CyberWire Daily - Ring around the ransom.

Episode Date: August 7, 2026

Vishing attacks target hedge funds. Metabase Cloud breached by zero-day flaw. Cyberattack disrupts North Carolina Ports operations. The Chinese government has launched a security review of Palo Alto N...etworks products. US defense supplier breached by phishing attack. Healthcare software provider breach affected 3.8 million people. New macOS malware spreads via ClickFix attacks. Microsoft and Apple issue new security updates. Cryptography expert says new AI cryptanalysis results show promise, but not an AES breakthrough. James Turgal, Optiv Security’s vice president, cyber risk, strategy and board relations, is discussing how Iranian operators and their proxies appear to pursue disruption. And a Kentucky Fried Chicken order doxxes Chinese spyware operator. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today we are joined  by James Turgal, Optiv Security’s vice president, cyber risk, strategy and board relations, discussing how Iranian operators and their proxies appear to pursue disruption by exploiting poorly secured operational technology in sectors such as water, energy, healthcare, and transportation. Selected Reading Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group (BleepingComputer) Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments (GTIG) Cyberattack on North Carolina Ports ‘contained’ as Coast Guard, state officials investigate (The Record) China launches cybersecurity review into Palo Alto Networks products (Reuters) Attacker phished way into US defense supplier's Microsoft 365 account (The Register) Unlimited Technology Systems Data Breach Affects 3.8 Million Patients (HIPAA Journal) Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam (Huntress) China-linked LightSpy spyware caught targeting victims in 13 countries, including the US (TechCrunch) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. AI is making fishing attacks faster, more convincing, and harder for people to spot, and traditional security awareness and fishing training weren't designed for this level of attack. Hawkshunt helps security teams prepare employees for the attacks they face every day, with personalized fishing training that adapts to each employee and reduces risky behavior over time. For IT and security leaders looking to strengthen their human layer of defense without adding more manual work, visit hoxhunt.com slash cyberwire to learn more. That's hoxhunt-com slash cyberwire. Vishing attacks target hedge funds.
Starting point is 00:01:06 Metabase cloud breached by zero-day flaw. Cyber attack disrupts North Carolina ports operations. The Chinese government has launched a security review of Palo Alto now. OutWorks products. U.S. defense supplier breached by a fishing attack. Healthcare software provider breach affected 3.8 million people. New macOS malware spreads via ClickFix attacks. Microsoft and Apple issue new security updates.
Starting point is 00:01:32 Cryptography expert says new AI cryptanalysis results show promise, but not an AES breakthrough. James Turgel, Optiv Securities Vice President, Cyber Risk, Strategy, and Board Relations is discussing how Iranian operators and their proxies appear to pursue disruption. And the Kentucky Fried Chicken Order Dox's Chinese spyware operator. Yeah. Today is August 7th, 2026th. I'm Maria Vermazes, and this is your Cyberwire Intel briefing. Hello, everyone. Happy Friday, and thank you for joining me. Dave Bittner is out as he's recovering from a very busy week at Black Hat in Las Vegas. In the meantime, let's dive into today's Intel briefing. First up, Google's Threat Intelligence Group has linked
Starting point is 00:02:45 recent cyber attacks targeting hedge funds, private equity firms, and other financial organizations to the UNC 6671 extortion group, formerly known as Blackfile. The group is using help desk impersonation and voice fishing to compromise Microsoft 365 and Octa accounts, then targeting cloud services to steal sensitive data for extortion. Notably, the threat actors often target employees' personal mobile devices. Writers cites sources as saying the campaign has targeted 0.72, Millennium Management, 2 Sigma Investments, Citadel, and several other private equity firms. Google's researchers note that concentrating on organizations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data
Starting point is 00:03:33 to maximize leverage extortion demands. Metabase disclosed a security incident involving a zero-day vulnerability that affected some Metabase Cloud customers. The company detected the attack, patched the issue, and began an investigation with external forensic support. Affected customers are being notified and should rotate credentials for connected databases, review admin accounts, and check logs for suspicious activity. The company stated, after gaining access to your instance, the attacker could inject arbitrary SQL against the Metabase application database, which can give them administrator access to the instance.
Starting point is 00:04:11 From there, the attacker could change your application configuration, steel stored credentials for your connected databases, read any data accessible through those connections, and export data. North Carolina ports is recovering from a cyber attack that disrupted operations across its three port facilities, forcing staff to switch to manual processes. Officials say that the breach has been contained, and the Coast Guard and state agencies are investigating the incident.
