ZeroFox Daily Deep and Dark Web Intelligence - August 7, 2026
|by Alpha Team

ZeroFox Daily Deep and Dark Web Intelligence - August 7, 2026
Product Serial: D-2026-08-07a
TLP:CLEAR
Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report for today here
Key Findings
- Ransomware and Digital Extortion: New entries posted on multiple leak sites, including INC Ransomware, Qilin Ransomware, OROVA Ransomware, and The Gentlemen Ransomware.
- Unauthorized Access Marketplace: An actor auctioned RDWeb access purportedly to an undisclosed U.S.-based company on the Russian-language forum deep and dark web forum Exploit.
- Vulnerability and Tooling Commercialization: An actor auctioned an alleged remote code execution exploit affecting an unnamed OpenCart plugin on Exploit.
- Vulnerability Disclosures: Four CVEs were disclosed across widely deployed enterprise and open-source software, most notably an authentication bypass in Veeam Service Provider Console (CVE-2026-58073) and cross-tenant credential reuse in HashiCorp's terraform-mcp-server (CVE-2026-16498).
- Emergent Leak Site Infrastructure: ZeroFox observed four new data leak and ransomware leak sites—Helix, L Group, Storm, and Barracuda—collectively listing roughly 40 claimed targets at time of reporting.
- Data Dissemination and Telemetry: Threat actors posted several breach and data sale claims referencing construction, financial services, and payment-sector organizations, including data allegedly associated with Morgan Sindall Group and DEGIRO, alongside an advertised dataset purportedly containing PII on U.S.-based individuals. Separately, credential intelligence systems ingested over 1.1 billion combined compromised account credentials (CAC) and botnet records between July 10 and August 6, 2026.
Tags: tlp:clear, dark web, vulnerability/exploit, data breach, threat actor