Daily brief at 7am Melbourne. Unsubscribe any time.

Tuesday 16 June 2026

UNC6508: China's Quiet Year Inside Medical and Military Research Networks

A year-long Chinese espionage campaign quietly drained medical, military, and AI research from North American networks — and the tool they weaponised was hiding in plain sight.

Lead story

UNC6508: China's Quiet Year Inside Medical and Military Research Networks

For more than a year, a Chinese state-linked hacking group sat inside the networks of medical institutions, defence contractors, and AI research facilities across North America — and nobody noticed. Google's Threat Intelligence Group disclosed the campaign Monday, attributing it to a cluster it tracks as UNC6508, which it says has been active since at least early 2025.

The group's method of entry was REDCap — an open-source research data platform widely used by universities and hospitals to manage clinical trial data. Attackers found internet-exposed REDCap servers, exploited them to drop a custom malware family researchers are calling InfiniteRed, and then settled in for the long game. Not ransomware. Not noise. Just quiet, sustained collection.

What they were after tells you a lot about Beijing's priorities right now. According to Google, the stolen material spans medical research data, drone and aerospace technology, pathogen research, and AI development work. That's not a smash-and-grab — it's a shopping list aligned directly with China's strategic technology goals under Made in China 2025 and its successor frameworks.

The dwell time is the part that should keep security teams up at night. Twelve-plus months undetected, siphoning data through Gmail accounts to blend outbound traffic with normal web activity. By the time Google disrupted the campaign, the damage — in terms of intellectual property — was already done.

REDCap is the thread worth pulling here. The platform is deployed at hundreds of universities, hospitals, and research bodies worldwide. It's often managed by research IT teams rather than dedicated security teams, which means patching cadences can be slow and exposure can be invisible to central security operations. Any institution running a public-facing REDCap instance should treat this as a fire drill.

The pattern also mirrors what we've seen from other Chinese espionage clusters — Salt Typhoon's long residency in US telco networks, Volt Typhoon's pre-positioning in critical infrastructure — but with a sharper focus on intellectual property over access and disruption. The target profile suggests UNC6508 is filling gaps in China's domestic R&D pipeline.

Australian institutions are directly in scope here. REDCap is widely deployed across Australian universities and hospital networks — the University of Melbourne, Monash, and several state health departments use it for clinical research. Australian universities collaborate extensively with North American research programmes, often sharing data environments. The ACSC's guidelines on protecting research data are relevant here, as is the Government's existing guidance under the Research Security Action Plan, which specifically flags foreign interference in university research as a priority threat vector.

Watch for: whether Google's disclosure leads to a coordinated advisory from the Five Eyes intelligence alliance, which has previously issued joint alerts on Chinese espionage activity targeting research institutions. An ACSC advisory in the coming days wouldn't be surprising.

Also today

SearchLeak: One Click Drained Your Entire Microsoft 365 Account

Researchers at Varonis Threat Labs disclosed a vulnerability chain in Microsoft 365 Copilot Enterprise they've named SearchLeak. By chaining three bugs, an attacker could send a target a link pointing to a legitimate Microsoft domain — the kind that sails through anti-phishing filters — and on a single click extract emails, calendar entries, OneDrive files, and even MFA codes. The attack worked because Copilot's enterprise search function could be manipulated to exfiltrate indexed data back to an attacker-controlled endpoint. Microsoft has patched the chain. Any organisation running M365 Copilot Enterprise should confirm they're on the latest version — and this is a useful reminder that AI productivity tools create novel attack surfaces beyond traditional email or endpoint vectors.

Bleeping Computer

Palo Alto's GlobalProtect VPN Is Being Actively Exploited Right Now

Palo Alto Networks confirmed active exploitation of CVE-2026-0257, an authentication bypass flaw in the portal and gateway components of PAN-OS — the software underpinning its GlobalProtect VPN product. The flaw carries a CVSS score of 7.8 and lets an unauthenticated attacker gain unauthorised access to GlobalProtect portals. Palo Alto has released a patch. Given how heavily GlobalProtect is deployed in enterprise and government environments — including across Australian federal agencies and large corporates — patching this one quickly is non-negotiable. The ACSC's three-day patch window guidance for actively exploited vulnerabilities applies here directly.

The Hacker News

OptinMonster CDN Hack Planted Backdoors Across Thousands of WordPress Sites

Attackers compromised the content delivery network used by Awesome Motive — the company behind WordPress plugins OptinMonster, TrustPulse, and PushEngage — and tampered with trusted JavaScript files served to millions of sites. The poisoned scripts checked whether a site administrator was logged in; if so, they silently created a new admin account under attacker control and installed a hidden backdoor plugin. Ordinary visitors saw nothing. Collectively, the affected plugins are active on hundreds of thousands of WordPress installations globally. Site admins running any of the three plugins should audit their admin user lists immediately and check for unfamiliar installed plugins.

Bleeping Computer

LiteLLM Flaw Chain Hands Attackers the Keys to Every AI Provider

Researchers at Obsidian Security disclosed a three-vulnerability chain in LiteLLM — a widely deployed open-source AI gateway that proxies calls to more than 100 model providers behind a single OpenAI-compatible API. A default low-privilege account can chain the three flaws to escalate to full admin and execute arbitrary code on the server. The critical consequence: a compromised LiteLLM server exposes every API key it holds for every connected model provider. For any organisation using LiteLLM to manage access to OpenAI, Anthropic, Gemini, or other models in a shared environment, this is a supply-chain-style blast radius. Patches are available; rotate your provider keys as a precaution.

