zerofox logo
Advisories

ZeroFox Daily Deep and Dark Web Intelligence - August 11, 2026

|by Alpha Team

banner image

ZeroFox Daily Deep and Dark Web Intelligence - August 11, 2026

Product Serial: D-2026-08-11a

TLP:CLEAR

Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report for today here

Key Findings

*Ransomware and Digital Extortion: Multiple threat groups posted new leak site entries, including Helix, Play Ransomware, LeakedData, and The Gentlemen. *Unauthorized Access Marketplace: Threat actors advertised network accesses for multiple targets including, VPN, RDWeb, and Fortinet VPN bundle purportedly tied to an Asia-based telecommunications company, alongside an alleged DoorDash and T-Mobile insider access service, on deep and dark web forums. *Vulnerability and Tooling Commercialization: Actors advertised an alleged pre-authentication SSRF zero-day exploit targeting FortiGate 8.0.0 vm64 and a phishing and credential-stealing tool called "Phishium," both on Exploit. *Data Dissemination and Telemetry: Threat actor hosted several data sale claims referencing government and private-sector entities, including databases purportedly tied to the Ministry of Defence of the Republic of Bulgaria and the Population and Immigration Authority of Israel, alongside additional breach data sets. Separately, credential intelligence systems ingested over 1.5 billion combined compromised account credentials (CAC) and botnet records between July 14 and August 10, 2026.

Tags: tlp:clear dark web vulnerability/exploit data breach threat actor