ZeroFox Daily Intelligence Brief - September 24, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 24, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- OpenAI Agent Breaches Australian Government Health Portal
- LA Freeway Sign Compromised to Promote Dissident-Doxxing Site
- Academic Publisher Elsevier Hit by LAPSUS$ Redirect Attack
OpenAI Agent Breaches Australian Government Health Portal
What we know: Australian Prime Minister Anthony Albanese revealed that an OpenAI AI agent breached a government health statistics portal in June 2026. The agent also gained unauthorized access to files, marking the first publicly reported instance of an AI agent hacking a government website.
Context: OpenAI reportedly confirmed that the agent accessed both public and non-public files on the Medicare Statistics Reporting Service—a portal containing aggregate health statistics related to Australia's universal healthcare scheme. The firm became aware of the incident in August 2026. No patient records were accessed.
Analyst note: The agent's autonomous expansion beyond its assigned task very likely signals that current evaluation sandboxing remains structurally insufficient.
LA Freeway Sign Compromised to Promote Dissident-Doxxing Site
What we know: A portable electronic freeway message sign near Westwood, Los Angeles, was reportedly compromised and used to display the URL of the Goorkan website, which publishes the names, photographs, and personal information of Iranian dissidents. The unauthorized message was reportedly visible for about a week before being removed.
Context: The sign was located near Westwood, an area with a large Iranian-American population. A Telegram channel linked to Goorkan website also solicits information on individuals abroad that the Iranian regime labels as traitors.
Analyst note: Although no threat actor or state has been attributed to the intrusion, the incident is very likely to be carried out by Iran-linked or ideologically driven actors to project power and influence over diaspora communities. It comes amid broader efforts attributed to Iran-linked actors to target dissidents, activists, and journalists outside Iran, as warned in this FBI report.
Academic Publisher Elsevier Hit by LAPSUS$ Redirect Attack
What we know: Academic publishing giant Elsevier confirmed that on September 21, 2026, visitors to its select platforms were redirected to a third-party page associated with the LAPSUS$ cybercriminal group. Elsevier stated the incident was narrowly scoped and limited in duration, with normal service restored.
Context: The redirect incident was posted publicly by a student on Reddit after being unable to access course materials. Elsevier did not disclose which platforms were affected or for how long. LAPSUS$ has previously targeted Rockstar Games, Adidas, and GitHub. The group resurfaced in 2025 alongside threat groups Scattered Spider and ShinyHunters before its activity reportedly dropped to about six attacks per month.
Analyst note: The redirect was likely intended to steal credentials of Elsevier users. Although no confirmed data theft has been reported, any data compromise is likely to result in account takeover attempts. Given the group's recent pattern of collaborating with other threat actors, follow-on social engineering targeting the academic/publishing sector is plausible.
THREAT ACTOR WATCH
ShinyHunters (Read ZeroFox flash report) : ShinyHunters' September 22 claimed breach of the FBI job application portal comes amid three U.S. political flashpoints: the November 3 midterm elections in the United States, the escalating U.S.-Iran conflict, and Russia's gray-zone campaign against NATO. None of these shows state direction. However, nation-states have historically used R&DE brands for low-cost, deniable operations, and Rhysida's theft of Berlin city government data in August 2026, ahead of the city's elections, is a recent precedent.
Analyst note: ZeroFox assesses there is a roughly even chance that the group's brand, timing, or handling of the stolen data is separately being shaped, wittingly or not, by an actor seeking political disruption or intelligence value. ZeroFox holds no confident view on which state, if any, would benefit.
- Watch For: Leak or sale timing relative to November 3, and listings of the data on dark web forums or ShinyHunters’ leak sites.
TTPs to Watch
- Target: Government and law enforcement entities, alongside large enterprises running SaaS and ERP platforms.
- Method: Data theft and extortion, historically through vishing and OAuth token abuse.
- Aim: Financial gain and retaliation against law enforcement. The more immediate risk is that the group sells the personnel data to criminal or nation-state buyers.
- IoCs: See ZeroFox threat actor profile for details.
INDUSTRY ALERT
Legal Sector in the United States Threat group “LeakedData” has listed U.S.-based law firm Cozen O'Connor on its leak site, claiming to have exfiltrated client data and alleging the firm offered USD 5.8 million for its protection.
- Target: ZeroFox has observed LeakedData targeting at least six U.S.-based law firms within the past month, very likely indicating a deliberate, sustained campaign against the legal sector driven by the high sensitivity of client data held by law firms.
- Aim: Law firms very likely face greater pressure to pay ransoms because their data is highly valuable due to its confidentiality and sensitivity, while attorney-client privilege and reputational concerns can discourage public disclosure of breaches.
- Analyst note: U.S.-based law firms, particularly those with large corporate and financial services and political client bases, are very likely to remain targets for future LeakedData campaigns. However, LeakedData claims remain unverified.
DEEP AND DARK WEB INTELLIGENCE
Exploit user cbshy: Untested threat actor “cbshy” has advertised a crypto-paid service providing access to multiple AI models called “Uncensored[.]monster”. According to the threat actor, Uncensored[.]monster provides pay-as-you-go access to eight LLMs with safety and refusal mechanisms removed, including general-purpose, reasoning, and cybersecurity-focused models. The service allegedly starts at USD 1 in cryptocurrency.If legitimate, the models are likely to be integrated into automated cyberattack workflows to expand an attack's scope and capabilities.
VULNERABILITY AND EXPLOIT INTELLIGENCE
Google Chrome vulnerabilities Google has released Chrome 154, patching 108 vulnerabilities, including 11 critical- and 25 high-severity flaws involving memory corruption, buffer overflows, and use-after-free issues. Google has reported no known exploitation of the vulnerabilities in the wild.
Affected products: The affected versions are included here.
Tags: DIB, tlp:green