I think this briefing has the wrong headline.
If anyone walks into this room wanting another FortiBleed discussion, stop there. The scale numbers are ugly, yes, but unless we get new Fortinet or CISA-confirmed IOCs, the response doesn’t change much this morning. We monitor it. We do not let it eat the table.
Today is about fresh exploitability and stolen access paths. Ubiquiti UniFi OS is under active pressure, and that means admin compromise, rogue accounts, and exposed management surfaces. Cisco SD-WAN is back on the table only because Mandiant added usable tradecraft — root access, troot, config theft, unauthorized peers. That is a hunting agenda, not a headline.
Then we have two very practical web and app-stack problems: unauthenticated Langflow RCE in exposed AI workflows, and Laravel Livewire exploitation moving straight into credential and cloud key theft. Those are not theoretical. They become incident response tickets quickly.
And one more thing: the MFA comfort blanket is fraying. Device-code and token phishing are turning “MFA enabled” into a false sense of security, especially in Microsoft 365-heavy environments.
So we start with what changes response today: exploitable edge/admin platforms, exposed AI apps, stolen tokens, stolen secrets. Alex, James, Lena — I want decision-ready findings, not CVE theater. Patch this, hunt that, rotate these. That is the bar this morning.