zerofox logo
Advisories

ZeroFox Daily Deep and Dark Web Intelligence - September 25, 2026

|by Alpha Team

banner image

ZeroFox Daily Deep and Dark Web Intelligence - September 25, 2026

Product Serial: D-2026-09-25a

TLP:CLEAR

Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.

Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report for today here

Key Findings

  • Ransomware and Digital Extortion: Multiple threat actor groups posted new leak site entries, including INC Ransomware, Qilin Ransomware, The Gentlemen Ransomware, Rhysida Ransomware, and LockBit 5.0 Ransomware.
  • Unauthorized Access Marketplace: Threat actors advertised GitHub access allegedly tied to Pfizer, along with RDWeb and network access allegedly tied to an unnamed Canada-based accounting company and an unnamed Italy-based industrial machinery and equipment company, on deep and dark web (DDW) BreachForums and Exploit.
  • Vulnerability and Tooling Commercialization: A threat actor advertised an alleged one-day exploit for VMware vCenter across DDW forums Exploit and RehubCom.
  • Dark Web Ecosystem Developments: Three new leak sites were identified, operating under the names "ULOSE," "ImNotAVillain," and "NoTrace Group."
  • Data Dissemination and Telemetry: Threat actors hosted a claim of access to data and property-management systems belonging to multiple hotels in South Korea. Separately, credential intelligence systems ingested over 1.4 billion combined compromised account credentials (CAC) and botnet CAC records between August 28 and September 24, 2026 reporting period.

Tags: tlp:clear,  dark web,  vulnerability/exploit,  data breach,  threat actor