Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

4272 threat reports
Page 7 of 356

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Financial Services Threat Reports

Showing 7384 / 4272 reports
CVE-2026-87886: Acronis cPanel Backup Plugin Under Active Attack
Impact· MEDIUM

CVE-2026-87886: Acronis cPanel Backup Plugin Under Active Attack

In September 2026, Acronis disclosed CVE-2026-87886, a high-severity Linux local privilege escalation vulnerability in its backup plugins for cPanel, WebHost Manager (WHM), and Plesk. The vulnerability allows low-privileged attackers to escalate permissions on vulnerable Linux servers without user interaction, potentially enabling access to sensitive data and system disruption. Acronis confirmed active exploitation in limited, targeted attacks against hosting environments, prompting immediate patching recommendations for affected versions. This incident highlights the growing trend of attackers targeting web hosting infrastructure and third-party plugins, which provide attractive attack surfaces due to their privileged access to multiple customer environments and critical business operations.

5 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
KREMLIN Banking Malware: How Brazilian Cybercriminals Weaponize Browser Extensions
Impact· HIGH

KREMLIN Banking Malware: How Brazilian Cybercriminals Weaponize Browser Extensions

The KREMLIN banking malware operation, tracked as REF9334, has been targeting Brazilian financial institutions since May 2025 through sophisticated browser hijacking techniques. The threat actors deploy malicious Chrome and Microsoft Edge extensions that bypass Chromium integrity mechanisms by manipulating Secure Preferences files and regenerating required HMACs. The operation leverages Ethereum smart contracts as dead drop resolvers to dynamically update command-and-control endpoints, making disruption extremely difficult. Over 1,515 infected systems have been identified, with 98% located in Brazil. This incident represents the growing sophistication of banking malware that exploits browser extension ecosystems and blockchain infrastructure for resilient operations. As financial institutions increasingly rely on web-based services and multi-factor authentication through browsers, attackers are adapting with advanced techniques that bypass traditional security controls.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Tajin Group Exposed: Inside China's Sophisticated Guarantee Marketplace Cybercrime Network
Impact· HIGH

Tajin Group Exposed: Inside China's Sophisticated Guarantee Marketplace Cybercrime Network

Tajin Group, a Chinese-speaking cybercriminal organization, operates as a third-party vendor on Telegram-based guarantee marketplaces, conducting extensive phishing campaigns, payment card theft, and money laundering operations. The group has demonstrated sophisticated financial crime capabilities by testing payment cards from twelve countries on platforms like CCAvenue and Geidea, while maintaining operations across multiple guarantee marketplaces including Dabai and Xinbi. Their activities target Chinese citizens and banks, with the group depositing over 208,000 USDT as operational stakes, indicating large-scale criminal enterprise operations that pose significant risks to global financial institutions and payment processors. This incident highlights the evolving sophistication of Chinese-language cybercriminal ecosystems and their increasing use of guarantee marketplaces as force multipliers for coordinated financial crimes. The emergence of these organized criminal networks represents a growing threat to international banking systems and demonstrates the need for enhanced cross-border cybersecurity cooperation and financial transaction monitoring.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
VectraRAT: How a $250 Subscription Makes Enterprise Hacking Accessible
Impact· HIGH

VectraRAT: How a $250 Subscription Makes Enterprise Hacking Accessible

VectraRAT represents a sophisticated malware-as-a-service (MaaS) platform discovered by SOCRadar researchers in June 2026, offering cybercriminals comprehensive enterprise attack capabilities for just $250 per month. The platform provides a full-stack solution including a custom Windows implant, command-and-control infrastructure, and operator panel built entirely from scratch rather than leveraging existing malware frameworks. The RAT incorporates advanced features like User Account Control bypass, proprietary C2 protocols, credential harvesting, and remote desktop access. Analysis revealed 48% of victims were corporate Windows environments including Enterprise editions and Windows Server 2025, with confirmed data exfiltration from compromised systems across the US, Russia, and Germany. This incident highlights the concerning democratization of sophisticated cyberattack capabilities, as professional-grade attack infrastructure becomes increasingly accessible through affordable subscription models, significantly lowering the technical barriers for cybercriminals targeting enterprise networks.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Sandworm's Cyclops Blink Evolution: How Russian APT Exploited Cisco Infrastructure
Impact· MEDIUM

