<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>Threat Digest</title><link>https://threat-digest.pages.dev/</link><description>Weekly reading aid for Microsoft 365 security, from reviewed public sources.</description><item><title>Week 38: Access control failures drive six of eleven exploited flaws this week</title><link>https://threat-digest.pages.dev/2026/w38/</link><guid isPermaLink="true">https://threat-digest.pages.dev/2026/w38/</guid><pubDate>Wed, 16 Sep 2026 08:00:00 +0000</pubDate><description>Forty-five items were reviewed between 9 and 16 September, and eleven of them have published exploitation. Five touch Microsoft 365, and none of those five have published exploitation. One publisher supplied 22 of the 45 items, so treat the shape of the week as partly a property of the source mix.</description></item><item><title>Why a weekly page, not a feed</title><link>https://threat-digest.pages.dev/posts/why-a-weekly-page/</link><guid isPermaLink="true">https://threat-digest.pages.dev/posts/why-a-weekly-page/</guid><pubDate>Wed, 16 Sep 2026 08:00:00 +0000</pubDate><description>What Threat Digest is for, and why it publishes once a week instead of streaming every headline.</description></item><item><title>When writing code is free, review becomes the control</title><link>https://threat-digest.pages.dev/posts/when-writing-code-is-free-review-becomes-the-control/</link><guid isPermaLink="true">https://threat-digest.pages.dev/posts/when-writing-code-is-free-review-becomes-the-control/</guid><pubDate>Wed, 16 Sep 2026 08:00:00 +0000</pubDate><description>A look inside one lab&#x27;s agentic software factory shows that once generation costs nothing, the scarce resource — and the real security control — becomes review, provenance, and containment.</description></item></channel></rss>
