DEFENDERS CLOCK
THE PUBLIC OPERATING SIGNAL FOR DEFENDERS
ISSUED 2026-09-14 · 14:00 UTC
ARCHIVED READING · PERMANENT RECORD

WEEK OF AUGUST 17, 2026

64/ 100HIGH PRESSURE

Exploitation broadens for a third week — firewalls, hypervisors, Windows zero-days — and ransomware crews convert last month's edge-device access; pressure climbs within the high band.

↑ 3 POINTS SINCE LAST WEEK2026-W34ISSUED 2026-08-17 · 14:00 UTCMETHODOLOGY V1.0

SIGNALS

ACTIVE EXPLOITATION
RISING

A third consecutive rising week, now spanning firewall appliances, hypervisor management, business-intelligence servers, and Windows kernel zero-days.

CONFIDENCE · HIGH
IDENTITY & HUMAN ATTACK PRESSURE
STEADY

Adversary-in-the-middle phishing targets payroll workflows; published passkey-attack research is a watch item, not yet observed in the wild.

CONFIDENCE · MEDIUM
INTRUSION / RANSOMWARE TEMPO
RISING

Ransomware operations are converting last month's edge-device exploitation into deployments; CISA issues a #StopRansomware advisory for Gunra.

CONFIDENCE · MEDIUM

THREE MOVES THIS WEEK
01Patch the actively exploited set — Cisco ASA/FTD, VMware vCenter, Progress LoadMaster, Metabase, and this month's Windows zero-days — internet-facing systems first.
02Hunt for ransomware staging behind any N-able or Fortinet exposure from the past month; assume initial access has already changed hands.
03Keep payroll and finance mailboxes behind AitM-resistant auth and alert on new inbox rules; track the passkey research — no control changes warranted yet.

WHY WE BELIEVED THIS

RECEIPT LOG · WEEK 3410 RECEIPTS
CISA KEV · ANCHORCISA adds Cisco ASA/FTD, Windows AFD, and Metabase CVEs to the KEV catalogCVE-2026-20349, CVE-2026-68820 (AFD zero-day; reporting ties exploitation to Lazarus), CVE-2026-72898 EXPLOITATION · 2026-08-11
CISA KEV · ANCHORCISA adds Progress LoadMaster CVE-2026-8037 to the KEV catalog792 reported exploit attempts before KEV listing EXPLOITATION · 2026-08-07
VENDOR ADVISORY · CORROB.Cisco advisory: ASA/FTD heap inspection vulnerability (exploited) EXPLOITATION · 2026-08-11
INCIDENT REPORTING · CORROB.BleepingComputer: critical VMware vCenter RCE exploited for reverse SSH access EXPLOITATION · 2026-08-13
GOV ADVISORY · ANCHORCISA #StopRansomware advisory: Gunra ransomware (AA26-222A) INTRUSION · 2026-08-10
INCIDENT REPORTING · CORROB.The Hacker News: Gunra ransomware exploits Fortinet FortiOS/FortiProxy flaws INTRUSION · 2026-08-11
INCIDENT REPORTING · CORROB.BleepingComputer: Polish energy plant breached via private APN (December 2025 incident, disclosed by CERT Polska)Historical incident newly disclosed — informative for OT defenders, does not move this week's tempo INTRUSION · 2026-08-11
INCIDENT REPORTING · ANCHORThe Hacker News: Microsoft 365 AitM phishing collects payroll and finance emails IDENTITY · 2026-08-07
INCIDENT REPORTING · CORROB.The Hacker News: new passkey attacks claim synced-key recovery and MFA bypass (research)Research disclosure only — no in-the-wild attacks observed at publication IDENTITY · 2026-08-10
REVISION HISTORY
2026-08-17 · 14:00 UTCOriginal publication.
READINGS ARE IMMUTABLE ONCE PUBLISHED · CORRECTIONS APPEND TO THE REVISION HISTORY ABOVE · RUBRIC AT /METHODOLOGY
← FULL ARCHIVE