This is a busy morning, but the shape is clear: exposed infrastructure is the center of gravity.
We should not turn this into a 600-CVE parade. The urgent lane is active exploitation against things enterprises and critical infrastructure still depend on: SonicWall SMA1000, on-prem SharePoint, Oracle E-Business Suite, old Cisco IOS, and routers linked to FSB Center 16 activity. The uncomfortable detail is that several of these are not just patch problems — they touch credentials, sessions, TOTP seeds, SharePoint machine keys, and domain trust.
So we’ll lead there. First, exploitability and compromise assumptions: if you had these systems exposed yesterday, what must you assume today? Then attribution and intent around the Russian router activity — espionage, pre-positioning, or opportunistic harvesting? After that, we’ll pull in identity and defensive architecture because patching alone will not unwind stolen trust material.
I also want a tighter second lane: Scattered Spider’s help-desk path, AnyDesk persistence, and the Transport for London sentencing as a reminder that social engineering is still producing real operational disruption. Supply chain and AI-enabled intrusion are important, but unless we find a decision that changes this morning, they stay secondary. DeFi losses, deepfake fraud, and the larger patch wave get quick treatment unless someone sees a hidden enterprise consequence.
Let’s keep the test simple today: what does a CISO need to do before close of business, and what can safely wait?