Skip to content
feed: live
>_ 0dayNews
$ briefings

Briefings

Periodic SITREPs that compress the week's vulnerability and exploit news into a single readable digest, sourced throughout.

~/briefings/2026-07-19-weekly
July 19, 2026

Week in Review: KEV, Certificates, and the Old Debt

Kilobaud on a week where the KEV cascade, a DigiCert attribution, and a passkey default all pointed at the same debt underneath old software.

~/briefings/2026-07-19-weekend
July 19, 2026

Weekend desk: wp2shell in the open, 27 DigiCert EV certs

Sunday desk. wp2shell shipped with a working PoC. 7-Zip closed the XZ hole, DigiCert's April intrusion is attributed, Abbott and E&Y remain open.

~/briefings/2026-07-17-daily
July 17, 2026

Desk briefing: KEV +3 in 24 hours, Fairlife goes dark

Thursday desk. Three new KEV entries — FortiSandbox pair (Sunday) and a fourth SharePoint. Coca-Cola halted Fairlife US production. TfL Spider pair got 5.5 years.

~/briefings/2026-07-15-daily
July 15, 2026

Desk briefing: KEV grew by four, SonicWall deadline is Friday

Wednesday desk. CISA added four to KEV Tuesday — SonicWall SMA1000 (federal deadline Friday) and Microsoft AD FS + SharePoint zero-days from July Patch Tuesday. SAP shipped a 9.9. Progress ShareFile is patched, CVE reserved.

~/briefings/2026-07-14-daily
July 14, 2026

Desk briefing: Gatekeeper cleared it, and that is the story

Tuesday desk briefing — a macOS stealer rides a valid Apple notarization past Gatekeeper, ModHeader shipped a dormant collector to 1.6M installs both stores signed, Jscrambler's npm compromise now covers four releases not one, and CISA admits nine leak alerts sat in an unread inbox for six months.

~/briefings/2026-07-13-daily
July 13, 2026

Desk briefing: the fire drill this week is on the routers

Monday desk briefing — a thirteen-nation router-hygiene advisory drops on the same morning as the first joint EU-UK cyber sanctions package, two Joomla file-upload flaws hit their KEV deadline today, and a supply-chain compromise in a legitimate npm library still deserves your CI's attention.

~/briefings/2026-07-11-weekly
July 11, 2026

Week in Review: AI Attacks Stopped Being Theoretical

Eight named AI-agent incidents in one week, another wave of Microsoft 365 device-code vishing landing on the same targets it always does, and the usual queue of edge-appliance KEV additions — Kilobaud on what the collection has in common.

~/briefings/2026-07-06-daily
July 6, 2026

Desk Briefing: the install-time gate is not the gate you think it is

Three stories on the desk in 48 hours land on the same nerve — the trust boundary around installers is porous — plus a ransomware group that never encrypted a file and a KEV status change on Defender's BlueHammer LPE.

~/briefings/2026-07-04-weekly
July 4, 2026

Week in Review: DPRK Broke Supply Chains, an LLM Ran Ransomware

Three DPRK supply-chain campaigns in parallel, JadePuffer's LLM-agent ransomware milestone, and yet another week of unpatched edge RCEs across Kemp, FatFs, and Cisco Unified CM — Kilobaud on what this collection of stories has in common.

~/briefings/2026-06-29-weekly
June 29, 2026

Week in Review: Five Zero-Days, One Pattern — Edge Devices Are the Front Line

This week's SITREP: Cisco IOS XE, Citrix Bleed, the Ivanti Connect Secure chain, PAN-OS GlobalProtect, and Outlook's MonikerLink bug — plus what's still active in the CISA KEV catalog and what to watch next.