zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 11, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 11, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Brief - JADEPUFFER and the Arrival of Agentic Ransomware Threats
  • Another Member Linked to “The Com” Sentenced
  • Geopolitical Focus: Iran Aims to Bolster Military, U.S. Extends Fuel Shipping Waiver, and More

ZeroFox Intelligence Brief - JADEPUFFER and the Arrival of Agentic Ransomware Threats

Source: https://www.zerofox.com/advisories/41403/

What we know: ZeroFox has observed that threat actors have crossed a ransomware tradecraft threshold with the first documented end-to-end ransomware operation driven by a large language model (LLM) agent. The operation was conducted by a financially motivated threat actor known as JADEPUFFER.

Context: JADEPUFFER exploited CVE-2025-3248, delivering over 600 dynamically generated payloads through an autonomous LLM agent to conduct credential theft and database extortion against a single victim. Additionally, in a second campaign the actors deployed EncForge ransomware to target the victim's AI model artifacts, training datasets, and vector databases.

Analyst note: The targeting of AI model artifacts as a distinct asset class is likely to be adopted beyond JADEPUFFER, given that these assets are often poorly backed up, difficult to reconstruct, and highly valuable to victim organizations. Threat actors are unlikely to abandon traditional ransomware tradecraft in favor of agentic operations in the near term. The two modes are likely to coexist, with agentic tooling serving as a supply-side expansion that lowers the entry barrier for low-skilled operators.

Another Member Linked to “The Com” Sentenced

Source: https://www.nationalcrimeagency.gov.uk/news/com-group-member-sentenced-for-campaign-of-abuse-against-117-victims-worldwide

What we know: A member of the “Com” network was reportedly sentenced to two years in prison for blackmailing and coercing 117 victims worldwide into sexual activity and physical harm.

Context: The Com is a decentralized cybercriminal network involved in online abuse, hacking, data theft, and extortion. Its members have been linked to groups including Scattered Spider, LAPSUS$, and ShinyHunters, which have conducted major cyberattacks against organizations worldwide.

Analyst note: Continued law-enforcement pressure will likely drive The Com to limit information and identity sharing between members and compartmentalize recruitment, intrusion and extortion activities to reduce the intelligence value from a single arrest. Law enforcement entities are likely to conduct further undercover operations exploiting offenders’ pursuit of peer status and notoriety to elicit communication channels and operational details in pursuit of recognition.

Geopolitical Focus: Iran Aims to Bolster Military, U.S. Extends Fuel Shipping Waiver, and More

  • Iran’s Supreme Leader Mojtaba Khamenei is “reshuffling” the country’s military leadership, appointing six senior officials—armed forces chief of staff, IRGC commander-in-chief, IRGC Navy commander, and head of the Basij. The reshuffle is reportedly aimed at expanding Iran’s domestic intelligence network and readiness for “powerful offensive operations.”
  • U.S. President Donald Trump has extended a narrowed Jones Act waiver for additional 90 days to allow certain foreign ships carrying energy cargo to transport fuel between U.S. ports.
  • Meanwhile, on August 10, 2026, an individual was taken into custody in Halifax, Canada, after allegedly communicating a bomb threat against the U.S. Consulate.
  • Spain has announced temporary border checks on travelers arriving from Italy until September 7, 2026, citing continued irregular migration pressure after Italy imposed similar controls following the mass migrant influx into Ceuta.
  • A 7.4-magnitude earthquake struck western Colombia on August 10, 2026, killing at least 111 people, injuring hundreds, and prompting the government to declare a national state of emergency.
  • Additionally, Typhoon Dolphin has struck eastern China, prompting authorities to evacuate more than one million people and suspend transport services, including about 1,500 flights in Shanghai.

DEEP AND DARK WEB INTELLIGENCE

DarkForums user GordonFreeman: Untested threat actor "GordonFreeman" has advertised an alleged database associated with the Population and Immigration Authority of Israel on dark web forum DarkForums. The threat actor claims the 7.5 GB database contains more than 9.22 million records, including full names, national identification numbers, gender, marital and vital statuses, full addresses, phone numbers, dates of birth, and countries of birth. The threat actor also highlighted the personal details of several Israeli political figures, including senior government officials.

DATA BREACH INTELLIGENCE

CEVA logistics reportedly hacked: French shipping and logistics company CEVA Logistics has reportedly confirmed a cyberattack affecting eight European warehouses. The hack has exposed customer information linked to multiple organizations, including De Bijenkorf, Ajax, ING, Ace & Tate, and Valve. The compromised data includes customer names, delivery addresses, phone numbers, and email addresses collected through the affected logistics operations. If legitimate, the exposed customer information could be leveraged in cargo theft, phishing, and other social engineering campaigns.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Vulnerabilities in Belgian eID software: Flaws in the Connective digital identity system, a browser extension used by over two million users in Belgium including major banks and government agencies, enables malicious websites to communicate with the eID application without proper authorization. Attackers can exploit the flaws to access users’ eID and payment card details and steal eID PINs. The stolen PINs can then be used to generate unauthorized approval tokens and forge legally binding electronic signatures when a victim’s eID card is connected to a card reader.

Affected products: Connective eID browser extension

Tags: DIBtlp:green