zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 13, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 13, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Pro-Iran Threat Actors Claim Responsibility Minnesota Water Cyberattack
  • Taiwan Reports AI-Assisted Cyberattack on Government Agencies
  • Ransomware Hits Colombia Justice Ministry Ahead of Presidential Transition

Pro-Iran Threat Actors Claim Responsibility Minnesota Water Cyberattack

Source: https://cloud.zerofox.com/intelligence/advanced_dark_web/109000

What we know: Iran-linked threat group “APT IRAN” has claimed joint responsibility with threat actor “CyberAv3ngers” for the coordinated cyberattack targeting more than 30 Minnesota community water systems between July 26 and July 27, 2026.

Context: APT IRAN's claim was made via Telegram in direct response to a security researcher disputing Iranian attribution for the incident. The group threatened further retaliatory cyber operations against U.S. critical infrastructure—specifically electricity, telecommunications, and water systems.

Analyst note: CyberAv3ngers has a documented history of targeting U.S. critical infrastructure, however attribution to the recent water systems attacks remain unconfirmed. The groups are almost certainly seeking to maximize the psychological and reputational impact of the operation by making a public statement. As the U.S.-Iran tensions remain elevated, critical infrastructure operators are very likely to remain targets for continued Iran-linked cyber activity.

Taiwan Reports AI-Assisted Cyberattack on Government Agencies

Source: https://www.reuters.com/world/china/taiwan-says-it-was-targeted-last-month-ai-driven-hacking-campaign-2026-08-13/

What we know: Taiwan's Ministry of Digital Affairs (MODA) has reportedly detected an AI-assisted cyber campaign targeting multiple government agencies in July 2026. The attacks, originating from an overseas source, combined manual operations with AI agents, including OpenClaw, to steal credentials, access personnel records, and scan systems for vulnerabilities. The affected agencies have contained the incident.

Context: The disclosure follows an earlier report , which found that AI agents targeted Taiwan's Ministry of Justice and Nuclear Safety Commission. Taiwan has repeatedly warned of increasing cyber threats amid tensions with China, reporting an average of 2.63 million cyberattacks per day against its critical infrastructure in 2025.

Analyst Note: The use of AI agents to support reconnaissance, credential theft, and vulnerability assessment very likely improves the speed and efficiency of state-linked cyber espionage campaigns, while also maintaining human oversight.

Ransomware Hits Colombia Justice Ministry Ahead of Presidential Transition

Source: https://www.darkreading.com/cyberattacks-data-breaches/ransomware-hits-colombian-justice-ministry-presidential-transition

What we know: A ransomware attack hit part of Colombia’s Ministry of Justice IT infrastructure on August 2, 2026, disrupting several public-facing services just five days before Colombia’s presidential transition.

Context: The attack affected systems tied to illicit-drug monitoring and certain legal process services. Colombian authorities said some files were encrypted, which is consistent with a ransomware attack but the acting Justice Minister stated that officials had found no evidence of data theft.

Analyst Note: The attack is likely to have been conducted by a state-backed threat group using ransomware as a disruptive or cover mechanism to conceal intelligence-gathering objectives, particularly given the targeting of counternarcotics and legal-process systems. The targeting of illicit-drug monitoring and legal-process systems is likely to provide access to sensitive counternarcotics and law-enforcement information.

DEEP AND DARK WEB INTELLIGENCE

ShinyHunters adds Metabase to leak site: ShinyHunters has claimed data theft targeting Metabase, a U.S.-based open-source business intelligence company. Metabase has been listed on ShinyHunters’ leak site along with alleged internal files and GitHub repositories related to the entity.

THREAT CAMPAIGN WATCH

“City-Forum” data theft campaign:

TTPs to watch:

Method: Exploitation of misconfigured, unauthenticated guest-user access on Salesforce Experience Cloud and ServiceNow customer portals.

Target: Telecommunications companies, banks and financial-services firms, enterprise software/security vendors, data-privacy companies, and public-sector organizations worldwide.

Aim: Large-scale data theft

IoCs: IP address 158[.]220.87.79, Go-http-client/1, city-forum[.]com (includes multiple subdomains)

VULNERABILITY AND EXPLOIT INTELLIGENCE

Microsoft “ShieldBreak” vulnerability Security researcher "ChaoticEclipse" has released a proof-of-concept (PoC) for "ShieldBreak", an alleged patch bypass flaw in the Microsoft Defender vulnerability CVE-2026-50656 (RoguePlanet) that can enable SYSTEM-level privileges. CVE-2026-50656 has been patched, but ChaoticEclipse claims the patch introduced a new issue that could cause Defender to leak 8 bytes of data under certain conditions.

Affected products: Windows 11 25H2, Windows Server 2025, and Windows 10

Tags: DIBtlp:green