zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 3, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 3, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • FBI Issues Advisory on TeamPCP Software Supply Chain Campaign
  • NetNut Infrastructure Disrupted, Limiting Proxy Operations
  • Geopolitical Focus: Iran Prepares for AliKhamenei’s Funeral, West Africa Floods Kill 59 since May

FBI Issues Advisory on TeamPCP Software Supply Chain Campaign

Source: https://www.ic3.gov/CSA/2026/260702.pdf

What we know: The FBI has released an advisory detailing threat group TeamPCP’s tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs). The group has conducted large-scale software supply chain attacks targeting widely used developer and security tools.

Context: TeamPCP’s campaign weaponized widely used CI/CD tools through trojanized updates and deployed four custom malware families: CanisterWorm, SANDCLOCK, Mini Shai-Hulud, and Miasma. The group has also engaged in extortion by publishing victim names on a public leak site and threatening to disclose stolen data.

Analyst note: The theft of cloud credentials and infrastructure access creates opportunities for follow-on operations, including ransomware, extortion, and access brokerage. As similar large-scale supply chain operations are likely to become more frequent with the open sourcing of TeamPCP’s Shai Hulud malware, there is a growing need for Zero Trust CI/CD practices, software provenance verification, and continuous credential hygiene.

NetNut Infrastructure Disrupted, Limiting Proxy Operations

Source: https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html

What we know: FBI and partners have reportedly weakened the NetNut residential proxy network by disabling accounts used to support its malware command-and-control (C2) infrastructure.

Context: Over 300 distinct cybercriminal threat clusters reportedly used NetNut exit nodes in June 2026 to carry out activities like password-guessing attacks. The proxy network has reportedly been linked to a publicly traded Israeli company, which denies the alleged connection. The network reportedly consisted of over 2 million compromised home devices like Android TV boxes, Smart TVs, and Streaming devices.

Analyst note: Although weakening the network is unlikely to completely dismantle the proxy network, the operation is likely to immediately reduce NetNut's capacity to facilitate cybercriminal activity. Threat actors are likely to be forced to migrate to alternative proxy providers or reseller networks. The migration is likely to enable law enforcement to identify and monitor threat actors through honeypot proxy infrastructure.

Geopolitical Focus: Iran Prepares for Ali Khamenei’s Funeral, West Africa Floods Kill 59 Since May

  • Tehran is reportedly preparing for former Supreme Leader Ayatollah Ali Khamenei’s funeral, to be held between July 4-9, 2026. Meanwhile,Iran’s Revolutionary Guard Gen. Ahmad Vahidi has made his first public appearance since reportedly being wounded in Israeli airstrikes.
  • U.S.-Iran talks have been paused ahead of the funeral ceremonies, with Iranian negotiators departing Doha and the U.S. military deploying additional forces to the Middle East as regional tensions remain high.
  • Torrential rains and flooding across coastal West Africa have reportedly killed at least 59 people in Côte d'Ivoire since May 2026, with authorities warning of rising casualties, particularly in Abidjan. Severe flooding has extended into Ghana, Nigeria, Benin, and Togo, disrupting critical power infrastructure and raising regional flood alarms.
  • The WHO has launched the "PARTNERS" clinical trial in the Democratic Republic of Congo (DRC) to evaluate MBP134 and remdesivir as the first treatments for the rare, vaccine-resistant Bundibugyo Ebola strain. The trial begins amid more than 1,400 confirmed cases.
  • Russian drone strikes reportedly hit Kyiv during early hours of Thursday, with 30 reported fatalities, forcing President Zelenskyy to cut short his diplomatic visit to Dublin. This coincided with targeted Russian strikes on retail fuel stations across other regions in Ukraine, resulting in at least one civilian death.

DEEP AND DARK WEB INTELLIGENCE

PwnForums user pine: Threat actor "pine" has leaked a partial dataset allegedly associated with Asendia, a subsidiary of Swiss Post and La Poste, which are major providers of international e-commerce logistics and cross-border mail delivery. The alleged dataset contains 123,257 records, including sender and recipient names, approximate delivery locations, and other delivery-related information. If legitimate, the exposed data is likely to facilitate phishing and social engineering using fake delivery alerts, or financial fraud targeting customers and logistics operations.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2026-8451: This is an out-of-bounds read vulnerability in Citrix NetScaler ADC and NetScaler Gateway configured as a SAML Identity Provider (IDP). The flaw enables the XML parser to read past the memory buffer and return sensitive memory contents in an HTTP response cookie. This vulnerability is being actively exploited within 24 hours of public disclosure. Organizations unable to patch immediately should disable SAML IDP and inspect logs for suspicious /saml/login traffic and anomalous NSC_TASS cookie values.

Affected products: The affected products are listed here.

Tags: DIBtlp:green