Cyber Risk Brief: 17 - 23 August 2026
CRB-2224 August 2026Sovereign GRC Intel20 min read
Disclaimer:This brief is governance commentary for leadership and risk teams, not incident notification, public attribution, legal advice, or quantitative risk analysis. Threat prioritization, framework mappings, attribution, and risk-zone groupings are informational only. Validate all technical claims against vendor advisories and internal telemetry before operational response.
Threat Intelligence Summary
Nine CISA KEV entries landed this week; six deadlines had already expired at publication. Windows IKE CVE-2026-33824 carries the highest EPSS at 0.78: unauthenticated RCE over UDP 500/4500 on every supported Windows release. vCenter CVE-2026-59310 escalates last week's active campaign to Babuk-derived ransomware, moderate-confidence China-nexus. SharePoint CVE-2026-55040 is a second, distinct CVE from last week's ransomware-flagged CVE-2026-45659. Ray CVE-2025-62593 is browser-triggered RCE against AI infrastructure, weaponized by a botnet before its own disclosure. macOS Screen Sharing CVE-2026-65400 delivered a cryptominer via local-network auth bypass. TrueConf CVE-2026-72529/72530 confirm a month of Head Mare installer-trojanization first flagged without a CVE on 10 August. Zimbra CVE-2026-73570, due today, is unauthenticated SMTP command injection across 12,100+ exposed instances. MLflow CVE-2026-64849, due 2 September, is the one live clock with real runway: SSRF reaching cloud metadata within hours of CVE assignment. GitLab CVE-2026-19478, not KEV-listed, drew honeypot exploitation in minutes, faster than any KEV-listed entry this week. Medusa ransomware's 500-plus critical-infrastructure victims since 2021 now run a six-figure initial-access-broker marketplace. What connects them: a KEV catalogue lagging exploitation on both ends, and an AI-engineering stack now drawing the same federal clocks as the network perimeter.
Threat Register
| Threat | |||||
|---|---|---|---|---|---|
| T1 | Windows IKE Extension Double-Free RCE (CVE-2026-33824) CVE-2026-33824 is a double-free in the Windows IKE Extension (MS-IKEE) that lets an unauthorized attacker execute code over the network via crafted IKE packets to UDP 500/4500, reachable on every supported Windows 10, 11 and Server release (CVSS 3.1 9.8, EPSS 0.77898, the highest EPSS in this register). Microsoft fixed it in the April 2026 Patch Tuesday. CISA added it to KEV on 18 August 2026 with remediation due 21 August, a deadline that passed before this brief published. Microsoft's own advisory has not been updated to flag exploitation; the KEV listing is CISA's sole confirmation. | 9.8 | 77.90% | Critical | Immediate |
| T2 | VMware vCenter Syslog RCE Now KEV, Babuk-Derived Ransomware (CVE-2026-59310) CVE-2026-59310, the vCenter Syslog server directory-traversal RCE covered in last week's brief as an active but non-KEV campaign, is now CISA KEV-listed (added 18 August, due 21 August, passed) and carries a new payload: The Hacker News reports a Babuk-derived ransomware deployment in at least one confirmed case. QUIRSO, the DFIR firm that first tracked the campaign, now assesses moderate confidence that a China-nexus actor is behind it, citing UTC+08:00 working-hours activity and Chinese-language artifacts. The victim count from last week, 361 IPs across 47 countries, stands; Germany (55), the United States (41), Turkey (38), Iran (26) and France (25) lead the country breakdown. | 9.8 | 2.40% | Critical | Immediate |
| T3 | Microsoft SharePoint Weak Authentication (CVE-2026-55040) CVE-2026-55040 is a weak-authentication flaw in Microsoft SharePoint Server that lets an unauthorized attacker bypass a security feature over the network (CVSS 3.1 9.1, EPSS 5.49%). CISA added it to KEV on 18 August 2026, its first appearance in the catalogue, with remediation due 21 August, a deadline that passed before publication. The Hacker News reports exploitation by unknown actors following release of a public proof of concept. This is a different CVE from last week's ransomware-flagged SharePoint deserialization RCE (CVE-2026-45659) and from the July cluster (CVE-2026-56164, CVE-2026-58644), which named CVE-2026-55040 but carried no CISA due date for it at the time. | 9.1 | 5.49% | Critical | Immediate |