Sandworm's Cyclops Blink Evolution: How Russian APT Exploited Cisco Infrastructure

In September 2026, the Russian state-sponsored threat group Sandworm exploited two critical vulnerabilities in Cisco's Firewall Management Center (FMC) software to deploy an upgraded version of the Cyclops Blink malware. The attackers chained CVE-2026-20079 (a maximum severity authentication bypass flaw) with CVE-2026-20316 (a privilege escalation vulnerability) to gain root access and deploy sophisticated backdoors capable of credential harvesting, network scanning, and traffic interception. This campaign represents a significant evolution of Cyclops Blink from its original 2022 variant, now targeting 64-bit Linux systems with enhanced reconnaissance capabilities across network infrastructure devices. This incident highlights the growing trend of state-sponsored actors targeting critical network infrastructure through vulnerability chaining, demonstrating how APT groups are rapidly adapting their malware arsenals to exploit modern enterprise environments and expanding their attack surface beyond traditional endpoints to network management platforms.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
GitLab's Maximum-Severity Vulnerability: A Supply Chain Security Wake-Up Call
Impact· CRITICAL

GitLab's Maximum-Severity Vulnerability: A Supply Chain Security Wake-Up Call

CVE-2026-85706, a maximum-severity path traversal vulnerability in GitLab Community and Enterprise Editions, is being actively exploited by threat actors to compromise software supply chains. The flaw, which received a CVSS score of 10.0, allows unauthenticated attackers to read arbitrary files from GitLab servers, including sensitive credentials and CI/CD secrets. GitLab disclosed and patched the vulnerability on September 10, 2026, but CISA added it to their Known Exploited Vulnerabilities catalog within days due to observed exploitation in the wild. Researchers detected rapid escalation from initial probes to full exploitation, with attackers extracting configuration files and SSH credentials that could enable complete system compromise and lateral movement into development environments. This incident highlights the growing threat to software supply chains as adversaries increasingly target development platforms to gain privileged access to source code, build processes, and deployment pipelines across multiple organizations.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CISA Elevates Cisco Email Gateway SQL Injection to Critical Threat Status
Impact· CRITICAL

CISA Elevates Cisco Email Gateway SQL Injection to Critical Threat Status

CISA has added CVE-2026-76461, a critical SQL injection vulnerability in Cisco Secure Email Gateway, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. This vulnerability allows attackers to execute arbitrary SQL commands, potentially leading to unauthorized data access, system compromise, and lateral movement within enterprise networks. The addition to the KEV Catalog under Binding Operational Directive (BOD) 26-04 requires federal agencies to prioritize rapid remediation of this high-risk vulnerability on publicly exposed assets. This incident highlights the continued targeting of email security infrastructure by threat actors seeking initial access to enterprise environments. As organizations increasingly rely on cloud-based email security solutions, vulnerabilities in these critical gateway systems present attractive attack vectors for data exfiltration and ransomware deployment campaigns.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Chinese APT UTA0560 Weaponizes Chrome-Windows Zero-Day Chain in GRIMWEDGE Campaign
Impact· HIGH

Chinese APT UTA0560 Weaponizes Chrome-Windows Zero-Day Chain in GRIMWEDGE Campaign

In September 2026, Chinese threat actor UTA0560 conducted a sophisticated spear-phishing campaign targeting multiple NGOs using a zero-day exploit chain dubbed BlueMoon. The attackers chained three vulnerabilities - CVE-2026-85046 and CVE-2026-87491 in Chrome, plus CVE-2026-85880 in Windows ALPC - to deploy the GRIMWEDGE JavaScript backdoor. The campaign leveraged reflected XSS vulnerabilities on legitimate university websites to redirect victims to malicious infrastructure hosting the multi-stage exploit chain, demonstrating advanced persistent threat capabilities. This incident highlights the growing threat of patch-gap exploitation, where attackers rapidly weaponize vulnerabilities that are patched in open-source codebases but not yet released in stable versions. With AI-powered exploit development accelerating vulnerability research timelines, organizations face compressed windows to defend against sophisticated nation-state campaigns targeting critical infrastructure and NGOs.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical SAML Flaw in Siemens Mendix Enables Account Hijacking Across Industrial Systems
Impact· HIGH

