Weekly review

ThreatNoir Afternoon Brief — August 7

2026-08-07Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — August 7, 2026

The cybersecurity landscape continues to shift as researchers unveil critical infrastructure vulnerabilities and threat actors expand their operational scope. Today's briefing covers emerging attack techniques against network infrastructure, supply chain compromises targeting AI platforms, and the evolution of financially motivated extortion campaigns.

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that exploits network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research demonstrates that the vulnerability affects independently developed NAT implementations across multiple platforms, including Windows systems.

The attack leverages fundamental weaknesses in how NAT devices manage connection state tables, allowing adversaries to manipulate these tables and intercept legitimate traffic. The research identifies two critical vulnerabilities tracked as CVE-2026-56181 and CVE-2026-63913. Source: The Hacker News

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

Researchers at Novee Security have identified critical vulnerabilities in AI coding agents from Anthropic, Google, and OpenAI that allow unauthenticated attackers to execute code on CI/CD infrastructure. The attack requires only opening a GitHub issue in a repository where the attacker has no privileges, yet this minimal action is sufficient to access sensitive CI workflow secrets.

The vulnerability affects the default configurations shipped by each vendor, making the risk immediate for organizations using these tools. On OpenAI's platform, the flaw enables complete hijacking of subsequent agent runs. The research was presented at Black Hat USA on August 5 and tracks two CVEs: CVE-2026-12537 and CVE-2026-54316. Source: The Hacker News

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

Threat intelligence analysis has established that the threat actor group TeamPCP has maintained continuous operations since at least 2020, initially targeting internet-facing Redis infrastructure before pivoting to software supply chain attacks. The connection between their early Redis exploitation campaigns and recent supply chain activities is supported by overlapping domains, malware deployment paths, staging techniques, and shared backend infrastructure.

The group's operational history spans six years of infrastructure compromise, demonstrating sophisticated persistence and evolution of tactics. The malware families associated with TeamPCP include CanisterWorm, Kamikaze, and kube.py, indicating a diverse toolkit for both initial access and post-compromise activities. Source: The Hacker News

Vishing Extortion Group UNC6671 Rebrands After Making Millions

The vishing extortion group tracked as UNC6671, previously operating under the BlackFile brand, has expanded operations across multiple new personas including Redact, Pink, Helix, and Falcon. The group's rebranding strategy follows substantial financial success through social engineering campaigns targeting employee credentials and multi-factor authentication tokens.

The group maintains multiple phishing infrastructure domains including addssopasskey[.]com, mysecurepasskey[.]com, passkeydeploy[.]com, passkeyhelpdesk[.]com, passkeyuser[.]com, and portalpasskey[.]com. These domains are designed to impersonate legitimate authentication and identity management services. Source: SecurityWeek

Closing Perspective

Today's threat landscape reflects both technical sophistication in infrastructure attacks and continued reliance on social engineering for credential theft. Organizations must prioritize NAT configuration hardening, secure CI/CD pipeline design, supply chain visibility, and employee security awareness training to defend against these converging attack vectors.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Vishing Extortion Group UNC6671 Rebrands After Making Millions
Domain6
  • portalpasskey[.]com
    Generic root domain used by UNC6671 for credential harvesting.
  • passkeyhelpdesk[.]com
    Generic root domain used by UNC6671 for credential harvesting.
  • mysecurepasskey[.]com
    Generic root domain used by UNC6671 for credential harvesting.
  • passkeydeploy[.]com
    Generic root domain used by UNC6671 for credential harvesting.
  • addssopasskey[.]com
    Generic root domain used by UNC6671 for credential harvesting.
  • passkeyuser[.]com
    Generic root domain used by UNC6671 for credential harvesting.