We’ve been circling exposed control planes all day, so I don’t want us to rehash the morning. The afternoon delta is sharper: analytics platforms, AI agents, payment nodes, conferencing servers, and even water utility controls are being used as trusted paths into data, money, or physical operations.
I’m going to challenge the obvious lead slightly. Rovo matters, but Metabase and the water-utility incidents have more immediate “what do we do tonight?” weight: one is active exploitation of a CVSS 10 SQLi against connected data stores; the other has real-world service disruption from internet-facing control systems.
So we’ll give real airtime to five items: Metabase/Framework, U.S. water utilities, Atlassian Rovo and AI workflow injection, BTCPay plus Coldcard crypto exposure, and TrueConf installer trojanization. WordPress, webmail CSS attacks, Kratos, deepfake apps, and the broader patch wave get monitored or folded in only where they change a decision.
First move: separate active compromise from research theater. Alex, Lena, Priya, Arjun, Viktor, Sara if needed, and James — listen for the same question underneath all of this: where does trust become authority, and what must be revoked before we simply patch?