Critical SAML Flaw in Siemens Mendix Enables Account Hijacking Across Industrial Systems

A critical authentication bypass vulnerability (CVE-2026-80465) was discovered in Siemens Mendix SAML modules across multiple versions, scoring 8.7 on the CVSS scale. The flaw stems from improper validation of SAML response signatures, allowing unauthenticated remote attackers to hijack user accounts and sessions in specific Single Sign-On (SSO) configurations. Affected versions include Mendix 9.24, 10, and 11 compatible modules, with the vulnerability impacting critical manufacturing and IT infrastructure worldwide. Siemens has released patches requiring immediate updates to versions 3.6.27 or 4.2.3 depending on the Mendix platform version. This incident highlights the growing trend of authentication protocol vulnerabilities targeting enterprise SSO systems, particularly as organizations increasingly rely on federated identity management for cloud and hybrid environments.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Cisco Email Gateway Under Attack: CVE-2026-76461 Grants Root Access via Malicious Emails
Impact· CRITICAL

Cisco Email Gateway Under Attack: CVE-2026-76461 Grants Root Access via Malicious Emails

In September 2026, Cisco disclosed CVE-2026-76461, a critical vulnerability in AsyncOS Software for Cisco Secure Email Gateway with a CVSS score of 9.8. The flaw stems from insufficient validation in email parsing logic, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges by sending crafted email messages containing malicious SQL statements. Cisco confirmed active exploitation in the wild and directly contacted customers whose devices showed signs of compromise. The U.S. CISA immediately added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies apply patches by September 17, 2026. This incident highlights the escalating threat to email security infrastructure as attackers increasingly target messaging gateways to gain initial foothold and root-level access, coinciding with broader campaigns against network appliances like the concurrent Fortinet VPN credential attacks reported in late August 2026.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Vite Development Servers Under Attack: Mass Campaign Steals Cloud Credentials
Impact· HIGH

Vite Development Servers Under Attack: Mass Campaign Steals Cloud Credentials

In 2024, cybersecurity researchers from F5 Labs disclosed a mass-scanning campaign targeting exposed Vite development servers to extract sensitive cloud credentials and configuration data. The automated attack systematically scanned internet-facing Vite instances, exploiting misconfigurations to steal AWS and Microsoft Azure credentials, infrastructure state files, and other sensitive development artifacts. The campaign demonstrated how exposed development environments can become critical attack vectors for cloud infrastructure compromise, potentially leading to broader cloud account takeovers and data breaches across multiple organizations. This incident highlights the growing threat to cloud-native development workflows as attackers increasingly target DevOps toolchains and CI/CD pipelines. With organizations rapidly adopting cloud-first development practices and infrastructure-as-code approaches, securing development servers and preventing credential exposure has become a critical security imperative for preventing cloud account compromise.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(low)
Read Report
Apple's Record-Breaking Security Update: 261 Vulnerabilities Patched Across All Platforms
Impact· HIGH

Apple's Record-Breaking Security Update: 261 Vulnerabilities Patched Across All Platforms

On September 14, 2024, Apple released comprehensive security updates across all operating systems, patching a record-breaking 261 vulnerabilities in iOS 27, macOS Golden Gate 27, and other platforms. The vulnerabilities spanned critical system components including kernel memory corruption, privilege escalation flaws, and sandbox escape vulnerabilities affecting core frameworks like WebKit, Kernel, CUPS, and SMB protocols. While Apple reported no active exploitation, the patches addressed severe security gaps including remote code execution, information disclosure, and authentication bypass vulnerabilities that could enable attackers to gain root privileges or access sensitive user data. This massive patch release reflects the evolving complexity of modern attack surfaces and Apple's proactive approach to security hardening. The scale of vulnerabilities demonstrates the critical importance of comprehensive endpoint security and zero-trust architectures as threat actors increasingly target foundational system components and inter-service communications.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports