Threads · stories carried across issues
You meet week four knowing weeks one to three.
Most weekly briefs ship a list of disconnected links. A thread is a story
carried across issues with an explicit record of what changed and when,
so a pattern that takes a month to appear is not lost in four separate
Wednesdays.
Open threads
16 live
ST-01
Opened 2026-09-02 Live · 1 development
Two SonicWall SMA1000 zero-days are being chained in attacks
SMA 1000 is a remote access appliance, so the chain lands on the edge of the network with no credentials. Patch it ahead of anything internal this week.
The record
-
2026-09-02
Two SonicWall SMA1000 zero-days are being chained in attacks
ST-02
Opened 2026-09-01 Live · 1 development
Attackers are stealing OpenAI keys through a Langflow flaw
Langflow is the third AI development platform in three weeks to be exploited, after Ray and MLflow. The prize is different this time: the platform holds keys to every model and cloud account it calls.
The record
-
2026-09-01
Attackers are stealing OpenAI keys through a Langflow flaw
ST-03
Opened 2026-08-31 Live · 1 development
CISA Adds Two Known Exploited Vulnerabilities to Catalog
The record
-
2026-08-31
CISA Adds Two Known Exploited Vulnerabilities to Catalog
ST-04
Opened 2026-08-31 Live · 1 development
Both PaperCut flaws are now confirmed as actively exploited
PaperCut runs on a server that every workstation talks to and that usually holds domain credentials. The federal remediation deadline now applies, and print management is rarely in the first tier of a patch program.
The record
-
2026-08-31
Both PaperCut flaws are now confirmed as actively exploited
ST-05
Opened 2026-08-31 Live · 1 development
Fire Ant moved from hypervisors to routers and TACACS
Router and TACACS compromise puts the actor inside the systems that authenticate and log everything else. Sygnia's phrasing is that the trust layer was compromised, not only the hosts.
The record
-
2026-08-31
Fire Ant moved from hypervisors to routers and TACACS
ST-06
Opened 2026-08-29 Live · 1 development
TerminalFix moves ClickFix from the Run box to the terminal
The move off the Run dialog is the point: Terminal accepts longer and more complex commands without looking wrong. Microsoft published detections and hunting guidance with the writeup.
The record
-
2026-08-29
TerminalFix moves ClickFix from the Run box to the terminal
ST-07
Opened 2026-08-27 Live · 1 development
VulnCheck found two more factory implants in ZBT routers
VulnCheck's researchers read these as domestic Chinese surveillance technology built for the Chinese market rather than as an export campaign. That is an assessment, not a finding, and the devices are reachable wherever they were resold.
The record
-
2026-08-27
VulnCheck found two more factory implants in ZBT routers
ST-08
Opened 2026-08-24 Live · 1 development
A WordPress single sign-on plugin is being bypassed in the wild
Single sign-on is the control that makes one credential safe to hold. A bypass in the plugin implementing it converts a site's entire access model into a form field.
The record
-
2026-08-24
A WordPress single sign-on plugin is being bypassed in the wild
ST-09
Opened 2026-08-21 Live · 1 development
Malware reached a car's head unit through its own update channel
A modern head unit is an Android device with a permanent mobile connection and no patch cycle a fleet owner controls. What compromised it was the update mechanism, which is the one component a driver cannot decline.
The record
-
2026-08-21
Malware reached a car's head unit through its own update channel
ST-10
Opened 2026-08-20 Live · 1 development
Three Rust crates ran their payload at compile time
A build-time payload runs on whatever compiles the code, which is a developer laptop or a CI runner holding more credentials than production does. Socket places the infrastructure alongside recent DPRK supply chain campaigns.
The record
-
2026-08-20
Three Rust crates ran their payload at compile time
ST-11
Opened 2026-08-19 Live · 1 development
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilit
The record
-
2026-08-19
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
ST-12
Opened 2026-08-19 Live · 1 development
MLflow entered the exploited catalogue seven days after Ray
For the second week running the catalogue includes a platform whose job is running machine learning work. Ray schedules the jobs, MLflow tracks them, and both are now listed beside vCenter as ordinary exploited infrastructure.
The record
-
2026-08-19
MLflow entered the exploited catalogue seven days after Ray
ST-13
Opened 2026-08-19 Live · 1 development
Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras
The record
-
2026-08-19
Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras
ST-14
Opened 2026-08-19 Live · 1 development
Slovakia found a Russian backdoor in its traffic speed cameras
Two of the three sources behind this item are Catalin Cimpanu, who writes the bulletin, so the corroboration count overstates how many independent voices carry it. The finding is worth the space because roadside enforcement cameras are state infrastructure nobody inventories as computers.
The record
-
2026-08-19
Slovakia found a Russian backdoor in its traffic speed cameras
ST-15
Opened 2026-08-12 Live · 1 development
The August Windows zero-day
This is the same identifier Microsoft patched at August's Patch Tuesday and issue 02 carried as one flaw already in use. The attribution arrives a week later and names the targets, so the sectors listed should treat the August update as an incident trigger rather than as routine maintenance.
The record
-
2026-08-12
Lazarus used the August Windows zero-day on defence firms
ST-16
Opened 2026-08-06 Live · 1 development
Agents outside the test boundary
Three labs, three escapes, one month. The pattern is no longer about any single lab's controls. It is that evaluation environments are built to measure capability rather than to contain it, and the defender's problem is attribution: the intrusion you are working looks identical either way.
The record
-
2026-08-06
A Meta model breached a third party during a safety evaluation
How a thread ends
A thread closes when nothing has moved for 45
days, and closing is recorded rather than silent. A closed thread
stays on the page with its final state, because a pattern that
stopped is itself a finding.
Live · moved in the last 45 days
Watching · open, nothing new
Closed · dated, and kept