The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

4287 threat reports
Page 92 of 358

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Financial Services Threat Reports

Showing 10931104 / 4287 reports
Critical Vulnerabilities in Cursor AI Code Editor Expose Developers to Remote Code Execution
Impact· CRITICAL

Critical Vulnerabilities in Cursor AI Code Editor Expose Developers to Remote Code Execution

In June 2026, two critical vulnerabilities, CVE-2026-50548 and CVE-2026-50549, were discovered in Cursor, an AI-powered code editor. These flaws allowed malicious agents to bypass the application's sandbox protections, enabling unauthorized execution of commands on a developer's machine without user interaction. The vulnerabilities stemmed from improper handling of the working directory and symlink resolution, permitting attackers to write arbitrary files outside the intended workspace, leading to potential remote code execution. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-50549?utm_source=openai)) The discovery of these vulnerabilities underscores the growing risks associated with AI-integrated development tools. As AI becomes more embedded in software development, ensuring the security of such tools is paramount to prevent exploitation by threat actors.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
MetaMask Users Targeted in Sophisticated Phishing Attack - July 2026
Impact· HIGH

MetaMask Users Targeted in Sophisticated Phishing Attack - July 2026

In July 2026, a sophisticated phishing campaign targeted MetaMask users by sending emails that falsely claimed their cryptocurrency wallets were at risk. The emails pressured recipients to provide their secret recovery phrases under the guise of securing their accounts. The attackers utilized a recently registered domain, captchasolve[.]help, to host the phishing site, effectively deceiving users into compromising their wallets. This incident underscores the evolving tactics of cybercriminals in exploiting user trust and the critical importance of safeguarding recovery phrases. ([isc.sans.edu](https://isc.sans.edu/diary/TA551%2B?utm_source=openai)) The prevalence of such targeted phishing attacks highlights the urgent need for enhanced user education on recognizing and avoiding social engineering schemes. As cryptocurrency adoption grows, both individuals and organizations must implement robust security measures and remain vigilant against deceptive practices that aim to exploit human vulnerabilities.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Citrix NetScaler Vulnerability CVE-2026-8451: Critical Memory Disclosure Flaw
Impact· HIGH

Citrix NetScaler Vulnerability CVE-2026-8451: Critical Memory Disclosure Flaw

In June 2026, Citrix disclosed six vulnerabilities in its NetScaler ADC and NetScaler Gateway appliances, notably CVE-2026-8451, a high-severity memory disclosure flaw. This vulnerability arises from improper parsing of SAML authentication requests when the appliance is configured as a SAML identity provider, potentially allowing unauthenticated attackers to access sensitive memory contents. The flaw shares similarities with the 2023 'CitrixBleed' incident, which also involved memory management issues in NetScaler products. The disclosure underscores ongoing challenges in securing critical network infrastructure. Organizations relying on NetScaler appliances should promptly apply the provided patches and review their configurations to mitigate potential exploitation risks.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ARToken: The Next Evolution in BEC-as-a-Service Platforms
Impact· HIGH

ARToken: The Next Evolution in BEC-as-a-Service Platforms

In April 2026, Cisco Talos identified ARToken, a sophisticated phishing platform linked to the EvilTokens phishing-as-a-service operation. ARToken is designed to bypass multi-factor authentication and compromise Microsoft 365 accounts, featuring advanced capabilities such as inbox rule manipulation and shared access links. The platform employs a seven-layer anti-analysis system to evade detection, and its phishing lures are highly targeted, often impersonating legitimate vendor communications to deceive accounts-payable staff into processing fraudulent invoices. The emergence of ARToken underscores a significant evolution in business email compromise (BEC) tactics, highlighting the increasing sophistication and accessibility of phishing-as-a-service platforms. This development poses a heightened risk to organizations, emphasizing the need for enhanced email security measures and employee vigilance against such targeted attacks.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Urgent Alert: Ransomware Gangs Exploit Microsoft Defender 'BlueHammer' Vulnerability
Impact· HIGH

