Zero-day exploitation of perimeter security products and a coordinated attack on water utilities push defender pressure up this week.
↑ 5 POINTS SINCE LAST WEEKWEEK OF AUGUST 3, 2026
ACTIVE EXPLOITATION↑
RISING
Three KEV additions land in one week, led by a hardcoded-credential zero-day in Cisco Secure Firewall Management Center; an Exchange OWA zero-day is also under active exploitation.
CONFIDENCE · HIGH
RATIONALE & SOURCE TYPES
CISA added Cisco FMC CVE-2026-20316 (hardcoded credentials, exploited as a zero-day) on July 29 and Fortinet FortiOS CVE-2025-68686 plus Arista VeloCloud CVE-2026-16812 on July 27 — all network-edge or security-management products. Incident reporting separately documents Russian actors exploiting a Microsoft Exchange OWA zero-day for persistent mailbox access. Confidence is high: KEV anchor, vendor advisories, and independent reporting align.
CISA KEVVENDOR ADVISORYINCIDENT REPORTING
IDENTITY & HUMAN ATTACK PRESSURE→
STEADY
Exposed-credential abuse and voice-phishing-led intrusions continue at elevated levels without a verified step-change.
CONFIDENCE · MEDIUM
RATIONALE & SOURCE TYPES
Reporting on the Hugging Face breach documents an autonomous agent reusing exposed credentials across four services — a reminder that leaked secrets are exploited immediately; separate reporting ties Microsoft Teams vishing to subsequent Chaos ransomware deployment. Confidence is medium: sustained pressure, no verified step-change this week.
INCIDENT REPORTING
INTRUSION / RANSOMWARE TEMPO↑
RISING
A coordinated attack disrupted water utilities, a data-theft wave hits healthcare, and the Clop extortion campaign continues.
CONFIDENCE · MEDIUM
RATIONALE & SOURCE TYPES
A coordinated cyberattack targeted more than 30 Minnesota water systems, taking one plant offline, and CISA issued an alert urging the water/wastewater sector to protect OT against activity targeting PLCs (government advisory — the second independent source class supporting the raise). Health-ISAC warns of rising ShinyHunters data theft against healthcare; Clop's Windchill/FlexPLM extortion continues from last week. Confidence is medium: attribution and full scope of the water-sector activity are still developing.
GOV ADVISORYINCIDENT REPORTING
THREE MOVES THIS WEEK
01Patch the actively exploited perimeter set — Cisco FMC, FortiOS, Arista VeloCloud, Exchange OWA — rotate any static credentials, and hunt for pre-patch access.
02If you operate water or industrial systems, apply CISA's PLC-hardening alert now; everyone else, re-verify IT/OT and management-plane segmentation.
03Brief helpdesk and staff that Teams voice-phishing is preceding ransomware deployment; tighten controls on remote-management tool installs.