zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 9, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 9, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • China-Linked Campaign Targets Universities in U.S. and Canada
  • Telstra Network Outage Halts Trains, Freezes Payments Across Australia
  • Geopolitical Focus: U.S. Launches Fresh Strikes on Iran, Typhoon Bavi Moves towards Taiwan, and More

China-Linked Campaign Targets Universities in U.S. and Canada

Source: https://www.bleepingcomputer.com/news/security/hackers-exploit-roundcube-flaw-to-spy-on-academic-researchers/

What we know: A China-linked threat group, known as “UNK_MassTraction,” is reportedly targeting U.S. and Canadian universities by exploiting vulnerable Roundcube servers to steal credentials and deploy backdoor malware. Separately, Canada-based Mount Royal University confirmed a data breach after threat group CMD Organization listed it on their leak site.

Context: The campaign has been targeting physics and engineering departments, along with staff involved in astrophysics, particle physics, or national security research. It begins with a phishing email, clicking on which results in exploitation of a cross-site scripting (XSS) flaw in vulnerable Roundcube webmail. loading a credential-stealing payload called IceCube. A second flaw, CVE-2025-49113, is used to install VShell backdoor for follow-on access.

Analyst note: The targeting of physics, engineering, and national security research departments likely suggests a deliberate state intelligence-gathering effort regarding emerging technologies with defense or military value. Additionally, the Mount Royal breach likely indicates emerging threat actor interest in breaching North American universities.

Telstra Network Outage Halts Trains, Freezes Payments Across Australia

Source: https://www.reuters.com/business/media-telecom/telstra-outage-disrupts-australian-train-services-taxi-payments-2026-07-07/

What we know: Telstra, an Australian telecommunication provider, reportedly experienced a nationwide service outage on July 8, 2026, leading to disruption of train services, phone calls, and wireless payment systems, among others. The company did not attribute the outage to any cyberattack but confirmed it was due to a software defect.

Context: At the time of writing, the outage is still being remediated. The software defect reportedly affected time synchronization servers at Telstra's Sydney and Melbourne data centers.

Analyst note: The outage is likely to trigger an influx of phishing websites, fraudulent support pages, and videos containing malicious links that claim to restore affected services or resolve connectivity issues, with the aim of stealing credentials or conducting financial fraud.

Geopolitical Focus: U.S. Launches Fresh Strikes on Iran, Typhoon Bavi Moves towards Taiwan, and More

DEEP AND DARK WEB INTELLIGENCE

PwnForums user TheSyndicate: Untested threat actor “TheSyndicate” has allegedly breached data from Nayax, an Israeli global fintech company, on dark web forum PwnForums and their leak site. The actor claims to have maintained access for approximately one year, exfiltrating over 100 terabytes of data including personally identifiable information (PII), approximately 1 billion card records, Know Your Customer (KYC) details, internal API keys and credentials, financial records, and source code repositories. Nayax is also reportedly investigating an unusual activity affecting the cloud accounts of one of its subsidiaries.

DATA BREACHES INTELLIGENCE

AssuranceAmerica reports data breach: AssuranceAmerica, a U.S.-based car and rental insurance provider, has confirmed a data breach affecting approximately 6.99 million individuals. Threat actors targeted a company employee to gain access to their systems on March 17, 2026. The stolen data reportedly includes customer names, contact information, driver's license numbers, auto insurance policy and account details, vehicle and driver information, and insurance claims data. No threat actor has been attributed.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Ubiquiti releases security updates: Ubiquiti has released patches for seven critical vulnerabilities across UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. The flaws enable network-adjacent attackers to execute arbitrary commands, escalate privileges, and make unauthorized device changes across affected products via command injection, SQL injection, server-side request forgery (SSRF), and improper access control issues.

Affected products: The affected products are listed here.

Tags: DIBtlp:green