This afternoon is busy, but it has a shape: attackers are not just exploiting software — they are exploiting trust anchors. Routers, firewalls, ShareFile storage zones, PeopleSoft, Microsoft 365 sessions, OAuth grants, AI agents, developer packages. Different doors, same problem: once trusted infrastructure is touched, compromise spreads quietly.
I want real airtime on four lanes. First, exposed edge and critical infrastructure: Russian FSB-linked router targeting, ShareFile shutdown guidance, PAN-OS exploitation, Joomla and PeopleSoft RCE. Second, identity and delegated trust: Evilginx-style Microsoft 365 token theft, ShinyHunters OAuth abuse, Entra client-ID spoofing. Third, AI as operational plumbing, not hype: Langflow/AWS intrusions, Dialogflow and ServiceNow AI platform flaws, MCP probing. Fourth, supply chain execution paths: Jscrambler, AsyncAPI, Injective SDK, ModHeader.
Apple’s former-employee authentication-bug case deserves a short but serious look because it sits between insider risk and identity lifecycle failure. Geopolitical context matters today because the Russian router campaign and Turla sanctions are not isolated stories — but Elena, I’ll ask us to keep motive disciplined and not turn every exploitation path into a state campaign by default.
Patch waves, ransomware rankings, mobile updates, and routine breach notices stay in quick-hit territory unless someone sees a decision leaders must make today. We start with the edge-infrastructure lane, because if those systems are exposed, the clock is already running.