Security & Threat Intelligence

The Watch

The Signal

UNC6671 poses as IT and gets employees to enroll the attacker's passkey themselves.

The pretext is the FIDO2 rollout your program is mid-flight on, so the enrollment window opened for security reasons is the one being worked. A service desk can legitimately initiate MFA enrollment, which leaves staff no decision rule to catch the call. Google traced $10.69M to the crew's wallets during the three months the retired BlackFile brand read as an all-clear. A retired brand is not a retired crew.

In Play

  1. Helpdesk-Initiated Passkey Enrollment Is Now the Pretext

    Today's items share one shape: adversaries stopped attacking products and started attacking the workflows wrapped around them — the enrollment path, the offboarding step, the token scope, the review cycle. None of those generate an advisory or blockable infrastructure. Start with the deep dive below, "The Enrollment Call Is the Attack": UNC6671, the identity-log detections, the passkey coverage gap and this week's policy edit are all there.

    Ask Clarity
    Try
  2. Command and Control Moved Into the Microsoft 365 Calendar

    Covered in the deep dive "The Only Sensor Left Is the Identity Log": the HollowGraph hunt signals in the unified audit log, and the tuning problem that gets calendar analytics switched off inside a fortnight.

    Ask Clarity
    Try
  3. A Breach That Finished in 87 Seconds Beat a 10-Minute Pipeline

    Also in "The Only Sensor Left Is the Identity Log": the 87-second clone, and the token-scope, IP-allowlist and rate-limit settings that would have made it impossible.

    Ask Clarity
    Try
  4. Exposed Industrial Controllers Are Being Found by Scanners, Not APTs

    The FBI and EPA confirmed attacks on water and wastewater utilities across at least 12 states since July 27, and CyberScoop reports over 4,000 Rockwell/Allen-Bradley PLCs still reachable from the public internet, including at cities already breached. Post-access behavior was process manipulation — setpoint changes and operator lockout — rather than data theft. There is no CVE in this chain; the exploited surface is asset inventory and ownership, which a patch-centric plan does not address. No deep dive covers this one, so schedule it yourself: enumerate every internet-reachable PLC you own this week and put it behind a VPN or remove the route.

    Ask Clarity
    Try
  5. AI Cryptanalysis Reprices Peer Review

    Covered in the deep dive "A NIST Finalist Fell in 60 Hours for $100,000": the withdrawal sequence on pqc-forum, the Stanford secure-code measurements, and the crypto-agility work to schedule this quarter.

    Ask Clarity
    Try

Deep Dives

The Enrollment Call Is the Attack

Brand-keyed threat intelligence handed out three months of false all-clear while the same crew kept working, and the pretext it uses is the security upgrade your program is mid-rollout on.

The rebrand is the intelligence failure

The actor is UNC6671, tracked by Google Threat Intelligence Group, previously operating the BlackFile extortion brand. Mechanism: calls to employees on personal mobile numbers, caller poses as IT, pushes urgent FIDO2 or passkey enrollment. The victim lands on a lookalike portal. Adversary-in-the-middle infrastructure captures Microsoft 365 and Okta credentials plus MFA tokens. Automated scripts then drain SaaS data. BlackFile announced retirement in May 2026 and never stopped operating. GTIG puts the same actor across four new brands: Redact, Pink, Helix and Falcon. Tradecraft unchanged. Yield unchanged: 141.65 BTC across 18 wallets. Every blocklist entry, feed filter and board slide keyed to the retired name reported clean for roughly a quarter while the operation ran continuously. An intel program that pivots on brand names rather than tradecraft and infrastructure patterns has just been graded, and that is the finding to write up.

Where the session persistence is actually visible

Exfiltration is automated once session persistence lands, so the egress point and downstream DLP see the aftermath, not the intrusion. The evidence sits in the identity provider log. Four detections are buildable against Entra ID and the Okta System Log:

  1. Token replay from a mismatched ASN or user-agent against a live session.
  2. New device or authenticator registration within minutes of a successful sign-in. The direct artifact of the enrollment pretext succeeding.
  3. Impossible travel with a valid MFA assertion, which the AitM proxy produces by construction.
  4. Refresh or OAuth token issuance from non-corporate IP space.

"We rolled out passkeys" is not a defense

The exploited gap is coverage, not technology. Phishing-resistant factors land on the primary identity provider first. Legacy tenants and identity providers inherited through acquisition keep OTP and push fallback enabled. An actor who reaches any one of those never has to defeat FIDO2. Disabling push and OTP fallback for privileged roles across every identity provider is the control; enrolling security keys on the main tenant is the project.

