zerofox logo
Advisories

ZeroFox Daily Deep and Dark Web Intelligence - July 31, 2026

|by Alpha Team

banner image

ZeroFox Daily Deep and Dark Web Intelligence - July 31, 2026

Product Serial: D-2026-07-31a

TLP:CLEAR

Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report for today here

Key Findings

  • Ransomware and Digital Extortion: SECUROTROP, GLOBAL SECRET GROUP, The Gentlemen, and BlackNevas posted new leak site entries spanning energy, government, and logistics.
  • Unauthorized Access Marketplace: Threat actors advertised on deep and dark web (DDW) forums high-privilege accesses (most notably, GitLab and CI/CD accesses) purportedly tied to an unnamed major UK bank, alongside SSH and domain-admin VPN/RDP accesses tied to unnamed manufacturing organizations in the United States and India.
  • Vulnerability Disclosure: An unauthenticated remote code execution flaw in JetBrains TeamCity On-Premises (CVE-2026-63077).
  • Emerging Extortion Infrastructure: A new ransomware leak site, "GAMMAX," came online with two entries already listed.
  • Data Dissemination and Telemetry: Threat actors advertised several breach and data sale claims referencing government and private sector organizations, including data purportedly tied to the Hungarian State Treasury and Grand Est Automobiles. Separately, credential intelligence systems ingested over 1.4 billion combined compromised account credentials (CAC) and botnet records between July 3 and July 31, 2026.

Tags: tlp:clear dark web vulnerability/exploit data breach threat actor