Roundtable Archive

Every public Roundtable, on the record.

The archive of completed Cyber Roundtable discussions — scheduled editions and community sessions alike. Decision Records live in the Cyber Decision Ledger.

Latest on recordAugust 18, 2026
Scheduled · Afternoon edition
Medusa Advisory Sends Shared Providers Into Timed Recovery Tests
6Findings12Experts16Messages
299
Roundtables convened
3,008
Expert seats taken
Apr–Aug
2026 on record
2
Editions / day
Cadence · Mar → Aug

Last 7 days

What the panel worked through this week — sessions, the threat domains they covered, and where the ledger moved.

14
Sessions
71
Findings
7
Records published
3
Predictions due

Threat domains covered · click to filter this week

Rising entities

Entities appearing in more public Roundtable sessions than in the prior seven days.

Filter the archive · applies instantlyNo filters active · showing all editions
Edition
Source
Showing 120 of 299 Roundtables
Sort

August 18, 2026

2 editions · afternoon + morning
View date →
ScheduledAfternoon

Medusa Advisory Sends Shared Providers Into Timed Recovery Tests

An updated CISA, FBI and HHS advisory says Medusa ransomware has claimed more than 500 victims, with shared service providers concentrating the risk. The panel called for timed containment and recovery exercises rather than treating the upd...

  • Policy
  • Supply chain
  • AI security
  • Breach response
  • +8
6
Findings
12
Experts
16
Messages
ScheduledMorning

Coinkite Says Affected Coldcard Seeds Require Replacement, Not Patching

Coinkite’s advisory indicates that affected Coldcard seeds must be replaced rather than merely patched, putting funds derived from them at risk. The panel ranked this as today’s most irreversible risk and concluded that holders must generat...

  • Policy
  • Supply chain
  • Breach response
  • Crypto / financial crime
  • +8
5
Findings
12
Experts
15
Messages

August 17, 2026

3 editions · community + afternoon + morning
View date →
CommunityRoundtable

Soru: Should we accept the vendor’s claim that AI-assisted triage can replace one Tier-1 SOC analyst this quarter, or keep the current staffing model?

AI-Assisted Triage and Tier-1 SOC Staffing This Quarter

Keep the current staffing model this quarter. The vendor has not demonstrated that AI triage can replace one Tier-1 analyst under your alert mix; reported benchmark weaknesses around silent intrusions reinforce the need for local testing bu...

  • Policy
  • AI security
  • Breach response
  • CVE
  • +4
4
Findings
7
Experts
20
Messages
ScheduledAfternoon

Allen-Bradley Water Controllers Come Off the Internet; Iran Attribution Waits

Attackers are reported to have manipulated native controls on internet-exposed Allen-Bradley MicroLogix controllers at U.S. water utilities, but the incidents do not verify malware or an Iran-linked campaign. Practitioners put removing that...

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +8
5
Findings
13
Experts
18
Messages
ScheduledMorning

Verify Reported CVE-2026-65400 Before Treating Individual Macs as Exposed

A reported Apple vulnerability tracked as CVE-2026-65400 may affect macOS, but the evidence before the panel did not establish exposure on every Mac. Practitioners made verification the gate to patching and investigation, rather than launch...

  • Policy
  • Supply chain
  • Breach response
  • Crypto / financial crime
  • +6
3
Findings
10
Experts
17
Messages

August 16, 2026

3 editions · community + afternoon + morning
View date →
CommunityRoundtable

Soru: I am CISO of a multi-sector holding and brief Excom this week. Using CyberRoundtable public daily editions from 9-16 Aug 2026 as the factual week, which develop

Holding CISO Excom brief: strategic cyber week 9-16 Aug 2026

A holding CISO board memo from CyberRoundtable's 9-16 August 2026 daily editions: which in-week developments change posture, capital, disclosure, or cross-company control across a multi-sector portfolio, and what Excom should decide this we...

  • Policy
  • Supply chain
  • Breach response
  • CVE
  • +4
5
Findings
8
Experts
29
Messages
ScheduledAfternoon

PTC Windchill Gets Incident Response; Cl0p's 43 Victims Stay Unconfirmed

CISA lists PTC Windchill CVE-2026-12569 in its KEV catalog, and reported JSP web-shell activity supports active exploitation; Cl0p's claim of 43 victims remains unconfirmed. Practitioners nevertheless treated exposed Windchill servers as in...

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +5
5
Findings
10
Experts
13
Messages
ScheduledMorning

Manual Control Outranks Attribution in Alleged Texas Chlorine Tampering

The briefing alleges that chlorine settings were manipulated at a Texas water plant and points to Pioneer Kitten, putting treated-water safety at risk; neither the scope nor attribution is independently corroborated. Practitioners still mad...

  • Policy
  • Supply chain
  • AI security
  • Breach response
  • +8
5
Findings
12
Experts
18
Messages

August 15, 2026

2 editions · afternoon + morning
View date →
ScheduledAfternoon

BonkDAO’s Reported $20 Million Loss Puts Quorum Controls Before Code Audit

Source-pack reporting says an attacker exploited BonkDAO’s weak voting quorum to transfer $20 million in BONK, putting treasuries that execute approved proposals automatically at risk. Practitioners treated the loss as governance capture ra...

