zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - June 29, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - June 29, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Profile - ICARUS
  • Authorities Seize Nearly 400 Domains Illegally Streaming FIFA World Cup Matches
  • Over 20 Npm Packages Compromised by the Miasma Campaign

ZeroFox Intelligence Profile - ICARUS

Source: https://www.zerofox.com/advisories/40678/

What we know: ZeroFox has published a threat actor profile on ICARUS, a ransomware and digital extortion (R&DE) collective, behind the recent Klue supply chain attack. ZeroFox first observed the collective’s data leak site (DLS) and associated extortion campaigns in late April to early May 2026.

Context: ICARUS employs a multitiered extortion model centered on supply chain compromise, data exfiltration, and public disclosure threats. Operators of "The Underground _ Uwu" Telegram channel, who previously claimed affiliations with Scattered Lapsus$ Hunters (SLH), have reposted ICARUS's original leak posts, though ICARUS has not publicly acknowledged this affiliation.

Analyst note: ZeroFox assesses that ICARUS is likely an operationally immature financially motivated threat group based on multiple observed operational security (OPSEC) lapses. Organizations participating in shared SaaS integration ecosystems—particularly those relying on OAuth-based third-party access—should treat this group as a credible and ongoing risk.

Authorities Seize Nearly 400 Domains Illegally Streaming FIFA World Cup Matches

Source: https://www.justice.gov/opa/pr/united-states-seizes-hundreds-internet-domains-used-illegally-stream-world-cup-matches

What we know: The United States and its partners have seized nearly 400 domains that were illegally streaming FIFA World Cup Finals matches in violation of U.S. copyright law, as part of Operation Offsides.

Context: Servers and domains were targeted in Peru and Bulgaria, while additional disruptions took place in Croatia, Romania, Poland, and Colombia. Apart from violating intellectual property rights, illegal streaming sites also fuel criminal organizations and expose viewers to threats such as malware infections and unsecure connections that can compromise personal and financial data.

Analyst note: Illegal streaming platforms are very likely to be operated by transnational organized crime groups, as evidenced by the multinational law enforcement operation. Profits from these operations are likely to finance broader criminal activities.

Over 20 Npm Packages Compromised by the Miasma Campaign

Source: https://www.theregister.com/security/2026/06/26/miasma-campaign-poisons-20-plus-npm-packages-hunts-for-developer-secrets/5262886

What we know: The Miasma malware campaign reportedly published malicious updates to more than 20 legitimate npm packages used by the Leo Platform and RStreams ecosystems. The packages were reportedly published in under three seconds after attackers compromised the npm maintainer account "czirker" on June 24, 2026. The affected packages are listed here.

Context: The malware strain was observed stealing developer and cloud credentials, and bypassing npm two-factor authentication (2FA) to republish compromised packages, while self-propagating across software supply chains.

Analyst note: The rapid publication of malicious versions of more than 20 npm packages in seconds demonstrates a highly efficient operation likely capable of exploiting compromised maintainer accounts before defenders can respond, maximizing the campaign’s scope.

DEEP AND DARK WEB INTELLIGENCE

DarkForums user Datavortex_BD: Untested threat actor “Datavortex_BD” has advertised a database associated with Saudi Arabia-based logistics company Isnaad. The actor claimed the database contains 910,000 user records, including names, phone numbers, and physical addresses. Additionally, the actor made general mentions of other logistics companies without clarifying if they are connected to the compromised Isnaad database.

DATA BREACHES INTELLIGENCE

KDDI discloses data breach: Japanese telecommunications operator KDDI Corporation has disclosed a data breach that potentially exposes 14.2 million internet service provider (ISP) email logins, including passwords. Five ISP operators—STNet, JCOM, Chubu Telecommunications, NIFTY Corporation, and BIGLOBE—have been impacted. On April 18, 2026, ZeroFox observed threat actor “ShinyHunters” advertising a stolen dataset that listed KDDI among the impacted companies. The compromised credentials are very likely to facilitate account takeover, credential stuffing attacks, and business email compromise. They can enable follow-on intrusion attempts where passwords have been reused across multiple services.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2026-12957: This is a high-severity flaw in Amazon's AI coding assistant for Visual Studio Code (VS Code) that enables arbitrary code execution and credential theft. The vulnerability occurs because the extension automatically loads and executes commands from a repository's .amazonq/mcp[.]json file without user prompt, consent, or workspace trust checks. Attackers are likely to gain unauthorized access to AWS credentials, API keys, authentication tokens, and SSH agent sockets.

Affected products: The affected products are listed here.

Tags: DIBtlp:green