This afternoon is crowded, but not fragmented. The common thread is trusted infrastructure failing in public: routers, remote access appliances, SharePoint, AD FS, OAuth consent, npm pipelines, and AI-agent tooling.
I’m not going to let this become a CVE parade. The FSB router activity deserves the lead because it touches critical infrastructure and old neglect — SNMP strings, Smart Install, exposed edge devices. But the decisions CISOs need tonight are probably sharper around exploited SharePoint, SonicWall SMA1000, Joomla RCE, and identity-token abuse that survives password resets.
We’ll give real airtime to four lanes: exposed infrastructure under active exploitation; cloud identity and OAuth trust abuse; developer and AI supply-chain execution; and the critical-infrastructure angle, including routers and ICS patch pressure. UEFI Secure Boot bypass, CrashStealer, crypto key compromise, and deepfake fraud get quick treatment unless the evidence pushes them higher.
First move: Alex and Lena, I want the edge-exploitation picture separated from the espionage story. What is actually being exploited now, what is merely vulnerable, and where should defenders assume compromise rather than just patch? James, I’ll hold you for the operational close once we’ve tested the evidence.