ZeroFox Daily Deep and Dark Web Intelligence - July 31, 2026
|by Alpha Team

ZeroFox Daily Deep and Dark Web Intelligence - July 31, 2026
Product Serial: D-2026-07-31a
TLP:CLEAR
Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report for today here
Key Findings
- Ransomware and Digital Extortion: SECUROTROP, GLOBAL SECRET GROUP, The Gentlemen, and BlackNevas posted new leak site entries spanning energy, government, and logistics.
- Unauthorized Access Marketplace: Threat actors advertised on deep and dark web (DDW) forums high-privilege accesses (most notably, GitLab and CI/CD accesses) purportedly tied to an unnamed major UK bank, alongside SSH and domain-admin VPN/RDP accesses tied to unnamed manufacturing organizations in the United States and India.
- Vulnerability Disclosure: An unauthenticated remote code execution flaw in JetBrains TeamCity On-Premises (CVE-2026-63077).
- Emerging Extortion Infrastructure: A new ransomware leak site, "GAMMAX," came online with two entries already listed.
- Data Dissemination and Telemetry: Threat actors advertised several breach and data sale claims referencing government and private sector organizations, including data purportedly tied to the Hungarian State Treasury and Grand Est Automobiles. Separately, credential intelligence systems ingested over 1.4 billion combined compromised account credentials (CAC) and botnet records between July 3 and July 31, 2026.
Tags: tlp:clear, dark web, vulnerability/exploit, data breach, threat actor