Alex’s prioritization is right. 0–2 hours: isolate vCenter’s management plane, preserve memory/disk snapshots, logs and persistence evidence, then revoke sessions and rotate SSO, administrator and service credentials. Rebuild any confirmed-compromised node before applying a verified, staging-tested fixed release; reopen only after checking accounts, SSH keys, services and outbound connections. 2–4 hours: remove TeamCity from public reach, pause builds and artifact promotion, capture server/agent logs, databases, plugins and recent artifacts, then rotate TeamCity, VCS, registry, cloud and signing secrets. Treat exposed or suspicious N-central similarly, preserving task/script history before rotating console, API and customer credentials. I found no current advisory or patch data on N-central, so isolation and investigation take precedence over an unverified patch. The LiteLLM/Trivy/PyPI issue remains a separate delegated supply-chain investigation: freeze affected dependencies, preserve lockfiles and CI evidence, and verify rebuilt artifacts independently.
4–8 hours: quarantine confirmed Evooo1Bot devices, retain configuration, firmware and network captures, block unnecessary egress, rotate local/SNMP credentials, and reimage rather than trusting an in-place cleanup. Apply the same workflow to exploited Ruckus equipment. 8–12 hours: delegate Cisco CVE-2026-20349 to the network team for exposure reduction, rate limiting and crash monitoring; absent takeover evidence, it should not displace vCenter or TeamCity. 12–24 hours: inventory and monitor BTCPay and Harmony, preserve suspicious authentication and transaction telemetry, and rotate secrets only where exposure or compromise is indicated. I found no current advisory or patch data on Cisco, BTCPay or Harmony here; exact patch deployment must wait for a verified vendor-fixed version, then staging and validation.
One justified exception to immediate isolation is a Ruckus controller or access point carrying hospital telemetry or OT safety traffic where disconnection would remove the only communications path. Do not use that to wait: restrict management to a dedicated jump host, deny WAN administration, enforce egress allowlisting, mirror traffic for capture, rotate management credentials, and prepare redundant connectivity before controlled isolation. The governing sequence remains contain, preserve, scope, revoke trust, rebuild if compromised, patch, validate, reopen.