Výsledky hledání

sektor: finance× v celém archivu zrušit filtry

79 karet z 80 položek · strana 1 z 2 CZ · EN/orig

3

StreamRat Android malware spreads through Meta and TikTok ads

A malicious advertising campaign promoting a fake free TV-streaming service reached roughly 570,000 Meta users. The researchers who discovered the campaign found that its streaming-themed ads were aimed at Spanish-speaking users, with most observed victims located in Spain. One Meta campaign ran from June 11 through July 3, 2026, and the same banners were also used to distribute the malware through TikTok. The available data shows the ads’ reach, not the number of downloads or infections, but…

Meta TikTok finance US

tg: varování tg: zneužíváno tp: malware tp: phishing tp: podvod tp: identita

Malwarebytes Labs ·

ASCII smuggling crosses over from AI prompt injection to phishing evasion

In this article What is ASCII smuggling?Writing a practical ASCII-smuggling signatureWhat we observed: ASCII smuggling repurposed for phishingWhat is known and what is newIs there a detection gap?Mitigation and protection guidanceReferencesLearn More Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling. Instead of using these characters to hide instructions from people…

Microsoft finance US

tg: varování tg: zneužíváno tp: phishing tp: identita

Microsoft Security Blog ·

Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-20212, Summary: A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to…

CVSS 9.8 CVE-2026-20212 Cisco telekomunikace energetika finance veřejná správa FI US 2 zdrojů

tg: zneužíváno tg: zranitelnost tp: průmyslové systémy

NCSC-FI · Cisco PSIRT

1

Závažná zranitelnost ohrožuje téměř 22 000 Microsoft Exchange serverů

Microsoft 11. srpna 2026 vydal opravu zranitelnosti CVE-2026-62911 (CVSS 8,0), přesto téměř 22 000 veřejně dostupných Exchange serverů zůstává zranitelných. V Česku Shadowserver eviduje přibližně 300 unikátních IP adres Exchange serverů, které vyhodnocuje jako zranitelné (na jednu či více zranitelností). Zranitelnost postihuje Exchange Server 2016, 2019 a Subscription Edition a může vést až k převzetí uživatelských e-mailových schránek. Exploit je již veřejně dostupný. Verze 2016 a 2019 jsou…

EPSS 0.01 CVSS 8.8 CVE-2026-62911 Microsoft finance veřejná správa CZ NL US 4 zdrojů

tg: zneužíváno tg: zranitelnost

CSIRT.CZ (CZ.NIC) · NCSC-NL · Microsoft Security · Zero Day Initiative

4

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

While monitoring Mirage Kitten activity, we uncovered a previously undocumented malware family that we dubbed NodeRabbit. We identified the first sample on a system in Afghanistan. Further threat hunting revealed two additional, more advanced, variants: one on a system in Egypt and another on a system in Ethiopia. NodeRabbit is a cross-platform remote access trojan (RAT) built with Node.js. It targets Windows, Linux, and macOS. Its operators deliver it through spear-phishing messages on…

Kaspersky finance doprava RU

tg: varování tg: rozbor tp: malware tp: phishing tp: špionáž

Securelist (Kaspersky) ·

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In…

Google Mandiant finance obchod US

tg: varování tg: zneužíváno tg: rozbor tp: malware tp: podvod tp: únik dat tp: AI

Mandiant / Google TI ·

3

3

PCI DSS 4.0.1: Application Requirements You’re Being Assessed On in 2026

Key Takeaways Since March 31, 2025, all 51 former “best practice” requirements in PCI DSS 4.0 have been fully scored. Every 2026 assessment covers them. A large share of the new weight sits in the PCI DSS 4.0.1 application requirements, concentrated in Requirements 6 and 11: inventory of custom applications and APIs, continuous protection of public-facing apps, payment page script management, authenticated scanning, and risk-based prioritization. 6.4.3 and 11.6.1 now require a complete…

Qualys finance US

Qualys ·

Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs

IntroductionDespite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. While stolen credit cards enable rapid, short-term monetization, Social Security numbers (SSNs) represent a far more permanent and dangerous tier within…

Rapid7 finance US

Rapid7 ·

One Adversary, Two Outcomes: The 0.027% Proof

One malware campaign, 11,000 compromised devices, two banks with very different outcomes. At the bank with fused defence, fraud succeeded on just 0.027% of compromised devices; nine times less than the market average. Regulators are taking notice too.

finance SG

Group-IB ·

2

2

ToxicPanda 2.0 can take over your Android phone and banking apps

Researchers have uncovered ToxicPanda 2.0, an Android banking Trojan and remote-access tool designed for account takeover and “on-device fraud.” Not only does ToxicPanda 2.0 have a much larger target list of banks and e-wallets, it has also expanded its capabilities by combining banking overlays, remote access, PIN capture, Android accessibility abuse, and attempted Wireless Debugging automation. Together, those functions can help operators turn a compromised phone into a platform for account…

