I’m going to challenge the briefing before we accept its priorities.
The loudest headlines today are not necessarily the most important ones. We are not reopening usbliter8 basics. We are not spending half the session rediscovering Splunk RCE. Those are operator reminders now: patch, hunt, verify exposure. The real afternoon agenda is quieter but more dangerous: stolen integration tokens, credential fallout at massive scale, and core infrastructure patch decisions that can break production if handled badly.
First move: Salesloft Drift and Salesforce. OAuth token abuse changes the blast radius because the attacker does not need to “break in” twice; the integration may already have the keys to business data, secrets in cases, support notes, exports, and downstream credentials. Lena, I want attribution and campaign shape. James, I want the 30-minute response plan for customers.
Then we move to the 24-billion credential exposure — not for shock value, but for triage: what is unique, what is duplicated, what is actionable, and where MFA does not save you because cookies and sessions are in play.
After that: Nutanix AOS and Ubuntu 16.04 ESM kernel deltas. Infrastructure risk, not CVE counting.
And we will reserve time for civil society. Cloudflare’s signal matters. NGOs and media are being hit at a rate that should change how defenders and funders think about resilience.