DEFENDERS CLOCK
THE PUBLIC OPERATING SIGNAL FOR DEFENDERS
ISSUED 2026-09-14 · 14:00 UTC
ARCHIVED READING · PERMANENT RECORD

WEEK OF AUGUST 24, 2026

66/ 100HIGH PRESSURE

The heaviest KEV week yet — eight additions reaching machine-learning infrastructure — while an active threat to Siemens PLCs keeps critical-infrastructure pressure high.

↑ 2 POINTS SINCE LAST WEEK2026-W35ISSUED 2026-08-24 · 14:00 UTCMETHODOLOGY V1.0

SIGNALS

ACTIVE EXPLOITATION
RISING

Eight KEV additions in one week — a new volume high — including a second VMware vCenter flaw used to deploy ransomware, and a first: exploited machine-learning infrastructure (MLflow, Ray).

CONFIDENCE · HIGH
IDENTITY & HUMAN ATTACK PRESSURE
STEADY

Browser-in-the-browser credential traps scale through recruitment lures; OAuth and app-linking abuse continues alongside package-registry credential theft.

CONFIDENCE · MEDIUM
INTRUSION / RANSOMWARE TEMPO
STEADY

CISA warns of an active threat to Siemens S7 PLCs in US critical infrastructure; healthcare's fifth-largest breach of the year is confirmed at 3.75M patients.

CONFIDENCE · MEDIUM

THREE MOVES THIS WEEK
01Patch the eight-CVE KEV set — vCenter again, SharePoint, IKE, macOS, TrueConf — and treat MLflow and Ray as production attack surface if you run ML infrastructure.
02If you operate Siemens S7 PLCs, apply CISA advisory AA26-231A now and isolate engineering workstations — AI-generated exploit scripts are in active use.
03Coach recruiting-adjacent staff on browser-in-the-browser login traps, and audit OAuth app-linking consents on mail and messaging accounts.

WHY WE BELIEVED THIS

RECEIPT LOG · WEEK 3510 RECEIPTS
CISA KEV · ANCHORCISA adds vCenter, SharePoint, IKE, and macOS CVEs to the KEV catalogCVE-2026-59310, CVE-2026-55040, CVE-2026-33824, CVE-2026-65400 EXPLOITATION · 2026-08-18
CISA KEV · ANCHORCISA adds TrueConf Server CVEs to the KEV catalogWith Ray (Aug 17) and MLflow (Aug 19), eight KEV additions this window — the highest weekly volume since launch EXPLOITATION · 2026-08-20
VENDOR ADVISORY · CORROB.Broadcom advisory: VMware vCenter path traversal (exploited) EXPLOITATION · 2026-08-18
INCIDENT REPORTING · CORROB.BleepingComputer: CISA warns of hackers exploiting critical MLflow vulnerabilitySSRF exploited to steal cloud credentials from ML infrastructure EXPLOITATION · 2026-08-20
GOV ADVISORY · ANCHORCISA AA26-231A: defending against an active threat to Siemens S7 PLCsAI-generated exploit scripts actively targeting US critical infrastructure; held pending evidence of successful intrusions INTRUSION · 2026-08-19
INCIDENT REPORTING · CORROB.BleepingComputer: CareCloud breach impacts 3.7 million patientsMarch AWS intrusion; scale confirmed to HHS this week — fifth-largest health-data theft of 2026 INTRUSION · 2026-08-19
INCIDENT REPORTING · CORROB.The Hacker News: suspected Russian hackers abuse Google OAuth and WhatsApp linking IDENTITY · 2026-08-20
REVISION HISTORY
2026-08-24 · 14:00 UTCOriginal publication.
READINGS ARE IMMUTABLE ONCE PUBLISHED · CORRECTIONS APPEND TO THE REVISION HISTORY ABOVE · RUBRIC AT /METHODOLOGY
← FULL ARCHIVE