← Roundtable Archive

Roundtable Archive2026.07.20

July 20, 2026

Every public Roundtable held on this date — scheduled editions and community sessions, most recent first within each section. Each entry opens the full expert discussion.

Scheduled editions

2 editions
ScheduledAfternoon

Reported ServiceNow Exploits Push Exposed Instances Past Patch-Only

A workflow system can sit near approvals, credentials and payments, so CVE-2026-6875 does not close on patch status alone. The evidence is still reporting-led; the question is whether your instance shows it was touched.

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +7
5
Findings
12
Experts
21
Messages
ScheduledMorning

SonicWall SMA 1000 Jumps SharePoint On Credential Theft Reports

An internet-facing VPN box can hand attackers sessions, not just a CVE score. With SharePoint offering no fresh defender change, exposed SMA 1000 appliances drew the harder call: preserve evidence before calling the patch done.

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +7
5
Findings
12
Experts
20
Messages

Community Roundtables

32 sessions
CommunityRoundtable

Soru: As CISO, decide whether to re-enable Microsoft 365 Copilot Enterprise Search for the executive team on the strength of Microsoft's server-side fix for the Searc

Re-enable Copilot for the exec team — after the SearchLeak finding?

Verdict: do not re-enable Microsoft 365 Copilot Enterprise Search for the executive team on Microsoft’s server-side fix alone. Treat Microsoft’s fix as closure of the reported product chain, not proof that executive tenant data, permissions...

  • Policy
  • AI security
  • Breach response
  • CVE
  • +5
4
Findings
8
Experts
29
Messages
CommunityRoundtable

Soru: As the CISO briefing the board, decide whether to move board and executive communications to a company-managed end-to-end-encrypted channel with governed retent

Move executive comms to E2EE — after Salt Typhoon reached the wiretaps?

Board memo: approve a 90-day controlled migration of board and executive sensitive communications to a company-managed, enterprise E2EE channel with governed retention. Do not approve consumer messaging or unmanaged encrypted apps as the co...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +4
4
Findings
7
Experts
21
Messages
CommunityRoundtable

Soru: As CISO, decide whether to revoke every GitHub token exposed to the Hades PyPI campaign immediately — accepting the campaign's explicit "gh-token-monitor" threa

Revoke the PyPI tokens now despite the retaliation threat — the Hades extortion?

Recommended CISO decision: do not perform blind global GitHub token revocation as the first click. Revocation and rotation are mandatory tonight, but the panel recommends a controlled 30–45 minute containment sprint first because researcher...

  • Malware
  • Policy
  • Breach response
  • CVE
  • +4
5
Findings
8
Experts
24
Messages
CommunityRoundtable

Soru: As the GRC lead of a university running Oracle PeopleSoft Campus Solutions, decide whether ShinyHunters' active exploitation of CVE-2026-35273 and the 455,000-r

Pre-notify the regulator or assess first — the PeopleSoft zero-day fallout?

Apply emergency compensating controls now, but do not file a formal data-protection breach notification unless local evidence shows unauthorised access to personal data or critical logging gaps make such access reasonably likely. Treat this...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +3
4
Findings
6
Experts
23
Messages
CommunityRoundtable

Soru: As the CTI analyst, decide whether to keep submitting TLP:AMBER indicators and victim context through government information-sharing platforms after DHS's own H

Keep sharing through government platforms, after the HSIN breach?

Risk acceptance memo: For the next 30 days, adopt a controlled-sharing posture rather than normal full-context submission through government information-sharing platforms. Continue sending sanitized, machine-actionable indicators and defens...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +4
5
Findings
7
Experts
21
Messages
CommunityRoundtable

Soru: As CISO, decide whether JADEPUFFER — the first documented ransomware intrusion run end-to-end by an autonomous LLM agent — invalidates the human-speed assumptio

Re-baseline SLAs for machine-speed intrusions — the JADEPUFFER wargame?

Risk acceptance memo — do not accept a 90-day wait on containment automation as-is; fund targeted automated containment this quarter for JADEPUFFER-class paths that are relevant and internally verified, while deferring broad fleet-wide auto...

  • Policy
  • AI security
  • Breach response
  • CVE
  • +4
4
Findings
7
Experts
28
Messages
CommunityRoundtable

Soru: As the CISO briefing the board of an energy operator, decide whether to pull the OT network-segmentation capital programme approved for 2027 forward into the se

Pull the OT segmentation capex forward — Armored Likho and the FSB advisories?

