zerofox logo
Advisories

ZeroFox Daily Deep and Dark Web Intelligence - July 22, 2026

|by Alpha Team

banner image

ZeroFox Daily Deep and Dark Web Intelligence - July 22, 2026

Product Serial: D-2026-07-22a

TLP:CLEAR

Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report for today here

Key Findings

  • Ransomware and Digital Extortion: Multiple extortion groups, including Akira, Kairos, CMD Organization, and CoinbaseCartel, posted new leak site entries.
  • Unauthorized Access Marketplace: Actors advertised high-privilege network access to unnamed organizations across the real estate, education, software, and financial technology sectors on the Exploit forum—including auctioned RDWeb domain-user access (doZKey) and AnyDesk domain admin access (Big-Bro, Ritsu08).
  • Tooling Commercialization: Well-regarded threat actor "zerodayseller" advertised an alleged Windows Local Privilege Escalation zero-day affecting Windows 11 and Windows Server 2025.
  • Hacktivism: Pro-Palestinian group "313 Team" claimed a distributed denial-of-service (DDoS) attack against the OVHcloud login portal via its Telegram channel.
  • Data Dissemination and Telemetry: Threat actors advertised several breach and data sales on forums, including internal infrastructure mapping data allegedly tied to BlackRock. Separately, credential intelligence systems ingested over 1.3 billion combined compromised account credentials (CAC) and botnet records between June 24 and July 21, 2026.

Tags: tlp:clear dark web vulnerability/exploit data breach threat actor