ZeroFox Daily Intelligence Brief - July 21, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 21, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Hugging Face Urges Users to Rotate Credentials Following Data Breach
- Healthcare Vendor Craneware Breached
- Houthis Threaten Red Sea Shipping Alternative to Strait of Hormuz
Hugging Face Urges Users to Rotate Credentials Following Data Breach
Source: https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html
What we know: AI model repository Hugging Face has disclosed a data breach reportedly driven end-to-end by an autonomous AI agent system. Ongoing investigation has revealed unauthorized access to a limited set of internal datasets and credentials, which it has since revoked and rotated.
Context: Threat actors reportedly gained access to Hugging Face's automated dataset-processing pipeline using a malicious dataset. They then escalated to node-level access, harvested cloud and cluster credentials, and moved laterally into multiple internal clusters. The campaign was reportedly orchestrated by an autonomous agent framework.
Analyst note: Threat actors are likely to leverage the exfiltrated data to target Hugging Face users and downstream organizations through phishing and credential abuse. Emerging botnets capable of compromising exposed AI services are likely to be deployed to execute similar automated attacks.
Healthcare Vendor Craneware Breached
What we know: U.K.-based healthcare billing software provider Craneware has confirmed a cyberattack in which a significant volume of customer, employee, and partner data was exfiltrated from its systems.
Context: Craneware's software is used by thousands of clinics, hospitals, and pharmacies across the United States, handling large volumes of medical records and patient data. The company states the incident has been contained and that a large portion of the exfiltrated data is either non-sensitive or already public regulatory data.
Analyst note: As enterprise software platforms handle increasingly large volumes of centralized customer records, they are very likely to remain top-priority targets for cyber extortion. The exfiltrated data could enable attackers to carry out targeted social engineering campaigns.
Houthis Threaten Red Sea Shipping Alternative to Strait of Hormuz
Source: https://www.bbc.com/news/articles/cm2gmddx1ldo
What we know: Yemen's Houthis have announced an immediate "maritime embargo" against Saudi Arabia, supposedly in retaliation to Saudi blockade of ports and airports in Houthi-controlled areas. Houthi officials said they would close the Bab al-Mandab Strait to Saudi vessels.
Context: The Bab al-Mandab Strait has become a key route for Saudi oil exports following reduced transit through the Strait of Hormuz (SoH). Despite closures and uncertainty of SoH, global oil prices remained relatively stable. This was partly attributed to Saudi Arabia rerouting oil exports through the Red Sea as an alternative.
Analyst note: If the Houthis enforce the embargo, the ongoing disruption of the Strait of Hormuz and Bab al-Mandab are likely to reduce the resilience of current global energy supply chains. Shipping companies that recently resumed Red Sea transits, such as Maersk and Hapag-Lloyd, are likely to be forced to contend with routing decisions, increasing transit times, freight costs, and goods availability.
DEEP AND DARK WEB INTELLIGENCE
DarkForums user sheperd_craven: Untested threat actor “sheperd_craven” has advertised data allegedly associated with Uber Eats, a U.S.-based online food delivery platform, on the English-language dark web forum DarkForums. The threat actor claims the alleged dataset contains approximately 95 million records comprising personally identifiable information (PII) of customers and delivery personnel, including names, email addresses, phone numbers, delivery addresses, payment and order information, vehicle details, delivery statistics, and earnings.
DATA BREACHES INTELLIGENCE
Estée Lauder discloses data breach: Cosmetics giant Estée Lauder has disclosed a data breach after attackers reportedly exploited a vulnerability in its Oracle E-Business Suite (EBS) system used for human resources (HR) operations. The breach reportedly exposed PII of certain individuals, dates of birth, Social Security numbers (SSNs), passport numbers, financial account information (including bank account numbers), health information, and employment information. Previous breaches linked to exploitation of Oracle EBS systems have been attributed to the Clop ransomware group.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2026-6875: This is an actively exploited remote code execution (RCE) vulnerability in ServiceNow AI Platform, formerly known as the Now Platform. The flaw enables unauthenticated attackers to escape the sandbox and execute code remotely within the ServiceNow platform in high-complexity attacks.
Affected products: The affected products are listed in the advisory.
Tags: DIB, tlp:green