The clearest lesson is that exposure changes the presumption, but not every downstream conclusion. For internet-managed FortiOS 7.0.0–7.0.16 and FortiProxy 7.0.0–7.0.19 or 7.2.0–7.2.12, Alex’s position is firm: treat the appliance as compromised, then use external telemetry to determine whether the intrusion crossed into identity, virtualization, backup, or domain infrastructure. Unexpected jsconsole super-admin activity, account or MFA changes, session reuse, and appliance-originated lateral access are the threshold indicators; exposure alone does not establish domain compromise.
The same discipline sharpens the other cases. Lena characterized the North Korea-linked activity as better integration of an existing delivery and privilege-escalation chain, rather than a novel remote-entry method: fake jobs, DLL side-loading, CVE-2026-68820, and FudModule, alongside compromised webmail and RelayShell infrastructure. Confidence is high in the observed operational chain but only moderate in Lazarus attribution, so hunting should follow behavior rather than the actor label. In the TrueConf case, Tomas moved the trust boundary beyond the server to the installer-distribution channel. Any endpoint or external party that executed a substituted installer may fall inside the blast radius, and the distrust window must be based on forensic evidence or a previously verified clean hash—not a campaign date.
Sara added an essential OT distinction: reachable modems, PLCs, or HMIs demonstrate dangerous access, but they do not by themselves prove process manipulation. The minimum safe response begins with independent physical verification and narrowly controlled containment of remote access, while avoiding indiscriminate disconnection, PLC rebooting, or disruption of safety communications.
That gives us a consistent decision rule: identify the real trust boundary, separate access from demonstrated impact, and scale containment to evidence without waiting for perfect attribution. We now carry that rule into bridge integrity, AI-connected tooling, passkey claims, and patch governance—four areas where dramatic labels can otherwise outrun the operational facts.