zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 6, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 6, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Langflow Flaw Exploited in AI Ransomware Attack
  • North Korean “PolinRider” Campaign Compromises 1,900+ Repos
  • Threat Group Armored Likho Targets Government and Energy Sectors

Langflow Flaw Exploited in AI Ransomware Attack

Source: https://www.securityweek.com/agentic-ai-used-to-conduct-ransomware-attack-via-langflow/

What we know: A threat actor, known as “JadePuffer,” reportedly launched a ransomware attack using AI after exploiting a vulnerability in Langflow (CVE-2025-3248). Using AI, the threat actor conducted reconnaissance, stole credentials, moved laterally, established persistence, and encrypted configuration data.

Context: It is reportedly the first ransomware attack using a large language model (LLM) agent. The LLM encrypted 1,342 Alibaba Naming and Configuration Service (Nacos) configuration items, deleted the originals, and left a ransom note, while adapting its actions to errors throughout the intrusion.

Analyst note: This development highlights LLM’s ability for autonomous decision-making as demonstrated throughout the attack to ensure its success. Immature ransomware operators are likely to adopt similar fully automated attack techniques. Ransomware-as-a-service (RaaS) operators are likely to integrate such functionality into their offerings to increase the speed, scale, and sophistication of attacks.

North Korean “PolinRider” Campaign Compromises 1,900+ Repos

Source: https://thehackernews.com/2026/07/north-korean-hackers-publish-108.html

What we know: North Korean threat actors linked to the “Contagious Interview” campaign have reportedly published 108 malicious packages and browser extensions across npm, Packagist, Go, and the Chrome Web Store. The ongoing software supply chain campaign, dubbed "PolinRider," has compromised at least 1,951 public GitHub repositories till date.

Context: The campaign operates alongside a merged cluster called "TaskJacker," which injects malicious VS Code task files into developers' existing repositories to deliver a new variant of the BeaverTail infostealer. Parallelly, another cluster of malicious npm packages mimicking Rollup polyfills were discovered linked to Contagious Interview, deploying multi-stage loaders to steal developer secrets and local configurations for AI-assisted coding tools like Claude and Gemini.

Analyst note: Threat actors will likely use the stolen credentials to modify or steal software source code or launch downstream supply chain attacks.

Threat Group Armored Likho Targets Government and Energy Sectors

Source: https://thehackernews.com/2026/07/armored-likho-targets-government.html

What we know: A previously undocumented threat actor, known as “Armored Likho,” has reportedly been deploying a newly identified infostealer “BusySnake” targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan.

Context: Armored Likho reportedly conducts both financially motivated campaigns and targeted espionage operations against organizations. Attack chains originate with spear-phishing emails using government notice, which deliver malicious payloads that further exploit CVE-2025-9491, a now-patched Windows shortcut vulnerability, to deploy BusySnake.

Analyst note: The threat actor will very likely use compromised credentials and collected data to maintain access to government and energy sector networks. The targeting of energy infrastructure is particularly notable, as successful compromises are likely to enable long-term intelligence collection against critical infrastructure and increase the risk of follow-on malicious activity with potential national security and economic implications.

DEEP AND DARK WEB INTELLIGENCE

AdaptHealth discloses data breach: Medical equipment provider AdaptHealth has disclosed a data breach, where attackers gained unauthorized access to internal patient management and document storage systems, exposing personally identifiable information (PII), protected health information (PHI), and insurance billing-related credentials. Threat group ShinyHunters has reportedly claimed responsibility for the breach by listing the company on their leak site.

DATA BREACHES INTELLIGENCE

Shun Hing Group allegedly breached: Shun Hing Group, the sole authorized distributor of Panasonic and KDK products in Hong Kong and Macau, has reportedly confirmed that threat actors compromised the personal data of more than 921,000 customers and staff. The potentially affected information includes customer names, addresses, phone numbers, and email addresses. The data is likely to be leveraged in phishing, identity theft, and other fraud targeting the exposed individuals.

VULNERABILITY AND EXPLOIT INTELLIGENCE

FatFs filesystem vulnerabilities: Seven vulnerabilities have been disclosed in the FatFs filesystem library. The flaws can cause memory corruption and also enable remote code execution (RCE) via malicious USB drives, SD cards, or firmware images. Threat actors with physical access to vulnerable devices could exploit these flaws to gain full control.

Affected products: FatFs filesystem

Tags: DIBtlp:green