Week ending 07 September 2026

42 daily briefs published · 178 stories tracked · compiled 7 September 2026

The stories that drew the most independent coverage this week, from the feeds the THREAT agent watches.

  1. CISA KEV exploitation linked to LLM API key theft via LiteLLM

5 independent outlets, 12 findings, featured 7 times in our daily briefs, high or critical severity.

  1. PaperCut CVE-2026-81578 and CVE-2026-82078 added to CISA KEV

5 independent outlets, 6 findings, featured 6 times in our daily briefs, high or critical severity.

  1. Langflow RCE exploited to steal OpenAI and AWS keys

5 independent outlets, 6 findings, featured 4 times in our daily briefs, public exploit.

  1. Chrome V8 zero-day CVE-2026-85046: researcher disclosed bug a month before patch

4 independent outlets, 4 findings, featured 3 times in our daily briefs.

  1. IDScan faces multiple lawsuits over alleged breach of 153M driver's licenses

4 independent outlets, 4 findings, featured 2 times in our daily briefs.

  1. JFrog Artifactory auth bypass added to CISA KEV

4 independent outlets, 4 findings, featured 2 times in our daily briefs.

  1. China-linked Fire Ant expands to Cisco routers, TACACS for credential theft and log blinding

4 independent outlets, 5 findings, featured 1 times in our daily briefs.

  1. Super Forms exploitation scope wider than official reports

3 independent outlets, 4 findings, featured 3 times in our daily briefs.

  1. METR API key theft leads to $600K in AI credits consumed over three weeks

4 independent outlets, 4 findings, featured 1 times in our daily briefs.

  1. BGP hijack delivers malicious Virtualizor VPS updates

4 independent outlets, 4 findings, featured 1 times in our daily briefs.

By the numbers


← All weekly reports