zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - September 15, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - September 15, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CenterPoint Energy Discloses Customer Data Breach
  • VPN Vulnerability Exposes Japan Government Personnel Data
  • Attackers Abuse Verified HBO Max Reddit Account to Distribute Infostealers

CenterPoint Energy Discloses Customer Data Breach

Source: https://www.sec.gov/Archives/edgar/data/48732/000110465926107560/tm2625326d1_8k.htm

What we know: Texas-based utility CenterPoint Energy has disclosed a customer data breach. ZeroFox observed an untested threat actor "Hex_4d722e4d656f77" leaked data allegedly associated with CenterPoint Energy on BreachForums. The company has not confirmed the responsible threat actor at the time of reporting.

Context: The actor claims to have obtained more than 7.49 million records through a CenterPoint Energy application programming interface (API) lacking adequate authentication controls, rate limiting, and Web Application Firewall (WAF) protection. The alleged exposed data includes names, phone numbers, billing and service addresses, email addresses, driver's license numbers, and partial Social Security numbers (SSNs).

Analyst note: The affected individuals are very likely to face downstream risks of targeted phishing and identity fraud, and other misuse of personal information.

VPN Vulnerability Exposes Japan Government Personnel Data

Source: https://www.bleepingcomputer.com/news/security/japans-digital-agency-says-vpn-flaw-exposed-246-000-personnel-records/

What we know: Japan’s Digital Agency has confirmed that attackers exploited a medium-severity VPN vulnerability to gain unauthorized access to its Government Solution Service (GSS). The breach is suspected to have compromised approximately 246,000 records belonging to government employees and others who use the service. The specific VPN product and vulnerability have not been disclosed.

Context: The exposed data is suspected to have affected 236,000 names, 231,000 email addresses, 94,000 phone numbers, and 1,000 physical addresses. Other crucial connected information like My Number IDs (social security / tax number), bank, or pension information are confirmed to not have been compromised nor has any misuse been confirmed at the time of writing.

Analyst Note: The exposed contact information is likely to enable phishing and impersonation of government personnel and organizations, particularly because attackers could have obtained information linking individuals to government entities or GSS operations. However, the absence of financial and national identification data limits the potential for direct financial fraud from the exposed records alone.

Attackers Abuse Verified HBO Max Reddit Account to Distribute Infostealers

Source: https://cybernews.com/cybercrime/hbo-max-reddit-account-hacked-malware-fake-ads/

What we know: Threat actors have reportedly compromised the verified HBO Max Reddit account to distribute 108 malicious ads over 48 hours, using ClickFix lures to target HBO Max users, developers, and people seeking AI software or system utilities. The compromised account reportedly served as a trusted channel for a larger operation, although links to other known campaigns remain unclear.

Context: The ads included 40 HBO Max-themed lures, 36 fake OpenAI Codex downloads, 15 macOS disk-cleaning utilities, 11 desktop developer tools, and six fake macOS HBO Max apps. Each lure directed users into a ClickFix attack that ultimately deployed information-stealing malware on Windows or macOS devices.

Analyst Note: In this elaborate infostealing campaign, the attackers were likely seeking access to endpoint data and authentication material, rather than a specific set of credentials. The diversity of lures deployed by the threat actors likely suggests the objective was not solely to target HBO Max users, but to maximize the number and value of potential victims across different user groups.

DEEP AND DARK WEB INTELLIGENCE

Telegram user 313 Team: Pro-Palestinian group “313 Team” has claimed distributed denial-of-service (DDoS) attacks against the Saudi Ministry of Foreign Affairs and the Saudi National Bank (SNB) on its Telegram channel. The group alleges disruption of internal servers and complete takedown of both organizations' main websites and associated subdomains. The operations are very likely a part of a broader Iran-aligned retaliatory campaign that may be targeting the Saudi Arabia government and financial infrastructure, likely timed to coincide with reported Houthi missile strikes.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2026-85706 This is a path traversal vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE), stemming from improper path confinement and missing authentication checks in the platform's repository commits API. The flaw enables unauthenticated attackers to read arbitrary files from a GitLab server. Active exploitation was observed within days of GitLab's September 10 disclosure, with threat actors dumping configuration files, secrets, and SSH configurations.

Affected products: GitLab Community Edition and Enterprise Edition—fixed in versions 19.3.2, 19.2.6, and 19.1.8

Tags: DIB, tlp:green