Week ending 24 August 2026
42 daily briefs published · 182 stories tracked · compiled 24 August 2026
The stories that drew the most independent coverage this week, from the feeds the THREAT agent watches.
- Ray-Project RCE added to CISA KEV with active exploitation
5 independent outlets, 12 findings, featured 1 times in our daily briefs, high or critical severity.
- Adam Shostack publishes PHANTOM-B lightweight LLM threat model in response to Hugging Face attack
1 independent outlets, 1 findings, featured 11 times in our daily briefs.
- Ransom Busters affiliate poses as data-recovery firm to extort victims
5 independent outlets, 6 findings, featured 2 times in our daily briefs.
- CoSnitch meta-hacking and three Copilot Personal flaws enable one-click data exfiltration
5 independent outlets, 5 findings, featured 1 times in our daily briefs.
- Rust supply-chain attack hits three crates with 245M downloads
5 independent outlets, 5 findings, featured 1 times in our daily briefs.
- Clop Windchill web shell decrypts credentials and maps engineering data
3 independent outlets, 4 findings, featured 4 times in our daily briefs.
- Manic Android trojan scope expands: 12 countries, 169 apps, Ukraine is priority target
4 independent outlets, 4 findings, featured 2 times in our daily briefs.
- CISA adds MLflow SSRF (CVE-2026-64849) to Known Exploited Vulnerabilities catalog
4 independent outlets, 4 findings, featured 2 times in our daily briefs.
- AI-assisted attacks on Siemens controllers expand to US water and energy
4 independent outlets, 4 findings, featured 2 times in our daily briefs.
- macOS Screen Sharing auth bypass added to CISA KEV
3 independent outlets, 3 findings, featured 4 times in our daily briefs.
By the numbers
- 42 daily briefs published
- 182 stories tracked across 489 findings
- 11 high or critical findings
