zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 3, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 3, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Cryptographic Failure Exposes COLDCARD Wallets Private Keys
  • Lack of Safety Guardrails Encourage Chinese Actors to Use DeepSeek for Cyberattacks
  • Multiple Countries Warn of North Korean IT Worker Threats

Cryptographic Failure Exposes COLDCARD Wallets Private Keys

Source: https://www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/

What we know: A firmware vulnerability in COLDCARD hardware wallets has reportedly been exploited to steal an estimated USD 88.6 million in BTC from 4,585 addresses across multiple attacks between July 30 and August 1, 2026.

Context: The vulnerability stemmed from an integration error in COLDCARD's random number generation (RNG) code, causing the firmware to use a deterministic software generator instead of the intended hardware RNG. This enabled threat actors to generate possible wallet seeds offline, identify matching Bitcoin addresses on the blockchain, and reconstruct private keys to drain affected wallets.

Analyst note: A cryptographic flaw at the firmware level demonstrates that even self-custody solutions are likely to carry systemic vulnerabilities that can be exploited silently at scale. Threat actors are very likely to attempt to monetize remaining weak-entropy addresses before users can migrate funds to patched firmware. This incident will almost certainly erode confidence in hardware wallet security more broadly.

Lack of Safety Guardrails Encourage Chinese Actors to Use DeepSeek for Cyberattacks

Source: https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html

What we know: A China-based threat actor operating under aliases "knaithe" and "KnYuan," reportedly used DeepSeek AI and the open-source Hermes Agent framework to independently identify targets, research vulnerabilities, download exploits, and launch attacks with minimal human input. However, no servers were compromised.

Context: The actor configured Hermes Agent in "Yolo" mode—allowing it to execute commands, including risky ones, without operator approval. The agent autonomously selected the n8n workflow automation platform as its target, chaining CVE-2026-21858 and CVE-2025-68613. The actor also reportedly tested Claude and OpenAI models before switching to DeepSeek after safety guardrails on those platforms blocked offensive use.

Analyst note: AI-driven reconnaissance activity by threat actors is very likely to become a routine component of the threat landscape, reducing manual work and time-taking for such efforts. However, the limitations of the campaign suggests human input and technical knowledge are still required to successfully launch attacks.

Multiple Countries Warn of North Korean IT Worker Threats

Source: https://www.ic3.gov/CSA/2026/260731.pdf

What we know: The United States, Japan, the Republic of Korea, the United Kingdom, Australia, and Canada have issued a joint alert warning that North Korean IT workers continue to use stolen or false identities to secure remote IT jobs that generate revenue for North Korea's nuclear weapons and ballistic missile programs. The workers also pose an insider threat linked to data exfiltration, cryptocurrency theft, and the theft of sensitive information.

Context: North Korean IT workers use forged identities, third-party proxies, VPNs, remote desktop software, and AI-enabled techniques to conceal their identities and secure remote IT contracts. They primarily target roles in software, web, mobile application, and blockchain development, and often request payment through cryptocurrency or third-party accounts to evade detection and sanctions.

Analyst note: The advisory indicates that North Korean IT worker operations are becoming increasingly sophisticated through the use of AI and identity obfuscation techniques, making fraudulent remote hiring more difficult to detect. Their continued use of legitimate employment platforms suggests these schemes will likely remain a persistent source of revenue for North Korea while increasing insider threat risks for organizations.

DEEP AND DARK WEB INTELLIGENCE

PwnForums user 888: Well-regarded threat actor “888” advertised alleged access to “One of UK's Largest Banks" on the dark web forum PwnForums. 888 did not name the entity and had also marked the listing as “SOLD.” The offer included alleged access to GitLab and CI/CD environments. The threat actor is also a moderator on PwnForums, lending more credibility to the claims. The advertisement is likely to be genuine. The exposed data, if unrotated, is likely to grant access to the entity’s cloud environment, which can lead to malware deployment, data theft, or denial of service conditions.

DATA BREACHES INTELLIGENCE

Amgen discloses data breach: American biotech company Amgen has disclosed a data breach following unauthorized access to cloud storage systems run by third-party ‌ providers. The firm is assessing exposure of patient details, confidential business information, intellectual property, ‌research ⁠and development, and other information. The healthcare sector has faced numerous cyberattacks and data breaches this year so far. Exposed personally identifiable information (PII) and protected health information (PHI) poses risk of phishing and identity fraud attacks. Meanwhile, intellectual property theft likely risks development of unlicensed and potentially harmful drugs.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2026-48449: This is an incorrect authorization vulnerability in Adobe Campaign Classic (ACC). The flaw allows arbitrary code execution in the context of the current user without requiring user interaction. Successful exploitation could enable attackers to compromise sensitive data, execute malicious code, and potentially take control of affected systems.

Affected products: Adobe Campaign Classic (ACC) v7.4.3 build 9397 and earlier on Windows and Linux

Tags: DIBtlp:green