ZeroFox Daily Deep and Dark Web Intelligence - October 1, 2026
|by Alpha Team

ZeroFox Daily Deep and Dark Web Intelligence - October 1, 2026
Product Serial: D-2026-10-01a
TLP:CLEAR
Here is a curated list of critical incidents and compromised data observed on deep and dark web ransomware sites, forums, and marketplaces ingested into the ZeroFox Platform in the past 24 hours.
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit: https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report for today here
Key Findings
- Ransomware and Digital Extortion: Multiple threat groups posted new leak site entries, including M3RX Ransomware, Brain Cipher Ransomware, and INTERLOCK Ransomware.
- Unauthorized Access Marketplace: Threat actors advertised Citrix access allegedly tied to a U.S.-based government entity and SSH access allegedly tied to a U.S.-based telecommunications company, on a deep and dark web (DDW) forum T1erOne.
- Vulnerability and Tooling Commercialization: Threat actors advertised an undisclosed zero-day RCE, a Windows kernel zero-day LPE, and an alleged "Tripaul RAT Loader," on a DDW forum Exploit.
- New Leak Site Emergence: A new hacktivist-operated leak site, "UWAYS QARANI," identfied.
- Data Dissemination and Telemetry: Threat actors hosted several data sale claims, including over 1 million records tied to SoLo Funds and over 400,000 UK and Ireland institutional email contacts, on Exploit, alongside a smaller processed breach set. Credential systems ingested over 1.5 billion combined compromised account credentials (CAC) and botnet CAC records between September 3 and September 30, 2026.
Tags: tlp:clear, dark web, vulnerability/exploit, data breach, threat actor