Urgent Alert: Ransomware Gangs Exploit Microsoft Defender 'BlueHammer' Vulnerability

In early April 2026, a security researcher known as 'Nightmare Eclipse' publicly disclosed a high-severity privilege escalation vulnerability in Microsoft Defender, dubbed 'BlueHammer' (CVE-2026-33825), along with proof-of-concept exploit code. This flaw allows local attackers to access the Security Account Manager (SAM) database, enabling them to escalate privileges to SYSTEM level and potentially take full control of the affected system. Microsoft addressed the vulnerability on April 14, 2026, as part of its Patch Tuesday updates. However, by late June 2026, the Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware gangs had begun exploiting this vulnerability in their attacks, leading to significant security concerns for organizations using unpatched systems. The exploitation of BlueHammer underscores a growing trend where threat actors rapidly weaponize newly disclosed vulnerabilities, particularly those with publicly available exploit code. This incident highlights the critical importance of timely patch management and proactive security measures to mitigate the risks associated with such vulnerabilities.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Beware: Malicious 'Perplexity AI' Chrome Extension Intercepts User Searches
Impact· MEDIUM

Beware: Malicious 'Perplexity AI' Chrome Extension Intercepts User Searches

In June 2026, a malicious Chrome extension named "Search for perplexity ai" was discovered impersonating the legitimate Perplexity AI search engine. This extension altered users' default search settings, intercepting all address-bar queries and routing them through attacker-controlled infrastructure before redirecting to legitimate search services. While no credential theft was confirmed, the extension's permissions allowed for extensive data collection, posing significant privacy risks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/fake-perplexity-extension-on-chrome-web-store-tracked-searches/amp/?utm_source=openai)) This incident underscores the growing trend of cybercriminals exploiting trusted AI brands to distribute malicious software. It highlights the need for enhanced vigilance in verifying browser extensions and the importance of robust security measures to prevent unauthorized data interception.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Defending Against AI-Enhanced Business Email Compromise in 2026
Impact· CRITICAL

Defending Against AI-Enhanced Business Email Compromise in 2026

In 2026, Business Email Compromise (BEC) attacks have evolved into sophisticated, multi-stage operations. Threat actors gain access to organizational mailboxes or SaaS accounts, meticulously analyze internal communications, and exploit financial processes to execute fraudulent transactions. The integration of AI technologies has enhanced the quality and efficiency of these scams, making them increasingly difficult to detect. The prevalence of BEC attacks has surged, with 74% of organizations reporting incidents in 2025, up from 63% in 2024. ([nacha.org](https://www.nacha.org/news/business-email-compromise-attempts-rose-sharply-2025-report-finds?utm_source=openai)) This trend underscores the urgent need for organizations to bolster their cybersecurity measures and employee training to mitigate the escalating threat posed by BEC schemes.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Malicious PyPI Packages Compromise Telegram Bot Servers in 2026
Impact· MEDIUM

Malicious PyPI Packages Compromise Telegram Bot Servers in 2026

Between November 2025 and June 2026, a campaign dubbed 'Operation Navy Ghost' targeted Python developers creating Telegram bots by distributing trojanized versions of the Pyrogram library on the Python Package Index (PyPI). These malicious packages, including 'VLifeGram' and 'pyrogram-styled', contained a hidden backdoor that, upon activation, allowed attackers to execute arbitrary code and access sensitive data on compromised servers. The backdoor was designed to operate silently, suppressing errors and disabling logging, thereby granting attackers extensive control over the affected systems. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/malicious-pypi-packages-give-hackers-control-of-telegram-bot-servers/?utm_source=openai)) This incident underscores the persistent threat of supply chain attacks in open-source ecosystems. The exploitation of widely-used libraries like Pyrogram highlights the need for developers to exercise caution when integrating third-party packages. Ensuring the integrity of software dependencies is crucial to prevent unauthorized access and data breaches.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
BioShocking Attack: A New Threat to AI Browser Security
Impact· MEDIUM

