ZeroFox Daily Intelligence Brief - September 29, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 29, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Dark Web User Claims to Sell Exploits Used in FBI Hack by ShinyHunters
- ZeroFox Intelligence Flash Report - Buyer Seeks Baltic Access on Dark Web Amid Hybrid War Surge
- Japan's Keio Confirms Ransomware Attack Disrupted Business Systems
Dark Web User Claims to Sell Exploits Used in FBI Hack by ShinyHunters
Source: https://cloud.zerofox.com/intelligence_new/advanced_dark_web/111786
What we know: Following the alleged FBI jobs portal hack by ShinyHunters, ZeroFox observed a dark web forum user also named “ShinyHunters” advertising a pre-authentication remote code execution (RCE) exploit allegedly associated with Oracle PeopleSoft, along with an accompanying web application firewall bypass (WAF). The user refused to provide samples or test-runs for the exploits. Notably, these vulnerabilities were reported to be exploited by ShinyHunters in a cyberattack campaign.
Context: Separately, the original ShinyHunters group has reportedly said it never intended to publish or sell the FBI data it claims to have obtained, describing its one-week demand for the FBI to correct or remove disputed statements about the group as a “marketing campaign.” Furthermore, the extortion group is suspected of trying to implicate a former member of the group in its FBI hack by displaying the member’s alias and signature artwork on the compromised portal, as Dutch authorities reportedly arrested the individual in a separate cyberattack case.
Analyst note: ZeroFox assesses that the BreachForums user “ShinyHunters” is very likely impersonating the original extortion group as their recent activity has largely corresponded with announcements made directly on its leak site rather than posts on dark web forums. BreachForums also has several iterations following the seizure of the original portal, with forum owners likely manipulating their reputation and history on the forum. The advertisement is therefore likely opportunistic, leveraging publicity surrounding the FBI hack while attempting to sell fraudulent exploits or facilitate financial theft.
- Meanwhile, the original ShinyHunters group is likely attempting to obfuscate attribution of affiliates behind the FBI hack by using well-known symbols of former or inactive members. They are also likely trying to minimise legal consequences by stating that they don’t intend to leak FBI data, fearing law enforcement investigation.
ZeroFox Intelligence Flash Report - Buyer Seeks Baltic Access on Dark Web Amid Hybrid War Surge
Source: https://www.zerofox.com/advisories/42308/
What we know: Relatively newly emerged threat actor “root_zero” has posted on the Russian-language dark-web forum Exploit seeking to buy any type of network access in the Baltic states—Estonia, Latvia, or Lithuania. The actor did not specify a target organization, access type, or intended use. ZeroFox subsequently identified an identical post from root_zero on T1erOne, a more selective Russian-language forum.
Context: The actor registered on Exploit on July 20, 2026, and had no previous posts, making their capability and motivation difficult to establish. The post comes amid a broader increase in suspected Russian-linked hybrid activity in the Baltics and Eastern Europe, including drone incursions, suspected arson, and other incidents targeting defense and dual-use infrastructure.
Analyst note: Root_zero’s focus on the Baltic states likely indicates a geopolitical objective, given the region’s role in supporting Ukraine and its exposure to suspected Russian hybrid operations. If the requested access is intended for intelligence collection or disruptive activity, it is likely to complement broader efforts to pressure European governments and weaken support for Ukraine.
Japan's Keio Confirms Ransomware Attack Disrupted Business Systems
What we know: Keio Corporation, a major private railway and hospitality operator in Japan, confirmed a ransomware attack on its group servers on September 26, 2026, disrupting business systems across several group companies. Railway operations remain unaffected, while the company investigates potential data theft.
Context: The company shut down its network to prevent further damage. Disruptions affected hospitality and retail operations, including hotel reservations, customer inquiries, and payment systems at some stores, not train operations. Separately, Tokyo Metro disclosed unauthorized access exposing 59,000 member email addresses over the same weekend; a link between the two incidents remains unconfirmed.
Analyst note: The concentration of impact on business systems rather than railway operations suggests the attackers likely gained access to Keio’s corporate IT environment without reaching its core rail systems. The separate Tokyo Metro incident may warrant monitoring for additional targeting of Japanese transport operators.
DEEP AND DARK WEB INTELLIGENCE
Exploit user BigCash: An untested threat actor "BigCash" has advertised data allegedly from Medicare and Medicaid patient records, exfiltrated from an unnamed Kansas clinic, on dark web forum Exploit. The actor claims the compromised data includes personally identifiable information (PII)—such as names, driver's licenses, Medicare/Medicaid IDs, and photos of Medicare cards—alongside medical records including physician notes, orders, procedure histories, and diagnostic imaging (X-rays and head scans). Separately, the District of Columbia Department of Health Care Finance (DHCF) discovered in July that a web misconfiguration exposed nearly 400,000 Medicaid beneficiaries. The exposed dataset included Medicaid IDs, provider names, dates of birth, race, gender, ethnicity, and ward, and no Social Security numbers, names, or financial information were compromised.
- Medicaid data and other government information is likely to be leveraged for surveillance or high-targeted attacks. Threat actors are likely to further leverage the data for insurance fraud, phishing, and social engineering attacks.
BreachForums user sydneysweeneywhy: An untested threat actor "sydneysweeneywhy" has advertised alleged insider access and an active vulnerability impacting Anthropic's infrastructure and services on dark web forum BreachForums. The actor claims that the insider access enables extraction of customer and employee credentials, visibility into sensitive internal information, and access to unreleased AI training models associated with Claude. The actor maintains a low reputation score on the forum, and explicitly refused to provide preliminary samples or test runs prior to purchase, very likely indicating a scam or exaggerated claims.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2026-86950: This is an out-of-bounds write vulnerability within the CoreGraphics rendering framework in Apple products. The flaw enables an attacker to execute code arbitrarily, by processing a maliciously crafted file. Apple has issued emergency security updates to address this vulnerability.
Affected products: Versions prior to iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1, macOS Sequoia 15.8.1
Threat actor advertises MariaDB zero-day vulnerability and exploit: A moderately credible threat actor "Spaniard" has advertised an alleged unpatched zero-day vulnerability and exploit targeting an open-source relational database management system MariaDB on dark web forum PwnForums. The claim remains unverified as no proof-of-concept, technical samples, or demonstration were provided in the forum listing. However, if validated, attackers are likely to leverage this capability to exfiltrate sensitive data, map underlying schemas, and chain the flaw with secondary execution bugs for wider environment compromise.
Affected products: MariaDB
Tags: DIB, tlp:green