← All Intelligence

Finance Industry Intelligence

21 briefings11 vulnerability reports

Financial services are among the most targeted sectors in cybersecurity due to the direct monetary value of successful attacks. Banks, insurance companies, investment firms, and payment processors face sophisticated threats including banking trojans, BEC campaigns, and nation-state espionage targeting financial intelligence. defend.network monitors threats affecting the financial sector with a focus on regulatory implications and fraud prevention.

21
briefings
1
critical
10
high
22%
of all briefings

Threat Briefings

2026-06-19

NGINX RCE, Windows crypto-stealer, Salesforce breaches, INC ransomware surge

F5 patched critical NGINX RCE (CVE-2026-42530). Microsoft disclosed active Windows clipboard-stealing malware spreading via USB worms since Feb 2026. INC ransomware claims 830+ victims; Salesforce data stolen through Klue OAuth breach by Icarus group.

2026-06-17

Fortinet actively exploited; Rokarolla targets 217 banking apps; Google Vertex AI flaw

Fortinet FortiSandbox faces active in-the-wild exploitation of three CVEs. Android banking trojan Rokarolla targets 217 financial apps with 137 remote commands. Google Vertex AI SDK bucket-squatting flaw enables unauthorized model hijacking.

2026-06-15

Critical: Splunk RCE, Arch Linux supply-chain hijack, phishing-as-a-service dismantled

FBI dismantles Outsider Enterprise phishing network; Arch Linux AUR compromised with 400+ malicious packages deploying credential stealer and rootkit; Splunk Enterprise CVSS-9.8 RCE patched.

2026-06-09

Critical Check Point VPN and Linux kernel flaws under active exploitation; NSO spyware defies court order

Check Point VPN zero-day (CVSS 9.3) actively exploited since early May; Linux kernel use-after-free now has public exploit; NSO Group continues WhatsApp phishing despite federal court injunction.

2026-05-30

ChatGPT malware abuse, Marimo CVE-2026-39987 LLM exploitation, Russian infrastructure arrests

ChatGPT share links abused for malware delivery; Marimo CVE-2026-39987 exploited with LLM agents for post-compromise activity; Dutch authorities seize 800 Russian-linked servers and arrest hosting executives.

2026-05-26

Ghost CMS, Microsoft 365 phishing, and supply-chain malware in active exploitation

Ghost CMS SQL injection actively exploited across 700+ sites; Microsoft 365 phishing service Kali365 bypasses MFA; multi-ecosystem supply-chain attacks deliver credential stealers.

2026-05-21

GitHub breach, SonicWall VPN MFA bypass, Drupal critical flaw demand patching

GitHub suffered breach of 3,800+ internal repos via TeamPCP. Microsoft disrupted malware-signing operation. SonicWall VPN and Drupal require urgent patching.

2026-05-10

Canvas extortion attack; JDownloader, Hugging Face & Trellix hit

Canvas learning platform compromised in extortion attack affecting hundreds of schools; supply-chain attacks hit JDownloader, Hugging Face, and Trellix; banking trojan TCLBANKER targets 59 financial platforms; critical ICS/OT breaches at water treatment plants.

2026-05-09

TCLBANKER trojan; Canvas breach hits education; Ivanti zero-day

Critical threats including TCLBANKER banking trojan, Canvas platform breach disrupting nationwide education, and active Ivanti zero-day exploitation require immediate response across financial, education, and government sectors.

2026-05-08

Palo Alto & Ivanti EPMM RCE exploited; PCPJack worm hits cloud

Critical vulnerabilities in Palo Alto Networks and Ivanti EPMM under active exploitation. PCPJack credential stealer worm targeting cloud infrastructure. Russian state actors harvesting Office tokens via router compromise.

2026-05-05

cPanel & MOVEit exploited; RMM phishing hits 80+ organizations

Critical vulnerabilities in cPanel and MOVEit, widespread RMM-based phishing compromising 80+ organizations, and supply-chain malware in PyTorch Lightning demand immediate patching and credential rotation.

2026-04-30

SAP npm compromise; cPanel auth bypass; DPRK AI-assisted malware

Critical supply-chain attacks on SAP npm packages and North Korean AI-assisted malware, combined with cPanel authentication bypass and state-sponsored credential harvesting, create immediate existential threats to enterprise infrastructure and critical systems.

2026-04-29

GitHub, Hugging Face RCE; VECT 2.0 ransomware; BlueNoroff deepfakes

Critical RCE vulnerabilities in GitHub and Hugging Face, destructive VECT 2.0 ransomware, Russian token harvesting, and BlueNoroff deepfake attacks demand immediate defensive action.

2026-04-18

Microsoft Defender & ActiveMQ zero-days under exploitation

Critical zero-day exploits in Microsoft Defender and Apache ActiveMQ, Russian state-sponsored token harvesting, and sophisticated ransomware evasion techniques pose immediate threats requiring emergency patching and threat hunting.

