Briefing — 7 August 2026

🎧 Subscribe to the podcast feed | Direct download

Security News

China launches mysterious probe into security of Palo Alto Networks' products (The Register) — China has opened a formal security investigation into Palo Alto Networks products, a move analysts widely interpret as geopolitical leverage that could precede procurement bans.

ChainDrop: Inside a Self-Propagating npm Worm (Unit 42) — Researchers have published a detailed analysis of ChainDrop, a self-propagating worm targeting the npm ecosystem that spreads by modifying package files on infected systems, making containment in CI/CD environments particularly difficult.

Researcher Claims Control of ChatGPT Secure Sandbox (Dark Reading) — A security researcher claims to have gained control over ChatGPT's secure sandbox environment; OpenAI has not yet confirmed the scope of the finding.

Swiss government SharePoint breach compromised 200 accounts (BleepingComputer) — Switzerland's federal IT agency suffered another SharePoint-based breach compromising around 200 accounts, repeating a pattern from an earlier incident this year and raising remediation questions.

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes (BleepingComputer) — A newly published CPU-level side-channel attack called TONTOU bypasses existing Spectre v2 mitigations and can leak Linux password hashes from unpatched kernels.

Canadian Man Pleads Guilty in Snowflake Extortions (Krebs on Security) — A Canadian man has pleaded guilty in connection with the Snowflake extortion campaign, one of the largest credential-theft operations in recent years affecting over 165 companies and billions of records.

ClickFix attack pushes macOS infostealer for crypto theft attacks (BleepingComputer) — A ClickFix campaign has escalated to delivering a macOS infostealer targeting cryptocurrency wallets, a notable shift from the technique's historical Windows focus.

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud (Google Threat Intelligence) — The UNC6671 threat actor, linked to the BlackFile extortion group, has been tied to sophisticated vishing campaigns using multi-brand impersonation to harvest credentials from hedge funds and enterprise cloud environments.

Cyberattack on North Carolina Ports 'contained' as Coast Guard, state officials investigate (The Record) — The cyberattack that struck the North Carolina State Ports Authority on 4 August has been contained, with IT recovery ongoing across the ports of Wilmington, Morehead City, and Charlotte Inland Port; no group has claimed responsibility.

Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group (BleepingComputer) — Multiple hedge fund cyberattacks have been attributed to UNC6671, a financially motivated extortion group using sophisticated vishing and credential-harvesting techniques against financial sector targets.

Ransomware Victims (48h)

GroupVictimCountrySector
akiraBasic Grain ProductsUS 🇺🇸Agriculture & Food
akiraPharma Test Apparatebau AGCH 🇨🇭Manufacturing (Pharma)
BarracudaRS Automation Co., Ltd.CN 🇨🇳Manufacturing (637 GB)
bravoxMITC AGCH 🇨🇭IT / Engineering
cry0Hope's WindowsUS 🇺🇸Retail
GammaxKing International LLCUS 🇺🇸Food Distribution
lynx⚠️ Talbot County Dept of Emergency ServicesGB 🇬🇧Emergency Services (9-1-1 / EMS)
lynxJerry Leigh (jerryleigh.com)US 🇺🇸Retail / Manufacturing
OrovaCountry Oaks Veterinary ClinicUS 🇺🇸Healthcare
OrovaDavid King ArchitectUS 🇺🇸Professional Services
OrovaFirst Baptist Church of BelleviewUS 🇺🇸Other
OrovaGemstone UKUS 🇺🇸Other
OrovaHilliard's Air Conditioning & HeatingUS 🇺🇸Professional Services
Orova⚠️ Magnolia DentalUS 🇺🇸Healthcare
OrovaSt Theresa Catholic ChurchUS 🇺🇸Other
OrovaStonecrest POAUS 🇺🇸Other
OrovaStoneybrook West Master AssociationUS 🇺🇸Other
OrovaWoodside RanchUS 🇺🇸Agriculture
playGCATS InvestmentsUS 🇺🇸Financial Services
playPlatinum GroupSG 🇸🇬Manufacturing
playSignature ServicesUS 🇺🇸Professional Services
qilin⚠️ AmSpecUS 🇺🇸Energy & Utilities
qilinAkuur Law FirmTR 🇹🇷Professional Services
qilinALIZE (alize-sud.fr)FR 🇫🇷Professional Services
qilin⚠️ Crystal PharmatechUS 🇺🇸Healthcare / Pharma
qilinJakle & AlexanderUS 🇺🇸Legal
qilinJ&T Bank and TrustUS 🇺🇸Financial Services
SilentRansomGroupMayer BrownUS 🇺🇸Professional Services (Major Law Firm)
threeamClub One Casino (clubonecasino.com)US 🇺🇸Hospitality
clop (Aug 5)~40 redacted victimsMixed (incl. Financial Services, Technology)

⚠️ = Healthcare or Critical Infrastructure. Clop mass-dump entries remain partially redacted; see yesterday's briefing for full list.

Show Comments