| T4 | Ray Browser-Based RCE via DNS Rebinding (CVE-2025-62593) CVE-2025-62593 lets an attacker achieve remote code execution against Ray, the open-source distributed-compute framework used across AI and ML pipelines, by combining a User-Agent bypass with DNS rebinding to reach Ray's unauthenticated /api/jobs endpoint from a malicious webpage in Firefox or Safari (CVSS 4.0 9.4, EPSS 1.00%). CISA added it to KEV on 17 August 2026 with remediation due 20 August, a deadline that passed before publication. Ray carries more than 43,500 GitHub stars and 7,900 forks; the vendor fixed the flaw in version 2.52.0. | 9.4 | 1.00% | Critical | Immediate |
| T5 | Apple macOS Screen Sharing Improper Authentication (CVE-2026-65400) CVE-2026-65400 is an improper-authentication flaw in macOS Screen Sharing that lets an attacker on the local network authenticate without valid credentials (CVSS 3.1 9.8, EPSS 0.75%). CISA added it to KEV on 18 August 2026 with remediation due 21 August, a deadline that passed before publication. Apple fixed it in macOS Sequoia 15.7.9, Sonoma 14.8.9 and Tahoe 26.6.1. The Hacker News reports the flaw was abused to deliver a Monero cryptocurrency miner. | 9.8 | < 1% | Critical | Immediate |
| T6 | TrueConf Server Missing Auth and Sandbox Escape, Head Mare Campaign (CVE-2026-72529 / CVE-2026-72530) TrueConf Server, self-hosted video-conferencing software, carries two newly KEV-listed flaws: CVE-2026-72529, missing authentication for an undocumented function on port 4307/TCP allowing unauthenticated code execution (CVSS 4.0 9.3, EPSS 0.79%, KEV due 23 August, passed), and CVE-2026-72530, a sandbox escape from the isolated execution environment reached after that code execution (CVSS 4.0 9.5, EPSS 0.97%, KEV due 3 September). Kaspersky now attributes the Head Mare group's installer-trojanization campaign, first covered in this brief on 10 August under Kaspersky IDs KLCERT-26-057 and KLCERT-26-058 with no CVE assigned, to exploitation of these two CVEs since at least July 2026. | 9.3 | < 1% | Critical | Immediate |
| T7 | Zimbra Collaboration SNMP Command Injection (CVE-2026-73570) CVE-2026-73570 is an unauthenticated command-injection flaw in Zimbra Collaboration Suite's optional SNMP component, reachable via SMTP, that lets an attacker execute OS commands as the Zimbra user when zimbra-snmp is installed and SNMP notifications are enabled (CVSS 3.1 8.9, EPSS 1.04%). CERT Polska disclosed active exploitation on 20 August 2026. CISA added it to KEV on 21 August with remediation due 24 August, today, the tightest live clock in this register. Shadowserver counts more than 12,100 internet-exposed Zimbra instances, split roughly 4,382 in Europe and 4,492 in Asia. | 8.9 | 1.04% | Critical | Immediate |
| T8 | MLflow Unauthenticated Webhook SSRF (CVE-2026-64849) CVE-2026-64849 is an unauthenticated SSRF in MLflow's webhook-testing endpoint that lets an attacker reach internal services and cloud metadata endpoints by directing the platform to fetch redirect-following URLs its validation does not catch (CVSS 3.1 9.3, EPSS 8.15%). CISA added it to KEV on 19 August 2026 with remediation due 2 September. MLflow, a Linux Foundation project with roughly 60 million monthly downloads, ships with no authentication on its Tracking Server by default. watchTowr reports scanning began within hours of the CVE's assignment, with attackers reaching AWS Instance Metadata Service credentials and exfiltrating cloud credentials and secrets. | 9.3 | 8.15% | Critical | Immediate |
| T9 | GitLab GraphQL Code Injection (CVE-2026-19478) CVE-2026-19478 is an unauthenticated code-injection flaw in GitLab's GraphQL API, via the @gl_introduced directive, that lets an attacker remotely modify or delete public projects and, per The Hacker News, go further: deleting repositories, forging merge records, and banning maintainers (CVSS 3.1 9.4, EPSS 1.94%). It is not KEV-listed, but watchTowr reports reproducing the exploit in minutes and observing honeypot exploitation attempts, and CCCS's AV26-827 Update 1 states that open-source reporting indicates active exploitation. Fixed in GitLab 18.11.11, 19.0.8, 19.1.6 and 19.2.4; affected from version 18.2. | 9.4 | 1.94% | Critical | Immediate |
