ZeroFox Daily Intelligence Brief - July 22, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 22, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- South Korea's Diplomatic Academy Suffers Data Breach; Exposes User Data
- Authorities Dismantle Kratos Phishing-as-a-Service Platform
- New GPU Based Attack Technique Targeting Power Grids Discovered
South Korea's Diplomatic Academy Suffers Data Breach; Exposes User Data
What we know: A data breach at South Korea's Korea National Diplomatic Academy (KNDA) has leaked the personal information of over 6,000 current and former diplomats and government officials, including personnel stationed overseas.
Context: According to the breach notice, the leaked information includes the user ID, name, email, and encrypted password of the trainees in the Korea National Diplomatic Academy's online education system. Attackers reportedly exploited a previously unknown zero-day vulnerability and security misconfigurations in the academy's online education system.
Analyst note: The affected organization and victim profile likely suggest potential involvement of a nation-state actor, in particular North Korea. The stolen data is likely to enable mapping of South Korean diplomatic networks, identifying officials with access to specific government information, and more. Exposed individuals are also likely to be targeted in phishing and social engineering attacks.
Authorities Dismantle Kratos Phishing-as-a-Service Platform
What we know: German and U.S. authorities have dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform, arrested its developer in Indonesia, and seized more than 200 servers, rendering the service inoperable.
Context: The phishing toolkit enabled threat actors to create fake Microsoft authentication pages with convincing login forms to steal user credentials. Compromised Microsoft accounts were subsequently used for business email compromise (BEC), account takeover, data theft, and further phishing attacks.
Analyst note: The disruption is likely to temporarily reduce phishing activity associated with Kratos. The seized infrastructure is also likely to support ongoing investigations and help identify additional users of the platform.
New GPU Based Attack Technique Targeting Power Grids Discovered
Source: https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html
What we know: A new attack technique, called the “Bit2Watt”, has been discovered that enables cloud tenants to destabilize regional power grid infrastructure using standard GPU access without requiring software exploits or elevated privileges.
Context: Bit2Watt reportedly exploits the direct relationship between GPU compute intensity and power consumption, enabling an attacker to generate controlled power oscillations that propagate to the data center's upstream grid connection. A more sophisticated variant conceals this manipulation within a legitimate LLM training run blending malicious power modulation into normal workload noise.
Analyst note: As critical enterprises increasingly depend on shared AI data centers and renewable energy grids, a successful attack is likely to trigger regional service disruptions and cause hardware-level damage affecting interconnected service providers. Threat actors are likely to use this technique to conduct cyber-physical denial-of-service attacks.
DEEP AND DARK WEB INTELLIGENCE
Telegram user 313 Team: A pro-Palestinian hacktivist group, 313 Team, has claimed to have conducted a distributed denial-of-service (DDoS) attack against airbnb[.]com, the domain associated with Airbnb, a U.S.-based online marketplace for short-term lodging, experiences, and travel services.
THREAT ACTOR WATCH
JADEPUFFER: This AI-agent-driven threat actor, first documented in July 2026, is reportedly deploying ENCFORGE ransomware targeting AI infrastructure files across the host systems, including model weights, vector indexes, training datasets, and SafeTensors. The actor is still using the same initial access vector by exploiting CVE-2025-3248, a flaw in Langflow. Notably, when its preferred delivery route was blocked, JADEPUFFER iterated through six revised scripts in under six minutes to execute a Docker socket-based host breakout, reflecting highly adaptive, agentic operational behavior.
VULNERABILITY AND EXPLOIT INTELLIGENCE
LegacyHive vulnerability: An unofficial security patch is available for the “LegacyHive” vulnerability in Windows User Profile Service, an alleged zero-day flaw. The flaw enables a threat actor to escalate privileges on up-to-date Windows systems. A non-administrator user can modify the Classes registry hive and achieve automatic code execution when an administrator logs into a compromised system.
Affected products: Windows 10 2004 or later and Windows Server 2022 or later
Tags: DIB, tlp:green