This is a busy morning, but the lead is not ambiguous: Clop against PTC Windchill and FlexPLM gets first airtime. Unauthenticated RCE, JSP webshells, engineering and product-design data, and extortion pressure — that is a same-day board issue for manufacturing, aerospace, automotive, retail, and apparel.
The second lane is control-plane abuse: Zimbra stealing mail, 2FA codes, and app passwords; hotel Wi-Fi poisoning Microsoft 365 sign-ins; GlobalProtect tied to Qilin; Splunk in KEV. Different products, same failure pattern: trusted access surfaces becoming intrusion infrastructure.
Then we’ll test the higher-consequence but more nuanced items: the OpenAI/Hugging Face sandbox incident, Iran’s SS7 targeting of US military phones, and Iran-linked ICS activity. I want evidence discipline there — not hype, not geopolitics by reflex.
Crypto bridge losses, Oracle’s huge patch wave, Chrome, FastJson, AD CS Certighost, mrmustard, and the privacy breaches stay as quick triage unless they change a decision today.
First move: Alex and Maya, we start with Windchill mechanics and compromise assumptions. Lena, keep us honest on Clop attribution and campaign continuity. Then Marcus and James convert that into what defenders actually do before lunch.