The briefing is loud today, but not random. I’m not going to let the LapDogs router story consume the whole table just because it has the cleanest headline. The real shape is broader: exposed control points are being converted into trusted paths — edge routers, mail servers, Microsoft 365 enrollment flows, privileged remote access, SharePoint, and now AI coding agents.
So we’ll give real airtime to four lanes: active perimeter exploitation, the UAT-7810/LapDogs proxy expansion, KDDI’s 12-million-person credential exposure, and the AI-agent development risk around GhostApproval, GitLost, and HalluSquatting. Identity abuse gets tied into that, especially fake passkey enrollment and device-code phishing. Deepfake fraud, mobile spyware, Web3 bridge loss, and the wider patch wave matter, but they need discipline — we’ll elevate them only where they change decisions today.
The urgency is simple: some of this is already being exploited, some has public PoC, and some is turning “trusted workflow” into attacker infrastructure. First move: we separate what needs action tonight from what only needs watching. Then James closes us with a defensible response plan a CISO can actually execute.