| T10 | Medusa Ransomware, 500+ U.S. Critical-Infrastructure Victims A joint CISA, HHS and FBI advisory reports Medusa ransomware has claimed more than 500 U.S. critical-infrastructure victims as of April 2026, up from the prior joint report's count of over 300 in March 2025, spanning Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, Financial Services, and organizations in medical, education, legal, insurance, technology and manufacturing sectors. Medusa surfaced in January 2021, established a leak site in 2023, and now recruits initial access brokers with payments ranging from $100,000 to $1 million. It is a distinct operation from MedusaLocker and from the Medusa Android malware-as-a-service platform (also known as TangleBot); this brief does not conflate the three. | — | — | High | Post-incident |
| Select a row for narrative, affected systems, remediation, and sources. | |||||
Strategic context
Eight federal clocks landed in seven days, and six had already expired
- CISA added nine KEV entries dated inside this window: CVE-2026-33824 (Windows IKE), CVE-2026-59310 (vCenter), CVE-2026-55040 (SharePoint), CVE-2025-62593 (Ray), CVE-2026-65400 (macOS Screen Sharing), CVE-2026-72529/72530 (TrueConf) and CVE-2026-73570 (Zimbra, due the day this brief publishes). Six of those deadlines had already passed before publication; CVE-2026-64849 (MLflow) is the only one with real runway, due 2 September.
- The Hermes Sheet's KEV column flagged one of nine additions. A direct feed query recovered the other eight, the same miss pattern this brief documented on 3 August and 17 August: the Sheet's KEV enrichment cannot be trusted as a standalone signal.
- The decision this forces: a weekly reconciliation cycle is not fast enough when six of nine deadlines expire before the next brief ships. Continuous KEV monitoring, not a publication-day check, is the control this pattern demands.
The AI-engineering stack is drawing the same clocks as the network edge
- Ray (T4) is unauthenticated RCE reachable through a developer's browser tab via DNS rebinding, weaponized by the RondoDox botnet before its own disclosure. MLflow (T8) is an unauthenticated webhook that reaches cloud metadata and exfiltrates IAM credentials within hours of CVE assignment.
- Neither tool was built with an internet-facing threat model, and both now carry federal remediation clocks alongside Windows kernel drivers and collaboration platforms.
- The decision this forces: AI/ML infrastructure inventories belong inside the same emergency-patch SLA as production internet-facing systems, not a separate, slower track for 'developer tooling.'
Two continuity cards prove that a numberless finding is not a closed one
- vCenter (T2) moved in one week from 'active campaign, not KEV-listed' to a passed federal deadline and a Babuk-derived ransomware payload. TrueConf (T6) moved from Kaspersky's internal KLCERT identifiers on 10 August to two KEV-listed CVEs confirming a month of prior Head Mare exploitation.
- Both cards were accurate when published and incomplete within weeks, because the underlying campaigns were already running before either register entry existed.
- The decision this forces: any card closed on 'no CVE yet' or 'not KEV-listed' needs a standing re-review trigger, not a one-time write-off, because the exploitation clock does not wait for the paperwork.
Threat Actor Profiling
Two threats carry named-group attribution: Head Mare for the TrueConf installer-trojanization campaign (T6, per Kaspersky as reported by BleepingComputer) and the Medusa ransomware operation for the critical-infrastructure campaign (T10, per the joint CISA/HHS/FBI advisory). QUIRSO assesses moderate-confidence China-nexus attribution for the vCenter campaign (T2) without naming a group; that hedge is carried in the register. The Hacker News, citing Unit 42, attributes the Windows IKE zero-day (T1) to a Chinese-speaking actor; this brief cites the reporting outlet and treats the attribution as unconfirmed. The remaining six threats (T3, T4, T5, T7, T8, T9) have confirmed exploitation or exploitation attempts without a public actor name. MITRE technique codes are shown as hover-to-define abbreviations.
