ZeroFox Daily Intelligence Brief - July 9, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 9, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- China-Linked Campaign Targets Universities in U.S. and Canada
- Telstra Network Outage Halts Trains, Freezes Payments Across Australia
- Geopolitical Focus: U.S. Launches Fresh Strikes on Iran, Typhoon Bavi Moves towards Taiwan, and More
China-Linked Campaign Targets Universities in U.S. and Canada
What we know: A China-linked threat group, known as “UNK_MassTraction,” is reportedly targeting U.S. and Canadian universities by exploiting vulnerable Roundcube servers to steal credentials and deploy backdoor malware. Separately, Canada-based Mount Royal University confirmed a data breach after threat group CMD Organization listed it on their leak site.
Context: The campaign has been targeting physics and engineering departments, along with staff involved in astrophysics, particle physics, or national security research. It begins with a phishing email, clicking on which results in exploitation of a cross-site scripting (XSS) flaw in vulnerable Roundcube webmail. loading a credential-stealing payload called IceCube. A second flaw, CVE-2025-49113, is used to install VShell backdoor for follow-on access.
Analyst note: The targeting of physics, engineering, and national security research departments likely suggests a deliberate state intelligence-gathering effort regarding emerging technologies with defense or military value. Additionally, the Mount Royal breach likely indicates emerging threat actor interest in breaching North American universities.
Telstra Network Outage Halts Trains, Freezes Payments Across Australia
What we know: Telstra, an Australian telecommunication provider, reportedly experienced a nationwide service outage on July 8, 2026, leading to disruption of train services, phone calls, and wireless payment systems, among others. The company did not attribute the outage to any cyberattack but confirmed it was due to a software defect.
Context: At the time of writing, the outage is still being remediated. The software defect reportedly affected time synchronization servers at Telstra's Sydney and Melbourne data centers.
Analyst note: The outage is likely to trigger an influx of phishing websites, fraudulent support pages, and videos containing malicious links that claim to restore affected services or resolve connectivity issues, with the aim of stealing credentials or conducting financial fraud.
Geopolitical Focus: U.S. Launches Fresh Strikes on Iran, Typhoon Bavi Moves towards Taiwan, and More
- The United States launched new strikes on sites in Iran after attacks on commercial ships in the Strait of Hormuz, triggering Iranian attacks on U.S.-linked military sites in Kuwait and Bahrain. U.S. President Donald Trump also ordered an immediate halt to all trade with Spain following disagreements over NATO defence spending and the Iran war.
- Typhoon Bavi is moving towards Taiwan and eastern China, with authorities warning residents to prepare for severe weather ahead of its expected landfall. Severe storms across China have killed at least 15 people, prompting President Xi Jinping to order an all-out rescue effort.
- The Democratic Republic of the Congo (DRC) has reported at least 600 confirmed Ebola-related deaths, with the number of confirmed cases rising to 1,759. Health authorities also reported 51 new cases and 20 additional deaths in the past 24 hours.
- Ukraine has stepped up its campaign against Russian merchant shipping in the Sea of Azov to disrupt fuel supplies to occupied Crimea. The Ukrainian military said it struck eight fuel tankers after targeting two larger vessels from Russia's shadow fleet a day earlier.
DEEP AND DARK WEB INTELLIGENCE
PwnForums user TheSyndicate: Untested threat actor “TheSyndicate” has allegedly breached data from Nayax, an Israeli global fintech company, on dark web forum PwnForums and their leak site. The actor claims to have maintained access for approximately one year, exfiltrating over 100 terabytes of data including personally identifiable information (PII), approximately 1 billion card records, Know Your Customer (KYC) details, internal API keys and credentials, financial records, and source code repositories. Nayax is also reportedly investigating an unusual activity affecting the cloud accounts of one of its subsidiaries.
DATA BREACHES INTELLIGENCE
AssuranceAmerica reports data breach: AssuranceAmerica, a U.S.-based car and rental insurance provider, has confirmed a data breach affecting approximately 6.99 million individuals. Threat actors targeted a company employee to gain access to their systems on March 17, 2026. The stolen data reportedly includes customer names, contact information, driver's license numbers, auto insurance policy and account details, vehicle and driver information, and insurance claims data. No threat actor has been attributed.
VULNERABILITY AND EXPLOIT INTELLIGENCE
Ubiquiti releases security updates: Ubiquiti has released patches for seven critical vulnerabilities across UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. The flaws enable network-adjacent attackers to execute arbitrary commands, escalate privileges, and make unauthorized device changes across affected products via command injection, SQL injection, server-side request forgery (SSRF), and improper access control issues.
Affected products: The affected products are listed here.
Tags: DIB, tlp:green