The Hacker News

Cisco SD-WAN Zero-Day Was Already Being Exploited When Patch Landed

Cisco released a fix for CVE-2026-20262 in its Catalyst SD-WAN Manager (vManage) — but the vulnerability had already been exploited in the wild to escalate privileges to root before the patch existed. The flaw affects a core component of Cisco's enterprise networking stack, meaning attackers with initial access to a vManage instance could take full control of the underlying system. SD-WAN infrastructure is notoriously difficult to patch quickly given its role in maintaining network connectivity. Organisations running Cisco Catalyst SD-WAN should treat this as urgent — root-level access to network management infrastructure is as bad as it gets.

Bleeping Computer

North Korea's Contagious Interview Group Is Back Targeting Developers

Proofpoint researchers flagged two fresh campaigns linked to North Korea's Contagious Interview cluster — also tracked as Famous Chollima and Void Dokkaebi. The group is continuing its playbook of impersonating developer recruiters or fake code-review requests to lure targets into running malware-laced packages. What's notable is the persistence: this group has been running essentially the same developer-targeting operation for years, and it keeps working. Threat actors linked to the same cluster were behind last week's GitHub repo poisoning campaign. Australian tech companies with engineering teams active on GitHub or LinkedIn recruitment should brief staff on this pattern.

The Hacker News

Fox Acquires Roku for $22 Billion — and TV Just Got Complicated Again

Fox Corporation agreed to acquire Roku for $22 billion, a deal that would hand the traditional broadcaster control of the dominant smart TV operating system in the United States. Roku's OS powers tens of millions of screens and its FAST (free ad-supported streaming) channel network is one of the largest in the world. For Fox, it's a direct pipeline into streaming households without paying carriage fees. For Roku's hardware partners and app developers, it raises immediate questions about platform neutrality. The deal still requires regulatory approval. In Australia, Roku has a more limited footprint than the US, but the deal signals where the global streaming platform wars are heading next.

TechCrunch

Salesforce Pays $3.6B for Fin to Supercharge Agentforce

Salesforce announced it will acquire Intercom's AI customer service spinout Fin for $3.6 billion, with the explicit goal of bolting Fin's technology and team into Agentforce — its enterprise AI agent platform. Fin built its reputation on AI agents that can genuinely resolve customer support tickets end-to-end, rather than just triage them. For Salesforce, this is an admission that Agentforce needed a credibility boost in the agentic AI race against ServiceNow and Microsoft Copilot. For Fin's customers, the acquisition raises the usual questions about product roadmap continuity. Salesforce has significant enterprise presence in Australia across financial services, retail, and government sectors.

TechCrunch

Cybersecurity Veterans Tell White House: The Anthropic Ban Is Backfiring

Dozens of senior cybersecurity practitioners signed an open letter urging the White House to rescind its export control order forcing Anthropic to cut off foreign nationals — including Anthropic's own non-US staff — from Fable 5 and Mythos 5. Their argument: defenders rely on frontier models to analyse malware, audit code, and respond to incidents, and restricting access doesn't neutralise the offensive risk, it just hobbles the blue team. Separately, CyberScoop reported that practitioners who examined the jailbreak claims underpinning the ban found nothing that distinguished Fable 5's capabilities from other available models. The pushback adds pressure on an already contested policy decision — and has direct implications for Australian security firms that rely on Anthropic's API.

TechCrunch

AMD Quietly Removed Memory Encryption from Consumer CPUs — Users Are Furious

AMD stripped Transparent Secure Memory Encryption (TSME) from its consumer-grade Ryzen CPUs without announcement, and users are now crying foul after discovering the change post-purchase. TSME encrypts all data in RAM automatically, providing a meaningful layer of protection against physical memory attacks — cold boot attacks, DMA attacks, and certain firmware exploits. AMD appears to have removed it to differentiate from its workstation and data centre SKUs, which retain the feature. The move is drawing comparisons to Intel's long-running feature segmentation controversies. For most home users the risk is low, but for journalists, lawyers, activists, and others with physical security concerns, it matters.

Ars Technica

ASX Faces $20.5M Penalty Over Blockchain Replacement That Was 'Progressing Well' Right Until It Wasn't

The Australian Securities Exchange is facing a $20.5 million penalty following the spectacular failure of its CHESS blockchain replacement project — a years-long saga that saw the ASX tell regulators the project was on track even as it quietly unravelled. The regulator found the ASX misled the market about the project's progress. The CHESS replacement, meant to modernise Australia's core equity settlement infrastructure, was abandoned in 2022 after more than six years and hundreds of millions of dollars. The penalty is a significant outcome for Australia's financial markets governance and a case study in the risks of legacy IT transformation programmes built on unproven technology.

iTnews

Reddit Manipulation Requires Just 13 Words to Corrupt AI Search Results

New research published by 404 Media reveals that AI-powered search agents — the kind increasingly embedded in Google, Bing, and ChatGPT — can be manipulated into promoting spam or scam content via planted text on user-generated content platforms like Reddit, Wikipedia, and Quora. The kicker: it takes as few as 13 words of injected text to reliably shift an AI agent's output. Researchers call this a retrieval-augmented generation (RAG) poisoning attack — the agent fetches the planted snippet as a trusted source and incorporates it into its answer. As AI search replaces traditional link-based results, this attack surface grows. Australia's ACCC has been examining AI-driven misinformation as part of its digital platform services inquiry.

404 Media

Sources consulted