Výsledky hledání

sektor: finance× v celém archivu zrušit filtry

104 karet z 105 položek · strana 2 z 2 CZ · EN/orig

4

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

Written by: Tyler McLellan, Austin Larsen Introduction Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. UNC6671 continues to rely on voice…

Microsoft Okta finance US

· Mandiant / Google TI · UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

1

1

3rd August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported that drinking water safety was not affected. While the attack was not officially attributed, federal…

KEV ✓ · ransomware EPSS 0.87 CVSS 9.8 CVE-2026-20316 CVE-2026-42897 CVE-2026-59309 CVE-2026-59310 CVE-2026-59726 CVE-2026-63077 CVE-2026-66066 Cisco Broadcom JetBrains Microsoft vodárenství finance zdravotnictví telekomunikace IL

tg: incident tg: zranitelnost tg: přehled tp: phishing tp: únik dat tp: AI tp: průmyslové systémy

· Check Point Research · 3rd August – Threat Intelligence Report

1

Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security

Canada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance.Key takeaways:Bill C-8 introduces stringent new cyber incident reporting requirements and heavy financial penalties for critical infrastructure operators. Eliminating network blind spots with a hybrid IT/OT discovery approach, including Safe Active…

Tenable telekomunikace energetika doprava finance US

tg: regulace tg: návod tg: propagace tp: průmyslové systémy

· Tenable Research · Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security

1

SPOJENO PŘES CVE Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the…

KEV ✓ EPSS 0.92 CVE-2026-20127 CVE-2026-20182 CVE-2026-20245 Cisco telekomunikace energetika doprava finance obchod zdravotnictví US

· Cisco PSIRT · Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability · Mandiant / Google TI · Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

1

20th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, employee details, and other sensitive information submitted while requesting technical assistance. Jscrambler, a…

KEV ✓ · ransomware EPSS 0.97 CVE-2026-15409 CVE-2026-15410 CVE-2026-56155 CVE-2026-56164 CVE-2026-60137 CVE-2026-63030 Microsoft WordPress SonicWall výroba a průmysl finance IL

· Check Point Research · 20th July – Threat Intelligence Report

1

3

13th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximately 7 million people. Attackers targeted an employee and used compromised credentials to access company systems, stealing names, contact information, driver’s license numbers, insurance policy and account data, vehicle information, and claims details. Latvia’s state…

KEV ✓ · ransomware EPSS 1.00 CVE-2025-3248 CVE-2026-11405 CVE-2026-53359 Tenda Google Opera U-Boot školství finance IL

· Check Point Research · 13th July – Threat Intelligence Report

1

Compromised Injective SDK npm Package Exfiltrates Cryptocurrency Wallet Keys (Campaign)

A malicious version of the @injectivelabs/sdk-ts npm package (version 1.20.21) was briefly published to the official Injective Labs npm namespace after a contributor account was compromised. The package contained credential-stealing functionality that silently exfiltrated cryp...

Injective Labs finance US

· Wiz Research · Compromised Injective SDK npm Package Exfiltrates Cryptocurrency Wallet Keys (Campaign)

2

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

A Mexican banking fraud operation we're tracking as REF6045 doesn't run on autopilot. A human operator is behind the wheel, monitoring infected machines and deciding what happens next. Victims are infected through fake CAPTCHA pages that trick them into running a single command, which installs SCMBANKER, a PowerShell toolkit with components dating back to at least October 2025. Once installed, the operator can see when a victim opens a banking session, lock the screen behind a fake bank warning…

finance telekomunikace US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Elastic Security · ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

A Mexican banking fraud operation we're tracking as REF6045 doesn't run on autopilot. A human operator is behind the wheel, monitoring infected machines and deciding what happens next. Victims are infected through fake CAPTCHA pages that trick them into running a single command, which installs SCMBANKER, a PowerShell toolkit with components dating back to at least October 2025. Once installed, the operator can see when a victim opens a banking session, lock the screen behind a fake bank warning…

finance telekomunikace US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Elastic Security · ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

1

22nd June – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Texas Parks and Wildlife Department has been affected by a third-party data breach involving its license system vendor. The incident exposed driver’s license information, passport numbers, emails, phone numbers, and residential addresses for 3,087,721 hunting and fishing license customers. Social Security numbers and payment data were not affected.…

KEV ✓ EPSS 0.96 CVE-2026-20245 CVE-2026-33017 CVE-2026-34908 CVE-2026-34909 CVE-2026-34910 CVE-2026-41947 CVE-2026-41948 CVE-2026-55255 Cisco Ubiquiti Dify Langflow veřejná správa zdravotnictví finance IL

· Check Point Research · 22nd June – Threat Intelligence Report

2

1

1

SilabRAT, What’s Your Power?