| Threats | Actor | Sectors | MITRE tradecraft | Kill chain |
|---|---|---|---|---|
| T1 | Unattributed threat actor, alleged Chinese-speaking actor per Unit 42 (unconfirmed) | Windows infrastructure, all sectors | Crafted IKE packets to UDP 500/4500 → double-free in MS-IKEE → remote code execution, no authentication required | |
| T2 | Suspected China-nexus threat actor (moderate confidence, per QUIRSO) | virtualization, enterprise datacenters | Directory traversal RCE on vCenter Syslog server → vcenter_admin account creation → reverse_ssh persistence → Babuk-derived ransomware deployment | |
| T3 | Unknown actors (SharePoint weak-auth exploitation) | collaboration infrastructure | Public PoC release → weak-authentication bypass → security-feature circumvention on SharePoint Server | |
| T4 | RondoDox botnet operators; unattributed exploitation post-KEV | AI/ML infrastructure, developer tooling | Malicious/malvertised webpage → DNS rebinding bypasses User-Agent check → unauthenticated Ray /api/jobs RCE → cryptomining or botnet incorporation | |
| T5 | Unattributed threat actor (macOS Screen Sharing cryptomining) | endpoint infrastructure, all sectors | Local-network adjacency → authenticate to Screen Sharing without valid credentials → deploy Monero miner | |
| T6 | Head Mare | transport, energy, IT, electronics, software (Russian organizations) | Unauthenticated access via undocumented function on port 4307/TCP → code execution → sandbox escape → trojanized TrueConf client installer replacement | |
| T7 | Unattributed threat actor (Zimbra SNMP exploitation, per CERT Polska) | collaboration infrastructure, all sectors | Unauthenticated SMTP request → SNMP notification command injection → OS command execution as the Zimbra user | |
| T8 | watchTowr-observed scanning activity; unattributed exploitation | AI/ML infrastructure, cloud-hosted MLOps | Unauthenticated webhook-test request → redirect bypasses URL validation → cloud metadata service reached → IAM credential exfiltration | |
| T9 | watchTowr honeypot-observed activity; unattributed exploitation | software development, open-source infrastructure | Unauthenticated @gl_introduced GraphQL directive → code injection → repository deletion, merge-record forgery, maintainer bans | |
| T10 | Medusa ransomware operation (ransomware-as-a-service) | healthcare, defense industrial base, critical manufacturing, government services and facilities, financial services | Initial access broker sale ($100K–$1M) → network intrusion → double extortion via leak site → ransomware deployment |
▶Table methodology & sourcing notes
- CVSS, EPSS and KEV status were re-derived independently from NVD 2.0, FIRST EPSS and the CISA KEV catalogue on 24 August 2026 via scripts/verify-cve.py, plus a direct KEV-feed query for window additions. The Sheet's KEV column flagged one of nine window additions and missed the other eight; all eight were recovered from the feed. TrueConf (T6) carries CVE-2026-72529's score (CVSS 4.0 9.3, EPSS 0.79%) on the combined row; CVE-2026-72530 separately scores CVSS 4.0 9.5, EPSS 0.97%, with a later KEV deadline of 3 September. Zimbra (T7) scores CVSS 3.1 8.9, below the 9.0 threshold this brief otherwise reserves for CRITICAL; severity is carried by KEV listing, unauthenticated command injection, and CERT Polska's field confirmation, the same override applied to the 8.6-scored Cisco ASA/FTD card on 17 August. Medusa (T10) carries no CVE and no scores. vCenter (T2) is a material update of the 17 August card: same CVE, now KEV-listed with a Babuk-derived ransomware payload. TrueConf (T6) is a material update of the 10 August card, which carried Kaspersky KLCERT identifiers and no CVE. SharePoint (T3) is a distinct CVE from the 17 August card (CVE-2026-45659) and from the 20 July cluster, which named this CVE without a CISA due date. EPSS is a daily-moving score; all values here are the 24 August 2026 pull.