Three independent lines of reporting converge on voice

This is a delivery-channel shift, not one campaign. GTIG documents the helpdesk pretext arriving by phone to personal mobile numbers, outside corporate telephony and outside any mail gateway. Separately, a confirmed wave of AI voice phishing has hit major hedge funds. Voice-preserving translation across 90+ languages is now a production API, which retires the accent and language heuristics staff rely on and never wrote down. CyberScoop's enforcement read closes the loop: 13 federal agencies hold overlapping scam-center authorities with no designated lead, and capacity is relocating rather than shrinking. Nothing there reduces call volume.

The sources agree on the countermeasure, which is unusual and worth weighting: mandatory out-of-band callback to a directory-of-record number, plus a rotating passphrase, for credential resets, MFA re-enrollment and payment-detail changes. Knowledge-based verification loses to a cloned voice. Replacing it costs process, not budget.

The crew stealing your MFA tokens now impersonates the team that rolls out your MFA, and brand-based threat intel told you it had retired.

One caveat on scope. The underlying reporting is GTIG's, arriving through a single downstream channel. Treat the wallet totals and the brand list as single-relay reporting from an authoritative source until the primary advisory is in hand. The process gap does not depend on those numbers being exact.

What to do

  1. Eliminate helpdesk-initiated MFA and passkey enrollment as a possible workflow this week: require self-initiated enrollment from a managed device and publish one out-of-band verification path (internal ticket number plus callback to the published helpdesk line).

  2. Ship the four AitM session-persistence detections into Entra ID and Okta System Log monitoring this sprint, prioritizing authenticator registration within minutes of sign-in.

  3. Extend phishing-resistant MFA to every identity provider including legacy and acquired-entity tenants by end of quarter, then disable push and OTP fallback for all privileged roles.

The Only Sensor Left Is the Identity Log

Three unrelated incidents this cycle produced no blockable infrastructure, no CVE and no malware, and all three left their only evidence in authentication and API telemetry most teams never mine.

What a HollowGraph hunt looks like

Group-IB disclosed HollowGraph, an Iranian MOIS-linked implant with no command-and-control infrastructure to block. Commands arrive as Microsoft 365 meeting invites carrying encrypted attachments, responses return as appointments, all through legitimate Microsoft Graph API calls that resemble ordinary Outlook traffic. Mail-tier controls and network monitoring cannot inspect authenticated first-party API calls to calendar objects, structurally, so the hunt is behavioral and it lives in the unified audit log. Candidate signals: calendar item create and update sequences at machine cadence, invites carrying binary or encrypted attachments, Graph API token use from client patterns that are not Outlook, and Graph sign-in anomalies. Untuned analytics against calendar telemetry make enough noise to get the rule disabled inside a fortnight, so validate with a purple-team replay before it reaches the queue. There is nothing here to add to a blocklist. Waiting for network indicators means waiting indefinitely.

Constraint beats detection where you own the ceiling

CyberScoop reported a breach that cost one company 3,600 repositories and got underway in roughly 87 seconds, against a fast log-enrichment pipeline that needs about 10 minutes. Roughly seven times longer than the event itself. That is the cleanest argument available for capping blast radius instead of shortening response time. Mass cloning at that velocity requires a long-lived, over-scoped token and a platform with no bulk-access limit. The controls that would have made the event impossible are all configuration:

  • Long-lived organization-wide personal access tokens revoked; tokens short-lived and repository-scoped.
  • CI and administrative paths behind an IP allowlist.
  • Platform-side rate limits enabled, with alerting on bulk-clone anomalies at a threshold such as more than 20 repositories per token per 5 minutes.
  • Secret scanning run and findings rotated. Repositories exfiltrated at that scale carry embedded credentials out with them.

The sessions that outlive the employee

OpenAI's motion to dismiss Apple's trade-secret suit describes a departed engineer who kept accessing files and stayed logged into his accounts after leaving, reportedly with the former employer's knowledge during a transition period. Strip the litigation and the mechanism is the one most offboarding runbooks miss: disabling an identity provider account does not revoke long-lived refresh tokens, authenticated sessions on personal devices, SaaS-local accounts outside single sign-on, OAuth grants issued to third-party apps, personal access tokens in CI, or SSH keys on build hosts.

Where the sources agree, and where they pull apart

All three converge on one point. The authenticated session is the asset being taken, not the credential and not the payload, and it is the thing that has to be observed. Network-indicator-centric detection is a declining asset for any SaaS-heavy estate.

They diverge usefully on remedy. CyberScoop's position is that constraint makes detection latency irrelevant, since a credential that physically cannot perform the action needs no alert. The HollowGraph material implies the opposite, because the API belongs to Microsoft and there is no capping what Graph permits a legitimately authenticated token to do with calendar objects. The reconciliation is a rule of thumb worth carrying: hard constraint wherever you own the platform ceiling, meaning version control, token scope and CI identity, with behavioral analytics accepted as the only available control wherever the API is a vendor's.

If your detection strategy assumes hostile traffic eventually leaves the tenant, the tenant is now the network.

