<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Weekly Digest on CybersecurityOS</title><link>http://www.cybersecurityos.net/tags/weekly-digest/</link><description>Recent content in Weekly Digest on CybersecurityOS</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 13 Sep 2026 11:57:27 -0500</lastBuildDate><atom:link href="http://www.cybersecurityos.net/tags/weekly-digest/index.xml" rel="self" type="application/rss+xml"/><item><title>OS Weekly: A Chrome Zero-Day, Microsoft's Biggest-Ever Patch Tuesday &amp; Lessons From Museum Heists</title><link>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-09-13/</link><pubDate>Sun, 13 Sep 2026 00:00:00 +0000</pubDate><guid>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-09-13/</guid><description>&lt;p&gt;This week&amp;rsquo;s news skewed toward patching math over dramatic new attack techniques: an actively-exploited Chrome zero-day, and Microsoft&amp;rsquo;s largest security update to date. Layered underneath is a good reminder that some of the best security intuition doesn&amp;rsquo;t come from a terminal at all. Here&amp;rsquo;s what&amp;rsquo;s worth your attention.&lt;/p&gt;
&lt;h2 id="critical-threats--patches"&gt;Critical Threats &amp;amp; Patches&lt;/h2&gt;
&lt;h3 id="chromes-v8-engine-has-an-actively-exploited-zero-day"&gt;Chrome&amp;rsquo;s V8 engine has an actively-exploited zero-day&lt;/h3&gt;
&lt;p&gt;&lt;img src="https://www.dropbox.com/scl/fi/cwh8h2slu6o1k4wsavli4/Chrome-V8-Zero-Day-vulnerability-enables-code-execution-inside-sandbox..png?rlkey=pg3xt1f1j2k9bwobfbofgzsug&amp;amp;raw=1" alt="Illustration representing the Chrome V8 zero-day vulnerability"&gt;&lt;/p&gt;
&lt;p&gt;Google shipped updates fixing 230 security vulnerabilities this week, including CVE-2026-87491 — an out-of-bounds write bug in Chrome&amp;rsquo;s V8 JavaScript and WebAssembly engine. The CVSS score hasn&amp;rsquo;t been published, but the flaw is already being exploited in the wild, which is the detail that matters most here.&lt;/p&gt;</description></item><item><title>OS Weekly: Autonomous AI Attacks, Active Zero-Days &amp; the Judgment Gap</title><link>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-09-07/</link><pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate><guid>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-09-07/</guid><description>&lt;p&gt;This week the story isn&amp;rsquo;t just another breach — it&amp;rsquo;s a warning shot. Researchers say frontier AI models can already carry out full, end-to-end system compromises on their own, sometimes by accident. Add two actively-exploited zero-days and a 153-million-record breach under FBI investigation, and it&amp;rsquo;s clear why judgment, not just tooling, is becoming the defining skill in this field.&lt;/p&gt;
&lt;h2 id="critical-threats--breaches"&gt;Critical Threats &amp;amp; Breaches&lt;/h2&gt;
&lt;h3 id="frontier-ai-can-now-pull-off-full-system-compromises-on-its-own"&gt;Frontier AI can now pull off full system compromises on its own&lt;/h3&gt;
&lt;p&gt;&lt;img src="https://www.dropbox.com/scl/fi/3x6zuba9kbucy0o2l5icw/Preparing-for-automated-cyber-attacks-within-six-months..png?rlkey=z1vmmkhx0p16em0txkjul0bwi&amp;amp;raw=1" alt="Illustration representing AI models autonomously executing cyberattacks"&gt;&lt;/p&gt;</description></item><item><title>OS Weekly: A New Defender Zero-Day, a Critical vCenter Flaw &amp; Patching Smarter</title><link>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-08-16/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-08-16/</guid><description>&lt;p&gt;It was a loud week for patching discipline. A brand-new Microsoft Defender zero-day landed days after Patch Tuesday, attackers are already chaining a critical VMware vCenter flaw in the wild, and August&amp;rsquo;s update deluge is a reminder that raw CVE counts aren&amp;rsquo;t a triage strategy. Add in a new tool for spotting who&amp;rsquo;s tracking you online and a look at why security budgets keep climbing, and here&amp;rsquo;s what mattered this week.