zerofox logo
Advisories

ZeroFox Daily Deep and Dark Web Intelligence - July 24, 2026

|by Alpha Team

banner image

ZeroFox Daily Deep and Dark Web Intelligence - July 24, 2026

Product Serial: D-2026-07-24a

TLP:CLEAR

Here is a curated list of critical incidents and compromised data observed in deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report for today here

Key Findings

  • Ransomware and Digital Extortion: Multiple extortion groups posted new leak site entries, including The Gentlemen (which listed roughly 30 new entries in this window), Qilin, Play, Chaos, and KRYBIT.
  • Unauthorized Access Marketplace: Actors advertised high-privilege access—network and RDP access with domain-administrator rights, plus VNC/HVNC access—to unnamed organizations in the legal-services, real-estate, and public-education sectors on Exploit and RehubCom.
  • Vulnerability Disclosures: Two notable CVEs were reported: a Linux kernel XFS local privilege-escalation race condition (CVE-2026-64600) and an authentication-bypass flaw in Check Point Security Management SmartConsole (CVE-2026-16232).
  • Hacktivism: Pro-Palestinian group "313 Team" claimed a DDoS operation against Microsoft 365, alleging worldwide disruption to Azure and SharePoint services.
  • Emerging Extortion Infrastructure: A new ransomware leak site, "DarkMatter," was observed via Tor hidden service with 15 mirrors, though it lists no entries at the time of reporting.
  • Data Dissemination and Telemetry: Forums hosted several breach and data sale claims referencing government and private-sector organizations, including data purportedly tied to the Saudi General Intelligence Presidency and to a U.S.-based LLM API firm, ModelsLab. Separately, credential intelligence systems ingested over 1.2 billion combined compromised account credentials (CAC) and botnet records between June 26 and July 23, 2026.

Tags: tlp:clear dark web vulnerability/exploit data breach threat actor