Entry 001verifiedOFAC · CISA KEV · 4 sourcespublic

Desk note

What official US actions just put on the lookback list

Enforcement flash · 6–12 August 2026
For: trade-finance, sanctions, and international-ops leads
Decision this note serves: whether to run a lookback, tighten a corridor, or send a name out for deeper work.

What's on the official record

Three OFAC actions in one week, plus a cluster of CISA known-exploited vulnerabilities on internet-facing gear.

12 August — an enforcement settlement. OFAC announced a $60,764 settlement with Rice Lake Weighing Systems, Inc. (Wisconsin). OFAC says Rice Lake’s Italian subsidiary, Dini Argeo S.r.l., exported weighing equipment to a UAE distributor between July 2019 and November 2021 knowing the goods were destined for Iran. OFAC treated the case as voluntarily self-disclosed and non-egregious.[1]

7 August — Iran commercial + CT exchange names. OFAC added individuals and entities under Iran secondary-sanctions and counter-terrorism authorities. The commercial set includes UAE general-trading companies, Hong Kong traders in Kwun Tong industrial buildings, a Singapore PTE, and Iran-linked exchange names (including Aban Tether and Titan Exchange). The CT set includes UAE DMCC crypto names, a Georgia-registered Shelbit vehicle, and a Polish Shelbit company in liquidation, with published digital-currency addresses.[2]

6 August — Cuba technical import and military industry. OFAC designated Cuban state technical-import companies (including Tecnotex and Tecnoimport), military-industry names (UIM, EMI Yuri Gagarin), Duna SA, and several individuals, with a State Department release on enablers of Cuban arms imports and foreign military cooperation. Two existing GLOMAG listings were updated onto the Cuba EO program.[3]

11 August — KEV, internet-facing. CISA added actively exploited vulnerabilities in Metabase (unauthenticated SQL injection, CVE-2026-72898), Cisco ASA/FTD VPN (remote DoS, CVE-2026-20349), and a local Windows WinSock elevation (CVE-2026-68820). LoadMaster command injection (CVE-2026-8037) landed 7 August. Federal civilian due dates on the unauthenticated pair were 14 August.[4]

Assessment

Two clocks, one week.

For a sanctions, trade-finance, or corridor committee, the 6–12 August window added names and a diversion pattern. Rice Lake is the path (EU subsidiary → UAE distributor → Iranian end-user), not the dollar amount. The 7 August Iran/CT set is a vehicle-class refresh — published legal names and digital-currency addresses go on the next list pull. The 6 August Cuba adds are specific SOEs (Tecnotex, Tecnoimport, UIM, EMI Yuri Gagarin, Duna SA), not “Cuba” as a word.

For a country GM or sponsor whose operating book includes internet-facing analytics or remote-access gear, the so-what is the 11 August KEV cluster. Metabase and Cisco ASA/FTD change a remote-access and analytics posture this week. That is a facilities question sitting next to the sanctions lookback — same operators, different clock.

For a financial institution, run the new OFAC names and addresses through the next list refresh, and ask whether Metabase or Cisco ASA/FTD sit on the estate. A clean SDN pull does not close the KEV item; a patched pair does not close the lookback.

Call: treat 6–12 August as a lookback window for the named OFAC actions, and treat Metabase / Cisco ASA/FTD as the KEV items that move a posture this week.

What to check next

  1. Iran diversion path. Re-screen counterparties that look like the Rice Lake fact pattern: EU manufacturing subsidiary, UAE distributor, Iranian end-user. The settlement is small. The pattern is the point.
  2. New vehicle classes, 7 August. Add the published legal names and digital-currency addresses from the OFAC notice to the next list refresh. Treat UAE "general trading" LLCs, HK industrial-unit traders, and DMCC exchange names as a class to re-open. Listing status still comes from the file.
  3. Cuba technical import. If the book touches Cuban spare parts, dual-use equipment, or military-adjacent procurement, run the new SOE names (Tecnotex, Tecnoimport, UIM, EMI Yuri Gagarin, Duna SA) through the next SDN file.
  4. KEV on the same clock. Metabase and Cisco ASA/FTD are the ones that change a remote-access and analytics posture this week. That is a facilities question sitting beside the sanctions lookback — same operators, different clock.

Whether a named bank customer, supplier, or wallet touched any of the new listings is book-specific work. Three questions stay open, and each has a place it can be answered.

Open questionWhat it takesWhere that comes from
Did this payment or shipment hit a new name or address?Customer file + current list / wallet screenYour own desk, then a known institutional firm once the committee needs the name
Who owns the UAE distributor or HK trader?Corporate records, possibly field workAn investigations or corporate-integrity firm
Is a discrete dated policy event hedgeable (license drop, corridor close)?Event definition + notionalA priced-event specialist, privately

Confidence

High on what OFAC and CISA published. Medium on how widely the new Iran/CT vehicles already sit in correspondent books — that needs a file. A local sanctions snapshot last built 11 July 2026 is not the source for the names above. Those names come from the August notices.

Sources

[1] OFAC, Settlement Agreement with Rice Lake Weighing Systems, Inc., 12 Aug 2026. https://ofac.treasury.gov/recent-actions/20260812

[2] OFAC, Counter Terrorism and Iran-related Designations; Counter Narcotics Designations Removals, 7 Aug 2026. https://ofac.treasury.gov/recent-actions/20260807

[3] OFAC, Cuba-related Designations, 6 Aug 2026. https://ofac.treasury.gov/recent-actions/20260806 · State Department release linked from that notice.

[4] CISA, Known Exploited Vulnerabilities Catalog (entries dated 7–11 Aug 2026). https://www.cisa.gov/known-exploited-vulnerabilities-catalog