Daily Recap, UNC6671’s vishing and hedge fund intrusion campaign has been tied to the BlackFile extortion crew, while North Carolina Ports reported a cyberattack that disrupted operations before investigators described it as contained. In other updates, a Swiss government SharePoint breach compromised 200 accounts, ClickFix is delivering a macOS infostealer for crypto theft, Cisco patched multiple SD-WAN and IOS XE flaws, and new CPU-side-channel research highlights Spectre v2 bypass paths via interrupt injection and TONTOU.
#UNC6671 #BlackFile #NorthCarolinaPorts #CoastGuard #SharePoint #SwissGovernment #Snowflake #RansomCartel #Zapscape #ZapscapeKVM #L1 #Cisco #SDWAN #IOSXE #SpectreV2 #Intel #AMD #ClickFix #TONTOU #InterruptInjection #LinuxPasswordHashes #RockwellControllers #Meta #AIModel #BlackHatUSA2026 #CapitolHill
#UNC6671 #BlackFile #NorthCarolinaPorts #CoastGuard #SharePoint #SwissGovernment #Snowflake #RansomCartel #Zapscape #ZapscapeKVM #L1 #Cisco #SDWAN #IOSXE #SpectreV2 #Intel #AMD #ClickFix #TONTOU #InterruptInjection #LinuxPasswordHashes #RockwellControllers #Meta #AIModel #BlackHatUSA2026 #CapitolHill
Intrusions & Extortion
- UNC6671’s vishing and hedge fund intrusion campaign has been linked to the BlackFile extortion crew, which reportedly made millions before rebranding. – UNC6671, Hedge Fund Attacks
- North Carolina Ports said a cyberattack disrupted operations but was later described as contained while Coast Guard and state officials investigate. – Ports Attack, Contained Probe
- A Swiss government SharePoint breach compromised 200 accounts, highlighting continued exposure of public-sector collaboration systems. – Swiss Breach
- The Snowflake hacker pleaded guilty in U.S. court, and the creator of Ransom Cartel was sentenced to 16 years in prison. – Snowflake Plea, Ransom Sentence
Vulnerabilities & Patches
- A new Zapscape KVM flaw could let a privileged L1 guest escape to Linux hosts, raising the risk of virtual-machine breakout. – Zapscape Flaw
- Cisco patched 12 SD-WAN and IOS XE flaws, including three 9.8 CVSS bugs with high exploitation impact. – Cisco Patches
- New interrupt injection and TONTOU CPU attacks can bypass Spectre v2 defenses on Intel and AMD chips, with the latter able to leak Linux password hashes. – Interrupt Attack, TONTOU Leak
- A truck brake controller safety recall also served as a hidden security fix, underscoring risks in embedded automotive systems. – Brake Recall
Scams, Malware & Credential Theft
- ClickFix attacks are pushing a macOS infostealer used for crypto theft, showing how social engineering continues to drive malware delivery. – ClickFix Malware
- Two H1 2026 attack chains used real emails to hijack payments, combining trusted communication with financial fraud. – Payment Hijack
- Meta said its AI model “hacked” a company during a misconfigured cyber test, exposing the security risks of poorly controlled AI red-teaming. – Meta AI Test
Critical Infrastructure & Policy
- Thousands of U.S. industrial controllers used in water systems remain exposed online despite federal warnings, and experts say the water sector still needs urgent defensive improvements. – Exposed Controllers, Water Wake-Up
- Capitol Hill is probing whether the executive branch and foreign allies are coordinating enough to combat transnational scams. – Scam Hearing
Industry Events & Announcements
- Black Hat USA 2026 vendor announcements continued to roll in, with the event highlighting new security products and updates from major vendors. – Black Hat