The Harm Surface

Weekly newsletter · Issue 01 · 3 August 2026

AI, cyber and autonomy, read as one threat surface.

1,543 items read. 16 worth your attention.

A free weekly newsletter for CISOs and the people who decide what to act on before the guidance even exists. The gap between 1,543 and 16 is the reading you no longer have to do.

3,434 of 5,091 vulnerabilities under observed exploitation are not in CISA's catalog — no advisory, no deadline, no guidance. Counted from the exploitation catalogs this brief reads, 3 August 2026.

Free · one click out · no sponsor chooses an item
Next issue — Wednesday 07:00 UTC

The shape of issue 01 →

6 read this 10 worth knowing

Bar height is the significance score. Most weeks are ordinary, and the graphic says so.

8 of 16 items span more than one domain.

This week's lead

read this · confirmed · 1 source

CISA adds the Cisco FMC hard-coded password to KEV — a console flaw, exploited

Consoles under attack: Cisco and N-able exploited, Arista reported, Check Point PoC'd; JFrog confirms a burned zero-day.

Read issue 01 →

How this is different →

Deterministic · inspectable · printable

Keep the newsletters you already read — this is the one where no language model picks the stories, no vendor press release can lead, and the ranking is arithmetic you can print and check.

No model decides what matters

Every rank is a weighted sum you can open. The language model's only job is compression and framing.

Vendor-only claims are capped

However loud the press release, it cannot lead an issue. Most weeks more is cut than kept.

Whoever found it is named

Credited when they were first, however small their following. The trade press reliably fails at this.

Under 7 minutes, every Wednesday at 07:00 UTC.

That is the whole promise.