ZeroFox Daily Intelligence Brief - July 20, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 20, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Abbott Laboratories Environments Compromised
- New "NadMesh" Botnet Targets Exposed AI Services
- Geopolitical Focus: Middle East Conflict, Iran Threatens Hormuz Shipping, Peru Quakes Leave Multiple Dead
Abbott Laboratories Environments Compromised
What we know: Abbott Laboratories was reportedly targeted in two apparently unrelated cyber attacks. One of the attacks allegedly involved unauthorized access to internal Exact Science systems in its Cancer Diagnostics business, while another claimed unauthorized access to its LabCentral customer portal.
Context: ShinyHunters claims to have gained initial access to the Exact Sciences systems via a vishing attack against employees, enabling them to compromise a single sign-on (SSO) account to gain access. The group claims to have stolen more than 30 million rows of personally identifiable information (PII) of customers, as well as 22 million notes of conversations between doctor-patient and 20 million medical orders. Separately, threat actor “ShadowByt3$” claims to have accessed Abbott's LabCentral portal through compromised customer credentials and exfiltrated proprietary business documents and intellectual property.
Analyst note: The near-simultaneous targeting of a major healthcare organization by two apparently distinct threat actors almost certainly reflects the sustained and escalating interest of cybercriminals in the medtech sector. Claims of both patient-facing data and internal intellectual property theft suggest a deliberate dual-extortion strategy that increases pressure on victim organizations to negotiate. Organizations in the healthcare sector should anticipate an escalation in identity-focused social engineering campaigns and reassess identity management controls accordingly.
New "NadMesh" Botnet Targets Exposed AI Services
Source: https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
What we know: A new Go-based botnet dubbed "NadMesh" scans for exposed AI services to harvest cloud environment variables, AWS keys, Kubernetes cluster tokens, and AI model access. The operator's control panel reportedly claims to have harvested over 3,800 unique AWS keys.
Context: The primary intrusion vectors reportedly exploit open Docker APIs and Jenkins script consoles, though the botnet also targets unauthenticated Redis instances, weak Telnet/SSH credentials, and unauthenticated Model Context Protocol (MCP) commands. Notably, the malware persists in three different ways at once and obfuscates each copy so that no two files share the same hash, meaning a single file fingerprint will not detect all instances. The malware also auto-blacklists suspected honeypots, suggesting the threat actor is actively monitoring for security researchers to evade detection.
Analyst note: Threat actors are likely to use stolen AWS keys and Kubernetes cluster tokens to bypass traditional network defenses and laterally move into broader enterprise environments to steal data and launch supply-chain attacks. The access is likely to be leveraged for data theft, cloud resource abuse such as large-scale LLM consumption (LLMjacking), or resale to initial access brokers.
Geopolitical Focus: Middle East Conflict, Iran Threatens Hormuz Shipping, Peru Quakes Leave Multiple Dead
- The United States has reportedly conducted a ninth consecutive night of strikes on Iran. Additionally, Kuwait has reported another Iranian strike on a power and desalination plant and Jordan and Bahrain intercepting incoming attacks.
- Iran's Islamic Revolutionary Guard Corps (IRGC) has claimed that two oil tankers were disabled while transiting an alternative route near the Strait of Hormuz, although the claims remain unverified. The IRGC has also warned that no oil, gas, or petrochemical shipments would safely transit the Strait of Hormuz as long as aggression in the region persists.
- Brent crude price has risen above USD 90 per barrel after the recent escalating U.S.-Iran hostilities have disrupted oil shipments through the Strait of Hormuz.
- At least six people were killed and 21 injured after two earthquakes struck Peru's Junín region, affecting around 300 residents.
- Three people have died in a Legionnaires' disease outbreak on New York City's Upper East Side, where 74 cases have been reported and officials linked the infections to contaminated building cooling towers. Additionally, the FDA said that the initial positive test linking iceberg lettuce to the Cyclospora outbreak was a false positive, leaving the source of the infections under investigation.
DEEP AND DARK WEB INTELLIGENCE
Exploit user chemda5lek3asba: An untested threat actor “chemda5lek3asba” has advertised over 30,000 alleged business-level API keys on Russian-language dark web forum Exploit. The threat actor claims the listing includes API keys associated with GitHub, Platform (GCP), OpenAI,Telegram, and identifies wallstreetitalia[.]com and shift44[.]com as examples of affected entities. The dataset was likely aggregated from multiple sources, consistent with threat actors harvesting exposed API keys from public repositories, paste sites, and leaked datasets.
DATA BREACHES INTELLIGENCE
Ecopetrol confirms data breach: Colombia's state-owned energy company Ecopetrol has disclosed that a cyberattack resulted in the theft of data linked to approximately 3,300 user accounts, warning the incident could have a “material adverse” impact.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2026-39808 and CVE-2026-25089: These are actively exploited OS command injection vulnerabilities in FortiSandbox that can enable unauthenticated attackers to execute arbitrary commands through specially crafted HTTP requests, without requiring valid credentials or user interaction, leading to remote code execution. Fortinet has released patches for the vulnerability.
Affected products: FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS
CVE-2026-15409 and CVE-2026-15410: These are actively exploited zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. When chained together, the flaw can enable attackers to execute arbitrary commands and take over susceptible devices. The vulnerabilities have been exploited as zero-days by a previously undocumented threat actor tracked as UTA0533. SonicWall has released patches.
Affected products: SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances
Tags: DIB, tlp:green