Loading summary
A
You're listening to the Cyberwire Network, powered by N2K.
B
Maybe that's an urgent email from your CEO, or maybe it's a deepfake targeting your business. Doppel is the AI native social engineering defense platform, fighting back against impersonation and manipulation. As attackers use AI to make their tactics more sophisticated, Doppel uses it to fight back, automatically dismantling cross channel attacks, building team resilience and providing agentic email protection. Doppel outpacing what's next in social engineering? Learn more@doppel.com that'S-O-P-P-E-L.com.
A
Phishing attacks target hedge funds Metabase cloud breached by zero day flaw cyber attack disrupts North Carolina ports operations the Chinese government has launched a security review of Palo Alto Networks products. US Defense supplier breached by a phishing attack Healthcare software provider breach affected 3.8 million people New macOS malware spreads via click fix attacks Microsoft and Apple issue new security updates Cryptography expert says new AI cryptanalysis results show promise but not an AES breakthrough James Turgel, Optiv Securities Vice President, Cyber Risk Strategy and Board Relations, is discussing how Iranian operators and their proxies appear to pursue disruption and the Kentucky Fried Chicken order Doxes Chinese spyware operator. Today is August 7th, 2026. I'm Maria Varmazes and this is your Cyberwire Intel Brief.
B
Foreign
A
Happy Friday and thank you for joining me. Dave Bittner is out as he's recovering from a very busy week at Black Hat in Las Vegas. In the meantime, let's dive into today's intel briefing. First up, Google's Threat Intelligence Group has linked recent cyber attacks targeting hedge funds, private equity firms and other financial organizations to the UNC6671 extortion group, formerly known as Blackfile. The group is using help desk impersonation and voice phishing to compromise Microsoft 365 and Okta accounts, then targeting cloud services to steal sensitive data for extortion. Notably, the threat actors often target employees personal mobile devices. Reuters cites sources as saying the campaign has targeted 0.72 Millennium Management, Two Sigma Investments, Citadel and several other private equity firms. Google's researchers note that concentrating on organizations involved in mergers, acquisitions, capital deployment and litigation may reflect a strategy to target high value corporate and confidential data to maximize leverage extortion demands. Metabase disclosed a security incident involving a zero day vulnerability that affected some Metabase Cloud customers. The company detected the attack, patched the issue and began an investigation with external forensic support. Affected customers are being notified and should rotate credentials for connected databases, review admin accounts and check logs for suspicious activity, the company stated. After gaining access to your instance, the attacker could inject arbitrary SQL against the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change your application configuration, steal stored credentials for your connected databases, read any data accessible through those connections, and export data. North Carolina Ports is recovering from a cyber attack that disrupted operations across its three port facilities, forcing staff to switch to manual processes. Officials say that the breach has been contained and the Coast Guard and state agencies are investigating the incident. The attack disrupted port operations at Wilmington, Moorhead City and Charlotte. A spokesperson for North Carolina Ports told the Record that the facilities are now following a normal operating schedule, but companies should expect delays as the ports are still relying on manual operations. China has launched a cybersecurity review of Palo Alto Networks products, citing national security concerns. The Cyberspace Administration of China initiated the review but did not disclose which products were involved or or if any vulnerabilities were identified. Reuters notes that the move echoes China's review of micron in 2023, which eventually led to restrictions on the chip maker's products. Palo Alto has an established presence in the Chinese market, with offices in Beijing, Shanghai, Guangzhou, Shenzhen and Macau. I Corporation, which is a US Defense and aerospace supplier, disclosed that a phishing attack against an employee allowed an attacker to Access the company's Microsoft 365 mailbox. The compromised account contained emails, engineering documents, customer communications, purchase orders and potentially export controlled technical information. While IEH says it has no evidence that the data was exfiltrated, the attacker had access to the information during the compromise. The company is continuing to investigate the incident. A cyber attack against Ohio based healthcare software provider Unlimited Technology Systems has exposed the personal and medical information of 3.8 million people. Stolen data may include names, Social Security numbers, dates of birth, diagnoses, treatment details, insurance information and other sensitive health records. The company says that the breach occurred in October 2025. The HIPAA Journal notes that this is the largest confirmed healthcare Data breach of 2026 so far. Huntress has identified a new macOS malware campaign targeting cryptocurrency wallets, browser credentials, Apple keychain data and other sensitive information. The malware is delivered via click fix social engineering attacks that pose as