ZeroFox Weekly Intelligence Brief – August 21, 2026
|by Alpha Team

ZeroFox Weekly Intelligence Brief – August 21, 2026
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 6:00 AM (EST) on August 20, 2026; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
1Password Users Targeted in Active Phishing Campaign
What we know:
- Password manager 1Password has confirmed that an active phishing campaign is targeting its users with fake payment update emails that link to fraudulent pages designed to steal account credentials.
- 1Password noted that the campaign is not the result of any breach of 1Password's systems.
CISA Warns of Active Threat Targeting Siemens S7 Series PLCs
What we know:
- The Cybersecurity and Infrastructure Security Agency (CISA) warned that an active cyber threat is targeting Siemens S7 Series programmable logic controllers (PLCs) across multiple U.S. critical infrastructure sectors. Threat actors are reportedly using artificial intelligence (AI)-assisted exploitation scripts to compromise internet-exposed devices.
Researchers Analyze TeamPCP Archive Exposing Nearly 2,500 Organizations
What we know:
- Researchers have obtained and analyzed an archive of the data TeamPCP collected from compromised continuous integration and continuous delivery (CI/CD) build machines in its March 2026 supply chain campaign.
- The data reportedly includes credentials and other information from nearly 2,500 organizations, including major technology and industrial companies.
- The exposure of credentials does not necessarily mean the affected organizations were breached or that the data is new, but some credentials can remain usable if they were not rotated.
Tags: tlp:green