The CyberWire Daily Podcast 8.7.26
Ep 2610 | 8.7.26

Ring around the ransom.

Transcript

Vishing attacks target hedge funds. Metabase Cloud breached by zero-day flaw. Cyberattack disrupts North Carolina Ports operations. The Chinese government has launched a security review of Palo Alto Networks products. US defense supplier breached by phishing attack. Healthcare software provider breach affected 3.8 million people. New macOS malware spreads via ClickFix attacks. Microsoft and Apple issue new security updates. Cryptography expert says new AI cryptanalysis results show promise, but not an AES breakthrough. James Turgal, Optiv Security’s vice president, cyber risk, strategy and board relations, is discussing how Iranian operators and their proxies appear to pursue disruption. And a Kentucky Fried Chicken order doxxes Chinese spyware operator.

Today is Aug 7, 2026. I’m Maria Varmazis. And this is your CyberWire Intel Briefing.

Vishing attacks target hedge funds.

Google's Threat Intelligence Group has linked recent cyberattacks targeting hedge funds, private equity firms, and other financial organizations to the UNC6671 extortion group, formerly known as BlackFile. The group is using helpdesk impersonation and voice phishing to compromise Microsoft 365 and Okta accounts, then targeting cloud services to steal sensitive data for extortion. Notably, the threat actors often target employees’ personal mobile devices.

Reuters cites sources as saying the campaign has targeted Point72, Millennium Management, Two Sigma Investments, Citadel, and several other private-equity firms. Google’s researchers note, “Concentrating on organizations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximize leverage extortion demands.”

Metabase Cloud breached by zero-day flaw.

Metabase disclosed a security incident involving a zero-day vulnerability that affected some Metabase Cloud customers. The company detected the attack, patched the issue, and began an investigation with external forensic support. Affected customers are being notified and should rotate credentials for connected databases, review admin accounts, and check logs for suspicious activity.

The company stated, “After gaining access to your instance, the attacker could inject arbitrary SQL against the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change your application configuration, steal stored credentials for your connected databases, read any data accessible through those connections, and export data.”

Cyberattack disrupts North Carolina Ports operations.

North Carolina Ports is recovering from a cyberattack that disrupted operations across its three port facilities, forcing staff to switch to manual processes. Officials say the breach has been contained, and the Coast Guard and state agencies are investigating the incident. The attack disrupted port operations at Wilmington, Morehead City, and Charlotte. A spokesperson for North Carolina Ports told the Record that the facilities are now following a normal operating schedule, but companies should expect delays as the ports are still relying on manual operations.

The Chinese government has launched a security review of Palo Alto Networks products.

China has launched a cybersecurity review of Palo Alto Networks products, citing national security concerns. The Cyberspace Administration of China initiated the review, but did not disclose which products were involved or if any vulnerabilities were identified. 

Reuters notes that the move echoes China's review of Micron in 2023, which eventually led to restrictions on the chipmaker’s products. Palo Alto has an established presence in the Chinese market, with offices in Beijing, ⁠Shanghai, Guangzhou [gwan-JOE], Shenzhen [shen-JEN], and Macau.

US defense supplier breached by phishing attack.

IEH Corporation, a US defense and aerospace supplier, disclosed that a phishing attack against an employee allowed an attacker to access the company’s Microsoft 365 mailbox. The compromised account contained emails, engineering documents, customer communications, purchase orders, and potentially export-controlled technical information. While IEH says it has no evidence that data was exfiltrated, the attacker had access to the information during the compromise. The company is continuing to investigate the incident.

Healthcare software provider breach affected 3.8 million people.

A cyberattack against Ohio-based healthcare software provider Unlimited Technology Systems has exposed the personal and medical information of 3.8 million people. Stolen data may include names, Social Security numbers, dates of birth, diagnoses, treatment details, insurance information, and other sensitive health records. The company says the breach occurred in October 2025. The HIPAA Journal notes that this is the largest confirmed healthcare data breach of 2026, so far.

New macOS malware spreads via ClickFix attacks.

Huntress has identified a new macOS malware campaign targeting cryptocurrency wallets, browser credentials, Apple Keychain data, and other sensitive information. The malware is delivered via ClickFix social engineering attacks that pose as CAPTCHA prompts. The malware is written in Go, and is designed to harvest passwords and drain all or part of the victim’s cryptocurrency wallets. The researchers note that this is “the first time we had seen malware capable of emptying a cryptocurrency wallet that could be used to remove any less than the entire wallet's value.”

Microsoft and Apple issue new security updates. 

Microsoft and Apple have released new security updates addressing multiple vulnerabilities across their product portfolios. Microsoft fixed more than a dozen flaws affecting Azure, Entra, SharePoint, Teams, Active Directory, and other products, including three critical remote code execution vulnerabilities with CVSS scores of 10. Apple, meanwhile, patched a high-severity authentication bypass issue, among other flaws.

Cryptography expert says new AI cryptanalysis results show promise, but not an AES breakthrough.

Cryptography expert Matthew Green argued in a recent blog post that Anthropic's recent cryptanalysis results are technically impressive but have been overstated in some media coverage. Green notes that while Claude helped discover improved attacks against the HAWK post-quantum signature scheme and a reduced 7-round version of AES, it did not break the full AES algorithm used in real-world encryption. The AES result is a modest improvement over prior academic work and remains far from practical, requiring unrealistic computational resources and chosen-plaintext access. Green's broader takeaway is that AI is becoming a valuable tool for cryptanalysis and security research, but these results do not signal that widely deployed encryption standards are suddenly at risk

 

Stick with us after the break we are joined by James Turgal, Optiv Security’s vice president, cyber risk, strategy and board relations, discussing how Iranian operators and their proxies appear to pursue disruption. And a Kentucky Fried Chicken order doxxes Chinese spyware operator.

I recently sat down with James Turgal, Optiv Security’s vice president, cyber risk, strategy and board relations, to discuss how Iranian operators and their proxies appear to pursue disruption by exploiting poorly secured operational technology in sectors such as water, energy, healthcare, and transportation. Here’s our conversation.

That was James Turgal, Optiv Security’s vice president, cyber risk, strategy and board relations discussing how Iranian operators and their proxies appear to pursue disruption.

 

Kentucky Fried Chicken order doxxes Chinese spyware operator.

Arctic Wolf researchers revealed at Black Hat that LightSpy, a spyware platform linked to China, has expanded far beyond its initial focus on mainland China and is now targeting victims in 13 countries, including the United States. The spyware has evolved into a commercial espionage platform capable of infecting smartphones, computers, Linux servers, and even routers, allowing operators to steal messages, passwords, precise location data, recordings, and other sensitive information. The tool can also remotely wipe compromised devices. 

Investigators uncovered evidence tying the operation to a Chinese contractor after an operator inadvertently exposed their identity while using the tool. According to TechCrunch, the operator used the LightSpy administrative panel to place an order with Kentucky Fried Chicken using his real name and work address.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
Be sure to check out Research Saturday tomorrow, where we are joined by Brian Hussey, SVP of Howler Cell Threat Services at Cyderes, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." That’s Research Saturday, check it out. 

T-Minus: Space-Cyber Briefing podcast plug. 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.