This afternoon is busy, but not chaotic. The center of gravity is clear: exposed trusted systems are being turned into access — CMS platforms, VPN edges, ShareFile controllers, routers, SaaS credentials, developer packages, browser extensions.
I don’t want us to run a CVE parade. The real airtime goes to four lanes.
First: active exploitation at the edge — Joomla iCagenda and Balbooa Forms in KEV, Australia’s CMS webshell warning, PAN-OS GlobalProtect, ColdFusion, NetScaler with DragonForce, and the ShareFile emergency shutdown. That is tonight’s operational lane.
Second: Russian FSB Centre 16 targeting critical infrastructure routers and network devices. This is not exotic tradecraft. It is weak SNMP, exposed management, Cisco legacy paths, and stolen configs. Basic controls, high consequence.
Third: software trust is still bleeding — jscrambler npm, ModHeader, poisoned Go modules. Tomas, Priya, I’ll want us to separate “developer inconvenience” from “secret exposure requiring rotation.”
Fourth: identity and fraud — Evilginx against Microsoft 365, Odido’s Salesforce breach via social engineering and MFA capture, Scattered Spider-style help-desk pressure, and AI-enabled payment fraud. Marcus and Isabelle, this is where “MFA passed” and “the voice sounded right” both stop being sufficient evidence.
We’ll keep RedHook Android, MCP reconnaissance, Bluetooth EV battery systems, and the breach disclosures on the table, but they get airtime only if they change decisions today.
First move: we test the exploitation lane hard. What must be patched, isolated, shut down, or hunted tonight — and what is merely loud?