The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

4291 threat reports
Page 95 of 358

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Financial Services Threat Reports

Showing 11291140 / 4291 reports
Hijacked npm and Go Packages Exploit VS Code to Deploy Python Infostealer
Impact· HIGH

Hijacked npm and Go Packages Exploit VS Code to Deploy Python Infostealer

In June 2026, cybersecurity researchers identified a sophisticated supply chain attack involving hijacked npm and Go packages designed to deploy a Python-based information stealer across Windows, Linux, and macOS systems. The attackers embedded malicious code within Visual Studio Code (VS Code) tasks, configured to execute automatically when a project folder was opened. This method bypassed traditional npm execution paths, allowing the malware to retrieve encrypted JavaScript from blockchain transactions, establish a backdoor via socket.io, and ultimately deploy the Python infostealer. The compromised npm packages, 'html-to-gutenberg' and 'fetch-page-assets', were uploaded on May 25, 2026, and have since been removed from the registry. This incident underscores a growing trend of attackers exploiting development environments and tools to infiltrate systems, highlighting the need for enhanced security measures within the software supply chain. The use of blockchain as a resilient command-and-control mechanism further complicates detection and mitigation efforts, emphasizing the importance of vigilance and proactive defense strategies among developers and organizations.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Microsoft Eliminates 119 Malicious Edge Extensions Concealing Malware
Impact· HIGH

Microsoft Eliminates 119 Malicious Edge Extensions Concealing Malware

In June 2026, Microsoft identified and removed 119 malicious extensions from the Edge Add-ons store, collectively known as 'StegoAd.' These extensions, active since at least 2021, utilized steganography to conceal malware within image and font files. After installation, the malware remained dormant, later activating to steal user credentials and conduct ad fraud. The affected extensions, including ad blockers, VPNs, translators, and video downloaders, amassed up to 2.6 million installations. The exact number of compromised users remains undetermined. This incident underscores the evolving sophistication of cyber threats, particularly in the realm of browser extensions. The use of steganography to evade detection highlights the need for enhanced security measures and vigilant monitoring of third-party add-ons. Organizations must prioritize the implementation of robust security protocols to mitigate such risks.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
Impact· CRITICAL

Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw

In June 2026, a critical vulnerability identified as CVE-2026-55200 was discovered in libssh2 versions up to and including 1.11.1. This flaw resides in the ssh2_transport_read() function, which fails to properly validate the packet_length field in incoming SSH packets. As a result, remote attackers can send specially crafted SSH packets with excessively large packet_length values, leading to heap memory corruption and potential remote code execution without requiring authentication or user interaction. The issue was addressed in commit 7acf3df. The release of a public proof-of-concept (PoC) exploit for this vulnerability has heightened the risk of widespread exploitation. Given libssh2's integration into numerous applications and systems, including curl, Git, PHP, and various backup agents, the potential attack surface is extensive. Organizations are urged to assess their environments for affected versions and apply the necessary patches promptly to mitigate the risk of compromise.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical DirtyClone Vulnerability in Linux Kernel (CVE-2026-43503) Exposes Systems to Root Access
Impact· HIGH

Critical DirtyClone Vulnerability in Linux Kernel (CVE-2026-43503) Exposes Systems to Root Access

In June 2026, a critical vulnerability known as DirtyClone (CVE-2026-43503) was discovered in the Linux kernel, allowing local users to escalate privileges to root by exploiting cloned network packets. This flaw, a variant of the earlier DirtyFrag vulnerability, affects multiple Linux distributions, including Debian, Ubuntu, and Fedora. The vulnerability arises from the kernel's mishandling of shared socket-buffer fragments during network packet processing, enabling attackers to manipulate the Linux page cache and gain unauthorized access. ([thehackernews.com](https://thehackernews.com/2026/06/new-dirtyclone-linux-kernel-flaw-lets.html?utm_source=openai)) The emergence of DirtyClone underscores the persistent challenges in securing the Linux kernel against privilege escalation attacks. With the increasing adoption of multi-tenant cloud environments and containerized workloads, the risk of such vulnerabilities being exploited has escalated, highlighting the need for prompt patching and vigilant system monitoring. ([securityweek.com](https://www.securityweek.com/dirtyclone-linux-kernel-vulnerability-leads-to-root-access/?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Massive Crypto Scam Operation Exploits DCloud Uni-App Framework
Impact· HIGH

