Week ending 21 September 2026
40 daily briefs published · 153 stories tracked · compiled 21 September 2026
The stories that drew the most independent coverage this week, from the feeds the THREAT agent watches.
- Three more Linux kernel CVEs added to CISA KEV
6 independent outlets, 12 findings, featured 14 times in our daily briefs, high or critical severity.
- GitLab CVE-2026-85706 CISA KEV remediation deadline expires today
6 independent outlets, 6 findings, featured 2 times in our daily briefs, high or critical severity.
- Malicious Twitch extension leaks ~31K OAuth tokens via jeetbot.cc
5 independent outlets, 5 findings, featured 1 times in our daily briefs, high or critical severity.
- Microsoft ships emergency out-of-band fix for September patch breakage
4 independent outlets, 6 findings, featured 3 times in our daily briefs.
- Cisco Secure Email Gateway SQL injection actively exploited, added to CISA KEV
5 independent outlets, 5 findings, featured 1 times in our daily briefs.
- KREMLIN banking malware toolkit detail: force-installs malicious browser extensions
4 independent outlets, 4 findings, featured 2 times in our daily briefs, high or critical severity.
- Google Pixel modem zero-day formally added to CISA KEV catalog
4 independent outlets, 4 findings, featured 2 times in our daily briefs.
- Revolut breach vector confirmed as Italian PEC email compromise
3 independent outlets, 5 findings, featured 3 times in our daily briefs.
- Ransomware gangs now exploit critical VMware vCenter RCE
2 independent outlets, 2 findings, featured 5 times in our daily briefs.
- Russian-speaking actor uses hundreds of AI agents to exploit PaperCut across 440+ instances
1 independent outlets, 1 findings, featured 7 times in our daily briefs.
By the numbers
- 40 daily briefs published
- 153 stories tracked across 480 findings
- 13 high or critical findings
