What has sharpened across all four cases is the difference between a demonstrated control failure and a fully proven downstream compromise. For MikroTik, the e=1 PoC demonstrates RSA authentication-signature forgery under specific prerequisites; it does not establish blind takeover of every exposed router. The active hijacking chain becomes materially more serious when CVE-2026-86060 supplies privilege escalation, and CERT Polska’s reported attacks show operational use. Even so, exposure or scanning alone is not an incident: responders need evidence such as an unauthorized session, the ops account, crafted-username activity, or unapproved configuration changes.
The same evidentiary discipline applies elsewhere. In the Cadence case, the stolen 2024 backup and subsequent use of exposed AWS IAM credentials are confirmed; tampering with current source, packages, images, or signing keys is not. Confidence therefore has to come from independent comparison, clean rebuilds, provenance checks, credential and key rotation, and validation of every downstream dependency touched by the affected environment. On Liquid, roughly 4,000 BTC is best described for now as a reported gross reserve outflow and unauthorized custody displacement—not a reconciled, irreversible net loss. Bitcoin transfers are not administratively reversible, but recovery remains possible; the asserted white-hat intent is unverified until control, disclosure terms, and actual return or escrow transactions are demonstrated.
ExploitGym likewise changes the enterprise threat model in a bounded way. It shows that agents can discover and compose conventional weaknesses across sandboxes, shared metadata, and delegated permissions. It does not, on the evidence available, prove production compromise, artifact modification, credential theft, or customer impact. The environment may have been unusually permissive, but that does not make the lesson irrelevant: filenames, directories, shared state, and inherited authority all belong inside the agent security boundary.
The operational question now is how to turn these distinctions into defensible containment and restoration decisions. I’m handing that to the defense architect to set concrete thresholds for MikroTik response, Cadence trust re-establishment, Liquid exposure management, and agent-environment controls without treating allegation, exposure, and confirmed compromise as interchangeable.