ZeroFox Daily Intelligence Brief - August 6, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 6, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Snowflake Hacker Pleads Guilty to Extorting Victims for Millions
- Kali365 Continues OAuth Token Theft Campaigns Across U.S. Organizations
- Geopolitical Focus: Drone Found Near German Airport, Iran–Oman Hormuz Agreement, and Ceuta Minor Transfers
Snowflake Hacker Pleads Guilty to Extorting Victims for Millions
What we know: Individual who hacked cloud storage providing company Snowflake pleaded guilty in a U.S. court on August 5, 2026. The hacking conspiracy had compromised more than 165 organizations, and resulted in theft of billions of customer records.
Context: Between February and October 2024, the individual and co-conspirators used stolen credentials to access cloud-hosted customer data of Snowflake, exfiltrating financial records, registration numbers, and Social Security Numbers (SSNs), among other data. Victims were extorted for over USD 2.5 million.
Analyst note: Cross-border prosecution may reinforce deterrence, though credential-theft-driven extortion will almost certainly persist given continued forum demand for such datasets.
Kali365 Continues OAuth Token Theft Campaigns Across U.S. Organizations
Source: https://hackread.com/kali365-exploit-microsoft-device-login-access-us-data/
What we know: Kali365, a phishing-as-a-service (PhaaS) platform, is reportedly enabling device-code phishing campaigns against U.S. organizations by abusing a widely used cloud productivity suite’s legitimate authentication workflow. The operation can capture OAuth access and refresh tokens and does not steal passwords directly.
Context: The FBI warned in May 2026 that Kali365, first observed in April 2026 and distributed primarily via Telegram, enables attackers to steal OAuth tokens and maintain access while bypassing multi-factor authentication (MFA) protections.
Analyst note: Kali365’s use of device-code phishing to obtain authentication tokens is likely to encourage threat actors to pivot from traditional credential theft toward token-based account compromise, reducing reliance on stolen passwords. Beyond just financially motivated cybercriminals, this type of platform is likely to benefit state-backed espionage groups and others looking to access corporate accounts and establish persistence.
Geopolitical Focus: Drone Found Near German Airport, Iran–Oman Hormuz Agreement, and Ceuta Minor Transfers
- Russian-linked influence operations have reportedly intensified online disinformation campaigns targeting German political candidates and amplifying regional divides ahead of upcoming elections.
- German authorities are investigating a suspected "hybrid attack" after a drone containing an explosive device was found and defused near Ukrainian cargo planes at Leipzig/Halle Airport, followed by a second drone that collided mid-air with a freight aircraft.
- Iran and Oman have reached an agreement on geographic coordinates for a designated shipping lane through the Strait of Hormuz (SoH), though Iran cautioned that the deal alone will not guarantee the waterway's overall security.
- Iran has warned neighboring Gulf states that any new U.S. military strikes on its territory will trigger retaliatory attacks against critical energy and transport infrastructure across the region.
- Spanish authorities are seeking to transfer hundreds of unaccompanied migrant minors from the enclave of Ceuta to mainland regions. The Spanish government approved EUR 25 million (approximately USD 29 million) in funding to support the transfer. The death toll on both sides of the border has neared 100, with dozens of migrants still unaccounted for.
DEEP AND DARK WEB INTELLIGENCE
Exploit user impotent4000: Untested threat actor “impotent4000” has advertised alleged VPN access linked to United Arab Emirates-based Abu Dhabi National Energy Company on dark web forum Exploit. The announcement claimed to include more than 250 VPN accounts, web access, and Active Directory credentials with access to internal file systems, with bidding starting at USD 700. If authentic, the access is likely to attract hacktivist interest due to the potential for disruptive operations, data leaks, and other politically motivated campaigns.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2026-59774: This is an arbitrary file read vulnerability in Gitea that can enable an unauthenticated attacker to read any file accessible to the Gitea service account without requiring login or repository write access. A public repository with crafted Org-mode markup is sufficient to exploit the flaw. The vulnerability could expose sensitive files, including app.ini, internal tokens, OAuth credentials, JWT signing keys, and database credentials, and could potentially be chained to achieve remote code execution (RCE).
Affected products: Gitea versions 1.22.1 through 1.27.0. Fixed in Gitea 1.27.1.
Tags: DIB, tlp:green