<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>Threat Digests | East Bay Cyber</title><link>https://eastbaycyber.com/digests/</link><description>Daily and weekly cybersecurity threat digests, breach analyses, and CISA KEV updates.</description><lastBuildDate>Sun, 04 Oct 2026 07:43:53 GMT</lastBuildDate><item><title>Threat Digest: SharePoint Attacks &amp; Critical RCE Flaws</title><link>https://eastbaycyber.com/content/2026-10-03-digest-sharepoint-ransomware-rce-flaws/</link><guid isPermaLink="false">2026-10-03-digest-sharepoint-ransomware-rce-flaws</guid><pubDate>Sat, 03 Oct 2026 00:00:00 GMT</pubDate><description>Cybersecurity threat digest for October 3, 2026 covering SharePoint ransomware attacks, critical RCE flaws, Chrome updates, and urgent defender actions. CISA added 7 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Cybersecurity Threat Digest: October 2, 2026</title><link>https://eastbaycyber.com/content/2026-10-02-digest-fortimail-zero-day-ai-attacks/</link><guid isPermaLink="false">2026-10-02-digest-fortimail-zero-day-ai-attacks</guid><pubDate>Fri, 02 Oct 2026 00:00:00 GMT</pubDate><description>A practical October 2, 2026 cybersecurity digest covering the FortiMail zero-day, AI-driven attacks, ransomware disruption and urgent defender actions. CISA added 7 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Threat Digest: Cisco SD-WAN Added to CISA KEV</title><link>https://eastbaycyber.com/content/2026-10-01-digest-cisco-sdwan-kev/</link><guid isPermaLink="false">2026-10-01-digest-cisco-sdwan-kev</guid><pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate><description>Cybersecurity threat digest for October 1, 2026: Cisco SD-WAN enters CISA KEV, critical vulnerabilities, breach reports, and actions for defenders. CISA added 8 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Cybersecurity Threat Digest: September 30, 2026</title><link>https://eastbaycyber.com/content/2026-09-30-digest-bitget-citrix-clickfix/</link><guid isPermaLink="false">2026-09-30-digest-bitget-citrix-clickfix</guid><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate><description>September 30, 2026 cybersecurity digest: Bitget&#x27;s $387.5M theft, Citrix NetScaler exploitation, ClickFix malware, and urgent actions for security teams. CISA added 9 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Threat Digest: Apple Zero-Day &amp; Cloud Attacks</title><link>https://eastbaycyber.com/content/2026-09-29-digest-apple-zero-day-cloud-attacks/</link><guid isPermaLink="false">2026-09-29-digest-apple-zero-day-cloud-attacks</guid><pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate><description>September 29 threat digest covering an exploited Apple zero-day, NetScaler attacks, exposed Supabase databases, Azure destruction, and critical CVEs. CISA added 8 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Threat Digest: Citrix NetScaler Zero-Days | Sep 28</title><link>https://eastbaycyber.com/content/2026-09-28-digest-citrix-netscaler-zero-days/</link><guid isPermaLink="false">2026-09-28-digest-citrix-netscaler-zero-days</guid><pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate><description>September 28, 2026 threat digest: exploited Citrix NetScaler flaws, crypto theft, cloud isolation, healthcare, and OT risks. CISA added 11 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Threat Digest — September 27, 2026: NetScaler Zero-Days</title><link>https://eastbaycyber.com/content/2026-09-27-digest-netscaler-peoplesoft-zero-days/</link><guid isPermaLink="false">2026-09-27-digest-netscaler-peoplesoft-zero-days</guid><pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate><description>Cybersecurity threat digest for September 27, 2026: NetScaler zero-days, PeopleSoft WAF bypass, supply-chain risk, and critical CVEs. CISA added 12 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Cybersecurity Threat Digest: September 26, 2026</title><link>https://eastbaycyber.com/content/2026-09-26-digest-cybersecurity-threats-linux-kernel/</link><guid isPermaLink="false">2026-09-26-digest-cybersecurity-threats-linux-kernel</guid><pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate><description>Today&#x27;s cybersecurity threat digest covers exploited enterprise flaws, a Kiteworks shutdown warning, telecom crime sentencing, and Linux kernel vulnerabilities for defenders. CISA