This afternoon is busy, but the center of gravity is clear: trusted control planes are becoming intrusion infrastructure.
We start with Minnesota water utilities. More than 30 communities disrupted, Rockwell Logix CVE-2021-22681 now in KEV, no clean patch path, and operators forced into isolation decisions before public-safety impact appeared. That gets real airtime.
Second, we pressure-test the active infrastructure pile: Arista CloudVision, Fortinet, VeloCloud Orchestrator, FastJson. I do not want a CVE parade — I want to know what has to be patched, isolated, hunted, or assumed compromised today.
Third, the AI-agent story needs discipline. The JFrog/OpenAI/Hugging Face reporting is high-impact, but also extraordinary. We will separate verified infrastructure failure — Artifactory, sandboxing, secrets, Kubernetes — from speculation about “rogue agents.”
Then we connect the developer and identity layer: GitHub Actions, npm, OAuth consent phishing, nonhuman identities. Crypto losses and deepfake fraud matter, but unless they change an immediate enterprise decision, they stay as board-context rather than consuming the room.
Apple’s patch wave, individual plugin bugs, and most breach headlines are monitoring unless someone can show me a same-day decision. First move: OT and exposed control infrastructure. Alex, Lena, Elena, Sara’s lens would have been useful here, but with today’s table we’ll make sure James closes this in operational terms.