This afternoon is busy, but not random. The common thread is trusted platforms turning into attacker paths: Oracle E-Business Suite, SharePoint, ColdFusion, NetScaler, Gitea, Langflow, Roundcube, Ruckus routers, even DeFi governance and package maintainers.
I don’t want us hypnotized by the AI-agent ransomware headline and miss the simpler emergency: exposed enterprise systems are being exploited now, with patches available and measurable attack surface still online. JadePuffer matters because it may compress the intrusion timeline, but SharePoint, Oracle, NetScaler, ColdFusion, and Rockwell access are the decisions CISOs have to make before dinner.
So we’ll spend real airtime on four lanes: first, exploited internet-facing enterprise platforms; second, Langflow and what agentic automation actually changes in ransomware; third, China-linked Roundcube/Ruckus activity and developer supply-chain compromise; fourth, DeFi governance and identity abuse where money or tokens move fast. Deepfake fraud, mobile patches, policy updates, and the long advisory list stay in monitoring unless they change today’s action.
Alex, I’ll come to you first for exploitability and exposure realism. Marcus and James, be ready to translate that into containment. Arjun, I want you sharp on what is real AI-enabled intrusion versus branding. And Lena — keep us honest on attribution.