zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 30, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 30, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • LeakNet Claims Data Theft Linked to 12 Million NYC Health + Hospitals Patients
  • ZeroFox Intelligence Flash Report - Introduction of WhatsApp Usernames
  • Geopolitical Focus: Iran Conflict Escalates, Two LNG Tankers Hit Near Suez, Europe Wildfires

LeakNet Claims Data Theft Linked to 12 Million NYC Health + Hospitals Patients

Source: https://hackread.com/leaknet-11tb-stolen-nyc-health-hospitals-data-breach/

What we know: Data extortion group, "LeakNet," has claimed to have stolen an 11 TB archive from U.S. municipal healthcare system NYC Health + Hospitals (NYCHH), allegedly containing information linked to more than 12 million people.

Context: LeakNet published a preview of the alleged dataset containing screenshots of databases, medical spreadsheets, and internal messages, with visible patient names, Social Security numbers, medical records, and biometric data. NYCHH had previously disclosed a breach in March 2026, reporting that 1.8 million individuals were affected.

Analyst note: The significant disparity between LeakNet's claims and NYCHH's previously disclosed affected individual count likely indicates that the threat actor is either exaggerating the impact or gained access extending beyond the incident previously acknowledged by NYCHH. If true, the exposure will very likely expose affected patients to targeted identity theft, medical fraud, and phishing campaigns.

ZeroFox Intelligence Flash Report - Introduction of WhatsApp Usernames

Source: https://www.zerofox.com/advisories/41224/

What we know: Meta has started allowing WhatsApp's three-billion-plus users to reserve a username that new contacts can use instead of a phone number, ahead of a phased, country-by-country rollout later in 2026.

Context: Meta has reserved usernames for public figures, government entities, celebrities, and verified accounts, and introduced safeguards including messaging limits and username guess protection. Within 48 hours of the announcement, India's MEITy temporarily paused the rollout, citing concerns over increased fraud, phishing, digital arrest scams, and impersonation attacks. Finland's Traficom also issued a similar public warning.

Analyst note: The feature will likely increase the credibility of impersonation and social engineering campaigns rather than introduce a new attack method. Impersonation risk is very likely to be highest during the initial rollout as threat actors test platform controls and attempt to register deceptive usernames before enforcement matures.

Geopolitical Focus: Iran Conflict Escalates, Two LNG Tankers Hit Near Suez, Europe Wildfires

  • The United States has conducted a “heavy wave of strikes” against Iran in response to an earlier Iranian missile attack on a U.S. base in Jordan.
  • On July 29, 2026, an explosion and fire at Egyptian port Damietta near the Suez Canal damaged U.S. and Greek owned LNG vessels, reportedly due to a drone strike. The attack is unlikely to significantly affect global gas markets but can heighten security concerns along the Suez Canal shipping corridor.
  • The U.S. Treasury has sanctioned two Iranian firms for allegedly helping the Islamic Revolutionary Guard Corps (IRGC) force commercial ships transiting the Strait of Hormuz to buy Iranian maritime insurance.
  • Separately, a massive wildfire in southwest France remained out of control as temperatures neared 40°C (104°F) and winds strengthened, while three firefighters were killed in Greece amid a broader southern European wildfire crisis.

DEEP AND DARK WEB INTELLIGENCE

PwnForums user Jurak: Credible threat actor “Jurak” has advertised a database allegedly linked to Bulgaria-based insurance company Euroins Insurance on dark web forum PwnForums. The actor claims to be selling selected database tables rather than the full dataset, including 17 CSV files with nearly 10 million records, including about 4.55 million customer entries and 5.21 million vehicle records. Euroins was previously targeted by the KRYBIT ransomware group and offered the compromised data for public purchase on July 20, 2026. It is likely that Jurak acquired the dataset from KRYBIT and is now reselling it.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2026-42897: This is an actively exploited cross-site scripting (XSS) vulnerability in Microsoft Exchange Server Outlook Web Access (OWA). The flaw allows remote attackers to execute arbitrary JavaScript in a victim's browser by sending a specially crafted email that is opened in OWA. Successful exploitation could enable attackers to steal session tokens, maintain persistent mailbox access, and access mailbox contents. The vulnerability has been exploited by the Russian state-sponsored threat group Laundry Bear (Void Blizzard) in cyber espionage campaigns.

Affected products: The affected products are listed in this advisory.

Tags: DIBtlp:green