Weekly Recap
A standing weekly desk brief for the advisories, outages, releases, and deadlines that should reshape change priorities.
The weekly recap is not a retrospective list of headlines. It is a compact operational brief for people who need to notice what changed outside their organization before the next change window or CAB agenda is locked. A useful edition connects vendor advisories, exploited-vulnerability developments, service disruptions, regulatory clocks, and platform releases to the decisions they may force. CAB chairs can use it to ask whether scheduled work now carries new dependencies. Security leaders can spot remediation items that need an owner. Operations leads can compare an external event with an assumption in their own recovery plan. The value lies in the selected implications, not in repeating every announcement from the week.
This series follows the signals most likely to alter a change-risk queue and frames them for practical review. Each installment can become a standing agenda input: items requiring triage, changes needing revalidation, provider events worth monitoring, and deadlines that should not wait for a monthly cycle. It is particularly useful for teams whose operational knowledge is spread across security, cloud, compliance, and service management functions. Rather than treating external intelligence as a separate research task, readers can use these briefs to create a predictable handoff into planning and governance. The discipline is simple but demanding: identify the signal, name the potentially affected service or control, assign investigation, and decide whether the current plan still holds.
Start here
-
This Week in Change Risk — Week of Aug 10, 2026
Demonstrates the latest edition's compact format for turning current signals into operational follow-up.
-
This Week in Change Risk — Week of Jul 20, 2026
Shows the recurring column's role as a cross-functional intake point for change-risk decisions.
More on Weekly Recap
-
This Week in Change Risk — Week of Sep 7, 2026
A record 970-plus-flaw Patch Tuesday with two exploited zero-days, MikroTik and Citrix NetScaler KEV additions, and Cloudflare Workers wobbles this week.
-
This Week in Change Risk — Week of Aug 31, 2026
AI infrastructure hit the CISA KEV catalog hard this week: LiteLLM, Kestra, and JFrog joined nine new exploited CVEs. Plus SonicWall, PaperCut, and DORA.
-
This Week in Change Risk — Week of Aug 24, 2026
A CVSS-10.0 Oracle flaw with CISA's tightest three-day deadline, six more KEV entries, GitHub's outage pledge, and PagerDuty's SRE-agent drop.
-
This Week in Change Risk — Week of Aug 17, 2026
Eight new CISA KEV entries led by a critical VMware vCenter flaw, GitHub's near-8-hour outage post-mortem, and NIS2's October deadline closing in.
-
This Week in Change Risk — Week of Aug 3, 2026
A CVSS 9.8 JetBrains TeamCity RCE in KEV, two GitHub Actions outages in two days, Microsoft's Aug 11 Patch Tuesday, and NIS2 pressure this week.
-
This Week in Change Risk — Week of Jul 27, 2026
A CVSS 10.0 Arista SD-WAN flaw in KEV, a GitHub Copilot incident, Datadog's DASH launches, and the ECB's AI deadline — the week's change-risk signals.