Report Date: 2026-08-05
New KEVs: 5 ▲ +2 vs last weekRansomware Victims: 276 ▲ +19 vs last week
5 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. N-Able products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference Salt Typhoon (China). Ransomware activity is moderate with 276 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.
Patch This Week
The top 3 KEVs to remediate right now, ranked by CISA deadline proximity, ransomware exploitation, and severity. These are confirmed exploited — if you do nothing else today, patch these.
- CVE-2026-18577 – N-able N-central | CVSS 8.2 | EPSS 4.1% / 90th pct
CISA deadline: 2026-08-06 (1d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. - CVE-2026-34486 – Apache Tomcat | CVSS 9.8 | EPSS 81.2% / 100th pct
CISA deadline: 2026-08-07 (2d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. - CVE-2026-9198 – IBM Langflow | CVSS 9.8 | EPSS 17.1% / 97th pct
CISA deadline: 2026-08-07 (2d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Top KEVs
Vulnerabilities confirmed actively exploited in the wild by CISA — ranked by ransomware use, then severity. Patch these before anything else.
New Today
- CVE-2026-63077 – JetBrains TeamCity | CVSS 9.8 (CRITICAL) | AV: Network | EPSS 0.6% / 48th pct | Ransomware Use: No
Still Outstanding
- CVE-2026-34486 – Apache Tomcat | CVSS 9.8 (CRITICAL) | AV: Network | EPSS 81.2% / 100th pct | Ransomware Use: No
- CVE-2026-9198 – IBM Langflow | CVSS 9.8 (CRITICAL) | AV: Network | EPSS 17.1% / 97th pct | Ransomware Use: No
- CVE-2026-18556 – N-able N-central | CVSS 8.2 (HIGH) | AV: Network | EPSS 0.5% / 40th pct | Ransomware Use: No
- CVE-2026-18577 – N-able N-central | CVSS 8.2 (HIGH) | AV: Network | EPSS 4.1% / 90th pct | Ransomware Use: No
Security News
Advisories, threat research, and incident reports from 12 sources across government, commercial research, and security journalism — prioritized by source credibility.
- CISA ICS AdvisoryAdvisory · yesterday – Acrisure KARR BT and DR-100
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations. The following versions of Acrisure KARR BT and DR-100 are affected: KARR BT firm… - CISA ICS AdvisoryAdvisory · 6 days ago – Schneider Electric IGSS
View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a stat… - CISA ICS AdvisoryAdvisory · 6 days ago – Toptech Systems RCU II+ and Multiload II+
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources. The following versions of Toptec… - SANS ISCIncident · today – Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every sup… - SANS ISCResearch · yesterday – Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th)
This morning, I noticed specific sources "hunting" for vulnerabilities in URLs that I haven&#;x26;#;39;t noticed before. All of these URLs appear to be associated with diagnostic tools:
 - Unit 42Research · yesterday – The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software
Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain. The post The Frontier AI Vulnerability Burst: Industrializin… - Unit 42Research · yesterday – Almost Half of Malware Samples Communicate Direct to IP
Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared f… - Sophos X-OpsIncident · yesterday – 2608-volatility-interlock
<p>Multiple legitimate DFIR tools abused by GOLD EMBRACE double-extortion specialists</p> Categories: Threat Research - Sophos X-OpsResearch · yesterday – N-able N-central exploitation results in RMM tool deployment
After compromising systems via CVE-2026-18577, threat actors use the additional RMM tools and network tunnels to establish persistent remote access Categories: Threat Research Tags: RMM, N-able, vulnerability - The RecordNews · today – Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says
Three Chinese telecommunications giants continue to have footholds in the U.S. internet ecosystem despite their alleged role in previous Chinese hacking campaigns, a House committee report concluded. - The RecordIncident · today – Canadian man pleads guilty to Snowflake hacks that led to 165 breaches
A 26-year-old from Ontario faces as many as 32 years in prison after pleading guilty to fraud, identity theft and conspiracy charges related to the 2024 hacks of cloud platform Snowflake. - Security Affairs (APT)Incident · 3 days ago – CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks
After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technol… - Security Affairs (APT)News · 4 days ago – Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, … - Security Affairs (Cybercrime)Incident · yesterday – INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit
INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations. Resecurity disclosed that INC Ransomware has emerged as the dominant… - Security Affairs (Cybercrime)Incident · yesterday – 31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register
Cyberattack exposed data of 31,000 people in Liechtenstein’s beneficial ownership register for companies and foundations. A cyberattack compromised data belonging to about 31,000 people in Liechtenstein’s reg…
Ransomware Activity
Victim counts posted to ransomware group leak sites — use this to gauge which groups are most active and which sectors and regions are being targeted.
90 new victims posted today
7-day total: 276 via Ransomware.live
Infostealer Exposure: 3,269 employee credentials and 83,996 user credentials compromised via infostealer malware across victim organisations — indicating credential theft likely preceded these ransomware deployments.
Most Active Groups
Group Intelligence
- Thegentlemen — The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
- Clop — The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505.<br> <br> At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware.<br> <br> After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the variant, any of the ransom text files were created with names like 'ClopReadMe.txt, README_README.txt, Cl0pReadMe.txt, and READ_ME_!!!.TXT.'<br> <br> The Clop operation has shifted from delivering its final payload via phishing and has begun initiating attacks using vulnerabilities that resulted in the exploitation and infection of victims' infrastructures.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
- Qilin — Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
- Everest — Everest ransom group collects and analyzes information about their victims. They specialize in customer privacy data, financial information, databases, credit card information, and more. The Everest ransom group leaks the victim's data to the darknet and they announced that any victim that will not contact them will suffer from a data leak and they will not delete hist files for future usage.
- Orova — First seen 2026-07-07
Most Targeted Sectors
Top Countries
US (95), GB (11), TR (9), IN (9), DE (8)
Notable Incidents
- Oleoductos del Valle (Energy & Utilities · AR) — claimed by Incransom. During the analysis of data obtained from Oldelval, we have compiled information covering key aspects of the company's operations. The materials include:
1.HR documentation: full payroll data, bank account details (CB…
Press coverage → - Universitatea De Vest Vasile Goldi Din Arad (Education · RO) — claimed by Qilin. N/A Press coverage →
- Loyalist College (Education · CA) — claimed by Incransom. The management of this institution was repeatedly warned about the disclosure of hundreds of personal data. Each of you who is faced with the consequences of the leak can be absolutely sure that the management of Loyalis… Press coverage →
- Mairie de Drancy (Government & Defense · FR) — claimed by Qilin. N/A Press coverage →
- Stadler Rail (Transportation · CH) — claimed by Everest. [AI generated] Stadler Rail is a Swiss manufacturer of railway vehicles headquartered in Bussnang, Switzerland. Founded in 1942, the company designs and produces a wide range of trains including regional and intercity tr… Press coverage →
Vendor-Specific Risks
Vendors with confirmed KEV exploitation this week — the stacked bar shows how that exposure breaks down across exploited CVEs (red), critical CVEs to watch (orange), and news mentions (yellow). Prioritize patching vendors with the largest red segment.
Stay Ahead
Found this useful? Get the daily report in your reader.
Free. No account. No email. Follow in Feedly, Inoreader, or any RSS reader.