Massive Crypto Scam Operation Exploits DCloud Uni-App Framework

In June 2026, cybersecurity firm Infoblox uncovered that over 236,000 websites were utilizing investment scam templates built with the DCloud Uni-App framework. These sites facilitated a range of fraudulent activities, including fake cryptocurrency exchanges, phishing schemes, and crypto wallet drainers. The malicious domains spanned multiple continents and languages, indicating a coordinated effort by various threat actors. Notably, the RainbowEx platform, implicated in a Ponzi scheme affecting thousands in Argentina in late 2024, was among the identified domains. ([thehackernews.com](https://thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html?utm_source=openai)) The exploitation of legitimate development frameworks like DCloud Uni-App underscores the evolving tactics of cybercriminals. This incident highlights the critical need for organizations to implement robust security measures, including thorough vetting of third-party tools and continuous monitoring for suspicious activities. ([thehackernews.com](https://thehackernews.com/2026/06/236000-dcloud-uni-app-sites-used-in.html?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Exploiting AI Coding Agents: The New Frontier in Supply Chain Attacks
Impact· HIGH

Exploiting AI Coding Agents: The New Frontier in Supply Chain Attacks

In June 2026, researchers at Mozilla's Zero Day Investigative Network (0DIN) identified a novel supply chain attack targeting AI coding agents. The attack involved a seemingly benign GitHub repository containing standard setup instructions. When an AI coding agent, such as Claude Code, cloned and initialized the repository, it encountered an error message prompting the execution of an initialization command. This command triggered a shell script that retrieved and executed a payload from a DNS TXT record controlled by the attacker, resulting in the establishment of an interactive shell on the developer's machine. This method allowed attackers to gain unauthorized access to sensitive information without any malicious code present in the repository itself. This incident underscores the evolving sophistication of supply chain attacks, particularly those exploiting AI-driven development tools. As AI coding agents become more integrated into software development workflows, they present new vectors for exploitation. Organizations must enhance their security protocols to address these emerging threats, ensuring that AI tools are configured to disclose and verify the full execution chain of setup commands to prevent unauthorized code execution.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Russian Intelligence Services' Phishing Campaigns Targeting Messaging Apps in 2026
Impact· HIGH

Russian Intelligence Services' Phishing Campaigns Targeting Messaging Apps in 2026

In March 2026, the FBI and CISA issued a Public Service Announcement warning of ongoing phishing campaigns by Russian Intelligence Services (RIS) targeting commercial messaging applications (CMAs) such as Signal and WhatsApp. These campaigns aim to compromise individual user accounts by impersonating official support channels and tricking users into sharing verification codes or personal information. High-value targets include U.S. government officials, military personnel, political figures, and journalists. Once access is gained, attackers can view messages, contact lists, and conduct further phishing attacks. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260626?utm_source=openai)) This incident underscores the persistent threat posed by nation-state actors employing social engineering tactics to bypass encryption and gain unauthorized access to sensitive communications. The rise in such targeted phishing campaigns highlights the need for heightened vigilance and robust security practices among users of CMAs.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Cybersecurity Firms Deceived by Fraudulent OpenAI Organization Invitations
Impact· MEDIUM

Cybersecurity Firms Deceived by Fraudulent OpenAI Organization Invitations

In June 2026, cybersecurity firms were targeted by a sophisticated social engineering campaign dubbed 'Poisoned Tenant.' Threat actors created fraudulent OpenAI ChatGPT organizations impersonating legitimate companies and sent authentic-looking invitations to employees, urging them to join these fake tenants. Upon acceptance, employees were granted administrative privileges, potentially exposing sensitive company information. The attackers utilized OpenAI's legitimate notification system, making the invitations appear credible and bypassing standard email security measures. This incident underscores the evolving tactics of cyber adversaries who exploit trusted platforms to execute social engineering attacks. The use of legitimate services to deliver malicious content highlights the need for organizations to enhance their security awareness training and implement robust verification processes for unsolicited invitations, even when they appear to originate from trusted sources.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Polymarket Supply-Chain Attack Results in $3 Million Theft
Impact· HIGH

