ZeroFox Weekly Intelligence Brief – July 18, 2026
|by Alpha Team

ZeroFox Weekly Intelligence Brief – July 18, 2026
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 6:00 AM (EST) on July 16, 2026; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Telegram Shortlink Domain t[.]me Restored
What we know:
- Telegram’s shortened t[.]me domain has been restored following a day-long serverHold suspension on July 13, 2026.
- The outage blocked the one-click t[.]me links used to join public Telegram groups.
World Leaks Publishes Blueprints and Supplier Data of Indian Nuclear Plant
What we know:
- The World Leaks ransomware group has published approximately 858,000 files allegedly linked to Reliance Group, including around 19,000 files related to India’s largest nuclear power plant in Kudankulam .
CISA Warns of Active Exploitation of SharePoint Vulnerabilities
What we know:
- The Cybersecurity and Infrastructure Security Agency (CISA) has warned that threat actors are actively exploiting three SharePoint vulnerabilities (namely, CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) to gain unauthorized access to on-premises SharePoint Server instances.
- Additionally, CISA has also highlighted CVE-2026-55040 and CVE-2026-58644 as newly disclosed vulnerabilities that are not yet known to be exploited but should be patched promptly.
Tags: tlp:green