Report Date: 2026-08-03
New KEVs: 2 ▼ -5 vs last weekRansomware Victims: 186 ▼ -82 vs last week
2 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Cisco products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 186 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.
Patch This Week
The top 3 KEVs to remediate right now, ranked by CISA deadline proximity, ransomware exploitation, and severity. These are confirmed exploited — if you do nothing else today, patch these.
- CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC) | CVSS 5.3 | EPSS 0.8% / 53th pct
CISA deadline: 2026-08-01 (overdue by 2d) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. - CVE-2026-18577 – N-able N-central | CVSS 8.2 | EPSS 1.5% / 71th pct
CISA deadline: 2026-08-06 (3d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Top KEVs
Vulnerabilities confirmed actively exploited in the wild by CISA — ranked by ransomware use, then severity. Patch these before anything else.
New Today
- CVE-2026-18577 – N-able N-central | CVSS 8.2 (HIGH) | AV: Network | EPSS 1.5% / 71th pct | Ransomware Use: No
Still Outstanding
- CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC) | CVSS 5.3 (MEDIUM) | AV: Network | EPSS 0.8% / 53th pct | Ransomware Use: No
Security News
Advisories, threat research, and incident reports from 12 sources across government, commercial research, and security journalism — prioritized by source credibility.
- CISA ICS AdvisoryAdvisory · 4 days ago – Schneider Electric IGSS
View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a stat… - CISA ICS AdvisoryAdvisory · 4 days ago – Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4… - CISA ICS AdvisoryAdvisory · 4 days ago – Johnson Controls OpenBlue Employee
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following versions … - SANS ISCIncident · 2 days ago – Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)
Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, … Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on … - SANS ISCResearch · 5 days ago – Apple Patches Everything (July 2026), (Wed, Jul 29th)
I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions … - Unit 42Research · today – Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor. The post Pass the Passkey: A Novel Attack Surface in Passwordless … - Unit 42Research · 3 days ago – The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Ve… - Sophos X-OpsResearch · 6 days ago – Chaos in Teams vishing
Attackers used Microsoft Teams vishing, custom malware, and remote access tools to facilitate ransomware deployment Categories: Threat Research Tags: Microsoft Teams, vishing, Ransomware, Chaos - Sophos X-OpsResearch · 7 days ago – 2607-secai
<p>What that means for Customer Protections&nbsp;</p> Categories: Threat Research, AI Research - The RecordIncident · today – Bitcoin hardware wallet maker destroys some inventory after more than $88 million stolen
The company behind a popular hardware wallet for bitcoin owners was forced to destroy part of its inventory after thieves siphoned more than $88 million from customers through a firmware vulnerability. - The RecordIncident · today – Hackers steal 31,000 records identifying people behind Liechtenstein companies, foundations
A cyberattack compromised tens of thousands of records related to companies, foundations and trusts in Liechtenstein, prompting the government to to form a âcrisis unitâ to address the breach. - Security Affairs (APT)Incident · yesterday – CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks
After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technol… - Security Affairs (APT)News · 2 days ago – Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, … - Security Affairs (Cybercrime)Incident · today – River Bank obtained assurances from the attackers that the stolen data in the June attack was deleted
River Bank says hackers deleted data stolen in its June ransomware attack, though the investigation into the incident is still ongoing. River Financial Corporation, the parent company of River Bank & Trust, says hack… - Security Affairs (Cybercrime)Incident · today – PNLD Confirms Data Breach Affecting UK Police and Justice Staff
UK police legal database breach exposed officers’ names and work emails, increasing phishing risks. NCA is investigating. The Police National Legal Database (PNLD), the legal reference system used by all 43 Home Of…
Ransomware Activity
Victim counts posted to ransomware group leak sites — use this to gauge which groups are most active and which sectors and regions are being targeted.
31 new victims posted today
7-day total: 186 via Ransomware.live
Infostealer Exposure: 1,911 employee credentials and 64,926 user credentials compromised via infostealer malware across victim organisations — indicating credential theft likely preceded these ransomware deployments.
Most Active Groups
Group Intelligence
- Thegentlemen — The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
- Qilin — Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
- Crpxo — CRPxO is actively recruiting affiliates, offering:
🔹 70% revenue share
🔹 XMR/BTC payouts
🔹 Claimed payouts within 24 hours
🔹 $333 one-time affiliate access - Incransom — INC Ransom is a prolific ransomware-as-a-service operation active since July 2023 that systematically targets healthcare, government, education, and manufacturing sectors in North America and Europe, having posted over 200 victims in 2025 alone with no sector off-limits.
- Safepay — SafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all operations internally, claiming over 300 victims worldwide by mid-2025 with a high-profile early attack against UK telematics firm Microlise stealing 1.2 TB of data.
Most Targeted Sectors
Top Countries
US (71), TR (10), GB (9), DE (5), FR (5)
Notable Incidents
- Universitatea De Vest Vasile Goldi Din Arad (Education · RO) — claimed by Qilin. N/A Press coverage →
- Mairie de Drancy (Government & Defense · FR) — claimed by Qilin. N/A Press coverage →
- greenecountyga.gov (Government & Defense · US) — claimed by Incransom. Greene County, Georgia is a historic and scenic county located in the east-central "Lake Country" region of the state, roughly halfway between Atlanta and Augusta. Established in 1786 as Georgia's 11th county, it is wide… Press coverage →
Vendor-Specific Risks
Vendors with confirmed KEV exploitation this week — the stacked bar shows how that exposure breaks down across exploited CVEs (red), critical CVEs to watch (orange), and news mentions (yellow). Prioritize patching vendors with the largest red segment.
Stay Ahead
Found this useful? Get the daily report in your reader.
Free. No account. No email. Follow in Feedly, Inoreader, or any RSS reader.