This is a busy morning, but not a random one. The headline is PeopleSoft and Nissan, and it deserves the lead — unauthenticated RCE into HR and finance data is board-level risk. But the bigger pattern is trust being broken across control points: ERP, RMM technician sessions, endpoint protection, FortiGate credentials, OAuth/device-code flows, and now AI agents with tool access.
We will give real airtime to five lanes: first, Oracle PeopleSoft CVE-2026-35273 and whether Oracle E-Business Suite belongs in the same operational response bucket; second, SimpleHelp OIDC abuse and Microsoft Defender BlueHammer in ransomware; third, FortiBleed plus Microsoft 365 device-code/token abuse as identity trust failure, not password hygiene; fourth, AI browser and coding-agent prompt injection where secrets and shell access are in play; fifth, OT and critical infrastructure — Quebec water, tank gauges, UK healthcare, and medical imaging.
DeFi losses, AI-enabled fraud, malicious extensions, and software supply-chain worms matter, but we will not let them dilute the urgent response lanes unless they change what a CISO must do today. Apple patch waves, AirDrop DoS, FIFA scams, and routine advisories are quick hits unless someone can show a sharper operational delta.
First move: I want us to separate “headline severity” from “same-day action.” Alex and Lena, we start with PeopleSoft — mechanics and attribution confidence. Then Marcus and James will turn that into containment: what has to be revoked, isolated, patched, or hunted before close of business.