Control Deficiency & Framework Mapping
| Threat | Control gaps | ISO 27001 | NIST CSF 2.0 | CIS Controls | Privacy Act / PIPEDA | ITSG-33 | OSFI B-13 | ISO 42001 |
|---|---|---|---|---|---|---|---|---|
T1Windows IKE Extension Double-Free RCE (CVE-2026-33824) |
| , | , , | , | — | , , | , | — |
T2VMware vCenter Syslog RCE Now KEV, Babuk-Derived Ransomware (CVE-2026-59310) |
| , , , | , , , | , , | — | , , | , | — |
T3Microsoft SharePoint Weak Authentication (CVE-2026-55040) |
| , | , , | , | — | , | — | |
T4Ray Browser-Based RCE via DNS Rebinding (CVE-2025-62593) |
| , , | , , | , | — | , , | , | |
T5Apple macOS Screen Sharing Improper Authentication (CVE-2026-65400) |
| , , | , , | , , | — | , , | — | |
T6TrueConf Server Missing Auth and Sandbox Escape, Head Mare Campaign (CVE-2026-72529 / CVE-2026-72530) |
| , , , | , , , | , , | — | , , | — | |
T7Zimbra Collaboration SNMP Command Injection (CVE-2026-73570) |
| , , , | , , , | , , | , | , , | , | — |
T8MLflow Unauthenticated Webhook SSRF (CVE-2026-64849) |
| , , | , , | , | — | , , | ||
T9GitLab GraphQL Code Injection (CVE-2026-19478) |
| , , | , , | , , | — | , , | — | |
T10Medusa Ransomware, 500+ U.S. Critical-Infrastructure Victims |
| , , , | , , , | , , | , | , , | , | — |
Privacy Act / PIPEDA & OSFI: No entry in this register is a confirmed Canadian personal-data breach notification trigger, so every Privacy Act / PIPEDA column reads as a dash rather than an assumed obligation. Medusa (T10) is scoped to U.S. critical infrastructure in the cited advisory with no Canadian victim named; TrueConf (T6) targeting is Russian per Kaspersky, with the Canadian lesson framed as counterparty exposure rather than a domestic breach. If your estate holds Canadian personal information behind SharePoint (T3), vCenter-hosted workloads (T2), or GitLab-hosted repositories (T9), Schedule 1 Principle 4.7 safeguards and PIPEDA s.10.1 reporting analysis apply on your own facts. OSFI B-13 patch, vulnerability-management, access-control and third-party expectations apply to federally regulated institutions running the Windows, virtualization, collaboration, and AI/ML infrastructure named in T1 through T9. Assess all of it against your own data map and regulatory footprint.
Risk Triage
Threats are assigned to primary zones based on their dominant organizational risk characteristic. A threat may appear in a secondary zone when it presents a materially distinct compounding risk dimension.
Active exploitation or weaponized capability with immediate organizational exposure if unaddressed.
- T1Windows IKE double-free — highest EPSS, KEV deadline passed
Unauthenticated RCE over UDP 500/4500 on every supported Windows release, EPSS 0.78. Verify the April patch or apply the UDP-blocking workaround now.
- T2vCenter CVE-2026-59310 — now KEV, ransomware-active
Escalated from last week's campaign to a passed federal deadline with a Babuk-derived ransomware payload. Upgrade every vCenter instance; no workaround exists.
- T3SharePoint CVE-2026-55040 — first KEV listing, PoC-driven exploitation
Distinct from last week's SharePoint card; unknown actors exploiting a weak-auth bypass after a public PoC. Patch every farm as a separate item.
- T4Ray CVE-2025-62593 — botnet-weaponized before disclosure
Browser-triggered RCE against AI infrastructure; RondoDox incorporated it two days before its original disclosure. Upgrade to 2.52.0 and restrict API access.
- T5Apple Screen Sharing CVE-2026-65400 — local-network auth bypass
Confirmed cryptominer delivery via authentication-free desktop access. Update every Mac and disable Screen Sharing where not required.
- T7Zimbra CVE-2026-73570 — KEV deadline is today
Unauthenticated SMTP command injection across 12,100+ exposed instances. Confirm zimbra-snmp exposure and patch before the same-day clock closes.
Confirmed campaign or large-scale exposure with direct impact on organizations or their data.
- T6TrueConf / Head Mare — month-old campaign now has CVEs
Kaspersky confirms installer-trojanization exploitation since at least July, now retroactively mapped to CVE-2026-72529/72530. Verify installer hashes.
- T8MLflow CVE-2026-64849 — credential exfiltration confirmed
watchTowr observed scanning within hours of CVE assignment and confirmed IAM credential exfiltration via cloud metadata. Patch and block metadata-endpoint access.
- T10Medusa ransomware — 500+ critical-infrastructure victims
Joint CISA/HHS/FBI advisory; a mature RaaS now running its own initial-access-broker marketplace. Verify segmentation and remote-access origin restrictions.
Structural control deficiencies revealed by the day's threats, independent of any single exploit.
