This is a busy morning, but I don’t want us turning it into a CVE parade.
The Fortinet FortiSandbox KEV deadline is tomorrow, and SharePoint exploitation is still an enterprise emergency. Those get real airtime first. Around them, I want a tight exploited-infrastructure lane: Joomla JCE, Oracle EBS Payments, SonicWall SMA, legacy Cisco IKEv1, and the FortiBleed credential exposure — not as separate headlines, but as one question: which exposed trust points must be patched, hunted, isolated, or credential-reset today?
Second lane: NadMesh. That one matters because it shows AI and cloud tooling becoming botnet substrate — Gradio, ComfyUI, Docker APIs, Jenkins, Airflow, Kubernetes tokens, AWS keys. That is not “AI risk” in the abstract; it is exposed ops tooling turning into credential theft.
Third lane: developer and software supply-chain compromise — Shai-Hulud hitting @bitwarden/cli, Mastra/easy-day-js, fake Vite packages, North Korean Contagious Interview activity. Tomas and Maya, I’ll want the execution-path view there, not a package-name list.
We’ll touch crypto, but I’m not going to let the $1.3 billion CertiK number dominate unless Viktor can turn it into a decision for Web3 operators this week. Same with AI deepfake fraud: important, but it has to translate into payment controls and executive verification, not fascination with cloned voices.
Elena, we will make room for the military smartphone tracking story — that is a different class of exposure. Sofia, I’ll bring you in where notification, settlement, or regulatory timing changes decisions, especially 23andMe, EY, CMMC, and the Fortinet/KEV obligations.
First move: Alex on exploitability and exposure triage. Then Lena for what the actor evidence actually supports. James closes the first pass with what teams should do before the weekend.