2026-04-10

Adobe Reader zero-day exploited; APT28 router credential theft

Critical zero-day in Adobe Reader, state-sponsored credential theft via routers, and major supply-chain compromises demand immediate action across all organizations.

2026-04-06

FortiClient RCE exploited; DPRK & Chinese APTs hit EU institutions

State-sponsored DPRK and China-linked APT campaigns, critical FortiClient RCE exploit, and cascading supply chain attacks affecting European institutions and npm ecosystem.

2026-04-03

Next.js, Cisco IMC, Progress ShareFile exploited; $280M DPRK theft

Critical vulnerabilities in Next.js, Cisco IMC, and Progress ShareFile actively exploited; $280M cryptocurrency theft attributed to North Korea; credential harvesting impacts 766 hosts

2026-03-31

Citrix exploited; Axios npm RAT supply-chain; OpenAI data theft

Critical Citrix vulnerability actively exploited, Axios npm supply chain attack spreading RAT, OpenAI vulnerabilities enabling data theft, state-sponsored APT operations escalating against telecom and healthcare sectors

2026-03-22

Oracle RCE exploited; Iran wiper hits healthcare; Trivy worm spreads

Critical Oracle RCE, Russian state-sponsored phishing, Trivy supply-chain worm, and Iran-backed healthcare wiper attacks demand immediate emergency response and patching across enterprise infrastructure.

2026-03-21

Oracle Identity Manager, Langflow exploited; Trivy supply-chain worm

Critical vulnerabilities in Oracle Identity Manager and Langflow actively exploited; Trivy supply chain attack escalates with CanisterWorm across 47 npm packages; Russian intelligence phishing campaigns compromise thousands.

2026-03-20

VMware ESXi ransomware exploit; BlackSuit healthcare breach

Critical VMware ESXi vulnerability actively exploited by ransomware operators. BlackSuit group claims major U.S. healthcare breach. CISA adds 3 new CVEs. Microsoft patches Windows kernel zero-day. New PhishRelay kit enables real-time MFA bypass.

Vulnerability Reports

June 15 – 21

Vulnerability Report – Week 3 of June 2026

This week's verified vulnerability coverage is limited to one actively exploited CVE: CVE-2026-20253 affecting Splunk Enterprise, which CISA has added to its Known Exploited Vulnerabilities catalog wi

11 critical 9 high
June 1 – 7

Vulnerability Report – Week 1 of June 2026

Three verified CVEs dominated this week's reporting: one actively exploited Linux kernel vulnerability (CVE-2022-0492) now in CISA's Known Exploited Vulnerabilities catalog, one proof-of-concept relea

8 critical 6 high
May 18 – 24

Vulnerability Report – Week 3 of May 2026

This week presents an exceptionally high-risk threat landscape with multiple critical vulnerabilities under active exploitation across infrastructure, enterprise, and open-source ecosystems. Immediate

0 critical 2 high
May 11 – 17

Vulnerability Report – Week 2 of May 2026

This week marks a significant surge in actively exploited vulnerabilities, with three critical flaws requiring immediate patching across IT infrastructure and OT systems. The Ollama out-of-bounds read

2 critical 2 high
May 4 – 10

Vulnerability Report – Week 1 of May 2026

This week presents an exceptionally high-risk threat landscape dominated by active exploitation campaigns and critical infrastructure vulnerabilities. Federal agencies face an immediate Sunday deadlin

0 critical 0 high
April 27 – May 3

Vulnerability Report – Week 4 of April 2026

This week presents elevated risk from actively exploited vulnerabilities across network infrastructure, IoT devices, and enterprise software. Immediate patching is required for Cisco Firepower/ASA dev

3 critical 7 high
April 20 – 26

Vulnerability Report – Week 3 of April 2026

This week presents elevated risk across OT/ICS sectors with multiple critical RCE vulnerabilities in industrial control systems and emerging threats to cloud infrastructure. Active exploitation of Mic

5 critical 8 high
April 13 – 19

Vulnerability Report – Week 2 of April 2026

This week presents an elevated threat landscape dominated by actively exploited critical vulnerabilities in both IT and OT environments. Iranian-affiliated threat actors are actively targeting US crit

0 critical 0 high
April 6 – 12

Vulnerability Report – Week 1 of April 2026

This week presents elevated risk with five critical vulnerabilities actively exploited in the wild, including FortiClient EMS and video conferencing systems requiring immediate patching. Organizations

0 critical 0 high
March 30 – April 5

Vulnerability Report – Week 5 of March 2026

This week reflects sustained critical threats across OT/ICS and enterprise systems with multiple actively exploited vulnerabilities. F5 BIG-IP APM (CVE-2025-53521) and Citrix NetScaler (CVE-2026-3055)

0 critical 0 high
March 14–20

Vulnerability Report – Week 3 of March 2026

This week demands immediate attention. Two actively exploited vulnerabilities (VMware ESXi and FortiOS) require emergency patching. Organizations using Windows Server should prioritize the kernel priv

0 critical 0 high

Get the Daily Briefing in Your Inbox

Subscribe free and never miss a threat briefing.