This morning is busy, but the shape is clear: trusted platforms are being turned into intrusion paths — AI tooling, SharePoint, FortiGate, Oracle EBS, NetScaler, identity tokens, and developer packages.
I don’t want us to run this as a CVE parade. The board-level question is simpler: which systems should be treated as already exposed today, which can be patched in the normal emergency lane, and where do we need credential or token revocation rather than just software updates?
Real airtime goes first to JADEPUFFER and Langflow, because “agentic ransomware” is not just a label if cloud keys, API keys, persistence, and database destruction are in the chain. Then we move to the exploited enterprise stack: SharePoint, Oracle E-Business Suite, FortiGate/FortiBleed, Citrix NetScaler, and Cisco Unified CM. After that, Marcus and Arjun will get space on the identity and AI-agent trust problem — ConsentFix, ClickFix, ARToken, MCP poisoning, coding-agent command bypasses.
We will keep Adobe ColdFusion, Chrome, Android browser-ransomware PoC, and the broader breach rollup in view, but unless the evidence says “active exploitation plus immediate decision,” they stay as quick hits. Monitoring items stay off the floor.
First move: I want to separate novelty from operational urgency. “First known agentic ransomware” may be the headline, but SharePoint, FortiGate, Oracle, and Citrix may be what keeps CISOs awake tonight.