Security & Threat Intelligence

The Watch

The Signal

BlackFile added med-tech to its targets and still hasn't used a single exploit.

Entry is voice phishing aimed at service-desk MFA resets. Mandiant has logged 25-plus engagements since January, running at roughly 1.5 new victims a day. The operation publishes under four brands: Redact, Pink, Helix and Falcon. Leak-site trackers score each one as mid-tier, which means the intel feed you're grading vendors against undercounts this crew fourfold.

In Play

  1. Help-Desk Vishing Is BlackFile's Entire Entry Path

    CyberScoop reports BlackFile has added med-tech to a target set already covering private equity, law firms and ratings agencies, running roughly 1.5 new victims per day. Mandiant has handled more than two dozen compromises tied to the actor since January. No CVE and no exploit chain appear anywhere in the reporting: confirmed entry is voice phishing against service desks and identity workflows. The control that matters is your MFA-reset verification policy, not your patch queue.

    Ask Clarity
    Try
  2. Four Exploited Bugs, and C2 Living Inside Your Microsoft Tenant

    CISA added four actively exploited 2026 CVEs to KEV: a VMware vCenter path traversal, a SharePoint flaw, a Microsoft IKE flaw and the Apple macOS ScreenShare bug. Separately, Ontinue documented TWINLOOT, a framework whose command-and-control runs entirely inside Azure, M365 and SharePoint, and ANY.RUN profiled Mirage2FA, phishing-as-a-service built to intercept M365 second factors. Patch vCenter and SharePoint first, and hunt them before closing the ticket: a KEV listing means exploitation predates the advisory.

    Ask Clarity
    Try
  3. GitHub's Outage Took SAML, OIDC and SCIM Down Together

    Monday's GitHub incident hit the identity plane, not just repositories: SAML, OIDC and SCIM failed together, with roughly 20% error rates across web and API traffic and about 50% on raw repository and archive downloads. Terminations, role changes and group revocations queued in that window may have failed silently, because most SCIM implementations fail quietly. Meanwhile engineers who needed to keep shipping minted personal access tokens and SSH keys that outlive the incident and ignore conditional access.

    Ask Clarity
    Try
  4. Insolvency Became a Data-Transfer Channel

    The Information reports Google paid $10M in bankruptcy court for Spirit Airlines' internal Slack, GitHub, Asana, Drive and employee email, outbidding Mercor's $7.5M; the approval hearing is Wednesday. Separately, Nine PBS lost access to 50TB of archives after Open Source Storage dissolved and Iron Mountain held the hardware with no contract to the data owner. Your standard DPA covers termination, not liquidation — and secrets committed to a dead partner's repositories stay live until someone rotates them.

    Ask Clarity
    Try
  5. The Iran Escalation Clock Reset on August 17

    Morning Brew reports the 60-day US-Iran ceasefire deadline expired on August 17 with no formal negotiations underway, a US naval blockade of Iranian shipping in place, and an Iranian official telling Reuters that Tehran must be prepared to escalate. The US also unsealed a superseding indictment against 17 Mabna Institute hackers — an IRGC contractor tracked as Cobalt Dickens, up from nine defendants in 2018 — with a $10M State Department reward. Prior cycles with this shape produced hacktivist-branded DDoS against US financial services, defacement of internet-exposed industrial controllers, and destructive wipers. The work is hunting and exposure reduction, because no patch attaches to a geopolitical trigger.

    Ask Clarity
    Try

Deep Dives

The Extortion Crew That Never Needs a Vulnerability

Four rotating brands, a predictable negotiation curve, and a target list that just added medical technology — decide the verification policy and the settlement number before the phone rings.

Four brands, one operation, four tracker entries

BlackFile runs Redact, Pink, Helix and Falcon as parallel extortion identities under a single operation. Not branding vanity. The split fragments victim counts across IOC and leak-site trackers, so each brand reads as a mid-tier crew, and the operation keeps running when law enforcement seizes one of them. Threat models that sort extortion groups by leak site are carrying four low-priority entries for one actor whose tempo annualizes past 500 organizations.

The negotiation curve is already documented

CyberScoop puts the anchor demand at roughly $3 million and observed settlements below $1 million. That is a consistent 67%-plus discount across a large victim pool. The opening number is theater. The procedural consequence is narrow: settlement range, named decision authority, and the counsel and insurer call tree belong in a pre-authorized tabletop, not in a 2 a.m. decision. Med-tech is the newest vertical, and the leverage there is not the encryption. It is HIPAA exposure, FDA device-reporting obligations and patient-safety pressure to restore fast, all of which raise effective ransom leverage well above the nominal ask.