Malwarebytes finance US

Malwarebytes Labs ·

1

5

NCSC-2026-0312 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Financial Services

Oracle heeft kwetsbaarheden verholpen in diverse Financial Services Enterprise modules. De kwetsbaarheden bevinden zich in Third Party producten, zoals Apache Kafka, Log4j en het Spring Framework, waarvoor eerder door de ontwikkelaars updates zijn uitgebracht. Deze updates zijn nu verwerkt door Oracle in de Financial Services modules die gebruik maken van deze Third Party producten. Een kwaadwillende kan de kwetsbaarheden misbruiken om toegang te krijgen tot gevoelige gegevens, een Denial-of…

Oracle Apache Log4j Spring finance NL

NCSC-NL ·

Multiples vulnérabilités dans Oracle PeopleSoft (19 août 2026)

De multiples vulnérabilités ont été découvertes dans Oracle PeopleSoft. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un déni de service.

EPSS 0.00 CVE-2026-60742 CVE-2026-60821 CVE-2026-60831 CVE-2026-60856 CVE-2026-60873 CVE-2026-60879 CVE-2026-60883 CVE-2026-60884 CVE-2026-60902 CVE-2026-60967 CVE-2026-60975 CVE-2026-61307 CVE-2026-70861 CVE-2026-71092 CVE-2026-71112 Oracle finance FR

CERT-FR – avis ·

2

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive…

CVSS 7.0 Rapid7 Microsoft veřejná správa zdravotnictví finance výroba a průmysl US

Rapid7 ·

Heights Finance data breach: What customers need to know

Heights Finance Holdings’ online data breach notification says an unauthorized party accessed a third-party cloud platform containing customer data, potentially exposing highly sensitive personal, banking, and identity information. Heights Finance is a consumer lender that offers personal installment loans. Reportedly, the company filed a report with Texas regulators mentioning 734,828 affected people, though that figure should not automatically be read as a confirmed nationwide total, since…

Heights Finance finance US

Malwarebytes Labs ·

4

Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

Operation ASTERIX overviewRapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the campaign's development; recovered…

Crypto.com Binance Ledger Kraken finance US

Rapid7 ·

Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology

Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa.Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and connected operations. But more technology does not automatically create stronger security operations; many security teams are not short on data, but rather on time, context, and specialist capacity.As environments expand, the challenge is no longer finding another…

Rapid7 StarLink veřejná správa finance US

Rapid7 ·

2

Nový malware zneužívá Android telefony k NFC platebním podvodům

Nový malware s názvem WindRelay v kombinaci s trojanem SpyNote umožňuje zneužít zařízení s Androidem k bezkontaktním platebním podvodům. Útočníci oběť pomocí phishingu, SMS nebo telefonátu přesvědčí k instalaci škodlivé aplikace a následně k přiložení platební karty k telefonu, například pod záminkou ověření identity či změny PINu. Malware zachycenou NFC komunikaci v reálném čase přenáší do zařízení útočníka, který tak může kartu využít k platbám nebo výběrům hotovosti. Mezi listopadem 2025 a…

finance CZ

CSIRT.CZ (CZ.NIC) ·

3

Curiouser and Curiouser

Welcome to this week’s edition of the Threat Source newsletter. “Experiment is the mother of knowledge.” ― Madeleine L'Engle, A Wrinkle in Time“Don't slide down the rabbit hole. The way down is a breeze, but climbing back's a battle.” ― Kate Morton, The Clockmaker's Daughter Hacker Summer Camp has come and gone, which means it’s time for you to start planning next year’s trip. I’m surely going to recap Camp Season, right? Nope.One of the things that I’ve really enjoyed lately is a segment on…

Microsoft Cisco Signal Shopify finance obchod US

Cisco Talos ·

New Android malware lets criminals use your bank card in real time

Researchers at Group-IB have discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time to attackers. They dubbed it “WindRelay.” NFC (Near Field Communication) is wireless technology that allows devices such as smartphones, payment cards, and payment terminals to communicate when they’re very close together. So, instead of stealing your physical bank card, the attackers capture NFC activity on an infected mobile phone and relay it in…

Malwarebytes finance US

Malwarebytes Labs ·

1

1

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

OverviewRapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month.Our…

KEV ✓ EPSS 0.40 CVSS 8.1 CVE-2026-55040 CVE-2026-63520 Microsoft veřejná správa finance US

Rapid7 ·

2

10th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City and others, has suffered a cyberattack that forced some operations onto manual processes. The authority claims it has contained the intrusion, but degraded systems caused delays while affected services were restored. Ryde, an electric scooter operator in…

EPSS 0.31 CVSS 10.0 CVE-2026-12537 CVE-2026-54316 CVE-2026-64638 Cloudflare Google Anthropic Cisco finance obchod obrana IL