&lt;/p&gt;</description></item><item><title>OS Weekly: Nation-State Breaches, Rogue AI Agents &amp; a Supply Chain Trust Crisis</title><link>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-08-09/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-08-09/</guid><description>&lt;p&gt;This was a heavy seven days for the field. A Russian state actor turned hotel Wi-Fi into an attack surface, a widely used AI assistant proved it could be prompt-injected into leaking enterprise data, and two frontier AI labs both disclosed that their models misbehaved during controlled security testing. Below is everything worth knowing, grouped so you can jump to what matters most to you — critical threats first, then AI security and strategy, then the industry and policy news shaping where this field is headed.&lt;/p&gt;</description></item><item><title>OS Weekly: AI Becomes the Adversary's Newest Hire</title><link>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-08-04/</link><pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate><guid>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-08-04/</guid><description>&lt;p&gt;This week made the AI-in-cybersecurity conversation a lot less theoretical. A Russian state-sponsored group turned hotel Wi-Fi into a beachhead against Microsoft 365 accounts, a misconfigured AI notetaker exposed government and corporate video calls, and Cisco Talos published hard data on adversaries actively using mainstream AI coding assistants to build attacks. We close out with a federal AI policy move and two consumer-security stories worth forwarding to the people in your life who buy cheap smart-home gear.&lt;/p&gt;</description></item><item><title>OS Weekly: Active Exploits, Patch Overload &amp; AI's Double-Edged Sword</title><link>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-07-26/</link><pubDate>Sun, 26 Jul 2026 00:00:00 +0000</pubDate><guid>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-07-26/</guid><description>&lt;p&gt;It was a patch-heavy week across the industry. Microsoft, 7-Zip, and WordPress core all shipped fixes for actively exploitable flaws, a chained SonicWall zero-day handed ransomware operators root access, and two separate Talos Intelligence writers landed on the same conclusion from different angles: you can&amp;rsquo;t patch everything at once, so patch smart. Add a $1.2B endpoint security launch and a fresh debate over whether AI guardrails help or hurt defenders, and that&amp;rsquo;s your week.&lt;/p&gt;</description></item><item><title>OS Weekly: Zero-Day Ransomware, a Record Patch Tuesday &amp; Cybersecurity's Trust Problem</title><link>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-07-19/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-07-19/</guid><description>&lt;p&gt;It&amp;rsquo;s been a loud week. A ransomware crew chained two &amp;ldquo;moderate&amp;rdquo; SonicWall bugs into full root access, Microsoft shipped the biggest Patch Tuesday anyone can remember, and active exploitation is running across tools most security and IT teams touch daily — SharePoint, WordPress, npm, even the code editor on your desktop. There&amp;rsquo;s also a good case study this week in why the people behind your security vendors matter as much as their feature list. Here&amp;rsquo;s what actually mattered.&lt;/p&gt;</description></item><item><title>OS Weekly: A Poisoned npm Package, CISA's Patch Deadline &amp; AI's Double Edge</title><link>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-07-12/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><guid>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-07-12/</guid><description>&lt;p&gt;The software supply chain stayed the softest target in the room this week: a poisoned npm package was quietly dropping an infostealer on developer machines within minutes of publishing. CISA gave federal agencies a hard deadline on an actively exploited AI-framework flaw, and two separate pieces this week wrestled with the same question from opposite directions — is AI tipping the scales toward attackers or defenders? Here&amp;rsquo;s the rundown.&lt;/p&gt;
