ZeroFox Daily Deep and Dark Web Intelligence - July 22, 2026
|by Alpha Team

ZeroFox Daily Deep and Dark Web Intelligence - July 22, 2026
Product Serial: D-2026-07-22a
TLP:CLEAR
Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report for today here
Key Findings
- Ransomware and Digital Extortion: Multiple extortion groups, including Akira, Kairos, CMD Organization, and CoinbaseCartel, posted new leak site entries.
- Unauthorized Access Marketplace: Actors advertised high-privilege network access to unnamed organizations across the real estate, education, software, and financial technology sectors on the Exploit forum—including auctioned RDWeb domain-user access (doZKey) and AnyDesk domain admin access (Big-Bro, Ritsu08).
- Tooling Commercialization: Well-regarded threat actor "zerodayseller" advertised an alleged Windows Local Privilege Escalation zero-day affecting Windows 11 and Windows Server 2025.
- Hacktivism: Pro-Palestinian group "313 Team" claimed a distributed denial-of-service (DDoS) attack against the OVHcloud login portal via its Telegram channel.
- Data Dissemination and Telemetry: Threat actors advertised several breach and data sales on forums, including internal infrastructure mapping data allegedly tied to BlackRock. Separately, credential intelligence systems ingested over 1.3 billion combined compromised account credentials (CAC) and botnet records between June 24 and July 21, 2026.
Tags: tlp:clear, dark web, vulnerability/exploit, data breach, threat actor