This afternoon is not a quiet vulnerability day. It is a control-plane day.
The obvious headline is Cl0p hitting PTC Windchill and FlexPLM, and we will lead there because engineering data theft changes the board conversation for manufacturers, aerospace, automotive, and retailers tonight. But I do not want us to miss the wider pattern: ServiceNow, SharePoint, PeopleSoft, Fastjson, GitLab, and exposed PLCs are all different doors into systems that run the business, not just systems that store data.
We have talked a lot recently about trusted platforms becoming intrusion paths. What is new today is the mix: PLM extortion, possible pre-auth enterprise workflow compromise, and OT visibility manipulation — HMIs showing one thing while controller logic says another. That last piece is safety-relevant, not just cyber-relevant.
I want real airtime on four lanes: Cl0p/Windchill first; then the enterprise exploitation wave around ServiceNow, SharePoint, PeopleSoft, and Fastjson; then Iranian-linked PLC/HMI activity; then a shorter but serious pass on AI sandbox/agent containment and crypto bridge losses. We will keep deepfake politics, generic ransomware statistics, Chrome patching, and the smaller CVE list mostly in monitoring unless someone sees a same-day decision hiding there.
Alex, Lena, Sara, James — I’m going to start by asking whether this is truly a “patch now” day, or whether for some exposed systems we should already be saying “assume compromise.”