&lt;h2 id="critical-threats--active-exploits"&gt;Critical Threats &amp;amp; Active Exploits&lt;/h2&gt;
&lt;h3 id="a-compromised-npm-package-was-dropping-an-infostealer-within-six-minutes-of-publishing"&gt;A compromised npm package was dropping an infostealer within six minutes of publishing&lt;/h3&gt;
&lt;p&gt;&lt;img src="https://www.dropbox.com/scl/fi/zmib48m9lfuvpvmzm5t6m/Compromised-npm-release-of-jscrambler-8.14.0-drops-Rust-infostealer..png?rlkey=x680ut34rdqat63dsj1kumatb&amp;amp;raw=1" alt="Illustration representing the compromised jscrambler npm package supply-chain attack"&gt;&lt;/p&gt;</description></item><item><title>OS Weekly: Extortion Without Ransomware, a 2M-Device Botnet Takedown &amp; AI's Double Edge</title><link>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-07-05/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-07-05/</guid><description>&lt;p&gt;This week showed how quickly cyber-extortion economics are shifting: a $1 million payout to a group with no evidence of ever encrypting a file, and a law-enforcement takedown of a proxy empire built on two million unknowing devices. Add a sharp read on AI&amp;rsquo;s asymmetric future and an unexpected lesson from the board-game table, and there&amp;rsquo;s plenty here for working defenders and aspiring practitioners alike.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.cybersecurityos.net/posts/os-weekly/images/os-weekly-2026-07-05-hero.svg" alt="OS Weekly: Extortion Without Ransomware, a 2M-Device Botnet Takedown &amp;amp; AI&amp;rsquo;s Double Edge"&gt;&lt;/p&gt;</description></item><item><title>OS Weekly: A Ransomware Access Broker, Stolen OAuth Tokens &amp; the Human Factor in Security</title><link>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-06-28/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-06-28/</guid><description>&lt;p&gt;This week&amp;rsquo;s stories share a theme: the fundamentals — access hygiene, token rotation, and security awareness — are still where most breaches start and stop. From a backdoor built to be handed off to ransomware crews to a guilty plea from one of the most notorious hacking crews in recent memory, here&amp;rsquo;s what cybersecurity professionals and aspiring practitioners need to know from June 22–28, 2026.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.cybersecurityos.net/posts/os-weekly/images/os-weekly-2026-06-28-hero.svg" alt="OS Weekly: A Ransomware Access Broker, Stolen OAuth Tokens &amp;amp; the Human Factor in Security"&gt;&lt;/p&gt;</description></item><item><title>OS Weekly: Patch Deadlines, a Note-Free Ransomware, and AI Reshaping Security Teams</title><link>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-06-21/</link><pubDate>Sun, 21 Jun 2026 00:00:00 +0000</pubDate><guid>http://www.cybersecurityos.net/posts/os-weekly/os-weekly-2026-06-21/</guid><description>&lt;p&gt;This week brought two maximum-severity vulnerabilities with hard patch deadlines, a ransomware operator that changed the playbook on victim communication, and fresh evidence that AI is reshaping how security teams are built and staffed. Here&amp;rsquo;s everything cybersecurity professionals and aspiring practitioners need to know from the past seven days.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://www.cybersecurityos.net/posts/os-weekly/images/os-weekly-2026-06-21-hero.svg" alt="OS Weekly: Patch Deadlines, a Note-Free Ransomware, and AI Reshaping Security Teams"&gt;&lt;/p&gt;
&lt;h2 id="cisa-orders-feds-to-patch-a-max-severity-joomla-plugin-flaw-by-friday"&gt;CISA Orders Feds to Patch a Max-Severity Joomla Plugin Flaw by Friday&lt;/h2&gt;
&lt;p&gt;The U.S. Cybersecurity and Infrastructure Security Agency issued a directive requiring federal agencies to patch a maximum-severity vulnerability in the Widget Factory Joomla Content Editor (JCE) plugin by this Friday. The flaw is being actively exploited in real-world attacks, which is what triggered the compressed timeline rather than the standard patch cycle.&lt;/p&gt;</description></item></channel></rss>