The room is busy, but the priority is concentrated. Citrix has moved from an unnamed, uncertain NetScaler threat to confirmed worldwide exploitation of two patched RCE zero-days. That is the lead: identify exposed appliances, patch or isolate them, and hunt for access that predates remediation.
SharePoint CVE-2026-65660 follows closely—active exploitation, webshell attempts, public PoC, and a federal deadline today. We will then test whether PeopleSoft’s reported mitigation bypass changes decisions for organizations that believed themselves protected, and briefly cover exploited Roundcube systems.
After that, I want a harder evidence check on TrustSink and the reported WhatsApp zero-click chain: serious identity and payment-fraud consequences, but very different prerequisites and confidence levels. Bitget deserves a strategic look because the alleged backend transaction manipulation matters more than the headline attribution.
Operation Master and the Windows injection technique were already covered; without a genuine delta, they stay in monitoring. The sprawling patch wave, AI-agent incidents, public-sector breach claims, and Kerala defacement will not displace actively exploited enterprise infrastructure. Alex, start with what Citrix confirmation changes operationally—and what evidence would justify treating a patched NetScaler as an incident rather than a completed maintenance task.