🎧 Subscribe to the podcast feed | Direct download
Security News
China launches mysterious probe into security of Palo Alto Networks' products (The Register) — China has opened a formal security investigation into Palo Alto Networks products, a move analysts widely interpret as geopolitical leverage that could precede procurement bans.
ChainDrop: Inside a Self-Propagating npm Worm (Unit 42) — Researchers have published a detailed analysis of ChainDrop, a self-propagating worm targeting the npm ecosystem that spreads by modifying package files on infected systems, making containment in CI/CD environments particularly difficult.
Researcher Claims Control of ChatGPT Secure Sandbox (Dark Reading) — A security researcher claims to have gained control over ChatGPT's secure sandbox environment; OpenAI has not yet confirmed the scope of the finding.
Swiss government SharePoint breach compromised 200 accounts (BleepingComputer) — Switzerland's federal IT agency suffered another SharePoint-based breach compromising around 200 accounts, repeating a pattern from an earlier incident this year and raising remediation questions.
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes (BleepingComputer) — A newly published CPU-level side-channel attack called TONTOU bypasses existing Spectre v2 mitigations and can leak Linux password hashes from unpatched kernels.
Canadian Man Pleads Guilty in Snowflake Extortions (Krebs on Security) — A Canadian man has pleaded guilty in connection with the Snowflake extortion campaign, one of the largest credential-theft operations in recent years affecting over 165 companies and billions of records.
ClickFix attack pushes macOS infostealer for crypto theft attacks (BleepingComputer) — A ClickFix campaign has escalated to delivering a macOS infostealer targeting cryptocurrency wallets, a notable shift from the technique's historical Windows focus.
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud (Google Threat Intelligence) — The UNC6671 threat actor, linked to the BlackFile extortion group, has been tied to sophisticated vishing campaigns using multi-brand impersonation to harvest credentials from hedge funds and enterprise cloud environments.
Cyberattack on North Carolina Ports 'contained' as Coast Guard, state officials investigate (The Record) — The cyberattack that struck the North Carolina State Ports Authority on 4 August has been contained, with IT recovery ongoing across the ports of Wilmington, Morehead City, and Charlotte Inland Port; no group has claimed responsibility.
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group (BleepingComputer) — Multiple hedge fund cyberattacks have been attributed to UNC6671, a financially motivated extortion group using sophisticated vishing and credential-harvesting techniques against financial sector targets.
Ransomware Victims (48h)
| Group | Victim | Country | Sector |
|---|---|---|---|
| akira | Basic Grain Products | US 🇺🇸 | Agriculture & Food |
| akira | Pharma Test Apparatebau AG | CH 🇨🇭 | Manufacturing (Pharma) |
| Barracuda | RS Automation Co., Ltd. | CN 🇨🇳 | Manufacturing (637 GB) |
| bravox | MITC AG | CH 🇨🇭 | IT / Engineering |
| cry0 | Hope's Windows | US 🇺🇸 | Retail |
| Gammax | King International LLC | US 🇺🇸 | Food Distribution |
| lynx | ⚠️ Talbot County Dept of Emergency Services | GB 🇬🇧 | Emergency Services (9-1-1 / EMS) |
| lynx | Jerry Leigh (jerryleigh.com) | US 🇺🇸 | Retail / Manufacturing |
| Orova | Country Oaks Veterinary Clinic | US 🇺🇸 | Healthcare |
| Orova | David King Architect | US 🇺🇸 | Professional Services |
| Orova | First Baptist Church of Belleview | US 🇺🇸 | Other |
| Orova | Gemstone UK | US 🇺🇸 | Other |
| Orova | Hilliard's Air Conditioning & Heating | US 🇺🇸 | Professional Services |
| Orova | ⚠️ Magnolia Dental | US 🇺🇸 | Healthcare |
| Orova | St Theresa Catholic Church | US 🇺🇸 | Other |
| Orova | Stonecrest POA | US 🇺🇸 | Other |
| Orova | Stoneybrook West Master Association | US 🇺🇸 | Other |
| Orova | Woodside Ranch | US 🇺🇸 | Agriculture |
| play | GCATS Investments | US 🇺🇸 | Financial Services |
| play | Platinum Group | SG 🇸🇬 | Manufacturing |
| play | Signature Services | US 🇺🇸 | Professional Services |
| qilin | ⚠️ AmSpec | US 🇺🇸 | Energy & Utilities |
| qilin | Akuur Law Firm | TR 🇹🇷 | Professional Services |
| qilin | ALIZE (alize-sud.fr) | FR 🇫🇷 | Professional Services |
| qilin | ⚠️ Crystal Pharmatech | US 🇺🇸 | Healthcare / Pharma |
| qilin | Jakle & Alexander | US 🇺🇸 | Legal |
| qilin | J&T Bank and Trust | US 🇺🇸 | Financial Services |
| SilentRansomGroup | Mayer Brown | US 🇺🇸 | Professional Services (Major Law Firm) |
| threeam | Club One Casino (clubonecasino.com) | US 🇺🇸 | Hospitality |
| clop (Aug 5) | ~40 redacted victims | — | Mixed (incl. Financial Services, Technology) |
⚠️ = Healthcare or Critical Infrastructure. Clop mass-dump entries remain partially redacted; see yesterday's briefing for full list.