SilabRAT (aka SnappyClient) is an advanced Remote Access Trojan (RAT) sold as a Malware-as-a-Service (MaaS) on Darkweb forums. Developed by the threat actor "o1oo1," SilabRAT is heavily focused on financial gain through credential theft. It offers stability and is capable of bypassing existing security measures.

finance SG

· Group-IB · SilabRAT, What’s Your Power?

1

1

Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in the United States. UNC3753 leverages voice phishing (vishing) and social engineering deception…

Google Microsoft Zoom AnyDesk finance obrana US

· Mandiant / Google TI · Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

1

2

1

1

1

Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America

TrendAI™ Research has identified two emerging threat campaigns—SHADOW-AETHER-040 and SHADOW-AETHER-064—that use agentic AI to drive intrusion operations against government and financial organizations in Latin America, marking these among the first cases we have observed of AI agents executing attacks from initial access to data exfiltration.

veřejná správa finance JP

tg: varování tg: rozbor tp: únik dat tp: AI tp: špionáž

· Trend Micro · Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America

1

TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook

Elastic Security Labs identified a new Brazilian banking trojan that we are tracking as TCLBANKER, a malware family we assess is a major update of the MAVERICK/SORVEPOTEL family. The campaign, tracked as REF3076, features a loader with robust anti-analysis capabilities that deploys two embedded .NET Reactor-protected modules: a full-featured banking trojan and a worm module for self-propagation. The banking trojan monitors the victim's browser address bar via UI Automation, targeting 59…

Logitech finance US

tg: varování tg: rozbor tp: malware tp: podvod

· Elastic Security · TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook

1

1

1

Phantom in the vault: Obsidian abused to deliver PhantomPulse RAT

A follow-up publication will provide a deeper technical analysis of PHANTOMPULSE itself, covering its injection engines, persistence internals, and C2 protocol in greater detail. Preamble Elastic Security Labs has identified a novel social engineering campaign that abuses the popular note-taking application, Obsidian, as an initial access vector. The campaign, which we track as REF6598, targets individuals in the financial and cryptocurrency sectors through elaborate social engineering on…

Obsidian Shell Commands Hider finance US

tg: varování tg: rozbor tp: malware tp: phishing

· Elastic Security · Phantom in the vault: Obsidian abused to deliver PhantomPulse RAT

2

O365 Device Code Phishing Campaign using EvilTokens and Abusing Railway Platform (Campaign)

A phishing campaign has been reported leveraging the EvilTokens Phishing-as-a-Service platform to target O365 users. The attackers use device code phishing to bypass Multi-Factor Authentication (MFA), and they also utilize Railway to host their malicious infrastructure. The ca...

finance veřejná správa US

· Wiz Research · O365 Device Code Phishing Campaign using EvilTokens and Abusing Railway Platform (Campaign)

Stolen SaaS Integration Tokens Enable Data Theft Across Snowflake Environments (Campaign)

The attack originated reportedly from a security incident affecting Anodot, a SaaS analytics and anomaly detection platform that integrates with multiple cloud services (e.g., Snowflake, S3, and streaming pipelines). Threat actors reportedly obtained authentication tokens asso...