added 10 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Cybersecurity Threat Digest: September 25, 2026</title><link>https://eastbaycyber.com/content/2026-09-25-digest-roundcube-bitget-docker-vulnerabilities/</link><guid isPermaLink="false">2026-09-25-digest-roundcube-bitget-docker-vulnerabilities</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Daily cybersecurity threat digest covering active Roundcube exploitation, Bitget crypto theft, Windows failures, malware campaigns, and critical flaws. CISA added 10 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Threat Digest: TeamCity Ransomware &amp; Critical CVEs</title><link>https://eastbaycyber.com/content/2026-09-24-digest-teamcity-ransomware-critical-cves/</link><guid isPermaLink="false">2026-09-24-digest-teamcity-ransomware-critical-cves</guid><pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate><description>Cybersecurity threat digest for September 24, 2026: TeamCity ransomware exploitation, VPN attacks, WordPress abuse, critical CVEs, and defender actions. CISA added 10 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Cybersecurity Threat Digest — September 23, 2026</title><link>https://eastbaycyber.com/content/2026-09-23-digest-f5-check-point-ai-malware/</link><guid isPermaLink="false">2026-09-23-digest-f5-check-point-ai-malware</guid><pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate><description>F5 and Check Point flaws face active exploitation, while defenders respond to ransomware, AI-enabled malware, MFA abuse, and data theft campaigns. CISA added 8 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Cybersecurity Threat Digest: September 21, 2026</title><link>https://eastbaycyber.com/content/2026-09-21-digest-npm-codex-router-flaws/</link><guid isPermaLink="false">2026-09-21-digest-npm-codex-router-flaws</guid><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><description>Daily cybersecurity threat digest for September 21, 2026 covering npm malware, Codex sandbox escapes, critical router flaws, and defender actions today. CISA added 7 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Threat Digest: AI Agent Attacks and Critical CVEs</title><link>https://eastbaycyber.com/content/2026-09-20-digest-ai-agent-attacks-waterplum-critical-vulnerabilities/</link><guid isPermaLink="false">2026-09-20-digest-ai-agent-attacks-waterplum-critical-vulnerabilities</guid><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><description>Cybersecurity threat digest for September 20, 2026 covering AI agent attacks, WaterPlum activity, ransomware disruption and five critical vulnerabilities. CISA added 7 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Threat Digest: AI Breaches, vm2 Escapes &amp; Data Theft</title><link>https://eastbaycyber.com/content/2026-09-19-digest-ai-breaches-vm2-escapes-data-theft/</link><guid isPermaLink="false">2026-09-19-digest-ai-breaches-vm2-escapes-data-theft</guid><pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate><description>September 19, 2026 cybersecurity threat digest covering AI-assisted breaches, Gyazo data theft, vm2 sandbox escapes, malware campaigns, and urgent fixes. CISA added 7 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Threat Digest: Check Point, AI Malware &amp; Supply Chain</title><link>https://eastbaycyber.com/content/2026-09-18-digest-check-point-ai-malware-supply-chain/</link><guid isPermaLink="false">2026-09-18-digest-check-point-ai-malware-supply-chain</guid><pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate><description>Cybersecurity threat digest for September 18, 2026 covering a critical Check Point flaw, AI-enabled Android malware, Brevo supply-chain abuse, and urgent fixes. CISA added 7 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Threat Digest: Cisco ISE Zero-Day and Linux Flaws</title><link>https://eastbaycyber.com/content/2026-09-17-digest-cisco-ise-linux-kernel-flaws/</link><guid isPermaLink="false">2026-09-17-digest-cisco-ise-linux-kernel-flaws</guid><pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate><description>September 17, 2026 threat digest: exploited Cisco ISE zero-day, Linux kernel flaws, malware campaigns, and Windows domain issues. CISA added 8 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Threat Digest — September 16, 2026: Zero-Days &amp; MCP</title><link>https://eastbaycyber.com/content/2026-09-16-digest-android-wordpress-mcp/</link><guid isPermaLink="false">2026-09-16-digest-android-wordpress-mcp</guid><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><description>Cybersecurity threat digest for September 16, 2026 covering an exploited Android zero-day, WordPress backdoors, critical MCP flaws, and urgent defender actions. CISA added 10 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Cisco Secure Email Gateway Zero-Day | Threat Digest</title><link>https://eastbaycyber.com/content/2026-09-15-digest-cisco-secure-email-gateway-zero-day/</link><guid isPermaLink="false">2026-09-15-digest-cisco-secure-email-gateway-zero-day</guid><pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate><description>Cybersecurity threat digest for September 15, 2026: Cisco&#x27;s exploited zero-day, critical vulnerabilities, Microsoft fixes, breaches, and active attacks. CISA added 11 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>ClickFix macOS Theft, Water System Risk, and Apache CXF Flaws Lead the August 7 Threat Digest</title><link>https://eastbaycyber.com/content/2026-08-07-digest-clickfix-macos-theft-water-system-risk-apache-cxf-flaws/</link><guid isPermaLink="false">2026-08-07-digest-clickfix-macos-theft-water-system-risk-apache-cxf-flaws</guid><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate><description>Daily cybersecurity threat digest covering ClickFix on macOS, water sector exposure, SharePoint fallout, and critical Apache CXF and WSO2 flaws. CISA added 6 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>CISA Flags Active Exploitation as Snowflake Theft Case Advances</title><link>https://eastbaycyber.com/content/2026-08-06-digest-cisa-flags-active-exploitation-as-snowflake-theft-case-advances/</link><guid isPermaLink="false">2026-08-06-digest-cisa-flags-active-exploitation-as-snowflake-theft-case-advances</guid><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate><description>Daily threat digest covering active exploitation warnings, major cybercrime cases, and practical defender actions for August 6, 2026. CISA added 5 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>QuickFox Supply Chain Backdoor, Omada ZTP Flaws, and Microsoft 365 Phishing Lead the Cybersecurity Threats on August 5, 2026</title><link>https://eastbaycyber.com/content/2026-08-05-digest-quickfox-supply-chain-backdoor-omada-ztp-flaws-microsoft-365-phishing/</link><guid isPermaLink="false">2026-08-05-digest-quickfox-supply-chain-backdoor-omada-ztp-flaws-microsoft-365-phishing</guid><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate><description>QuickFox supply chain malware, TP-Link Omada ZTP flaws, and Microsoft 365 phishing headline today&#x27;s cybersecurity threats and actions. CISA added 5 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Hotel Wi-Fi M365 Breaches, Google Passkey Abuse, and Critical SiYuan and Adobe Flaws Lead August 4 Security News</title><link>https://eastbaycyber.com/content/2026-08-04-digest-hotel-wi-fi-m365-breaches-google-passkey-abuse-and-critical-siyuan-and-adobe-flaws-lead-august-4-security-news/</link><guid isPermaLink="false">2026-08-04-digest-hotel-wi-fi-m365-breaches-google-passkey-abuse-and-critical-siyuan-and-adobe-flaws-lead-august-4-security-news</guid><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><description>Today’s top cybersecurity threats include hotel Wi-Fi Microsoft 365 attacks, passkey abuse research, and critical SiYuan and Adobe flaws. CISA added 5 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Energy OT Supply Chain Risk, COLDCARD Wallet Losses, and Critical PyAthena and FreeRDP Flaws Lead Today’s Cybersecurity Threats</title><link>https://eastbaycyber.com/content/2026-08-03-digest-energy-ot-supply-chain-risk-coldcard-wallet-losses-and-critical-pyathena-and-freerdp-flaws-lead-todays-cybersecurity-threats/</link><guid isPermaLink="false">2026-08-03-digest-energy-ot-supply-chain-risk-coldcard-wallet-losses-and-critical-pyathena-and-freerdp-flaws-lead-todays-cybersecurity-threats</guid><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><description>Today’s cybersecurity threats include OT supply chain risk, costly ransomware fallout, AI-enabled fraud, and critical flaws in PyAthena and FreeRDP. CISA added 2 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Iran-Linked Water