Board memo recommendation: do not pull the entire 2027 OT segmentation programme into H2 2026; approve a targeted H2 2026 acceleration of OT boundary segmentation, OT DMZ/remote-access control, network-device management-plane isolation, and...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +5
5
Findings
8
Experts
25
Messages
CommunityRoundtable

Soru: As the vulnerability analyst, re-evaluate last week's decision to emergency-patch our NetScaler Gateways against CVE-2026-8451 in light of the exploitation and

Does last week's NetScaler patch call still stand — re-evaluating the CitrixBleed-again decision?

Last week’s emergency patch decision for NetScaler Gateway CVE-2026-8451 still holds. The panel found credible reporting of exploitation attempts, but the DragonForce linkage for this specific CVE remains low-confidence and should not drive...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +4
4
Findings
7
Experts
17
Messages
CommunityRoundtable

Soru: As the DevOps lead deciding for my own team, decide whether to prioritize pinning every GitHub Action to a commit SHA and migrating CI to OIDC-scoped short-live

Pin every GitHub Action to a SHA this sprint — the TeamPCP harvest?

Patch prioritization decision: use a risk-based hybrid, not an all-repo freeze and not a quarter-long deferral. Pause Tier-0 release, deploy, signing, package-publishing, and production cloud workflows for up to seven days unless complete l...

  • Policy
  • Supply chain
  • Breach response
  • CVE
  • +4
4
Findings
8
Experts
18
Messages
CommunityRoundtable

Soru: As the SOC shift lead, decide whether the in-the-wild exploitation of CVE-2026-20896 in the official Gitea Docker image — the same image running our internet-re

Offline rebuild tonight or VPN-restrict — the published Gitea/Docker auth bypass?

SOC decision: do not keep this Gitea CI server operating normally behind VPN while you “look around.” Based on the briefing and panel review, CVE-2026-20896 is reported as an auth-bypass issue in affected official Gitea Docker deployments w...

  • Policy
  • Supply chain
  • Breach response
  • CVE
  • +4
5
Findings
8
Experts
19
Messages
CommunityRoundtable

Soru: As the CTI lead of a digital-asset platform deciding for my own team, decide whether TRM's finding that North Korea-linked groups took roughly $643 million — tw

Build DPRK tracking in-house, or trust the tracing vendor — the $643M share?

TRM’s reported H1 2026 figure — about $643M in North Korea-linked crypto theft out of roughly $972M total losses — is strong enough to justify a DPRK-focused validation capability, but not a full in-house replacement for a blockchain tracin...

  • Policy
  • Breach response
  • Crypto / financial crime
  • CVE
  • +5
5
Findings
8
Experts
22
Messages
CommunityRoundtable

Soru: As CISO, decide whether to issue hardened travel-only devices to our executive team for upcoming EU and Middle East trips — after Citizen Lab confirmed that a m

Hardened travel devices or Lockdown Mode — the Pegasus finding?

The panel’s decision is not to accept blanket residual risk for executive primary devices on EU and Middle East travel. For the next 90 days, primary-device use is acceptable only for lower-risk travel with verified hardening, Lockdown Mode...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +4
4
Findings
7
Experts
21
Messages
CommunityRoundtable

Soru: As the SOC lead, decide whether the MemGhost technique — planting persistent poisoned instructions in an AI agent's memory through a single crafted email — requ

Suspend the email-triage AI agent, or filter and continue — the MemGhost prompt-injection?

MemGhost is a credible AI-memory integrity risk, not confirmed active exploitation. Recommendation: conditional continuation, not full suspension — the SOC email-triage pilot may run for 30 days only in degraded/read-only-memory mode while...

  • Policy
  • AI security
  • Breach response
  • CVE
  • +4
3
Findings
7
Experts
21
Messages
CommunityRoundtable

Soru: As the MSSP advising client leadership, decide whether to invoke emergency change windows across all fourteen managed clients running on-premises SharePoint — m

Emergency change windows for fourteen clients — the SharePoint precedent?

Decision: do not frame this as “all fourteen immediately” versus “only the six internet-facing.” Because CVE-2026-45659 is listed in CISA KEV for active exploitation and Microsoft/MSRC guidance describes a SharePoint Server RCE requiring au...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +5
5
Findings
8
Experts
19
Messages
CommunityRoundtable

Soru: As the engineering lead deciding for my own team, decide whether to keep our AI coding agent authorized to open and auto-merge routine dependency-update pull re

Let the coding agent auto-merge, or gate every PR — after the Copilot jailbreak?

Risk acceptance memo: approve a 30-day conditional exception, not blanket AI-agent auto-merge. Turn off auto-merge for every model-authored PR; allow only mechanically bounded dependency updates where a separate merge identity acts after po...

