Read from Microsoft's own CVRF. Nothing is publicly disclosed, the 1,170 figure is a month's accumulation, and the field to check is Customer Action Required.
Read from Adobe's own bulletin, the NVD record and CISA's catalogue. A fully patched store was still taken, and the catalogue has not moved since Friday.
MikroTrick, the indicators of compromise, and the methodology section almost nobody quoted. The vendor's own detection marker does not prove a device is clean, and CERT Polska say so.
The most consequential sentence in the IOS XR advisory is the one about how the flaws were found, and almost every write-up removed it. What follows from it is a counting problem.
A directive reported as reducing the patching burden coincides with the most aggressive tier becoming the default on three quarters of new entries. Two opposite errors are circulating about it.
AS62390 announced a Hetzner /24 for 33 hours, diverting Softaculous update traffic. Let's Encrypt issued a valid certificate because its own domain validation was routed through the hijack.
Exploit code for an unpatched local privilege escalation in CrowdStrike Falcon Sensor appeared at 02:48 UTC. The README contains two qualifications the coverage has dropped.
Kestra, LiteLLM and Starlette joined the KEV catalogue at 16:54 UTC with no coverage at all. All three were months old, and the titles misdescribe two of them.
Check Point Research documents Gambling Goblin compromising Brazilian government web servers since mid-2025. The module reverse-proxies three hardcoded prefixes and strips their Content-Security-Policy.
Read from the KEV feed and the NVD API on 2 September 2026: three loud exploitation claims, none catalogued, and a substitution trap where searching KEV by product name clears the wrong identifier.
Thirteen trojanised theme packages were pulled after Socket published. Checked by hand today: a sibling package Socket named as a sleeper is still installable, and the malicious jQuery is still on GitHub.
Kaspersky documents a recruitment lure whose README bans AI code review, declares the trojanised file bug-free, and ships a malicious package inside the archive so no scanner ever sees it.
CVE-2026-82329 lets an unauthenticated attacker reach admin on Artifactory. JFrog fixed it the same day it was published, its advisory misstates the 7.146 fix, and the exploitation claim rests on one firm.
ESET disclosed an inert comment block designed to make AI analysis refuse. The whole primary source is three posts on X, nobody tested it, and Endor Labs documented the same trick in June.
Every stage uses documented Windows behaviour, so there is no patch, no KEV deadline and no scanner finding. The controls that reach it had to be set before the lure arrived.
Black Hat 2026 research with four identifiers, one unpatched open-source path AWS has assigned to the customer, and the reason prompt hardening measured the wrong component.
Huntress documents the first Akira use of Safe Mode boot. The full technique chain contains no exploit at all, the encryptor starved of virtual memory and failed, and the victim is still extortable.
One million implant check-ins, more than 15 government webmail tenants watering-holed by a single script tag, and a supplier relationship the coverage flattened into one team.
Pass-ta-key, Silver and Golden: account takeover with no user interaction, forged biometric verification, and every synced key exported for resale. Why two outlets reached opposite conclusions from the same paper.
Check Point attributes the August zero-day to Lazarus. The exploit is fixed, but the delivery chain, a recruiter approach and an SEO-ranked impersonation site, is untouched and still works.
Counted from Microsoft's release document: 420 CVEs, 176 elevation of privilege, 119 in Office. Why the published totals disagree, and why severity-first triage gets this month wrong.
Initial access changed. The attack path did not. Half of ransomware victims with a credential leak saw it within 95 days of the attack, a window long enough to act in, if anyone is looking.