This is a busy, sharp-edged morning — not because we have 80-plus items, but because several of them hit systems that grant real authority: PLC logic, mail sessions, firewall management, SaaS agents, software vendors, and bridge signing keys.
We have talked before about trusted paths being abused. What is new today is the consequence level. Iranian-linked activity against internet-exposed Siemens, Schneider, and Rockwell PLC environments gets first airtime because safety and process integrity outrank everything else. Then we move to active enterprise front-door compromise: Zimbra’s zero-click Classic UI flaw, Check Point SmartConsole admin access, and the SonicWall/FortiSandbox/GlobalProtect edge queue. After that, we’ll test the trust-abuse pattern across Kimsuky’s software-provider targeting, rogue AI workspace agents, OAuth/SaaS abuse, and crypto bridge key failures.
KARR/SWDS vehicle Bluetooth exposure, Korea diplomatic academy data exposure, WordPress exploitation, and the Microsoft/Oracle patch waves matter — but we will not let volume decide the agenda. They get airtime only where they change a decision today.
Sara, I want the OT safety lens first. Alex and Lena, listen for exploit reality versus attribution confidence. James, you close us later with what an operator or CISO actually does before tonight.