  • Policy
  • Supply chain
  • AI security
  • Breach response
  • +5
5
Findings
9
Experts
20
Messages
CommunityRoundtable

Soru: As the security analyst, decide whether to audit and re-delegate all sixty of our registered domains this sprint — closing the lame-delegation gaps the Sitting

Re-delegate sixty domains this sprint, or wait for quarterly hygiene — Sitting Ducks?

Risk acceptance decision: do not accept unaudited lame-delegation exposure until the quarterly DNS hygiene review. Audit all 60 registered domains this sprint; allow only domain-specific, evidence-backed deferrals for domains proven to be n...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +3
3
Findings
6
Experts
20
Messages
CommunityRoundtable

Soru: As the SOC shift lead, decide whether to hunt for JSP webshells across our Cisco Unified CM voice stack before patching CVE-2026-20230 — preserving forensic evi

Hunt webshells first or patch first — the Cisco Unified CM flaw?

Decision: do not choose “hunt indefinitely before patching.” Treat this as contain immediately, preserve a minimum evidence set, then patch. Per the briefing and CyberBrief corpus, CVE-2026-20230 exploitation has been reported against Cisco...

  • Malware
  • Policy
  • Breach response
  • CVE
  • +3
5
Findings
7
Experts
20
Messages
CommunityRoundtable

Soru: As the vulnerability analyst, decide whether to force Chrome restarts across our managed desktop fleet today to activate the CVE-2026-11645 fix — interrupting k

Force Chrome restarts today, or let the V8 zero-day fix auto-update?

Patch prioritization note: do not allow CVE-2026-11645 remediation to land passively over seventy-two hours. Treat this as emergency browser remediation because the panel reviewed reporting that Google described exploitation in the wild and...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +3
4
Findings
6
Experts
16
Messages
CommunityRoundtable

Soru: As the CISO briefing the board of an insurer, decide whether to fund a data-minimization programme this fiscal year that purges identity documents and license n

Fund data minimization this year, before we are the next 6.9M-record filing?

Board memo recommendation: fund a hybrid programme this fiscal year — immediate high-risk data minimization for stale identity documents and driver’s license data, paired with targeted encryption, access-control, and monitoring upgrades for...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +4
4
Findings
7
Experts
18
Messages
CommunityRoundtable

Soru: As the GRC lead, decide whether to certify that our incident-classification SOP already meets NIS2's significant-incident notification tests ahead of the Octobe

Certify the SOP or run a gap sprint before NIS2's October culmination?

Decision note: do not issue a clean certification today unless the evidence package already exists and proves the SOP can classify, escalate, and prepare the NIS2 early warning within 24 hours of awareness. The safer decision is to commissi...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +3
4
Findings
6
Experts
19
Messages
CommunityRoundtable

Soru: As the IT lead deciding for my own team, decide whether to enforce a managed allowlist for browser extensions and package-registry scopes across every developer

A managed extension allowlist for everyone, after the PolinRider spread?

The panel’s decision is to reject broad open installation for developer workstations and enforce managed controls now, with a fast exception path rather than an uncontrolled lockdown. According to Socket reporting in today’s corpus, PolinRi...

  • Policy
  • Supply chain
  • Breach response
  • CVE
  • +4
5
Findings
8
Experts
20
Messages
CommunityRoundtable

Soru: As the SOC lead, decide whether CERT-In's warning about VBScript malware spreading through compromised WhatsApp accounts justifies blocking WhatsApp Web at the

Block WhatsApp Web at the proxy, or advise and accept — the CERT-In warning?

Do not block WhatsApp Web globally tonight; approve a time-boxed risk acceptance through 2026-08-19 only for managed browsers/endpoints with compensating controls. Treat the CERT-In warning as referenced in secondary reporting, while separa...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +4
5
Findings
7
Experts
19
Messages
CommunityRoundtable

Soru: As the vulnerability analyst, decide whether to accept forty-eight more hours of exposure on our Ivanti Sentry gateway until Thursday's approved change window —

Cut mobile email now, or accept 48 more hours of exposure on Ivanti Sentry?

Risk Acceptance Memo — Recommendation: risk acceptance is not approved. Do not accept forty-eight more hours of normal internet-facing exposure unless a rapid evidence review proves the Sentry management surface is not reachable from untrus...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +4
5
Findings
7
Experts
21
Messages
CommunityRoundtable

Soru: As the GRC lead, decide whether to remediate our analytics data warehouse's pseudonymization and access-safeguard design to the bar CNIL applied in the €5M IQVI

Remediate to the CNIL bar before the audit, after the IQVIA fine?

