DEFENDERS CLOCK
THE PUBLIC OPERATING SIGNAL FOR DEFENDERS
ISSUED 2026-09-14 · 14:00 UTC
ARCHIVED READING · PERMANENT RECORD

WEEK OF AUGUST 10, 2026

61/ 100HIGH PRESSURE

Exploited flaws in remote-management and developer infrastructure drive a second week of rising exploitation; the reading crosses into high pressure.

↑ 2 POINTS SINCE LAST WEEK2026-W33ISSUED 2026-08-10 · 14:00 UTCMETHODOLOGY V1.0

SIGNALS

ACTIVE EXPLOITATION
RISING

Five KEV additions in one week, led by an N-able N-central authentication bypass exploited through an incomplete patch — with confirmed customer compromises and pivots into managed endpoints.

CONFIDENCE · HIGH
IDENTITY & HUMAN ATTACK PRESSURE
STEADY

Commodity phishing kits now automate OAuth device-code abuse; ClickFix-style lures continue delivering infostealers.

CONFIDENCE · MEDIUM
INTRUSION / RANSOMWARE TEMPO
STEADY

Amgen discloses a material data-exfiltration incident; government and financial-sector intrusions continue at last week's elevated tempo.

CONFIDENCE · MEDIUM

THREE MOVES THIS WEEK
01Patch N-able N-central to 2026.3 HF1 now, audit Take Control sessions and tunnel binaries on managed endpoints — and require the same of your MSP.
02Patch TeamCity, Tomcat, and Langflow; remove build and automation servers from direct internet exposure.
03Constrain OAuth device-code sign-ins in conditional access — commodity phishing kits now automate that path.

WHY WE BELIEVED THIS

RECEIPT LOG · WEEK 339 RECEIPTS
CISA KEV · ANCHORCISA adds N-able N-central CVE-2026-18577 to the KEV catalogAuth bypass via incomplete patch; exploited since Aug 1; N-able confirms customer compromises EXPLOITATION · 2026-08-03
CISA KEV · ANCHORCISA adds N-central CVE-2026-18556, Tomcat CVE-2026-34486, Langflow CVE-2026-9198 to the KEV catalogTeamCity CVE-2026-63077 followed on Aug 5 EXPLOITATION · 2026-08-04
VENDOR ADVISORY · CORROB.JetBrains advisory: TeamCity CVE-2026-63077 deserialization EXPLOITATION · 2026-08-05
PUBLIC RESEARCH · CORROB.Rapid7: CVE-2026-18577 N-central authentication bypass exploited in the wild EXPLOITATION · 2026-08-03
INCIDENT REPORTING · ANCHORThe Hacker News: Greatness PhaaS adds device-code phishing to bypass MFA IDENTITY · 2026-08-04
INCIDENT REPORTING · CORROB.BleepingComputer: ClickFix attack pushes macOS infostealer for crypto theft IDENTITY · 2026-08-06
PUBLIC DISCLOSURE · ANCHORAmgen SEC 8-K (Item 1.05): material cybersecurity incidentProprietary data and patient PHI exfiltrated from third-party cloud environments; materiality determined Jul 29 INTRUSION · 2026-07-31
INCIDENT REPORTING · CORROB.BleepingComputer: Swiss government SharePoint breach compromised 200 accounts INTRUSION · 2026-08-06
INCIDENT REPORTING · CORROB.The Hacker News: INC ransomware dominates exploitation of SonicWall SMA 1000 flaws INTRUSION · 2026-08-03
REVISION HISTORY
2026-08-10 · 14:00 UTCOriginal publication.
READINGS ARE IMMUTABLE ONCE PUBLISHED · CORRECTIONS APPEND TO THE REVISION HISTORY ABOVE · RUBRIC AT /METHODOLOGY
← FULL ARCHIVE