The Signal, An Offensive Intelligence Digest (Volume 002)
Welcome to the 2nd edition of The Signal, a newsletter designed to improve your signal-to-noise ratio. A monthly digest curated by our Offensive Security Operations Center (OSOC), delivering timely insights into emerging vulnerabilities, threat trends, and the exposures that matter most.
August 2026 In Review: 5 Vulnerabilities Under Active Exploitation, 4 Threat Actors to Watch
OSOC's monthly breakdown of what adversaries actually exploited last month, not what they could theoretically do, and what to patch first.
Legacy annual pentesting can't keep pace with a threat landscape that moves like this. In August 2026, CISA added 29 new entries to its Known Exploited Vulnerabilities (KEV) catalog — 12 of them Critical. Evolve Security's Offensive Security Operations Center (OSOC) independently tracked five vulnerabilities under active exploitation in the wild and four distinct threat actors behind the activity: one nation-state group, two ransomware operators, and a financially motivated group scanning roughly 170,000 URLs worldwide.
This is our monthly read on what adversaries actually did last month, who did it, and what it means for your program. Review the sections below, assess your exposure, and prioritize patching accordingly.
August 2026 By the Numbers
• 5 vulnerabilities confirmed exploited in the wild: 4 Critical, 1 High
• 29 new CISA KEV catalog additions: 12 Critical, 12 High, 5 Medium
• 9.8 highest CVSS score of the month: CVE-2026-59310, the VMware vCenter zero-day
• 4 threat actors tracked: 1 nation-state, 2 ransomware operators, 1 financially motivated scanning operation
• 361 confirmed victim IPs across 47 countries tied to a single coordinated ransomware campaign
Lazarus Group — Nation-State (North Korea)
Weaponized a Windows AFD.sys use-after-free zero-day (CVE-2026-68820) through Operation Dream Job, its long-running fake-recruiter phishing lure, to precisely target engineers and program staff at defense and aerospace firms across Europe, India, and Brazil. The payload: a trojanized PDF viewer backdoor (“Troy”) that loads the FudModule v3.1 kernel-mode rootkit to blind EDR telemetry.
UAT-10147 — Cybercriminal (China-linked, unattributed to a state)
Runs broad, internet-wide scanning against roughly 170,000 URLs, chaining aging Linux privilege-escalation bugs with fresher RCE flaws like CVE-2021-23758. Notable for using agentic AI tooling (DeepAudit, PentestGPT-style) to automate exploit refinement, reconnaissance, and post-exploitation — then deploying the SPECTRE cross-platform implant and BadIIS persistence module for SEO fraud and data theft.
Babuk-Derived Ransomware Affiliates — Financially Motivated
A coordinated actor or affiliate group mass-exploited the VMware vCenter path-traversal zero-day (CVE-2026-59310) to deploy Babuk-derived ransomware, compromising 361 confirmed victim IPs across 47 countries. Researchers describe the pattern as coordinated, not opportunistic — and the group is deliberately sabotaging backup infrastructure before encrypting.
Gunra Ransomware (“Golden Community”) — Financially Motivated
Subject of a joint CISA/FBI #StopRansomware advisory issued August 10, 2026. Built on leaked 2022 Conti source code, Gunra moved to a ransomware-as-a-service model in 2026, exploiting internet-facing firewall and VPN appliances for initial access before moving laterally via SMB/RDP, stealing credentials (Mimikatz, secretsdump.py), exfiltrating through OneDrive/SharePoint, and encrypting with ChaCha20 + RSA-4096.
The 5 Vulnerabilities Under Active Exploitation
Active exploitation in the wild — not merely disclosure — was the bar for inclusion. Every entry below is validated against CISA advisories and public threat-actor reporting.
1. CVE-2026-59310 — Broadcom VMware vCenter Server (CVSS 9.8, Critical)
Path traversal allowing unauthenticated remote code execution against vCenter's management interface. Since Broadcom's July 29 patch, ransomware affiliates have mass-exploited it, hitting Germany, the U.S., Turkey, Iran, and France hardest.
Do this: patch immediately if you haven't; take vCenter management interfaces off any internet-facing path; segment access; audit backup infrastructure for signs of compromise.
2. CVE-2026-68820 — Microsoft Windows AFD.sys (CVSS 7.0, High)
A use-after-free race condition in the Ancillary Function Driver for WinSock lets a local attacker escalate to SYSTEM. Weaponized by Lazarus Group via Operation Dream Job spear-phishing.
