This afternoon is not a single-incident day. It is a trusted-paths day.
The first priority is SharePoint CVE-2026-45659: active exploitation, KEV listing, ransomware-linked follow-on tooling, and enough post-exploitation detail that exposed systems should be treated as potentially compromised, not merely unpatched.
But I do not want us to miss the bigger pattern: developer and automation trust is being attacked from multiple sides — PolinRider across packages and extensions, TeamPCP stealing cloud secrets through developer tools, JADEPUFFER abusing Langflow into cloud credential theft and ransomware, and the Claude Code proof-of-concept showing how a “clean” repo can still steer an agent into execution.
We will also give airtime to identity and token compromise — ARToken, LastPass/Klue OAuth, infostealer datasets — then a focused mobile pass on Android CVE-2025-48595 and NFC fraud. Armored Likho against government and power operators gets a threat-actor check.
Bad Epoll, PamStealer, Pegasus, Hinkal, Aptos, and the deepfake/legal developments are important, but unless someone sees a stronger operational delta, they stay as quick hits or monitoring.
First move: Alex, Priya, Marcus — I want us to decide whether SharePoint is a patch-now problem, a hunt-as-compromised problem, or both.