Week ending 14 September 2026

42 daily briefs published · 148 stories tracked · compiled 14 September 2026

The stories that drew the most independent coverage this week, from the feeds the THREAT agent watches.

  1. CISA KEV adds Chrome V8, Fortinet, and Citrix NetScaler CVEs

6 independent outlets, 17 findings, featured 11 times in our daily briefs, high or critical severity.

  1. Microsoft September Patch Tuesday grows to ~1,000 fixes with two exploited zero-days

6 independent outlets, 7 findings, featured 2 times in our daily briefs.

  1. Cisco FMC flaws exploited by ransomware gang and state-sponsored hackers

4 independent outlets, 8 findings, featured 4 times in our daily briefs, high or critical severity.

  1. Six Chinese companies named in large-scale AI model distillation from Claude, GPT, Gemini, Grok

5 independent outlets, 6 findings, featured 3 times in our daily briefs.

  1. Russian-speaking actor uses hundreds of AI agents to exploit PaperCut across 440+ instances

3 independent outlets, 4 findings, featured 7 times in our daily briefs.

  1. StyleSmuggler named as actively exploited Magento/Adobe Commerce RCE

4 independent outlets, 5 findings, featured 3 times in our daily briefs.

  1. Artifactory flaws chained to deploy Rust backdoor on self-hosted servers

4 independent outlets, 4 findings, featured 3 times in our daily briefs.

  1. Liquid Network attackers return 3,400 BTC, ~598.5 BTC still unreturned

4 independent outlets, 5 findings, featured 2 times in our daily briefs.

  1. Chrome V8 zero-day CVE-2026-87491 added to CISA KEV

4 independent outlets, 4 findings, featured 2 times in our daily briefs.

  1. Nightmare-Eclipse releases ShieldCrash patch bypass

4 independent outlets, 4 findings, featured 2 times in our daily briefs.

By the numbers


← All weekly reports