The evidence hierarchy now separates confirmed compromise paths from consequential but incomplete claims. PaperCut remains the first enterprise priority because its exploit chain is technically established and active exploitation has been observed. vCenter comes next because compromise of the management plane could be catastrophic, but the Babuk attribution is not yet strong enough to treat ransomware as the default outcome. The meaningful hunt signals are privileged-account creation, malformed cron activity, reverse_ssh, SSH persistence, web shells, and ESXi encryption artifacts—not scanning or vulnerable-version exposure alone. Rails ranks higher on evidence confidence than several other claims, yet follows vCenter operationally because of the latter’s control-plane impact. The purported self-hosted ServiceNow issue remains verification-only until the component, version, ownership, exposure, advisory, and patch information are established.
Across those systems, evidence preservation must precede disruptive remediation wherever possible. Tonight’s sequence is to capture volatile, appliance, application, authentication, and hypervisor records; restrict exposure and management access; then apply only confirmed fixes. In the vCenter cases examined, separate operational chains and limited sample-level malware evidence mean neither one incident nor .babyk extensions alone proves representative Babuk deployment across the wider reported population.
The same discipline applies to supply-chain and financial exposure. An llms.txt reference, callback, or claimed enterprise installation does not establish malicious payload execution. Until ownership is validated, agents should use exact-version and hash allowlists through internal registry proxies, disposable non-root sandboxes, default-deny egress, short-lived scoped credentials, and human approval for installation, shell access, publishing, or deployment. On WFLOW, 15.5 million tokens transferred is distinct from $9.3 million being realized. Boards should isolate affected pools and unwind according to leverage and executable liquidity rather than assume Flow, Ankr, Aave, or LayerZero is compromised wholesale.
That leaves one claim needing direct pressure-testing: whether the public llms.txt evidence supports the headline at all, and exactly where defensible enterprise concern ends and unsupported impact claims begin.