Leak-Site WatchWeekly
Leak-site watch: read the extortion feed, don't react to it
Updated 12 August 2026 · Timeframe: Ransomware-flagged KEV this week; 52-week trend chart
No newly KEV-listed CVEs were flagged for ransomware use this week — but the leak-site economy runs on recycled access and recycled claims, so a quiet KEV week is not a quiet extortion week.
Why it matters
Leak-site posts are the loudest but least-verified corner of threat intelligence. A listing is a claim, not a confirmation — the number that matters is the confirmation rate, not the claim volume.
What to do
- Security leaders. Don't brief the board off an unconfirmed leak-site listing — corroborate first, then act on the facts that aren't in dispute.
- Lean IT orgs. A leak-site post is a reason to check whether a vendor you rely on is affected, not a reason to panic.
- MSPs. Treat new listings as a supply-chain query across your client base; hold escalation until a claim is corroborated.
Our take
Resilience means reading the signal, not the noise. Grade every claim, corroborate before you escalate, and measure groups by what they confirm — not by how loudly they post.
The data behind this