What to do

  1. Build and purple-team-validate HollowGraph behavioral hunts in the Microsoft 365 unified audit log this sprint, starting with machine-cadence calendar create/update sequences and Graph token use from non-Outlook client patterns.

  2. Cap source-code-platform blast radius now: revoke long-lived organization-wide personal access tokens, scope replacements to single repositories with short lifetimes, and enable alerting on more than 20 repositories cloned per token per 5 minutes.

  3. Run a token-level offboarding audit this quarter for every identity terminated in the last 12 months, enumerating and explicitly revoking refresh tokens, OAuth grants, personal access tokens, SSH keys and non-SSO SaaS accounts.

A NIST Finalist Fell in 60 Hours for $100,000

Nothing in production was decrypted, which is the least interesting fact about the moment cryptanalysis stopped being limited by the supply of expert labor.

The withdrawal happened in under 48 hours

Sequence first, mathematics second. Anthropic researcher Stephen Weis posted an attack on HAWK, a NIST post-quantum signature finalist, to the public pqc-forum list on July 28, with working key-recovery code. Cryptographer Daniel Apon verified the reduction independently that evening. Next morning HAWK's lead designer Leo Ducas wrote that the obvious remedies, doubled parameters or higher-rank modules, would leave the scheme uncompetitive, and withdrew the submission. NIST's round-three page records it.

Weis's was the third AI-assisted attack on the same candidate inside a week. A version drafted with OpenAI's Codex predated it by eleven days. Academics working by hand with LLM assistance got there too. Claude Mythos Preview, run as multiple agents under human steering, took about 60 hours and roughly $100,000 in API spend. Anthropic called the human contribution project management, and the directing researcher had no expertise in this specific cryptography. Johns Hopkins' Matthew Green flagged the weight-bearing detail: no new mathematics was invented. Published tools, recombined. The weakness sat reachable for two years. Nobody had the labor to reach it.

Separate the confirmed finding from the deck it will appear in

Expect an AES headline this month. The disclosed attack applies only to a deliberately weakened seven-round practice variant, not the ten-round AES-128 in production. Nothing to patch, and nothing exposed. Write that distinction down before the board asks.

The same capability is writing production code

Stanford turned the MITRE Top 25 CWEs into 500 realistic requests with all explicit vulnerability language stripped, then scanned the output with Semgrep. Frontier models emitted MITRE Top 25 flaws in 15.8 to 22.1% of programs even when explicitly asked for secure code.

ModelAsked for secure codeSecureForge promptRelative reduction
Cross-model average (10 models)20.1%11.8%~41%
GPT-5.415.8%10.1%~36%
GPT-5.4 Mini21.4%12.4%~42%
GPT-5.4 Nano22.1%15.6%~29%

The secure-prompt column is the one that matters. Naming the classes to avoid still leaves CWE-class flaws in roughly one program in five, and the cheap tiers are worst. That is where token-cost pressure is pushing engineering. SecureForge is free, needs no fine-tuning, and was optimized against known vulnerability classes only, so 11.8% is defense-in-depth, not a control.

Two adjacent signals that change the timeline

Publicly reported, not confirmed: frontier reasoning at roughly $200 per solved open problem, with availability plausibly near-term. Self-reported, and probably excluding failed attempts. Directionally it is the same economics that made a $100,000 cryptanalysis run rational. Separately, Anthropic's Fable model reportedly ships with strict cybersecurity prompt limits, following intervention after the Mythos disclosure. That is worth naming plainly: the current brake on this capability is vendor policy, not difficulty, and policy is the most fragile control class there is. The same harness aimed at an internally developed protocol, a custom auth flow or homegrown crypto now fits inside a mid-size security budget.

Sixty hours of directed agent time found what two years of expert peer review missed, and it invented nothing to do it.

What to do

  1. Stand up a cryptographic bill of materials this quarter and convert the PQC plan from algorithm selection to algorithm negotiation: hybrid classical plus PQC, no hard-coded scheme identifiers, and a documented time-to-replace target.

  2. Make SAST a blocking merge gate on any pull request containing AI-assisted code this sprint, and tag commit provenance so escape rate can be measured against the published per-model baseline.

  3. Add the NIST pqc-forum list to threat-intel collection now, with a documented trigger to reopen the PQC decision if another round-three candidate is attacked.

The bottom line

The pattern under today's items: adversaries stopped attacking products and started attacking the workflows wrapped around them — the enrollment path, the offboarding step, the token scope, the review cycle whose only real protection was how long a human needed to do the work. That breaks a severity model built on advisories and blockable infrastructure, because none of these generate either. The one place they all leave evidence is authentication and API telemetry almost nobody mines. Rebuild this week around that: name every process that can grant, extend or inherit an authenticated session, and require each one to prove ownership out-of-band before it succeeds.