ARCHIVED READING · PERMANENT RECORD
WEEK OF AUGUST 17, 2026
64/ 100HIGH PRESSURE
Exploitation broadens for a third week — firewalls, hypervisors, Windows zero-days — and ransomware crews convert last month's edge-device access; pressure climbs within the high band.
↑ 3 POINTS SINCE LAST WEEK2026-W34ISSUED 2026-08-17 · 14:00 UTCMETHODOLOGY V1.0
SIGNALS
ACTIVE EXPLOITATION↑
RISING
A third consecutive rising week, now spanning firewall appliances, hypervisor management, business-intelligence servers, and Windows kernel zero-days.
RATIONALE & SOURCE TYPES
CISA added Cisco ASA/FTD CVE-2026-20349, Windows AFD CVE-2026-68820 (reporting ties active exploitation to Lazarus), and Metabase CVE-2026-72898 to KEV on Aug 11, after Progress LoadMaster CVE-2026-8037 on Aug 7 (792 reported exploit attempts). VMware vCenter RCE is exploited for persistent reverse-SSH access, and a SharePoint authentication bypass is exploited following a public PoC. Confidence is high: KEV anchors, vendor advisories, and independent reporting align.
CISA KEVVENDOR ADVISORYINCIDENT REPORTING
IDENTITY & HUMAN ATTACK PRESSURE→
STEADY
Adversary-in-the-middle phishing targets payroll workflows; published passkey-attack research is a watch item, not yet observed in the wild.
RATIONALE & SOURCE TYPES
Microsoft 365 AitM phishing campaigns hijack accounts to silently collect payroll and finance mail; developer-supply-side credential theft continues (~800 malicious npm packages, trojanized VS Code extensions). New research claims recovery of synced passkey private keys and bypass of phishing-resistant MFA — a watch item: research-only, no observed attacks. Confidence is medium: sustained pressure, no verified step-change.
INCIDENT REPORTING
INTRUSION / RANSOMWARE TEMPO↑
RISING
Ransomware operations are converting last month's edge-device exploitation into deployments; CISA issues a #StopRansomware advisory for Gunra.
RATIONALE & SOURCE TYPES
CISA and partners published a #StopRansomware advisory for Gunra (Aug 10), which reporting shows actively exploiting Fortinet FortiOS/FortiProxy flaws for network access; a China-linked actor is deploying the new StormEncryptor ransomware likely via the N-able N-central flaw from two weeks ago — exploited edge access converting to ransomware at tempo. Two independent source classes support the raise. Separately, CERT Polska disclosed a December 2025 OT intrusion at a Polish heat-and-power plant (turbine stopped via a private-APN pivot) — informative for OT defenders but a historical incident, not this week's tempo. Confidence is medium: disclosure lag limits week-level precision.
GOV ADVISORYINCIDENT REPORTING
THREE MOVES THIS WEEK
01Patch the actively exploited set — Cisco ASA/FTD, VMware vCenter, Progress LoadMaster, Metabase, and this month's Windows zero-days — internet-facing systems first.
02Hunt for ransomware staging behind any N-able or Fortinet exposure from the past month; assume initial access has already changed hands.
03Keep payroll and finance mailboxes behind AitM-resistant auth and alert on new inbox rules; track the passkey research — no control changes warranted yet.
WHY WE BELIEVED THIS
RECEIPT LOG · WEEK 3410 RECEIPTS
REVISION HISTORY
2026-08-17 · 14:00 UTCOriginal publication.
← FULL ARCHIVE