ZeroFox Daily Intelligence Brief - August 7, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 7, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Extortion Group BlackFile Reportedly Linked to Cyberattacks Against Finance Sector
- Meta AI Testing Incident Follows Recent OpenAI and Anthropic Cases
- China-made Zbtlink Routers Found With Factory-Installed Backdoors
Extortion Group BlackFile Reportedly Linked to Cyberattacks Against Finance Sector
What we know: A recent series of cyberattacks targeting hedge funds, private-equity firms, and financial organizations at Wall Street have reportedly been attributed to the BlackFile extortion group. In May 2026, BlackFile had announced that it was rebranding under the name “Redact”.
Context: BlackFile also reportedly operates under various public brands like Pink, Helix, and Falcon. In the recent campaign, BlackFile operators contact employees on personal mobile phones spoofing corporate helpdesks, and direct victims to adversary-in-the-middle (AitM) phishing sites that steal single sign-on (SSO) credentials and session cookies in real time. Automated tools then exfiltrate data across all linked cloud platforms while security notifications are deleted to delay detection.
Analyst note: The public attribution of BlackFile’s infrastructure and tactics is likely to prompt the group to rotate domains and rebrand. However, because the operation very likely depends on human operators conducting live vishing calls, operational disruption to the threat group’s activity is unlikely without direct law enforcement action against the individuals.
Meta AI Testing Incident Follows Recent OpenAI and Anthropic Cases
What we know: Meta said one of its AI models gained unintended internet access during a cybersecurity evaluation, because of a configuration error in the testing environment managed by an external evaluator. Meta said the incident occurred during controlled testing and did not involve a sandbox escape.
Context: During testing, Meta’s model reportedly exploited a vulnerability in a third-party service and accessed another company’s systems, where it allegedly altered part of the internal environment. In a separate testing incident, China’s Kimi K3, an open-weight AI model from Moonshot AI, unexpectedly gained access to the internet after a sandbox configuration error. These events follow the recent AI-testing breaches involving Anthropic and OpenAI.
Analyst note: Similar incidents involving OpenAI, Anthropic, and now Meta suggest that such incidents are becoming a recurring industry pattern rather than an isolated event, making additional incidents involving other advanced AI models likely in the near term. As these systems become better at navigating networks and using tools, the same capabilities are likely to be adapted by threat actors for reconnaissance and cyberattacks.
China-made Zbtlink Routers Found With Factory-Installed Backdoors
Source: https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html
What we know: At least 20 models of China-made Zbtlink routers have reportedly been found with a factory-installed backdoor, ENDLESSDOORS, embedded in firmware released over the past two years. The implant automatically contacts command-and-control (C2) servers and lacks authentication or server verification, allowing attackers to execute commands or gain remote root access.
Context: Researchers found the ENDLESSDOORS implant in all 21 firmware images available from Zbtlink, where it starts automatically at boot. The manufacturer said the functionality was intended for after-sales maintenance and was generally retained only on sample units to assist customers with software debugging.
Analyst note: The incident is likely to increase concerns about the security of Chinese-made network equipment, as hidden or insecure features in trusted devices could create risks for organizations. Companies may place greater focus on reviewing the security of third-party hardware and firmware before deployment.
DEEP AND DARK WEB INTELLIGENCE
Exploit user renn: Untested threat actor "renn" has advertised data allegedly associated with SS&C Black Diamond Wealth Solutions, a US-based wealth management technology platform, on the Russian-language dark web forum Exploit. The advertised dataset allegedly contains 555,577 records with personally identifiable information (PII) belonging to platform users, including full names, physical addresses, mobile phone numbers, email addresses, dates of birth, and Social Security numbers (SSNs).
VULNERABILITY AND EXPLOIT INTELLIGENCE
Cisco patches critical vulnerabilities: Cisco has released patches for 24 vulnerabilities across Catalyst SD-WAN, IOS XE, Secure Firewall Management Center (FMC), and Integrated Management Controller (IMC). The flaws collectively enable low-privilege attackers to inject commands, bypass access controls, escalate privileges to root, and access sensitive information stored in cleartext.
Affected products: Affected products are listed here.
Tags: DIB, tlp:green