Starting point is 00:04:38 The attack disrupted port operations at Wilmington, Moorhead City, and Charlotte. A spokesperson for North Carolina ports told the record that the facilities are now following a normal operating schedule, but companies should expect delays as the ports are still relying on manual operations. China has launched a cybersecurity review of Palo Alto Networks products, citing national security concerns. The cyberspace administration of China initiated the review but did not disclose which products were involved or if any vulnerabilities were identified. writers notes that the move echoes China's review of Micron in 2023,
Starting point is 00:05:16 which eventually led to restrictions on the chipmaker's products. Palo Alto has an established presence in the Chinese market with offices in Beijing, Shanghai, Guangzhou, Shenzhen, and Macau. IEH Corporation, which is a U.S. defense and aerospace supplier, disclosed that a fishing attack against an employee allowed an attacker to access the company's Microsoft 365 mailbox. The compromised account contained emails, engineering documents, customer communications, purchase orders, and potentially export-controlled technical information.
Starting point is 00:05:50 While IEH says it has no evidence that the data was exfiltrated, the attacker had access to the information during the compromise. The company is continuing to investigate the incident. A cyber attack against Ohio-based healthcare software provider unlimited technology systems has exposed the personal and medical information of 3.8 million people. Stolen data may include names, social security numbers, dates of birth, diagnoses, treatment details, insurance information, and other sensitive health records. The company says that the breach occurred in October 2025. The HIPAA Journal notes that this is the largest confirmed health care data breach of 2026 so far. Huntress has identified a new macOS malware campaign targeting cryptocurrency wallets, browser credentials, Apple keychain data,
Starting point is 00:06:41 other sensitive information. The malware is delivered via ClickFix social engineering attacks that pose as captcha prompts. The malware is written in Go and is designed to harvest passwords and drain all or part of the victim's cryptocurrency wallets. The researchers note that this is the first time we had seen malware capable of emptying a cryptocurrency wallet that could be used to remove any less than the entire wallet's value. Microsoft and Apple have released new security updates addressing multiple vulnerabilities across their product portfolios. Microsoft fixed more than a dozen flaws affecting Azure, Entra, SharePoint, Teams, Active Directory, and other products, including three critical remote code execution
Starting point is 00:07:25 vulnerabilities with CVS scores of 10. Apple, meanwhile, patched a high-severity authentication bypass issue, among other flaws. Cryptography expert Matthew Green argued in a recent blog post that Anthropics' recent cryptanalysis results are technically impressive, but have been overstated in some media coverage. Green notes that while Claude helped discover improved attacks against the Hawk post-quantum signature scheme and a reduced seven-round version of AES, it did not break the full AES algorithm used in real-world encryption. The AES result is a modest improvement over prior academic work and remains far from practical, requiring unrealistic computational resources and chosen plaintext
Starting point is 00:08:10 access. Green's broader takeaway is that AI is becoming a valuable tool for cryptanalysis and security research, but these results do not signal that widely deployed encryption standards are suddenly at risk. Stick with us now after the break, where we are joined by James Turgel, Optiv Securities Vice President, Cyber Risk Strategy, and Board Relations discussing how Iranian operators and their proxies appear to pursue disruption. And a Kentucky Fried Chicken Order, Dox's Chinese spyware operator. What's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is another opportunity for something to go wrong. And most security programs weren't built to keep up with
Starting point is 00:09:23 AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform, trusted by more than 16,000 fast-moving companies like Ramp, Hursor, and Harvey to help them stay audit-ready. And now Vanta helps companies like yours keep an eye on the risks that appear between audits across your vendors, your AI tools, and your entire environment. The Vanta agent works like a 24-7 GRC engineer in the background. It finds it. issues, drafts fixes for you, and can cut vendor assessment time by up to 50%. Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today at vanta.com slash cyber. That's V-A-T-A-com
Starting point is 00:10:17 slash cyber. I recently spoke with James Turgel, who is Optiv Security's Vice President, Cyber Risk Strategy and Board Relations, to discuss how Iranian operators and their proxies appear to pursue disruption by exploiting poorly secured operational technology in sectors such as water, energy,
Starting point is 00:10:46 health care, and transportation. Here's our conversation. Unfortunately, this is absolutely within the wheelhouse of Iran and their proxies. right you know you've got a number of recent attacks i think as of right now it's about 12 states that we've seen reported recent you know water treatment attacks but this started actually going back to 2022 2023 when there were a number of smaller scale attacks and probings by uh iran and their proxies specifically the cyber avengers group that they call themselves which i laugh when i have to
Starting point is 00:11:23 say that. But it is a, it's a group and a number of their proxies that are trying to probe the operational technology aspects of U.S. water systems. And so they've, they've gotten a little bit better at it, you know, since 2023. Certainly the, the military action of the war in Iran has, you know, expedited their intent to cause disruption. So, you know, the 2023 attacks were really about defacements. They were about probing the systems. They were low-level types of attacks. This is because
Starting point is 00:11:59 of the most recent attacks and more likely because of the Iran War and all of the military action, these are specifically into, this is disruption. This is a highly sophisticated disruption campaign.
