ZeroFox Daily Intelligence Brief - September 2, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 2, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Three Recent Healthcare Data Breaches Highlight Growing Threats to Sector
- Russia-Aligned Actor Uses Nuclear Prompt in Malware Script to Evade Detection
- AI Model Testing METR Discloses API Key Theft
Three Recent Healthcare Data Breaches Highlight Growing Threats to Sector
What we know: On September 1, 2026, ZeroFox observed at least three data breaches affecting the healthcare industry located in the United States, involving Aesto Health, Novocure, and Nutex. ZeroFox has observed that, in the past 30 days, the healthcare sector experienced at least 100 attacks, of which ransomware and data breaches accounted for nearly 90 percent of attacks.
Context:
- Aesto Health, a healthcare SaaS provider, has confirmed that unknown threat actors compromised data affecting more than 9 million individuals, and their personally identifiable information (PII), including names, financial account numbers, health insurance information, individual taxpayer identification numbers, and other government identification numbers. The breach reportedly indirectly affects at least two dozen connected healthcare providers.
- Oncology firm Novocure has confirmed that threat actors compromised records belonging to nearly 1,500 U.S. cancer patients, along with employee contact information. ShinyHunters has claimed responsibility and threatened to leak more than 30 GB of data; however, Novocure has not confirmed any link to the group.
- Healthcare services and operations company Nutex has confirmed that threat actors have targeted the company and compromised personal and financial data of patients and employees. The company has not confirmed the threat actors behind this attack. However, The Gentlemen ransomware group (see threat actor profile) claimed to have recently targeted Nutex.
Threat actors to watch:
- Qilin ransomware group (see threat actor profile) and the ShinyHunters extortion group led the attacks on the healthcare sector in the past month.
- While Qilin led the ransomware attacks, ShinyHunters was the most prominent group behind data breach activity.
- Additionally, in the past month ShinyHunters (see threat actor profile) targeted the healthcare sector the most compared to other sectors, accounting for nearly 50 percent of all attacks.
Analyst note: The sector's focus, particularly from ShinyHunters, is likely due to the success of initial vishing attacks targeting healthcare employees, which can provide access to further internal systems.
- The sensitive patient and insurance data held by these entities, combined with the immediate human-safety risks associated with disruptions to medical technology companies, increases the value of stolen data and likely enables threat actors to negotiate ransoms with greater pressure on victims.
- Such data is also likely to be leveraged for insurance fraud and financial extortion targeting vulnerable patients.
Russia-Aligned Actor Uses Nuclear Prompt in Malware Script to Evade Detection
Source: https://thehackernews.com/2026/09/russia-aligned-uac-0099-plants-nuclear.html
What we know: Russia-aligned threat actor "UAC-0099" has reportedly employed a new technique, dubbed "GuardBreaker," that embeds a nuclear weapons-related prompt within malware to prevent AI-assisted analysis of the malicious code.
Context: The GuardBreaker-embedded script is designed to download and install MATCHBOIL to deliver payloads against targets in Ukraine's transportation and energy sectors. The technique exploits the built-in safety mechanisms of large language models (LLMs), causing AI security scanners to refuse analysis of nuclear technology or become distracted before reaching the malicious portions of the code. Similar adversarial prompt injections were previously identified in the Mini Shai-Hulud, Miasma, and Hades supply chain attack campaigns.
Analyst note: GuardBreaker's appearance across both state-aligned and financially motivated campaigns very likely signals broad adoption of AI guardrail manipulation as a standard evasion technique by threat actors. As security teams increasingly rely on AI for threat analysis, even its guardrails are almost certainly going to create blind spots that threat actors will exploit.
AI Model Testing METR Discloses API Key Theft
What we know: AI model testing nonprofit METR has reportedly disclosed two security incidents, including an incident where a threat actor obtained a public-model API key through an AI agent, and used it for three weeks to consume approximately USD 600,000 in credits from a researcher’s account.
Context: In March 2026, a fail-open bug in a researcher's personal, publicly exposed EC2 instance leaked an API key for METR's public models account, which the attacker is suspected to have maintained access to via an added SSH key. Separately in May, suspected financially motivated actors ran a sustained campaign (credential stuffing, OAuth abuse, phishing) targeting frontier model accessMETR reports no confirmed access to sensitive data in either case and has since added security staff and isolated public infrastructure.
Analyst note: Free or subsidized credits and already-high usage baselines likely blind AI labs to the kind of cost anomalies that would normally flag theft. This incident will likely encourage attackers to keep hunting certificate transparency logs for exposed, quickly built LLM infrastructure at similarly under-resourced organizations.
DEEP AND DARK WEB INTELLIGENCE
PwnForums user franceOr: Untested threat actor "franceOr" has advertised unauthorized webmail access allegedly associated with Polizia di Stato, the Italian State Police, on the predominantly English-language dark web forum PwnForums. The access allegedly leads to Kodex Global, a secure portal used by law enforcement agencies to submit legal data requests to telecommunications and technology companies. The actor further claims the access enables retrieval of legal documents and citizen information, including Italian security camera footage, as well as fraudulent use of official law enforcement portals.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2026-0768: This is an actively exploited unauthenticated remote code execution (RCE) vulnerability in Langflow, an open-source framework for building AI applications. The flaw resides in the code validator of Langflow's custom component editor, where insufficient validation of user-supplied input enables arbitrary Python code execution with root privileges without authentication. Attackers are likely to use the vulnerability to harvest Langflow superuser credentials, OpenAI API keys, and other secret keys, SSH access, and shell history.
Affected products: Langflow versions 1.4.2 and earlier
Tags: DIB, tlp:green