All Issues
Threat Intelligence Monthly Roundup · August 2026

August Roundup 2026: Threat Intelligence

Published September 1, 2026

August was a waiting game on the policy side and a fast-moving one on the threat side. The CMMC Reform Task Force's public comment window closed on schedule August 14, exactly as set out in July's suspension memo — and the Department of War has said nothing since about how many comments came in or which direction the review is leaning. The task force's report is still expected "around mid-September," which means contractors go another month without a clearer answer on Phase 2's fate. What did move in August: prime contractors kept tightening CMMC Level 2 flow-down language in their own subcontracts, a trend we first flagged in June and one that's now doing more to force subcontractor readiness than the paused federal deadline is. On the threat side, a newly disclosed pre-authentication remote code execution flaw in Kiteworks' Secure File Gateway — a platform defense primes and suppliers use to exchange CAD files, bills of materials, and CUI-adjacent engineering data — went from disclosure to confirmed exploitation in five days, and ransomware activity held near its 2026 highs for a third straight month.

Major Incidents

Kiteworks Secure File Gateway: Pre-Auth RCE Exploited Within Days, Espionage Pattern Suspected: CVE-2026-41207 (CVSS 9.6), a pre-authentication remote code execution flaw in Kiteworks' Secure File Gateway, was publicly disclosed August 6. Kiteworks shipped a patch two days later on August 8, but that wasn't fast enough — researchers confirmed active exploitation in the wild by August 11, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 12 with an August 26 federal remediation deadline. Early incident-response reporting points to data staging and exfiltration rather than extortion, a different signature than July's Windchill campaign and one more consistent with espionage-motivated activity than a ransomware crew angling for a payday. Kiteworks is widely used by defense primes and their suppliers specifically to move CAD files, bills of materials, and other CUI-adjacent engineering data across organizational boundaries — which makes this the month's most directly relevant incident for a CMMC-scoped readership, in the same way Windchill was in July.

Halberd Precision Castings: Ransomware Idles Aerospace Forging Lines for Nine Days: A ransomware intrusion attributed to Qilin knocked Halberd Precision Castings, a Midwest aerospace and defense forging subcontractor, offline for nine days in mid-August, halting casting production for several Tier 1 aerospace customers. Qilin's leak site claims theft of engineering drawings and supplier contract data; Halberd has not confirmed the scope of what was taken. As with Fairlife in July, the specific product is beside the point — a ransomware crew idling a physical production line for over a week is exactly the operational-continuity failure mode CMMC's supply-chain provisions exist to prevent, and it happened to an actual aerospace subcontractor this time, not an analogy.

Meridian Behavioral Health Network: Large Healthcare Ransomware Claim: The Gentlemen claimed an attack on Meridian Behavioral Health Network, a multi-state outpatient provider, asserting theft of patient records, billing data, and internal clinical documentation. Meridian says it's still validating the scope of the claim. Healthcare remained the single most consistently targeted sector in August per every tracker reviewed this month (see Ransomware Trends below), and this is the largest single claimed healthcare incident of the month by data volume.

Torvane Marine Systems: Norwegian Shipbuilder's Subcontractor Network Breached: A threat group calling itself SaltFathom claimed a breach of Torvane Marine Systems, a Norwegian naval and offshore-vessel systems integrator, asserting access to a shared supplier portal used by roughly a dozen subcontractors across Scandinavia and the Baltic states. Torvane says it has isolated the affected portal and is notifying impacted suppliers. As with Nidec last month, the actual entry point according to early reporting wasn't Torvane's own perimeter but a smaller subcontractor with weaker controls sitting inside its supplier network — the same fourth-party risk pattern defense primes are increasingly being asked to account for in their own flow-down requirements.

Critical Vulnerabilities

CVE-2026-41207 (Kiteworks Secure File Gateway, CVSS 9.6): Covered above under Major Incidents given its direct relevance to defense-adjacent file exchange — included here as well since it's also the month's top vulnerability by both severity and exploitation speed. Organizations running Kiteworks Secure File Gateway that have not yet applied the August 8 patch should treat this as an emergency change, not a routine one.

CVE-2026-61120 (Ivanti Endpoint Manager Mobile, CVSS 9.8): Authentication Bypass Chained With a Second Flaw for Full Device Takeover: Ivanti disclosed an authentication bypass in Endpoint Manager Mobile on August 5 that, when chained with a lower-severity API injection flaw (CVE-2026-61121, CVSS 7.2) patched in the same advisory, allows an unauthenticated attacker to enroll a rogue device and push arbitrary configuration profiles to every managed endpoint. Ivanti confirmed limited exploitation of the chained pair prior to disclosure; CISA added CVE-2026-61120 to the KEV catalog August 7 with an August 21 federal deadline. Any organization using EPMM for mobile device management — common among distributed contractor workforces — should confirm both CVEs are patched, not just the higher-severity one.

CVE-2026-53390 (Fortinet FortiWeb, CVSS 9.1): Web Application Firewall Bypass Enabling Backend Access: A flaw in FortiWeb's request-parsing logic allows a specially crafted HTTP request to bypass WAF rule enforcement entirely and reach the backend application unfiltered. Fortinet patched August 19; CISA added it to KEV August 22, noting exploitation attempts against internet-facing FortiWeb deployments protecting VPN and remote-access portals. Because the whole point of a WAF is to be the layer other controls rely on, this one is worth prioritizing even where FortiWeb isn't the primary perimeter device.

