Week ending 28 September 2026
42 daily briefs published · 153 stories tracked · compiled 28 September 2026
The stories that drew the most independent coverage this week, from the feeds the THREAT agent watches.
- Check Point confirms active exploitation of Security Gateway VPN RCE (CVE-2026-85102)
5 independent outlets, 17 findings, featured 16 times in our daily briefs, high or critical severity.
- FBI breach leak exposes members of secret hacker unit ROU
4 independent outlets, 6 findings, featured 2 times in our daily briefs.
- Microsoft disrupts EvilTokens device-code phishing service compromising 12,000 accounts
5 independent outlets, 5 findings, featured 0 times in our daily briefs.
- GitLab issue-email addresses deliberately exposed in READMEs for code-push abuse
4 independent outlets, 4 findings, featured 2 times in our daily briefs.
- ShinyHunters breached Clop leak site via Grav CMS path traversal; Clop relocates Tor site
4 independent outlets, 4 findings, featured 2 times in our daily briefs.
- ClosedQuorum malware consults four LLMs for autonomous attack decisions
4 independent outlets, 4 findings, featured 1 times in our daily briefs.
- Bitget exchange hacked for $351.6M by suspected North Korean actors
4 independent outlets, 4 findings, featured 1 times in our daily briefs.
- Two Check Point CVEs added to CISA KEV — both exploited in the wild
3 independent outlets, 3 findings, featured 3 times in our daily briefs.
- Compromised GitHub Actions re-enabled, malicious payload live for over a week
3 independent outlets, 3 findings, featured 3 times in our daily briefs.
- WordPress CVE-2026-87902 exploitation escalates from probing to code execution
3 independent outlets, 6 findings, featured 2 times in our daily briefs.
By the numbers
- 42 daily briefs published
- 153 stories tracked across 505 findings
- 9 high or critical findings
