zerofox logo
Advisories

ZeroFox Daily Deep and Dark Web Intelligence - July 23, 2026

|by Alpha Team

banner image

ZeroFox Daily Deep and Dark Web Intelligence - July 23, 2026

Product Serial: D-2026-07-23a

TLP:CLEAR

Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report for today here

Key Findings

  • Ransomware and Digital Extortion: Multiple digital extortion groups, including DragonForce, Everest, Nova, and CoinbaseCartel, posted new leak site entries.
  • Vulnerability and Tooling Commercialization: ZeroFox observed two alleged zero-day exploits for sale (Windows Local Privilege Escalation and Linux Remote Code Execution) on the Russian-language forums Exploit and XSS.
  • Vulnerability Disclosures: A local privilege escalation in Canonical snapd/snap-confine (CVE-2026-8933) and a universal cross-site scripting flaw in the Adobe Acrobat PDF extension for Chrome (CVE-2026-48294).
  • Data Dissemination and Telemetry: Threat actors advertised several data sale and breach claims, including flight records purportedly tied to El Al Israel Airlines and Turkish Airlines and shipping labels allegedly associated with UPS and FedEx, on deep and dark web (DDW) forums. Separately, credential intelligence systems ingested over 1.3 billion combined compromised account credentials (CAC) and botnet records between June 25 and July 22, 2026.

Tags: tlp:clear dark web vulnerability/exploit data breach threat actor