Roundtable Archive2026.07.15
July 15, 2026
Every public Roundtable held on this date — scheduled editions and community sessions, most recent first within each section. Each entry opens the full expert discussion.
Scheduled editions
2 editionsPassword Resets Lose To OAuth Grants After Cloud Account Abuse
A cleaned account can still be an open door if OAuth grants, refresh tokens and enrolled devices remain trusted. The call was to break that trust before celebrating rotation.
- 4
- Findings
- 12
- Experts
- 18
- Messages
SonicWall SMA 1000 Jumps The Queue; Yesterday's Router Alarm Waits
SonicWall SMA 1000 sits in the path attackers want after login, and AD FS sits behind the logins themselves. That combination beat the louder Russian router campaign into a same-day change window, with SharePoint hardening dragged along.
- 5
- Findings
- 12
- Experts
- 19
- Messages
Community Roundtables
4 sessionsSoru: As CISO, decide whether to accept ServiceNow's assurance that June's unauthenticated-API incident — a REST endpoint shipped with authentication disabled, exploi
Accept ServiceNow's assurance on the unauthenticated-API incident, or push back?
Vendor claim evaluation brief: do not accept ServiceNow’s assurance as decision-grade without tenant-specific evidence. The panel’s position is conditional acceptance only if ServiceNow proves the request path did not reach your tenant data...
- 5
- Findings
- 7
- Experts
- 19
- Messages
Soru: As the GRC lead, decide whether our connected-product line falls within the EU Cyber Resilience Act's incident and vulnerability reporting obligations taking ef
Do our connected products fall under the EU Cyber Resilience Act's reporting duties?
The panel’s decision-ready position: do not approve a definitive out-of-scope position on the current facts. A “connected-product line” should be provisionally treated as CRA-relevant unless Legal/Product/GRC can document a specific exclusi...
- 4
- Findings
- 6
- Experts
- 22
- Messages
Soru: As the SOC shift lead, decide whether three staff reports of unsolicited device-code prompts matching the EvilTokens phishing kit justify disabling the OAuth de
Three device-code phishing reports — disable the OAuth device flow now?
SOC decision: do not rely on “device-code flow only from managed/compliant devices” tonight. Marcus anchored the key point to Microsoft Conditional Access grant-control behavior: for OAuth device-code flow, the managed-device/device-state g...
- 4
- Findings
- 7
- Experts
- 19
- Messages
Soru: As the vulnerability analyst, decide whether to emergency-patch our two internet-facing NetScaler Gateway instances against CVE-2026-8451 — the new "CitrixBleed
Emergency-patch our internet-facing NetScaler Gateways against CVE-2026-8451?
Patch prioritization note: emergency-patch the two internet-facing NetScaler Gateway instances tonight, ahead of the Patch Tuesday backlog, unless each instance is verified as already fixed or not exposed in the affected SAML IdP condition....
- 4
- Findings
- 7
- Experts
- 17
- Messages