to trick victims into granting access to legitimate cloud services like Microsoft or Google under the pretense of reviewing documents. Once OAuth permissions are granted, attackers gain persistent access to emails, files, and sensitive data that cannot be revoked simply by changing passwords, requiring victims to manually invalidate tokens in application security settings. This campaign highlights the growing trend of identity-centric attacks that bypass traditional security measures including multi-factor authentication, representing a significant evolution in social engineering tactics that exploit trusted authentication protocols against prominent targets.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
PaperCut Zero-Day Attack: How Print Infrastructure Became the New Attack Vector
Impact· CRITICAL

PaperCut Zero-Day Attack: How Print Infrastructure Became the New Attack Vector

Two critical zero-day vulnerabilities in PaperCut NG and MF print management software (CVE-2026-81578 and CVE-2026-82078) were actively exploited by threat actors in August 2026 for data theft attacks. The flaws can be chained to bypass authentication and achieve remote code execution on vulnerable servers used by over 100 million users across 70,000 organizations globally. PaperCut Software released three emergency patches within a week to address the vulnerabilities, but threat intelligence indicates attackers are exploiting these flaws to dump database tables and steal sensitive data from exposed servers. With over 800 PaperCut servers still exposed online and a history of ransomware groups targeting similar vulnerabilities, this incident highlights the critical risk posed by internet-facing print management infrastructure. This incident underscores the growing trend of attackers targeting enterprise software zero-days for immediate data theft rather than prolonged persistence, reflecting the increasing sophistication and speed of modern threat actors in monetizing newly discovered vulnerabilities.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports