Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The Guardian view on the Conservative conference: a party still searching for a purpose | Editorial

    October 2, 2026

    Video supposedly showing BBC News linking Indian passenger to Flydubai attack is a deepfake – Full Fact

    October 2, 2026

    Top Democrats slam ‘Trump’s failing economic agenda’ after weaker-than-expected jobs growth – US politics live | Trump administration

    October 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Guardian view on the Conservative conference: a party still searching for a purpose | Editorial
    • Video supposedly showing BBC News linking Indian passenger to Flydubai attack is a deepfake – Full Fact
    • Top Democrats slam ‘Trump’s failing economic agenda’ after weaker-than-expected jobs growth – US politics live | Trump administration
    • ‘Maxi merde’: French presidential campaign rattled by a week of chaos – POLITICO
    • Unusual Issues at War Court Stand Out as a Case Finally Heads to Trial
    • Blackstone’s Jas Khaira joins Disrupt 2026
    • SWIFT Banking & Government Middleware Enables RCE
    • Bitcoin Price Surges Above $87,000 On Jobs Data
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    SWIFT Banking & Government Middleware Enables RCE

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 2, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Researchers have discovered a critical vulnerability in a hardware authentication program used to access highly sensitive global government and financial systems.

    In cases where purely digital methods just aren’t secure enough, especially careful organizations may require that users authenticate to sensitive systems with multifactor authentication (MFA) hardware. After all, you wouldn’t want a simple password to allow hackers into a system that facilitates financial transfers or official government business. Hardware-based MFA requires some means of communicating between one’s hardware token and a website in question, though, which researchers continually find is the weak point in the whole arrangement.

    “SConnect,” owned by the Thales Group conglomerate, is one such example of this. It’s a browser extension with more than 1 million users on the Chrome Web Store, and plenty more on other app stores. It’s used for authentication to major national government systems — like Qatar’s national identity provider, Tawtheeq, and the Swedish Tax Agency, Skatteverket — and various banking and insurance portals. Most notably, SConnect has long been one of the primary methods for accessing the Society for Worldwide Interbank Financial Telecommunication (SWIFT) banking system that supports the entire global financial apparatus.

    Related:Is Your Organization Ready for 2027’s AI Accountability Era?

    In a report shared exclusively with Dark Reading ahead of publication, the browser extension aficionados at Bay Area Labs outlined a vulnerability in SConnect. The vulnerability allows attackers to perform drive-by remote code execution (RCE) attacks against users in a matter of seconds. And, the researchers say, the potential attack scenarios could get a lot worse.

    Thales Group patched SConnect on the Apple App Store and Chrome Web Store in August and removed the app entirely from Microsoft Edge in September. It published a CVE, CVE-2026-18397, on Oct. 1. The company assigned it a “critical” 9.4 out of 10 in the Common Vulnerability Scoring System (CVSS) 4.0 scale, and users should update their instances as soon as possible.

    Critical Vulnerability in Government, Banking Middleware

    SConnect, like other sensitive authentication middleware, pairs a light browser extension with a workhorse desktop program. Users visit SConnect-integrated websites, mash their hardware keys into their computers or connected device readers, and the extension and native host facilitate the communication back and forth, like two little lawyers. If everything goes to plan, the software confirms that both the website and hardware token are trusted, authorized entities.

    Related:Vulnerability Backlogs Are an Ownership Problem

    The first problem with SConnect was that the browser extension accepted messages from any webpage or embedded iframe, be it the SWIFT banking system or lowtpills[.]com. Thus, any attacker could attempt to step into an SConnect authentication flow if they could get a victim to the right webpage.

    SConnect would still verify that the site was authorized, of course, by checking if it possessed a valid RSA digital signature from its vendor, Thales Group. In doing so, it reserved a buffer to hold the result of the RSA calculation. The app developers designed this check themselves, Bay Area Labs concluded, and they failed to protect against a scenario where the attacker supplied an invalid, oversized signature. In that case, the calculation would fail without writing anything to the reserved memory space. SConnect didn’t check whether the original calculation succeeded, but it did still read the stale buffer. If an attacker heap-sprayed it with carefully designed byte patterns meant to fake signature results, the software might accept the attacker’s ersatz replacement as valid. Using AI agents, Bay Area Labs succeeded at this about 18% of the times they tried, and meanwhile, failed attempts caused no visible error that could alert users they were under attack.

