This is a busy afternoon, but the center of gravity is not the Cisco headline. Cisco FMC stays urgent, especially for anyone with exposed management planes, but CVE-2026-20316 looks like action tracking unless we see a real delta. I don’t want us spending the first twenty minutes re-litigating yesterday’s edge-appliance story.
The sharper issue is operational disruption: exposed Rockwell and Allen-Bradley PLCs, municipal water systems hit across several states, and Iranian-affiliated activity sitting close to public-service continuity. That gets first airtime because the failure mode is not “data stolen”; it is residents conserving water and operators losing confidence in what their control systems are showing them.
After that, we’ll move fast through three live enterprise risk lanes: Exchange OWAReaper and token/mailbox theft, React2Shell exploitation with real payload delivery, and the TanStack/npm compromise where valid provenance did not mean trusted code. I also want Priya, Marcus, and Tomas ready on the identity and supply-chain overlap, because today’s pattern is privilege escaping its intended boundary.
Mobile spyware, crypto losses, AI evaluation failures, deepfake satellite imagery, and telecom espionage all matter, but they don’t all get equal floor time today. We’ll separate what requires action tonight from what belongs on executive watchlists.
First move: OT and water. I want us to answer one practical question: if you are a municipal operator, energy provider, or government facility with exposed PLCs, what do you do before close of business?