The clearest correction is that four KEV entries do not equal four equally verified compromises or one unified campaign. macOS Screen Sharing has the strongest independent evidence of exploitation, root access, and Monero mining, although the conflicting CVE identifiers still need reconciliation. SharePoint exploitation is credibly reported, but its connection to the exact flaw under discussion is not conclusive. For vCenter and Microsoft IKE, KEV inclusion establishes active exploitation somewhere, not victim-level confirmation in this record. Likewise, the 361 IPs are campaign observations—not 361 victims—and could include scanners, relays, attacker infrastructure, or duplicate endpoints. Tonight’s defensible move is to identify internet-facing Macs exposing TCP/5900 with Screen Sharing or Remote Management enabled and investigate vulnerable matches as potential compromises. Claims of backdoors, ransomware, or nation-state activity remain unconfirmed or low confidence without host artifacts, payloads, deduplicated victim data, and corroborated infrastructure and behavioral links.
The same discipline applies to the bridge incidents. The Sandbox attacker’s enormous nominal mint does not represent an equivalent realized loss. Roughly 14.75 million genuine SAND reportedly left the Ethereum adapter, while The Sandbox placed direct impact below 0.01% of supply; that discrepancy and the attacker’s net realizable proceeds remain unresolved. Containment depended on disabling routes, preventing counterfeit redemption, and exchange suspensions. That is materially different from the reported realized losses at Allbridge and Maya or BounceBit’s decision to retire its L1. Recovery should be counted only when assets are returned or frozen with an executable recovery path.
For Mini Shai-Hulud, the failure boundary is the compromised maintainer and publication path. A lockfile match proves exposure, not execution; a malicious lifecycle script executed on a runner warrants treating accessible credentials and produced artifacts as compromised until rotated and cleanly reproduced. Teams should halt affected pipelines, preserve runners, logs, lockfiles, caches, tarballs, hashes, SBOMs, and provenance before remediation, while acknowledging that the affected-version set is still incomplete.
We now need to carry this evidence standard into the next triage: determine what is genuinely new in Zimbra, separate reported power-sector disruption from verified control-system effects, and rank exploited systems ahead of serious but not yet exploited Cisco flaws.