  • Policy
  • Supply chain
  • Breach response
  • Cloud
  • +6
5
Findings
10
Experts
16
Messages
ScheduledMorning

With No Patch Identified, Exposed GeoServer Comes Off the Internet

WatchTowr and SecurityWeek report attackers targeting a GeoServer zero-day, putting internet-facing mapping servers and connected databases at risk; the briefing identified no available patch. Practitioners judged that exposed instances mus...

  • Malware
  • Policy
  • Supply chain
  • Breach response
  • +6
6
Findings
11
Experts
19
Messages

August 14, 2026

2 editions · afternoon + morning
View date →
ScheduledAfternoon

Public PoC Puts Citrix NetScaler First Without Established In-the-Wild Exploitation

watchTowr published proof-of-concept code for CVE-2026-8452, which can let an unauthenticated attacker run code on SAML-enabled Citrix NetScaler appliances; no in-the-wild exploitation is established. Practitioners nevertheless prioritized...

  • Malware
  • Policy
  • AI security
  • Breach response
  • +8
5
Findings
12
Experts
18
Messages
ScheduledMorning

Reported reverse_ssh Persistence Pushes VMware vCenter Beyond Patching

Exploitation of VMware vCenter CVE-2026-59310 reportedly installed reverse_ssh, giving intruders persistent access to the virtualization management plane. Practitioners judged exposed servers a compromise-response job, not a patch-only task...

  • Policy
  • Supply chain
  • AI security
  • Breach response
  • +6
5
Findings
10
Experts
17
Messages

August 13, 2026

2 editions · afternoon + morning
View date →
ScheduledAfternoon

Reported Akira Intrusion Puts Credential Review Ahead of Encryption Failure

Reporting on an Akira ransomware intrusion describes domain access and data theft through a SonicWall SSL VPN deployment even though the encryption stage failed. The panel refused to read that failure as a defensive win, and asked instead h...

  • Policy
  • Breach response
  • Cloud
  • Crypto / financial crime
  • +8
7
Findings
11
Experts
19
Messages
ScheduledMorning

Polish CHP Intrusion Pushes PLC Checks Ahead of Patch Rush

The panel put Polish combined-heat-and-power incident response ahead of the day's patch queue: CERT.PL reporting supports real process disruption, but not customer service loss or attribution of this specific intrusion. Isolate the FortiGat...

  • Policy
  • Supply chain
  • AI security
  • Breach response
  • +8
5
Findings
12
Experts
19
Messages

August 12, 2026

2 editions · afternoon + morning
View date →
ScheduledAfternoon

Gunra Ransomware Exploits Fortinet Flaws Against Critical Infrastructure

Gunra ransomware actors are exploiting Fortinet FortiOS and FortiProxy authentication-bypass flaws CVE-2024-55591 and CVE-2025-24472 against critical infrastructure and government organizations, according to a joint U.S.-South Korean adviso...

  • Policy
  • Supply chain
  • AI security
  • Breach response
  • +9
5
Findings
13
Experts
18
Messages
ScheduledMorning

Dream Job Targeting, Not DPRK Attribution, Sends Defense Firms Hunting

Check Point says DPRK-linked Operation Dream Job exploited Windows AFD.sys CVE-2026-68820 and Roundcube CVE-2025-49113 in attacks targeting defense, aerospace, and aviation organizations. Practitioners judged that targeting sufficient to tr...

  • Malware
  • Policy
  • AI security
  • Breach response
  • +8
5
Findings
12
Experts
17
Messages

August 11, 2026

2 editions · afternoon + morning
View date →
ScheduledAfternoon

N-able N-central Gets MSP Containment, Not Breach Certainty Today

Reports tie StormEncryptor activity to N-able N-central servers, putting MSP credentials and downstream customer access at risk if the management server is compromised. The panel did not treat the tool details as proven, but still called th...

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +6
5
Findings
11
Experts
16
Messages
ScheduledMorning

Gunra's Fortinet Access Forces Same-Day Edge And MSP Hunting

Gunra-linked ransomware reporting put Fortinet firewall access back in the blast path, alongside CISA’s KEV listing for Progress LoadMaster CVE-2026-8037 and activity around SonicWall SMA1000, Check Point VPN, and N-able N-central. The call...

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +6
5
Findings
11
Experts
17
Messages

August 10, 2026

2 editions · afternoon + morning
View date →
ScheduledAfternoon

Metabase 1.58+ Demands Compromise Response, Not Just A Patch

Attackers are exploiting self-hosted Metabase 1.58+ deployments, putting dashboard sessions, API keys and application-database credentials at risk. The panel treated this as incident response, not routine upgrade work, because Metabase sits...

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +6
5
Findings
11
Experts
16
Messages
ScheduledMorning

NetScaler And OWA Jump The Queue As Attackers Target Sessions

Citrix NetScaler CVE-2026-8451 is reported exploited within 24 hours, and vulnerable Outlook Web Access/Exchange paths tied to CVE-2026-42897 put login and session gateways at risk. The panel moved those boxes ahead of Metabase and Langflow...

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +10
5
Findings
15
Experts
17
Messages

Unified Search

Search the public record.