Week ending 31 August 2026
41 daily briefs published · 175 stories tracked · compiled 31 August 2026
The stories that drew the most independent coverage this week, from the feeds the THREAT agent watches.
- ownCloud CVE-2023-49105 added to CISA KEV after nuclear records theft
5 independent outlets, 18 findings, featured 4 times in our daily briefs, high or critical severity.
- Hugging Face breach scope expands with multistage attack details
6 independent outlets, 6 findings, featured 3 times in our daily briefs.
- Zimbra RCE KEV deadline expires while active exploitation continues
4 independent outlets, 5 findings, featured 4 times in our daily briefs, high or critical severity.
- TeamPCP linked to 1,000 organisations and 300 GB stolen data as arrests proceed
5 independent outlets, 5 findings, featured 2 times in our daily briefs.
- PaperCut patch bypassed within a day via new CVE chain
3 independent outlets, 5 findings, featured 3 times in our daily briefs.
- NemoClaw sandbox limitation: blocks execution but not model takeover
4 independent outlets, 4 findings, featured 1 times in our daily briefs.
- ServiceNow patches three CVSS 10.0 AI Platform flaws
4 independent outlets, 4 findings, featured 1 times in our daily briefs.
- DOJ corrects inflated QTFY hack-count claims
3 independent outlets, 4 findings, featured 2 times in our daily briefs.
- CISA SOC comparison highlights alert-fatigue blind spots
3 independent outlets, 3 findings, featured 2 times in our daily briefs.
- ZBT routers ship with two factory backdoors
3 independent outlets, 3 findings, featured 2 times in our daily briefs.
By the numbers
- 41 daily briefs published
- 175 stories tracked across 452 findings
- 19 high or critical findings
- 1 story with public exploit code
