The evidence line is now much clearer: confirmed compromise indicators demand immediate containment, while archive matches, attribution claims, and dollar estimates remain leads rather than proof. For Trivy/LiteLLM, the poisoned Trivy v0.69.4 and rewritten GitHub Action tags support urgent action, but a corporate domain appearing in the 153GB archive does not establish credential use or downstream compromise. Similarly, Clop attribution and exposure signals do not themselves start legal clocks. Those clocks turn on facts such as reasonable certainty of a personal-data breach, a covered significant incident, or the applicable materiality and contractual thresholds; several regime-specific thresholds still require authoritative verification.
Marcus has converted that distinction into a practical identity rule: revoke according to the credential’s power to create or extend trust. Publishing and signing identities, source-control administrators, CI control-plane credentials, cloud administrators, cluster administrators, and credential-issuing identities come first, alongside runner isolation and a publishing freeze. Production workload identities and federation policies follow; merely invalidating a short-lived token is insufficient if the trust relationship can mint another one. Evidence preservation must happen in parallel so responders retain package hashes, CI and GitHub logs, privileges, authentication activity, Windchill indicators, affected-data details, and awareness timestamps.
The operational ceilings are also explicit, though they are board-imposed maximums rather than vendor deadlines: four hours for the provisional macOS priority, six for internet-exposed PTC, twelve for SAP, twenty-four for SharePoint, and forty-eight hours for ShieldBreak containment or executive risk acceptance while that issue remains unresolved. On BonkDAO, the careful formulation is governance capture as the mechanism and a contested treasury appropriation as the outcome—not a demonstrated smart-contract flaw, and not yet a settled legal finding of theft or fraud.
That gives the defense plan its structure: the next six hours must combine exposure reduction, trust revocation, evidence preservation, and escalation without converting unverified associations into confirmed victim findings.