zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 10, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 10, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Brief - Cumulative Energy and Food Crisis Inspiring Cyber Actors
  • U.S. Defense Manufacturer IEH Hit by Phishing Attack
  • North Carolina Port Cyberattack Disrupts Operations

ZeroFox Intelligence Brief - Cumulative Energy and Food Crisis Inspiring Cyber Actors

Source: https://www.zerofox.com/advisories/41385/

What we know: ZeroFox has observed a surge in cyber threat actor activity targeting the energy and food sectors as three simultaneous conflicts—the conflict in Iran, the Russia-Ukraine war, and Houthi attacks in the Red Sea—converge with a global heatwave to disrupt energy and food supply chains, pushing global food prices to a three-year high in July 2026.

Context: From July 8 to August 5, 2026, ZeroFox identified 19 instances of cyber threat actors targeting the energy sector and 23 instances targeting the food and agriculture sector, as well as five instances targeting organizations in the fertilizer trade since June 1.

Analyst note: Threat actors targeting energy sectors are likely financially motivated, responding to the accompanying LNG price increase by targeting organizations impacted by the supply shock. The activity across the food sector is claimed by separate actors and likely does not reflect a coordinated campaign.

U.S. Defense Manufacturer IEH Hit by Phishing Attack

Source: https://www.theregister.com/security/2026/08/07/ieh-corp-says-phished-staffer-opened-gates-to-company-m365/5284523

What we know: U.S.-based defense and aerospace supplier IEH Corporation has disclosed a security breach after threat actors used an alias to trick an employee via a phishing email.

Context: IEH manufactures connectors used in aircraft, fighter jets, missiles, satellites, and other defense systems, including the PATRIOT, AMRAAM, and THAAD programs. Threat actors reportedly accessed mailbox contents including customer communications, engineering documentation, and export-controlled technical information with no reported evidence of data exfiltration or operational disruption.

Analyst Note: Threat actors are likely to conduct further email-based reconnaissance, monitor communications tied to defense programs, procurement, and supply-chain activity, and identify additional accounts or systems to launch spear-phishing campaigns against downstream aerospace partners and government entities.

North Carolina Port Cyberattack Disrupts Operations

Source: https://www.bleepingcomputer.com/news/security/north-carolina-ports-confirms-cyberattack-disrupting-operations/

What we know: The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems at three of its facilities, the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. The incident caused systems outage, forcing gates at all three facilities to open later than normal, resulting in delays for port operations and truck traffic.

Context: No threat actor has claimed responsibility and data compromise has not been confirmed. North Carolina Ports operates two deep-water ports in Wilmington and Morehead City and an inland port in Charlotte, forming a major regional logistics network. The Port of Wilmington alone handles more than 5,000 container gate moves per week and over 320,000 Twenty-Foot Equivalent Unit (TEU) annually, making it an essential cargo gateway for the southeastern United States.

Analyst Note: The incident is likely to create short-term supply-chain friction, increasing regional freight costs temporarily and prompting carriers and shippers to adjust schedules and reroute cargo until operations completely stabilize. For the duration of delays and operational uncertainty, shippers are likely to divert containers to competing U.S. East Coast gateways adding distance and cost for North Carolina shippers and compounding congestion at those terminals.

DEEP AND DARK WEB INTELLIGENCE

DarkForums user dreamss: Untested threat actor "dreamss" has advertised an alleged dataset associated with Spain-based online stockbroker and digital trading platform, DEGIRO on dark web forum DarkForums. The actor claims the dataset contains 217,642 user records including names, phone numbers, physical addresses, email addresses, and platform account details.

THREAT ACTOR WATCH

BlackFile: Extortion group BlackFile has reportedly been linked to a recent data breach at Levi Strauss. The company said that consumer data or operations were not affected. BlackFile was also attributed to cyberattacks targeting major financial organizations at Wall Street. The group reportedly emerged in early 2026 using targeted IT helpdesk vishing and adversary-in-the-middle attacks to compromise accounts. Although BlackFile reportedly retired its name in May 2026, BlackFile has continued operating under brands such as Redact, Pink, Helix, and Falcon.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Metabase zero-day This is a zero-day vulnerability in Metabase that enables threat actors to inject arbitrary SQL into the application database, grant themselves administrator access, and steal or export customer data. The bug is reportedly under active exploitation. Metabase has blocked the endpoints used in the attacks and rolled out automatic patches for its Cloud SaaS platform. Compromised systems are very likely at risk of enabling further intrusions into networks that can be used for data and credential theft.

Affected products: Metabase Cloud SaaS platforms and self-hosted installations running version 1.58 and above

Tags: DIBtlp:green