- T9GitLab CVE-2026-19478 — exploited faster than any KEV entry
Not KEV-listed, yet watchTowr reproduced it in minutes and caught honeypot exploitation. The gap this exposes is a patch-priority process that waits on a federal catalogue.
- T4 · T8Ray and MLflow — AI tooling outside the emergency-patch lane
Neither tool was built with an internet-facing threat model, yet both now carry federal deadlines. The gap is inventory scope, not patch availability.
- T1Windows IKE — Hermes flagged one of nine KEV additions
Eight of nine KEV additions this window required a direct feed query to recover. The gap is intake reliability, not exploitation detection.
Cross-cutting pattern requiring board-level awareness and programme-level response.
- T1 · T2 · T3 · T4 · T5 · T6 · T7Six of eight federal clocks expired before this brief could name them
A weekly reconciliation cycle cannot keep pace with three-day BOD deadlines landing mid-week. Boards should treat continuous KEV monitoring as a standing control, not a publication-day task.
- T2 · T6A numberless finding is not a closed one
vCenter and TrueConf both reopened within weeks of being covered as unconfirmed or CVE-less findings, because the underlying campaigns were already running. Standing re-review triggers, not one-time write-offs, are the control this pattern demands.
Remediation Actions
Consolidated actions across all ten threats, organized by time horizon. T-badges indicate which threat each action addresses.
0 – 24 hours
Immediate response
- T1Verify the April 2026 patch on every Windows host reachable on UDP 500/4500, or block/allowlist those ports immediately.
- T2Upgrade every vCenter instance to 9.1.0.0300, 9.0.2.0100, or 8.0 U3k/U2f; no workaround exists and the deadline passed.
- T3Apply Microsoft's update for CVE-2026-55040 to every SharePoint farm as a separate patch item from CVE-2026-45659.
- T4Upgrade every Ray deployment to 2.52.0 and restrict API access to trusted hosts; the KEV deadline passed 20 August.
- T5Update every Mac to Sequoia 15.7.9, Sonoma 14.8.9, or Tahoe 26.6.1; disable Screen Sharing where not required.
- T7Confirm zimbra-snmp exposure and patch to ZCS 10.1.20 today; the KEV deadline is 24 August.
7 days
Short-term hardening
- T6Update TrueConf Server beyond 5.5.5, restrict port 4307/TCP, and verify installer hashes against Head Mare's trojanized replacements before 3 September.
- T8Upgrade MLflow to 3.15.0, require authentication on every Tracking Server, and block metadata-service IP ranges at the network layer.
- T9Upgrade GitLab to 18.11.11/19.0.8/19.1.6/19.2.4, or restrict unauthenticated /api/graphql access and public-repo visibility in the interim.
- T2Hunt vCenter hosts for reverse_ssh binaries, the vcenter_admin account, and the GoodMoodle-VCFleet/1.0 user agent.
- T7Hunt Zimbra hosts for planted files in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/, and unexpected service restarts.
14 – 30 days
Programme remediation
- T4T8Bring AI/ML infrastructure (Ray, MLflow) inside the same emergency-patch SLA and asset inventory as production internet-facing systems.
- T10Review third-party and remote-access relationships for initial-access-broker indicators, and verify segmentation against the Medusa advisory's recommendations.
- T3Move SharePoint patch tracking to per-CVE granularity so a farm patched against one CVE is not assumed patched against all three this quarter.
- T9Audit merge records and maintainer lists on public GitLab projects for unauthorized changes made before the patch was applied.
Ongoing
Structural controls
- T1–T7Run continuous KEV monitoring rather than weekly reconciliation; six of eight federal clocks this window expired before this brief could name them.
- T1T7Reconcile the Hermes Sheet's KEV column against the CISA feed directly every cycle; it missed eight of nine additions this window.
- T2T6Apply a standing re-review trigger to any card closed as "no CVE yet" or "not KEV-listed," since both vCenter and TrueConf reopened within weeks.
- T9Read primary vendor and researcher reporting independently of the KEV catalogue; GitLab's exploitation preceded any KEV listing entirely.
Provenance
Intelligence Sources
Cadence
Published weekly. Each issue distills the week's most material threats from primary security reporting and vendor advisories, cross-referenced against authoritative sources (CVE/NVD, CISA KEV, and MITRE ATT&CK) and mapped to the compliance obligations that govern your response. Use Subscribe or Share on any issue to join the distribution list.
See how this week's threats map to your control gaps.
Book a briefing →