Sector Cyber Concerns and Critical Rails, Wazuh, FreeRDP Flaws Lead August 2 Threat Digest</title><link>https://eastbaycyber.com/content/2026-08-02-digest-iran-linked-water-sector-cyber-concerns-and-critical-rails-wazuh-freerdp-flaws-lead-august-2-threat-digest/</link><guid isPermaLink="false">2026-08-02-digest-iran-linked-water-sector-cyber-concerns-and-critical-rails-wazuh-freerdp-flaws-lead-august-2-threat-digest</guid><pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate><description>August 2 threat digest covering suspected Iran-linked water sector activity, a critical Rails flaw, and high-severity bugs in Wazuh, FreeRDP, and WordPress. CISA added 3 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Amgen Cloud Breach, Arch AUR Lockdown, and CISA Water Utility Warning</title><link>https://eastbaycyber.com/content/2026-08-01-digest-amgen-cloud-breach-arch-aur-lockdown-cisa-water-utility-warning/</link><guid isPermaLink="false">2026-08-01-digest-amgen-cloud-breach-arch-aur-lockdown-cisa-water-utility-warning</guid><pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate><description>Daily digest covering Amgen’s cloud breach, Arch AUR malware response, Adform script compromise, water sector threats, and critical CVEs. CISA added 3 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Claude Test Breaches, TeamCity RCE Warning, and VMware Flaws</title><link>https://eastbaycyber.com/content/2026-07-31-digest-claude-test-breaches-teamcity-rce-warning-and-vmware-flaws/</link><guid isPermaLink="false">2026-07-31-digest-claude-test-breaches-teamcity-rce-warning-and-vmware-flaws</guid><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate><description>Today&#x27;s threat digest covers Claude breaches, TeamCity RCE, VMware flaws, and actions defenders should take now. CISA added 3 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>Exchange OWA Zero-Day and Cisco FMC Exploitation - July 30 Security Digest</title><link>https://eastbaycyber.com/content/2026-07-30-digest-exchange-owa-zero-day-and-cisco-fmc-exploitation/</link><guid isPermaLink="false">2026-07-30-digest-exchange-owa-zero-day-and-cisco-fmc-exploitation</guid><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate><description>Digest on Exchange OWA zero-day abuse, Cisco FMC exploitation, healthcare theft risks, and critical Apache flaws. CISA added 3 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>DNS Hijack, Artifactory Zero-Days, and vBulletin RCE Lead Today’s Cybersecurity Threats</title><link>https://eastbaycyber.com/content/2026-07-29-digest-dns-hijacking-artifactory-zero-days-vbulletin-rce/</link><guid isPermaLink="false">2026-07-29-digest-dns-hijacking-artifactory-zero-days-vbulletin-rce</guid><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><description>July 29 threat digest covering CubePilot DNS hijack, OpenAI-Artifactory abuse, vBulletin RCE, and five critical flaws defenders should triage. CISA added 3 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>FastJson Zero-Day Attacks, Arista VeloCloud KEV Patch, and Dysphoria Botnet Lead July 28 Threat Digest</title><link>https://eastbaycyber.com/content/2026-07-28-digest-fastjson-zero-day-arista-velocloud-dysphoria-botnet/</link><guid isPermaLink="false">2026-07-28-digest-fastjson-zero-day-arista-velocloud-dysphoria-botnet</guid><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate><description>Daily cybersecurity digest for July 28, 2026 covering FastJson attacks, Arista VeloCloud exploitation, Dysphoria botnet, and critical CVEs. CISA added 4 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item><item><title>GitHub and PyPI Tighten Supply Chain Defenses as TELESHIM Targets Middle East Governments</title><link>https://eastbaycyber.com/content/2026-07-27-digest-github-pypi-tighten-supply-chain-defenses-as-teleshim-targets-middle-east-governments/</link><guid isPermaLink="false">2026-07-27-digest-github-pypi-tighten-supply-chain-defenses-as-teleshim-targets-middle-east-governments</guid><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate><description>Cybersecurity digest for July 27, 2026 covering GitHub and PyPI protections, TELESHIM activity, ENISA policy moves, and vulnerabilities. CISA added 8 vulnerabilities to the Known Exploited Vulnerabilities catalog in the seven days to this digest.</description></item></channel></rss>
