zerofox logo
Advisories

ZeroFox Daily Deep and Dark Web Intelligence - July 14, 2026

|by Alpha Team

banner image

ZeroFox Daily Deep and Dark Web Intelligence - July 14, 2026

Product Serial: D-2026-07-14a

TLP:CLEAR

Here is a curated list of critical incidents and compromised data observed in deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report for today here

Key Findings

  • Ransomware and Digital Extortion: Multiple extortion groups posted new leak-site entries, including DragonForce, INTERLOCK, TITAN, DOOMMAGEDDON, and CMD Organization.
  • Unauthorized Access Marketplace: Threat actors advertised network access for sale, including administrator-level web panel access purportedly to an unnamed France-based assurance company (DarkForums) and a SQL injection access auction against an unnamed U.S.-based file hosting service (Exploit).
  • **Vulnerability and Tooling Commercialization: **An actor advertised a zero-day exploit for Castles VEGA 3000 point-of-sale terminals on the Exploit forum (platovoplomo).
  • Vulnerability Disclosures: Two file-upload vulnerabilities in Joomla extensions were added to CISA, as widely exploited—Balbooa Forms (CVE-2026-56291) and JoomliC iCagenda, the latter enabling remote code execution (CVE-2026-48939).
  • Data Dissemination and Telemetry: Forums hosted several breach and data-sale claims referencing government and private-sector organizations, including a 1.2 GB dataset purportedly tied to the Pakistan Army and Air Force (Cyb3R_Shubh4M) and an auction for data claimed to belong to U.S. law firm Hastings and Hastings (Citrix_one_love). Separately, credential intelligence systems ingested over 1.7 billion combined compromised account (CAC) and botnet records between June 16 and July 13, 2026.

Tags: tlp:clear dark web vulnerability/exploit data breach threat actor