Skip to content
Weekly Signal

Before the vulnerability record

Threat Activity

Track reported campaigns, active threat actors and targeted sectors, including activity described before a CVE is named.

Updated 20 Aug 2026 · 15:32 UTC

Evidence, not prediction.

Pre-CVE means a trusted source has described malicious activity or a previously unknown weakness without naming a CVE. ATT&CK mappings marked Explicit were stated by the source. Inferred mappings are conservative interpretations of source wording and must be verified against the original report.

5Reports in 24 hours
0Pre-CVE reports · 7 days
30Named actors · 30 days
7Targeted sectors · 30 days
2ATT&CK-mapped reports · 7 days

Emerging activity

1 of 1 reports shown

49Signal
THREAT REPORT

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

Written by: Tyler McLellan, Austin Larsen Introduction Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry…

Source
Google Threat Intelligence Group
Published
6 Aug 2026 · 14:00 UTC
Actor
UNC6671
Targets
Financial services, Cloud, Identity, Mobile, Operational technology
Read source ↗

Provenance and freshness

Source coverage

The dashboard currently uses freely available government, vendor and vendor-research reporting. A source problem is shown here instead of silently hiding stale data.

HEALTHY

UK NCSC

Last successful collection 20 Aug 2026 · 14:58 UTC

HEALTHY

SentinelLABS

Last successful collection 20 Aug 2026 · 14:58 UTC

HEALTHY

ESET Research

Last successful collection 20 Aug 2026 · 14:58 UTC

HEALTHY

Securelist

Last successful collection 20 Aug 2026 · 14:58 UTC