Starting point is 00:12:16 Yeah. So we're seeing a progression then in terms of intent, I suppose, and capabilities, is there also sort of a perfect storm maybe that's going on in terms of our ability to defend from these kinds of attacks or have our capabilities not kept up with the needs there? Well, you know, certainly there is an argument to be made that, you know, you everybody, no matter who you are, whether your financial services or you're a local municipal water company could spend more money and have more people working on cyber and working on cyber defense. clearly it's one of those things that you have your fortune 500 companies that spend you know billions of dollars a year
Starting point is 00:12:55 unfortunately you don't have that with the smaller municipal and county water systems they are you know older systems they are systems where they haven't spent a lot of money on them they are usually you have one or two cyber folks that that originally built the system it's a a problem of both historical type of systems. It is, I know, unfortunately, one of those situations where you have a number of vendors and right now you have an opportunistic threat actor who's taking a look at what those vulnerabilities are. Because unfortunately, if you don't spend a lot of money on cyber and you don't, you know,
Starting point is 00:13:35 spend a lot, you don't have great cyber hygiene, right? You end up with things like default vendor passwords and shared, you know, engineering passwords and weak or no passwords, right? And so you've got these forward internet-facing program logic controllers and all types of internet-facing items, devices, that, you know, threat actors, including Iran, can utilize AI and other tools to scan for and then, you know, actually attack. You mentioned a couple of possibilities in there.
Starting point is 00:14:06 Do we know or what do we know about the nature of these specific recent attacks in terms of their sophistication or anything. What do we know? I should start there. Yeah, so of the attacks that we know now, right, Minnesota, Michigan, Georgia, New Jersey, those are the ones that have been widely reported. Most of them are what I talked about earlier, right?
Starting point is 00:14:28 The programmable logic controllers, most of this is, you know, malicious access to these systems. Because what are these systems do? They allow municipalities to remotely monitor control the water equipment. So these programmable logic controllers not only and take care of the flow, but they really more importantly take care of what are the chemicals used to actually treat these, the water, right, and actually make it so that, you know, you can drink it.
Starting point is 00:14:59 And so what we've seen is this is not really a, it's not actions taken on the billing systems or the email or the administrative networks. it's really on the operational technology piece, you know, these controllers. And so that tells me, right, as a trained investigator, this is really about a disruption campaign. You know, the Iran and the proxies are not going after the, you know, the PII, you know, the personally identifiable information. They're not, you know, engaging in ransom where they're not taking the information. They're not ransoming it or encrypting it.
Starting point is 00:15:34 This is about a disruption campaign. This is about making a statement to see a. if they can take down or monitor, certainly monitor, but take down or disrupt these water systems. Yeah, and I can imagine if this is something of a shot across the bow that maybe we should be anticipating more incoming. So along those lines, whether or not that's the case, I imagine many industries really need to be standing up and paying special close attention right now. Who needs to be really taking notice and what do they need to be doing? So right in the aftermath of the bombing that started, the military action that started back in February, you know, I've been meeting with all of our clients and certainly their boards of directors to get them to understand, right? The world has changed, right? You have, you know, not only do you have an organization that are, you know, coming after our water treatment facilities, right? You've had Iran and their proxies that have kind of changed the rules of, you know, what I call asymmetric warfare.
