DEFENDERS CLOCK
THE PUBLIC OPERATING SIGNAL FOR DEFENDERS
ISSUED 2026-08-03 · 14:00 UTC
DEFENDER PRESSURE
020406080100ELEVATEDWEEK OF AUGUST 3, 2026
THIS WEEK’S DEFENDER READING
59/ 100ELEVATED

Zero-day exploitation of perimeter security products and a coordinated attack on water utilities push defender pressure up this week.

↑ 5 POINTS SINCE LAST WEEKWEEK OF AUGUST 3, 2026
ACTIVE EXPLOITATION
RISING

Three KEV additions land in one week, led by a hardcoded-credential zero-day in Cisco Secure Firewall Management Center; an Exchange OWA zero-day is also under active exploitation.

CONFIDENCE · HIGH
IDENTITY & HUMAN ATTACK PRESSURE
STEADY

Exposed-credential abuse and voice-phishing-led intrusions continue at elevated levels without a verified step-change.

CONFIDENCE · MEDIUM
INTRUSION / RANSOMWARE TEMPO
RISING

A coordinated attack disrupted water utilities, a data-theft wave hits healthcare, and the Clop extortion campaign continues.

CONFIDENCE · MEDIUM
THREE MOVES THIS WEEK
01Patch the actively exploited perimeter set — Cisco FMC, FortiOS, Arista VeloCloud, Exchange OWA — rotate any static credentials, and hunt for pre-patch access.
02If you operate water or industrial systems, apply CISA's PLC-hardening alert now; everyone else, re-verify IT/OT and management-plane segmentation.
03Brief helpdesk and staff that Teams voice-phishing is preceding ransomware deployment; tighten controls on remote-management tool installs.
WHY WE BELIEVE THIS
CISA KEVVENDOR ADVISORYINCIDENT REPORTINGGOV ADVISORY

Every reading links to its public evidence, scores confidence openly, and preserves its revision history.