ARCHIVED READING · PERMANENT RECORD
WEEK OF AUGUST 24, 2026
66/ 100HIGH PRESSURE
The heaviest KEV week yet — eight additions reaching machine-learning infrastructure — while an active threat to Siemens PLCs keeps critical-infrastructure pressure high.
↑ 2 POINTS SINCE LAST WEEK2026-W35ISSUED 2026-08-24 · 14:00 UTCMETHODOLOGY V1.0
SIGNALS
ACTIVE EXPLOITATION↑
RISING
Eight KEV additions in one week — a new volume high — including a second VMware vCenter flaw used to deploy ransomware, and a first: exploited machine-learning infrastructure (MLflow, Ray).
RATIONALE & SOURCE TYPES
CISA added eight CVEs: VMware vCenter path traversal (exploited by a suspected China-nexus actor deploying Babuk-derived ransomware), Microsoft SharePoint and IKE, Apple macOS (exploited for cryptomining on exposed Macs), TrueConf Server (two), MLflow SSRF (exploited to steal cloud credentials), and Ray code injection — the last two marking ML/AI infrastructure's arrival as exploited attack surface. Zimbra RCE exploitation also confirmed. Fourth consecutive rising week. Confidence is high: KEV anchors, vendor advisories, and independent reporting align.
CISA KEVVENDOR ADVISORYINCIDENT REPORTING
IDENTITY & HUMAN ATTACK PRESSURE→
STEADY
Browser-in-the-browser credential traps scale through recruitment lures; OAuth and app-linking abuse continues alongside package-registry credential theft.
RATIONALE & SOURCE TYPES
Research documents more than 3,000 recruitment-themed browser-in-the-browser phishing URLs; suspected Russian actors abuse Google OAuth and WhatsApp account linking to hijack accounts; TWINLOOT abuses SharePoint and Teams for internal credential theft; and package-registry poisoning continues (typosquatted RubyGems, a poisoned Rust crate). Confidence is medium: broad sustained activity, no verified step-change.
INCIDENT REPORTING
INTRUSION / RANSOMWARE TEMPO→
STEADY
CISA warns of an active threat to Siemens S7 PLCs in US critical infrastructure; healthcare's fifth-largest breach of the year is confirmed at 3.75M patients.
RATIONALE & SOURCE TYPES
CISA's advisory AA26-231A describes AI-generated exploit scripts actively targeting Siemens S7 PLCs in US critical infrastructure — an active threat, held pending evidence of successful intrusions. CareCloud confirmed its March AWS intrusion affects 3.75 million patients (disclosure-lag evidence: the intrusion predates this window). Ransomware deployment via the vCenter flaw and a rogue affiliate re-extorting past victims round out a tempo consistent with recent weeks' raised level. Confidence is medium: disclosure lag limits week-level precision.
GOV ADVISORYINCIDENT REPORTING
THREE MOVES THIS WEEK
01Patch the eight-CVE KEV set — vCenter again, SharePoint, IKE, macOS, TrueConf — and treat MLflow and Ray as production attack surface if you run ML infrastructure.
02If you operate Siemens S7 PLCs, apply CISA advisory AA26-231A now and isolate engineering workstations — AI-generated exploit scripts are in active use.
03Coach recruiting-adjacent staff on browser-in-the-browser login traps, and audit OAuth app-linking consents on mail and messaging accounts.
WHY WE BELIEVED THIS
RECEIPT LOG · WEEK 3510 RECEIPTS
REVISION HISTORY
2026-08-24 · 14:00 UTCOriginal publication.
← FULL ARCHIVE