Halil, outside-in, I would make the next 24 hours very practical: “what can an attacker see and log into today?”
First priority: exposed management and enterprise-app surfaces. Verify internet-facing SimpleHelp RMM instances immediately, especially OIDC-enabled deployments, because prior reporting says CVE-2026-48558 can allow unauthenticated creation of privileged Technician accounts, and the current pack treats SimpleHelp as actively exploited. Also enumerate exposed Oracle E-Business Suite and PeopleSoft portals; the pack includes Oracle EBS exposure tied to “over 900” exposed instances under ongoing attack, and a Nissan PeopleSoft breach item. From the outside, defenders should confirm: public hostnames, version banners where visible, auth portals reachable without VPN, unexpected technician/admin accounts, and whether any of these sit behind SSO but still expose legacy login paths.
Second priority: identity exposure. For FortiBleed, I would not treat the dataset name alone as proof of compromise; defenders should verify whether their Fortinet VPN domains, usernames, or credential formats appear in the dataset before forcing enterprise-wide resets. But if there is any match to a live VPN endpoint, rotate those credentials and revoke sessions. For Azure CLI ROPC spraying, the outside-in check is identity telemetry mapped to public tenant exposure: look for password-spray patterns using Azure CLI / ROPC flows, legacy auth exceptions, impossible travel, and successful logins after repeated failures. This is actionable because the pack includes Microsoft account compromises tied to Azure CLI password spraying.
Third: phishing infrastructure. ARToken/EvilTokens deserves hunting, but carefully. Talos ties ARToken to an EvilTokens affiliate panel targeting Microsoft 365 OAuth/device-code phishing; historical OSINT also claims EvilTokens used large-scale Cloudflare Workers infrastructure and X-Antibot-Token headers. Those infrastructure traits are useful pivots, not convictions by themselves. Same with phantom-squatted hallucinated domains: newly registered domains matching AI-hallucinated package names, brands, or documentation references should be watched, sinkholed where owned, and blocked if they host credential collection or malware. But “looks hallucinated” is too noisy alone; drive action from registration recency plus hosting, content, redirects, TLS/cert linkage, and observed traffic.
Too noisy alone: raw FortiBleed counts without samples, EvilTokens domain lists without landing-page or header confirmation, Cloudflare Workers use by itself, Azure CLI user-agent hits without failed-login clustering, and hallucinated-looking domains with no traffic or malicious content. The urgent checks are exposed SimpleHelp/Oracle/PeopleSoft, confirmed VPN credential matches, and successful Azure ROPC/device-code auth events.