zerofox logo
Advisories

ZeroFox Daily Deep and Dark Web Intelligence - August 7, 2026

|by Alpha Team

banner image

ZeroFox Daily Deep and Dark Web Intelligence - August 7, 2026

Product Serial: D-2026-08-07a

TLP:CLEAR

Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report for today here

Key Findings

  • Ransomware and Digital Extortion: New entries posted on multiple leak sites, including INC Ransomware, Qilin Ransomware, OROVA Ransomware, and The Gentlemen Ransomware.
  • Unauthorized Access Marketplace: An actor auctioned RDWeb access purportedly to an undisclosed U.S.-based company on the Russian-language forum deep and dark web forum Exploit.
  • Vulnerability and Tooling Commercialization: An actor auctioned an alleged remote code execution exploit affecting an unnamed OpenCart plugin on Exploit.
  • Vulnerability Disclosures: Four CVEs were disclosed across widely deployed enterprise and open-source software, most notably an authentication bypass in Veeam Service Provider Console (CVE-2026-58073) and cross-tenant credential reuse in HashiCorp's terraform-mcp-server (CVE-2026-16498).
  • Emergent Leak Site Infrastructure: ZeroFox observed four new data leak and ransomware leak sites—Helix, L Group, Storm, and Barracuda—collectively listing roughly 40 claimed targets at time of reporting.
  • Data Dissemination and Telemetry: Threat actors posted several breach and data sale claims referencing construction, financial services, and payment-sector organizations, including data allegedly associated with Morgan Sindall Group and DEGIRO, alongside an advertised dataset purportedly containing PII on U.S.-based individuals. Separately, credential intelligence systems ingested over 1.1 billion combined compromised account credentials (CAC) and botnet records between July 10 and August 6, 2026.

Tags: tlp:clear dark web vulnerability/exploit data breach threat actor