Today is busy, but the pattern is clean: attackers are not winning through novelty; they are winning through trusted but neglected paths.
Routers with weak SNMP. Remote access gateways. SharePoint. OAuth grants. npm install scripts. Notarized macOS apps. Default OT passwords. That is the frame.
We are not doing a 93-item CVE parade. Real airtime goes to five lanes: Russian-linked router targeting against critical infrastructure; Microsoft’s July patch surge with active SharePoint and AD FS exploitation; SonicWall, Joomla, and other exposed edge/web entry points; npm and developer-trust compromise; and the identity/control-plane thread running through CrashStealer, OAuth abuse, M365 phishing kits, and AI-agent operations.
Water utilities and Unitronics default-password exposure also stay on the table because operational risk changes the tone. UEFI shim, ShareFile, PeopleSoft, SAP, crypto bridge theft, and the major breach stories get triaged as quick hits unless the panel sees a sharper decision point.
Monitoring stays monitoring unless new evidence moves it.
First move: Alex, Lena, James — I want us to test whether the router campaign is truly today’s lead, or whether Microsoft/SharePoint should outrank it operationally. Then we widen to Tomas, Marcus, Maya, Nadia, Elena, Sofia, and Pierre for the trust-chain and board-impact angles.