Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-20 · 02:03 UTC
articleTotal: 593 reports

Filtered Reports

21 / 21 results
Active filter:tag: #financial-services✕ clear
Malicious npm and PyPI packages impersonate Paysafe payment SDKshighbug_reportVulnerability
bug_reportVulnerability

Malicious npm and PyPI packages impersonate Paysafe payment SDKs

Developers using npm and PyPI repositories who may have installed counterfeit packages impersonating Paysafe, Skrill, and Neteller payment SDKs. Affects development environments and potentially downstream applications integrating these malicious pack…

Paysafe17:54 UTC
RedWing Android MaaS enables bank fraud via credential thefthighbug_reportVulnerability
bug_reportVulnerability

RedWing Android MaaS enables bank fraud via credential theft

Android devices targeted by RedWing malware, distributed as Malware-as-a-Service on Telegram. Variant of Oblivion MaaS. Primarily affects banking applications and users with compromised devices.

The Hacker News15:10 UTC
Ousaban banking trojan targets Spain and Portugal via phishinghighbug_reportVulnerability
bug_reportVulnerability

Ousaban banking trojan targets Spain and Portugal via phishing

Windows users in Spain and Portugal. Ousaban banking trojan campaign using fake PDF lures with geolocation filtering and steganography techniques. No specific product vulnerability; threat actor campaign identified by Fortinet FortiGuard Labs in May…

Fortinet13:26 UTC
Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensionshighperson_alertThreat Actor
person_alertThreat Actor

Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensions

Silent Swap is an active cybercrime campaign leveraging malicious browser extensions to conduct cryptocurrency theft. The operation distributes unsigned installers written in both .NET and Golang variants, masquerading as a legitimate Google Notes br…

Google13:40 UTC
Pre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectorshighperson_alertThreat Actor
person_alertThreat Actor

Pre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectors

The threat actor behind this campaign remains unattributed. Motivation appears financially driven, leveraging the global interest in FIFA World Cup 2026 to conduct fraud operations.

The Hacker News09:30 UTC
236K+ malicious sites use DCloud Uni-App templates for crypto scamshighbug_reportVulnerability
bug_reportVulnerability

236K+ malicious sites use DCloud Uni-App templates for crypto scams

Organizations and users interacting with websites built using DCloud Uni-App framework templates. Over 236,000 malicious sites identified conducting cryptocurrency scams, phishing, wallet draining, pig-butchering schemes, and fake gambling platforms.

DCloud09:57 UTC
Polymarket frontend compromised via third-party vendor; $3M stolenhighbug_reportVulnerability
bug_reportVulnerability

Polymarket frontend compromised via third-party vendor; $3M stolen

Polymarket platform users. Attack vector: malicious JavaScript injected into frontend via compromised third-party vendor. Approximately $3 million in customer funds stolen. No CVE assigned.

Polymarket16:04 UTC
Clipboard-stealing malware spreads via USB, targets crypto walletshighbug_reportVulnerability
bug_reportVulnerability

Clipboard-stealing malware spreads via USB, targets crypto wallets

Windows systems with USB connectivity. Targets cryptocurrency wallet users. No specific vendor or product vulnerability; relies on user interaction with malicious Windows shortcut (.lnk) files on removable media.

BleepingComputer14:20 UTC
Windows cryptocurrency clipper campaign uses USB worms and Tor C2highbug_reportVulnerability
bug_reportVulnerability

Windows cryptocurrency clipper campaign uses USB worms and Tor C2

Windows systems with Windows Script Host and ActiveX enabled. Campaign active since February 2026 targeting cryptocurrency users via USB-based LNK worm propagation.

Microsoft12:30 UTC
Cryptocurrency clipper malware with worm propagation targets Windowshighbug_reportVulnerability
bug_reportVulnerability

Cryptocurrency clipper malware with worm propagation targets Windows

Windows systems globally. No specific product vulnerability; threat relies on social engineering, malicious downloads, or lateral movement. All cryptocurrency wallet users on Windows are potential targets.

