Report Date: 2026-08-27
New KEVs: 7 — unchanged vs last weekRansomware Victims: 252 ▲ +16 vs last week
7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Microsoft products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 252 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.
Patch This Week
The top 3 KEVs to remediate right now, ranked by CISA deadline proximity, ransomware exploitation, and severity. These are confirmed exploited — if you do nothing else today, patch these.
- CVE-2026-73570 – Synacor Zimbra Collaboration Suite (ZCS) | CVSS 8.9 | EPSS 1.5% / 72th pct
CISA deadline: 2026-08-24 (overdue by 3d) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. - CVE-2026-21962 – Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in | CVSS 10.0 | EPSS 42.0% / 99th pct
CISA deadline: 2026-08-27 (0d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. - CVE-2026-60004 – Gitea Gitea | CVSS 9.8
CISA deadline: 2026-08-28 (1d remaining) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Top KEVs
Vulnerabilities confirmed actively exploited in the wild by CISA — ranked by ransomware use, then severity. Patch these before anything else.
This Reporting Window
- CVE-2026-21962 – Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in | CVSS 10.0 (CRITICAL) | AV: Network | EPSS 42.0% / 99th pct | Ransomware Use: No
- CVE-2026-60004 – Gitea Gitea | CVSS 9.8 (CRITICAL) | AV: Network | Ransomware Use: No
- CVE-2026-73570 – Synacor Zimbra Collaboration Suite (ZCS) | CVSS 8.9 (HIGH) | AV: Network | EPSS 1.5% / 72th pct | Ransomware Use: No
- CVE-2026-8452 – Citrix NetScaler ADC and NetScaler Gateway | CVSS 8.8 (HIGH) | AV: Network | EPSS 1.0% / 62th pct | Ransomware Use: No
- CVE-2019-1068 – Microsoft SQL Server | CVSS 8.8 (HIGH) | AV: Network | EPSS 44.7% / 99th pct | Ransomware Use: No
- CVE-2021-23758 – Ajax.NET Professional Ajax.NET Professional | CVSS 8.1 (HIGH) | AV: Network | EPSS 89.1% / 100th pct | Ransomware Use: No | PoC Available
- CVE-2015-5287 – Red Hat Automatic Bug Reporting Tool | CVSS 7.8 (HIGH) | AV: Local | EPSS 3.4% / 88th pct | Ransomware Use: No | PoC Available
Security News
Advisories, threat research, and incident reports from 12 sources across government, commercial research, and security journalism — prioritized by source credibility.
- CISA ICS AdvisoryAdvisory · 2 days ago – FURUNO FA-50 Class B AIS Transponder
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to alter device settings. The following versions of FURUNO FA-50 Class B AIS Transponder are affected: FURUNO FA-50 Class B AIS T… - CISA ICS AdvisoryAdvisory · 2 days ago – Zoneminder
View CSAF Summary Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user. The following versions of Zoneminder are affected: Zoneminder 1.37.48|1.38.3 … - CISA ICS AdvisoryAdvisory · 2 days ago – PayRange API
View CSAF Summary Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of servic… - SANS ISCResearch · 2 days ago – Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)
It is pretty obvious that hostnames can replace IP addresses. Pretty much any software accepting an IP address will also accept a hostname as an argument. Last week, I wrote about scans for the cloud metadata service lis… - SANS ISCResearch · 3 days ago – DOUBLECUP's PNG Payload, (Mon, Aug 24th)
New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up. It doesn&#;x26;#;39;t use real steganography:
 - Unit 42Research · 2 days ago – The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abus… - Unit 42Incident · 6 days ago – Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overlooked Corners of the S… - Sophos X-OpsResearch · 8 days ago – Fake AI, real malware: Attackers impersonating AI brands
<p>A year of MDR casework shows attackers repeatedly exploiting demand for AI tools</p> Categories: Threat Research Tags: AI, malvertising, infostealer, Sophos X-Ops - Sophos X-OpsResearch · 10 days ago – 2608-patch-tuesday
<p>421 CVEs, a relatively small set of Edge patches, and two spicy stragglers</p> Categories: Threat Research Tags: Patch Tuesday, MICROSOFT PATCH TUESDAY - The RecordNews · yesterday – Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit
The National Security Agency will welcome back to campus potentially hundreds of former members of the elite group known as Tailored Access Operations (TAO) to celebrate the divisionâs recent rebranding. - The RecordIncident · yesterday – Medical device firm Boston Scientific says cyberattack has disrupted shipment processes
