This is a crowded afternoon, but we are not going to turn it into a CVE parade.
The lead is SharePoint. Active exploitation, emergency patches, KEV listing, possible chaining, and on-prem exposure — that is a board-level incident-prevention problem today, not just patch management. SonicWall SMA sits right beside it because ransomware operators are reportedly already using those zero-days, and one has public PoC pressure.
WordPress gets airtime, but differently: critical unauthenticated core RCE, no confirmed exploitation yet, details withheld. That means fast patching, not panic. DeFi toxic pools deserve a separate lens because the risk is not “another protocol hack”; it is execution-path manipulation where simulations lie. And I want us to touch the US military mobile-tracking report because location metadata is becoming an operational security failure, not a privacy footnote.
We will keep the huge Microsoft/Chrome/Samsung patch wave as prioritization context unless someone sees a same-day decision hiding in it. The weaker monitoring items stay off the floor.
First move: Alex, Lena, James — we start with SharePoint and SonicWall as exposed-infrastructure emergencies. Then we widen to WordPress, DeFi, developer supply chain, and mobile surveillance only where the action changes today.