zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - September 30, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - September 30, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - Emerging Threat Actor Targets Data Backups
  • French Security Agency Releases Report on Tax Agency Cyberattack
  • Kimi AI Models Reportedly Bypass Guardrails to Provide Harmful Guidance During Training

ZeroFox Intelligence Flash Report - Emerging Threat Actor Targets Data Backups

Source: https://www.zerofox.com/advisories/42336/

What we know: ZeroFox has observed a new data leak site attributed to the threat actor "n0n," claiming over a dozen victims on the Tor-hosted site. During its short operational life, n0n has claimed attacks across nearly all business sectors, with technology and professional services combined accounting for 46 percent of its targeting activity.

Context: What sets n0n apart from other recently launched threat collectives is its threat to encrypt or delete data backups. In recent months, ZeroFox has reported on an increase in the number of ransomware and digital extortion (R&DE) incidents eschewing the encryption model commonly seen in traditional ransomware attacks in favor of encryption-free data extortion. The combination of improved data backups and reduced ransom payments has likely created a trajectory in the R&DE landscape that trends toward less encryption and more data extortion.

Analyst note: With a sharp reduction in paid ransoms over the past several years, threat actors will very likely continue to deploy new techniques in an effort to increase profits and decrease reliance on expensive infrastructure. Further tactical experiments will almost certainly continue over the next six to 12 months.

French Security Agency Releases Report on Tax Agency Cyberattack

Source: https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html

What we know: The French Cybersecurity Agency has released a report detailing the malicious activity targeting the systems of the French public administration directorate for Finance (DGFiP) between May and August 2026. The report also mentions a separate initial-access path used to access DGFiP’s cadastral data system allegedly affecting 2 million French people.

Context: Threat actors reportedly compromised infrastructure belonging to the Ministry of National Education and laterally moved to gain access to DGFiP's ADER portal. The Education Ministry was responding to an incident, when attackers attempted to move laterally to the Interministerial State Network (RIE) connecting other government entities, including DGFiP. Meanwhile, ZeroFox had observed threat actor “ZeroBytes” advertising datasets associated with the French Ministry of National Education, General Directorate of Public Finances and its official portal that included DGFiP’s SPDC cadastral data, in August 2026.

Analyst note: ZeroFox has observed multiple threat actors targeting French government entities, including Tchap, the French messaging app for government employees, likely indicating a broader security exposure across government infrastructure or along its supply chain, potentially stemming from recurring vulnerabilities or gaps in security controls.

Kimi AI Models Reportedly Bypass Guardrails to Provide Harmful Guidance During Training

Source: https://www.bbc.com/news/articles/cmrergq3j7lgo

What we know: Chinese open-weight AI models, Kimi K2.6 and K3 Swarm, were reportedly jailbroken, bypassing safety guardrails to guide researchers how to make biological weapons and carry out assassinations during training. Researchers also reportedly warned that jailbroken Kimi K2.6 could potentially enable hackers to execute code on the model’s computing infrastructure and access the internet.

Context: Jailbreaking involves using crafted instructions to bypass an AI model’s safety guardrails and elicit restricted or harmful responses. Researchers did not ascertain whether the models’ biological-weapon or assassination guidance was actionable. Separately, Anthropic reported identifying and disrupting attempts to misuse one of its AI models for malicious activities that could support biological weapons development.

Analyst note: Given that Kimi is an open-weight model, its trained weights can be downloaded and deployed independently of its developer’s infrastructure. This can likely enable users to modify the model’s deployment and safety controls, making provider-enforced safeguards less effective when the model is run independently.

DEEP AND DARK WEB INTELLIGENCE

ULOSE leak site: A newly observed dark web data leak site operating under the name “ULOSE” was observed claiming five South Korea-based entities, across almost all business sectors, on September 25, 2026. The claimed entities include healthcare and pharmaceutical company Handok and aerospace manufacturer HIZE Aero Co. among others.. At the time of writing, none of the entities have publicly confirmed a recent compromise. In the past month, ZeroFox observed at least 23 instances of threat actors claiming access to South Korean entities, with manufacturing being the most targeted sector and threat actor “ULOSE” accounting for the largest number of attacks.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Authentication vulnerability in Titan analytics service: An authentication vulnerability in Titan analytics service reportedly enabled a researcher to bypass some signature verification, impersonate an administrator, and execute SQL queries against the service. The environment reportedly contained an estimated 17.3 trillion stored rows across 17 analytics databases, although the researcher reportedly said they did not access customer data or personal information.

Affected products: Titan internal analytics service/API

Windows Defender exploit: Well regarded threat actor QatarRat has advertised a Windows Defender update-pipeline denial of service (DoS) exploit for USD 20,000 on a dark web forum. The actor claims that it can freeze malware-signature updates without administrative privileges while bypassing Tamper Protection. The actor also claimed the exploit can prevent recovery by locking MRT[.]exe, potentially leaving Defender operational-looking but unable to receive updated malware signatures.

Affected products: Windows Defender (unspecified versions)

Tags: DIB, tlp:green