ZeroFox Daily Intelligence Brief - July 29, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 29, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- OpenAI Rogue Agent Linked to Additional Third-Party Compromise
- TeamPCP Resurfaces to Sell Old Data: Assessing the Impact
- Coordinated Cyberattack Hits 30+ Minnesota Water Systems
OpenAI Rogue Agent Linked to Additional Third-Party Compromise
What we know: OpenAI’s rogue AI agent involved in the Hugging Face breach also reportedly breached a customer at U.S.-based tech company Modal. Modal reportedly confirmed that its underlying infrastructure, isolation mechanisms, and platform security controls remained intact; only a customer-hosted workload was abused.
Context: A customer code hosted on Modal platform had reportedly exposed an unauthenticated internet-facing endpoint that enabled code execution inside that customer’s sandbox environment. OpenAI’s agent reportedly exploited that exposed endpoint, gained access to the customer environment, and used it as part of the broader attack chain against Hugging Face. The rogue agent has also accessed four third-party accounts and services during the incident.
Analyst note: The Modal compromise shows the rogue agent roamed further than was previously known, and the confirmed count of four breached accounts suggests the full scope is likely still emerging. Organizations operating customer-facing sandbox or code-execution platforms should assume unauthenticated or publicly accessible endpoints are likely targets for AI-enabled opportunistic exploitation.
TeamPCP Resurfaces to Sell Old Data: Assessing the Impact
Source: https://www.zerofox.com/advisories/41199/
What we know: ZeroFox has observed a potential resurfacing of threat group TeamPCP following its relative operational silence since at least May 2026, disclosing and repurposing previously harvested data.
Context: On July 21, 2026, threat actor Xploitrs advertised data allegedly from the U.S.-based cybersecurity company RapidFort on dark web forums. The actor claimed the breach was part of TeamPCP's CanisterWorm campaign and dated the stolen data to March 2026. Xploitrs has allegedly remained a consistent partner to TeamPCP across several strained or unsuccessful collaborations.
Analyst note: ZeroFox assesses that the group is likely still validating and operationalizing credentials from the initial wave of compromises, and is sharing or selling datasets within the cybercriminal ecosystem. TeamPCP is also very likely interested in combining supply chain compromise and credential theft with ransomware deployment, which is very likely to significantly increase the operational and financial impact on affected organizations.
Coordinated Cyberattack Hits 30+ Minnesota Water Systems
What we know: A coordinated cyberattack reportedly targeted the operational technology (OT) infrastructure at more than 30 community water systems in Minnesota between July 26–27, 2026, with no reported breaches to water quality or safety.
Context: While no group has claimed responsibility for the attacks as of writing the article, Iran-linked hacktivist group Handala is reportedly suspected following similar alleged attacks on California Water Service (Cal Water), Maryland’s Operational Technology (OT) infrastructure and subsequent threats against critical U.S. infrastructure. Additionally, CISA has issued an advisory urging critical infrastructure operators to isolate OT from enterprise networks to limit intrusions.
Analyst note: Threat actors are likely to collect engineering project files to map the OT environment and establish a foothold for timed disruption using programming-level access. Threat actors are also likely to upload malicious logic, manipulate industrial processes, and potentially cause equipment damage or prolonged operational disruption.
DEEP AND DARK WEB INTELLIGENCE
DarkForums user skra1a: Untested threat actor "skra1a" has advertised persistent administrative access allegedly associated with the Saudi Arabian government web ecosystem (.gov[.]sa) on the English-language dark web forum DarkForums. According to the threat actor, the access includes an administrative panel, backend API keys, active SAML signing certificates, access to a connected .gov[.]sa subdomain, government Gmail SMTP access, SMS API keys, and a MySQL database containing 100,271 government user records, including full names, email addresses, and hashed passwords.
VULNERABILITY AND EXPLOIT INTELLIGENCE
Apple security patches: Apple has patched 87 vulnerabilities in iOS and iPadOS and 155 vulnerabilities in macOS Tahoe, along with multiple vulnerabilities in macOS Sequoia, macOS Sonoma, watchOS, tvOS, and visionOS. The patched vulnerabilities include flaws that could enable attackers to execute arbitrary code, access sensitive user data, bypass security protections, escalate privileges, and cause denial-of-service (DoS) attacks.
Affected products: The affected products are listed in this advisory.
CVE-2013-4786: This is an information disclosure vulnerability in the Intelligent Platform Management Interface (IPMI) 2.0 authentication protocol used by Baseboard Management Controllers (BMCs). Researchers identified 24,650 internet-exposed BMCs vulnerable to the flaw. It allows unauthenticated remote attackers to obtain password-derived authentication hashes from the RMCP+ Authenticated Key-Exchange Protocol (RAKP) and perform offline password-cracking attacks. Successful exploitation is likely to result in server takeover and compromise of data center infrastructure.
Affected products: Baseboard Management Controllers (BMCs) implementing the IPMI 2.0 protocol.
Tags: DIB, tlp:green