ZeroFox Daily Deep and Dark Web Intelligence - July 23, 2026
|by Alpha Team

ZeroFox Daily Deep and Dark Web Intelligence - July 23, 2026
Product Serial: D-2026-07-23a
TLP:CLEAR
Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report for today here
Key Findings
- Ransomware and Digital Extortion: Multiple digital extortion groups, including DragonForce, Everest, Nova, and CoinbaseCartel, posted new leak site entries.
- Vulnerability and Tooling Commercialization: ZeroFox observed two alleged zero-day exploits for sale (Windows Local Privilege Escalation and Linux Remote Code Execution) on the Russian-language forums Exploit and XSS.
- Vulnerability Disclosures: A local privilege escalation in Canonical snapd/snap-confine (CVE-2026-8933) and a universal cross-site scripting flaw in the Adobe Acrobat PDF extension for Chrome (CVE-2026-48294).
- Data Dissemination and Telemetry: Threat actors advertised several data sale and breach claims, including flight records purportedly tied to El Al Israel Airlines and Turkish Airlines and shipping labels allegedly associated with UPS and FedEx, on deep and dark web (DDW) forums. Separately, credential intelligence systems ingested over 1.3 billion combined compromised account credentials (CAC) and botnet records between June 25 and July 22, 2026.
Tags: tlp:clear, dark web, vulnerability/exploit, data breach, threat actor