ZeroFox Daily Intelligence Brief - July 27, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 27, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Europol Disrupts an Online Violent Extremist Ecosystem
- Data Leaked by ShinyHunters Used in Sextortion Emails
- U.S. Pauses Strikes on Iran, Shooting in Seattle, Wildfires in France and Spain
Europol Disrupts an Online Violent Extremist Ecosystem
What we know: Europol has disrupted the online ecosystem of a decentralized network of nihilistic violent extremist groups known as "The Com." As part of the operation, 4,340 URLs hosting illegal and extremist content were disrupted.
Context: The network recruits, grooms, and radicalizes victims who are predominantly minors across social media and gaming platforms. Content disseminated includes child sexual abuse material (CSAM), self-harm and suicide footage, animal cruelty, and violent attack videos. Separately, Dutch authorities arrested a suspect in connection with The Com subgroup "764," on July 20, 2026.
Analyst note: Takedowns of URLs and arrest of the "764" suspect will very likely cause operational disruptions to the network. However, as Europol’s ECTC report highlights, a single enforcement action against the evolving network of “The Com” remains insufficient. Given the decentralized and adaptive nature of these online communities, the network will very likely attempt to reconstitute its presence.
Data Leaked by ShinyHunters Used in Sextortion Emails
What we know: Threat actors are using email addresses exposed in ShinyHunters-linked data breaches to send sextortion emails demanding USD 2,000 in Bitcoin. The emails falsely claim recipients' devices were compromised and appear to come from ShinyHunters.
Context: The campaign uses email addresses from leaked datasets associated with Hallmark, Substack, CarGurus, ADT, and McGraw Hill. The ShinyHunters extortion group has denied involvement in the campaign.
Analyst note: The incident demonstrates the prolonging impact of data breaches that can be reused by other threat actors for extortion and other social engineering attacks.
Geopolitical Focus: U.S. Pauses Strikes on Iran, Shooting in Seattle, Wildfires in France and Spain
- The United States has paused strikes on Iran amid ongoing diplomatic negotiations. Iran also said it is halting its “retaliatory” operations. Meanwhile, Israeli Prime Minister Benjamin Netanyahu is expected to visit the White House on July 28, 2026.
- Houthi forces struck oil installations in Jizan and Yanbu on Saturday, causing ship traffic through the Bab el-Mandeb strait to drop to its lowest level in months. The disruption has pushed physical crude prices in the Middle East, Europe, and Africa to two-month highs.
- In the United States, two people were killed and at least five others injured in a shooting at the Bite of Seattle food festival on Sunday evening. No suspect has been identified or arrested, and authorities have asked the public to avoid the Seattle Center area.
- German police shot and killed a suspect in the Berlin Pride attack. The suspect is accused of vehicle-ramming into a crowd and stabbing attack near Brandenburg Gate on Saturday night, which killed one person and injured 29 others.
- A fast-moving wildfire in southwest France has forced 220,000 people from their homes, with flames advancing toward Bordeaux, while neighboring Spain also conducted evacuations along its eastern coast.
- The Democratic Republic of Congo has confirmed 3,200 Ebola cases including 1,405 deaths as of July 26, 2026.
DEEP AND DARK WEB INTELLIGENCE
BreachForums users 0cx00iq and Resolute: Threat actors "0cx00iq" and "Resolute" have independently advertised data allegedly associated with Saudi Arabia’s General Intelligence Presidency (GIP), on dark web forum BreachForums. The GIP is Saudi Arabia’s primary foreign intelligence agency. The datasets on both posts allegedly include information on 52,000 employees including their personally identifiable information (PII), government ID details, military rank, security clearance levels, and more. 0cx00iq is the moderator of BreachForums, while Resolute is the owner of the forum. If legitimate, exposed individuals are likely to face phishing and social engineering attempts, while adversarial nations may leverage the data for physical and cyber surveillance. Forum owners are also likely to exploit the listing to scam buyers ahead of a potential forum shutdown.
DATA LEAKS
Vatican prayer app exposes users: The Vatican's official prayer app "Click to Pray" was reportedly found exposing the personally identifiable information (PII) of over 700,000 users through an unauthenticated, publicly accessible API endpoint vulnerable to an insecure direct object reference (IDOR) flaw. The vulnerability requires no technical skill to exploit and remains unpatched at the time of publication.
Tribeca Film Festival data leak: Four publicly accessible, unprotected databases reportedly associated with the Tribeca Film Festival have been discovered exposed online. The databases reportedly contain a total of 666,369 records from 2019 to 2026. The exposed data includes images, press kits, confidential documents, and a production backup file containing 295,916 records with email addresses, phone numbers, IP addresses, and hashed passwords linked to users, film contacts, and industry personnel, including that of A-list directors and celebrities.
VULNERABILITY AND EXPLOIT INTELLIGENCE
Rockwell Automation security patches: Rockwell Automation has patched four high-severity vulnerabilities in its Arena Simulation software. The flaws could enable attackers to execute arbitrary code on affected systems. The flaws—CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, and CVE-2026-8314—are memory corruption issues stemming from improper validation of user-supplied data that can result in an out-of-bounds write. Successful exploitation is likely to enable attacks to manipulate simulation models and workflow data leading to compromised results. Data theft and malware / ransomware deployment are also likely.
Affected products: Arena versions up to and including 17.00.00
Tags: DIB, tlp:green