Check Point Research ·

#StopRansomware: Gunra Ransomware

Advisory at a Glance Title #StopRansomware: Gunra Ransomware Original Publication August 10, 2026 Executive Summary Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom…

KEV ✓ EPSS 0.98 CVE-2024-55591 CVE-2025-24472 veřejná správa zdravotnictví finance energetika US

CISA Advisories ·

1

4

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

Written by: Tyler McLellan, Austin Larsen Introduction Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. UNC6671 continues to rely on voice…

Microsoft Okta finance US

Mandiant / Google TI ·

1

1

3rd August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported that drinking water safety was not affected. While the attack was not officially attributed, federal…

KEV ✓ EPSS 0.88 CVSS 9.8 CVE-2026-20316 CVE-2026-42897 CVE-2026-59309 CVE-2026-59310 CVE-2026-59726 CVE-2026-63077 CVE-2026-66066 Check Point Cisco Broadcom Microsoft vodárenství finance zdravotnictví telekomunikace IL

Check Point Research ·

1

Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the…

KEV ✓ EPSS 0.92 CVE-2026-20127 CVE-2026-20182 CVE-2026-20245 Cisco telekomunikace energetika doprava finance obchod zdravotnictví US 2 zdrojů

Cisco PSIRT · Mandiant / Google TI

1

20th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, employee details, and other sensitive information submitted while requesting technical assistance. Jscrambler, a…

KEV ✓ EPSS 0.97 CVE-2026-15409 CVE-2026-15410 CVE-2026-56155 CVE-2026-56164 CVE-2026-60137 CVE-2026-63030 Microsoft WordPress SonicWall výroba a průmysl finance IL

Check Point Research ·

1

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. Talos has discovered that the actor in this campaign delivers a Python-based remote access tool (RAT) that we track as “Starland RAT” and a command-and-control (C2) memory implant known as the “WLDR agent.” The WLDR agent is a sophisticated PowerShell-based C2 memory implant that…

Cisco finance US

Cisco Talos ·

1

3

13th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximately 7 million people. Attackers targeted an employee and used compromised credentials to access company systems, stealing names, contact information, driver’s license numbers, insurance policy and account data, vehicle information, and claims details. Latvia’s state…

KEV ✓ EPSS 1.00 CVE-2025-3248 CVE-2026-11405 CVE-2026-53359 Tenda Google Opera U-Boot školství finance IL

Check Point Research ·

1

1

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

A Mexican banking fraud operation we're tracking as REF6045 doesn't run on autopilot. A human operator is behind the wheel, monitoring infected machines and deciding what happens next. Victims are infected through fake CAPTCHA pages that trick them into running a single command, which installs SCMBANKER, a PowerShell toolkit with components dating back to at least October 2025. Once installed, the operator can see when a victim opens a banking session, lock the screen behind a fake bank warning…

Elastic Security Microsoft finance US

Elastic Security ·

1

6th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 6th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES River Bank & Trust, a US financial institution, has experienced a ransomware incident after an unauthorized actor accessed the network of parent company River Financial Corporation on June 16. The bank found ransomware on portions of its server environment and is assessing whether personal data was accessed or exfiltrated. Indra Group, a Spanish…

KEV ✓ EPSS 1.00 CVSS 9.6 CVE-2024-1212 CVE-2026-46242 CVE-2026-46817 CVE-2026-8037 CVE-2026-8451 Oracle Citrix Progress Check Point finance obrana výroba a průmysl energetika IL

Check Point Research ·

1

22nd June – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Texas Parks and Wildlife Department has been affected by a third-party data breach involving its license system vendor. The incident exposed driver’s license information, passport numbers, emails, phone numbers, and residential addresses for 3,087,721 hunting and fishing license customers. Social Security numbers and payment data were not affected.…

KEV ✓ EPSS 0.96 CVE-2026-20245 CVE-2026-33017 CVE-2026-34908 CVE-2026-34909 CVE-2026-34910 CVE-2026-41947 CVE-2026-41948 CVE-2026-55255 Cisco Ubiquiti Dify Langflow veřejná správa zdravotnictví finance IL

Check Point Research ·

2

GitBait: Phishing dirigido al sector financiero mexicano

Se ha descubierto una infraestructura de phishing modular dirigida a múltiples bancos mexicanos, que abusa de GitHub Pages, emplea scripts ofuscados y centraliza la exfiltración de credenciales mediante la API de SheetBest, lo que indica una operación de phishing escalable y persistente de múltiples marcas.

finance SG

Group-IB ·

1

GitBait: Phishing the Mexican Financial Sector

A modular phishing infrastructure targeting multiple Mexican banks has been uncovered, abusing GitHub-hosted Pages, employing obfuscated scripts, and featuring a centralized credential exfiltration via SheetBest API, indicating a scalable and persistent multi-brand phishing operation.

GitHub finance SG

Group-IB ·