This afternoon is not a patch-list session. The real shape is operational dependency under pressure: water utilities disrupted, security management planes being exploited, AI systems acting with too much authority, and trusted developer paths turning into attacker infrastructure.
We will lead with Minnesota because public service disruption changes the room. I want us to separate three things there: what is known about PLC exposure, what is being inferred about Iranian-linked activity, and what a small utility can actually do before the weekend without breaking plant operations.
After that, I’m not going to let Cisco FMC dominate as if it were fresh in every respect. The handoff flags prior coverage around remediation, exposure reduction, and detection tuning, so we will only touch Cisco if there is a new decision angle. Check Point SmartConsole, Exchange OWA with OWAReaper, and ColdFusion exploitation deserve the enterprise urgency slot instead: they all hit systems defenders tend to trust.
Then we need a hard conversation on AI. Not “AI is scary.” The useful question is narrower: when agents, copilots, browsers, and eval sandboxes can touch tokens, mailboxes, repositories, and production networks, where do we draw the authority boundary?
Quick hits only for the DeFi loss roundup, deepfake fraud, privacy fines, VMware and TeamCity patch waves, and the open-source package compromises unless someone can show me a decision that has to be made today.
First move: Sara, Alex, Lena, James — I’m going to start by pulling apart the Minnesota water story from four angles: physical consequence, exploit path, attribution confidence, and tonight’s defensive sequence. Then we’ll widen.This afternoon is not a patch-list session. The real shape is operational dependency under pressure: water utilities disrupted, security management planes being exploited, AI systems acting with too much authority, and trusted developer paths turning into attacker infrastructure.
We will lead with Minnesota because public service disruption changes the room. I want us to separate what is known about PLC exposure, what is being inferred about Iranian-linked activity, and what a small utility can actually do before the weekend without breaking plant operations.
After that, Cisco FMC gets only a delta check — prior coverage already handled remediation and exposure reduction. Check Point SmartConsole, Exchange OWA with OWAReaper, and ColdFusion exploitation deserve the enterprise urgency slot.
Then we need a hard AI conversation: not “AI is scary,” but where authority boundaries belong when agents, copilots, browsers, and eval sandboxes can touch tokens, mailboxes, repositories, and production networks.
First move: Sara, Alex, Lena, James — we start with Minnesota from physical consequence, exploit path, attribution confidence, and tonight’s defensive sequence.