ZeroFox Daily Intelligence Brief - October 2, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - October 2, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Law Enforcement Disrupts KillSec, Seizes 110 TB of Stolen Data
- AI Agents Attempt Intrusions on Certain Government Sites
- Cryptocurrency Wallet Metamask Confirms Security Incident
Law Enforcement Disrupts KillSec, Seizes 110 TB of Stolen Data
What we know: Law enforcement Operation KillSwitch has disrupted the KillSec ransomware group by seizing its dark web data leak site and five servers, including its main server and servers used to store stolen data. KillSec was reportedly active since 2024 and allegedly exploited vulnerabilities and unsecured systems to steal data for extortion, while also using AI to build infrastructure and identify victims.
Context: The operation also seized approximately 110 TB of stolen data and targeted the group's alleged criminal proceeds, including cryptocurrency. The investigation began in 2025 and examined approximately 1,000 suspected attacks worldwide. Investigators have so far identified around 500 successful attacks, including at least 70 targeting organizations in Germany.
Analyst note: The arrests and seizure of KillSec’s infrastructure are likely to disrupt the group’s current operations, while seized systems and data can enable authorities to identify additional members, victims, and criminal proceeds. The group’s surviving affiliates are likely to attempt to regroup under new identities or infrastructure.
AI Agents Attempt Intrusions on Certain Government Sites
What we know: Autonomous AI agents have reportedly attempted to bypass website security controls on some government websites while performing data-retrieval tasks. This follows the recent OpenAI-linked breach of an Australian government health portal, marking another reported instance of autonomous AI agents targeting government portals this month.
Context: The incident forms part of broader AI-agent probing of government websites, involving high-volume requests, URL manipulation, disposable accounts, attempts to bypass anti-bot controls, filename guessing, and reuse of exposed credentials. No government systems were reportedly compromised at the time of writing. Separately, OpenAI has reportedly acknowledged unintended interactions between its agents and targeted government websites, while some of the broader activity has not been reportedly clearly attributed to OpenAI.
Analyst note: Threat actors are likely to exploit the demonstrated tendency of AI agents to autonomously escalate when access is restricted, manipulating them into conducting high-speed, automated reconnaissance. Threat actors are also likely to blend malicious probing attempts with legitimate automated traffic while shifting attribution onto AI service providers.
Cryptocurrency Wallet MetaMask Confirms Security Incident
Source: https://thehackernews.com/2026/10/metamask-security-incident-prompts-exit.html
What we know: Cryptocurrency wallet MetaMask has disclosed an ongoing security incident affecting part of its infrastructure, prompting the exit of affected Ethereum validators from its non-custodial staking operations as a precautionary measure. MetaMask has confirmed no evidence that user wallets or customer funds have been affected.
Context: The exits may incur foregone staking rewards and potential downtime penalties. MetaMask has not disclosed the nature or root cause of the incident, and the investigation and containment process remains ongoing.
Analyst note: A confirmed compromise of MetaMask's infrastructure is almost certainly of significant interest to financially motivated threat actors. Access to MetaMask's systems can likely expose user account data, transaction histories, and behavioral patterns that threat actors could use to craft highly targeted phishing attacks or impersonation attempts against individual users.
DEEP AND DARK WEB INTELLIGENCE
PwnForums user ShadowByt3S: Moderately credible threat actor "ShadowByt3S" has advertised alleged vulnerability scan results targeting an undisclosed New York University (NYU) subdomain on dark web forum PwnForums. The actor claims that the offering is a scan confirmation only and that exploitation remains the buyer's responsibility. The confirmed scan result is likely to lower the barrier for a motivated buyer to attempt to target NYU's infrastructure.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2026-104286 Fortinet has warned of this critical path traversal and NULL byte neutralization flaw that is reportedly being actively exploited in zero-day attacks. The vulnerability reportedly enables unauthenticated remote code execution or arbitrary file writes via specifically crafted HTTP or HTTPS requests. CISA has added this vulnerability to its Known Exploited Vulnerability catalog.
Affected products: FortiMail management interfaces running versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9
Tags: DIB, tlp:green