zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - October 1, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - October 1, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Secure File-Transfer Provider FTAPI Hit by Ransomware Attack
  • Attackers Abuse ChatGPT Custom GPTs via ClickFix Lures
  • South African Air Traffic Control Targeted in Suspected Ransomware Attack

Secure File-Transfer Provider FTAPI Hit by Ransomware Attack

Source: https://cybernews.com/security/ftapi-eu-data-transfer-platform-data-breach/

What we know: The Gentlemen ransomware group has claimed to have targeted German secure file-transfer provider FTAPI. The company reportedly confirmed that attackers accessed an internally operated server at a local site and deployed ransomware, but said its customer platform and customer-exchanged data were not affected.

Context: Germany-based FTAPI provides solutions for secure data exchange services and is considered to be compliant with EU data security and privacy law GDPR. ZeroFox has observed that The Gentlemen carried out 92 attacks against entities mostly in the Europe-Russia region in September 2026. Separately, In May 2026, the Gentlemen reportedly suffered a breach after attackers leaked internal correspondence while the group claimed its core infrastructure remained unaffected.

Analyst note: FTAPI’s role in handling sensitive data for government, healthcare, and other organizations is likely to make it an attractive target for ransomware groups seeking high-value information or access to a trusted service provider. The compromised FTAPI server and connected services are likely to face operational disruption. Internal company data such as employee information, financial, administrative, and configuration details is likely to enable threat actors to manipulate systems and leverage data for phishing and credential attacks.

Attackers Abuse ChatGPT Custom GPTs via ClickFix Lures

Source: https://thehackernews.com/2026/09/attackers-abuse-chatgpt-custom-gpts-to.html

What we know: Threat actors are reportedly abusing ChatGPT's Custom GPT feature to impersonate legitimate product offerings and direct victims to malicious sites, resulting in the delivery of remote access trojans (RATs) to at least 40 confirmed victims.

Context: Attackers created a Custom GPT named "Plus 5.6," promoted via sponsored Google search results, which responds to user prompts with a fake service availability notice directing them to a malicious backup site. The site presents a fraudulent Cloudflare verification prompt that tricks victims into executing a malicious command, ultimately installing a RAT on their device. The RAT is reportedly capable of remote desktop access, camera and microphone capture, browser credential theft, and delivering additional malicious payloads.

Analyst note: By embedding the attack within a familiar, widely trusted service, threat actors almost certainly obfuscate their activity from traditional security tools. As AI tools become a routine part of daily work and personal life, they are very likely to become an increasingly common entry point for attacks targeting everyday users.

South African Air Traffic Control Targeted in Suspected Ransomware Attack

Source: https://www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control

What we know: South Africa’s state-owned air traffic control provider, Air Traffic and Navigation Services (ATNS), reportedly discovered malware commonly associated with the early stages of ransomware attacks. The malware was found in an operational technology (OT) network at Port Elizabeth Airport (FAPE). The incident may have involved data exfiltration to external IP addresses in China.

Context: Monitoring systems detected suspicious activity in OT environments supporting weather-related services to air traffic services. East London Airport (FAEL) may also have been affected.

Analyst note: Aviation will likely remain an attractive target for financially-motivated threat actors, as disruptions to flights and threat to passenger safety enable successful ransom negotiations under pressure.

DEEP AND DARK WEB INTELLIGENCE

Exploit user ikki: Untested threat actor "ikki" has advertised a dataset allegedly containing more than 400,000 institutional email contacts from organizations in the United Kingdom and Ireland on the predominantly Russian-language dark web forum Exploit. The dataset reportedly includes contacts from government agencies, public-sector organizations, schools, educational institutions, non-profits, and private companies. The exposed records allegedly contain school names, staff positions, and institutional email addresses.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2026-76504: This is an authentication-bypass vulnerability in the API session management of Cisco Catalyst SD-WAN Manager and is being actively exploited with attackers escalating to admin privileges. The vulnerability stems from improper URI encoding that enables attackers to bypass an authentication rule protecting a specific API endpoint. CISA has added this vulnerability to its Known Exploited Vulnerability catalog.

Affected products: Cisco Catalyst SD-WAN Manager regardless of system configuration

Tags: DIB, tlp:green