This afternoon is busy, but the shape is clear: trusted systems are becoming attacker infrastructure.
The obvious lead is N-able N-central — active exploitation, incomplete patching, account takeover, Take Control abuse, Cloudflare tunnels, MSP downstream blast radius. But I don’t want us treating it as a one-off RMM story. SonicWall SMA, VeloCloud Orchestrator, Fortinet persistence, water-sector PLC exposure, Lazarus abusing a South Korean security product, Axios/npm, Arch AUR, Coldcard seed weakness, and AI agent sandbox failures all point to the same failure mode: control planes, update paths, identity paths, and automation paths are being trusted faster than they are being verified.
We’ll give real airtime to three clusters: first, exploited management and edge infrastructure; second, AI-assisted exploitation and AI supply-chain escape; third, trust-anchor failures in crypto, software supply chain, and security-product ecosystems. Water systems get a focused critical-infrastructure pass because the impact is physical, even if the technical path is depressingly familiar. Deepfakes, Apple patching, Chrome policy hardening, and breach claims stay as quick hits unless someone sees a decision that has to be made today.
I want the room to resist easy consensus. If the answer is only “patch faster,” we have failed. The question for this table is sharper: which trusted systems should be treated as already compromised before business closes tonight?