ZeroFox Daily Deep and Dark Web Intelligence - September 28, 2026
|by Alpha Team

ZeroFox Daily Deep and Dark Web Intelligence - September 28, 2026
Product Serial: D-2026-09-28a
TLP:CLEAR
Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 72 hours.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report for today here
Key Findings
- Ransomware and Digital Extortion: Multiple groups posted new leak site entries, including Metaencryptor Ransomware, PEAR Ransomware, DragonForce Ransomware, Clop Ransomware, and Vexy Ransomware.
- Unauthorized Access Marketplace: Threat actors advertised corporate SSO access allegedly tied to a Dynatrace platform via a Kyndryl email account, and VPN and RMM access allegedly tied to GSE Group, on deep and dark web (DDW) PwnForums and T1erOne.
- Tooling Commercialization: Actors advertised a MariaDB zero-day exploit and a unified hardware wallet exploit panel targeting Ledger, Trezor, SafePal, and OneKey.
- Ransomware-as-a-Service Expansion: A threat actor advertised a new RaaS partner program dubbed "KillSec," and a new RaaS site, "ContFR," is identified.
- Data Dissemination and Telemetry: Forums hosted several data sale claims, including alleged data tied to Sasai Fintech, Wealthfront, and Medicare and Medicaid patient records exfiltrated from a Kansas clinic. Credential systems ingested over 1.39 billion combined compromised account credentials (CAC) and botnet CAC records between August 31 and September 27, 2026.
Tags: tlp:clear, dark web, vulnerability/exploit, data breach, threat actor