Briefings
Periodic SITREPs that compress the week's vulnerability and exploit news into a single readable digest, sourced throughout.
Week in Review: KEV, Certificates, and the Old Debt
Kilobaud on a week where the KEV cascade, a DigiCert attribution, and a passkey default all pointed at the same debt underneath old software.
Weekend desk: wp2shell in the open, 27 DigiCert EV certs
Sunday desk. wp2shell shipped with a working PoC. 7-Zip closed the XZ hole, DigiCert's April intrusion is attributed, Abbott and E&Y remain open.
Desk briefing: KEV +3 in 24 hours, Fairlife goes dark
Thursday desk. Three new KEV entries — FortiSandbox pair (Sunday) and a fourth SharePoint. Coca-Cola halted Fairlife US production. TfL Spider pair got 5.5 years.
Desk briefing: KEV grew by four, SonicWall deadline is Friday
Wednesday desk. CISA added four to KEV Tuesday — SonicWall SMA1000 (federal deadline Friday) and Microsoft AD FS + SharePoint zero-days from July Patch Tuesday. SAP shipped a 9.9. Progress ShareFile is patched, CVE reserved.
Desk briefing: Gatekeeper cleared it, and that is the story
Tuesday desk briefing — a macOS stealer rides a valid Apple notarization past Gatekeeper, ModHeader shipped a dormant collector to 1.6M installs both stores signed, Jscrambler's npm compromise now covers four releases not one, and CISA admits nine leak alerts sat in an unread inbox for six months.
Desk briefing: the fire drill this week is on the routers
Monday desk briefing — a thirteen-nation router-hygiene advisory drops on the same morning as the first joint EU-UK cyber sanctions package, two Joomla file-upload flaws hit their KEV deadline today, and a supply-chain compromise in a legitimate npm library still deserves your CI's attention.
Week in Review: AI Attacks Stopped Being Theoretical
Eight named AI-agent incidents in one week, another wave of Microsoft 365 device-code vishing landing on the same targets it always does, and the usual queue of edge-appliance KEV additions — Kilobaud on what the collection has in common.
Desk Briefing: the install-time gate is not the gate you think it is
Three stories on the desk in 48 hours land on the same nerve — the trust boundary around installers is porous — plus a ransomware group that never encrypted a file and a KEV status change on Defender's BlueHammer LPE.
Week in Review: DPRK Broke Supply Chains, an LLM Ran Ransomware
Three DPRK supply-chain campaigns in parallel, JadePuffer's LLM-agent ransomware milestone, and yet another week of unpatched edge RCEs across Kemp, FatFs, and Cisco Unified CM — Kilobaud on what this collection of stories has in common.
Week in Review: Five Zero-Days, One Pattern — Edge Devices Are the Front Line
This week's SITREP: Cisco IOS XE, Citrix Bleed, the Ivanti Connect Secure chain, PAN-OS GlobalProtect, and Outlook's MonikerLink bug — plus what's still active in the CISA KEV catalog and what to watch next.