Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
CISA Adds Three Known Exploited Vulnerabilities to Catalog
On August 4, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-9198 (IBM Langflow Code Injection), CVE-2026-18556 (N-able N-central Authentication Bypass), and CVE-2026-34486 (Apache Tomcat Missing Encryption of Sensitive Data). These vulnerabilities are actively exploited, posing significant risks to federal enterprises. CISA's Binding Operational Directive (BOD) 26-04 mandates Federal Civilian Executive Branch (FCEB) agencies to prioritize remediation of such high-risk vulnerabilities to protect against active threats. While BOD 26-04 applies to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
1 month ago
Kill Chain
Kali365: A New Phishing Threat Targeting Microsoft 365 Users
In April 2026, the FBI identified 'Kali365,' a Phishing-as-a-Service platform that enables attackers to hijack Microsoft 365 accounts by exploiting the OAuth device code authentication flow. This method allows cybercriminals to bypass multi-factor authentication (MFA) by capturing access and refresh tokens, granting persistent access to services like Outlook, Teams, and OneDrive without requiring user credentials. The attack typically involves phishing emails that direct victims to enter a device code on a legitimate Microsoft login page, unknowingly authorizing the attacker’s device. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260521?pubDate=20260525&utm_source=openai)) The emergence of Kali365 underscores a significant shift in phishing tactics, highlighting the vulnerabilities in current authentication processes. As attackers increasingly adopt such sophisticated methods, organizations must reassess and strengthen their security protocols to mitigate the risks associated with token-based authentication exploits.
1 month ago
Kill Chain
Microsoft Defender's Rapid Response Halts QNET Cyberattack in 2026
In August 2026, QNET, a global direct-selling company, experienced a multi-stage cyberattack where an adversary utilized a legitimate Windows tool to execute a malicious payload. Microsoft Defender's new device isolation feature autonomously intervened, isolating the compromised endpoint within 128 seconds of detection, effectively halting the attack before the second-stage payload could establish persistence or propagate laterally. This swift response prevented potential data exfiltration and operational disruption. The incident underscores the growing prevalence of sophisticated attacks leveraging legitimate tools to evade detection. It highlights the critical importance of advanced, automated defense mechanisms like device isolation in rapidly containing threats and minimizing organizational impact.
1 month ago
Kill Chain
North Korean Hackers Utilize 'NullReceiver' in Trojanized npm Packages
In August 2026, cybersecurity researchers identified a sophisticated supply chain attack involving two trojanized npm packages, 'bianira-ui' and 'fluid-type-ui'. These packages employed a novel technique, dubbed 'NullReceiver', to conceal command-and-control (C2) server IP addresses within the recipient addresses of zero-value Ethereum transactions. This method, an evolution of the previously documented 'EtherHiding' technique, was linked to North Korean state-sponsored actors. The malicious packages were uploaded to npm on July 28, 2026, and collectively downloaded nearly 700 times before their removal. The 'NullReceiver' approach enhances operational resilience by eliminating fixed, trackable destinations, thereby complicating detection and mitigation efforts. This incident underscores the escalating sophistication of supply chain attacks and the persistent threat posed by nation-state actors leveraging blockchain technologies for stealthy malware deployment.
1 month ago
Kill Chain
Understanding the ChainDrop Supply Chain Compromise
In August 2026, a large-scale supply chain attack, dubbed 'ChainDrop,' compromised over 400 npm packages across multiple publishers. The attackers injected a self-propagating, credential-stealing worm into these packages, which executed automatically via npm preinstall hooks. Once activated, the malware harvested credentials from developer workstations and CI/CD environments, targeting npm, GitHub, AWS, Kubernetes, and HashiCorp Vault. The stolen credentials facilitated further unauthorized access and propagation, significantly amplifying the attack's reach and impact. This incident underscores the escalating threat of supply chain attacks, particularly those leveraging automated propagation mechanisms. Organizations must enhance their security postures by implementing stringent code review processes, monitoring for unauthorized package modifications, and adopting robust credential management practices to mitigate such risks.
1 month ago
Kill Chain
INC Ransomware's Exploitation of SonicWall Zero-Day Vulnerabilities in 2026
In June 2026, the INC ransomware group exploited two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, in SonicWall's Secure Mobile Access (SMA) 1000 Series appliances. These vulnerabilities allowed unauthenticated attackers to gain root-level access, leading to the deployment of ransomware and potential data exfiltration. The attacks began on June 22, 2026, prior to SonicWall's disclosure and patch release on July 14, 2026. Organizations utilizing these appliances were urged to apply patches immediately and investigate for signs of compromise. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/07/21/sonicwall-sma-zero-days-exploited-cve-2026-15409-cve-2026-15410/?utm_source=openai)) This incident underscores the increasing trend of ransomware groups targeting critical infrastructure through zero-day vulnerabilities. The rapid exploitation of these flaws highlights the need for organizations to maintain vigilant patch management practices and implement robust monitoring to detect unauthorized access promptly.
