Report Date: 2026-08-04
New KEVs: 5 ▲ +1 vs last weekRansomware Victims: 196 ▼ -72 vs last week
5 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. N-Able products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 196 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.
Patch This Week
The top 3 KEVs to remediate right now, ranked by CISA deadline proximity, ransomware exploitation, and severity. These are confirmed exploited — if you do nothing else today, patch these.
- CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC) | CVSS 5.3 | EPSS 0.8% / 53th pct
CISA deadline: 2026-08-01 (overdue by 3d) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. - CVE-2026-18577 – N-able N-central | CVSS 8.2 | EPSS 2.5% / 83th pct
CISA deadline: 2026-08-06 (2d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. - CVE-2026-9198 – IBM Langflow | CVSS 9.8 | EPSS 1.9% / 78th pct
CISA deadline: 2026-08-07 (3d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Top KEVs
Vulnerabilities confirmed actively exploited in the wild by CISA — ranked by ransomware use, then severity. Patch these before anything else.
New Today
- CVE-2026-9198 – IBM Langflow | CVSS 9.8 (CRITICAL) | AV: Network | EPSS 1.9% / 78th pct | Ransomware Use: No
- CVE-2026-18556 – N-able N-central | CVSS 8.2 (HIGH) | AV: Network | EPSS 0.3% / 19th pct | Ransomware Use: No
- CVE-2026-34486 – Apache Tomcat | CVSS 7.5 (HIGH) | AV: Network | EPSS 42.6% / 99th pct | Ransomware Use: No
Still Outstanding
- CVE-2026-18577 – N-able N-central | CVSS 8.2 (HIGH) | AV: Network | EPSS 2.5% / 83th pct | Ransomware Use: No
- CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC) | CVSS 5.3 (MEDIUM) | AV: Network | EPSS 0.8% / 53th pct | Ransomware Use: No
Security News
Advisories, threat research, and incident reports from 12 sources across government, commercial research, and security journalism — prioritized by source credibility.
- CISA ICS AdvisoryAdvisory · today – Acrisure KARR BT and DR-100
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations. The following versions of Acrisure KARR BT and DR-100 are affected: KARR BT firm… - CISA ICS AdvisoryAdvisory · 5 days ago – Schneider Electric IGSS
View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a stat… - CISA ICS AdvisoryAdvisory · 5 days ago – Toptech Systems RCU II+ and Multiload II+
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources. The following versions of Toptec… - SANS ISCResearch · today – Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)
This morning, I noticed specific sources "hunting" for vulnerabilities in URLs that I haven&#;x26;#;39;t noticed before. All of these URLs appear to be associated with diagnostic tools:
 - SANS ISCIncident · 3 days ago – Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)
Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, … Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on … - Unit 42Research · today – The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software
Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain. The post The Frontier AI Vulnerability Burst: Industrializin… - Unit 42Research · today – Almost Half of Malware Samples Communicate Direct to IP
Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared f… - Sophos X-OpsResearch · 7 days ago – Chaos in Teams vishing
Attackers used Microsoft Teams vishing, custom malware, and remote access tools to facilitate ransomware deployment Categories: Threat Research Tags: Microsoft Teams, vishing, Ransomware, Chaos - Sophos X-OpsResearch · 8 days ago – 2607-secai
<p>What that means for Customer Protections&nbsp;</p> Categories: Threat Research, AI Research - The RecordIncident · today – Polish convenience store chain Å»abka hacked through third-party account
Reports said intruders appeared to gain access to the Jira environment and other sensitive data of the Å»abka retail chain. The company confirmed an intrusion occurred in late July. - Security Affairs (APT)Incident · 2 days ago – CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks
After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technol… - Security Affairs (APT)News · 3 days ago – Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, … - Security Affairs (Cybercrime)Incident · today – INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit
INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations. Resecurity disclosed that INC Ransomware has emerged as the dominant… - Security Affairs (Cybercrime)Incident · today – 31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register
Cyberattack exposed data of 31,000 people in Liechtenstein’s beneficial ownership register for companies and foundations. A cyberattack compromised data belonging to about 31,000 people in Liechtenstein’s reg… - Bleeping ComputerIncident · today – Phishing service spoofs RingCentral to steal Microsoft 365 accounts
The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. […]
Ransomware Activity
Victim counts posted to ransomware group leak sites — use this to gauge which groups are most active and which sectors and regions are being targeted.
32 new victims posted today
7-day total: 196 via Ransomware.live
Infostealer Exposure: 2,016 employee credentials and 66,037 user credentials compromised via infostealer malware across victim organisations — indicating credential theft likely preceded these ransomware deployments.
Most Active Groups
Group Intelligence
- Thegentlemen — The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
- Qilin — Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
- Orova — First seen 2026-07-07
- Incransom — INC Ransom is a prolific ransomware-as-a-service operation active since July 2023 that systematically targets healthcare, government, education, and manufacturing sectors in North America and Europe, having posted over 200 victims in 2025 alone with no sector off-limits.
- Crpxo — CRPxO is actively recruiting affiliates, offering:
🔹 70% revenue share
🔹 XMR/BTC payouts
🔹 Claimed payouts within 24 hours
🔹 $333 one-time affiliate access
Most Targeted Sectors
Top Countries
US (77), TR (10), DE (7), GB (6), HK (5)
Notable Incidents
- Oleoductos del Valle (Energy & Utilities · AR) — claimed by Incransom. During the analysis of data obtained from Oldelval, we have compiled information covering key aspects of the company's operations. The materials include:
1.HR documentation: full payroll data, bank account details (CB…
Press coverage → - Universitatea De Vest Vasile Goldi Din Arad (Education · RO) — claimed by Qilin. N/A Press coverage →
- Mairie de Drancy (Government & Defense · FR) — claimed by Qilin. N/A Press coverage →
Vendor-Specific Risks
Vendors with confirmed KEV exploitation this week — the stacked bar shows how that exposure breaks down across exploited CVEs (red), critical CVEs to watch (orange), and news mentions (yellow). Prioritize patching vendors with the largest red segment.
Stay Ahead
Found this useful? Get the daily report in your reader.
Free. No account. No email. Follow in Feedly, Inoreader, or any RSS reader.