This is not a quiet morning. The headline says N-able, and that deserves real airtime — an RMM zero-day reaching customer networks is a force multiplier. But the water-utility PLC activity is the one that changes the room: exposed controllers, password changes, pressure drops, manual operations. That is public-safety territory, not just incident response.
I’m going to run this by decision impact. First: N-able N-central and downstream MSP/customer compromise. Second: U.S. water PLC exposure and whether we treat this as Iran-backed disruption or simply exposed OT being punished. Third: the active exploitation cluster — Metabase, TeamCity, WinRAR, Tomcat — because patching alone may be too late. Then we’ll pull together the identity and trust thread: Storm-2945 hotel Wi-Fi credential theft, Microsoft 365 AiTM, Windows Hello abuse, and developer/supply-chain compromise from TeamPCP and npm waves.
Coldcard and BTCPay matter, but I don’t want crypto losses to consume the whole table unless Viktor sees current recovery or exposure decisions. AI-agent stories also matter, but we’ll separate real execution paths in CI, browsers, and developer workstations from the benchmark drama.
Patch waves, breach notices, and policy items stay as quick hits unless someone can show a same-day executive decision. First move: Alex and Lena, I want the exploit reality and actor-confidence split on N-able and the water PLC incidents before James closes us into what defenders do tonight.