Summary
By
the N2K CyberWire staff
Top stories.
- Vishing attacks target hedge funds.
- Cyberattack disrupts North Carolina Ports operations.
- Metabase Cloud breached by zero-day flaw.
Google's Threat Intelligence Group has linked recent cyberattacks targeting hedge funds, private equity firms, and other financial organizations to the UNC6671 extortion group, formerly known as BlackFile. The group is using helpdesk impersonation and voice phishing to compromise Microsoft 365 and Okta accounts, then targeting cloud services to steal sensitive data for extortion. Notably, the threat actors often target employees’ personal mobile devices.
Reuters cites sources as saying the campaign has targeted Point72, Millennium Management, Two Sigma Investments, Citadel, and several other private-equity firms. Google’s researchers note, "Concentrating on organizations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximize leverage extortion demands."
Cyberattack disrupts North Carolina Ports operations.
North Carolina Ports is recovering from a cyberattack that disrupted operations across its three port facilities, forcing staff to switch to manual processes, the Record reports. Officials say the breach has been contained, and the Coast Guard and state agencies are investigating the incident. The attack disrupted port operations at Wilmington, Morehead City, and Charlotte. A spokesperson for North Carolina Ports told the Record that the facilities are now following a normal operating schedule, but companies should expect delays as the ports are still relying on manual operations.
Metabase Cloud breached by zero-day flaw.
Metabase yesterday disclosed a security incident involving a zero-day vulnerability that affected some Metabase Cloud customers. The company detected the attack, patched the issue, and began an investigation with external forensic support. Affected customers are being notified and should rotate credentials for connected databases, review admin accounts, and check logs for suspicious activity.
The company stated, “After gaining access to your instance, the attacker could inject arbitrary SQL against the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change your application configuration, steal stored credentials for your connected databases, read any data accessible through those connections, and export data.”
Sponsored Events
HIP Conf 26: Clarity. Confidence. And people in your corner. (, Sep 8 - 10, 2026) From strategy to implementation, HIP Conf is built to help you make better decisions before, during, and after a crisis. Join the community helping prevent compromise, respond with clarity, and recover with resilience across hybrid identity environments.
Selected Reading
Attacks, Threats, and Vulnerabilities
China-linked LightSpy spyware caught targeting victims in 13 countries, including the US (TechCrunch) Researchers linked the latest malicious activity to a Chinese company, after one of the spyware's operators placed an order with KFC using their real name and office address.
Unlimited Technology Systems Data Breach Affects 3.8 Million Patients (The HIPAA Journal) On July 23, 2026, the HIPAA Journal reported on a data breach at Unlimited Technology Systems, a Montgomery, Ohio-based provider of revenue cycle A data breach at the Ohio revenue cycle management company, Unlimited Technology Systems, has affected more than 3.8 million patients of its healthcare provider clients.
Marketplace
China launches cybersecurity review into Palo Alto Networks products (Reuters) China reviews Palo Alto products over national security risks
Industry Events
For a complete running list of events, please visit the Event Tracker.
Events
DEF CON 34 (Las Vegas, Nevada, USA, Aug 6 - 9, 2026) DEF CON has been a part of the hacker community for over three decades. Originally started in 1993, it was a meant to be a party for member of "Platinum Net", a Fido protocol based hacking network out of Canada. As the main U.S. hub I was helping the Platinum Net organizer (I forget his name) plan a closing party for all the member BBS systems and their users. He was going to shut down the network when his dad took a new job and had to move away. We talking about where we might hold it, when all of a sudden he left early and disappeared. I was just planning a party for a network that was shut down, except for my U.S. nodes. I decided what the hell, I'll invite the members of all the other networks my BBS (A Dark Tangent System) system was a part of including Cyber Crime International (CCI), Hit Net, Tired of Protection (ToP), and like 8 others I can't remember. Why not invite everyone on #hack? Good idea!
Cybersecurity Operational Methods and Education Training (COMET) cohort (Virtual, USA, Aug 31 - Sep 28, 2026) COMET was established to provide relevant, up-to-date training to Maryland state and local government employees to elevate the ability of the workforce to identify and respond to the largest cybersecurity challenges facing the state and local government.
Books in Cyber: A conference about the books that shape cybersecurity (Virtual, Sep 8, 2026) A half-day virtual conference about the books that shape cybersecurity - the writers, the readers, and the ideas that endure.
.conf26 (Denver, Colorado, USA, Sep 14 - 17, 2026) .conf26 is a three-day conference filled with hands-on training, AI insights, new certifications, fun celebrations, and endless opportunities to see how others use Splunk. Take your skills to the next level and build your most resilient defense yet. See you in Denver!
Sponsor & Support
Grow your brand, generate leads, and fill your funnel.
With the industry's largest B2B podcast network, popular newsletters, and influential readers and listeners all over the world, companies trust N2K CyberWire to get the message out. Learn more.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.