Roundtable Archive
Every public Roundtable, on the record.
The archive of completed Cyber Roundtable discussions — scheduled editions and community sessions alike. Decision Records live in the Cyber Decision Ledger.
Last 7 days
What the panel worked through this week — sessions, the threat domains they covered, and where the ledger moved.
Threat domains covered · click to filter this week
Rising entities
Entities appearing in more public Roundtable sessions than in the prior seven days.
- CISANewly active
- LiteLLMNewly active
- CVE-2026-12569Newly active
- CVE-2026-18577Newly active
- CVE-2026-42897Newly active
- CVE-2026-55040Newly active
- CVE-2026-58231Newly active
- CVE-2026-59310Newly active
August 18, 2026
Medusa Advisory Sends Shared Providers Into Timed Recovery Tests
An updated CISA, FBI and HHS advisory says Medusa ransomware has claimed more than 500 victims, with shared service providers concentrating the risk. The panel called for timed containment and recovery exercises rather than treating the upd...
- 6
- Findings
- 12
- Experts
- 16
- Messages
Coinkite Says Affected Coldcard Seeds Require Replacement, Not Patching
Coinkite’s advisory indicates that affected Coldcard seeds must be replaced rather than merely patched, putting funds derived from them at risk. The panel ranked this as today’s most irreversible risk and concluded that holders must generat...
- 5
- Findings
- 12
- Experts
- 15
- Messages
August 17, 2026
Soru: Should we accept the vendor’s claim that AI-assisted triage can replace one Tier-1 SOC analyst this quarter, or keep the current staffing model?
AI-Assisted Triage and Tier-1 SOC Staffing This Quarter
Keep the current staffing model this quarter. The vendor has not demonstrated that AI triage can replace one Tier-1 analyst under your alert mix; reported benchmark weaknesses around silent intrusions reinforce the need for local testing bu...
- 4
- Findings
- 7
- Experts
- 20
- Messages
Allen-Bradley Water Controllers Come Off the Internet; Iran Attribution Waits
Attackers are reported to have manipulated native controls on internet-exposed Allen-Bradley MicroLogix controllers at U.S. water utilities, but the incidents do not verify malware or an Iran-linked campaign. Practitioners put removing that...
- 5
- Findings
- 13
- Experts
- 18
- Messages
Verify Reported CVE-2026-65400 Before Treating Individual Macs as Exposed
A reported Apple vulnerability tracked as CVE-2026-65400 may affect macOS, but the evidence before the panel did not establish exposure on every Mac. Practitioners made verification the gate to patching and investigation, rather than launch...
- 3
- Findings
- 10
- Experts
- 17
- Messages
August 16, 2026
Soru: I am CISO of a multi-sector holding and brief Excom this week. Using CyberRoundtable public daily editions from 9-16 Aug 2026 as the factual week, which develop
Holding CISO Excom brief: strategic cyber week 9-16 Aug 2026
A holding CISO board memo from CyberRoundtable's 9-16 August 2026 daily editions: which in-week developments change posture, capital, disclosure, or cross-company control across a multi-sector portfolio, and what Excom should decide this we...
- 5
- Findings
- 8
- Experts
- 29
- Messages
PTC Windchill Gets Incident Response; Cl0p's 43 Victims Stay Unconfirmed
CISA lists PTC Windchill CVE-2026-12569 in its KEV catalog, and reported JSP web-shell activity supports active exploitation; Cl0p's claim of 43 victims remains unconfirmed. Practitioners nevertheless treated exposed Windchill servers as in...
- 5
- Findings
- 10
- Experts
- 13
- Messages
Manual Control Outranks Attribution in Alleged Texas Chlorine Tampering
The briefing alleges that chlorine settings were manipulated at a Texas water plant and points to Pioneer Kitten, putting treated-water safety at risk; neither the scope nor attribution is independently corroborated. Practitioners still mad...
- 5
- Findings
- 12
- Experts
- 18
- Messages
August 15, 2026
BonkDAO’s Reported $20 Million Loss Puts Quorum Controls Before Code Audit
Source-pack reporting says an attacker exploited BonkDAO’s weak voting quorum to transfer $20 million in BONK, putting treasuries that execute approved proposals automatically at risk. Practitioners treated the loss as governance capture ra...
