logo

What 345 Days of Untested Exposure Looks Like at a Bank

ID: d3e8fffa-3966-5c56-8493-b3f5c1b2a224

STIX ID: report--d3e8fffa-3966-5c56-8493-b3f5c1b2a224

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Sponsored by Sprocket Security

...
...

Executive summary: A single unpatched VPN vulnerability and insecure vendor-operated APIs led to large-scale exposures across financial institutions, highlighting that annual penetration tests leave substantial unvalidated attack surface; a Sprocket engagement found an unauthenticated tenant-ID API with permissive CORS that returned staff PII and allowed submission-forgery across tenants, demonstrating how vendor-hosted assets and change-driven infrastructure create ongoing regulatory and fraud risk and motivating continuous testing and attack-surface management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.