1 month ago
Kill Chain
Massive Supply Chain Attack: TeamPCP's 'Mini Shai-Hulud' Worm Compromises Over 440 npm Packages
In May 2026, the cybercriminal group TeamPCP executed a rapid supply chain attack, compromising over 440 npm packages within four hours. Utilizing the 'Mini Shai-Hulud' worm, they injected malicious code into widely-used packages such as keyv, flat-cache, and file-entry-cache, affecting software with a combined total of over 2 billion monthly installs. The malware harvested sensitive data, including npm, GitHub, AWS credentials, AI configuration files, and cryptocurrency wallets, posing significant risks to developers and organizations relying on these packages. This incident underscores the escalating threat of supply chain attacks targeting open-source ecosystems. The rapid propagation and extensive reach of the 'Mini Shai-Hulud' worm highlight the need for enhanced security measures, including rigorous package vetting, continuous monitoring, and the adoption of zero-trust principles to safeguard against such pervasive threats.
1 month ago
Kill Chain
Unveiling TeamPCP's Extensive Supply Chain Attacks on Open-Source Software
TeamPCP, a sophisticated threat actor, has been actively compromising open-source software supply chains since at least 2020. Their operations involve injecting malicious code into widely-used software packages, leading to unauthorized access and control over numerous systems. In late 2025, they exploited the ShadowRay vulnerability (CVE-2023-48022) in the Ray AI framework, creating a self-propagating botnet that hijacked AI infrastructure globally. ([oligo.security](https://www.oligo.security/blog/shadowray-2-0-attackers-turn-ai-against-itself-in-global-campaign-that-hijacks-ai-into-self-propagating-botnet?utm_source=openai)) The rapid evolution of TeamPCP's attack methods, facilitated by AI, underscores the growing threat to open-source ecosystems. Their ability to adapt and scale attacks highlights the urgent need for enhanced security measures in software development and deployment processes.
1 month ago
Kill Chain
Pass-ta-key Attacks: A New Threat to Passwordless Authentication
In August 2026, security researchers from Palo Alto Networks' Unit 42 identified three novel attacks, collectively termed "Pass-ta-key," targeting Google Password Manager's passkey synchronization on Windows devices equipped with Trusted Platform Modules (TPMs). These attacks enable malware on already-compromised systems to impersonate trusted devices, register malicious user-verification keys, and extract master keys used to encrypt all synced passkeys. Notably, the "Golden Pass-ta-key" technique allows attackers to access the security domain secret, potentially compromising all passkeys stored in the victim's Google Password Manager. This incident underscores the evolving threats to passwordless authentication systems and highlights the necessity for robust validation mechanisms and secure handling of cryptographic materials. Organizations must reassess their reliance on passkey synchronization and implement additional safeguards to mitigate such vulnerabilities.
1 month ago
Kill Chain
ChainDrop npm Supply-Chain Attack: A Wake-Up Call for Open-Source Security
In August 2026, a self-propagating malware named 'ChainDrop' compromised over 1,300 packages on the Node Package Manager (npm) registry, affecting packages with a combined 2 billion monthly downloads. The attack began when the threat actor gained access to the GitHub account of Keyv's maintainer, leading to the infection of popular packages such as Keyv, Cacheable, flat-cache, and file-entry-cache. The malware deployed a Shai-Hulud-based worm that inserted malicious files into the main branches of these projects, which were then published through legitimate GitHub Actions workflows, resulting in npm releases with valid provenance information. The malicious packages contained scripts designed to steal sensitive information, including developer and cloud credentials, which were encrypted and exfiltrated to a public GitHub repository. The malware also exhibited self-spreading capabilities, infecting additional packages that depended on the compromised ones. This incident underscores the escalating threat of supply-chain attacks targeting open-source ecosystems. The widespread impact of ChainDrop highlights the critical need for robust security measures, including dependency allowlisting, integrity checks, and provenance controls, to safeguard against such vulnerabilities.
1 month ago
Kill Chain
New XCSSET Variant Compromises macOS Developer Environments via Xcode Projects
In August 2026, a new variant of the XCSSET malware emerged, targeting macOS developers through compromised Xcode projects. The malware infiltrates developer environments by embedding itself into Xcode project files, particularly the project.pbxproj configuration files. When developers build these infected projects, the malware executes, leading to credential theft, browser data exfiltration, and the potential propagation to other Xcode projects on the same system. This method poses a significant supply chain risk, as it can silently spread through shared repositories and developer workflows. The resurgence of XCSSET underscores the evolving nature of supply chain attacks, emphasizing the need for developers to scrutinize third-party code and monitor their development environments for anomalies. The incident highlights the importance of implementing robust security measures within the software development lifecycle to prevent such infiltrations.
1 month ago
Kill Chain
77 Malicious Open VSX Extensions Harvest Developer Data
Between July 26 and August 1, 2026, Manifold Security identified 77 malicious extensions on the Open VSX marketplace that impersonated legitimate developer tools. These 'evil twin' extensions collected and transmitted system and development environment data to a server at mangorbit[.]com. While 58 extensions sent minimal system information, 19 conducted extensive reconnaissance, exfiltrating metadata related to developers, Git repositories, and continuous integration environments. Notably, these extensions did not access source code, credentials, authentication tokens, SSH material, or browser data. The malicious packages were removed from Open VSX by August 3, 2026, but developers are advised to manually remove them from their systems. This incident underscores the growing threat of supply chain attacks targeting developer environments. The use of counterfeit extensions to harvest sensitive metadata highlights the need for enhanced vigilance and security measures when sourcing and installing development tools.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports