ZeroFox Daily Intelligence Brief - September 21, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 21, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- ShinyHunters Compromises Clop Ransomware Group’s Data Leak Site
- Gemini AI Model Hacked Three Companies During Testing
- ZeroFox Intelligence Flash Report - Data Breach in Berlin Weeks Ahead of Election
ShinyHunters Compromises Clop Ransomware Group’s Data Leak Site
Source: https://hackread.com/shinyhunters-hacks-defaces-clop-ransomware-leak-site/
What we know: ShinyHunters extortion group has compromised Clop ransomware group’s Tor-based data leak site, claiming full access to the underlying server. The group says it exploited an unauthenticated file-upload vulnerability in Grav CMS, then used that access to deface the site. Read this advisory to know more about ShinyHunters.
Context: ShinyHunters claims to have exfiltrated Clop’s server data and the private keys, and plans to issue a 72-hour extortion demand to the ransomware group. In the past month, Clop accounted for close to 300 ransomware attacks, mostly against the manufacturing industry, followed by technology. See Clop’s threat actor profile.
Analyst note: The claimed access to Clop’s Tor private keys is likely to enable ShinyHunters to retain control of Clop’s existing leak-site address. Clop will likely migrate its leak site to new infrastructure to restore its victim-notification and extortion operations.
Gemini AI Model Reportedly Hacked Three Companies During Testing
What we know: Gemini AI model reportedly hacked three companies in May 2026 during a cybersecurity evaluation, joining similar incidents involving OpenAI and Anthropic models that breached external infrastructure during evaluation.
Context: In one case, Gemini repeatedly guessed passwords until it gained access; in two others, it located credentials in a public repository to obtain unauthorized entry. The breaches were attributed to a naming error in which a fictional domain inadvertently matched a real company's domain. Separately, security researchers used Claude to chain two vulnerabilities to access the internal code repository of OpenAI, taking over its staff accounts.
Analyst note: Rogue AI agents are likely going to be weaponized by threat actors to carry out hacks. Furthermore, organizations integrating agentic AI into their workflows and platforms are likely to carry the risk of the agents going rogue and causing unintended harm or carrying out misaligned objectives.
ZeroFox Intelligence Flash Report - Data Breach in Berlin Weeks Ahead of Election
Source: https://www.zerofox.com/advisories/42130/
What we know: Threat actor “Rhysida” advertised the sale of 5.79 TB of data allegedly exfiltrated from the city government of Berlin, Germany. The breach was confirmed by the government of Berlin on August 14, 2026, while the attack itself very likely occurred between August 7–12, 2026.
Context: Berlin has refused to pay the ransom demanded by Rhysida , likely reflecting government priority to demonstrate resolve against cybercrime in the lead-up to the Berlin State elections on September 20, 2026, which will elect a new state parliament and local district councils.
Analyst note: ZeroFox assesses that, as further elections across Europe draw near over the next six to 12 months, threat actors will almost certainly seek to influence public perceptions by conducting timed operations likely intended to sow distrust in government institutions.
THREAT ACTOR WATCH
Lapsus$ group announces return: Lapsus$ Group has announced its return from retirement and stated its intent to directly target a law enforcement agency. The group has named an unspecified global company generating more than USD 50 billion in annual revenue as a victim.
- Lapsus$ Group was part of the Scattered Lapsus$ Hunters alliance before temporarily dissolving in October 2025 following law enforcement operations.
- Lapsus$ Group emerged in 2021 and gained notoriety through high-profile intrusions targeting governments and major technology companies, including Nvidia, Samsung, and Uber.
INDUSTRY ALERT
Cyberattacks in Maritime and Shipping sector: The United States is reportedly monitoring nearly 20 vessels worldwide as a third tanker bringing fuel from the United States to Europe experienced failures affecting internal control systems while sailing in the Mediterranean. The incident has been reported as a suspected cyberattack, but no threat actor has been identified and the cause has not been independently confirmed.
- The incident follows two cyberattacks on Texas-bound tankers in August, which U.S. authorities have acknowledged as malicious cyber activity.
- Separately, Anthropic has reported that an Iran-linked threat actor used Claude for reconnaissance of U.S. naval forces and maritime systems, including researching shipboard vulnerabilities, VSAT terminals, Cisco communications equipment, industrial control products, naval movements, and personnel.
Analyst note: The three recent incidents involve cyberattacks on commercial energy tankers, suggesting that vessels transiting geopolitically sensitive chokepoints and major energy corridors are likely to face elevated exposure to both physical and cyber attacks. The suspected threat actors have targeted or reportedly disrupted communications, navigation, and internal control systems, likely to interfere with vessel operations without necessarily requiring direct control of the ship.
DEEP AND DARK WEB INTELLIGENCE
Exploit user betway: Well-regarded threat actor "betway" has advertised a database allegedly containing more than 3.1 million records belonging to individuals in Saudi Arabia on the predominantly Russian-language dark web forum Exploit. The actor claims the data was collected through advertising campaigns targeting customers interested in luxury cars, yachts, restaurants, and hotels. The dataset allegedly contains personally identifiable information (PII), including names, email addresses, and phone numbers, with approximately 1 million records containing all three; 78,000 containing names and email addresses; and 1.4 million containing names and phone numbers.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2026-28326: An unauthenticated remote code execution (RCE) vulnerability in SolarWinds Access Rights Manager (ARM) caused by a hard-coded static key, could enable attackers to execute arbitrary code remotely. No exploitation in the wild has been reported, and SolarWinds has fixed the flaw in ARM 2026.2.1.
Affected products: SolarWinds Access Rights Manager 2026.2 and earlier
Tags: DIB, tlp:green