This is a control-plane day, not a vulnerability-count day.
The obvious lead is the npm binding.gyp campaign: compromised maintainer accounts, install-time execution through node-gyp, and a path into CI/CD that can bypass the script-hook monitoring many teams proudly think they have covered. If that propagates through build systems, the decision is not “patch when convenient.” It may be package freeze, build-host review, and secret rotation today.
But I do not want us to miss the live infrastructure exposure. Cisco Unified Communications Manager CVE-2026-20230 is in KEV with active exploitation, and the federal deadline was June 28 — so this morning, any unpatched environment is already in exception territory. Android CVE-2025-48595 is also being exploited, limited but serious, with no user interaction.
The second lane is identity abuse: FortiBleed against Fortinet access points, Kali365 abusing Microsoft device-code login, and Klue showing how one dormant SaaS credential can become Salesforce data exfiltration downstream. That is the same story in three accents: trusted access becoming attacker infrastructure.
We will give focused airtime to the AI coding-agent prompt-injection work, because it sits right beside the npm issue: repositories are becoming execution environments, not just source code. Polymarket, SecondFi, Tata, deepfake enforcement, and the malware takedown stay as quick hits unless someone sees a decision-changing delta.
First move: I want us to test whether npm binding.gyp is truly today’s highest operational priority, or whether active exploitation of Cisco/Android should outrank it for most CISOs. Tomas and Alex will be central, but I want dissent from the room — especially from James and Marcus — before we settle on the order.