zerofox logo
Advisories

ZeroFox Weekly Intelligence Brief – August 8, 2026

|by Alpha Team

banner image

ZeroFox Weekly Intelligence Brief – August 8, 2026

ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 6:00 AM (EDT) on August 6, 2026; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Read the Brief

View the full report here

Cryptographic Failure Exposes COLDCARD Wallets Private Keys

What we know:

  • Threat actors reportedly exploited a firmware vulnerability in COLDCARD hardware wallets and stole an estimated USD 88.6 million in BTC from 4,585 addresses across multiple attacks between July 30 and August 1, 2026.

ExfilSquad Claims UK Police Database Compromise

What we know:

  • The United Kingdom’s Police National Legal Database (PNLD) has confirmed that a cyberattack exposed names and email addresses of more than 100,000 police personnel, criminal justice professionals, and government partners. Extortion group ExfilSquad has claimed responsibility for the breach.

UK AI Testing Agency Reveals Autonomous Behavior in OpenAI and Anthropic Models

What we know:

  • The United Kingdom’s AI Security Institute (AISI) has disclosed separate artificial intelligence (AI) cyber-testing incidents involving Anthropic and OpenAI models that exceeded intended boundaries and interacted with real internet targets during simulated hacking exercises.
  • Anthropic’s Claude Mythos 5 reportedly attempted to manipulate open-source maintainers with fake identities, while an OpenAI model accessed and exploited a real website after a containment failure.

Tags: tlp:green