ZeroFox Daily Intelligence Brief - June 30, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - June 30, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Apple’s iPhone 18 Pro Supply Chain Data Leaked in Tata Electronics Incident
- Spike in Venezuela Earthquake-Themed Domains Raises Donation Scam Concerns
- Mustang Panda Targets India; Uses Zoho WorkDrive to Evade Detection
Apple’s iPhone 18 Pro Supply Chain Data Leaked in Tata Electronics Incident
What we know: Files detailing Apple's supplier list and component specifications for the unreleased iPhone 18 Pro and Pro Max were reportedly part of the files posted to the dark web in the Tata Electronics breach claimed by World Leaks ransomware group.
Context: The exposed data disclose supplier mappings that Apple does not make public, along with details on chips, battery components, and camera parts. The files reportedly carry "confidential" watermarks and internal code names associated with the iPhone 18 Pro series.
Analyst note: The exposure of unreleased supplier and product data will very likely provide competitors with insight into Apple's guarded sourcing strategies and deepen supply chain risk ahead of the iPhone 18 Pro's anticipated September 2026 launch. This incident is also likely to further strain the Apple-Tata relationship at a critical point in Apple's expansion of manufacturing in India.
Spike in Venezuela Earthquake-Themed Domains Raises Donation Scam Concerns
Source: https://hackread.com/venezuela-earthquake-domains-donation-scam-warnings/
What we know: Over 200 newly registered domains referencing the June 24, 2026 Venezuela earthquake have prompted donation scam warnings. Many reported domains used terms related to donations, rescue efforts, missing persons, and medical aid.
Context: Some websites reportedly solicited cryptocurrency donations without clearly identifying the organization or explaining how funds will reach victims. Ninety-three percent of the newly registered domains also concealed registrant contact information through privacy services or lacked visible registrant email addresses.
Analyst note: The activity mirrors historical disaster-response campaigns, in which threat actors exploit public urgency through donation scams, phishing, and other forms of social engineering. Dubious solicitation of donations and opaque ownership details indicate that at least some of the domains are likely created for fraudulent purposes.
Mustang Panda Targets India; Uses Zoho WorkDrive to Evade Detection
Source: https://thehackernews.com/2026/06/mustang-panda-uses-zoho-workdrive-as.html
What we know: Chinese APT group Mustang Panda is reportedly using Zoho WorkDrive as a covert command-and-control (C2) channel to target the Indian government and hydropower networks in two cyber espionage campaigns. Zoho WorkDrive is a cloud service commonly used by the Indian government.
Context: Mustang Panda targeted Indian government employees phishing to gain initial access. Victims were then tricked into installing a novel malware dubbed ZOHOMURK, which connected directly to an attacker-controlled Zoho WorkDrive account to exfiltrate data. Separately, a researcher discovered 14 flaws in Indian government IT systems that reportedly risked exposure of private citizen data. The flaws have since been patched.
Analyst note: Mustang Panda will likely use the exfiltrated hydropower intelligence to map vulnerabilities within India's critical infrastructure, leveraging it for future cyber-physical disruptions during geopolitical disputes. Threat actors are likely to continue expanding their evasion techniques beyond Zoho WorkDrive, targeting locally popular platforms to blend malware into legitimate traffic.
DEEP AND DARK WEB INTELLIGENCE
DarkForums user ZeroFingerGuard: Untested threat actor "ZeroFingerGuard" has advertised a database allegedly belonging to the Iraqi Ministry of Health on the English-language dark web forum DarkForums. The actor claims the database contains approximately 480,000 personnel records and shared sample screenshots as supposed proof of possession.
VULNERABILITY AND EXPLOIT INTELLIGENCE
Apple releases security updates: Apple has released patches (iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2) for over 30 vulnerabilities across Kernel, WebKit, WebRTC, and libxslt components in response to AI cybersecurity concerns. Majority of the fixes target the WebKit flaws that could enable malicious web content to crash Safari, and expose sensitive user information.
Affected products: The affected products are listed here.
CVE-2026-46817: A critical vulnerability in the File Transmission component of Oracle E-Business Suite's (EBS) Oracle Payments product is being actively exploited. The flaw enables an unauthenticated attacker with HTTP network access to take over vulnerable systems through low-complexity attacks. Oracle released a fix for the vulnerability as part of its May 2026 Critical Security Patch Update.
Affected products: Oracle E-Business Suite versions 12.2.3-12.2.15
Tags: DIB, tlp:green