ARCHIVED READING · PERMANENT RECORD
WEEK OF AUGUST 10, 2026
61/ 100HIGH PRESSURE
Exploited flaws in remote-management and developer infrastructure drive a second week of rising exploitation; the reading crosses into high pressure.
↑ 2 POINTS SINCE LAST WEEK2026-W33ISSUED 2026-08-10 · 14:00 UTCMETHODOLOGY V1.0
SIGNALS
ACTIVE EXPLOITATION↑
RISING
Five KEV additions in one week, led by an N-able N-central authentication bypass exploited through an incomplete patch — with confirmed customer compromises and pivots into managed endpoints.
RATIONALE & SOURCE TYPES
CISA added N-central CVE-2026-18577 (Aug 3, exploited in the wild since Aug 1 after an incomplete fix; N-able confirms compromised customers, with attackers using Take Control to reach managed endpoints), then N-central CVE-2026-18556, Apache Tomcat CVE-2026-34486, and Langflow CVE-2026-9198 (Aug 4), and JetBrains TeamCity CVE-2026-63077 (Aug 5). Remote-management and CI/CD platforms carry outsized blast radius. Confidence is high: KEV anchors, vendor advisories, and independent research align.
CISA KEVVENDOR ADVISORYPUBLIC RESEARCH
IDENTITY & HUMAN ATTACK PRESSURE→
STEADY
Commodity phishing kits now automate OAuth device-code abuse; ClickFix-style lures continue delivering infostealers.
RATIONALE & SOURCE TYPES
The Greatness phishing-as-a-service kit added device-code phishing to bypass MFA and steal tokens — commoditizing a technique previously seen in targeted campaigns — while ClickFix lures push macOS infostealers for credential and wallet theft. Confidence is medium: sustained elevated activity, no verified step-change.
INCIDENT REPORTING
INTRUSION / RANSOMWARE TEMPO→
STEADY
Amgen discloses a material data-exfiltration incident; government and financial-sector intrusions continue at last week's elevated tempo.
RATIONALE & SOURCE TYPES
Amgen's Item 1.05 8-K discloses exfiltration of proprietary data and patient health information from third-party cloud environments (materiality determined July 29). A Swiss government SharePoint breach compromised roughly 200 accounts, an extortion cluster targets hedge funds, and INC ransomware dominates exploitation of SonicWall SMA appliances. Held steady: sustained high-impact activity consistent with last week's raised level, no further step-change. Confidence is medium: disclosure lag limits week-level precision.
PUBLIC DISCLOSUREINCIDENT REPORTING
THREE MOVES THIS WEEK
01Patch N-able N-central to 2026.3 HF1 now, audit Take Control sessions and tunnel binaries on managed endpoints — and require the same of your MSP.
02Patch TeamCity, Tomcat, and Langflow; remove build and automation servers from direct internet exposure.
03Constrain OAuth device-code sign-ins in conditional access — commodity phishing kits now automate that path.
WHY WE BELIEVED THIS
RECEIPT LOG · WEEK 339 RECEIPTS
REVISION HISTORY
2026-08-10 · 14:00 UTCOriginal publication.
← FULL ARCHIVE