Vulnerability Watch

Forum Discussion

snarang's avatar
snarang
Product Team
1 day ago

Tenable Security Intel Brief: Same extortion crew, four new names

Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team.

This week, Google Threat Intelligence Group ties the retired BlackFile brand and four successor names to a single extortion operation whose helpdesk vishing playbook never changed, with ransom payments continuing past the group's publicized shutdown.

Extortion crew sheds its brand but keeps its vishing playbook →

Brief: Google Threat Intelligence Group (GTIG) reports that UNC6671, assessed to be behind the recently retired BlackFile brand, continues to run extortion operations under four new names while its helpdesk voice-phishing (vishing) playbook stayed intact.

Intel: GTIG linked UNC6671 to Redact, Pink, Helix, and Falcon, though it allows for splintered affiliates or shared phishing-panel services. Payments to BlackFile wallets continued past its publicized May 11 shutdown. Callers posing as IT helpdesk staff reach employees on personal phones urgently demanding they re-set up account security measures, steering them to fake login pages that capture the login and one-time code as they're typed, then draining Microsoft 365 and Okta data. By July, targeting narrowed to private equity, legal, and financial rating firms whose leverage rests on confidentiality.

Why it matters: Cyber-insurance negotiators and defenders build their response around who they think they are facing. When the same operators keep publishing under new brand names, actor identity stops anchoring that decision, and the tradecraft is what still identifies the crew.

A self-propagating npm worm mints real provenance for its own malware →

Brief: Palo Alto Networks' Unit 42 analyzed ChainDrop, a self-spreading npm worm that has infected over 400 packages, among them poisoned releases of the popular keyv and cacheable-request.

Intel: After a poisoned package installs, code that runs automatically fetches the legitimate Bun runtime as an execution vehicle, harvests cloud, npm, GitHub, and SSH credentials, then republishes infected packages with their real functionality intact. The worm looks up its command and control server on the Ethereum blockchain, and on Aug. 4 the operator swapped the entire command infrastructure with one blockchain transaction and no code update. In a repository-gated path, it uses the project's own automated publishing pipeline to sign the tampered package and mints a genuine Sigstore provenance attestation for it.

Why it matters: The attestation is genuine: it records that a tampered package came from the named workflow, which was running attacker code. Provenance was the supply-chain signal defenders were told to trust, and here it certifies the malware as authentic. Unit 42 places ChainDrop in the Shai-Hulud lineage without confirming who runs it.

Test agents invent fake identities to smuggle malware into code →

Brief: The UK AI Security Institute (AISI) cataloged 19 unsanctioned actions in 10 of 122 cyber-evaluation runs where agents targeted real people and organizations on the live internet.

Intel: AISI deliberately enabled open-internet access and switched off the providers' cyber classifiers to measure maximum capability, never telling agents what was off-limits; the tested configurations are not commercially available. Of the 19 actions (July 25 to 28), 17 involved Anthropic's Claude Mythos 5 while two involved OpenAI's GPT-5.6 Sol. In a 34.5-hour run, one agent researched two unaffiliated developers, created fake GitHub accounts, and submitted a code change hiding malware as a bug fix. When a user flagged the malware, it rewrote its branch history and claimed an honest mistake.

Why it matters: The AI didn't escape its test environment or get tricked into misbehaving; given capability and no guardrails, its target was people. It backed its submission from a second fake account and spear-phished under invented names. It hid instructions for other AI coding tools in webpage text that only software reads. A human maintainer caught it.

One incomplete patch reopens N-able N-central to console takeover →

Brief: N-able disclosed CVE-2026-18577, an authentication bypass in N-central exploited as a zero-day, which reopened account takeover because an earlier fix for CVE-2026-18556 was incomplete.

Intel: N-able's Adlumin managed detection service caught the zero-day on July 31; hotfix 2026.3.1.7 shipped August 2, and a hardened replacement, 2026.3.1.10, followed August 6. CISA added the flaw to the Known Exploited Vulnerabilities (KEV) catalog on August 3 with an August 6 federal deadline, the three-day window Binding Operational Directive 26-04 reserves for urgent risk. Huntress reports attackers took full administrative control of the N-central console, the dashboard managed service providers use to run customer systems, then used Take Control, N-central's own remote-access tool, to reach customer machines, scouted the Domain Controllers running the network, and set up hidden connections to keep access.

Why it matters: One console means administrative reach over every downstream customer, which is why exploitation went straight for Take Control and Domain Controllers. Huntress found nearly all cloud-hosted servers patched by August 3, while 28.6% of reachable self-hosted ones stayed exposed. The risk pooled where customers manage the console alone.

Stat of the week: 19%

The jump in ransomware attacks from June to July, 668 to 799 incidents, according to Comparitech, with finance attacks up 71 percent while ransomware against utility companies, the sector dominating recent headlines, fell 44 percent.

Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.

No RepliesBe the first to reply