ZeroFox Daily Deep and Dark Web Intelligence - September 25, 2026
|by Alpha Team

ZeroFox Daily Deep and Dark Web Intelligence - September 25, 2026
Product Serial: D-2026-09-25a
TLP:CLEAR
Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report for today here
Key Findings
- Ransomware and Digital Extortion: Multiple threat actor groups posted new leak site entries, including INC Ransomware, Qilin Ransomware, The Gentlemen Ransomware, Rhysida Ransomware, and LockBit 5.0 Ransomware.
- Unauthorized Access Marketplace: Threat actors advertised GitHub access allegedly tied to Pfizer, along with RDWeb and network access allegedly tied to an unnamed Canada-based accounting company and an unnamed Italy-based industrial machinery and equipment company, on deep and dark web (DDW) BreachForums and Exploit.
- Vulnerability and Tooling Commercialization: A threat actor advertised an alleged one-day exploit for VMware vCenter across DDW forums Exploit and RehubCom.
- Dark Web Ecosystem Developments: Three new leak sites were identified, operating under the names "ULOSE," "ImNotAVillain," and "NoTrace Group."
- Data Dissemination and Telemetry: Threat actors hosted a claim of access to data and property-management systems belonging to multiple hotels in South Korea. Separately, credential intelligence systems ingested over 1.4 billion combined compromised account credentials (CAC) and botnet CAC records between August 28 and September 24, 2026 reporting period.
Tags: tlp:clear, dark web, vulnerability/exploit, data breach, threat actor