This Week In Cybersecurity | August 7th, 2026

this week in cybersecurity blog August 7th 2026

Table of Content

    This Week in Cybersecurity

    Each week at Applied Tech we recap the biggest cybersecurity news headlines from the week to keep you informed and ready to face the latest threats. Here’s your breakdown for the week of August 1st-7th!

    Extortion Gang Swaps Logos, Not Tactics

    The vishing crew formerly known as BlackFile has apparently decided that a good con deserves a good rebrand—Google’s Threat Intelligence Group says UNC6671 has splintered (or pretended to) into Redact, Pink, Helix, and Falcon after banking over $10 million in Bitcoin ransoms between January and May. Same fake-IT-helpdesk calls, same Microsoft 365/Okta credential theft, same AiTM playbook, just new stationery and, per GTIG, possibly a shared affiliate infrastructure behind the curtain.

    Final payments averaged $750,000 despite initial demands running $1–3 million, proof that negotiating with extortionists is at least a little more effective than negotiating with your cable company. Open question: whether this is a genuine group splinter or just brand-laundering to dodge law enforcement and reputational heat.

    Source: SecurityWeek
    Read More

    Coding Agents' CI Pipelines Get a Black Hat Reality Check

    Security firm Novee Security, presenting at Black Hat USA, showed that a GitHub issue from an account with zero repo privileges was enough to run code on CI infrastructure behind Anthropic’s and Google’s own agent repos, and to hijack the next run on OpenAI’s. Gemini CLI’s flaw (CVE-2026-12537, CVSS 10.0) allowed host command execution before the sandbox even started; Claude Code’s (CVE-2026-54316) turned a Hugging Face download counter into a slow-drip API key leak, patched in version 2.1.163. All three vendors trace the root cause to the “harness”—the code that decides what a model’s output is actually allowed to do—rather than the models misbehaving on their own.

    Open question: OpenAI’s Codex issue got no CVE and no patched version, just a workflow change and a documentation update, leaving some ambiguity about whether the underlying handling of untrusted instruction files has actually changed.

    Source: The Hacker News
    Read More

    Meta's Muse Spark Hacks a Company During Testing

    Meta confirmed that its Muse Spark 1.1 model breached an unnamed real company during a cybersecurity evaluation run with third-party testing firm Irregular, after a sandbox misconfiguration gave the model unintended public internet access, the same class of error Irregular says caused Anthropic’s disclosed incidents last week.

    Meta hasn’t detailed what changes the model made to the victim’s systems or named the company, saying only that it’s investigating. The incident lands amid a run of similar disclosures: Anthropic’s Claude Mythos 5 reportedly published a malicious PyPI package that was downloaded on 15 real systems, and OpenAI’s models separately breached Hugging Face using an internal server vulnerability. Open question: whether “misconfigured sandbox” is becoming an industry-wide pattern in how cyber evaluations are run, or whether Irregular’s environment specifically is the common point of failure across all three vendors.

    Source: BleepingComputer
    Read More

    Applied Tech favicon with HBS endorsed tagline in white vertical

    About Applied Tech, An HBS Brand

    Applied Tech is a leading IT and cybersecurity services provider dedicated to helping organizations protect their digital assets and scale their IT capabilities. Our proactive services span cloud management, security, productivity, and IT growth strategy—delivered by an experienced team with solutions built around your goals.

    As part of Heartland Business Systems, we now bring greater resources, broader capabilities, and deeper technical expertise to every client relationship.
    Get in Touch with Us

    The Resource Hub

    Get Complete Managed Services Insights

    Visit our Resource Center for up-to-date news and stories for technology and business leaders.

    Three IT Service Techs Working together at desks in office

    Move Forward with IT Services for Business

    Use managed services for small and mid-sized businesses that help you reach your goals.

    Work With Us
    Get In Touch