This afternoon is busy, but not evenly busy. I don’t want us drowning in 622 Microsoft fixes or turning this into a CVE parade.
The sharpest lane is active exploitation against enterprise trust anchors: FortiSandbox because a compromised sandbox can poison downstream Fortinet verdicts, and SharePoint because the reported chain moves from web request to machine-key theft, web shells, lateral movement, and potentially domain compromise. Those two get real airtime.
Second lane: trust-path compromise. SleeperGem, npm dependency abuse, Contagious Interview SVG malware, ACR Stealer ClickFix, and macOS credential theft are different surfaces, but the same operational failure: users and developers are executing things because the workflow looks legitimate.
Crypto governance failures — BonkDAO and Ostium — deserve a focused pass, not because every enterprise CISO cares about BONK, but because proposal logic, vault accounting, and approval controls are now live attack surfaces. Ransomware gets tied back to exposed IIS and production disruption, not treated as a separate headline.
We will set aside the weaker watchlist CVEs unless someone sees a same-day exploitation signal. Kudankulam, AI policy, context bombing, and grid resilience are context unless they change a decision today.
First move: Fortinet and SharePoint. I want us to answer one question before anything else — if a CISO has only tonight to act, which trust chain must be assumed broken, and how do they prove it is clean?