<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Last Week in Threats — Focused Hunts</title>
    <link>https://www.focusedhunts.com/blog/last-week-in-threats</link>
    <description>A weekly retrospective recap of ransomware activity, exploited CVEs, and malicious infrastructure, with attributed metrics.</description>
    <language>en-us</language>
    <lastBuildDate>Tue, 08 Sep 2026 11:20:02 GMT</lastBuildDate>
    <atom:link href="https://www.focusedhunts.com/blog/last-week-in-threats/feed.xml" rel="self" type="application/rss+xml" />
    <image>
      <url>https://www.focusedhunts.com/img/logo/Focused-Hunts-Logo.png</url>
      <title>Last Week in Threats — Focused Hunts</title>
      <link>https://www.focusedhunts.com/blog/last-week-in-threats</link>
    </image>
    <item>
      <title>Last Week in Threats: Week 36</title>
      <link>https://www.focusedhunts.com/blog/last-week-in-threats/2026-W36-Last-Week-in-Threats</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/last-week-in-threats/2026-W36-Last-Week-in-Threats</guid>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <description>Week 36 (Aug 31 - Sep 6, 2026): Ransomware volume dropped 20%, datacenter hosting dominated the most-reported malicious IPs, and CISA added three developer-tooling vulnerabilities to KEV.</description>
    </item>
    <item>
      <title>Last Week in Threats: Week 35 (August 24-30, 2026)</title>
      <link>https://www.focusedhunts.com/blog/last-week-in-threats/2026-W35-Last-Week-in-Threats</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/last-week-in-threats/2026-W35-Last-Week-in-Threats</guid>
      <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
      <description>Qilin ransomware surged 31% week-over-week while overall ransomware victim volume dropped 14.5%. CISA added 11 CVEs targeting developer tooling, infrastructure, and edge appliances.</description>
    </item>
    <item>
      <title>Last Week in Threats: Week 34 (August 17-23, 2026)</title>
      <link>https://www.focusedhunts.com/blog/last-week-in-threats/2026-W34-Last-Week-in-Threats</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/last-week-in-threats/2026-W34-Last-Week-in-Threats</guid>
      <pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate>
      <description>Weekly retrospective recap of ransomware leak-site activity, most-reported malicious IPs, and newly exploited vulnerabilities for the week of August 17-23, 2026. Direwolf surged 40 percent, Zimbra and MLflow CVEs under active exploitation, manufacturing sector concentrated.</description>
    </item>
    <item>
      <title>Last Week in Threats: Week 33</title>
      <link>https://www.focusedhunts.com/blog/last-week-in-threats/2026-W33-Last-Week-in-Threats</link>
      <guid isPermaLink="true">https://www.focusedhunts.com/blog/last-week-in-threats/2026-W33-Last-Week-in-Threats</guid>
      <pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate>
      <description>Week 33 threat recap: Clop and Qilin ransomware doubled leak-site postings, targeting healthcare and education. Three actively-exploited CVEs added to CISA KEV.</description>
    </item>
  </channel>
</rss>
