Financial services are among the most targeted sectors in cybersecurity due to the direct monetary value of successful attacks. Banks, insurance companies, investment firms, and payment processors face sophisticated threats including banking trojans, BEC campaigns, and nation-state espionage targeting financial intelligence. defend.network monitors threats affecting the financial sector with a focus on regulatory implications and fraud prevention.
Mantax Otax and Gigabud banking trojans spread across Android, Russian-speaking actors deployed hundreds of AI agents to exploit PaperCut flaws on 395 organizations
Microsoft released 974 security patches including two actively exploited zero-days. AI-driven credential harvesting compromised thousands of accounts in six hours. F5 BIG-IP devices are being breached to deploy Linux rootkits.
PEEP toolkit turns Chrome and Edge into post-compromise backdoors; Magento StyleSmuggler zero-day actively exploited to deploy Linux backdoors; BigBear phishing framework bypassed MFA at 258 organizations and stole 5,000+ Microsoft 365 credentials.
Cisco patches critical Nexus 9000 unauthenticated RCE affecting 10 Silicon One switches; HPE releases 8 CVEs in ArubaOS-CX. Coder's Cloudflare infrastructure hijacked to distribute malicious Terraform modules. 153M+ driver licenses offered on dark web.
JFrog Artifactory CVE-2026-82329 (CVSS 9.8) exploited to mint admin tokens; Langflow CVE-2026-0768 RCE active for API key theft. Two alleged TeamPCP supply-chain attackers arrested in Australia. iOS spyware campaign harvesting wallet seeds.
Infostealer malware targets Anthropic and Microsoft users; Aurora ransomware gang deploys Cursor AI; North Korean threat actors expand beyond IT into healthcare and sales.
Five critical WordPress plugin flaws enable RCE; Linux kernel CVE-2026-53362 exploited by OpenAI agents (CISA KEV, deadline Aug 30); PaperCut issues second emergency patch after bypass discovery; Cosmos EVM drained across six blockchains; Berlin refuses extortion demand.
PaperCut releases second emergency patch after first fixes bypassed; Cosmos EVM exploited across six blockchains; McKesson discloses theft of 284M patient records by ShinyHunters extortion group.
Mirage2FA phishing toolkit has compromised 4,500 US/EU organizations via Microsoft 365 spoofing; Oracle Weblogic Server vulnerability (CVE-2026-21962) added to CISA KEV with 3-day patch deadline; NVIDIA NemoClaw vulnerable to unauthenticated model poisoning.
Red Hat patches critical Keycloak account-takeover flaw; Microsoft releases 398 patches including one under active exploitation; WordlistLoader and SynkLoader malware families accelerate ransomware-adjacent payload delivery via ClickFix.
Microsoft released 398 security patches including one actively exploited flaw; Zimbra command injection (CVE-2026-73570) in CISA KEV with Aug 24 federal deadline; Android vehicle head units infected via supply-chain attack distributing proxy botnet malware.
Android car head units infected via malware-laden firmware updates; 9,300+ AWS keys remain active; Snowflake extortionist pleads guilty after compromising 165+ organizations.
GitLab patched critical GraphQL flaw; Forminator WordPress plugin RCE affects 600K+ sites; threat actor claims 3.6M Azure account records stolen from Fortune 500 companies.
Nearly 800 malicious npm packages deliver cross-platform RAT/infostealer; Metabase SQL injection exploited at Framework and Tally; UNC6671 extortion group rebrands across Redact, Pink, Helix, Falcon operations after millions in vishing revenue.
Malware on Windows machines can hijack Google-synced passkeys without verification. Russian APT29 is actively compromising hotel Wi-Fi globally to steal Microsoft 365 credentials. N-able N-central RMM faces active CVE-2026-18577 exploitation with a second bypass vector discovered post-patch.
Coldcard hardware wallet firmware flaw allowed theft of 1,082.65 BTC (~$70.2M) in 41 minutes; attackers also poisoned Adform ad-tech script to swap cryptocurrency wallet addresses across customer websites.
