This afternoon is busy, but not random. The common thread is trust being turned against its owners: NetScaler at the edge, DNS delegations in Sitting Ducks, OAuth and device-code flows, developer tools, AI workflow platforms, and even spyware against a European Parliament investigator.
I’m not going to let the domain-hijacking headline hide the most time-sensitive item: Citrix NetScaler CVE-2026-8451 is already being probed, and the SAML identity-provider angle makes this more than a routine edge patch. That goes first.
After that, we need three lanes with real airtime: Sitting Ducks and Dalbit as infrastructure abuse; Langflow and Marimo as the “AI-assisted intrusion” question — with skepticism, not hype; and TeamPCP/NPM/GitHub Actions as the developer trust-collapse lane. Pegasus gets its own short but serious geopolitical and regulatory pass. Hinkal and Gnosis Pay stay in scope because crypto laundering windows are collapsing, but we won’t let DeFi mechanics consume the whole table.
Quick hits only for Adobe’s new patch rhythm, Bad Epoll, FatFs, and the AI browser prompt-injection research unless someone sees an operational reason to elevate them. Plugin-only Tomcat, Flowise, Cacti, and similar weak-signal items stay on the watch floor for now.
First move: Citrix, identity exposure, and what a CISO must do before the evening change window closes.