zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 23, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 23, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • CISA Warns of Iran-Linked Targeting of Critical Infrastructure
  • Australian Energy Company Investigates Potential Cyber Incident
  • Everest Ransomware Targets Swiss Rail via Compromised Supplier Platform

CISA Warns of Iran-Linked Targeting of Critical Infrastructure

Source: https://www.cisa.gov/news-events/news/cisa-fbi-epa-and-us-government-partners-update-warning-iran-affiliated-threat-actors-targeting

What we know: CISA has updated its advisory on Iran-affiliated threat to internet-connected operational technology (OT) devices by adding new guidance on detecting malicious changes in reusable code modules exploited within Rockwell Automation PLC programs.

Context: The advisory expands the manufacturer scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded/manufactured programmable logic controllers (PLCs). Threat actors are attempting to download malicious PLC project files and manipulate data on human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial losses.

Analyst note: Organizations operating critical infrastructure are likely to remain at elevated risk until publicly accessible OT assets are secured and cybersecurity best practices are implemented.

Australian Energy Company Investigates Potential Cyber Incident

Source: https://www.reuters.com/business/energy/australias-origin-energy-probes-potential-unauthorised-data-access-2026-07-22/

What we know: Australian energy company Origin Energy is investigating a potential cybersecurity incident involving unauthorized access to customer data. At the time of writing, the company confirmed that payment card and bank account information were not affected.

Context: An unidentified threat actor has reportedly claimed to have accessed two million customer records. The sample data reportedly contains 50 customer records containing personal information, including names, email addresses, phone numbers, home addresses, and billing history.

Analyst note: If the actor's claims are true, the alleged exposure of customer information is likely to facilitate phishing, social engineering, and identity theft attacks targeting affected individuals. Additionally, there is currently no indication that the alleged compromise is likely to directly enable additional network access, ransomware deployment, or operational disruption.

Everest Ransomware Targets Swiss Rail via Compromised Supplier Platform

Source: https://www.bleepingcomputer.com/news/security/swiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack/

What we know: Swiss rail vehicle manufacturer Stadler Rail has confirmed a cyberattack by the Everest ransomware group. The group breached a shared third-party supplier platform and demanded a ransom of CHF 10 million (approximately USD 12 million). Stadler has refused to pay the ransom and filed a criminal complaint.

Context: The group gained access to the platform through compromised login credentials. Stadler confirmed that only non-security relevant technical information belonging to a supplier was exfiltrated, and that the incident had no impact on its internal IT systems or global production operations.

Analyst note: If ransom is not paid, the Everest group will very likely publish the stolen data to reinforce the credibility of its extortion model. Other entities whose supply chain includes the breached third-party in this incident are likely to be impacted. Given the ransomware group’s history as initial access brokers (IAB), the stolen technical assets are likely to be resold on dark web forums, which could lead to further downstream supply chain risks.

DEEP AND DARK WEB INTELLIGENCE

DarkForums user urharmless: Untested threat actor "urharmless" has published alleged internal infrastructure mapping data associated with BlackRock, a U.S.-based multinational investment and asset management firm, on the DarkForums. The dataset allegedly includes hostnames, internal and external IPs, FQDNs, and VPN tunnel IPs spanning the company's development, UAT, production, disaster recovery (DR) environments, internal phone numbers and Amelia/IPsoft software versions. If the claim is legitimate, the exfiltrated data is very likely to enable network reconnaissance, infrastructure mapping, and targeted supply chain attacks.

DATA BREACHES INTELLIGENCE

Chick-fil-A discloses data breach: U.S. fast-food chain Chick-fil-A disclosed a data breach compromised a limited number of customer accounts. Threat actors reportedly used usernames and passwords exposed in previous breaches to carry out credential stuffing attacks. The company stated that payment card information was not exposed. Exposed data potentially includes names, email addresses, phone numbers, Chick-fil-A One membership details, and transaction history. Compromised accounts are likely to be targeted in follow-on phishing, credential stuffing, and identity fraud campaigns.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2026-48294: This is an already-patched vulnerability in the Adobe Acrobat Chrome extension that leads to a universal cross-site scripting (UXSS) flaw.It enables data theft from websites open in the browser, including web applications such as WhatsApp Web. The issue stems from missing security checks in the extension's internal messaging system, enabling an attacker-controlled webpage to remotely activate the extension's "Hermes" integration engine.

Affected products: Adobe Acrobat extension for Chrome, versions 26.5.2.1 and earlier

Tags: DIBtlp:green