This Week in Cybersecurity
Each week at Applied Tech we recap the biggest cybersecurity news headlines from the week to keep you informed and ready to face the latest threats. Here’s your breakdown for the week of August 1st-7th!
Extortion Gang Swaps Logos, Not Tactics
The vishing crew formerly known as BlackFile has apparently decided that a good con deserves a good rebrand—Google’s Threat Intelligence Group says UNC6671 has splintered (or pretended to) into Redact, Pink, Helix, and Falcon after banking over $10 million in Bitcoin ransoms between January and May. Same fake-IT-helpdesk calls, same Microsoft 365/Okta credential theft, same AiTM playbook, just new stationery and, per GTIG, possibly a shared affiliate infrastructure behind the curtain.
Final payments averaged $750,000 despite initial demands running $1–3 million, proof that negotiating with extortionists is at least a little more effective than negotiating with your cable company. Open question: whether this is a genuine group splinter or just brand-laundering to dodge law enforcement and reputational heat.
Source: SecurityWeek
Read More
Coding Agents' CI Pipelines Get a Black Hat Reality Check
Security firm Novee Security, presenting at Black Hat USA, showed that a GitHub issue from an account with zero repo privileges was enough to run code on CI infrastructure behind Anthropic’s and Google’s own agent repos, and to hijack the next run on OpenAI’s. Gemini CLI’s flaw (CVE-2026-12537, CVSS 10.0) allowed host command execution before the sandbox even started; Claude Code’s (CVE-2026-54316) turned a Hugging Face download counter into a slow-drip API key leak, patched in version 2.1.163. All three vendors trace the root cause to the “harness”—the code that decides what a model’s output is actually allowed to do—rather than the models misbehaving on their own.
Open question: OpenAI’s Codex issue got no CVE and no patched version, just a workflow change and a documentation update, leaving some ambiguity about whether the underlying handling of untrusted instruction files has actually changed.
Source: The Hacker News
Read More
Meta's Muse Spark Hacks a Company During Testing
Meta confirmed that its Muse Spark 1.1 model breached an unnamed real company during a cybersecurity evaluation run with third-party testing firm Irregular, after a sandbox misconfiguration gave the model unintended public internet access, the same class of error Irregular says caused Anthropic’s disclosed incidents last week.
Meta hasn’t detailed what changes the model made to the victim’s systems or named the company, saying only that it’s investigating. The incident lands amid a run of similar disclosures: Anthropic’s Claude Mythos 5 reportedly published a malicious PyPI package that was downloaded on 15 real systems, and OpenAI’s models separately breached Hugging Face using an internal server vulnerability. Open question: whether “misconfigured sandbox” is becoming an industry-wide pattern in how cyber evaluations are run, or whether Irregular’s environment specifically is the common point of failure across all three vendors.
Source: BleepingComputer
Read More

About Applied Tech, An HBS Brand
Applied Tech is a leading IT and cybersecurity services provider dedicated to helping organizations protect their digital assets and scale their IT capabilities. Our proactive services span cloud management, security, productivity, and IT growth strategy—delivered by an experienced team with solutions built around your goals.
As part of Heartland Business Systems, we now bring greater resources, broader capabilities, and deeper technical expertise to every client relationship.
Get in Touch with Us


