ZeroFox Daily Intelligence Brief - September 14, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 14, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Revolut Customer Data Exposed Through Fake Government Requests
- Threat Actors Use Passkey Phishing and AI-Driven Invoice Scams At Scale
- Fake Sexual Misconduct Emails Target Universities
Revolut Customer Data Exposed Through Fake Government Requests
What we know: British fintech firm Revolut has reportedly confirmed that an unauthorized third party used a legitimate government agency email domain to submit fraudulent information requests, resulting in exposure of customer identity and contact information, identity documents, and potentially verification selfies, account statements, and transaction histories.
Context: Revolut said a limited number of customers were affected and that customer funds and systems were not compromised. In the past 30 days, ZeroFox observed Revolut data mentioned once by threat actor “Mister777” on Exploit, allegedly containing account holder’s personally identifiable information (PII).
Analyst note: The exposed identity and financial information is likely to increase the risk of targeted phishing, social engineering, identity theft, and financial fraud. The separate dark web references likely indicate continued interest in Revolut-related customer data, although there is currently insufficient evidence to verify that the two incidents are linked.
Threat Actors Use Passkey Phishing and AI-Driven Invoice Scams At Scale
Source: https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html
What we know: Threat actors are reportedly abusing third-party email delivery infrastructure to blast financial fraud scam messages and passkey-themed social engineering to breach cloud environments and exfiltrate data in two separate campaigns.
Context: Threat actors masquerading as CEOs of victim companies sent over 1 million scam emails to persuade accounts payable departments to initiate Automated Clearing House (ACH) transfers for a supposed ServiceNow subscription.The campaign primarily targeted U.S. IT services, consumer goods, real estate, and discrete manufacturing firms. The second campaign involves cloud-based intrusions by actors posing as IT help desk, attributed to actors that broke off from the BlackFile group.
Analyst note: Threat actors are likely to establish persistent footholds and exfiltrate data from compromised environments to use it for extortion, onward fraud, and impersonation of trusted internal accounts against downstream entities. Attribution to multiple threat actors likely shows a shared initial access layer feeding multiple extortion brands.
Fake Sexual Misconduct Emails Target Universities
Source: https://hackread.com/fake-sexual-misconduct-emails-universities-zoho-rat/
What we know: Threat actors are reportedly targeting universities with fake sexual misconduct phishing emails, impersonating senior university officials to trick staff into installing Zoho Assist, a legitimate remote-access tool, which can give attackers control of their systems.
Context: The emails reportedly impersonate university presidents and deans at institutions including Notre Dame and the University of Virginia. The emails claim that a Title IX or sexual misconduct case requires immediate attention and direct recipients through Google Drive to a Zoho Assist installer. Once installed, the tool enables attackers to control screens, transfer files, and deliver additional malware, including ransomware. More than 80% of identified targets were healthcare-related universities, including medical colleges and teaching hospitals.
Analyst note: The focus on healthcare-linked universities is likely linked to valuable medical, research, and institutional data. The abuse of legitimate remote-access software also likely helps attackers blend malicious activity with legitimate administrative activity, potentially making detection more difficult.
DEEP AND DARK WEB INTELLIGENCE
PwnForums user GoreTerminal: Untested threat actor “GoreTerminal” has advertised a dataset allegedly associated with FairMoney, a Nigeria-based digital micro-finance bank and mobile neobank on dark web forum PwnForums. The dataset allegedly includes approximately 330,000 phone numbers and 143,000 email addresses.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2026-85102 and CVE-2026-85103: The Dutch National Cyber Security Centrum (NCSC) has warned that exploitation of two critical Check Point VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, is likely to occur soon, despite no public proof-of-concept being available. The flaws enable remote code execution (RCE) on affected Security Gateways and Management Servers, likely enabling attackers to gain full system control, access confidential data, or disrupt operations.
Affected products: R81.20, R82, R82.10, R81.10.x, and R82.00.x, along with the end-of-support (EoS) versions R80 through R80.40, R81, and R81.10
JFrog Artifactory vulnerabilities: Two JFrog Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, are reportedly being chained together in an exploit to obtain administrator access to vulnerable self-hosted servers and deploy backdoors. A separate critical flaw, CVE-2026-82329, has also been exploited in the wild.
Affected products: The affected products are listed in this advisory.
Tags: DIB, tlp:green