zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - September 3, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - September 3, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Threat Actor Claims Access to 160 Million Driver’s Licenses
  • Threat Group “FulcrumSec” Publishes Manchester Airport Group Customer Data
  • ZeroFox Intelligence Flash Report - Operation Economic Outcast

Threat Actor Claims Access to 160 Million Driver’s Licenses

Source: https://cloud.zerofox.com/intelligence_new/advanced_dark_web/110384

What we know: A dark web marketplace dubbed "NEXUS" has advertised a dataset allegedly containing over 153 million American and Canadian driver's license scans, stolen from IDScan[.]net, a Louisiana-based identity verification platform. ZeroFox observed an untested threat actor, "databroker1," advertising the NEXUS portal on dark web forum Exploit.

Context: The dataset also allegedly includes 10 million secondary documents like international passports, residency permits, and medical cards. The NEXUS marketplace was taken offline shortly reportedly following an FBI inquiry.

Analyst note: If verified, the exposure of high-resolution ID scans and biometric data is very likely to fuel deepfake identity theft, account takeovers, targeted phishing against impacted individuals, and even auto insurance fraud.

Threat Group “FulcrumSec” Publishes Manchester Airport Group Customer Data

Source: https://cloud.zerofox.com/intelligence_new/advanced_dark_web/110382

What we know: Threat group “FulcrumSec” has published data belonging to at least 8.7 million individuals following failed ransom negotiations with Manchester Airports Group (MAG). The group also claims to have withheld nearly 200,000 records from public release.

Context: The actor claimed the dataset includes 184 judicial addresses, 77 UK Parliament and City of London addresses, over 1,000 central government and regulatory accounts, 1,704 defense industry addresses, and over 14,000 National Health Service (NHS) accounts, among other personal, travel and system configuration details.

Analyst note: Opportunistic scammers are likely to attempt targeted financial fraud using the exposed data, including fake traffic or parking fines, booking cancellation scams, and fake airport Wi-Fi account suspension notices. Exposure of information on future travel bookings and residential addresses are also likely to enable burglary attempts. Additionally, the threat actor’s claim of withholding 200,000 future travel records is likely an extortion tactic, as such data has reportedly already been exposed.

ZeroFox Intelligence Flash Report - Operation Economic Outcast

Source: https://www.zerofox.com/advisories/41802/

What we know: The United States’ Operation Economic Outcast (OEO) against Iran likely signals a strategic shift from military to economic tactics to secure Iranian concessions and weaken support for the ruling government. However, a shift back to major combat operations is not improbable.

Context: OEO proposes using secondary sanctions on Iranian trading partners that have helped Iran withstand previous restrictions. U.S. Treasury Secretary Scott Bessent also warned that any country conducting economic activity with Iran risked having key companies and financial entities cut off from the global financial system.

Analyst note: OEO will likely fail to persuade Iran to abandon its maximalist goals, especially if it is only implemented gradually. OEO is unlikely to coerce Iranian trade partners to sever their economic ties with Iran in the short term. Iran will likely respond to U.S. economic pressure with military escalation. A prolonged period of occasional escalation by both sides marked by economic pressure to induce concessions is likely for the remainder of 2026.

DEEP AND DARK WEB INTELLIGENCE

ZeroFox analyses on illicit network access sales on dark web for the past month

  • Threat actors to watch: SCP-2013 / Dark_Alpha (untested) and Big-Bro (well-regarded), who together accounted for 17 percent of all network access listings within the past one month period.
  • Data advertised: Fortinet SSL-VPN, FortiGate, SSH, and VPN access with domain or local administrator rights
  • Targeted industries: Technology, manufacturing, communications, logistics, government agencies in Thailand, Nigeria, and Portugal, among others
  • Impacted region: North America, followed by Europe and Russia

The dark web forum Exploit's preference among threat actors for the posts likely reflects the centrality of Russian-speaking IAB communities in the network access trade. ZeroFox observed a 43.5 percent month-over-month increase in network access offerings, rising from 92 in July 2026 to 132 in August 2026. The advertised access is likely to enable threat actors to conduct further network intrusions, particularly where actors obtain VPN, firewall, SSH, or domain/local administrator privileges. Access brokers are likely to sell the same accesses to multiple buyers or actors can use compromised infrastructure for follow-on campaigns, increasing the duration and potential impact of a compromise.

VULNERABILITY AND EXPLOIT INTELLIGENCE

SonicWall SMA1000 zero-day: Two actively exploited zero-day vulnerabilities in SonicWall SMA1000 appliances are being chained together in remote code execution (RCE) attacks. CVE-2026-83548 is a command injection flaw stemming from a server-side request forgery (SSRF) weakness, exploitable without authentication. CVE-2026-83549 is a command injection vulnerability in the SMA1000 Appliance Management Console requiring admin privileges. SonicWall has released a hotfix and urges immediate upgrade.

Affected products: SonicWall SMA1000 models 6210, 7210, and 8200v

ZeroFox has observed that moderately credible threat actor “grantall” was the most active actor advertising posts related to vulnerability and exploit on the dark web over the past month. The actor advertised auctions for four OpenCart vulnerabilities on dark web forum Exploit, including SQL injection flaws and an RCE vulnerability.

AI ALERT: OpenAI has classified its newest model, Astra, as the first to reach the company’s “critical” cybersecurity capability threshold, after internal testing confirmed it could find previously undetected security flaws and develop ways to exploit them across many well-protected systems without human guidance.

Tags: DIBtlp:green