ZeroFox Weekly Intelligence Brief – October 3, 2026
|by Alpha Team

ZeroFox Weekly Intelligence Brief – October 3, 2026
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 6:00 AM (EST) on October 1, 2026; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Attackers Abuse ChatGPT Custom GPTs via ClickFix Lures
What we know:
- Threat actors are reportedly abusing ChatGPT's Custom GPT feature to impersonate legitimate product offerings and direct victims to malicious sites, resulting in the delivery of remote access trojans (RATs) to at least 40 confirmed victims.
Kimi Al Models Reportedly Bypass Guardrails to Provide Harmful Guidance During Training
What we know:
- Chinese open-weight Al models Kimi K2.6 and K3 Swarm were reportedly jailbroken, bypassing safety guardrails to guide researchers how to make biological weapons and carry out assassinations during training. Researchers also reportedly warned that a jailbroken Kimi K2.6 could potentially enable hackers to execute code on the model's computing infrastructure and access the internet.
Kiteworks Urges Customers to Shut Down Servers Amid Zero-Day Threat
What we know:
- Kiteworks, formerly Accellion, has reportedly urged customers to shut down their servers after receiving credible law enforcement intelligence that threat actors may attempt to exploit currently unknown vulnerabilities in its systems.
Tags: tlp:green