Financial services threat intelligence report — 11–17 July 2026
The financial-services vertical continues to absorb a disproportionate share of organised criminal cyber activity directed at UK and European markets.
SOC status:Duty analyst on shift
Topic
13 articles tagged Banking.
The financial-services vertical continues to absorb a disproportionate share of organised criminal cyber activity directed at UK and European markets.
The financial-services vertical continues to absorb a disproportionate share of organised criminal cyber activity directed at UK and European markets.
Coverage this period is dominated by the CISA KEV addition of the SharePoint deserialisation defect (CVE-2026-45659) on 01 Jul with a three-day federal remediation deadline; the continued tail of CitrixBleed 3 session-token abuse against NetScaler estates…
The collection picture this week is dominated by edge-appliance exposure - the three Ubiquiti UniFi OS defects added to the CISA Known Exploited Vulnerabilities catalogue on 23 June chain to unauthenticated root RCE under the Bishop Fox proof-of-concept and present a material risk to FS branch and…
All assessments use estimative language and confidence ratings per Section 11.
The financial-services collection picture this week has been dominated by the addition of six further vulnerabilities to the CISA KEV catalogue, three of them confirmed under active in-the-wild exploitation against FS-relevant edge infrastructure: Cisco Catalyst SD-WAN Manager (CVE-2026-20245…
The financial-services collection picture this week has been shaped by the addition of three further CVEs to the CISA KEV catalogue on 02 and 03 June - CVE-2022-0492 (Linux Kernel cgroup releaseagent, revived for container-escape campaigns against cloud-banking workloads)…
The collection picture this week has been dominated by the continued exploitation of edge-appliance vulnerabilities — Cisco Catalyst SD-WAN (CVE-2026-20182) under Emergency Directive 26-03, the Ivanti EPMM credential-reuse chain (CVE-2026-6973)…
The week's collection picture has been dominated by continued exploitation of edge-appliance vulnerabilities (Cisco Catalyst SD-WAN CVE-2026-20182, Ivanti EPMM CVE-2026-6973), the Akira and Qilin ransomware crews reaching new weekly leak-site cadence highs…
During the reporting period 11 May 2026 – 17 May 2026 the financial-services threat picture remained dominated by ransomware and pure data-extortion crews against a backdrop of continued AI-accelerated patch-wave dynamics.
During the reporting period the financial-services threat picture continued to be dominated by ransomware and pure data-extortion crews…
During the reporting period the financial services threat picture continued to be dominated by ransomware and data-extortion crews, augmented by sustained credential-harvesting against retail and SME banking customers.