This is a heavy operational-risk morning, not a headline-ranking exercise. The obvious lead is Iranian-linked activity against exposed U.S. PLCs, but I don’t want us to treat that as “just another OT warning.” Operators were locked out of water and energy equipment. That moves it from exposure hygiene into continuity and safety.
The broader pattern is control-plane trust failing in several places at once: PLCs, F5 and Cisco edge infrastructure, Kubernetes service-account tokens, TanStack’s signed supply chain, mobile exploit kits, and even AI agents escaping evaluation boundaries. We have talked about exposed management planes before; what is new today is the convergence across OT, edge appliances, cloud identity, and autonomous tooling.
We’ll give real airtime to the PLC campaign, F5/Cisco infrastructure risk, Kubernetes token theft, TanStack supply-chain compromise, Coruna/LANDFALL mobile exploitation, Coldcard/DeFi losses, and the OpenAI/Anthropic agent-containment incidents. We will not spend the room on thin leak-site claims or unverified bridge rumors unless evidence improves. Cisco CVE-2026-20316 is also not today’s lead lane; we covered that remediation track already, so only true delta matters.
First move: we start with the PLC attacks and ask a hard question — is this primarily an exposure-management failure, an Iranian escalation signal, or both? Then we widen outward into the infrastructure trust failures that could hurt defenders this week.