The company released a statement and filed documents with the Securities and Exchange Commission (SEC) saying a cybersecurity incident was discovered on Tuesday. - Security Affairs (APT)News · yesterday – FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure
FBI seizes QScan and QTRouter, China-linked platforms used to hide intrusions and target U.S. critical infrastructure. The U.S. Department of Justice and the FBI have seized two platforms, QScan and QTRouter, used by a C… - Security Affairs (APT)Incident · 4 days ago – UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks
Iran-linked hackers shut down a UK power plant for four days in the first confirmed attack of its kind, concurrent with water infrastructure attacks across 12 US states. Iran-linked hackers shut down a British power plan… - Security Affairs (Cybercrime)Incident · yesterday – Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams
INTERPOL’s Operation Jackal IV made 58 arrests and exposed global networks laundering money from scams, fraud and sextortion. INTERPOL announced that Operation Jackal IV, running from November 2025 to June 2026, led to 5… - Security Affairs (Cybercrime)Incident · 2 days ago – Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown
WeedHack Minecraft Malware Survives C2 Takedown: Fake Client Sites Still Active, SEO Poisoning Puts Malicious Downloads at the Top of Google McAfee Labs published a follow-up report on the WeedHack Malware-as-a-Service c…
Ransomware Activity
Victim counts posted to ransomware group leak sites — use this to gauge which groups are most active and which sectors and regions are being targeted.
35 new victims posted today
7-day total: 252 via Ransomware.live
Infostealer Exposure: 4,325 employee credentials and 112,542 user credentials compromised via infostealer malware across victim organisations — indicating credential theft likely preceded these ransomware deployments.
Most Active Groups
Group Intelligence
- Qilin — Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
- Thegentlemen — The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
- Direwolf — Dire Wolf is a sophisticated human-operated ransomware group first documented in May 2025, written in Golang using Curve25519/ChaCha20 encryption, targeting manufacturing and technology sectors across 13+ countries with ransoms up to $500,000, operated by a tight core team rather than a broad affiliate program.
- Coinbasecartel — CoinbaseCartel specializes in data acquisition through system access and strategic partnerships. It focus exclusively on data exfiltration—our operations never involve system encryption or operational disruption.
- Krybit — Krybit is an emerging RaaS group that launched in late March 2026, offering affiliates an 80/20 revenue split with support for Windows, Linux, ESXi, and NAS device encryption, and became notable for a public feud with rival group 0APT in which each breached and leaked the other's operator data.
Most Targeted Sectors
Top Countries
US (88), IT (19), MX (9), GB (9), DE (8)
Notable Incidents
- Gruppo Spaggiari Parma (Manufacturing · IT) — claimed by Xpl0Itrs. School management software Press coverage →
- Brazosport College (Education · US) — claimed by Qilin. N/A Press coverage →
- icnavais.com (Not Found · PT) — claimed by Lockbit5. The Itaguaí Construções Navais S.A. known as ICN, is a Brazilian state-owned defence company special… Press coverage →
- City of Mitchell (Government & Defense · US) — claimed by Storm. Mitchell is a city in and the county seat of Davison County, South Dakota, United States. Mitchell is the principal city of the Mitchell Micropolitan Statistical Area, which includes all of Davison and Hanson counties.
… Press coverage → - adt.com (Professional Services · US) — claimed by Lockbit5. ADT is a security company that offers security systems, cameras, alarms ad home automation services…. Press coverage →
Vendor-Specific Risks
Vendors with confirmed KEV exploitation this week — the stacked bar shows how that exposure breaks down across exploited CVEs (red), critical CVEs to watch (orange), and news mentions (yellow). Prioritize patching vendors with the largest red segment.
Stay Ahead
Found this useful? Get the daily report in your reader.
Free. No account. No email. Follow in Feedly, Inoreader, or any RSS reader.