Alex and Lena’s evidence supports containment, but not collapsing every NetScaler report into one vulnerability. NetScaler, first four hours: 0–30 minutes: identify incident-linked and internet-facing appliances; isolate a node immediately for unexplained administrative changes, new binaries, log gaps, or backend pivoting—otherwise keep it serving while restricting management access. 30–90: preserve configuration, audit/authentication logs, flow data, disk state, and volatile evidence before rebooting; fail over only to a separately validated peer. 90–240: invalidate appliance administrator/API credentials and any backend secrets exposed to a suspect node; rotate certificate keys where access or export cannot be excluded. Rebuild from trusted media for unauthorized privileged execution, configuration tampering, unknown binaries, or damaged logs. Treat the alleged unnamed zero-days separately from CVE-2026-8452—the exact count and scope remain uncertain.
SharePoint CVE-2026-65660: 0–30: drain a suspect server from the load balancer when a web shell, unknown ASPX file, abnormal w3wp.exe activity, unexplained outbound traffic, or integrity failure appears; do not wipe it. 30–90: capture memory and disk, then preserve IIS/ULS/Event logs, web roots, configuration, scheduled tasks, and farm changes. 90–240: revoke service-account and application credentials accessible from that host; rotate broader farm keys or certificates when evidence shows access. Any web shell or unaccounted executable change means rebuild onto a clean, patched node—patching the compromised server does not restore trust. Serve from validated farm members if possible; if none exist, accept the outage. Mini Shai-Hulud: freeze only workflows that actually invoked the affected action or dependency, preserve run logs, artifacts, caches, lockfiles, runner images, and package metadata, and quarantine outputs. Execution on a privileged runner triggers runner isolation plus revocation of GitHub, registry, cloud, Vault, signing, and deployment credentials available to that job; mere dependency presence does not. Discard ephemeral runners, rebuild persistent runners when integrity is uncertain, and reproduce downstream releases from clean, pinned inputs. Tomas’s roughly 15,000 repositories is a reach figure—not 15,000 compromises—so do not shut down unrelated CI/CD.
Rapid calls: For WSO2 CVE-2026-5430, remove exposed affected API Manager nodes from public reach now, preserve and hunt before remediation, and rebuild on integrity loss; no verified fixed version is available in the evidence here. For WordPress CVE-2026-87902, isolate affected instances or disable the vulnerable path, preserve web/database evidence, inspect for web shells and rogue administrators, and rotate credentials only where execution or exposure is established; again, no verified fixed version is available here. The firm decision is preservation first, evidence-based isolation, and rebuild after confirmed integrity loss—the team must not convert uncertain NetScaler reporting or Mini Shai-Hulud dependency reach into estate-wide shutdowns.