ZeroFox Daily Intelligence Brief - July 8, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 8, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ZeroFox Intelligence Flash Report - Accenture Allegedly Breached
- GitLost Prompt Injection Attack Targets GitHub Agentic Workflows
- China-Aligned Campaign Targets Internet-Facing Routers
ZeroFox Intelligence Flash Report - Accenture Allegedly Breached
Source: https://www.zerofox.com/advisories/40849/
What we know: Prominent threat actor “888” has advertised a dataset allegedly stolen from Accenture, an Ireland-based professional services and management consulting company, on dark web forum PwnForums. 888 is also a moderator of PwnForums.
Context: The threat actor claimed Accenture suffered an intrusion in July 2026 that resulted in the theft of more than 35 GB of source code and related sensitive assets. As proof of the breach, 888 shared a sample file tree from the allegedly compromised dataset. The price has not been disclosed.
Analyst note: The dataset is likely legitimate based on 888's reputation within PwnForums and the specificity of the shared sample. However, the breach remains unverified pending confirmation from Accenture or independent validation of the data.
GitLost Prompt Injection Attack Targets GitHub Agentic Workflows
Source: https://www.darkreading.com/cyber-risk/gitlost-leaks-private-data-github-agentic-workflows
What we know: A prompt injection vulnerability, dubbed GitLost, is reportedly affecting GitHub Agentic Workflows. The flaw enables an unauthenticated attacker to manipulate AI-powered GitHub automation into accessing and leaking data from an organization's private repositories.
Context: Attackers can exploit this flaw by submitting a malicious GitHub Issue, containing hidden natural-language instructions, to a public repository monitored by GitHub Agentic Workflows. Launched in February 2026, GitHub Agentic Workflows enables AI agents, running within GitHub Actions, to automate repository tasks.
Analyst note: By manipulating these agents, threat actors are likely to abuse legitimate permissions without compromising accounts or exploiting software vulnerabilities, thereby rendering traditional defense mechanisms inefficient. Victim organizations are likely to succumb to espionage, intellectual property theft, and software supply chain compromise.
China-Aligned Campaign Targets Internet-Facing Routers
What we know: China-aligned threat actor "UAT-7810”’ has developed a new malware variant, LONGLEASH, to expand its Operational Relay Box (ORB) network. The network has compromised internet-facing edge devices, primarily unpatched Ruckus and ASUS routers.
Context: UAT-7810's ORB network serves as a secure relay infrastructure for other China-aligned APTs, proxying network traffic through regional devices to evade detection and complicate attribution. LONGLEASH expands on its predecessor SHORTLEASH with added capabilities.
Analyst note: As China-aligned APTs continue to mature and share relay infrastructure, their collective reach is likely to grow. Organizations should prioritize patching of known vulnerabilities in internet-facing devices and monitor for unusual outbound traffic patterns indicative of unauthorized relay activity.
DEEP AND DARK WEB INTELLIGENCE
PwnForums user lastopsecbroker: Untested threat actor “lastopsecbroker” has claimed to have leaked data associated with Hellenic Navy, the naval force of Greece, after identifying unauthorized access to a system. The threat actor alleged that Hellenic Navy's administrative interface could be accessed through a disclosed IP address. The actor included a supposed administrator login panel URL and administrator credentials for app[.]hellenicnavy[.]gr.
DATA BREACHES INTELLIGENCE
Washington DSHS data breach: The Washington Department of Social and Health Services (DSHS) has reportedly disclosed a data breach after a former employee allegedly accessed personal information without authorization, potentially affecting 8,600 people. The exposed data may include names, dates of birth, Social Security numbers, DSHS client numbers, and program enrollment information.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2026-11405: This is a hidden authentication backdoor vulnerability affecting multiple Tenda router firmware versions. The flaw reportedly enables threat actors to bypass normal authentication and gain administrator access to the router's web management interface, using an alternate password stored in the device configuration. At the time of writing, the issue remains unfixed. Although no active exploitation has been reported, the flaw is likely to attract botnets targeting vulnerable routers.
Affected products: The affected versions are listed in this advisory.
Tags: DIB, tlp:green