captcha prompts. The malware is written in go and is designed to harvest passwords and drain all or part of the victim's cryptocurrency wallets. The researchers note that this is the first time we had seen malware capable of emptying a cryptocurrency wallet that could be used to remove any less than the entire wallet's value. Microsoft and Apple have released new security updates addressing multiple vulnerabilities across their product portfolios. Microsoft fixed more than a dozen flaws affecting Azure, Entra, SharePoint Teams, Active Directory and other products, including three critical remote code execution vulnerabilities with CVSS scores of 10. Apple, meanwhile, patched a high severity authentication bypass issue, among other flaws. Cryptography expert Matthew Green argued in a recent blog post that Anthropic's recent cryptanalysis results are technically impressive but have been overstated in some media coverage. Green notes that while Claude helped discover improved attacks against the Hawk Post Quantum Signature Scheme and a reduced seven round version of AES, it did not break the full AES algorithm used in real world encryption. The AES result is a modest improvement over prior academic work and remains far from practical, requiring unrealistic computational resources and chosen plaintext access. Green's broader takeaway is that AI is becoming a valuable tool for cryptanalysis and security research, but these results do not signal that widely deployed encryption standards are suddenly at risk. Stick with us now after the break, where we are joined by James Turgel, Optiv Security's Vice President, Cyber Risk Strategy and Board Relations, discussing how Iranian operators and their proxies appear to pursue disruption and a Kentucky Fried Chicken order Doxes Chinese spyware operator.
B
Foreign. Is making phishing attacks faster, more convincing and harder for people to spot, and traditional security awareness and phishing training weren't designed for this level of attack. HOX Hunt helps security teams prepare employees for the attacks they face every day with personalized phishing training that adapts to each employee and reduces risky behavior over time for IT and security leaders looking to strengthen their human layer of defense without adding more manual work. Visit hoxhunt.com cyberwire to learn more. That's h o x h-u n t.com cyberwire.
A
I recently spoke with James Turgil, who is Optiv Securities Vice President, Cyber Risk Strategy and Board Relations, to discuss how Iranian operators and their proxies appear to pursue disruption by exploiting poorly secured operational technology in sectors such as water, energy, healthcare, and transportation. Here's our conversation.
C
Unfortunately, this is absolutely within the wheelhouse of Iran and their proxies, right? You know you've got a number of recent attacks. I think as of right now it's about 12 states that we've seen reported recent, you know, water treatment attacks. But this started actually going back to 2022, 2023, when there were a number of smaller scale attacks and probings by Iran and their proxies, specifically the Cyber Avengers group that they call themselves, which I laugh when I have to say that, but it is a, it's a, it's a group and a number of their proxies that are trying to probe the operational technology aspects of US Water systems. And so they've gotten a little bit better at it since 2023. Certainly the military action in the war in Iran has expedited their intent to cause disruption. So the 2023 attacks were really about defacements, they were about probing the systems. They were low level types of attacks. This is because of the most recent attacks and more likely because of the, you know, the Iran war and all of the military action. These are specifically into. This is disruption. This is, you know, a highly, highly sophisticated disruption campaign.
A
Yeah. So we're seeing a progression then in terms of intent, I suppose, and capabilities. Is there also sort of a perfect storm maybe that's going on in terms of our ability to defend from these kinds of attacks? Have our capabilities not kept up with the needs there?
C
Well, you know, certainly there is, there is an argument to be made that you know, you, everybody, no matter who you are, whether you're financial services or you're a, you know, a local municipal water company could spend more money and have more people working on cyber and working on cyber defense. Clearly it's one of those things that you have Fortune 500 companies that spend billions of dollars a year. Unfortunately you don't have that with the smaller municipal and county water systems. They are older systems. They are systems where they haven't spent a lot of money on them. They are usually you have one or two cyber folks that originally built the system. It's a problem of both historical type of systems. It is, I know, unfortunately, one of those situations where you have a number of vendors and right now you have an opportunistic threat actor who's taking a look at what those vulnerabilities are. Because unfortunately if you don't spend a lot of money on cyber and you don't spend a lot, you don't have great cyber hygiene. You end up with things like default vendor passwords and shared engineering passwords or weak or no passwords. Right. And so you've got these forward Internet facing program logic controllers and all types of Internet facing items, devices that threat actors, including Iran, can utilize AI and other tools to scan for and then actually attack.
