ZeroFox Weekly Intelligence Brief – September 19, 2026
|by Alpha Team

ZeroFox Weekly Intelligence Brief – September 19, 2026
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 6:00 AM (EST) on September 17, 2026; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
FBI Disrupts NightmareStresser DDoS-for-Hire Service
What we know:
- The Federal Bureau of Investigation (FBI) has seized domains associated with NightmareStresser, a distributed denial-of-service (DDoS)-for-hire platform reportedly used by threat actors to facilitate attacks against targets worldwide.
AI Coding Assistant Session Hijacked to Spread Shai-Hulud Worm
What we know:
- A threat actor reportedly hijacked an active artificial intelligence (AI) coding assistant session at an unnamed software-as-a-service (SaaS) provider and deployed the Shai-Hulud worm across approximately 100 internal code repositories to exfiltrate repository secrets and proprietary source code.
Spain Reports First Confirmed AI Agent-Linked Data Breach
What we know:
- Spain's Data Protection Agency (AEPD) has reported the first confirmed personal data breach allegedly carried out by an AI agent.
- A third party reportedly used an autonomous system powered by a large language model (LLM) to identify vulnerabilities, gain unauthorized access, modify personal data, and access invoices—all with limited human intervention.
Tags: tlp:green