FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Commerzbank $30M Supply Chain Fraud via Service Provider Exploitation

In November 2023, an international cybercrime syndicate executed a four-day fraud campaign resulting in a $30 million loss for Commerzbank customers. The attackers bypassed primary banking controls by exploiting vulnerabilities—specifically API insecurities or broken access controls—within a trusted third-party service provider's infrastructure. By pivoting from the service provider to the banking transaction layer, the syndicate implemented rapid-fire withdrawal logic to exfiltrate funds within a 96-hour window. The campaign culminated in "Operation First Light," a coordinated effort by the BKA, Brazilian Federal Police, and Interpol, leading to seven arrests across Germany and Brazil.

ServiceNow Unauthenticated API Access Vulnerability

In June 2026, a critical broken access control vulnerability was identified in ServiceNow hosted instances, allowing unauthenticated actors to gain unauthorized access to customer environments, likely via API exploitation. The flaw permitted potential data exposure and administrative access. While ServiceNow deployed a security update on June 5, 2026, to mitigate the risk, the incident was complicated by bug bounty researchers whose testing triggered security alerts in several organizations, creating false-positive breach notifications. Organizations should audit API logs for anomalous unauthenticated calls and unauthorized administrative activity to determine if their specific instance was compromised prior to patching.


LINK COPIED TO CLIPBOARD