ZeroFox Weekly Intelligence Brief – July 25, 2026
|by Alpha Team

ZeroFox Weekly Intelligence Brief – July 25, 2026
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the threat landscape, including digital, cyber, and physical threats. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 6:00 AM (EST) on July 23, 2026; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Autonomous AI Agent Breaches Hugging Face
What we know:
- Artificial intelligence (AI) model repository Hugging Face has disclosed that its production infrastructure was compromised by an autonomous AI agent.
- The agent reportedly gained unauthorized access to some internal data sets and service credentials before moving laterally across internal clusters.
- OpenAI later confirmed the AI agent was part of an internal cyber capability evaluation using GPT-5.6 Sol and a more advanced pre-release model with reduced safety refusals.
- The models reportedly escaped the isolated research environment, exploited a zero-day vulnerability, gained internet access, and compromised Hugging Face's infrastructure to access evaluation-related data.
CISA Warns of Iran-Linked Targeting of Critical Infrastructure
What we know:
- The Cybersecurity and Infrastructure Security Agency (CISA) has updated its advisory on Iran-affiliated threats to internet-connected operational technology (OT) devices and added new guidance on detecting malicious changes in reusable code modules exploited within Rockwell Automation programmable logic controller (PLC) programs.
New GPU-Based Attack Technique Targeting Power Grids Discovered
What we know:
- A new attack technique, called the “Bit2Watt,” has been discovered to enable cloud tenants to destabilize regional power grid infrastructure using standard graphics processing unit (GPU) access without software exploits or elevated privileges.
Tags: tlp:green