zerofox logo
Advisories

ZeroFox Daily Deep and Dark Web Intelligence - September 23, 2026

|by Alpha Team

banner image

ZeroFox Daily Deep and Dark Web Intelligence - September 23, 2026

Product Serial: D-2026-09-23a

TLP:CLEAR

Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report for today here

Key Findings

  • Ransomware and Digital Extortion: Multiple threat actor groups posted new leak site entries, including Settra Ransomware, Titan Ransomware, Storm Ransomware, Metaencryptor Ransomware, and Anubis Ransomware.
  • Unauthorized Access Marketplace: Threat actors advertised SSH and Fortinet access allegedly tied to an unnamed India-based energy company and an unnamed Philippines-based energy company, on deep and dark web (DDW) forums RehubCom and Exploit.
  • Vulnerability and Tooling Commercialization: Threat actors advertised an alleged Windows privilege escalation exploit and an alleged critical zero-day admin access bypass affecting PrestaShop.
  • Dark Web Ecosystem Developments: ShinyHunters posted an update on its leak site allegedly targeting the U.S. Federal Bureau of Investigation.
  • Data Dissemination and Telemetry: Threat actors posted data sale claims referencing organizations including OnTheHouse and France-based construction firm Réso. Separately, credential intelligence systems ingested over 1.1 billion combined compromised account crexdentials (CAC) and botnet CAC records between August 26 and September 22, 2026 reporting period.

Tags: tlp:clear,  dark web,  vulnerability/exploit,  data breach,  threat actor