The priority picture has sharpened around blast radius rather than headline severity. Pierre places externally reachable MLflow first because metadata access can turn one vulnerable service into durable cloud-identity exposure; Zimbra and Ray follow where vulnerable configurations or execution evidence exist. TrueConf ranks fourth despite a documented chain involving server exploitation, SYSTEM-level activity, installer replacement, and trusted distribution. Compromised Rust/npm dependencies call for freezing affected builds, tracing lockfiles or SBOMs, rotating publishing secrets, and rebuilding selectively—not stopping every pipeline without evidence of use. DoFun and CameraSwarm remain scoped inventory-and-hunt problems, and the reported 14,530-camera figure is not corroborated by the evidence available here.
The identity lesson is equally specific: password resets are not a universal containment measure. MLflow may expose workload identities through metadata services, while malicious packages can steal cloud keys, repository and registry tokens, API credentials, and CI/CD secrets. Those credentials must be individually enumerated, revoked, and rotated, alongside removing attacker-added deploy keys, grants, webhooks, or publishing identities. For SickKids, the current scope is a careers-platform incident potentially affecting employee or applicant information. Clinical systems, patient information, and PHIPA remain outside the case unless evidence changes. Preservation notices, forensic and access records, provider coordination, contractual roles, data sensitivity, and probability of misuse must drive the Canadian notification decision; affected records, population, and legal control are not yet established.
Attribution confidence also needs to stay separated from operational urgency. The FBI-supported Bybit–Lazarus linkage is high confidence, while Head Mare’s TrueConf attribution, the DPRK linkage for chalk-ultra and vitest-cli, and Kaspersky’s Lazarus attribution for the Chrome campaign remain moderate-confidence assessments. The Chrome activity should not be presented as the mechanism behind the Bybit theft.
That leaves one ranking decision requiring direct pressure-testing: whether TrueConf can reasonably remain fourth when its observed chain already reached SYSTEM and converted a trusted installer into a delivery mechanism. We turn next to that challenge.