ZeroFox Daily Intelligence Brief - August 19, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 19, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA Updates Medusa Ransomware Advisory
- 1Password Users Targeted in Active Phishing Campaign
- U.S. Charges 17 Iranian Nationals in State-Sponsored Cyber Theft Campaign
CISA Updates Medusa Ransomware Advisory
What we know: CISA and partners have updated the advisory on threats posed by the Medusa ransomware group. ZeroFox has observed at least 26 Medusa attacks in 2026, mostly targeting organizations in industries like retail, manufacturing, and healthcare in the North America region.
Context: Medusa actors use a double-extortion model; however, one FBI investigation reportedly found a victim was subjected to an additional ransom demand after payment, potentially indicating triple extortion or internal coordination discrepancies. CISA’s update also notes that Medusa recruits initial access brokers (IABs) through cybercriminal forums to obtain access to victims.
Analyst note: Medusa’s continued activity suggests that its competitive advantage likely increasingly stems from operational speed and access to the broader cybercrime ecosystem, rather than having developed novel attack capabilities over time.
1Password Users Targeted in Active Phishing Campaign
Source: https://x.com/1Password/status/2089500391016640788
What we know: Password manager 1Password has confirmed that an active phishing campaign is targeting its users with fake payment-update emails linking to fraudulent pages designed to steal account credentials. 1Password noted that the campaign is not the result of any breach of 1Password's systems.
Context: 1Password has asked affected users to report suspicious emails to the company. Additionally, according to one reported case on an online discussion platform, the phishing page allegedly mimics 1Password’s login flow, prompting the user for their email, password, and Secret Key. However, a “Sign Up” prompt appeared where a “Sign In” prompt would normally be expected, helping identify the scam.
Analyst note: The campaign’s attempt to obtain account credentials likely suggests an account-takeover objective beyond credential theft, as attackers appear to be seeking multiple authentication elements.
U.S. Charges 17 Iranian Nationals in State-Sponsored Cyber Theft Campaign
What we know: The U.S. Department of Justice (DoJ) has unsealed a 14-count superseding (S2) indictment charging 17 members of the Iran-based Mabna Institute with conducting a coordinated, state-sponsored campaign of cyber intrusions.
Context: The Mabna Institute, operating on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC) and other Iranian government entities, targeted more than 100,000 professors’ accounts worldwide, successfully compromising approximately 8,000 accounts, as well as at least 42 U.S. private sector companies, five U.S. federal and state government agencies, and two non-governmental organizations. The campaign resulted in the theft of more than 31.5 TB of academic data, intellectual property, and email inboxes. Stolen data was monetized through two Iranian websites.
Analyst note: The indictment represents a prosecutorial escalation of the 2018 Mabna Institute case, linking known Mabna operators to the 2017 HBO extortion hack; it is not related to a new campaign. The case highlights the risk of overlap between state-sponsored academic espionage and private-sector extortion.
DEEP AND DARK WEB INTELLIGENCE
PwnForums user GhostSec: Threat actor "GhostSec" has leaked data allegedly from the Administrative Court of Justice of Mexico City on dark web forum PwnForums. The threat actor framed the release as part of an ongoing operational campaign targeting Mexican cartels. The dataset allegedly includes court case records linked to cartel investigations, open-source intelligence findings mapping cartel-owned businesses, and internal documentation.
VULNERABILITY AND EXPLOIT INTELLIGENCE
Microsoft Copilot Personal Vulnerabilities: Dubbed “CoSnitch,” this is a set of three vulnerabilities (CVE-2026-24301) in Microsoft Copilot Personal, patched on August 18, 2026, that enabled a single crafted link to exfiltrate data from connected applications within a victim's authenticated session. The vulnerability also enabled a crafted web page to write persistent attacker-controlled instructions into the user's memory store. No evidence of exploitation in the wild was found prior to disclosure.
Affected products: Microsoft Copilot Personal—patched August 18, 2026
Tags: DIB, tlp:green