Where to hunt, and where the telemetry usually is not

StageTechniqueSignal to huntCommon gap
Initial contactT1566.004 voice phishing; T1656 impersonationInbound service-desk calls requesting credential or MFA changes; caller ID mismatch against the HR directoryCalls are not logged as security telemetry at all
AccessT1621 MFA request generation; T1556 modify auth processMFA re-enrollment from a new device or geography; reset ticket followed by privileged action inside 60 minutesReset events land in an IT queue and never reach the SOC
PersistenceT1078 valid accountsAnomalous OAuth or app consent grants; new federated trust; legacy auth usageNo baseline for normal consent activity
ImpactT1486 encrypt for impact; T1657 financial theftMass file access from a single identity; bulk egress to sanctioned cloud storageDLP tuned for email, not for approved cloud destinations

Where the sources converge, and where they stop

Three independent threads point at the same control. CyberScoop establishes that BlackFile's confirmed path is human. Risky.Biz's reporting on Mirage2FA, a phishing platform built specifically to intercept M365 second factors, explains why push-approval and SMS MFA cannot hold the privileged cohorts. SANS's read on the 2026 Verizon DBIR closes it: stolen credentials directly fuel ransomware and lateral movement, and third-party and federated identities sit inside that population, not outside it. Which makes phishing-resistant factors and human verification the same project. FIDO2 for privileged, finance and clinical-systems accounts. A callback or video-ID step for any reset touching those accounts.

The sources stop short in one place worth flagging. Google Threat Intelligence Group identified malicious infrastructure aimed at Blackstone, Bain Capital, Moody's, CME and Apollo, and explicitly could not determine whether any were compromised. Public: the infrastructure. Not established: any breach. That is a leading indicator decoupled from a confirmed compromise. Where one of those names is an investor, exchange, auditor or ratings provider, rotating shared secrets and inventorying authenticated integrations does not require waiting for a disclosure that may never come.

BlackFile does not need a vulnerability. It needs a help desk that takes a phone call at face value — and the fix is a policy change that costs nothing and needs no patch window.

What to do

  1. Eliminate knowledge-based verification for MFA resets and privileged account recovery within two weeks; require manager callback or video ID verification for any credential change on privileged, finance or clinical-systems accounts.

  2. Route identity-reset telemetry to the SOC in real time this month: alert on MFA re-enrollment from new devices, reset-then-privileged-action inside 60 minutes, and anomalous OAuth consent grants.

  3. Run a BlackFile tabletop this quarter with a pre-authorized negotiation posture, named decision authority, and counsel plus insurer on the call tree.

The Adversary's Command Channel Lives Inside Your Tenant

Four confirmed-exploited bugs need a 72-hour clock, but the durable change is that network reputation controls have stopped being a defense and your deprovisioning queue can now fail silently.

Patching the KEV four is not remediating them

Triage order follows blast radius, not CVSS. The vCenter path traversal reaches hypervisor management, which is every VM in the estate, domain controllers and backup servers included. SharePoint is proven pre-ransomware initial access and is usually internet-facing. Both are P0 on a 72-hour clock. Microsoft IKE sits on VPN and IPsec termination. The macOS ScreenShare bug lands on developer and executive Mac fleets and should ship by MDM. One discipline point on the P0 pair: a KEV listing means exploitation predates the advisory, so hunt webshells, unexpected service accounts and new scheduled tasks before the change ticket closes. The public reporting does not carry the four CVE identifiers — pull them from the KEV catalog directly before change tickets open.

Two research findings that retire network-layer detections

Ontinue documented TWINLOOT, a Python framework whose command-and-control runs entirely inside Azure, M365 and SharePoint. ANY.RUN profiled Mirage2FA, a phishing-as-a-service platform built to intercept M365 second factors. The two attack the same seam from opposite ends. Mirage2FA harvests the tokens that get an operator into the tenant. TWINLOOT hides the C2 in the SaaS that cannot be blocked. No suspicious domain to blocklist. No newly registered certificate to flag. The traffic is Graph API calls to *.sharepoint.com, and it looks like work. The claimed intrusions by the actor TheHatman into nearly a dozen Fortune 500 Azure tenants — McDonald's, Vodafone, Gap, Intercontinental and Wyndham named — map to plain T1078 valid accounts. Stolen credentials, permissive conditional access, no exploit involved.

The outage that manufactured static credentials

The GitHub incident is the same story arriving from the availability side. The identity plane went down as a unit, and two artifacts outlived the recovery. First, failed SCIM calls: the IdP believes it applied terminations and group revocations that GitHub never processed, so access-control state and access-review evidence have quietly diverged. Second, fallback credentials. Personal access tokens, SSH keys, deploy keys and self-hosted runner registrations minted to keep a release moving do not expire when the incident closes, do not respect conditional access, and do not appear in offboarding.

The roughly 50% failure rate on raw repository and archive downloads is the third artifact. That is a supply-chain integrity event, not a convenience problem, because some pipelines retried their way to green. Hunt for disabled checksum or signature verification, --no-verify flags, alternate mirrors and unpinned dependency fallbacks against a pre-outage lockfile baseline.

The pattern across all three

Every item here resolves to the same sensor. Adversaries have stopped making networking mistakes, so identity and SaaS-behavioral telemetry is the only layer that still sees them: OAuth consent grants, anomalous Graph API access, token replay from new ASNs, SharePoint and Teams used as outbound data channels, credential-creation spikes during any provider incident. Domain reputation and IP blocklists are decorative against this shape of intrusion.

