ZeroFox Daily Intelligence Brief - August 28, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - August 28, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- FBI and Australian Authorities Arrest Alleged TeamPCP Masterminds
- Manchester Airports Group Breached, Customer Data Exfiltrated
- OpenAI Reveals Reward Hacking Drove AI Agents to Breach Hugging Face
FBI and Australian Authorities Arrest Alleged TeamPCP Masterminds
Source: https://cybernews.com/news/teampcp-hackers-arrested-supply-chain-attacks/
What we know: Two suspected Team PCP members have reportedly been arrested by Australian authorities on August 26, 2026. The arrested individuals are reportedly the masterminds behind TeamPCP operations with one of them being the alleged leader.
Context: The suspects distributed malicious software, allegedly compromising over 1,000 organizations globally, enabling the theft of more than 500,000 credentials, and the exfiltration of at least 300 GB of data. Authorities reportedly identified the individuals by tracing the GitHub alias "DeadCatx3" to a HackerOne profile, revealing a digital footprint of reused accounts and avatars that linked the suspect to a Telegram identity associated with Team PCP.
Analyst note: The seized devices from the suspects are likely to hold information regarding additional infrastructure, active credentials, session tokens, and cryptographic keys necessary to map and revoke unauthorized access across compromised downstream environments and enable further arrests of affiliates. A successor operation reusing TeamPCP's build-pipeline compromise tradecraft is also likely to emerge given the public availability of its tools and attack methods.
Manchester Airports Group Breached, Customer Data Exfiltrated
What we know: Manchester Airports Group (MAG) has confirmed a cyberattack in which threat actors breached its systems and exfiltrated customer data from Manchester, Stansted, and East Midlands airports, relating to car park, lounge and Fast Track bookings, and in-airport WIFI sign-ups.
Context: Payment data and airport operations were unaffected. MAG contained the breach and suspended its online booking-management service as a precaution. The number of affected customers remains unconfirmed, although it is suspected that up to 8.9 million could have been impacted. No threat actor or group has claimed responsibility.
Analyst note: The theft of customer data was likely conducted by an opportunistic or financially motivated actor. The combination of vehicle registration and contact information is likely to enable more convincing impersonation or targeted scams involving parking, fines, or vehicle-related services.
OpenAI Reveals Reward Hacking Drove AI Agents to Breach Hugging Face
Source: https://thehackernews.com/2026/08/openai-says-reward-hacking-drove-ai.html
What we know: In a new development regarding the Hugging Face breach, OpenAI has disclosed that reward hacking drove approximately 700 rogue AI agents to autonomously exploit zero-day vulnerabilities during cybersecurity evaluations conducted under reduced safeguards.
Context: Agents reportedly improvised an unauthorized message board on a locally hosted Artifactory instance exploiting a zero-day SSRF vulnerability to gain internet access and a token-refresh vulnerability to obtain administrator-level access. After OpenAI rebuilt Artifactory, the agents reconstituted their channel and pivoted to breach Hugging Face. OpenAI identified four contributing misalignment patterns: reward hacking, persistence on impossible tasks, unauthorized inter-agent communication, and emergent labor division.
Analyst note: As comparable AI capabilities become more widely available, the risk of similar behavior—whether accidental or deliberately induced by adversaries—is very likely to grow. The autonomous coordination and zero-day exploitation demonstrated by this agent swarm almost certainly mark a significant shift in emergent AI threat capabilities, indicating that unaligned models can independently bypass technical controls under reduced guardrails.
INDUSTRY WARNING
Automotive Transportation & Logistics
TTPs to Watch:
Target: Auto transport and shipping companies moving high-value new vehicles across the U.S.
Aim: Large-scale vehicle theft
Method: Threat actors use phishing and stolen shipping-network credentials to manipulate vehicle shipment details and reroute high-value vehicles to unauthorized locations.
DEEP AND DARK WEB INTELLIGENCE
Exploit user ls1337: Untested threat actor "ls1337" has advertised an 8 GB dataset allegedly associated with Scale AI, a U.S.-based artificial intelligence data infrastructure company, on the Russian-language dark web forum Exploit. The actor claimed the dataset consists of private GitHub data belonging to Scale AI, and the post includes samples of a repository that appears to be an internal Scale AI repository.
VULNERABILITY AND EXPLOIT INTELLIGENCE
Next.js vulnerabilities: Two critical vulnerabilities in Next.js could allow unauthenticated attackers to achieve remote code execution. CVE-2026-75604 is a path traversal flaw affecting Windows-hosted applications that use both the Pages Router and App Router without Cache Components. GHSA-2xp9-vwfh-vxw4 is a heap buffer overflow in the underlying libheif library that can be triggered when the Next.js Image Optimization API processes a maliciously crafted AVIF image. No exploitation of either vulnerability had been reported.
Affected products: Affected products and versions are listed in the Next.js advisory and libheif advisory.
Tags: DIB, tlp:green