Microsoft21:11 UTC
Rokarolla Android banking trojan targets 217 banking and crypto appshighbug_reportVulnerability
bug_reportVulnerability

Rokarolla Android banking trojan targets 217 banking and crypto apps

Android devices with 217 targeted banking and cryptocurrency applications. Malware features 137 commands for comprehensive device control and data exfiltration. Specific app list and Android version scope not disclosed.

BleepingComputer18:04 UTC
FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platform

Outsider Enterprise is a Chinese phishing-as-a-service (PhaaS) operation disrupted by the FBI in coordination with Google and Black Lotus Labs. The actor operated thousands of phishing websites designed to harvest credit card data and passwords from…

BleepingComputer12:36 UTC
NFCShare Android malware distributed via GitHub as fake banking app updateshighbug_reportVulnerability
bug_reportVulnerability

NFCShare Android malware distributed via GitHub as fake banking app updates

Android mobile users, particularly customers of targeted banking applications. Malware distributed through GitHub repositories posing as legitimate banking app updates.

BleepingComputer20:11 UTC
UNC3753 Conducts Data Theft Extortion via Vishing and Physical Intrusionhighperson_alertThreat Actor
person_alertThreat Actor

UNC3753 Conducts Data Theft Extortion via Vishing and Physical Intrusion

UNC3753 is a financially motivated threat actor attributed by Mandiant. The group conducted a data theft extortion campaign targeting dozens of organizations in the United States between January and May 2026.

The Hacker News05:39 UTC
FBI Warns of FIFA World Cup 2026 Fraud Campaign with Banking Malwarehighperson_alertThreat Actor
person_alertThreat Actor

FBI Warns of FIFA World Cup 2026 Fraud Campaign with Banking Malware

This is a cybercrime campaign leveraging the FIFA World Cup 2026 tournament as a lure, rather than a single named threat actor. The campaign involves multiple financially motivated threat actors exploiting public interest in the tournament to distrib…

The Hacker News05:01 UTC
US national sentenced for selling 7M elderly records to Jamaican fraudstershighpublicGeopolitical
publicGeopolitical

US national sentenced for selling 7M elderly records to Jamaican fraudsters

This case illustrates the transnational nature of cybercrime and data exploitation, where domestic actors facilitate cross-border fraud schemes targeting vulnerable populations.

BleepingComputer09:07 UTC
Malicious NuGet package "Sicoob.Sdk" steals banking credentialshighbug_reportVulnerability
bug_reportVulnerability

Malicious NuGet package "Sicoob.Sdk" steals banking credentials

NuGet package "Sicoob.Sdk" versions 2.0.0 through 2.0.4. Targets developers integrating with Sicoob (Brazilian cooperative banking system). Affects .NET development environments where the malicious package was installed.

Sicoob07:11 UTC
FBI warns of FIFA-impersonating fraud sites targeting 2026 World Cuphighperson_alertThreat Actor
person_alertThreat Actor

FBI warns of FIFA-impersonating fraud sites targeting 2026 World Cup

Unknown fraud operators are conducting financially motivated cybercrime campaigns targeting fans and consumers interested in the 2026 FIFA World Cup. These actors leverage social engineering and brand impersonation tactics to establish fraudulent web…

BleepingComputer17:08 UTC
Banking trojans Grandoreiro and BTMOB target LATAM and Europehighbug_reportVulnerability
bug_reportVulnerability

Banking trojans Grandoreiro and BTMOB target LATAM and Europe

Windows and Android devices in Latin America (Brazil, Mexico) and Europe (Spain, Portugal). Grandoreiro targets Windows systems at companies; BTMOB RAT targets Android mobile users in Brazil.

Windows14:10 UTC
Lazarus Group deploys RemotePE cross-platform RAT against finance sectorhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Group deploys RemotePE cross-platform RAT against finance sector

Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through th…

The Hacker News07:32 UTC
Kieback & Peter DDC controllers vulnerable to XSS attackshighbug_reportVulnerability
bug_reportVulnerability

Kieback & Peter DDC controllers vulnerable to XSS attacks

Kieback & Peter DDC (Direct Digital Control) Building Controllers. Specific affected versions not disclosed in available data.

CVE-2026-429310:00 UTC