This is a busy afternoon, but the lead is not “more vulnerabilities.” The lead is operational control being exposed — water utilities losing pressure, visibility, or control because PLCs are reachable and weakly segmented. That gets first airtime.
Then we move to the other exposed control planes: SonicWall SMA 1000 under INC Ransomware exploitation, N-able N-central in KEV with MSP blast radius, plus Langflow and Tomcat where public-facing systems become initial access quickly. After that, we’ll take Coldcard and DarkSword together as trust failures in personal custody and mobile identity — different environments, same uncomfortable question: when the trusted device or browser becomes the attack surface, what can still be recovered?
I do not want us to spread thin across all 77 items. ChainDrop and the Keyv/Shai-Hulud npm compromises deserve a focused supply-chain pass. AI agent sandbox escapes and workflow prompt injection deserve a short but serious control-boundary discussion. Deepfakes, Booking.com, tl;dv, AWS SSM, passkeys, and the patch-watch items stay in quick-hit or monitoring unless someone can show a same-day decision for CISOs.
First move: we start with the water-sector PLC activity. Alex, Lena, Elena, Pierre, James — I’ll want distinct angles, not five versions of the same warning. Attribute carefully, act immediately.