Do this: confirm Microsoft's August 11 Patch Tuesday update is deployed fleet-wide; layer in kernel driver integrity monitoring and application allow-listing; enforce phishing-resistant MFA.
3. CVE-2026-8452 — Citrix NetScaler ADC & Gateway (CVSS 9.8, Critical)
Originally cataloged as denial-of-service, watchTowr Labs showed this memory-buffer flaw chains into full unauthenticated RCE. Exploitation began almost immediately after a public PoC dropped, with attackers planting web shells (x.php, z.php).
Do this: patch to 14.1-72.61, 13.1-63.18, 13.1-37.272, or later; hunt for unfamiliar .php web shells; review external-facing logs for anomalous requests.
4. CVE-2021-23758 — Ajax.NET Professional (CVSS 9.8, Critical)
A deserialization flaw in an end-of-life library allowing RCE via arbitrary .NET class instantiation. UAT-10147 has folded this and several aging Linux privilege-escalation CVEs into a broad, AI-assisted intrusion set against government, education, media, technology, and gaming targets.
Do this: decommission or isolate any internet-facing Ajax.NET Professional instances — there's no forthcoming patch; where legacy Linux hosts can't be patched, apply compensating kernel hardening and watch for SPECTRE/BadIIS indicators.
5. CVE-2026-18577 — N-able N-central (CVSS 9.1, Critical)
Authentication bypass enabling account takeover in this MSP remote-monitoring platform; the first fix was incomplete before a hotfix closed the gap. Huntress confirmed active exploitation against MSP-hosted servers, with attackers abusing the default “MSP Support” account to blend in.
Do this: upgrade self-hosted N-central to 2026.3.1.7 (Hotfix 1) or later without delay; search managed endpoints for unexpected svchost.exe files and “Cloudflared” services; review Take Control session logs.
12 Critical Vulnerabilities Added to CISA's KEV Catalog
Beyond the five actively exploited CVEs above, CISA's August additions included 12 more rated Critical. Federal agencies must remediate by the stated due dates — every organization should treat KEV additions as high-priority signals regardless of federal mandate:
• CVE-2023-49105 — ownCloud Core (improper authentication): due 2026-08-30
• CVE-2021-23758 — Ajax.NET Professional (deserialization): due 2026-09-09
• CVE-2026-8452 — Citrix NetScaler ADC/Gateway (buffer restriction): due 2026-08-29
• CVE-2019-1068 — Microsoft SQL Server (remote code execution): due 2026-08-29
• CVE-2026-73570 — Synacor Zimbra Collaboration Suite (OS command injection): due 2026-08-24
• CVE-2026-33824 — Microsoft IKE Service Extensions (double free): due 2026-08-21
• CVE-2026-59310 — Broadcom VMware vCenter Server (path traversal): due 2026-08-21
• CVE-2026-72898 — Metabase (SQL injection): due 2026-08-14
• CVE-2026-8037 — Progress LoadMaster (command injection): due 2026-08-10
• CVE-2026-63077 — JetBrains TeamCity (deserialization): due 2026-08-08
• CVE-2026-9198 — IBM Langflow (code injection): due 2026-08-07
• CVE-2026-18577 — N-able N-central (authentication bypass): due 2026-08-06
The remaining 12 High and 5 Medium entries are in CISA's full catalog: cisa.gov/known-exploited-vulnerabilities-catalog
What This Means for Your Program
August's exploited vulnerabilities reflect continued adversary focus on edge devices, enterprise application stacks, and OS privilege-escalation paths. Nation-state actors and ransomware operators are weaponizing newly disclosed CVEs within days of public disclosure, exploit development timelines keep compressing, not lengthening.
Your actual risk depends on four variables: asset exposure (internet-facing vs. internal), patch cadence, EDR coverage and detection-rule freshness, and whether compensating controls exist for what you can't patch immediately.
Organizations that maintain continuous visibility into their attack surface and prioritize patching against KEV and actively-exploited CVEs materially reduce their exposure window. That's the whole premise behind Continuous Penetration Testing (CPT): validation that your compensating controls still hold between patch cycles, not a once-a-year snapshot of a moving target.
Questions or Need Help Remediating?
Our team is here for yours. If any of the above touches your environment, talk to Evolve Security's OSOC, we'll help you validate exposure and prioritize what to fix first.
Start Playing Offense. Contact Evolve Security's Offensive Security Operations Center to talk through this month's findings.
Stay in the know. Subscribe to our monthly offensive intelligence digest THE SIGNAL