Adobe Campaign Classic patched critical CVSS 10.0 RCE flaw. Coldcard hardware wallet firmware flaw linked to $70.2M Bitcoin theft. Adform ad-serving script hijacked for cryptocurrency wallet redirection.
Microsoft patched record 570 vulnerabilities; Check Point SmartConsole and SharePoint RCE added to CISA KEV with July 25 federal deadline; BlueNoroff phishing kit profiles crypto wallets before malware delivery.
FakeGit campaign weaponizes 7,600 GitHub repositories to distribute SmartLoader malware. WordPress sites actively exploited via CVE-2026-60137/63030 chain within 72 hours of disclosure. SonicWall SMA1000 zero-days (CVE-2026-15409/15410) used in targeted attacks; Estée Lauder breach linked to Oracle E-Business flaw.
Microsoft patches record 622 flaws including two zero-days in Active Directory and SharePoint under active attack. SonicWall confirms exploitation of SMA1000 zero-days. GitHub supply-chain attack spreads 300 fake repositories with infostealer malware.
jscrambler npm 8.14.0 compromised with Rust infostealer, Zimbra XSS flaw enables code execution
Progress Software orders immediate shutdown of ShareFile Storage Zone Controllers; Injective Labs GitHub compromise distributes crypto-stealing malware; six new U-Boot bootloader vulnerabilities discovered in IoT and data-center devices.
GitHub Agentic Workflows leak private repo data via public issues; Gitea CVE-2026-20896 authentication bypass actively exploited; RedWing Android malware rented as fraud service on Telegram.
Oracle PeopleSoft zero-day exploited at Nissan and NAIC; malicious Chrome extension intercepted searches and address bar input; Mustang Panda uses Zoho WorkDrive in Indian government campaigns.
ShapedPlugin WordPress Pro plugins backdoored via build-pipeline compromise, Dify AI platform has four cross-tenant data-exposure flaws, immediate deployment required.
F5 patched critical NGINX RCE (CVE-2026-42530). Microsoft disclosed active Windows clipboard-stealing malware spreading via USB worms since Feb 2026. INC ransomware claims 830+ victims; Salesforce data stolen through Klue OAuth breach by Icarus group.
Fortinet FortiSandbox faces active in-the-wild exploitation of three CVEs. Android banking trojan Rokarolla targets 217 financial apps with 137 remote commands. Google Vertex AI SDK bucket-squatting flaw enables unauthorized model hijacking.
FBI dismantles Outsider Enterprise phishing network; Arch Linux AUR compromised with 400+ malicious packages deploying credential stealer and rootkit; Splunk Enterprise CVSS-9.8 RCE patched.
Check Point VPN zero-day (CVSS 9.3) actively exploited since early May; Linux kernel use-after-free now has public exploit; NSO Group continues WhatsApp phishing despite federal court injunction.
ChatGPT share links abused for malware delivery; Marimo CVE-2026-39987 exploited with LLM agents for post-compromise activity; Dutch authorities seize 800 Russian-linked servers and arrest hosting executives.
Ghost CMS SQL injection actively exploited across 700+ sites; Microsoft 365 phishing service Kali365 bypasses MFA; multi-ecosystem supply-chain attacks deliver credential stealers.
GitHub suffered breach of 3,800+ internal repos via TeamPCP. Microsoft disrupted malware-signing operation. SonicWall VPN and Drupal require urgent patching.
Canvas learning platform compromised in extortion attack affecting hundreds of schools; supply-chain attacks hit JDownloader, Hugging Face, and Trellix; banking trojan TCLBANKER targets 59 financial platforms; critical ICS/OT breaches at water treatment plants.
Critical threats including TCLBANKER banking trojan, Canvas platform breach disrupting nationwide education, and active Ivanti zero-day exploitation require immediate response across financial, education, and government sectors.
Critical vulnerabilities in Palo Alto Networks and Ivanti EPMM under active exploitation. PCPJack credential stealer worm targeting cloud infrastructure. Russian state actors harvesting Office tokens via router compromise.
Critical vulnerabilities in cPanel and MOVEit, widespread RMM-based phishing compromising 80+ organizations, and supply-chain malware in PyTorch Lightning demand immediate patching and credential rotation.
