Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

12 / 12 results
Active filter:tag: #finance✕ clear
19 malicious Chrome/Edge extensions steal crypto wallets and credentialshighbug_reportVulnerability
bug_reportVulnerability

19 malicious Chrome/Edge extensions steal crypto wallets and credentials

Google Chrome and Microsoft Edge users who installed any of 19 malicious extensions, including "Enable Right Click & Copy" (70,000+ Chrome users, 10,000+ Edge users). Campaign active since early 2024.

Google30 Aug · 12:17 UTC
BEC fraud campaign surges against Austrian orgs via impersonationhighbug_reportVulnerability
bug_reportVulnerability

BEC fraud campaign surges against Austrian orgs via impersonation

Austrian organizations across all sectors; targets finance, accounting, and HR departments. Attack vectors include email impersonation, compromised supplier accounts, and hijacked email threads. No specific product vulnerabilities exploited.

CERT.at (Austria)25 Aug · 18:04 UTC
French tax authority breach exposes 678,000 records amid rising attackshighpublicGeopolitical
publicGeopolitical

French tax authority breach exposes 678,000 records amid rising attacks

The breach of France's General Directorate of Public Finances (DGFiP) represents the latest in a sustained pattern of cyberattacks targeting French government infrastructure throughout 2026.

French Ministry of the Economy and Finance17 Aug · 08:09 UTC
Metabase SQL injection zero-day exploited to steal customer datacriticalbug_reportVulnerability
bug_reportVulnerability

Metabase SQL injection zero-day exploited to steal customer data

Metabase (specific versions not disclosed). Confirmed victims include Framework and Tally customer instances. All unpatched Metabase deployments potentially at risk.

Metabase7 Aug · 18:14 UTC
AitM phishing campaign targets Microsoft 365 for payroll email thefthighbug_reportVulnerability
bug_reportVulnerability

AitM phishing campaign targets Microsoft 365 for payroll email theft

Microsoft 365 accounts across healthcare, education, manufacturing, government, and professional services sectors in the U.S., Canada, and Europe. Hundreds of organizations targeted in July 2026, with focus on payroll, HR, and finance personnel.

Microsoft7 Aug · 08:38 UTC
Phishing campaign exploits COLDCARD wallet fears to deploy ScreenConnect RAThighbug_reportVulnerability
bug_reportVulnerability

Phishing campaign exploits COLDCARD wallet fears to deploy ScreenConnect RAT

COLDCARD hardware wallet users targeted via phishing emails. Attack delivers ConnectWise ScreenConnect remote access tool via malicious batch file (Coldcard_Diagnostic_Tool.bat) hosted on GitHub.

COLDCARD5 Aug · 15:49 UTC
China-Linked Group Uses Cruciferra Crypter in Tax-Themed Phishing Campaignshighperson_alertThreat Actor
person_alertThreat Actor

China-Linked Group Uses Cruciferra Crypter in Tax-Themed Phishing Campaigns

A China-linked cybercrime group, tracked as TA4922 by Proofpoint, has been conducting opportunistic phishing campaigns targeting Indian taxpayers, tax professionals, and corporate finance teams.

The Hacker News27 Jul · 08:51 UTC
Hermes AI Agent Used for Post-Exploitation at Thai Finance Ministryhighperson_alertThreat Actor
person_alertThreat Actor

Hermes AI Agent Used for Post-Exploitation at Thai Finance Ministry

The threat actor behind this intrusion remains unattributed. Hunt.io assesses with low-to-medium confidence that the operator is Chinese-speaking or fluent in Chinese, based on linguistic artifacts (password containing "Leishen," meaning thunder god)…

Hermes AI24 Jul · 08:15 UTC
Lazarus Deploys OtterCookie via Fake Job Lures in Contagious Interviewhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Deploys OtterCookie via Fake Job Lures in Contagious Interview

Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through cryptocu…

The Hacker News17 Jul · 11:48 UTC
China-nexus actor targets Indian finance sector via DcRAT malwarehighperson_alertThreat Actor
person_alertThreat Actor

China-nexus actor targets Indian finance sector via DcRAT malware

A suspected China-nexus threat actor is conducting Operation DragonReturn, a targeted espionage campaign against Indian taxpayers and finance professionals.

The Hacker News6 Jul · 08:58 UTC
Oracle E-Business Suite under active exploit via CVE-2026-46817criticalbug_reportVulnerability
bug_reportVulnerability

Oracle E-Business Suite under active exploit via CVE-2026-46817

Oracle E-Business Suite (EBS) financial application. Specific affected versions not disclosed in available intelligence.

CVE-2026-4681729 Jun · 11:46 UTC
Oracle PeopleSoft RCE actively exploited, immediate patching requiredcriticalbug_reportVulnerability
bug_reportVulnerability

Oracle PeopleSoft RCE actively exploited, immediate patching required

Oracle PeopleSoft (specific versions not disclosed in alert). Remote code execution vulnerability affecting internet-facing PeopleSoft instances.

Oracle12 Jun · 12:39 UTC