zerofox logo
Advisories

ZeroFox Daily Deep and Dark Web Intelligence - August 13, 2026

|by Alpha Team

banner image

ZeroFox Daily Deep and Dark Web Intelligence - August 13, 2026

Product Serial: D-2026-08-13a

TLP:CLEAR

Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report for today here

Key Findings

  • Ransomware and Digital Extortion: Multiple threat actor groups posted new leak site entries, including SETTRA Ransomware, Storm Ransomware, and Dark Project, while Clop Ransomware disclosed 42 previously redacted entities alongside two new entiries.
  • Unauthorized Access Marketplace: Threat actors advertised VPN, RDWeb, and AnyDesk access allegedly tied to an unnamed U.S. energy, utilities and waste company, a law firm, and a Latin America-based state psychiatric hospital on deep and dark web (DDW) forums.
  • New Leak Site Emergence: Four new dark web leak sites identified operating under the names Ethics, MAJINAHANASHI, EMPERADOR, and Eclipse—several already listing initial victims.
  • Critical Infrastructure Attack Claim: Pro-Russian group "NoName057(16)" claimed unauthorized access to a SCADA system of a Ukraine-based water treatment facility.
  • Vulnerability Disclosures: New vulnerabilities were disclosed, including an authentication bypass in Microsoft SharePoint Server (CVE-2026-55040) and a directory traversal vulnerability in VMware vCenter Server (CVE-2026-59310).
  • Data Dissemination and Telemetry: Several alleged breached data sets were disseminated via PwnForums. Separately, credential intelligence systems ingested over 1.7 billion combined compromised account credentials (CAC) and botnet CAC between July 16 and August 12, 2026.

Tags: tlp:clear dark web vulnerability/exploit data breach threat actor