Roundtable Archive2026.07.18
July 18, 2026
Every public Roundtable held on this date — scheduled editions and community sessions, most recent first within each section. Each entry opens the full expert discussion.
Scheduled editions
2 editionsExploited SharePoint Turns Patching Into A Key-Exposure Hunt
The patch is only the first cut: Rapid7 and CISA reporting put SharePoint CVE-2026-58644 in active exploitation, so the live question is whether RCE reached service accounts, sessions or machine keys.
- 5
- Findings
- 11
- Experts
- 20
- Messages
NadMesh Turns Exposed AI Tools Into A Cloud Secret Theft Case
The risk is not a chatbot going rogue; it is Gradio, ComfyUI and Docker APIs left reachable while NadMesh harvests AWS keys and Kubernetes tokens. That moved the fix from AI policy to exposed admin surfaces.
- 5
- Findings
- 12
- Experts
- 20
- Messages
Community Roundtables
4 sessionsSoru: As the vulnerability analyst, decide tonight which subset of today's July Patch Tuesday release qualifies for our emergency out-of-band window this week — judge
Which of July's Patch Tuesday CVEs earn an emergency out-of-band window?
Patch prioritization note: keep the emergency window narrow, but make AD FS a verification-first priority, not an automatic emergency claim. If Microsoft or CISA confirms a July AD FS issue affecting your deployed version as exploited or KE...
- 4
- Findings
- 7
- Experts
- 19
- Messages
Soru: As the vulnerability analyst, decide whether to emergency-patch our two legacy ColdFusion applications against CVE-2026-48282 this week or contain them behind t
Emergency-patch our legacy ColdFusion apps against CVE-2026-48282, or contain them?
Decision: emergency-patch both legacy ColdFusion applications this week. Do not rely on WAF containment until quarter-end replatforming; the panel assesses WAF containment may buy only limited short-term time while patching, and only if con...
- 4
- Findings
- 6
- Experts
- 23
- Messages
Soru: As CISO, decide whether to adopt a standing comply-first policy for vendor emergency orders issued without technical disclosure — shutting down within hours whe
Adopt a standing comply-first policy for undisclosed vendor emergency orders?
Adopt a standing comply-first containment policy for credible vendor emergency shutdown orders affecting internet-facing, trust-boundary, identity-adjacent, file-transfer, or sensitive-data systems. Use risk-assess-first only as a break-gla...
- 3
- Findings
- 8
- Experts
- 17
- Messages
Soru: As the CISO briefing the board, decide which single programme receives this year's remaining €800,000 of security capital — accelerating OT network segmentation
Where does this year's last €800k of security capital go?
Board memo — decision: Allocate the remaining €800,000 to a 90-day data-exfiltration detection and extortion-resilience programme. Identity enrollment hardening and OT network segmentation are both important, but under the strict one-progra...
- 4
- Findings
- 9
- Experts
- 25
- Messages