Polymarket Supply-Chain Attack Results in $3 Million Theft

In June 2026, Polymarket, a leading cryptocurrency-based prediction market platform, suffered a supply-chain attack resulting in the theft of approximately $3 million from its customers. Attackers compromised a third-party vendor, injecting malicious JavaScript into Polymarket's frontend. This script deceived users into approving fraudulent transactions, leading to unauthorized fund transfers. The platform's backend infrastructure remained unaffected, and Polymarket has committed to fully reimbursing the impacted users. This incident underscores the escalating threat of supply-chain attacks targeting financial platforms. As cybercriminals increasingly exploit third-party dependencies to infiltrate systems, organizations must enhance their security measures and conduct thorough audits of their supply chains to mitigate such risks.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
FBI Issues Warning on Russian Hackers Exploiting Signal Backup Recovery Keys
Impact· HIGH

FBI Issues Warning on Russian Hackers Exploiting Signal Backup Recovery Keys

In June 2026, the FBI and CISA issued an updated warning regarding Russian intelligence phishing campaigns targeting Signal users. Attackers impersonated Signal support, sending messages that prompted users to share their Backup Recovery Keys under the guise of preventing data loss. Once obtained, these keys allowed attackers to restore backups, access private messages, and take over accounts. The campaign primarily targeted individuals of high intelligence value, including government officials, military personnel, political figures, journalists, and Ukrainian officials. This incident underscores the evolving tactics of nation-state actors in exploiting legitimate features of secure messaging apps through social engineering. The focus on high-profile individuals highlights the strategic nature of the campaign, emphasizing the need for heightened vigilance and robust security practices among potential targets.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Persistent Cyber Scam Centers in Asia Despite Crackdowns
Impact· CRITICAL

Persistent Cyber Scam Centers in Asia Despite Crackdowns

In June 2026, reports from INTERPOL and Amnesty International highlighted the persistent and escalating issue of cyber scam centers across Asia, particularly in Cambodia, Myanmar, Laos, and the Philippines. Despite high-profile crackdowns and arrests, these operations continue to thrive, generating an estimated $40 billion annually through schemes like romance fraud and investment scams. The resilience of these criminal enterprises is largely attributed to local corruption and collusion with law enforcement, which undermine efforts to dismantle them. ([interpol.int](https://www.interpol.int/News-and-Events/News/2026/New-INTERPOL-report-highlights-escalating-cyber-threats-across-Asia-and-South-Pacific?utm_source=openai)) This situation underscores the urgent need for enhanced international cooperation and robust anti-corruption measures. The continued operation of these scam centers not only results in significant financial losses globally but also involves severe human rights abuses, including human trafficking and forced labor. Addressing this issue is critical to protecting vulnerable populations and maintaining global cybersecurity. ([amnesty.org](https://www.amnesty.org/en/latest/news/2026/06/cambodia-evidence-suggests-scamming-compounds-bypassed-despite-high-profile-crackdown/?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Operation Endgame: A Landmark Blow to Cybercriminal Networks in 2026
Impact· HIGH

Operation Endgame: A Landmark Blow to Cybercriminal Networks in 2026

In June 2026, Europol, in collaboration with international law enforcement agencies and private sector partners, executed Operation Endgame, a coordinated effort targeting the infrastructure supporting the SocGholish, Amadey, and StealC malware networks. This operation led to the dismantling of 326 servers and 142 domains, the recovery of 27 million stolen login credentials, and the seizure of over €41 million in cryptocurrency assets. The SocGholish malware, linked to the Russian cybercriminal group Evil Corp, had compromised nearly 15,000 legitimate websites to distribute malicious software. Amadey and StealC were utilized to gain initial access to systems and exfiltrate sensitive data, respectively. ([europol.europa.eu](https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks?utm_source=openai)) This operation signifies a strategic shift in combating cybercrime by disrupting entire malware ecosystems rather than focusing on individual threats. The success of Operation Endgame underscores the effectiveness of international cooperation and public-private partnerships in addressing large-scale cyber threats. ([europol.europa.eu](https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports