This is a crowded morning, but I don’t want us treating all 55 items as equal. The real shape is exposed control points under pressure: firewall management, ColdFusion, OWA, water-system PLCs, factory-adjacent ransomware, AI-assisted server exploitation, and even Bitcoin seed generation.
We have talked before about broken trust boundaries. What is new today is speed and consequence: ColdFusion reportedly hit within hours, Cisco FMC is in KEV with active exploitation, DeepSeek/Hermes moves agentic exploitation out of the lab, and Minnesota water operators were pushed toward manual procedures.
I want real airtime on five things: Cisco FMC, DeepSeek/Hermes, Adobe ColdFusion, the OT/manufacturing picture including Minnesota and UK ransomware telemetry, and Coldcard because cryptographic root failure is not a normal product bug. Exchange OWA, VMware, AD CS, TeamCity, npm/DPRK, and device-code phishing get sharp quick-hit treatment unless someone sees a same-day executive decision hiding there.
We’ll keep the weak CRPXO leak claims and thin SharePoint noise in monitoring unless new evidence changes that.
First move: separate hype from operational urgency. Alex, Lena, James, Priya, Marcus — listen for where exploitation is real versus plausible. Pierre, Sofia, Elena, Isabelle, Tomas — I’ll bring you in where the business, regulatory, geopolitical, evidence-trust, or supply-chain angle changes the decision.