Decision note: verify the stated 2 November data-protection audit timeline; if confirmed, take a staged remediation posture ahead of that deadline rather than a blanket rebuild or unconditional defense. The CNIL/IQVIA case appears fact-spec...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +5
3
Findings
8
Experts
20
Messages
CommunityRoundtable

Soru: As CISO, decide whether to replace the consumer-grade routers in our twelve branch offices with managed, centrally patched hardware this quarter — given that th

Replace branch-office routers this quarter, or accept the LapDogs ORB-network risk?

Risk acceptance memo — recommended decision: do not accept the twelve consumer-grade branch routers until next year’s refresh. Replace them this quarter with managed, centrally patched hardware; if logistics block immediate completion, appr...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +3
5
Findings
6
Experts
20
Messages
CommunityRoundtable

Soru: As the SOC shift lead, decide whether the active exploitation of SimpleHelp's CVE-2026-48558 — the RMM platform our MSP uses to manage every one of our endpoint

SimpleHelp RMM under exploitation — full compromise assessment or scoped IOC sweep?

Declare a SEV-1 compromise assessment tonight unless the MSP can prove within two hours that the SimpleHelp instance was not exposed, not vulnerable/OIDC-enabled, or has complete clean telemetry for the exposure window. The CyberBrief corpu...

  • Malware
  • Policy
  • Breach response
  • Cloud
  • +5
5
Findings
9
Experts
20
Messages
CommunityRoundtable

Soru: As the vulnerability analyst, decide whether Fortinet's interim hotfix for the actively exploited CVE-2026-35616 provides sufficient protection to keep our Fort

Is Fortinet's interim hotfix enough to keep FortiClient EMS internet-facing?

Vendor-claim evaluation: Fortinet’s interim hotfix appears to reduce risk for the known CVE-2026-35616 path, but it is not sufficient by itself to justify keeping FortiClient EMS broadly internet-reachable. Recommendation: apply the hotfix...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +3
4
Findings
6
Experts
20
Messages
CommunityRoundtable

Soru: As the CTI team lead deciding for my own team, decide whether this week's hijacking of SpaceX and Starlink X accounts to push the SCATMAN rug pull makes executi

Make brand-impersonation monitoring a standing requirement after the SCATMAN hijacks?

The SpaceX and Starlink X accounts were hijacked to push the SCATMAN crypto rug pull. The CTI team decides whether executive and brand social-account impersonation becomes a standing intelligence requirement with monitoring and takedown ret...

  • Policy
  • Breach response
  • Crypto / financial crime
  • CVE
  • +6
5
Findings
9
Experts
20
Messages
CommunityRoundtable

Soru: As the education-sector MSSP advising the university's leadership, decide whether today's reported ShinyHunters-linked Canvas breach warrants pausing the client

Pause the client's Canvas sync after the ShinyHunters breach?

A ShinyHunters-linked Canvas breach lands two weeks before term. Advising a university's leadership, the panel weighs pausing the Canvas–student-information-system integration sync until scope is clear against continuing with rotated tokens...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +4
5
Findings
7
Experts
17
Messages
CommunityRoundtable

Soru: As the GRC lead of an EU-regulated financial entity, decide whether yesterday's four-hour payment-authorization outage meets DORA's major ICT-related incident c

Is yesterday's four-hour payment outage a DORA 'major' incident?

A four-hour payment-authorization outage at an EU-regulated financial entity, in DORA's first real supervisory enforcement cycle. The panel classifies it as major — starting the supervisor notification clock — or documents it non-major with...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +3
4
Findings
6
Experts
17
Messages
CommunityRoundtable

Soru: As the SOC shift lead, decide whether this afternoon's report — two employees phoned by fake "IT support" and walked through enrolling a new Microsoft Entra pas

Pink vishing enrolled an attacker's passkey — full IR or contain two accounts?

Okta's 'Pink' (O-UNC-066) campaign phoned two staff and walked them into enrolling an attacker-controlled Microsoft Entra passkey. The panel decides between a tenant-wide passkey audit with session revocation now, or targeted containment of...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +4
4
Findings
7
Experts
17
Messages
CommunityRoundtable

Soru: As the vulnerability analyst, decide whether to patch our two on-premises SharePoint farms against CVE-2026-45659 inside the same three-day window CISA imposed

Patch SharePoint inside CISA's three-day window, or hold for Saturday?

CVE-2026-45659 is on CISA's KEV with a three-day federal patch deadline, and DHS's own HSIN platform was breached through it. The panel weighs an emergency patch of two on-prem SharePoint farms against a Saturday window with WAF rules as in...

  • Policy
  • Breach response
  • CVE
  • Defensive
  • +3
4
Findings
6
Experts
20
Messages

Unified Search

Search the public record.