I think this briefing has the wrong center of gravity.
The big credential-leak headline is not where we spend the room today. It is stale, it is broad, and our identity guidance does not materially change: kill reuse, revoke risky sessions, enforce MFA, watch account takeover. Fine. Not ignored — but not today’s debate.
Today is about trust in infrastructure that defenders normally assume is safe: endpoint protection, VPN configuration, embedded SSH libraries, AI build pipelines, and vendor update channels. That is a very different day. Defender has a public PoC and no clean patch story yet. SonicWall risk persists even after patching because the configuration plane is still exposed. libssh2 may be buried in products nobody has inventoried. vLLM shows us dependency confusion moving straight into AI containers. And FortiBleed is not “another Fortinet story” if the new evidence changes credential-harvesting scale and diagnostic-command tradecraft.
So I want us to stay disciplined. No FortiBleed basics. No duplicate CVE inflation. No single-IOC archaeology.
First move: Alex and James, I want the 30-minute operator version of RoguePlanet and SonicWall — exposure, interim controls, and what we do when the trusted security layer itself may be the uncertain component. Lena, you are listening for campaign signal and supply-chain deltas, not headline volume. James, you will close each thread with what a CISO can actually order today.