ZeroFox Daily Intelligence Brief - September 4, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 4, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Hungarian Non-Profit Development Office Allegedly Hit by Rhysida Ransomware
- Thomson Reuters Breach Impacts US and Canadian Court Systems
- U.S. NSA Issues Guidance on Defending Against AI-Enabled Threats
Hungarian Non-Profit Development Office Allegedly Hit by Rhysida Ransomware
Source: https://cloud.zerofox.com/intelligence_new/advanced_dark_web/110458
What we know: Rhysida ransomware group has claimed to have stolen data from Széchenyi Programme Office, a Hungary-based nonprofit that provides advisory and coordination services for EU and domestic development fund programs. The claim follows Rhysida's August 31 targeting of the City of Berlin.
Context: Rhysida is selling the Hungarian data for 20 BTC (approx. worth USD 80,856), which appears to include screenshots of passports and a document related to pay and bonuses. Unlike the Berlin claim, Rhysida has provided limited details on the Hungarian data, and the compromise has not been independently verified.
Analyst note: Rhysida's recent targeting of European public-sector and governance-related entities very likely indicates continued interest in the region’s government administration and policy implementation entities.
- The lack of details on Hungarian non-profit alleged data breach likely indicates the threat actor is attempting to extort the entity before publicly releasing additional data.
- Exposed employee and official personally identifiable information (PII), including the apparent passport images, are likely to be leveraged for intelligence collection efforts to target or influence individuals involved in European development policy by various interest groups.
Thomson Reuters Breach Impacts US and Canadian Court Systems
Source: https://cybernews.com/news/thomson-reuters-c-track-court-records-breach/;
What we know: Thomson Reuters has reportedly confirmed unauthorized access to its C-Track court case management platform, exposing court records across the United States and Canada. Separately, U.S. legal firms Quinn Emanuel and McDermott experienced separate social-engineering-related breaches involving sensitive files.
Context: The unauthorized access reportedly took place in March 2026. The affected court records contained names and other personal information, although the specific data compromised remains unclear. The company said C-Track remains operational and that affected customers have been notified.
Analyst note: The incident at Thomson Reuters and the two U.S. law firms likely indicate a campaign targeting the legal sector in the country. The sensitive information involving breaches at legal entities is very likely to enable threat actors to put pressure on individuals and entities for extortion.
U.S. NSA Issues Guidance on Defending Against AI-Enabled Threats
What we know: U.S. National Security Agency (NSA) has released a cyber hygiene guide warning that advanced persistent threats (APTs) and other cybercriminals are increasingly using AI to automate reconnaissance and network exploitation, particularly against poorly configured and unpatched systems.
Context: NSA’s guide recommends immediate risk-reduction measures, including network inventory, multifactor authentication (MFA), and patching, while encouraging organizations to progress toward Zero Trust practices such as network segmentation and continuous monitoring. It also prioritizes defenses against AI-enhanced threats through automated reconnaissance and living-off-the-land (LOTL) techniques.
Analyst note: The increasing use of AI to automate reconnaissance and network exploitation is likely to enable threat actors to identify and exploit weaknesses at greater speed and scale in the near term.
DEEP AND DARK WEB INTELLIGENCE
Exploit user brokering: Untested threat actor “brokering” has advertised a database allegedly stolen from Ticketmaster’s Latin American operations. The dataset allegedly contains 412,192 records, including names, contact details, 250,000 Brazilian CPF numbers, purchase information, and payment methods allegedly exposed. In 2026 alone, Ticketmaster was targeted in three breaches, including one in April where ShinyHunters advertised a dataset.
Ransomware leak site Vexy: A new ransomware leak site “Vexy” has listed Brazil-based adhesive manufacturer “Engefitas Soluções Adesivas" and claimed to have stolen 27.25 GB of data. Vexy also advertised a ransomware-as-a-service (RaaS) program, offering Linux and ESXi encryptors and an affiliate platform, indicating an effort to recruit affiliates and expand its operations.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2026-20212: Cisco has released software updates for this vulnerability in Cisco Nexus 9000 Series switches, running Silicon One-based hardware. The flaw can enable an unauthenticated, remote attacker to execute arbitrary code with root privileges. It exposes TCP ports 43210 and 43211 due to binding to an unrestricted IP address.
- Nexus 9000 series with Silicon One architecture is used in modern AI data centers; successful exploitation is likely to enable threat actors to disrupt AI workloads or manipulate traffic, further resulting in outages.
Affected products: Affected products are listed in this advisory.
Tags: DIB, tlp:green