zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 26, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 26, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - ZeroBytes Targets French Agencies
  • Norway’s Government Digital Infrastructure Hit by DDoS
  • ShinyHunters Claims Major Breach Targeting U.S. Data Center Operator

ZeroFox Intelligence Flash Report - ZeroBytes Targets French Agencies

Source: https://www.zerofox.com/advisories/41653/

What we know: Threat actor ZeroBytes has claimed to have breached France’s Ministry of National Education on the dark web forum PwnForums and its X profile. The Ministry confirmed that the breach occurred on July 25, 2026.

Context: This is the largest breach claimed by ZeroBytes and the second French central-government-body victim, the group has claimed in under two months. The actor claimed that despite being detected by the ministry, they continued to have access to the victim network and exfiltrated 43 GB of data. The Ministry stated that no student information, bank details, or passwords were stolen.

Analyst note: The discrepancy between government disclosure and threat actor claim is very likely a result of persistent access to databases. ZeroBytes is almost certain to continue targeting French government agencies. There’s a roughly even chance of using social engineering and credential stuffing to gain access to more secure data and sell it to third-party buyers.

Norway’s Government Digital Infrastructure Hit by DDoS

Source: https://www.bleepingcomputer.com/news/security/massive-ddos-attack-disrupts-norways-government-digital-services/

What we know: A large distributed denial-of-service (DDoS) attack has reportedly disrupted Norway's shared government digital infrastructure, affecting public-sector services operated by the Norwegian Digitalization Agency (Digdir) and its operations provider, Vivicta.

Context: Digdir operates critical shared government infrastructure including public-service logins, electronic IDs, secure digital mail, and data exchange between agencies. Several services were completely unavailable for short periods. Digdir confirmed no security breach or compromise of personal data occurred. Downstream services relying on Digdir's infrastructure also reported login issues and operational disruptions.

Analyst note: The targeting of centralized digital government infrastructure of a European country likely reflects Russian hybrid warfare tactics. Similar incidents have been documented against NATO member countries and other European nations for their support of Ukraine. Government digital infrastructure is likely to remain an attractive target for state-aligned actors seeking to disrupt crucial communications and/or steal valuable data for intelligence gathering.

ShinyHunters Claims Major Breach Targeting U.S. Data Center Operator

Source: https://cybernews.com/security/shinyhunters-cyrusone-breach-data-center/

What we know: Threat group Shinyhunters has claimed to have targeted a major U.S. data center operator and has demanded USD 13 million in ransom. At the time of writing, the group has not published any sample data.

Context: The group claims to have stolen close to 13 million Salesforce records and hundreds of gigabytes of SharePoint data from the data center operator. The stolen information allegedly includes employees’ personally identifiable information (PII), contracts, facility floor plans, electrical diagrams, access-control records, physical key inventories, security documentation, and credential-related data. The victim organization’s customers include Meta, AT&T, and others.

Analyst note: If the claims are legitimate and the data is leaked following failed negotiations, the exposed information is likely to be valuable to hacktivists and nation-state actors, particularly given the heightened physical and cyber threat activity targeting critical infrastructure owing to the Iran conflict. Detailed information on data center layouts, access controls, and power and cooling systems is likely to provide useful intelligence for reconnaissance or disruption attempts.

DEEP AND DARK WEB INTELLIGENCE

Exploit user sprite1: Untested threat actor "sprite1" has advertised an alleged dataset containing private email addresses and password combinations of users located in theUnited States, the European Union, and the United Kingdom on the predominantly Russian-language dark web forum Exploit. The threat actor claims the dataset is first hand information.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2026-75149: This is a code injection vulnerability in Marimo that could enable an attacker to execute an attacker-supplied Model Context Protocol (MCP) command as a local subprocess when a malicious notebook is opened in edit mode. The vulnerability requires user interaction but does not require attacker authentication. Successful exploitation can lead to arbitrary command execution on the targeted system.

Affected products: Marimo versions prior to 0.23.15.

Tags: DIBtlp:green