This is a busy morning, but it has a clear center of gravity: attackers are going after systems that multiply control.
Water PLCs, MSP RMM platforms, remote-access appliances, AI model access, mobile credential stores, package ecosystems — different headlines, same pressure point: trusted infrastructure becoming an intrusion amplifier.
I want real airtime on four things today. First, CyberAv3ngers and internet-exposed Unitronics PLCs in water and wastewater — that is safety and continuity, not just “cyber.” Second, the exploited access layer: N-able N-central, SonicWall SMA1000, and likely VeloCloud as a quick adjacent check. Third, whether the AI stories have crossed from hype into operational urgency — CrowdStrike’s LLMjacking, Hermes using DeepSeek, agent sandbox failures. Fourth, identity and trust anchors: DarkSword against iOS, passkey abuse, Coldcard seed-generation failure, and the supply-chain attacks around npm and developer tooling.
We will not relitigate every breach headline, every ransomware statistic, or every patched package. Those stay in monitoring unless they change a decision today.
First move: Alex, Lena, Elena, I want us to start with the water-sector activity and separate three things clearly — what is technically exposed, what we can actually attribute, and what operators must do before the end of the day.