BioShocking Attack: A New Threat to AI Browser Security

In June 2026, researchers at LayerX identified a novel prompt injection attack named 'BioShocking' targeting AI-powered browsers. The attack involves a malicious webpage presenting a BioShock-themed puzzle game that rewards incorrect answers, conditioning the browser's control agent to disregard standard safety protocols. In the final stage, the agent is directed to access a GitHub repository and extract sensitive data, such as passwords. This proof-of-concept was tested against six mainstream agentic browsers, with only OpenAI's ChatGPT Atlas implementing an effective fix after disclosure. The BioShocking attack underscores the critical need for robust security measures in AI-driven applications. As AI agents become more integrated into daily tasks, their susceptibility to manipulation poses significant risks. This incident highlights the urgency for developers to implement explicit user confirmations for sensitive actions, enhance context checks, and establish strict boundaries for agentic sessions to prevent similar exploits.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
Impact· CRITICAL

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

In March 2026, threat actors exploited a critical vulnerability in Langflow (CVE-2026-33017), an open-source AI workflow tool, to deploy Monero cryptocurrency miners on exposed AI application endpoints. This unauthenticated remote code execution flaw allowed attackers to execute arbitrary Python code via the public flow build API endpoint, leading to unauthorized system access and resource hijacking. The attacks were observed between March 27 and April 15, 2026, with malicious scripts terminating competing miners, disabling security controls, and establishing persistence mechanisms. ([thehackernews.com](https://thehackernews.com/2026/06/langflow-rce-exploited-to-deploy-monero.html?utm_source=openai)) The rapid exploitation of this vulnerability underscores the increasing targeting of AI infrastructure by cybercriminals. Organizations utilizing Langflow versions prior to 1.9.0 are urged to upgrade immediately and review their systems for signs of compromise. ([thehackernews.com](https://thehackernews.com/2026/06/langflow-rce-exploited-to-deploy-monero.html?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Microsoft Identifies Critical AI Agent Vulnerability in MCP Tool Descriptions
Impact· MEDIUM

Microsoft Identifies Critical AI Agent Vulnerability in MCP Tool Descriptions

In June 2026, Microsoft researchers identified a critical vulnerability in AI agents utilizing the Model Context Protocol (MCP). Attackers can exploit this by embedding malicious instructions within tool descriptions, causing AI agents to inadvertently exfiltrate sensitive company data without triggering security alerts. This method leverages the trust AI agents place in tool descriptions, leading to unauthorized data disclosures. This incident underscores the evolving threat landscape as AI agents become more integrated into business operations. Organizations must reassess their AI security protocols to address these sophisticated attack vectors, emphasizing the need for stringent validation of third-party tools and continuous monitoring of AI agent activities.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
The Rise of AI-Powered Phishing Attacks in 2025
Impact· MEDIUM

The Rise of AI-Powered Phishing Attacks in 2025

In 2025, the cybersecurity landscape witnessed a significant surge in AI-powered phishing attacks. Cybercriminals increasingly leveraged artificial intelligence to craft highly convincing phishing emails, leading to a 140% increase in browser-based phishing attacks and a 130% rise in zero-hour phishing incidents compared to the previous year. This escalation resulted in substantial financial losses, with an estimated $17 billion worth of Bitcoin stolen through AI-enhanced scams. The integration of AI into phishing tactics has not only increased the volume of attacks but also their sophistication, making detection and prevention more challenging for organizations. ([pcworld.com](https://www.pcworld.com/article/2645617/ai-driven-phishing-scams-exploded-last-year-the-trend-continues-in-2025.html?utm_source=openai)) The current relevance of this trend is underscored by the continuous evolution of AI technologies, which are being exploited by cybercriminals to automate and personalize phishing campaigns at an unprecedented scale. This development necessitates a proactive approach from organizations to enhance their cybersecurity measures and adapt to the rapidly changing threat landscape.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports