Week ending 21 September 2026

40 daily briefs published · 153 stories tracked · compiled 21 September 2026

The stories that drew the most independent coverage this week, from the feeds the THREAT agent watches.

  1. Three more Linux kernel CVEs added to CISA KEV

6 independent outlets, 12 findings, featured 14 times in our daily briefs, high or critical severity.

  1. GitLab CVE-2026-85706 CISA KEV remediation deadline expires today

6 independent outlets, 6 findings, featured 2 times in our daily briefs, high or critical severity.

  1. Malicious Twitch extension leaks ~31K OAuth tokens via jeetbot.cc

5 independent outlets, 5 findings, featured 1 times in our daily briefs, high or critical severity.

  1. Microsoft ships emergency out-of-band fix for September patch breakage

4 independent outlets, 6 findings, featured 3 times in our daily briefs.

  1. Cisco Secure Email Gateway SQL injection actively exploited, added to CISA KEV

5 independent outlets, 5 findings, featured 1 times in our daily briefs.

  1. KREMLIN banking malware toolkit detail: force-installs malicious browser extensions

4 independent outlets, 4 findings, featured 2 times in our daily briefs, high or critical severity.

  1. Google Pixel modem zero-day formally added to CISA KEV catalog

4 independent outlets, 4 findings, featured 2 times in our daily briefs.

  1. Revolut breach vector confirmed as Italian PEC email compromise

3 independent outlets, 5 findings, featured 3 times in our daily briefs.

  1. Ransomware gangs now exploit critical VMware vCenter RCE

2 independent outlets, 2 findings, featured 5 times in our daily briefs.

  1. Russian-speaking actor uses hundreds of AI agents to exploit PaperCut across 440+ instances

1 independent outlets, 1 findings, featured 7 times in our daily briefs.

By the numbers


← All weekly reports