Anodot Snowflake finance US

· Wiz Research · Stolen SaaS Integration Tokens Enable Data Theft Across Snowflake Environments (Campaign)

1

Hooking the Archipelago: Dissecting a Phishing Campaign Targeting Philippine Banking Users

Group-IB researchers uncover an ongoing phishing campaign targeting major banks in the Philippines. This blog details how threat actors abuse trusted and legitimate platforms to deceive users and evade detection. It highlights a significant threat escalation with the successful hijacking of a legitimate domain to host malicious infrastructure, enabling threat actors to operate with even greater credibility and reduced detection.

finance SG

· Group-IB · Hooking the Archipelago: Dissecting a Phishing Campaign Targeting Philippine Banking Users

1

1

Кібератака UAC-0255 під виглядом сповіщення від CERT-UA із застосуванням програмного засобу AGEWHEEZE (CERT-UA#21075)

Національною командою реагування на кіберінциденти, кібератаки, кіберзагрози CERT-UA 26-27 березня 2026 року зафіксовано випадки розповсюдження електронних листів нібито від імені CERT-UA із закликом завантажити з сервісу Files.fm захищений паролем архів ("CERT_UA_protection_tool.zip", "protection_tool.zip") та встановити "спеціалізоване програмне забезпечення". Серед отримувачів листів: державні організації, медичні центри, охоронні фірми, навчальні заклади, фінансові установи, компанії…

veřejná správa zdravotnictví finance školství UA

· CERT-UA · Кібератака UAC-0255 під виглядом сповіщення від CERT-UA із застосуванням програмного засобу AGEWHEEZE (CERT-UA#21075)

1

Elastic Security Labs uncovers BRUSHWORM and BRUSHLOGGER

Key takeaways A South Asian financial institution was targeted with two custom malware components: a modular backdoor (BRUSHWORM) and a keylogger (BRUSHLOGGER) BRUSHWORM features anti-analysis checks, AES-CBC encrypted configuration, scheduled task persistence, modular DLL payload downloading, USB worm propagation, and broad file theft targeting documents, spreadsheets, email archives, and source code The keylogger masquerades as libcurl via DLL side-loading, capturing system-wide keystrokes…

finance US

tg: incident tg: rozbor tp: malware tp: AI

· Elastic Security · Elastic Security Labs uncovers BRUSHWORM and BRUSHLOGGER

1

1

1

LexisNexis breach (Incident)

LexisNexis confirmed a cloud-based data breach after threat actor FulcrumSec leaked ~2GB of stolen data. The attacker exploited an unpatched React2Shell vulnerability in a frontend application to gain access to the company’s AWS environment, leading to large-scale data exfiltr...

LexisNexis finance US

· Wiz Research · LexisNexis breach (Incident)

1

JSAC2026 -Day 2-

Continuing from the previous report, this second installment introduces the presentations delivered during the Day 2 Main Track. Following the Trace: Reconstructing Attacks from Ext4 and XFS Journals Speaker: Minoru Kobayashi, Internet Initiative Japan Inc. Presentation Materials (English) Minoru Kobayashi presented an approach for inferring file operations and reconstructing them as a timeline based on the journal structures and analysis methods of the ext4 and XFS file systems. Through a…

Internet Initiative Japan Inc. NTT DOCOMO BUSINESS, Inc. Recruit Co., Ltd. finance veřejná správa doprava JP

· JPCERT/CC – blog · JSAC2026 -Day 2-

1

Kritische Sicherheitslücken in Cisco Catalyst SD-WAN - aktiv ausgenutzt - Updates verfügbar

26. Februar 2026 Beschreibung In Cisco Catalyst SD-WAN existieren mehrere kritische Sicherheitslücken. Die schwerwiegendste Schwachstelle (CVE-2026-20127) ermöglicht es einem nicht authentifizierten Angreifer aus der Ferne, die Authentifizierung zu umgehen und administrative Berechtigungen auf einem betroffenen System zu erlangen. Weitere Schwachstellen betreffen den Cisco Catalyst SD-WAN Manager und ermöglichen unter anderem Authentication Bypass, Privilege Escalation, Information Disclosure…

KEV ✓ EPSS 0.88 CVSS 10.0 CVE-2026-20122 CVE-2026-20126 CVE-2026-20127 CVE-2026-20128 CVE-2026-20129 CVE-2026-20133 Cisco telekomunikace finance AT

· CERT.at · Kritische Sicherheitslücken in Cisco Catalyst SD-WAN - aktiv ausgenutzt - Updates verfügbar