Report: Financial Technology Ecosystem Creates New Cyber Threats

Plus, ENISA issues new healthcare cybersecurity procurement guidelines.

Good morning! Here’s what’s up.

People

Assaf Keren has joined Meta as its newest chief information security officer, transitioning into the role after Guy Rosen departs later this year, Keren announced in a LinkedIn post. Keren joins Meta from Qualtrics, where he was chief security officer. Previously, he was CISO at PayPal.

Clips ✂️

Digital Banking’s Expanding Ecosystem Creates New Cybersecurity Challenges, Report Warns

The rapid development of digital banking services and financial technologies is resulting in an unprecedented cybersecurity paradigm, which the current security posture is not equipped to handle,” says the report titled ‘Digital Threat Report 2025-26’, complied by the Ministry of Electronics and Information Technology (MeitY), CERT-In, CSIRT-Fin, and cybersecurity firm SISA. “The cyber security landscape for banking is shifting due to an increasing reliance on connected financial systems, embedded finance, artificial intelligence (AI), real-time payments, APIs, and third-party services,” says the report.

“Unlike isolated legacy banking systems, where the attack surface was limited to the core banking application, contemporary interconnected systems allow attackers to target relationships rather than the bank itself.” It further says that modern cyber threats are now exploiting the trust surface between systems rather than infiltrating individual institutions and organizations. “Modern cyber threats are targeting the biometric onboarding, partner applications, AI-driven payments, processing and settlement flows, APIs, programmable finance, and connected payment ecosystems.

by CySecurity News

ENISA signs €6M agreement with European Commission, releases healthcare cybersecurity procurement guidelines

The European Union Agency for Cybersecurity (ENISA) signed a contribution agreement with the European Commission to help the healthcare sector strengthen its cyber defenses against evolving threats.

As one of its first deliverables under the EU Action Plan, ENISA published updated procurement guidelines to improve cybersecurity of hospitals and healthcare providers. The agreement’s primary objective is to implement the service catalogue, which currently groups Support Mechanism services into four categories, including preparedness, detection, response, and governance.

Launched by the European Commission in 2025, the EU Action Plan for the cybersecurity of hospitals and healthcare providers aims to strengthen the sector’s protection and resilience. Under the plan, ENISA has been assigned a series of initiatives, reflecting the European Commission’s confidence in the agency’s ability to support healthcare organizations in improving their cybersecurity posture.

by Industrial Cyber

Stadler Rail scoffs at Everst’s $12.3M extortion attempts

Swiss rail manufacturer Stadler Rail says it refused a CHF 10 million ($12.3 million) ransom demand after the Everest ransomware gang compromised one of its suppliers.

Stadler will not pay, and based on its account of events, the company appears to have got off lightly. It stated that "no security-relevant data [was] affected" in the breach, which was limited to "technical information from a supplier."

According to its announcement, "no relevant personal data was stolen," and the incident had no impact on the functioning of its rolling stock (train and tram carriages) or its global production lines.

The attackers accessed the technical data through a "data exchange platform" Stadler used with the unnamed supplier, authenticating with compromised login credentials.

by The Register

AI Bills of Materials (AI-BOMs) and Model Provenance: Contracting for Cybersecurity in AI-Enabled Manufacturing Supply Chains

Artificial Intelligence (AI)-BOMs and model provenance are emerging as cybersecurity diligence tools for manufacturers that buy or deploy systems. An AI bill of materials identifies the models, datasets, software components, APIs, and other dependencies that may create cyber exposure inside an AI system, while model provenance documents where those components came from, how they were trained or modified, and how they change over time.

For manufacturers and supply chain operators, these records can determine whether an organization can trace a corrupted dataset, identify a vulnerable open-source component, evaluate whether a vendor model update introduced new cyber risk, and preserve evidence when an AI-enabled production, quality, logistics, or maintenance system fails.

Vendor contracts should require both an initial AI bill of materials and ongoing model provenance obligations tied to cybersecurity accountability. Without clear disclosure, update, representation, audit, flow-down, and evidence-preservation terms, manufacturers may lack the information needed to determine whether an AI-related failure resulted from ordinary model performance, cyber compromise, or an undisclosed supply chain dependency.

by Foley & Lardner

The Illusion of Readiness: Understanding the Cyber Landscape in Brazil

Brazil’s digital environment is under pressure. The average cybersecurity maturity of Brazilian companies stands at 58% according to the latest Digital Risks Index from the Markets Innovation & Technology Institute (“MiTi”).

The annual report, sponsored by FTI Consulting, surveyed hundreds of Brazilian organizations on artificial intelligence, cybersecurity and data governance. The findings measure compliance readiness against the Lei Geral de Proteção de Dados (“LGPD”), Brazil’s primary data protection law.

While the findings show slight improvement from 2024 (53%), Brazilian companies continue to trail global peers in cybersecurity maturity. This gap underscores the structural vulnerabilities and governance challenges that still define the country’s risk landscape.

The current maturity score can be interpreted as intermediate sophistication: controls and practices are in place, but with gaps in consistency, governance and continuous execution.

by FTI Consulting

The Vulnerability Surge: How Companies Can Respond to AI-Driven Cyberattacks

Powerful AI models are showing that they can discover and exploit critical software vulnerabilities at unprecedented speed, scale, and effectiveness. Attackers already are leveraging these capabilities to launch highly automated cyberattacks and exploit software bugs before companies can fix them. Companies are finding that their existing patch management and incident response processes are not enough to deal with these emerging AI-driven security threats.

In this webinar, panelists discuss how recent developments in AI models' abilities to find and exploit vulnerabilities at scale are upending the threat landscape and pushing companies to overhaul cyber risk management. Panelists examine early legal and regulatory responses to these developments and provide practical guidance on how companies might rethink patch management, defense in depth, communications, and incident response in light of emerging security and legal risks.

This webinar is the first installment in a two-part series co-hosted by DWT and FTI on emerging technologies and cyber threats. Part two, on quantum computing and post-quantum cryptography, will be held in October 2026.

by Davis Wright Tremaine

X