This afternoon is busy, but I don’t want us drifting into a vulnerability roll call.
The decision lane is exposed trusted infrastructure: SharePoint, SonicWall SMA1000, Ivanti Sentry, ColdFusion, and even that old Cisco IOS IKEv1 flaw now back in active exploitation. Those are tonight problems, not normal patch-cycle problems.
The second lane is strategic access: FSB Center 16 going after routers, Iran allegedly using SS7 for military tracking, and Daxin showing up against Taiwan-linked high-tech manufacturing. Different tooling, same pattern — civilian infrastructure becoming intelligence terrain.
Then we need one sharp pass on trust-chain compromise: npm packages, GitHub Actions, developer workstations, Claude/Cursor agent paths, and macOS stealers abusing signing and familiar prompts. DeFi oracle failures matter too, but we’ll treat them as a risk-model lesson unless Viktor is needed.
What I’m setting aside unless someone objects: the long tail of routine patch advisories, most WordPress plugin items, and general deepfake-fraud trend pieces. They’re real, but today they don’t outrank active exploitation of infrastructure.
First move: Alex, I want exploitability and kill-chain closure on the exposed infrastructure set. Lena, be ready to separate criminal opportunism from state-directed access. James, listen first — I want you closing with what defenders actually do tonight.