zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 17, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 17, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Scattered Spider Members Imprisoned for Transport for London Hack
  • KFC Japan and Others Hit as Cyberattack Disrupts Logistics Infrastructure
  • PhantomEnigma Campaign Abuses Over 20 Brazilian Government Websites

Scattered Spider Members Imprisoned for Transport for London Hack

Source: https://www.nationalcrimeagency.gov.uk/news/two-sentenced-for-hacking-transport-for-london-in-uk-s-biggest-ever-cyber-crime-case

What we know: Two prominent members of the Scattered Spider cybercrime collective have been sentenced to over five years in prison by UK authorities for the 2024 cyberattack of Transport for London (TfL).

Context: TfL suffered GBP 29 million (approx. USD 39 million) in loss and recovery costs due to the cyberattack. The cyberattack impacted a number of services used by the public including Dial-a-Ride booking service, digital payments channel, and concessionary travel cards. Authorities found laptops, computer towers, hard drives, and USB sticks as well as a screenshot showing network connectivity of TfL infrastructure at one of the perpetrator’s residences.

Analyst note: The law enforcement action has very likely halted Scattered Spider collective’s criminal activity, though other threat actors can continue using the threat collective brand name. Reports suggest the arrests materially degraded the group's ability to continue conducting cybercriminal operations.

KFC Japan and Others Hit as Cyberattack Disrupts Logistics Infrastructure

Source: https://www.theregister.com/security/2026/07/16/cyberattack-threatens-utterly-critical-infrastructure-in-japan-kfc/5272220

What we know: A cyberattack disrupted the operations of Nichirei Group, a Japanese cold-chain logistics provider, disrupting deliveries to customers including KFC Japan. The company confirmed unauthorized access to its systems and stated that a server containing personal information was accessed.

Context: The disruption prevented shipments to and from refrigerated warehouses. KFC Japan suspended online orders and warned that some stores could reduce menu options or temporarily close due to ingredient shortages.

Analyst note: The limited details released by Nichirei Group, including its decision to withhold technical information to prevent further damage, suggest the incident is likely still being contained. Additional impacts or affected customers may emerge as the investigation and recovery efforts continue.

PhantomEnigma Campaign Abuses Over 20 Brazilian Government Websites

Source: https://thehackernews.com/2026/07/20-hijacked-government-websites.html

What we know: Threat actors have reportedly hijacked more than 20 Brazilian government websites to distribute PhantomEnigma malware, using fake police-themed documents and compromised [.]gov[.]br infrastructure. The campaign reportedly exploited government websites and look-alike domains rather than targeting the government systems themselves.

Context: The PhantomEnigma campaign leveraged compromised Brazilian municipal, public security, and judicial portals at various stages of its malware delivery chain. The malware strain reportedly collected system information, including the computer name, username, and other host details.

Analyst note: By embedding malicious activity within trusted infrastructure, attackers likely increase the chances of successful phishing emails. This technique likely reinforces the need for security controls that evaluate user and endpoint behavior rather than relying primarily on domain legitimacy.

DEEP AND DARK WEB INTELLIGENCE

Exploit user Domperidone: Untested threat actor "Domperidone" has advertised a dataset allegedly associated with Monster[.]com, a Puerto Rico-based global job search engine, on dark web forum Exploit. According to the actor, the dataset includes information on 70,000 job seekers. The threat actor is seeking USD 5,000 for the dataset. If legitimate, threat actors are likely to use the aggregated data to automate phishing and social engineering attacks. However, the information collected is unlikely to be exclusive, as it can be accessed using an employer account and other platforms. The actor's lack of established reputation, absence of sample data, and the relatively high price for scraped information suggest the post is likely fraudulent.

VULNERABILITY AND EXPLOIT INTELLIGENCE

F5 vulnerabilities: F5 has released security updates addressing eight vulnerabilities across F5 products, NGINX and BIG-IP. It includes patches for CVE-2026-42533, a high severity flaw that can enable unauthenticated attackers to trigger a heap buffer overflow and also achieve remote code execution (RCE). The updates also fix multiple vulnerabilities that could enable memory disclosure, denial-of-service, arbitrary configuration injection, or file deletion.

Affected products: The affected products are listed here.

Tags: DIBtlp:green