zerofox logo
Advisories

ZeroFox Daily Deep and Dark Web Intelligence - July 16, 2026

|by Alpha Team

banner image

ZeroFox Daily Deep and Dark Web Intelligence - July 16, 2026

Product Serial: D-2026-07-16a

TLP:CLEAR

Here is a curated list of critical incidents and compromised data observed in deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report for today here

Key Findings

  • Ransomware and Digital Extortion: Multiple extortion groups posted new leak-site entries, including ARCUS MEDIA, AiLock, NightSpire, Chaos, and CMD Organization.
  • Unauthorized Access Marketplace: Threat actors advertised network access auctions on the Exploit forum, including FortiGate admin access purportedly to an unnamed UAE-based retail company (Big-Bro) and administrator-level network access to an undisclosed cloud storage service (Deadsilence).
  • Vulnerability Disclosures: Several notable vulnerabilities were disclosed, including improper input validation in the Zoom Workplace client (CVE-2026-53412), a BitLocker security-feature bypass (CVE-2026-50661), code injection in the SonicWall SMA1000 management console (CVE-2026-15410), and hardcoded credentials in SAP Commerce Cloud (CVE-2026-44761).
  • Data Dissemination and Telemetry: Forums hosted several breach and data-sale claims referencing government and private-sector organizations, including an internal document purportedly tied to the SpaceX Starshield program (1XL) and data claimed to belong to Romania's national cadastre agency ANCPI, cross-posted across multiple forums (bytetobreach33). Separately, credential intelligence systems ingested over 1.8 billion combined compromised account (CAC) and botnet records between June 18 and July 15, 2026.

Tags: tlp:clear vulnerability/exploit data breach threat actordark web