zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - September 22, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - September 22, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Ribon Breach Exposes BigCommerce Customer Data
  • Hackers Target Rust Developers with Fake Job Offers and Malicious Commands
  • Threat Actor Advertises User Database Allegedly Belonging to Social Media Platform Parler

Ribon Breach Exposes BigCommerce Customer Data

Source: https://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/

What we know: E-commerce platform BigCommerce has reportedly alerted multiple merchants to data breaches after attackers compromised credentials for third-party shopping experience optimization applications, Ribon and Ribon 1.5.

Context: The attacker used a compromised application key belonging to Ribon and Ribon 1.5 to inject malicious scripts and access existing customer records held within BigCommerce merchant environments. Exposed data reportedly includes customer names, email addresses, phone numbers, and shipping addresses.

Analyst note: The Ribon breach is likely to have a larger downstream impact, given the number of other entities connected to the application and BigCommerce. Threat actors are very likely to use exposed data to impersonate retailers or shipping providers, tricking customers into revealing sensitive information, engaging with malicious links, or stealing cargo. For affected merchants, the incident is very likely to result in reputational damage, customer churn, and potential regulatory scrutiny under applicable data privacy laws.

Hackers Target Rust Developers with Fake Job Offers and Malicious Commands

Source: https://cybernews.com/news/rust-developers-hackers-fake-job/

What we know: Hackers are reportedly targeting Rust developers through one-on-one video calls posed as job interviews, contract opportunities, or project discussions, to persuade victims to install a supposedly missing audio codec or execute commands that compromise their devices and accounts and enable malware deployment.

Context: The threat actors have reportedly set up new but legitimate-looking company profiles, including LinkedIn accounts, to avoid suspicion. A North Korean state-sponsored actor tracked as Contagious Interview, also known as WaterPlum, is suspected to be behind the campaign.

Analyst note: Threat group Contagious Interview will likely continue targeting developers and job seekers across additional programming ecosystems and technical roles, as the group pursues cryptocurrency theft, account credentials, intellectual property, and initial access into specific organizations.

Threat Actor Advertises User Database Allegedly Belonging to Social Media Platform Parler

Source: https://cloud.zerofox.com/intelligence_new/advanced_dark_web/111359

What we know: Moderately credible threat actor “pepela” has advertised an alleged user database of U.S.-based social media platform Parler on dark web forum Exploit. Parler, founded in 2018, claims to provide an alternative to mainstream social media platforms like X and Facebook and reached its peak in 2021.

Context: The dataset allegedly containing 16.2 million records, includes emails, names, passwords, IP addresses, phone numbers, locations, and payment-related details. The actor is seeking USD 7,000.

Analyst note: ZeroFox assessed the sample data of approximately 3,000 records that appear to include names, password hashes, and partial phone numbers. But, the data has not been verified as linked to Parler. However, it is also likely not linked to the 2021 scraped data incident, which primarily captured user-generated content and metadata.

  • If authentic, brute-force attacks using password hashes, and also powered by AI, are possible, leading to account takeover. Exposed individuals are also likely to be targeted in ideologically-motivated campaigns.
  • Compromised accounts are likely to fuel phishing and other social engineering attacks, while the inclusion of military-affiliated profiles are likely to increase the value of the data for targeted profiling and social engineering.

DEEP AND DARK WEB INTELLIGENCE

PwnForums user 666op: Moderately credible threat actor "666op" has advertised a database allegedly belonging to the South Korean National Health Insurance Service (NHIS) on the predominantly English-language deep and dark web forum PwnForums. The dataset allegedly contains more than 51 million unique records, including national ID numbers, full names, gender, dates of birth, addresses, contact numbers, insurance and employment information, income, insurance premiums, and payment arrears. The dataset allegedly also contains extensive medical examination data, including physical measurements, blood pressure, blood sugar, cholesterol levels, kidney and liver function markers, chest X-ray results, and smoking and drinking status.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Linux Kernel vulnerabilities: CISA has warned of active exploitation of three Linux kernel vulnerabilities tracked as, CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682. Successful exploitation of these vulnerabilities is likely to enable attackers to crash affected systems, tamper with or steal sensitive data, and potentially gain elevated privileges.

CVE-2026-78306: This is a Bluetooth authentication bypass vulnerability in some DJI drone models. The flaw exists because only three Bluetooth commands verify a trusted UUID, while all other commands lack authentication checks, enabling any nearby attacker within Bluetooth range to issue unauthorized instructions without credentials. Researchers note that a mid-air takeover is a potential consequence of successful exploitation.

Affected products: DJI Mavic, Mini, Air 3, Air 3S, Neo, Flip, and Avata 2/360 drone models

Tags: DIB, tlp:green