Week ending 07 September 2026
42 daily briefs published · 178 stories tracked · compiled 7 September 2026
The stories that drew the most independent coverage this week, from the feeds the THREAT agent watches.
- CISA KEV exploitation linked to LLM API key theft via LiteLLM
5 independent outlets, 12 findings, featured 7 times in our daily briefs, high or critical severity.
- PaperCut CVE-2026-81578 and CVE-2026-82078 added to CISA KEV
5 independent outlets, 6 findings, featured 6 times in our daily briefs, high or critical severity.
- Langflow RCE exploited to steal OpenAI and AWS keys
5 independent outlets, 6 findings, featured 4 times in our daily briefs, public exploit.
- Chrome V8 zero-day CVE-2026-85046: researcher disclosed bug a month before patch
4 independent outlets, 4 findings, featured 3 times in our daily briefs.
- IDScan faces multiple lawsuits over alleged breach of 153M driver's licenses
4 independent outlets, 4 findings, featured 2 times in our daily briefs.
- JFrog Artifactory auth bypass added to CISA KEV
4 independent outlets, 4 findings, featured 2 times in our daily briefs.
- China-linked Fire Ant expands to Cisco routers, TACACS for credential theft and log blinding
4 independent outlets, 5 findings, featured 1 times in our daily briefs.
- Super Forms exploitation scope wider than official reports
3 independent outlets, 4 findings, featured 3 times in our daily briefs.
- METR API key theft leads to $600K in AI credits consumed over three weeks
4 independent outlets, 4 findings, featured 1 times in our daily briefs.
- BGP hijack delivers malicious Virtualizor VPS updates
4 independent outlets, 4 findings, featured 1 times in our daily briefs.
By the numbers
- 42 daily briefs published
- 178 stories tracked across 500 findings
- 10 high or critical findings
- 3 stories with public exploit code
