ZeroFox Daily Intelligence Brief - August 27, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 27, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- U.S. Seizes China-Linked Infrastructure Targeting Critical Infrastructure
- Medical Device Company Boston Scientific Hit by Cyberattack
- Geopolitical Focus: Nepal Flash Floods Kills Hundreds, Iran-Oman Negotiating Shipping Via Strait of Hormuz, and More
U.S. Seizes China-Linked Infrastructure Targeting Critical Infrastructure
What we know: The U.S. Department of Justice (DoJ) and FBI have seized domains supporting two Chinese state-sponsored hacking platforms, QScan and QTRouter. The platforms are reportedly operated by a threat group known as QTFY, which is employed by a China-based technology company and offers hacking services to China's Ministry of State Security and the People's Liberation Army.
Context: QScan automatically scans and infects internet-of-things (IoT) devices worldwide, adding them to QTRouter, which routes malicious traffic through compromised devices and commercial proxy services to conceal the origin of intrusion activity. QTFY has been active since at least 2018, exploiting both zero-day and known vulnerabilities across enterprise platforms for initial access, and using QTRouter to blend malicious traffic with legitimate network activity.
Analyst note: The use of commercially procured proxy services and compromised civilian IoT devices almost certainly signals a deliberate effort by China-linked actors to design operations resilient to attribution and disruption. Despite the seizures, operational disruptions are likely to be temporary, with China-linked groups reconstituting comparable infrastructure through alternative proxy networks.
Medical Device Company Boston Scientific Hit by Cyberattack
What we know: U.S.-based medical device company Boston Scientific has confirmed a cyberattack that caused a network outage and disrupted some of its corporate IT systems worldwide, affecting business operations, including order processing and shipping.
Context: The company has not confirmed any impact on patients or the type of cyberattack. Boston Scientific develops, manufactures, and markets medical devices across various interventional medical specialties. ZeroFox has observed over 600 cyberattacks on the healthcare industry from January to August 2026, with the majority of them against entities in North America.
Analyst note: If the outage persists, disruptions to order processing and shipping are likely to affect the availability of Boston Scientific's medical devices and supplies. Prolonged disruptions are likely to increase pressure from customers and healthcare providers, giving extortion actors greater leverage. However, there is currently no evidence of an extortion demand, ransomware deployment, data theft, or compromise of implanted devices or patient safety.
Geopolitical Focus: Nepal Flash Floods Kills Hundreds, Iran-Oman Negotiating Shipping Via Strait of Hormuz, and More
- At least 160 people have been killed and hundreds remain missing after flash floods along the Nepal-China border, with experts linking the disaster to a glacial collapse in the warming Himalayas.
- Iran and Oman are negotiating an agreement on shipping through the Strait of Hormuz, under which Iran would bar military vessels from transiting the waterway. Qatar’s prime minister is also expected to visit Tehran for de-escalation talks. Separately, the U.S. Secret Service confirmed awareness of an Iranian state media video appearing to threaten Barron Trump.
- CIA Director John Ratcliffe made an unannounced visit to Moscow for talks with Russian intelligence officials, with the Kremlin confirming the contacts but saying he did not meet President Vladimir Putin.
- The WHO declared Uganda’s Ebola outbreak over after 20 cases and two deaths, while cases in neighboring Democratic Republic of Congo continue to rise, with more than 5,600 cases and 2,700 deaths reported.
DEEP AND DARK WEB INTELLIGENCE
Darkforums user GordonFreeman: Moderately credible threat actor "GordonFreeman" has leaked data allegedly associated with the Ministry of Interior of the Palestinian Territories on dark web forum DarkForums. The actor claims the dataset contains 3,559,378 records belonging to residents of the Palestinian Territories, though the download link provided in the post was non-functional at the time of reporting. If verified, the exposure of a national civil registry at this scale would pose significant risks to affected individuals, including targeted surveillance, identity theft, and potential physical harm given the ongoing conflict in the region.
DATA BREACH INTELLIGENCE
Mercor allegedly suffers data breach: U.S.-based AI recruiting company Mercor has reportedly suffered a data breach, with attackers claiming to have exfiltrated 4 TB of data, including the source code. Samples reportedly contain user logs, prompts, and information on users and their roles. On August 25, untested threat actor “ls1337” advertised 4 TB of alleged Mercor database and source code on the Exploit forum. A similar claim involving Mercor was previously posted by LAPSUS$ in March 2026. Separately, Mercor had disclosed that it was affected by the early 2026 LiteLLM supply chain attack. If the current claims are authentic, the exposed data is likely to reveal private conversations, hiring activity, and operational workflows. Mercor’s client base includes major AI companies such as OpenAI and Meta, which is likely to increase the intelligence value of the compromised data.
VULNERABILITY AND EXPLOIT INTELLIGENCE
Chrome vulnerabilities: Google has released Chrome 152 with patches for 327 vulnerabilities, including 10 critical and 61 high-severity flaws. Most of the critical vulnerabilities are use-after-free issues affecting components such as Angle, Aura, Chromecast, Views, and SafeBrowsing. Google internally discovered 299 of the 327 vulnerabilities, with AI contributing to the increase in vulnerability discoveries this year. External researchers also identified high-value flaws, including CVE-2026-79282, which was rated critical.
Affected products: The affected versions are included in this advisory.
Tags: DIB, tlp:green