BlackFile Group Targets Retail and Hospitality with Vishing Attacks

2026-04-27T08:52:27Z85815f2d1755c2aee79686341f6346127a183576aab986c92905baee21d62289
CVE-2024-3721CVE-2026-33032active-exploitationai-riskblackfiledata-breachformbookgentlemen-raasiot-securitymcpmirainginx-uinpmnvd-policy-changepatching-noticesprompt-injectionproxy-smartransomwaresim-farmsupply-chainuk-biobankvishingwater-otworm-propagationzionsiphon

What happened

Infosecurity Magazine roundup: researchers report active exploitation of a critical nginx‑ui MCP authentication bypass (CVE-2026-33032, CVSS 9.8) and Mirai-based campaigns exploiting a TBK DVR command‑injection (CVE-2024-3721). Other notable incidents include a UK Biobank breach (≈500k health records exposed and offered for sale), emergence of the BlackFile vishing/extortion group targeting retail and hospitality, worm‑like malicious npm packages stealing developer credentials, ProxySmart enabling large SIM farms, ZionSiphon targeting water OT systems, and expanded activity from Gentlemen RaaS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
85815f2d1755c2aee79686341f6346127a183576aab986c92905baee21d62289
Enrichment time
2026-04-27T08:52:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · BlackFile Group Targets Retail and Hospitality with Vishing Attacks · Baitaphish