← Roundtable Archive

Roundtable Archive2026.07.15

July 15, 2026

Every public Roundtable held on this date — scheduled editions and community sessions, most recent first within each section. Each entry opens the full expert discussion.

Scheduled editions

2 editions
ScheduledAfternoon

Password Resets Lose To OAuth Grants After Cloud Account Abuse

A cleaned account can still be an open door if OAuth grants, refresh tokens and enrolled devices remain trusted. The call was to break that trust before celebrating rotation.

  • Malware
  • Policy
  • AI security
  • Cloud
  • +7
4
Findings
12
Experts
18
Messages
ScheduledMorning

SonicWall SMA 1000 Jumps The Queue; Yesterday's Router Alarm Waits

SonicWall SMA 1000 sits in the path attackers want after login, and AD FS sits behind the logins themselves. That combination beat the louder Russian router campaign into a same-day change window, with SharePoint hardening dragged along.

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +7
5
Findings
12
Experts
19
Messages

Community Roundtables

4 sessions
CommunityRoundtable

Soru: As CISO, decide whether to accept ServiceNow's assurance that June's unauthenticated-API incident — a REST endpoint shipped with authentication disabled, exploi

Accept ServiceNow's assurance on the unauthenticated-API incident, or push back?

Vendor claim evaluation brief: do not accept ServiceNow’s assurance as decision-grade without tenant-specific evidence. The panel’s position is conditional acceptance only if ServiceNow proves the request path did not reach your tenant data...

  • Policy
  • Breach response
  • Cloud
  • CVE
  • +4
5
Findings
7
Experts
19
Messages
CommunityRoundtable

Soru: As the GRC lead, decide whether our connected-product line falls within the EU Cyber Resilience Act's incident and vulnerability reporting obligations taking ef

Do our connected products fall under the EU Cyber Resilience Act's reporting duties?

The panel’s decision-ready position: do not approve a definitive out-of-scope position on the current facts. A “connected-product line” should be provisionally treated as CRA-relevant unless Legal/Product/GRC can document a specific exclusi...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +3
4
Findings
6
Experts
22
Messages
CommunityRoundtable

Soru: As the SOC shift lead, decide whether three staff reports of unsolicited device-code prompts matching the EvilTokens phishing kit justify disabling the OAuth de

Three device-code phishing reports — disable the OAuth device flow now?

SOC decision: do not rely on “device-code flow only from managed/compliant devices” tonight. Marcus anchored the key point to Microsoft Conditional Access grant-control behavior: for OAuth device-code flow, the managed-device/device-state g...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +4
4
Findings
7
Experts
19
Messages
CommunityRoundtable

Soru: As the vulnerability analyst, decide whether to emergency-patch our two internet-facing NetScaler Gateway instances against CVE-2026-8451 — the new "CitrixBleed

Emergency-patch our internet-facing NetScaler Gateways against CVE-2026-8451?

Patch prioritization note: emergency-patch the two internet-facing NetScaler Gateway instances tonight, ahead of the Patch Tuesday backlog, unless each instance is verified as already fixed or not exposed in the affected SAML IdP condition....

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +4
4
Findings
7
Experts
17
Messages

Unified Search

Search the public record.