Threat Digest is a weekly reading aid for people who run or depend on Microsoft 365 and the systems around it. A crawler on one machine reads reviewed public feeds, vendor advisories, and the CISA Known Exploited Vulnerabilities catalogue, with no credentials and no bot-protection bypass. Once a week the reviewed items become the page you see here.
Order is triage order, not severity order. Anything with published exploitation evidence outranks a higher-scoring item without it, and a Microsoft 365 workload match outranks everything else. The number shown beside each item is the raw severity score, kept visible so you can see where it disagrees with the ranking. The CISA catalogue often supplies no CVSS score, so a raw scorer would rank an actively exploited Microsoft product below an unexploited one; the triage order corrects that on purpose.
Each item's summary is made of claims quoted verbatim from the publisher's own text and checked against it before publication, whether a local model or Claude selected them. Behind each item, the "what it puts at risk" and "what to do about it" notes are written once per vulnerability class, such as authentication bypass or privilege escalation, by hand.
The headline, the standfirst, the one-line "why" and "do" beside each start-here item, the pattern paragraph, the trends reading and the weekly LinkedIn post are written by Claude Opus 5 from those quoted claims, the class notes and the week's counts, and published without a human edit. When that step is unavailable the page falls back to computed text built from counts and class names. Posts are written by hand.
Confirm against the linked publisher before acting on anything. Threat Digest is not affiliated with Microsoft or with any publisher linked here; names and links are attribution, not endorsement.
There is an RSS feed with one entry per week and one per post. What the digest reads is listed below.
20 sources, in the order the digest trusts them. A further 28 are in the registry but disabled, mostly dead feeds and community sources awaiting a reviewed adapter. The RSS ones are in feeds.opml for your own reader.
Read every week. These two decide what the top of this page says.
Vendor and workload detail. Where a Microsoft-specific issue shows up first.
Trade reporting. Useful for context and for spotting a story before it is an advisory.
Community and commentary. Occasionally early, frequently noise.