zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - September 25, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - September 25, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Threat Actor Claims Access to Saudi Hotel Management Systems
  • Crypto Exchange Bitget Confirms USD 351.6 Million Theft
  • U.S. Public Health Agency’s GitHub App Key Reportedly Exposed for 17 Months

Threat Actor Claims Access to Saudi Hotel Management Systems

Source: https://cloud.zerofox.com/intelligence_new/advanced_dark_web/111620

What we know: Moderately credible threat actor “DDEEAALLEERR” has claimed access to Property Management Systems (PMS) platforms used by the "largest" hotel organizations in Saudi Arabia and says the associated databases contain more than 700,000 bookings on Russian-language dark web forum Exploit.

Context: The dataset also includes bookings from hotels in Oman, Qatar, and the United Arab Emirates (UAE). The actor claims some access levels allow booking modifications, sending emails from legitimate hotel domains, changing payment gateway APIs, and modifying hotel websites. The listing follows previous DDEEAALLEERR activity targeting Saudi hotel and travel-management systems, indicating a continued focus on hospitality infrastructure.

Analyst note: In the backdrop of the ongoing conflict in the Middle East, the alleged access likely creates physical-security and intelligence risks affecting U.S. military personnel, government officials, contractors, or other high-profile individuals in the region, as hotel reservation data could expose guests' identities, travel dates, and locations to hostile actors.

  • According to a report, U.S. troops were relocated to civilian spaces, including hotels and offices across the Middle East, as Iranian attacks damaged military bases.
  • Additionally, financially motivated actors could leverage the alleged PMS access to redirect hotel payments and manipulate bookings for fraud.

Crypto Exchange Bitget Confirms USD 351.6 Million Theft

Source: https://hackread.com/bitget-hack-suspects-north-korea-lazarus-group/

What we know: Major crypto exchange Bitget has confirmed unauthorized transfers affecting a portion of its hot wallet and warm wallet layers that resulted in unauthorized transfers of approximately USD 351.6 million. This is reportedly the largest crypto breach in 2026 in terms of loss.

Context: Bitget attributes the attack to North Korea's state-backed Lazarus Group (see threat actor profile) based on on-chain transfer signatures and IP behavioral patterns. Threat actors compromised a critical backend administrative system within the wallet infrastructure to exfiltrate funds, bypassing cold wallet layers and avoiding direct private key theft. Bitget has temporarily suspended withdrawals, notified law enforcement, and engaged on-chain security firms to trace the stolen assets.

Analyst note: DPRK-linked groups like Lazarus have a history of targeting crypto exchange firms, the primary motive likely being to support North Korea’s heavily sanctioned economy, which struggles under international financial restrictions. Threat actors are likely to monitor social media for customer complaints and downstream entities where they can impersonate customer support with fake withdrawal restoration lures and attempt phishing using AI for customization and research. Lazarus group has historically launched follow-on supply chain attacks which if remains undetected can lead to further downstream risk and endpoint exposures.

U.S. Public Health Agency’s GitHub App Key Reportedly Exposed for 17 Months

Source: https://cybernews.com/security/leaked-github-key-cdc-health-agency-code-exposed-poisoning/

What we know: A private GitHub App key of Centers for Disease Control and Prevention (CDC) was reportedly left exposed between April 2025 and September 18, 2026, with write access to CDC-linked repositories and potential access to one of its cloud computing environments.

Context: The leaked CDC key has reportedly not been linked to any confirmed attacker activity or breach. The exposure is part of a broader GitHub App key-management issue identified by researchers, who found that 474 of 4,802 leaked GitHub App keys remained valid, including more than 200 with repository write access and 44 with organization-admin privileges.

Analyst note: Although there is no evidence of misuse, the prolonged validity of the exposed credential is likely to have increased the window in which an actor could have discovered and retained it for later use without immediately triggering detectable activity. Future likely impact can include a threat actor misusing the key's write permissions to tamper with code or workflow, creating a supply-chain risk.

THREAT ACTOR WATCH

ShinyHunters: On September 24, ZeroFox observed that extortion group ShinyHunters has taken down the previous post claiming FBI breach and a new post claims that the group has reached a stated “goal” while reiterating the five day deadline still holds.

  • Meanwhile, FBI has confirmed it is investigating claims of a compromise involving FBIJobs[.]gov and employee PII, but has not determined whether the breach originated with the FBI or a third-party provider.

DEEP AND DARK WEB INTELLIGENCE

PwnForums user Jaded: Well-reputed threat actor "Jaded" has leaked data allegedly associated with Horizane Santé, a France-based family-owned parapharmaceutical company, on the predominantly English-language dark web forum PwnForums. The same leak was also published by Jaded and several other threat actors across DarkForums, LeakForum, BreachForums (breached[.]st), Spear, and DarkNet Army. The compromised data allegedly includes 8,864 active customer records and bcrypt-hashed passwords, with exposed fields allegedly including identifiers, profile IDs, first and last names, email addresses, account status, and last generated passwords.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Tor network vulnerabilities The Tor Project has released emergency fixes for various flaws, including 10 tracked vulnerabilities. The flaws include a possible memory corruption issue that could crash or potentially allow attackers to take control of relays, anonymity flaws that could link browsing activity across sessions, an onion-service flaw that could enable denial-of-service attacks, and a use-after-free bug that could crash Tor connections.

Affected products: Tor across the entire network: relays, clients, and onion services

Tags: DIB, tlp:green