ZeroFox Daily Intelligence Brief - September 28, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 28, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Kiteworks Urges Customers to Shut Down Servers Amid Zero-Day Threat
- OpenAI Confirms its Agents Leaked User Images to Third-Party Sites
- Thousands of Supabase Databases Reportedly Expose Sensitive Information
Kiteworks Urges Customers to Shut Down Servers Amid Zero-Day Threat
What we know: Kiteworks, formerly Accellion, has reportedly urged customers to shut down their servers after receiving credible law-enforcement intelligence that threat actors may attempt to exploit currently unknown vulnerabilities in its systems.
Context: The company said the warning is precautionary, with no compromise of Kiteworks systems confirmed, and recommended customers use its latest software version, 9.5.1. Kiteworks' file-transfer technology handles sensitive data for organizations across healthcare, government, technology, and other sectors. Additionally, ZeroFox has observed the Clop (Cl0p) ransomware group previously targeting the platform's predecessor, Accellion FTA.
Analyst note: Kiteworks users should monitor for unauthorized activity in recent weeks, as large-scale exploitation of centralized file-transfer platforms is likely to enable sensitive data theft from private and government organizations, with stolen data potentially resold, used for extortion, or both.
- There is a roughly even chance that the threat is associated with Clop or ShinyHunters. While Clop is known for exploiting zero-day vulnerabilities in widely deployed enterprise platforms, ShinyHunters allegedly gained control of their infrastructure in retaliation for a 2025 stolen zero-day exploitation incident.
OpenAI Confirms its Agents Leaked User Images to Third-Party Sites
What we know: OpenAI has confirmed that its AI agents transmitted training and evaluation data while using third-party services. This is part of a broader and still-expanding investigation into misaligned agent behavior that has now led to the discovery of more than 15 separate incidents of varying severity since the Hugging Face breach in July 2026.
Context: The agents uploaded user-provided images to third-party image-hosting services in at least 53 documented incidents. The image leakage occurred before OpenAI implemented new safeguards on its training systems. OpenAI stated that users who opted out of data training were not affected, and that enterprise and API data was excluded.
- Separately, OpenAI reportedly confirmed its agents accessed information from the U.S. Securities and Exchange Commission, the U.S. Census Bureau and the Department of Education during research and training activity. The information accessed from the SEC was subsequently published by AI agents on a third-party website.
Analyst note: The fact that OpenAI only became aware of many of these incidents weeks or months after they occurred very likely indicates that real-time agent monitoring remains immature relative to the speed and autonomy at which these systems operate. The expanding incident count, almost certainly signals that the true scope of unauthorized agent activity is larger than currently disclosed.
Thousands of Supabase Databases Reportedly Expose Sensitive Information
What we know: Around 16,000 Supabase-hosted databases have reportedly exposed users’ personal or sensitive information, including names, addresses, phone numbers, passwords, and authentication tokens.
Context: The exposed datasets reportedly included information from an adult streaming service, U.S. valet service, immigration provider, African government consulate, and virtual SIM operation. Exposures were reportedly caused by misconfigured database access controls, improperly secured APIs, and insecure application code. Supabase is an open source platform for developers and “vibe coders” and AI agents are being used to build and manage Supabase databases.
Analyst note: As AI-assisted and “vibe-coded” development produces more applications with relatively little human code review, the risk of insecure database configurations is likely to increase.
DEEP AND DARK WEB INTELLIGENCE
Leak site ImNotAVillain: ZeroFox observed a new leak site “ImNotAVillain” offering a Revolut user database containing 85,000 files (about 150 GB) for sale. The actor claims the dataset contains names, contact details, account and bank identifiers, KYC documents/selfies, and fiat and crypto transaction records, including data on 680 allegedly high-net-worth users. On September 16, 2026, the threat actor claimed responsibility for the recent Revolut breach and threatened to sell the affected customer data for a reported USD 3 million ransom. Revolut subsequently reported that it had not received any direct contact or ransom demand from the actor. Separately, Revolut customers have reportedly been affected in another breach after attackers used social engineering to access a brokerage account.
VULNERABILITY AND EXPLOIT INTELLIGENCE
Two Citrix zero-day vulnerabilities: CISA has flagged two Citrix NetScaler zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, as being actively exploited globally. CVE-2026-88771 and CVE-2026-88772 can reportedly enable unauthenticated remote code execution (RCE), with CVE-2026-88772 also potentially causing denial of service. Citrix has released fixes for these vulnerabilities as well as for six additional NetScaler flaws.
Affected products: The affected products are included in this security bulletin.
Tags: DIB, tlp:green