This is a busy, fragmented morning, but the loudest headline is not automatically the biggest enterprise risk. Apple’s CVE-2026-86950 demands immediate patching because exploitation is confirmed and executive or otherwise targeted users are plausible victims. Still, the public proof-of-concept only demonstrates a crash—not code execution—so we will keep urgency separate from speculation.
The broader operational problem is simultaneous exploitation of trusted control points: Cisco SD-WAN Manager, FortiMail, Zimbra, Zammad, NetScaler, and ScreenConnect. We covered Cisco and NetScaler yesterday; unless new evidence changes the response, we will not relitigate them. I want our first attention on what is genuinely new: whether the Zammad “autonomous AI” claim changes the threat model, and whether Zimbra and FortiMail owners must treat patching as incident response.
We will then examine the nine-month DMDC intrusion and its long-lived identity consequences, followed by the concentrated crypto losses across Bitget, Liquid Network, and NEAR Intents. Legacy Office exploitation in Latin America gets a short operational note. KillSec’s disruption, the GitHub credential findings, and the supply-chain incidents remain secondary unless the evidence reveals a decision-changing delta. Alex and Lena, start by separating demonstrated exploit capability from headline inflation; James will close each thread with what defenders do today.