zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 14, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 14, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ShareFile Storage Zone Controllers Under “Security Threat”
  • CISA Warns of Russian State-Sponsored Targeting of Critical Infrastructure
  • German Textile Firm Files for Insolvency Following Cyberattack

ShareFile Storage Zone Controllers Under “Security Threat”

Source: https://www.securityweek.com/progress-prompts-sharefile-storage-zone-controller-shutdown-amid-security-concerns/

What we know: Major Enterprise software company Progress Software has warned of a “credible external security threat” targeting ShareFile Storage Zone Controllers and urged affected customers to immediately shut down the servers. Progress has also disabled access to ShareFile accounts using Storage Zone Controllers while it investigates the threat.

Context: The company's decision to immediately shut down Storage Zone Controllers likely suggests it is responding to a zero-day vulnerability. Successful compromise is likely to enable threat actors to pivot further into enterprise environments.

Analyst note: Ideologically motivated actors likely view MLB All-Star events as an opportunity to cause violent disruption or spread their message, while financially motivated cyber collectives are likely to impersonate official platforms to target fans seeking tickets. Additionally, active illicit game-streaming infrastructure and the biometric entry system for All-Star Week 2026 events almost certainly expand the digital attack surface.

CISA Shares Incident Response Strategy Following Data Exposure

Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a

What we know: A joint advisory by CISA and U.S. allies warns that Russian Federal Security Service (FSB) Centre 16 cyber actors are continuing to exploit poorly configured and vulnerable networking devices to compromise critical infrastructure networks globally.

Context: FSB Centre 16 scans for internet-facing devices using default or weak Simple Network Management Protocol (SNMP) community strings to extract device configurations and establish footholds. Separately, the European Union (EU) and the United Kingdom have formally attributed a December 2025 attack on Poland's energy grid to FSB Centre 16 and jointly sanctioned 24 individuals and entities linked to Russian Russian state and criminal networks.

Analyst Note: The advisory and the sanctions likely reflect a coordinated western effort to expose and deter Russian state cyber operations. Anticipating tighter defensive measures, Russian actors will likely broaden their targeting or adapt their operational security to bypass traditional detection.

German Textile Firm Files for Insolvency Following Cyberattack

Source: https://www.theregister.com/cyber-crime/2026/07/13/german-firm-files-for-insolvency-blames-cybercrims-who-shut-down-production-for-6-weeks/5270524

What we know: German textile company ZEGO Textilveredelungszentrum GmbH has filed for insolvency, citing financial fallout from a cyberattack on March 29, 2026. The attack had reportedly halted production for nearly six weeks.

Context: The attack type and data compromise remain undisclosed. ZEGO intends to keep the production running while restructuring the business, preserving jobs, and retaining its customer and supplier base. Similarly, ZeroFox had observed Akira ransomware group listing UK haulage firm Knights of Old on its leak site in 2023, roughly a year before its downfall.

Analyst Note: The insolvency is likely to impact companies and factories within ZEGO's supply chain network, particularly the workwear brands relying on it. The incident underscores the risk of cybercrime crippling production lines due to heavy integration with digital systems combined with limited security budget. Other threat actors are likely to target small- and mid-sized suppliers as disruption to their businesses risk continuity and increase the likelihood of ransom payments.

DEEP AND DARK WEB INTELLIGENCE

Telegram user Dark Storm Team: Pro-Palestinian hacktivist group Dark Storm Team has claimed a distributed denial-of-service (DDoS) attack against nypdonline[.]org, an official portal of the New York City Police Department (NYPD), on its Telegram channel. The claim is unlikely to be true or successful as the website remains operational and there are no official reports from the NYPD confirming the incident.

DATA BREACHES INTELLIGENCE

Lidl discloses data breach: Lidl, a German discount supermarket chain, has disclosed a data breach after attackers compromised an external IT service provider used for its online shop. There are two separate notifications on its websites in Belgium and the Netherlands. The breach exposed customer information, including names, email addresses, phone numbers, dates of birth, and customer numbers. Lidl has advised affected customers to watch out for phishing and identity theft attempts.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2026-56291 and CVE-2026-48939 These are actively exploited unauthenticated arbitrary file upload vulnerabilities in the Balbooa Forms and iCagenda Joomla extensions respectively. The flaws reportedly enable attackers to upload malicious PHP files and achieve remote code execution (RCE).

Affected products: Balbooa Forms versions prior to v2.4.1 and iCagenda versions prior to v4.0.8 and v3.9.15.

Tags: DIBtlp:green