An identity-plane outage is an access-control event with a delayed fuse: the deprovisioning queue and the tokens engineers minted around broken SSO both outlive the incident, and neither appears on a status page.

What to do

  1. Reconcile every IdP-driven termination, role change and group revocation against actual GitHub org and team state for Monday's outage window plus 24 hours, and revoke every PAT, SSH key, deploy key and runner registration created in that period without a matching ticket.

  2. Patch and hunt the two P0 KEV entries — internet-facing vCenter and SharePoint — inside 72 hours, with a webshell and rogue-service-account sweep before each ticket closes.

  3. Re-point detection engineering at identity and SaaS behavior this quarter: OAuth consent grants, anomalous Graph API access, token replay from new ASNs, and an explicit TWINLOOT-pattern hunt inside your own tenant.

Insolvency Is Now a Data-Transfer Path

Bankruptcy courts, dissolved storage providers and defunct AI startups all move your credentials and records without a breach, a notification, or a counterparty left to compel.

The estate has a fiduciary duty to sell the data

The standard DPA says the vendor returns or destroys customer data on termination. Liquidation is not termination. The data becomes an asset of the estate, with a duty to maximize sale value. The Spirit Airlines auction supplied a price benchmark and a repeatable legal template. The asset class is the uncomfortable part: internal Slack, GitHub and Asana content, Drive documents, employee email, years of staff meeting transcripts. Google says any data it receives will be scrubbed of personally identifiable information by a third party, with the court expected to appoint an independent expert. Take the intent at face value; the technical problem stands. De-identifying a conversational corpus is not de-identifying a database. Strip names and emails from Slack and what remains is roles, project codenames, vendor names and org structure. That is pseudonymized data, still in scope under GDPR Art. 4(5), and an ideal pretexting corpus for anyone who wants to sound like they know how a counterparty's work actually got done.

Two more variants of the same failure, both live

Resilience variant. Open Source Storage ceased operations. Iron Mountain held the physical equipment, had no contractual relationship to the data owner, and refused release. A Denver district court order on August 12 compelled surrender of the devices. Nine PBS still has to find a third party to extract 50TB representing roughly 70 years of archives without touching other customers' data. Encryption is an open question. The contract had a 30-day post-termination retrieval clause. It was worth nothing against a counterparty that no longer existed.

Code variant, per Bloomberg. Integral AI built models for autonomous vehicles and robotics from 2021 and shut down because it could not sustain funding. When a code-shipping vendor dissolves, the sequence is predictable: update and telemetry domains lapse at the registrar, code-signing certificates expire or their keys land in an unmanaged asset pool, and the fleet keeps beaconing to endpoints nobody owns. Re-registering an abandoned update FQDN is one of the cheapest trusted-path footholds available. Physical-AI components sit in robotics and industrial estates, where devices are long-lived and often outside EDR coverage.

These breaches came in through the same door

Four of the compromises were pure third- and fourth-party. Trezor lost customer contact data through logistics partner ShipMonk via a Metabase flaw: 11,742 customers between May 10 and August 8, plus 1,947 earlier. France's DGFiP lost data on 678,000 individuals and businesses, including reference tax income, withholding rates and cadastral data, to an actor using legitimate credentials belonging to a DGFiP agent and an authorized third party. MyDr is the instructive kill path: allegedly compromised GitHub certificates let attackers download application source, which yielded what they needed to reach the AWS back end, potentially exposing 19 million people across 12,000 facilities. Certificates to repo to cloud credentials. That path exists in most engineering organizations today.

One detail deserves to be burned into a program. DGFiP's June audit cut off the unauthorized access. The investigation launched on August 12, after the actor bragged publicly. An eviction without an investigation is not containment.

A vendor's bankruptcy is a data-transfer event your contract does not cover, and a vendor's shutdown is a security incident with a twelve-month fuse.

What to do

  1. Run a defunct-vendor sweep this month across procurement, CMDB and identity systems for every supplier that liquidated or was acquired in the past 24 months, then rotate every shared credential, API key, SFTP account and service principal.

  2. Add an insolvency and liquidation trigger to DPA and MSA disposal clauses this quarter, requiring certified deletion or court-supervised de-identification plus notice-and-objection rights.

  3. Stand up domain-expiry, certificate-expiry and DNS-delegation monitoring this quarter for every third-party update, telemetry and model-serving endpoint your assets call out to.

The bottom line

The highest-consequence intrusions no longer pass through anything your vulnerability program can see: they route through the person who resets a credential, the trusted service you cannot block, and a legal process you were never party to. Patch SLA has stopped being the metric that predicts a breach. The predictive metrics are how fast an identity change reaches your analysts, and whether you can name who holds custody of your data when a counterparty stops existing. Pull every identity-change and deprovisioning event into the SOC, and assign one named owner to verify each one actually executed.