## ZeroFox Weekly Intelligence Brief – September 5, 2026
|by Alpha Team

ZeroFox Weekly Intelligence Brief – September 5, 2026
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 6:00 AM (EST) on September 3, 2026; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Three Recent Healthcare Data Breaches Highlight Growing Threats to Sector
What we know:
- On September 1, 2026, ZeroFox observed at least three data breaches affecting U.S. healthcare organizations Aesto Health, Novocure, and Nutex Health.
- The healthcare sector has experienced at least 100 attacks in the past 30 days, nearly 90 percent of which are ransomware and data breaches.
AI Model Testing METR Discloses API Key Theft
What we know:
- Artificial intelligence (AI) model testing nonprofit METR has reportedly disclosed two security incidents, including an incident where a threat actor obtained a public model application programming interface (API) key through an AI agent and used it for three weeks to consume approximately USD 600,000 in credits from a researcher's account.
Anthropic Warns of Infostealer Campaigns Targeting Claude Session Credentials
What we know:
- A threat actor is reportedly identifying and exploiting stolen Claude session credentials to access user accounts and run up usage limits.
- The credentials were stolen from malware infected systems.
- The infostealers are often delivered through unofficial software downloads and malicious applications.
Tags: tlp:green