Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

KEV deadlines fell from 14 days to three

3 min read
16:08UTC

CISA's risk-tiered directive was sold as breathing room. Recounting the catalogue shows the median federal patch deadline has fallen from 14 days to three, and the 60-day checkpoint due next week enforces nothing. We also correct our own June ransomware league table, which the source does not support.

Key takeaway

CISA's directive promised flexibility; its actual deadlines have tightened, and its water-sector advice abandons deadlines altogether.

This briefing mapped
Regulatory
Infrastructure
Diplomatic
Competitive
Economic

CISA gave federal agencies three days to patch a hard-coded password in Cisco's firewall console on 29 July. Recounting the catalogue shows 34 of the 39 entries added since 10 June carry a window that short.

Sources profile:This story draws on neutral-leaning sources
Sources:CISA

CISA's 30 July alert says intruders reaching internet-exposed controllers at water and wastewater plants have already caused boil water notices and forced operators to run plant by hand. Its instruction is to disconnect the controllers, not to patch them.

Sources profile:This story draws on neutral-leaning sources

The Cybersecurity and Infrastructure Security Agency (CISA) published an alert on 30 July 2026. It reported a sharp rise in attackers reaching internet-exposed programmable logic controllers (PLC) at water and wastewater plants of every size. Intruders changed device passwords, locking operators out, and CISA says the activity has already triggered boil water notices and forced sustained manual operation.

Its instruction to operators is to disconnect exposed controllers, not to patch them. 

Sources:CISA

ReliaQuest reported on 23 July that compromised hotel routers are answering guest lookups with attacker-controlled addresses and steering travellers to counterfeit Microsoft 365 sign-in pages. No phishing email is involved and nothing lands on the laptop.

Sources profile:This story draws on neutral-leaning sources

ReliaQuest reported on 23 July 2026 that compromised hotel WiFi routers answer guest lookups with counterfeit Microsoft 365 sign-in pages. The technique, domain name system (DNS) poisoning, redirects travellers without any phishing email or software installed on the laptop.

ReliaQuest found affected devices across several American cities, plus India and Saudi Arabia, harvesting corporate credentials as staff typed them. 

Sources:ReliaQuest

ReliaQuest put the hotel campaign's initial-access route at low-to-medium confidence and named no state actor. heise online reported on 27 July that Russian state attackers were behind it and named APT28.

Sources profile:This story draws on neutral-leaning sources

ReliaQuest held the hotel router intrusion route at low-to-medium confidence, naming no state actor and citing only overlap with a cluster it calls FrostArmada. heise online reported on 27 July 2026 that Russian state attackers ran the campaign, naming APT28 directly.

The two accounts diverge: one hedges on attribution, the other commits to it. 

Leak-site postings tracked by ransomware.live ran The Gentlemen at 31 victims against Qilin's 19 over ten days to 3 August. Group-IB documented that the crew began inside Qilin's own affiliate programme and left over a $48,000 argument.

Sources profile:This story draws on neutral-leaning sources

Leak-site postings tracked by ransomware.live between 24 July and 3 August 2026 put The Gentlemen at 31 victims against Qilin's 19. Group-IB, the Singapore-based investigations firm, reported on 19 March that The Gentlemen began inside Qilin's own affiliate programme under the handle ArmCorp.

The pair split, Group-IB says, after a dispute over a $48,000 revenue share. 

Rockwell published advisory SD1790 on 30 July with no CVE attached, and the NCSC guidance CISA points water operators to is version 1.0 from March 2024. Only the alert itself is new.

Sources profile:This story draws on neutral-leaning sources

Rockwell Automation's advisory SD1790, published 30 July 2026 and revised the next day, covers MicroLogix 1100 and 1400 controllers with no Common Vulnerabilities and Exposures (CVE) attached. It offers operational recovery steps for a locked device, not a patch for a vulnerability.

The Cybersecurity and Infrastructure Security Agency (CISA)'s alert also cites National Cyber Security Centre (NCSC) guidance dating from March 2024. It also cites an FBI bulletin, referenced but never published, on the same targeting. 

BOD 26-04's second checkpoint falls around 9 August and requires agencies only to update internal procedures and hand copies to CISA on request. No public filing exists, and the directive provides no way to name an agency that misses it.

Sources profile:This story draws on neutral-leaning sources
Sources:CISA

River Financial Corporation told the SEC on 30 July that it still cannot say whether its ransomware intrusion is material or whether personal data was taken, resting partly on the attacker's word that the stolen files were deleted.

Sources profile:This story draws on neutral-leaning sources

River Financial Corporation filed a fifth disclosure on 30 July 2026, an amended Form 8-K to the Securities and Exchange Commission (SEC). The intrusion dates from 19 June 2026, over six weeks earlier.

The company still cannot determine whether the breach is material or whether personal data was taken. Part of its assessment rests on the attacker's own claim that stolen data was deleted. 

Sources:SEC EDGAR

CISA catalogued CVE-2026-16812 in Arista's VeloCloud Orchestrator and CVE-2025-68686 in Fortinet FortiOS on 27 July, then CVE-2026-20316 in Cisco's firewall console on 29 July.

Sources profile:This story draws on neutral-leaning sources

The Cybersecurity and Infrastructure Security Agency (CISA) added three flaws to its Known Exploited Vulnerabilities (KEV) catalogue between 24 July and 3 August 2026. Arista Networks supplied CVE-2026-16812, a command injection in VeloCloud Orchestrator due by 30 July, using the Common Vulnerabilities and Exposures (CVE) tracking system.

Fortinet's FortiOS information exposure, CVE-2025-68686, falls due on 10 August. Cisco's hard-coded password flaw in Secure Firewall Management Center, CVE-2026-20316, falls due on 1 August. 

Sources:CISA

The Cyber Security and Resilience Bill reached House of Lords committee stage with a running amendment paper dated 23 July. The status of Lord Alton's transnational-repression amendment could not be confirmed from the published record.

Sources profile:This story draws on neutral-leaning sources

A GOV.UK update records the G7 Cyber Expert Group's 2026 Cross-Border Coordination Exercise as concluded on or before 31 July. No readout has been published.

The G7 Cyber Expert Group's 2026 Cross-Border Coordination Exercise concluded on or before 31 July 2026, according to a UK government update. The group coordinates member states' response to cyber incidents crossing national borders.

No readout, participant list or scenario has been published, and the reason is not on the record. A reader cannot judge whether the exercise met its aims or exposed gaps in cross-border coordination without that detail. 

Sources:GOV.UK
Different Perspectives
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.