A
You mentioned a couple of possibilities in there do we know or what do we know about the nature of these specific recent attacks in terms of their sophistication or anything? What, what do we know? I should start there.
C
Yeah. So of the, of the attacks that we know now, right, Minnesota, Michigan, Georgia, New Jersey, those are the ones that have been widely reported. Most of them are what I talked about earlier. Right. The programmable logic controllers. Most of this is, you know, malicious access to these systems. Because what, what do these systems do? They allow municipalities to remotely monitor and control the water equipment. Right. So these programmable logic controllers not only take care of the flow, but they really, more importantly, take care of what are the chemicals used to actually treat these, the water. Right. And actually make it so that, you know, you can drink it. And so what we've seen is this is not really a, it's not actions taken on the billing systems or the email or the administrative networks. It's really on the operational technology piece, you know, these controllers. And so that tells me, right, as a trained investigator, this is really about a disruption campaign. You know, the Iran and the proxies are not going after the, you know, the pii, you know, the personally identifiable information. They're not, you know, engaging in ransomware. They're not taking the information. They're not ransoming it or encrypting it. Right. This is about a disruption campaign. This is about making a statement to see if they can take down or certainly monitor, but take down or disrupt these water systems.
A
Yeah. And I can imagine if this is something of a shot across the bow, that maybe we should be anticipating more incoming. So along those lines, whether or not that's the case, I imagine many industries really need to be standing up and paying special close attention right now. Who needs to be really taking notice and what do they need to be doing?
C
So, right. In the aftermath of the bombing that started the military action that started back in February, I've been meeting with all of our clients and certainly their boards of directors to get them to understand the world has changed. Not only do you have organizations that are coming after our water treatment facilities. Right. You've got Iran and their proxies that have kind of changed the rules of what I call asymmetric warfare. So you've got Iran and their proxies that are not only coming after our water treatment facilities and certainly municipal types of services to US Citizens, but you also have them sending bombs and drones against data centers in the Middle east as well. So now you're talking about a, a situation where it's data becomes that particular item where if you're bombing a data center, if you're bombing any types of those cloud data centers in the Middle east, you have US Data that's transiting those. So it's not just about the physical aspects of a particular municipality or water treatment facility. It's literally the data that we utilize to, to run our businesses, you know, in our country, if they're happening to, happening to transit through that particular area. So it's a much broader campaign. And so certainly everybody needs to, it doesn't matter who you are, whether you're, you know, a large financial institution, whether you're a manufacturer, you know, certainly everybody needs to be vigilant. But clearly Iran right now is focused on this disruption campaign which should really be getting everybody to understand if you are a state, a local, a municipal, you're a county and you have services, whether it's, you know, I've seen Iran modify these different types of attacks to, you know, try to execute them against, you know, police and county systems. So, so it is, it's right now they're focused on the disruption of the water treatment facilities, but this will morph into other types of disruption campaigns as well.
A
Yeah. And I'm wondering is the, is the advice that we should be giving people to think about, you know, security, hygiene, which is always much harder done than said, or are we thinking this is APT type stuff? You know, do we know what's, what's going on with that?
C
Yeah. So I mean, I have, I have a high degree of confidence that this absolutely is, you know, Iran and their proxies. So this is, this is a nation state. Right. This is an advanced persistent threat in apt. It's the sophistication of Iran's ability and their proxies ability to carry these out. Right. It ebbs and flows. Right. You're not, you know, Iran is not on the level of a China or a Russia as far as an advanced persistent threat nation state, you know, attack ability. But certainly they have, you know, the ability to carry out some sophisticated attacks. But really this is more, this is selective disruption. Right. This is trying to cause an economic cost in their eyes. They're trying to put some kind of public fear factor here to say, hey, we can attack your water system. So it's really a series of small visible incidents just trying to generate a little bit of the, hey, we can get to, you know, kind of compromise again. You know, we have, you know, all of these, even the most, the smallest municipalities have a number of different backup systems and they always have fail safe systems with that can go to manual. And we've seen that response and resilience piece from, from the victims as well. So you know, no, it's not gonna, it's not gonna, you know, affect our water system. It's really trying to, to get, get a little bit of a fear factor.
