ZeroFox Weekly Intelligence Brief – September 26, 2026
|by Alpha Team

ZeroFox Weekly Intelligence Brief – September 26, 2026
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 6:00 AM (EST) on September 24, 2026; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
OpenAI Agent Breaches Australian Government Health Portal
What we know:
- Australian Prime Minister Anthony Albanese revealed that an OpenAI artificial intelligence (AI) agent breached a government health statistics portal in June 2026.
- The agent also gained unauthorized access to files, marking the first publicly reported instance of an AI agent hacking a government website.
LA Freeway Sign Compromised to Promote Dissident Doxxing Site
What we know:
- A portable electronic freeway message sign near Westwood, Los Angeles, was reportedly compromised and used to display the URL of the Goorkan website, which publishes the names, photographs, and personal information of Iranian dissidents.
- The unauthorized message was reportedly visible for about a week before being removed.
Gemini AI Model Reportedly Hacked Three Companies During Testing
What we know:
- Gemini AI model reportedly hacked three companies in May 2026 during a cybersecurity evaluation, joining similar incidents involving OpenAI and Anthropic models that breached external infrastructure during evaluation.
Tags: tlp:green