This is a busy morning, but I don’t want us chasing all 90 items. The shape is clear: trusted control points are failing under pressure — edge appliances, MSP platforms, WordPress plugin infrastructure, hotel captive portals, AI agents, and OT access paths.
The headline is Progress LoadMaster in KEV, and we’ll cover it, but I don’t think it stands alone. SonicWall SMA1000, Check Point VPN, Fortinet, and N-able N-central all point to the same operational problem: internet-facing trust infrastructure is becoming ransomware’s shortest route to privilege.
We also need real airtime for BdThemes because that is not “just WordPress”; it is upstream infrastructure poisoning leading to admin creation and persistence. The OpenAI agent and Atlassian Rovo items deserve a sober discussion too — not AI hype, but authority boundaries, segmentation, and what happens when agents touch real systems.
OT gets its own lane today: suspected Iran-linked activity against U.S. water systems and the Russian-linked Polish CHP intrusion both raise the same uncomfortable question — are small operational networks still treating edge access and cellular links as exceptions instead of attack paths?
Crypto losses, broad patch waves, deepfake fraud, and routine breach litigation are mostly quick hits unless someone sees a same-day decision impact. We’ll start with exposed remote-access and control-plane exploitation, then move into supply chain and AI-agent trust failures.