ZeroFox Daily Deep and Dark Web Intelligence - August 18, 2026
|by Alpha Team

ZeroFox Daily Deep and Dark Web Intelligence - August 18, 2026
Product Serial: D-2026-08-18a
TLP:CLEAR
Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report for today here
Key Findings
- Ransomware and Digital Extortion: Multiple threat actor groups posted new leak site entries, including BLACKWATER, Akira, LockBit 5.0, and CoinbaseCartel.
- Unauthorized Access Marketplace: Threat actors advertised alleged network accesses to unnamed organizations, including SSH and FortiGate access to a U.S.-based company, RDWeb access to an Italy-based cloud and IT services company, and access to a GitHub project holding the source code of a mobile app with over 10 million Google Play downloads—all on the Russian-language deep and dark web (DDW) forum Exploit.
- Vulnerability and Tooling Commercialization: Threat actor advertised an alleged Windows Local Privilege Escalation (LPE) zero-day exploit for sale on Exploit.
- Data Dissemination and Telemetry: Forums hosted numerous breach and data sale claims referencing government and major private-sector organizations—including a 33 GB dataset and API keys purportedly tied to Stripe, the Republic Health Insurance Fund, and Tata Housing Development Company. Separately, credential intelligence systems ingested over 1.8 billion combined compromised account credentials (CAC) and botnet CAC during the July 21 to August 17, 2026 reporting period.
Tags: tlp:clear, dark web, vulnerability/exploit, data breach, threat actor