Four exploited zero-days across Chrome and Windows, a shared espionage exploit kit, and firewall-management exploitation trigger the federal three-day patch clock.
Archive
Every weekly reading, newest first. Readings are immutable once published — corrections append to a visible revision history.
Two chained SonicWall zero-days and admin-token forgery in Artifactory lead a hot exploitation week, while three material-incident filings mark rising intrusion tempo.
Pressure holds at high: an emergency NetScaler patch order and a confirmed federal-agency incident, against a KEV week inflated by catch-up additions of older flaws.
The heaviest KEV week yet — eight additions reaching machine-learning infrastructure — while an active threat to Siemens PLCs keeps critical-infrastructure pressure high.
Exploitation broadens for a third week — firewalls, hypervisors, Windows zero-days — and ransomware crews convert last month's edge-device access; pressure climbs within the high band.
Exploited flaws in remote-management and developer infrastructure drive a second week of rising exploitation; the reading crosses into high pressure.
Zero-day exploitation of perimeter security products and a coordinated attack on water utilities push defender pressure up this week.
Confirmed exploitation of a pre-auth WordPress Core chain drives pressure this week; identity abuse and intrusion tempo hold at elevated levels.