Google Threat Intelligence Group linked China-associated actor UNC6508 to a campaign that breached REDCap servers at a North American medical research organization in September 2023. The group deployed custom InfiniteRed malware three months later and maintained access until November 2025, exfiltrating targeted data through a novel email-based method using content compliance rules.

This rule searched for keywords tied to medical research, advanced technology, military subjects, and geo-strategic policy, automatically forwarding matches as blind carbon copies to the now-disabled address ‘BebitaBarefoot774@gmail.com.’
The campaign maintained strong operational security by routing activity through US-based residential proxies, compromised routers, VPS servers, credential replay, and purpose-built exfiltration infrastructure.
Medical and research institutions running REDCap must prioritize immediate version upgrades and MFA enforcement, as legacy deployments remain prime targets for prolonged espionage campaigns.
Tap a lens to see what this story means for you.
Reader-supported · The Brief
Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Anthropic has confirmed a worldwide outage affecting Claude and its API, with users receiving 529 Overloaded errors. The incident highlights the fragility of AI services that millions rely on for daily work.
CISA added CVE-2026-20316, a hard-coded password vulnerability in Cisco Secure Firewall Management Center, to its Known Exploited Vulnerabilities catalog on 2026-07-29. Federal agencies must remediate by 2026-08-01 per BOD 26-04 guidelines.
The Meta Box AIO WordPress plugin is vulnerable to missing authorization (CVE-2026-14488, CVSS 9.1) in versions up to 3.8.0, allowing unauthenticated attackers to delete arbitrary posts and pages via a bypassable nonce check. The flaw impacts any site with a frontend submission form regardless of delete settings.