The headline says Coldcard and $100 million, but I don’t want us hypnotized by the loss figure. The sharper pattern today is trust failure at control points: wallet entropy, CI/CD, AI workflow tools, VPN gateways, exposed Ray clusters, Oracle databases, and water-system controllers.
So this is a busy, high-urgency room. Real airtime goes to actively exploited TeamCity, Langflow, Check Point, ShadowRay, Oracle khunt, the crypto seed/RNG failures, and the U.S. water-system wave. UNC6671 MFA vishing and Shai-Hulud npm are close behind because they turn people and builds into entry points. Cisco, WordPress, TONTOU, KVM, Apple Private Relay, and the wider policy items are not ignored, but unless new evidence changes the risk, they stay as quick hits or monitoring.
One ambiguity I want us to challenge: which problems require emergency containment tonight, and which are severe but not operationally movable in the next 24 hours? Coldcard losses are huge, but old seed material is already burned. TeamCity and Langflow, if exposed, may still be actively usable by attackers right now.
We’ll start with the exploited developer and AI control-plane stack, then move into water/OT, then identity and crypto. James, listen for the close — I’ll want the defensive sequence after everyone has put their risk on the table.