ZeroFox Daily Intelligence Brief - July 31, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 31, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA Issues Alert on Escalating Cyberattacks Against Water Infrastructure
- Analog Devices Discloses Data Breach Amid Unverified Claims
- Hackers Exploit AnySign4PC Zero-Day via Compromised Korean Websites
CISA Issues Alert on Escalating Cyberattacks Against Water Infrastructure
What we know: CISA and partners have issued an alert regarding threat actors increasingly targeting water and wastewater systems in the United States. The alert comes following a coordinated cyberattack on more than 30 Minnesota water utilities. U.S. investigators have linked PLC exploitation to Iran-linked actors.
Context: Threat actors have been modifying internet-exposed programmable logic controller (PLC) passwords to lock out operators and changing IP addresses, resulting in boil water notices and sustained manual operations. Affected devices include Rockwell Automation MicroLogix 1100 and 1400 series PLCs, Schneider Electric, and Siemens devices, among others.
Analyst note: Amid sustained geopolitical tensions, Iran-linked cyberattacks against U.S. critical infrastructure are very likely to continue and intensify. The attack surface is likely broader than operators recognize, with CISA specifically flagging undocumented cellular modems installed by third-party vendors as overlooked but exploitable entry points.
Analog Devices Discloses Data Breach Amid Unverified Claims
What we know: Semiconductor company Analog Devices has disclosed a data breach following the detection of unauthorized access to certain company systems, from which an unauthorized party exfiltrated files. The company states that business operations were not affected.
Context: The nature of the compromised data has not been disclosed. Separately, extortion group ExfilSquad has claimed to have stolen 570,000 records from the company. It remains unconfirmed whether the ExfilSquad claim is connected to the breach Analog Devices disclosed.
Analyst note: If the group’s claims are true, the data could likely be used for extortion, credential abuse, or the sale of proprietary information to other threat actors. Given the company’s position in the semiconductor ecosystem, any exposure of engineering documentation, supplier information, or intellectual property is very likely to facilitate downstream supply chain targeting or follow-on attacks against trusted partners and customers.
Hackers Exploit AnySign4PC Zero-Day via Compromised Korean Websites
Source: https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html
What we know: A state-sponsored watering-hole campaign is compromising legitimate South Korean websites to exploit a zero-day vulnerability in AnySign4PC. The attackers deployed the SIGNBT or COPPERHEDGE backdoor on systems running vulnerable versions of the software without requiring user interaction.
Context: AnySign4PC is widely used in South Korea for online banking and government services. KISA confirmed that versions 1.1.4.4 through 1.1.4.6 are affected and recommends upgrading to version 1.1.5.0. Investigators identified 15 compromised websites used as watering holes and found evidence of related activity at 72 organizations.
Analyst note: The attackers likely targeted AnySign4PC because of its widespread use across South Korea's banking and public sectors, enabling them to maximize victim reach through trusted websites. The use of a no-user-interaction exploit likely increased the campaign's effectiveness while reducing the likelihood of detection.
DEEP AND DARK WEB INTELLIGENCE
Brinks Home discloses data breach: Residential security company Brinks Home has disclosed a data breach after the ShinyHunters extortion group claimed to have stolen more than 4.9 million Salesforce records containing customers’ personally identifiable information (PII), over 3.8 million customer support chat logs, and more than 4,000 rows of employee data.
DATA BREACHES INTELLIGENCE
CareCloud notifies of data breach: U.S. health tech company CareCloud is reportedly notifying people of a data breach, following unauthorized access to one of its electronic health record data stores between March 10 and March 16, 2026. The company stores patient records for over 45,000 healthcare providers across the country. The breached dataset includes personally identifiable information (PII), government identification details, financial information, and protected health information (PHI) of at least 345,000 individuals. The exposed individuals are likely to be targeted in phishing, social engineering, and identity theft attacks. Furthermore, threat actors are likely to leverage the data for insurance fraud.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2026-66803: Microsoft has patched a critical remote code execution (RCE) vulnerability in Azure Cosmos DB. The flaw enabled an unauthorized attacker to execute code over a network. Successful exploitation is likely to enable threat actors to locate and take control of databases belonging to any customer, resulting in data theft.
Affected products: Azure Cosmos DB
Tags: DIB, tlp:green