zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 21, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 21, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Alation Confirms Unauthorized Access to Internal System
  • ZeroFox Intelligence Flash Report - U.S. Private Companies to Conduct Cyber Attacks
  • Malicious Firefox Extensions Target Crypto Wallets

Alation Confirms Unauthorized Access to Internal System

Source: https://techcrunch.com/2026/08/20/ai-data-giant-alation-confirms-cyberattack/

What we know: Enterprise data software provider Alation has confirmed a cyberattack, days after reporting an incident that caused degraded service availability for a number of its customers.

Context: The company reportedly identified unauthorized access to one of its systems but has not disclosed the nature of the attack, the number of customers affected, or whether any data was exfiltrated. The company provides data cataloging and AI-powered search software to more than 500 global companies, including approximately half of the Fortune 1000.

Analyst note: Alation's customer base indicates that even a limited intrusion very likely carries downstream exposure risks across multiple high-value organizations. As AI-powered data platforms become more deeply embedded in enterprise workflows, they are very likely to become increasingly attractive targets for both financially motivated and espionage-driven threat actors.

ZeroFox Intelligence Flash Report - U.S. Private Companies to Conduct Cyber Attacks

Source: https://www.zerofox.com/advisories/41591/

What we know: On August 12, 2026, President Trump signed a National Security Presidential Memorandum (NSPM) directing the National Coordination Center (NCC) to build a program authorizing vetted U.S. companies to conduct cyber surveillance and disruption operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs).

Context: The memorandum authorizes operations against foreign criminal groups only, excluding nation-state actors and groups controlled by foreign governments. Operations must not be likely to cause loss of life or constitute a use of force under international law, and must minimize contact with U.S. persons or systems.

Analyst note: ZeroFox assesses the program is unlikely to measurably reduce top-tier extortion revenue within 12 months; state-directed actors remain outside its scope. Ransomware as-a-Service (RaaS) groups will likely tighten affiliate vetting and retreat from public forums, degrading human-source collection and broader visibility into criminal activity.

Malicious Firefox Extensions Target Crypto Wallets

Source: https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html

What we know: A campaign dubbed Offside Wallet Theft Factory has been using 40 malicious Firefox extensions disguised as legitimate cryptocurrency wallets and other Web3 products to steal users’ wallet credentials and assets. The extensions impersonated wallets with some capturing victim recovery phrases and private keys and others stealing serialized wallet keyrings, credentials, and clipboard data.

Context: The campaign has reportedly been active since March 2026 and is part of a broader network of 77 related extensions sharing code and infrastructure. Additionally, the extensions used fake wallet pages or embedded theft functionality, with some “repurposed” from sports-score and utility add-ons under the same Firefox IDs.

Analyst note: Given that the extensions are designed to steal wallet secrets and a lack of reported evidence that cryptocurrencies have been drained likely suggests that the threat actors are prioritizing the collection of wallet credentials for potential subsequent exploitation rather than immediate wallet draining.

DEEP AND DARK WEB INTELLIGENCE

PwnForums user Angel_Batista: Well-regarded threat actor "Angel_Batista" has advertised data allegedly associated with Alaxione, a France-based e-health company, on the English-language dark web forum PwnForums. The actor claims to have gained access to Alaxione's systems and obtained multiple database versions from development instances before accessing the full production database. The listing advertises approximately 12.8 GB of data containing 18 million rows, including 6.8 million patient records, more than 10.1 million appointments, and internal messages. The allegedly compromised data includes full names, dates of birth, email addresses, phone numbers, home addresses, French social-security numbers, stored passwords, bank details, IP addresses, and certain login tokens. Angel_Batista also claims to have previously compromised Alaxione in November 2025 and March 2025.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Chain of vulnerabilities in NASA/JPL AIT-GUI: A chain of flaws in NASA/JPL's AIT-GUI operator console, tracked as GHSA-p9r8-2q67-fp86, could enable unauthenticated network attackers to issue arbitrary commands to spacecraft and instruments. The flaws reportedly stem from missing credential-based authentication and CSRF protections, while path traversal in the /script/run and /seq endpoints could enable attackers to execute files outside their intended directories. Version 2.5.2 is listed as the fixed release.

Affected products: AIT-GUI versions 2.5.1 and earlier

CVE-2026-64849: This is a known exploited DNS-rebinding server-side request forgery (SSRF) vulnerability in MLflow’s outbound webhook delivery. An unauthenticated attacker can exploit the flaw without privileges to remotely access internal services or cloud metadata configurations on unpatched instances. Successful exploitation can enable attackers to steal certain cloud credentials in low-complexity attacks.

Affected products: MLflow versions ≤ 3.15.0

Tags: DIBtlp:green