Critical supply-chain attacks on SAP npm packages and North Korean AI-assisted malware, combined with cPanel authentication bypass and state-sponsored credential harvesting, create immediate existential threats to enterprise infrastructure and critical systems.
Critical RCE vulnerabilities in GitHub and Hugging Face, destructive VECT 2.0 ransomware, Russian token harvesting, and BlueNoroff deepfake attacks demand immediate defensive action.
Critical zero-day exploits in Microsoft Defender and Apache ActiveMQ, Russian state-sponsored token harvesting, and sophisticated ransomware evasion techniques pose immediate threats requiring emergency patching and threat hunting.
Critical zero-day in Adobe Reader, state-sponsored credential theft via routers, and major supply-chain compromises demand immediate action across all organizations.
State-sponsored DPRK and China-linked APT campaigns, critical FortiClient RCE exploit, and cascading supply chain attacks affecting European institutions and npm ecosystem.
Critical vulnerabilities in Next.js, Cisco IMC, and Progress ShareFile actively exploited; $280M cryptocurrency theft attributed to North Korea; credential harvesting impacts 766 hosts
Critical Citrix vulnerability actively exploited, Axios npm supply chain attack spreading RAT, OpenAI vulnerabilities enabling data theft, state-sponsored APT operations escalating against telecom and healthcare sectors
Critical Oracle RCE, Russian state-sponsored phishing, Trivy supply-chain worm, and Iran-backed healthcare wiper attacks demand immediate emergency response and patching across enterprise infrastructure.
Critical vulnerabilities in Oracle Identity Manager and Langflow actively exploited; Trivy supply chain attack escalates with CanisterWorm across 47 npm packages; Russian intelligence phishing campaigns compromise thousands.
Critical VMware ESXi vulnerability actively exploited by ransomware operators. BlackSuit group claims major U.S. healthcare breach. CISA adds 3 new CVEs. Microsoft patches Windows kernel zero-day. New PhishRelay kit enables real-time MFA bypass.
Three critical vulnerabilities require immediate attention this week. CVE-2026-55040 (Microsoft SharePoint) and CVE-2026-59310 (VMware vCenter) are confirmed under active exploitation following PoC re
CVE-2026-8037 in Progress Kemp LoadMaster represents a critical command injection flaw with 792+ reported exploit attempts. Organizations should prioritize patching known exploited vulnerabilities and
Three verified CVEs dominated this week's reporting: one actively exploited Linux kernel vulnerability (CVE-2022-0492) now in CISA's Known Exploited Vulnerabilities catalog, one proof-of-concept relea
This week presents an exceptionally high-risk threat landscape with multiple critical vulnerabilities under active exploitation across infrastructure, enterprise, and open-source ecosystems. Immediate
This week marks a significant surge in actively exploited vulnerabilities, with three critical flaws requiring immediate patching across IT infrastructure and OT systems. The Ollama out-of-bounds read
This week presents an exceptionally high-risk threat landscape dominated by active exploitation campaigns and critical infrastructure vulnerabilities. Federal agencies face an immediate Sunday deadlin
This week presents elevated risk from actively exploited vulnerabilities across network infrastructure, IoT devices, and enterprise software. Immediate patching is required for Cisco Firepower/ASA dev
This week presents elevated risk across OT/ICS sectors with multiple critical RCE vulnerabilities in industrial control systems and emerging threats to cloud infrastructure. Active exploitation of Mic
This week presents an elevated threat landscape dominated by actively exploited critical vulnerabilities in both IT and OT environments. Iranian-affiliated threat actors are actively targeting US crit
This week presents elevated risk with five critical vulnerabilities actively exploited in the wild, including FortiClient EMS and video conferencing systems requiring immediate patching. Organizations
This week reflects sustained critical threats across OT/ICS and enterprise systems with multiple actively exploited vulnerabilities. F5 BIG-IP APM (CVE-2025-53521) and Citrix NetScaler (CVE-2026-3055)
This week demands immediate attention. Two actively exploited vulnerabilities (VMware ESXi and FortiOS) require emergency patching. Organizations using Windows Server should prioritize the kernel priv
Subscribe free and never miss a threat briefing.