zerofox logo
Advisories

ZeroFox Daily Deep and Dark Web Intelligence - August 18, 2026

|by Alpha Team

banner image

ZeroFox Daily Deep and Dark Web Intelligence - August 18, 2026

Product Serial: D-2026-08-18a

TLP:CLEAR

Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report for today here

Key Findings

  • Ransomware and Digital Extortion: Multiple threat actor groups posted new leak site entries, including BLACKWATER, Akira, LockBit 5.0, and CoinbaseCartel.
  • Unauthorized Access Marketplace: Threat actors advertised alleged network accesses to unnamed organizations, including SSH and FortiGate access to a U.S.-based company, RDWeb access to an Italy-based cloud and IT services company, and access to a GitHub project holding the source code of a mobile app with over 10 million Google Play downloads—all on the Russian-language deep and dark web (DDW) forum Exploit.
  • Vulnerability and Tooling Commercialization: Threat actor advertised an alleged Windows Local Privilege Escalation (LPE) zero-day exploit for sale on Exploit.
  • Data Dissemination and Telemetry: Forums hosted numerous breach and data sale claims referencing government and major private-sector organizations—including a 33 GB dataset and API keys purportedly tied to Stripe, the Republic Health Insurance Fund, and Tata Housing Development Company. Separately, credential intelligence systems ingested over 1.8 billion combined compromised account credentials (CAC) and botnet CAC during the July 21 to August 17, 2026 reporting period.

Tags: tlp:clear dark web vulnerability/exploit data breach threat actor