Threat Intelligence Report — July 29, 2026 | 3 New KEVs · 257 Victims

Report Date: 2026-07-29

New KEVs: 3  ▼ -4 vs last weekRansomware Victims: 257  ▲ +93 vs last week

3 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Arista products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 257 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Patch This Week

The top 3 KEVs to remediate right now, ranked by CISA deadline proximity, ransomware exploitation, and severity. These are confirmed exploited — if you do nothing else today, patch these.

  1. CVE-2026-16812 – Arista VeloCloud Orchestrator | CVSS 10.0 | EPSS 0.9% / 56th pct
    CISA deadline: 2026-07-30 (1d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  2. CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC) | CVSS 5.3
    CISA deadline: 2026-08-01 (3d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  3. CVE-2025-68686 – Fortinet FortiOS | CVSS 5.9 | EPSS 1.3% / 67th pct
    CISA deadline: 2026-08-10 (12d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Top KEVs

Vulnerabilities confirmed actively exploited in the wild by CISA — ranked by ransomware use, then severity. Patch these before anything else.

New Today

  • CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC) | CVSS 5.3 (MEDIUM) | AV: Network | Ransomware Use: No

Still Outstanding

  • CVE-2026-16812 – Arista VeloCloud Orchestrator | CVSS 10.0 (CRITICAL) | AV: Network | EPSS 0.9% / 56th pct | Ransomware Use: No
  • CVE-2025-68686 – Fortinet FortiOS | CVSS 5.9 (MEDIUM) | AV: Network | EPSS 1.3% / 67th pct | Ransomware Use: No

Security News

Advisories, threat research, and incident reports from 12 sources across government, commercial research, and security journalism — prioritized by source credibility.

  • CISA ICS AdvisoryAdvisory · yesterdaySiemens SIMATIC S7-PLCSIM Advanced
    View CSAF Summary SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for pro…
  • CISA ICS AdvisoryAdvisory · yesterdayigloohome Smart Lock Mobile Application
    View CSAF Summary Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services. The following versions of igloohome Smart Lock Mobile Application are affected: S…
  • CISA ICS AdvisoryAdvisory · yesterdaySiemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
    View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is prep…
  • SANS ISCResearch · todayApple Patches Everything (July 2026), (Wed, Jul 29th)
    I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions …
  • SANS ISCResearch · yesterdayAutoIT Payload Injector , (Tue, Jul 28th)
    For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it&#x27s easy to write and powerful. Indeed, it can perform all the required actions to inject a pa…
  • Unit 42Incident · 6 days agoRussian Global Webmail Espionage
    Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42 .
  • Unit 42Research · 12 days agoThree Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
    A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Tri…
  • Sophos X-OpsResearch · yesterdayChaos in Teams vishing
    Attackers used Microsoft Teams vishing, custom malware, and remote access tools to facilitate ransomware deployment Categories: Threat Research Tags: Microsoft Teams, vishing, Ransomware, Chaos
  • Sophos X-OpsResearch · 2 days ago2607-secai
    <p>What that means for Customer Protections </p> Categories: Threat Research, AI Research
  • The RecordNews · todayLaundry Bear’s webmail hackers had more in store after February, report says
    Researchers say the Russian state-linked hacking group tracked as Laundry Bear recently began exploiting a bug in Microsoft Outlook Web Access.
  • The RecordIncident · todayRussia accuses Telegram founder of aiding terrorism, seeks international arrest
    Russia is seeking to place Telegram founder Pavel Durov on an international wanted list, alleging that the app has been used by Ukrainian intelligence to organize terrorist attacks and conduct espionage inside Russia.
  • Security Affairs (APT)Incident · 3 days agoHackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials
    Hackers compromised hotel Wi-Fi gateways to redirect users to fake Microsoft 365 login pages and steal credentials. ReliaQuest’s threat research team just documented attackers compromising the Wi-Fi gateways at hot…
  • Security Affairs (APT)Incident · 4 days agoIran-Linked Actors Breach Are Targeting US Water and Energy Control Systems
    US agencies warn Iran-linked actors are targeting internet-exposed water and energy control systems, risking disruption. Federal agencies updated their cybersecurity advisory this week: Iran-linked actors are inside Amer…
  • Security Affairs (Cybercrime)Incident · todayShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data
    ShinyHunters claimed the Ernst & Young data breach, threatening to leak stolen tax records unless the firm contacts the group by July 31. The ShinyHunters cybercrime group has taken responsibility for the recently di…
  • Security Affairs (Cybercrime)Incident · todayVPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims
    A breached “no-logs” VPN exposed 58 million connection logs and millions of user, device, and payment records, contradicting its privacy claims. A threat actor on the Altenen cybercrime forum is distributing …

Ransomware Activity

Victim counts posted to ransomware group leak sites — use this to gauge which groups are most active and which sectors and regions are being targeted.

11 new victims posted today
7-day total: 257 via Ransomware.live

Infostealer Exposure: 17,952 employee credentials and 1,003,536 user credentials compromised via infostealer malware across victim organisations — indicating credential theft likely preceded these ransomware deployments.

Most Active Groups

Thegentlemen 32 Global Secret Group 31 Qilin 27 Crpxo 20 Section9 19

Group Intelligence

  • ThegentlemenThe Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
  • QilinQilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
  • CrpxoCRPxO is actively recruiting affiliates, offering:
    🔹 70% revenue share
    🔹 XMR/BTC payouts
    🔹 Claimed payouts within 24 hours
    🔹 $333 one-time affiliate access

Most Targeted Sectors

Technology 41 Manufacturing 41 Healthcare 28 Professional Services 25 Other 20

Top Countries

US (104), GB (12), DE (12), CA (10), BR (10)

Notable Incidents

  • Universitatea de Vest „Vasile Goldiș” din Arad (Education · RO) — claimed by Qilin. N/A Press coverage →
  • BH Security, LLC. (brinkshome.com) (Professional Services · US) — claimed by Shinyhunters. Over 4.9 million Salesforce records containing some PII was compromised. This is a final warning to reach out by 30 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the … Press coverage →
  • Thialf (Energy & Utilities · NL) — claimed by Thegentlemen. ***.nl zoominfo.com/c/thialf/430686423 Thialf is a world-renowned ice arena located in Heerenveen, Netherlands, often referred to as the "Cathedral of Speed Skating." It serves as the home base for the Dutch national spe… Press coverage →
  • greenecountyga.gov (Government & Defense · US) — claimed by Incransom. Greene County, Georgia is a historic and scenic county located in the east-central "Lake Country" region of the state, roughly halfway between Atlanta and Augusta. Established in 1786 as Georgia's 11th county, it is wide… Press coverage →
  • Plitvička Jezera Nacionalni Park (Hospitality · HR) — claimed by Qilin. N/A Press coverage →

Vendor-Specific Risks

Vendors with confirmed KEV exploitation this week — the stacked bar shows how that exposure breaks down across exploited CVEs (red), critical CVEs to watch (orange), and news mentions (yellow). Prioritize patching vendors with the largest red segment.

Arista 1 Fortinet 1 Cisco 1 KEVs CVEs Mentions

Stay Ahead

Found this useful? Get the daily report in your reader.

Free. No account. No email. Follow in Feedly, Inoreader, or any RSS reader.