Threat Intelligence Report — August 1, 2026 | 3 New KEVs · 243 Victims

Report Date: 2026-08-01

New KEVs: 3  ▼ -3 vs last weekRansomware Victims: 243  ▲ +68 vs last week

3 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Fortinet products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 243 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Patch This Week

The top 3 KEVs to remediate right now, ranked by CISA deadline proximity, ransomware exploitation, and severity. These are confirmed exploited — if you do nothing else today, patch these.

  1. CVE-2026-16812 – Arista VeloCloud Orchestrator | CVSS 10.0 | EPSS 0.9% / 56th pct
    CISA deadline: 2026-07-30 (overdue by 2d) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  2. CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC) | CVSS 5.3 | EPSS 0.8% / 53th pct
    CISA deadline: 2026-08-01 (0d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  3. CVE-2025-68686 – Fortinet FortiOS | CVSS 5.9 | EPSS 1.3% / 67th pct
    CISA deadline: 2026-08-10 (9d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Top KEVs

Vulnerabilities confirmed actively exploited in the wild by CISA — ranked by ransomware use, then severity. Patch these before anything else.

This Reporting Window

  • CVE-2026-16812 – Arista VeloCloud Orchestrator | CVSS 10.0 (CRITICAL) | AV: Network | EPSS 0.9% / 56th pct | Ransomware Use: No
  • CVE-2025-68686 – Fortinet FortiOS | CVSS 5.9 (MEDIUM) | AV: Network | EPSS 1.3% / 67th pct | Ransomware Use: No
  • CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC) | CVSS 5.3 (MEDIUM) | AV: Network | EPSS 0.8% / 53th pct | Ransomware Use: No

Security News

Advisories, threat research, and incident reports from 12 sources across government, commercial research, and security journalism — prioritized by source credibility.

  • CISA ICS AdvisoryAdvisory · 2 days agoSchneider Electric IGSS
    View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a stat…
  • CISA ICS AdvisoryAdvisory · 2 days agoRockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
    View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4…
  • CISA ICS AdvisoryAdvisory · 2 days agoJohnson Controls OpenBlue Employee
    View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following versions …
  • SANS ISCIncident · todayPhishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)
    Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, … Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on …
  • SANS ISCResearch · 3 days agoApple Patches Everything (July 2026), (Wed, Jul 29th)
    I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions …
  • Unit 42Research · yesterdayThe Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
    Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Ve…
  • Unit 42Incident · 2 days agoChinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
    Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous…
  • Sophos X-OpsResearch · 4 days agoChaos in Teams vishing
    Attackers used Microsoft Teams vishing, custom malware, and remote access tools to facilitate ransomware deployment Categories: Threat Research Tags: Microsoft Teams, vishing, Ransomware, Chaos
  • Sophos X-OpsResearch · 5 days ago2607-secai
    <p>What that means for Customer Protections </p> Categories: Threat Research, AI Research
  • The RecordIncident · yesterdayCISA warns of spike in attacks on water systems as Minnesota incidents probed
    The Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible."
  • The RecordNews · yesterdayCyber Command plans Silicon Valley office to drive innovation
    The outpost will have its own director, though no one has yet been named for the post, and support the command’s nascent Cyber Warfare Innovation Center (CIWC).
  • Security Affairs (APT)News · todayRussian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
    Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, …
  • Security Affairs (APT)Incident · yesterdaySouth Korea Warns of State-Backed Watering Hole Attacks
    South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies (The National Intelligence Service, the National Police Agency, the…
  • Security Affairs (Cybercrime)News · 2 days agoResearchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App
    Researchers linked the Flying Eagle Android RAT to fake police apps, uncovering 170 servers in a growing cybercrime ecosystem. Hunt.io researchers and independent journalist NetAskari started with a fraudulent Android ap…
  • Security Affairs (Cybercrime)News · 2 days agoCybercriminals Are Leveraging Autonomous AI Offensive Security Agents
    Resecurity warns AI offensive agents are lowering hacking barriers, fueling an AI-driven race between attackers and defenders. Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStr…

Ransomware Activity

Victim counts posted to ransomware group leak sites — use this to gauge which groups are most active and which sectors and regions are being targeted.

27 new victims posted today
7-day total: 243 via Ransomware.live

Infostealer Exposure: 19,719 employee credentials and 826,008 user credentials compromised via infostealer malware across victim organisations — indicating credential theft likely preceded these ransomware deployments.

Most Active Groups

Thegentlemen 43 Crpxo 30 Qilin 27 Global Secret Group 20 Exfilsquad 15

Group Intelligence

  • ThegentlemenThe Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
  • CrpxoCRPxO is actively recruiting affiliates, offering:
    🔹 70% revenue share
    🔹 XMR/BTC payouts
    🔹 Claimed payouts within 24 hours
    🔹 $333 one-time affiliate access
  • QilinQilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
  • ExfilsquadOnly exfiltration

Most Targeted Sectors

Manufacturing 46 Technology 36 Professional Services 24 Healthcare 21 Other 19

Top Countries

US (111), GB (15), DE (12), TR (10), CA (8)

Notable Incidents

  • Universitatea de Vest „Vasile Goldiș” din Arad (Education · RO) — claimed by Qilin. N/A Press coverage →
  • BH Security, LLC. (brinkshome.com) (Professional Services · US) — claimed by Shinyhunters. Over 4.9 million Salesforce records containing some PII was compromised. This is a final warning to reach out by 30 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the … Press coverage →
  • greenecountyga.gov (Government & Defense · US) — claimed by Incransom. Greene County, Georgia is a historic and scenic county located in the east-central "Lake Country" region of the state, roughly halfway between Atlanta and Augusta. Established in 1786 as Georgia's 11th county, it is wide… Press coverage →
  • Analog Devices (Technology · US) — claimed by Exfilsquad. Revenue: $12.7B

    DATA SUMMARY:
    570K~ records containing: customer PII and addresses. Press coverage →

  • landesmuseum.de (Education · DE) — claimed by Safepay. Established in 1919, the museum preserves and presents more than 50,000 years of human cultural history, ranging from prehistoric artifacts … Press coverage →

Vendor-Specific Risks

Vendors with confirmed KEV exploitation this week — the stacked bar shows how that exposure breaks down across exploited CVEs (red), critical CVEs to watch (orange), and news mentions (yellow). Prioritize patching vendors with the largest red segment.

Fortinet 1 Arista 1 Cisco 1 KEVs CVEs Mentions

Stay Ahead

Found this useful? Get the daily report in your reader.

Free. No account. No email. Follow in Feedly, Inoreader, or any RSS reader.