This is a crowded, operationally urgent morning, but Apple is not automatically our lead. GeoServer has no patch and exploitation began within hours; SharePoint can be chained to server takeover; LiteLLM may have exposed durable credentials across cloud and Kubernetes environments. Those are the first containment decisions.
We’ll then test the Cl0p/PTC claims against confirmed exploitation, address Coldcard because firmware updates cannot rescue compromised seeds, and examine the reported Taiwanese AI-agent operation without accepting “autonomous” at face value. The U.S. water-utility incidents also deserve airtime, but operational impact and Iranian attribution must remain separate questions.
Trezor and Evooo1Bot get focused treatment. Broad patch counts, speculative GLM-5.3 claims, routine advisories, and the background watchlist stay off the floor unless someone finds a decisive delta.
Alex, start with the exposure queue: GeoServer, SharePoint, macOS Screen Sharing, SAP Commerce, and the wider Microsoft/VMware/Cisco wave. Which systems require isolation before patching, and where is the briefing overstating takeover risk?