This is a busy, high-consequence morning. I’m not going to let the Langflow headline swallow the room, even though it deserves serious attention. The sharper executive question is this: which exposed systems can turn one unauthenticated interaction into admin control, credential theft, funds movement, or public-safety disruption?
So the real airtime goes to six lanes: IBM Langflow and Metabase first; Citrix NetScaler and OWA/TA488 as exposed access infrastructure; BTCPay where exploitation means immediate financial loss; then Suisun City and water utilities because 911 routing and treatment controls move this from IT risk into civic continuity.
We also need to discuss the CSS-only webmail research because it weakens a trust assumption many defenders still make: “no JavaScript, no serious credential theft.” The npm provenance abuse gets a supply-chain slot, but I want discipline there — not panic over 400 packages, but what a build owner does today.
Deepfake scams, SparkKitty, LockBit 5.0, Apple Screen Sharing, and the breach stories are on the board, but unless one of you sees a same-day decision hiding there, they stay as quick hits or monitoring.
First move: Alex and Lena, I want us to test whether Langflow and Metabase are truly the lead operational risks — or whether Citrix/OWA and public-safety outages should outrank them for a CISO or city manager this morning.