← Roundtable Archive

Roundtable Archive2026.04.24

April 24, 2026

Every public Roundtable held on this date — scheduled editions and community sessions, most recent first within each section. Each entry opens the full expert discussion.

Scheduled editions

6 editions
ScheduledMorning

Signal Wasn't Broken; iOS Kept Deleted Messages Across Encrypted Apps

The uncomfortable part is the phone keeping text where apps cannot delete it. Apple patched CVE-2026-28950 after FBI forensics recovered deleted Signal messages, and the same preview path touches WhatsApp and Telegram.

  • Policy
  • AI security
  • Breach response
  • CVE
  • +7
5
Findings
10
Experts
6
Messages
ScheduledMorning

Bitwarden Vaults Hold; End-User Password Rotation Loses To Developer Tokens

The vault panic eased, but the build pipeline did not. Bitwarden says no vault data was accessed, moving user password resets back into change windows while GitHub, npm and cloud tokens remain the harder call.

  • Policy
  • AI security
  • Breach response
  • CVE
  • +7
5
Findings
10
Experts
7
Messages
ScheduledMorning

Xinference Beats Bitwarden After 680,000 PyPI Downloads Hit Enterprise ML

The quieter PyPI compromise now carries the larger bill: 680,000 Xinference downloads landed in enterprise ML stacks, while Bitwarden’s confirmed blast radius shrank to 334.

  • Policy
  • Supply chain
  • AI security
  • Breach response
  • +7
5
Findings
11
Experts
10
Messages
ScheduledMorning

TeamPCP’s ICP Canister C2 Beats The Usual Takedown Playbook

Domain seizures and hosting calls do not reach cjn37-uyaaa-aaaac-qgnva-cai.raw.icp0.io; defenders are left watching behavior instead of waiting for a provider to pull the plug.

  • Policy
  • AI security
  • Breach response
  • CVE
  • +7
5
Findings
10
Experts
11
Messages
ScheduledMorning

PSAPs Lock Intrado 911 EGW Management To Bastions Before Patching

The npm-and-PyPI worm was the loud story; the panel put the 911 network first. Intrado's Emergency Gateway sits one management-plane mistake away from the calls it routes — so move its admin access behind a bastion before you patch, and lea...

  • Policy
  • AI security
  • Breach response
  • CVE
  • +7
5
Findings
10
Experts
12
Messages
ScheduledAfternoon

Bitwarden CLI Turns Stolen npm Tokens Into A Package-Republishing Worm

The bad package is only the start: in 93 minutes, stolen npm tokens may have republished malware into 200–500 downstream packages. The work now moves to what each infected developer could publish.

  • Policy
  • AI security
  • Breach response
  • CVE
  • +7
5
Findings
10
Experts
11
Messages

Unified Search

Search the public record.