ZeroFox Daily Deep and Dark Web Intelligence - July 16, 2026
|by Alpha Team

ZeroFox Daily Deep and Dark Web Intelligence - July 16, 2026
Product Serial: D-2026-07-16a
TLP:CLEAR
Here is a curated list of critical incidents and compromised data observed in deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report for today here
Key Findings
- Ransomware and Digital Extortion: Multiple extortion groups posted new leak-site entries, including ARCUS MEDIA, AiLock, NightSpire, Chaos, and CMD Organization.
- Unauthorized Access Marketplace: Threat actors advertised network access auctions on the Exploit forum, including FortiGate admin access purportedly to an unnamed UAE-based retail company (Big-Bro) and administrator-level network access to an undisclosed cloud storage service (Deadsilence).
- Vulnerability Disclosures: Several notable vulnerabilities were disclosed, including improper input validation in the Zoom Workplace client (CVE-2026-53412), a BitLocker security-feature bypass (CVE-2026-50661), code injection in the SonicWall SMA1000 management console (CVE-2026-15410), and hardcoded credentials in SAP Commerce Cloud (CVE-2026-44761).
- Data Dissemination and Telemetry: Forums hosted several breach and data-sale claims referencing government and private-sector organizations, including an internal document purportedly tied to the SpaceX Starshield program (1XL) and data claimed to belong to Romania's national cadastre agency ANCPI, cross-posted across multiple forums (bytetobreach33). Separately, credential intelligence systems ingested over 1.8 billion combined compromised account (CAC) and botnet records between June 18 and July 15, 2026.
Tags: tlp:clear, vulnerability/exploit, data breach, threat actor, dark web