A Steady Month for the KEV Catalog: Beyond the headline items above, CISA added at least 14 vulnerabilities to its Known Exploited Vulnerabilities catalog across four batches in August, including flaws in Citrix NetScaler ADC, Zimbra Collaboration Suite, and a second, lower-severity Ivanti Connect Secure issue unrelated to the EPMM chain above. Organizations running any of these products should confirm patch status against CISA's published deadlines directly, rather than relying on a vendor's own release notes to flag urgency.

Ransomware Trends

761 Claimed Attacks, Third-Highest Month of 2026: Comparitech's August tracker recorded 761 claimed ransomware attacks, down modestly from July's 799 but still the third-highest month of the year so far — confirming July wasn't a one-off spike but part of a sustained elevated baseline. As always, claimed and independently confirmed are different numbers; treat leak-site totals as an activity indicator, not a verified breach count.

The Gentlemen and Qilin Hold the Top Two Spots Again: The Gentlemen and Qilin again led claimed activity in August, together accounting for roughly a third of the month's total — the same concentration seen in July. No new defense-adjacent or NATO-affiliated victim emerged on the scale of July's Indra Group incident, though Qilin's attack on Halberd Precision Castings (above) shows the group's aerospace-subcontractor targeting from earlier in the year hasn't let up.

Healthcare Still the Most Consistent Target: Healthcare remained the sector most consistently hit across every tracker reviewed this month, a pattern that has now held for multiple consecutive months. Manufacturing-sector ransomware claims stayed roughly flat month-over-month, but — as with the Kiteworks and Torvane incidents above — supply-chain risk to manufacturers is increasingly showing up through mass software exploitation and shared-portal compromise rather than classic opportunistic ransomware deployment.

Government Advisories and Nation-State Threats

CISA/NSA Joint Advisory on Chinese State-Affiliated Targeting of Managed File Transfer Products: CISA and the NSA issued a joint advisory August 13 warning that a China-linked actor CISA tracks internally as a distinct cluster has been targeting managed file transfer and secure file exchange products broadly — the advisory does not name Kiteworks specifically, but its publication four days after CVE-2026-41207's disclosure drew immediate attention given the overlap in product category. The advisory recommends network segmentation for MFT platforms and logging review going back to July 1 for any organization running affected product categories.

DHS/FBI Advisory on Physical Security Convergence Risk at Manufacturing Facilities: A joint DHS/FBI advisory issued August 20 highlighted a rise in incidents where compromised building-access and physical-security systems at manufacturing sites were used as an initial foothold into adjacent IT networks, rather than the reverse. The advisory is framed around manufacturing broadly rather than defense contractors specifically, but it's a direct fit for CMMC's physical-security control family (PE) and worth a look for any facility that has never mapped how its badge-access and camera systems connect to its production network.

AI-Enabled Threats

Vishing activity held at the elevated levels flagged in July's report, with no major new dataset published in August to move the needle either direction — CrowdStrike's mid-2026 doubling finding remains the most current baseline. What did surface this month was a handful of scattered reports, not yet aggregated into a formal tracker, of AI-generated voice clones being used in follow-up calls after an initial vishing contact to add false legitimacy to a request for a credential reset or wire transfer — the same underlying tactic, with an added layer meant to survive a skeptical callback if the callback number itself isn't independently verified. We did not find a verified incident this month naming a defense contractor specifically. The practical guidance is unchanged from July and June: out-of-band verification against a number established before the request, not one supplied during it, remains the most reliable control regardless of how convincing the voice on the other end sounds.

CMMC and Compliance Updates

CMMC Reform Task Force RFI Window Closes August 14 — Still No Signal From DoD: The public Request for Information window that July's suspension memo scheduled closed on time August 14, 2026. As of this writing, DoD has disclosed nothing about how many comments were submitted or what direction they leaned, and has not moved up its own timeline. The task force's report remains expected "around mid-September" — unchanged from what the July memo projected a month ago. This is a genuinely "still waiting" update, not a resolution: Phase 2's third-party certification requirement remains suspended, Phases 3 and 4 remain frozen, and the November 10, 2026 deadline that anchored the pre-suspension compliance conversation is still not an active enforcement date. Nothing here should be read as a signal in either direction about where the review is heading.

Prime Contractors Keep Tightening Flow-Down Requirements — Now the Real Forcing Function: The trend first flagged in June's report continued through August: individual prime contractors are writing CMMC Level 2-equivalent security requirements directly into their own subcontracts, independent of where the federal rulemaking process lands. With the DoD-level deadline paused and no new information from the task force, prime flow-down language is now doing more to force subcontractor readiness on a practical, month-to-month basis than the suspended federal timeline is. Subcontractors waiting for federal clarity before starting remediation work are, in practice, waiting on the wrong signal — their actual near-term deadline is likely to arrive in their next subcontract renewal, not in a Federal Register notice.

CGA's Gap Assessment Grant Splits Into Two Tracks: CGA has restructured its CMMC Gap Assessment Grant program from a single combined offering into two separate tracks matched to certification level: the CMMC Level 1 Gap Assessment Grant for contractors handling Federal Contract Information (FCI) only, and the CMMC Level 2 Gap Assessment Grant for contractors handling Controlled Unclassified Information (CUI) and scoped against the full 110-control NIST SP 800-171 baseline. Both remain fully funded, in-kind professional assessments at no cost to the applicant. The change reflects that Level 1 and Level 2 organizations are working from meaningfully different control sets and starting points, and a single combined grant page was making it harder for applicants to tell which scope of assessment actually applied to them. With third-party verification still paused and prime flow-down pressure doing the real forcing (above), a scoped self-funded gap assessment against the correct control set remains the most concrete step a contractor can take this month regardless of how the federal review concludes.

Concerned about your cybersecurity posture?

CGA offers grants to help defense contractors assess and improve their compliance with CMMC and NIST SP 800-171.

View Grant Programs