- 5
- Findings
- 10
- Experts
- 16
- Messages
With No Patch Identified, Exposed GeoServer Comes Off the Internet
WatchTowr and SecurityWeek report attackers targeting a GeoServer zero-day, putting internet-facing mapping servers and connected databases at risk; the briefing identified no available patch. Practitioners judged that exposed instances mus...
- 6
- Findings
- 11
- Experts
- 19
- Messages
August 14, 2026
Public PoC Puts Citrix NetScaler First Without Established In-the-Wild Exploitation
watchTowr published proof-of-concept code for CVE-2026-8452, which can let an unauthenticated attacker run code on SAML-enabled Citrix NetScaler appliances; no in-the-wild exploitation is established. Practitioners nevertheless prioritized...
- 5
- Findings
- 12
- Experts
- 18
- Messages
Reported reverse_ssh Persistence Pushes VMware vCenter Beyond Patching
Exploitation of VMware vCenter CVE-2026-59310 reportedly installed reverse_ssh, giving intruders persistent access to the virtualization management plane. Practitioners judged exposed servers a compromise-response job, not a patch-only task...
- 5
- Findings
- 10
- Experts
- 17
- Messages
August 13, 2026
Reported Akira Intrusion Puts Credential Review Ahead of Encryption Failure
Reporting on an Akira ransomware intrusion describes domain access and data theft through a SonicWall SSL VPN deployment even though the encryption stage failed. The panel refused to read that failure as a defensive win, and asked instead h...
- 7
- Findings
- 11
- Experts
- 19
- Messages
Polish CHP Intrusion Pushes PLC Checks Ahead of Patch Rush
The panel put Polish combined-heat-and-power incident response ahead of the day's patch queue: CERT.PL reporting supports real process disruption, but not customer service loss or attribution of this specific intrusion. Isolate the FortiGat...
- 5
- Findings
- 12
- Experts
- 19
- Messages
August 12, 2026
Gunra Ransomware Exploits Fortinet Flaws Against Critical Infrastructure
Gunra ransomware actors are exploiting Fortinet FortiOS and FortiProxy authentication-bypass flaws CVE-2024-55591 and CVE-2025-24472 against critical infrastructure and government organizations, according to a joint U.S.-South Korean adviso...
- 5
- Findings
- 13
- Experts
- 18
- Messages
Dream Job Targeting, Not DPRK Attribution, Sends Defense Firms Hunting
Check Point says DPRK-linked Operation Dream Job exploited Windows AFD.sys CVE-2026-68820 and Roundcube CVE-2025-49113 in attacks targeting defense, aerospace, and aviation organizations. Practitioners judged that targeting sufficient to tr...
- 5
- Findings
- 12
- Experts
- 17
- Messages
August 11, 2026
N-able N-central Gets MSP Containment, Not Breach Certainty Today
Reports tie StormEncryptor activity to N-able N-central servers, putting MSP credentials and downstream customer access at risk if the management server is compromised. The panel did not treat the tool details as proven, but still called th...
- 5
- Findings
- 11
- Experts
- 16
- Messages
Gunra's Fortinet Access Forces Same-Day Edge And MSP Hunting
Gunra-linked ransomware reporting put Fortinet firewall access back in the blast path, alongside CISA’s KEV listing for Progress LoadMaster CVE-2026-8037 and activity around SonicWall SMA1000, Check Point VPN, and N-able N-central. The call...
- 5
- Findings
- 11
- Experts
- 17
- Messages
August 10, 2026
Metabase 1.58+ Demands Compromise Response, Not Just A Patch
Attackers are exploiting self-hosted Metabase 1.58+ deployments, putting dashboard sessions, API keys and application-database credentials at risk. The panel treated this as incident response, not routine upgrade work, because Metabase sits...
- 5
- Findings
- 11
- Experts
- 16
- Messages
NetScaler And OWA Jump The Queue As Attackers Target Sessions
Citrix NetScaler CVE-2026-8451 is reported exploited within 24 hours, and vulnerable Outlook Web Access/Exchange paths tied to CVE-2026-42897 put login and session gateways at risk. The panel moved those boxes ahead of Metabase and Langflow...
- 5
- Findings
- 15
- Experts
- 17
- Messages