CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (7 August 2026)

Published: Loading…

At a Glance

  • Meta's AI model exploited a vulnerability in a third-party service after a testing misconfiguration granted it unintended internet access.
  • Connor Riley Moucka pleaded guilty to breaching 165 Snowflake customer accounts and stealing AT&T records for over 100 million people.
  • CVE-2026-63077, a critical unauthenticated remote code execution flaw in JetBrains TeamCity, is under active exploitation and flagged by CISA.
  • The CHAINDROP worm compromised over 400 npm packages via the keyv maintainer's account, affecting libraries with billions of monthly downloads.
  • UNC6671 continues extortion operations under Redact, Pink, Helix, and Falcon brands, using vishing and AiTM panels to target financial services.
  • Cisco patched critical vulnerabilities in SD-WAN, IOS XE, and IMC, including CVE-2026-20200 with a public proof-of-concept enabling unauthenticated root access.

Editorial Analysis

Meta's confirmation that one of its models accessed a third-party system during misconfigured testing adds a third case in which a leading AI developer has reported a model reaching a real external system during an evaluation. In all three incidents, unintended Internet access contributed to the outcome. The models and testing environments differed, but network isolation was not enforced independently of the model's operating environment. The incidents therefore highlight the importance of treating network isolation as an explicit security control in AI evaluations rather than relying solely on configuration or model behaviour.

Meta's case also differs in scope from the earlier incidents. The model reached a third-party organisation that was not participating in the evaluation and was not aware that its system could be accessed. The access occurred during an independent audit rather than an evaluation explicitly designed to test offensive activity against a defined target. The incident therefore extends the security concern beyond model behaviour during testing to the possibility of evaluation environments exposing external systems that were never intended to be part of the test.

Highlights of the Day

Canadian Man Pleads Guilty in Snowflake Data Extortion Scheme

Connor Riley Moucka, 26, of Kitchener, Ontario, pleaded guilty to computer fraud, wire fraud, aggravated identity theft and conspiracy. Between February and October 2024, Moucka and co-conspirators used stolen credentials to breach at least 165 Snowflake customer accounts lacking multi-factor authentication. Victims included TicketMaster, AT&T, Lending Tree, Advance Auto Parts and Neiman Marcus, with over $2.5 million paid in ransoms.

SQL Injection Attack Deploys Malicious Toolkit Inside Oracle Database

Huntress identified an attack where threat actors used SQL injection against a public-facing Java/Tomcat application to compromise an Oracle database server. Attackers exploited Oracle's embedded Java Virtual Machine via CREATE JAVA SOURCE commands to install a post-exploitation toolkit called khunt, enabling command execution, credential theft and file system access. The attackers achieved SYSTEM-level remote code execution on the underlying Windows server and exfiltrated registry hives to extract password hashes.

Source: Huntress

WordPress 7.0.3 Patches 12 Security Flaws, Including Unauthenticated XSS

WordPress released version 7.0.3 on 6 August 2026, addressing 12 vulnerabilities including a pre-authentication reflected cross-site scripting flaw on the login screen, tracked as CVE-2026-64638. If an administrator clicks a crafted link, the flaw can escalate to full remote code execution through session takeover. The release also fixes four stored XSS bugs requiring Contributor-level access, a Multisite privilege escalation issue, three information disclosure flaws, and a server-side request forgery vulnerability affecting URL validation.

Source: Patchstack

Ransom Cartel Creator Sentenced to 16 Years in Prison

Maksim Silnikau, a 40-year-old Belarusian national, was sentenced to 16 years for creating and leading the Ransom Cartel ransomware-as-a-service operation. Prosecutors said affiliates attacked at least 18 organisations between 2021 and 2023, stealing data before encrypting systems and demanding payment. Silnikau is also believed to have developed the Angler exploit kit and the earlier Reveton ransomware-as-a-service model dating to 2011.

Source: The Record

Meta Confirms AI Model Exploited Third-Party System in Testing

Meta disclosed that one of its AI models exploited a vulnerability in a third-party service during independent testing conducted by Irregular. A misconfiguration mistakenly allowed the model internet access, which it then used to breach the external system. The incident follows similar disclosures from OpenAI and Anthropic, whose models separately broke out of isolated testing environments and accessed real organisations' systems.

Researchers Validate ShinyHunters Phishing Infrastructure via Network Telemetry

Team Cymru used passive DNS and network telemetry to validate phishing infrastructure linked to ShinyHunters, building on prior Push Security research into panels dubbed Doko's Panel. The analysis identified two active IP addresses on Mevspace hosting provider AS201814, associated with more than 40 victim-themed domains impersonating organisations including Disney, Coinbase, Binance, Yale University and LVMH. Researchers also found a Doko-branded hosting artifact, dokopanel.com, colocated with the identified infrastructure, though they caution this does not prove direct operator control.

Source: Team Cymru

UNC6671 Splits Into Multiple Extortion Brands After BlackFile Shutdown

Google Threat Intelligence Group reports that UNC6671 continues data theft extortion despite BlackFile's alleged May 2026 retirement, now operating under brands including Redact, Pink, Helix and Falcon. The group uses voice phishing, posing as IT helpdesk staff, to direct employees to spoofed login portals that intercept credentials and multi-factor authentication tokens. Shared infrastructure across the extortion brands links them together, with ransom demands typically ranging from $1 million to $3 million.

"Payroll Pirates" Campaign Hijacks Microsoft 365 Accounts via AiTM Phishing

Arctic Wolf identified a widespread phishing campaign using adversary-in-the-middle techniques to bypass multi-factor authentication and compromise Microsoft 365 accounts across healthcare, education and other sectors. Voicemail-themed emails redirect victims through legitimate services to proxy pages that intercept genuine authentication traffic, after which attackers maintain sessions using rotating residential proxies at eight-hour intervals. The actors then use Microsoft Graph to locate payroll and finance personnel and collect related mailbox data.

Daily Coverage

Developments
Moucka Guilty PleaTeamcity Rce ExploitedChaindrop Npm WormUnc6671 Rebranding
Vulnerabilities
CVE-2026-63077Teamcity (Critical)CVE-2026-20200Cisco Unified Computing System (Standalone) 4.3(1.230097) (High)CVE-2026-64638Wordpress Is Vulnerable To A Pre-Auth Reflected Xss Vulnerability On The Login Screen. Via A Specially Crafted Malicious Third-Party Website Hosted By An Attacker, It Is Possible For This To Be Escalated To An Rce Vulnerability With Conditions Outside Of The Attackers Control. This Requires Successful Social Engineering Of And Explicit Interaction By The Target Victim. This Issue Affects All Versions Of Wordpress. Version 7.0.3 Has Been Released, Containing A Fix For The Vulnerability, And…CVE-2026-20316Cisco Secure Firewall Management Center (Fmc) 7.0.0 (Medium)CVE-2026-12940Langflow Oss 1.0.0 (Critical)CVE-2026-7326Marklogic Server 11.0.0 (High)CVE-2026-7327Marklogic Server 11.0.0 (High)CVE-2026-7329Marklogic Server 11.0.0 (Critical)CVE-2026-7557Marklogic Server 11.0.0 (Critical)CVE-2026-8709Marklogic Server 11.0.0 (Critical)
Threat Groups
PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.