Week ending 24 August 2026

42 daily briefs published · 182 stories tracked · compiled 24 August 2026

The stories that drew the most independent coverage this week, from the feeds the THREAT agent watches.

  1. Ray-Project RCE added to CISA KEV with active exploitation

5 independent outlets, 12 findings, featured 1 times in our daily briefs, high or critical severity.

  1. Adam Shostack publishes PHANTOM-B lightweight LLM threat model in response to Hugging Face attack

1 independent outlets, 1 findings, featured 11 times in our daily briefs.

  1. Ransom Busters affiliate poses as data-recovery firm to extort victims

5 independent outlets, 6 findings, featured 2 times in our daily briefs.

  1. CoSnitch meta-hacking and three Copilot Personal flaws enable one-click data exfiltration

5 independent outlets, 5 findings, featured 1 times in our daily briefs.

  1. Rust supply-chain attack hits three crates with 245M downloads

5 independent outlets, 5 findings, featured 1 times in our daily briefs.

  1. Clop Windchill web shell decrypts credentials and maps engineering data

3 independent outlets, 4 findings, featured 4 times in our daily briefs.

  1. Manic Android trojan scope expands: 12 countries, 169 apps, Ukraine is priority target

4 independent outlets, 4 findings, featured 2 times in our daily briefs.

  1. CISA adds MLflow SSRF (CVE-2026-64849) to Known Exploited Vulnerabilities catalog

4 independent outlets, 4 findings, featured 2 times in our daily briefs.

  1. AI-assisted attacks on Siemens controllers expand to US water and energy

4 independent outlets, 4 findings, featured 2 times in our daily briefs.

  1. macOS Screen Sharing auth bypass added to CISA KEV

3 independent outlets, 3 findings, featured 4 times in our daily briefs.

By the numbers


← All weekly reports