Cyber Threat Brief — August 3 2026

⚠️ This report is AI-generated. Always validate findings.

No new actionable threats meeting the 24-hour disclosure, actionable-artifact, and detectable-log-source gates were identified on August 3, 2026.

Status Updates

  • CVE-2026-42897 (Microsoft Exchange OWA XSS): Proofpoint attributed exploitation to TA488/Laundry Bear/Void Blizzard (Russian-aligned). OWAReaper browser implant persists through credential rotation and device reimaging. Half-click exploitation: viewing crafted email triggers XSS. Targets US/European government, telecom, financial, hospitality, aerospace. Permanent patch delivered June 10 Patch Tuesday. Original brief.
  • CVE-2026-20316 (Cisco Secure FMC): Federal CISA KEV deadline passed August 1. Static credential zero-day exploitation ongoing. Hot fixes available for FMC 7.0/7.2/7.4/7.6/7.7/10.0. Rotate all credentials stored on appliance. Original brief.
  • CVE-2026-6875 (ServiceNow AI Platform): Active exploitation entering third week without CISA KEV listing. Two sandbox-escape gadget chains confirmed. Fortune 500 and critical infrastructure victims. Patch regardless of KEV status.
  • CVE-2026-12569 (PTC Windchill/FlexPLM): Cl0p ransomware extortion ongoing via support@cryptohox[.]com. JSP webshells under /Windchill/login/[0-9a-f]{16}.jsp. C2 IP 5.180.41.35. Original brief.
  • LegacyHive-Windows-LPE: Still UNPATCHED by Microsoft. ACROS Security 0patch micropatches available since July 20. Original brief.