    Related:How the CISO-CMO Alliance Builds Trust Before Crisis Strikes

    “At the end of the day,” explains Bay Area Labs founder James Arnott, “they implemented a cryptographic check, and they did it themselves. They didn’t use a library, and they messed it up.”

    As a result, malicious websites could pass SConnect’s security check and load a malicious dynamic link library (DLL) through its native host for unfettered RCE. In their testing, the researchers were able to perform the attack end-to-end in six to 10 seconds flat. “Visit a page with a malicious iframe, then you have been infected. To be honest, from there, you can do pretty much whatever you want,” Arnott says.

    It’s not an obvious vulnerability simply exploited, he admits, but the acceleration capabilities of AI put the exploit within reach: “It would have previously required nation-state effort. But when I was developing this exploit, it was very much agent-driven. The agents had Ghidra to decompile the native host, and then Frida to look at the memory to see what would be successful for the heap spray and what wouldn’t.”

    Thales Group has not yet responded to Dark Reading’s request for comment on this story.

    Defenders, Re-Evaluate Your SWIFT Banking Security

    To authenticate to the SWIFT system, you’ll need a “3SKey” — a USB security token distributed to partner corporations for their most highly permissioned employees.

    For years, the default software program connecting 3SKeys with the system they unlocked was SConnect. In September 2025, the SWIFT cooperative introduced a replacement called “Web Connect.” It has since been trying to move its corporate customers towards Web Connect, and away from SConnect.

    SConnect is end of life (EoL) as of last month, but that doesn’t mean that everyone has made the jump yet.

    “I suspect most people will still have it, if they’re using SWIFT, [since] SConnect is the fallback if Web Connect isn’t set up already,” Arnott posits. He admits that it’s very difficult to gauge the blast radius of this issue, though, as the banking industry keeps the particulars of its security practices close to the chest.

    Bay Area Labs’ testing was limited by an inability to obtain a 3SKey, or tokens to other systems, like Qatar’s national government identity portal. Arnott suspects, however, that attack scenarios far beyond RCE against individual users could be possible with CVE-2026-18397. He speculates that “you could have a similar exploit chain like with Connective: to essentially relay challenges, to get the user’s identity card to sign documents. And then an attacker could steal the victim’s session and log in as them.”

    Similarly, “once you have RCE in a banking system, it could be quite easy to look around, figure out whose computer you’re on, and try to transfer money,” he says. “I just can’t prove it because no one will send me a 3SKey, unsurprisingly.”

    banking enables government Middleware RCE Swift
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Government wrong to claim over 14.5 million children used free bus scheme – Full Fact

    In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats

    US sanctions Tren de Aragua gang members in ATM hacks crackdown

    Vulnerability Backlogs Are an Ownership Problem

    macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

    OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The Guardian view on the Conservative conference: a party still searching for a purpose | Editorial

    October 2, 2026

    Video supposedly showing BBC News linking Indian passenger to Flydubai attack is a deepfake – Full Fact

    October 2, 2026

    Top Democrats slam ‘Trump’s failing economic agenda’ after weaker-than-expected jobs growth – US politics live | Trump administration

    October 2, 2026

    ‘Maxi merde’: French presidential campaign rattled by a week of chaos – POLITICO

    October 2, 2026
    Latest Posts

    Lime bikes hurtling around the city: is this the revenge of a priced-out generation? | Andy Beckett

    August 8, 2026

    Clarity Act Delayed Until September, Trump Praises Bitcoin

    August 8, 2026

    North Carolina Ports confirms cyberattack disrupting operations

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The Guardian view on the Conservative conference: a party still searching for a purpose | Editorial

    October 2, 2026

    Video supposedly showing BBC News linking Indian passenger to Flydubai attack is a deepfake – Full Fact

    October 2, 2026

    Top Democrats slam ‘Trump’s failing economic agenda’ after weaker-than-expected jobs growth – US politics live | Trump administration

    October 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.