Starting point is 00:16:37 So you've got Iran and their proxies that are not only coming after our water treatment facilities and certainly municipal types of services to U.S. citizens, but you also have them sending bombs and drones against data centers in the Middle East as well. So now you're talking about a situation where it data becomes, right, that particular item where if you're bombing a data center, if you're bombing any types of those cloud data centers in the Middle East, you have U.S. data that's transiting those. So it's not just about the physical aspects of a particular, you know,
Starting point is 00:17:18 municipality or water treatment facility. It's literally the data that we utilize to run our businesses, you know, in our country if they're happening to transit through that particular area. So it's a much broader campaign. And so certainly everybody needs to, it doesn't matter who you are, whether you're, you know, a large financial institution, whether you're a manufacturer. You know, certainly everybody needs to be vigilant. But clearly, Iran right now is focused on this disruption campaign, which should really be getting everybody to understand if you're a state, a local, a municipal, you're a county and you have services, whether it's, you know, I've seen Iran, modify these different types of attacks to, you know, try to execute them against, you know, police and county systems. So, so it is, it's right now they're focused on the disruption
Starting point is 00:18:15 of the water treatment facilities, but this will morph into other types of disruption campaigns as well. Yeah. And I'm wondering, is the, is the advice that we should be giving people to think about, you know, security hygiene, which is always much harder done than said, or are we thinking this is APTs type stuff? Like, you know, do we know what's going on with that? Yeah, so, I mean, I have a high degree of confidence that this absolutely is, you know, Iran and their proxies. So this is a nation state, right? This is an advanced persistent threat in APT.
Starting point is 00:18:51 It's the sophistication of, you know, Iran's ability and their proxy's ability to carry these out, right? It ebbs and flows, right? you're not, you know, Iran is not on the level of a China or Russia as far as an advanced, persistent threat, nation state, you know, attack ability. But certainly they have, you know, the ability to carry out some sophisticated attacks. But really, this is more, this is selective disruption, right? This is trying to cause an economic cost. In their eyes, right, they're trying to put some kind of public fear factor here to say, hey, we can, we can attack you. your water system. So it's a, it's really a series of small visible incidents. Just trying to generate that,
Starting point is 00:19:39 you know, a little bit of the, hey, we can get to you kind of compromise. Again, you know, we have, you know, all of these, even though most, the smallest municipalities have a number of different backup systems and they always have fail-safe systems with, that can go to manual. And we've seen that response and resilience piece from, from the victims as well. So, you know, No, it's not going to affect our water system. It's really trying to get a little bit of a fear factor. That was James Turgel, Optive Securities Vice President, Cyber Risk Strategy and Board Relations, discussing how Iranian operators and their proxies appear to pursue disruption.
Starting point is 00:20:22 And lastly, Arctic Wolf researchers revealed that Black Hat this week that Light Spy, a spyware platform linked to China, has expanded, far beyond its initial focus on mainland China and is now targeting victims in 13 countries, including the United States. The spyware has evolved into a commercial espionage platform capable of infecting smartphones, computers, Linux servers, and even routers, allowing operators to steal messages, passwords, precise location data, recordings, and other sensitive information. The tool can also remotely wipe compromised devices. Investigators uncovered evidence tying the operation to a Chinese contractor after an operator inadvertently exposed their identity while using
Starting point is 00:21:23 the tool. According to TechCrunch, the operator used the light spy administrative panel to place an order with Kentucky fried chicken using his real name and work address. Nobody said criminals were super smart. And that's the Cyberwire. For links to all of today's stories, check out our daily briefing at thecyberwire.com. Be sure to check out research, Saturday tomorrow, where we are joined by Brian Hussie, SVP of Howler Sell Threat Services at Sideris, discussing their work on bad ads, worst binaries, fake Claude Code installer drops info dealer.
Starting point is 00:22:06 That's Research Saturday. Check it out. And hello. Ethan Cook, producer and lead analyst of the T-minus and Kaviop podcast here. On this Sunday's T-minus space cyber briefing, Maria's interview with Jason Roberson of DeSalt Systems on Security for Satellite Design and Maintenance. That's Sunday on T-minus. Don't miss it. We'd love to know what you think of our podcast.
Starting point is 00:22:27 Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill up the survey in the show notes or send an email to Cyberwire at N2K.com. N2K's lead producer is Liz Stokes. We were mixed by Trey Hester with original music and sound design by Elliot Piltzman. Our executive producer is Jennifer Ivan. Peter Kilphee is our publisher, and I'm Maria Varmazes in for host Dave Bittner today. Thanks for listening. Have a great weekend.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.