A
That was James Turgel, Optiv Securities Vice President, Cyber Risk Strategy and Board Relations, discussing how Iranian operators and their proxies appear to pursue disruption.
B
What's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for. Every vendor that turns on AI features, every new integration, each one is another opportunity for something to go wrong. And most security programs weren't built to keep up with AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform trusted by more than 16,000 fast moving companies like Ramp, Purser and Harvey to help them stay audit ready. And now Vanta helps companies like yours keep an eye on the risks that appear between audits across your vendors, your AI tools and your entire environment. The Vanta Agent works like a 24.7grc engineer. In the background, it finds, issues, drafts, fixes for you and can cut vendor assessment time by up to 50%. Whether you're a fast growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today@vanta.com cyber that's V A N T A dot com cyber.
A
And lastly, Arctic Wolf. Researchers revealed at Black Hat this week that LightSpy, a spyware platform linked to China, has expanded far beyond its initial focus on mainland China and is now targeting victims in 13 countries, including the United States. The spyware has evolved into a commercial espionage platform capable of infecting smartphones, computers, Linux servers and even routers, allowing operators to steal messages, passwords, precise location data recordings and other sensitive information. The tool can also remotely wipe compromised devices. Investigators uncovered evidence tying the operation to a Chinese contractor after an operator inadvertently exposed their identity while using the tool. According to TechCrunch, the operator used the LightSpy administrative panel to place an order with Kentucky Fried Chicken using his real name and work address. Nobody said criminals were super smart. And that's the Cyber Wire. For links to all of today's stories, check out our daily briefing@thecyberwire.com be sure to check out Research Saturday tomorrow, where we are joined by Brian Hussey, SVP of Howler Cell Threat Services at Slideris, discussing their work on bad ads, worse binaries, fake Claude code installer drops, info stealer. That's research Saturday. Check it out.
C
And hello, Ethan Cook, producer and lead analyst of the T Minus and Caveat podcast here on this Sunday's T Minus Space Cyber Briefing, Maria's interview with Jason Roberson of Dassault Systems on security for satellite design and maintenance. That's Sunday on T Minus. Don't miss it.
A
We'd love to know what you think of our podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com N2K's lead producer is Liz Stokes. We are mixed by Trey Hester with original music and sound design by Elliot Piltzman. Our executive producer is Jennifer Ivan. Peter Kilpe is our publisher and I'm Maria Varmazes in for host Dave Buettner today. Thanks for listening. Have a great weekend.
Date: August 7, 2026
Host: Maria Varmazes (in for Dave Bittner)
Podcast: CyberWire Daily
Episode Theme:
This episode delivers a comprehensive briefing on the latest in cybersecurity threats, breaches, and developments, including targeted attacks on the financial sector, major software vulnerabilities, nation-state cyber operations, and evolving malware tactics. A centerpiece interview with James Turgel of Optiv Security explores Iranian disruption campaigns targeting US operational technology, especially in water infrastructure.
[02:33-04:00]
[04:00-04:44]
[04:44-05:15]
[05:15-05:51]
[05:51-06:23]
[06:23-06:52]
[06:52-07:33]
[07:33-07:51]
[07:51-08:29]
Guest: James Turgel, VP, Cyber Risk Strategy and Board Relations, Optiv Security
[09:55-19:36]
[21:26-22:20]
"This is disruption. This is, you know, a highly, highly sophisticated disruption campaign."
— James Turgel on Iranian cyber tactics [10:50]
"It's a problem of both historical type of systems... it's one of those situations where you have a number of vendors and right now you have an opportunistic threat actor."
— James Turgel on OT vulnerabilities [12:10]
"No, it's not gonna ... affect our water system. It's really trying to get a little bit of a fear factor."
— James Turgel on the intent behind the attacks [18:34]
"Nobody said criminals were super smart."
— Maria Varmazes with a wry closing anecdote on Chinese spyware operator’s opsec fail [22:22]
For additional details and resources, visit thecyberwire.com.