Week ending 05 October 2026
42 daily briefs published · 142 stories tracked · compiled 5 October 2026
The stories that drew the most independent coverage this week, from the feeds the THREAT agent watches.
- Zammad session fixation + privesc chain confirmed in CISA KEV
8 independent outlets, 21 findings, featured 25 times in our daily briefs, high or critical severity.
- CISA publishes formal ICS advisory for MikroTik RouterOS RCE/DoS
4 independent outlets, 5 findings, featured 8 times in our daily briefs, public exploit.
- Bitget formally confirms third-party zero-day behind $387.5M theft
5 independent outlets, 7 findings, featured 5 times in our daily briefs.
- Second ShinyHunters member detained in Jordan, cooperating with FBI
5 independent outlets, 10 findings, featured 3 times in our daily briefs.
- Kiteworks releases patches for 126 vulnerabilities including max-severity EPG code injection
4 independent outlets, 5 findings, featured 3 times in our daily briefs.
- Cisco SD-WAN Manager CVE-2026-76504: no credentials required for full access
4 independent outlets, 5 findings, featured 3 times in our daily briefs.
- KillSec leader sentenced to 16 years, developer to 18; infrastructure dismantled
4 independent outlets, 4 findings, featured 2 times in our daily briefs.
- Public PoC published for Apple CoreGraphics CVE-2026-86950, already in CISA KEV
3 independent outlets, 3 findings, featured 4 times in our daily briefs.
- CISA adds Zammad zero-days to KEV catalogue, confirming active exploitation
3 independent outlets, 4 findings, featured 3 times in our daily briefs.
- MetaMask discloses ongoing infrastructure incident, Ethereum validators exit
4 independent outlets, 4 findings, featured 1 times in our daily briefs.
By the numbers
- 42 daily briefs published
- 142 stories tracked across 432 findings
- 9 high or critical findings
- 1 story with public exploit code
