Decision RecordActivePublished without chair review
CRT-2026-003805 Jul 2026AFTERNOON EDITIONDaily Roundtable
Take same-day action for exposed REDCap in research and healthcare contexts
Research, healthcare, academic, medical, and military research organizations running legacy, unsupported, or internet-facing REDCap should take same-day action on the reported activity: restrict exposure, hunt for web shells and INFINITERED indicators, audit Google Workspace or mail routing/BCC/compliance rules, rotate REDCap-related credentials, and involve privacy/legal if sensitive patient or research data may have been accessed.
Current public guidance · the full record
What to do now
Under reviewAt a glanceIf you operate REDCap in a research, healthcare, academic, medical, or military research environment and it is legacy, unsupported, or internet-facing, act the same day: restrict external exposure; hunt for web shells; hunt for INFINITERED indicators; audit Google Workspace rules and mail routing/BCC/compliance rules; rotate REDCap-related credentials; and involve privacy/legal teams if sensitive patient or research data may have been accessed. If you do not operate REDCap or have no legacy, unsupported, or internet-facing REDCap exposure, move this to monitoring rather than emergency response.
Why now
Under reviewThe packet records a same-day recommendation on 2026-07-05 for the scoped REDCap audience.
The urgency comes from the reported combination of legacy or internet-facing REDCap, web shells, credential theft, INFINITERED persistence, email-rule abuse, and possible sensitive patient or research data access.
The same evidence also limits the urgency: the actor name UNC6508 / PRC-nexus is not the center of gravity, and exact affected REDCap versions are not provided.
Who is affected
Under reviewAffected operators are research and healthcare organizations running REDCap, especially North American academic, medical, and military research environments.
The highest-priority deployments are legacy, unsupported, or internet-facing REDCap instances. For REDCap application owners, the exposure is possible compromise through web shells and INFINITERED persistence.
For identity and mail administrators, the exposure is credential theft and abused Google Workspace or mail routing/BCC/compliance rules. For privacy, legal, research, and clinical data stewards, the consequence is possible access to sensitive patient or research data.
The packet does not support treating this as a general SharePoint-scale enterprise exposure for organizations that do not run REDCap.
What supports this
Under reviewThe intel analyst’s cited discussion supports same-day action for organizations running REDCap in research or healthcare contexts and lists legacy REDCap, web shells, credential theft, INFINITERED persistence, and email-rule abuse.
The moderator’s synthesis supports narrowing the urgency to research and healthcare organizations, especially North American academic, medical, and military research environments running legacy or internet-facing REDCap.
The evidence review supports the action list: restrict exposure, hunt for web shells and INFINITERED indicators, audit Google Workspace or mail routing/BCC/compliance rules, rotate REDCap-related credentials, and involve privacy/legal teams if sensitive patient or research data may have been accessed.
Separate evidence review findings flag gaps in UNC6508 / PRC-nexus attribution corroboration and exact REDCap version evidence, so those points should not be treated as stronger than the packet shows.
How the Roundtable reached this
Under reviewThe Roundtable narrowed the response rather than broadening it.
The intel analyst surfaced a same-day action call for organizations running REDCap in research or healthcare contexts, citing legacy REDCap, web shells, credential theft, INFINITERED persistence, email-rule abuse, and moderate-confidence UNC6508 / PRC-nexus attribution.
The moderator then resolved the scope: this is not a SharePoint-scale enterprise exposure; it is for research and healthcare organizations, especially North American academic, medical, and military research environments running legacy or internet-facing REDCap.
The evidence review supported the operational actions but separated them from the actor label, because attribution and exact affected-version details were not independently corroborated in the packet. The boundary review kept the public guidance behavior-led and scoped to exposed REDCap operators.
What is uncertain
MissingAttribution remains uncertain: the packet says the UNC6508 / PRC-nexus label is moderate confidence and largely from one reporting lane.
Affected-version detail is also uncertain: the evidence repeatedly points to legacy or internet-facing REDCap but does not name exact REDCap versions or patch baselines.
The evidence supports same-day defensive action for the scoped exposure group, but not broad enterprise-wide treatment for every organization that does not run REDCap.
What evidence is missing
MissingThe packet does not include exact affected REDCap versions, patch levels, or a vendor release baseline.
It also does not include the underlying Google Threat Intelligence report or independent public corroboration for the UNC6508 / PRC-nexus attribution. Treat the response as driven by exposed REDCap behavior and sector fit, not by a fully proven actor label or a precise version list.
What would change this
Under reviewThis guidance would narrow if reliable affected-version or patch-baseline evidence shows only specific REDCap releases are exposed.
It would broaden if new evidence shows exploitation of current supported REDCap deployments or a wider enterprise pattern beyond research and healthcare REDCap.
The attribution language would strengthen only if the underlying Google Threat Intelligence reporting or independent corroboration supports the UNC6508 / PRC-nexus label.
The urgency would drop for an operator that verifies it has no REDCap exposure or no legacy, unsupported, or internet-facing REDCap.
What to watch next
Under reviewWatch for three triggers.
First, if your REDCap exposure review finds legacy, unsupported, or internet-facing REDCap, start the same-day containment and hunting actions.
Second, if web shells, INFINITERED indicators, credential theft, or abusive Google Workspace or mail routing/BCC/compliance rules are found, escalate from exposure reduction to incident response and data-access assessment.
Third, if sensitive patient or research data access is confirmed or plausible, bring in privacy/legal teams immediately.
Evidence basis
The REDCap thread narrows the urgency rather than broadening it. Lena is not treating this as another SharePoint-style, enterprise-wide exposure; she is putting it in a specific lane: research and healthcare organizations, especially North …
CyberBrief handoff usage tool_call with attributed attribution. UNC6508 compromises legacy REDCap to steal North American research data UNC6508 legacy REDCap InfiniteRed web shells credential theft email rule abuse data theft academic medic…
Public value history
- 05 Jul 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableAfternoon roundtableConvened 05 Jul 2026Methodology
How the panel reaches a Public Decision Record.