Roundtable Archive

Every public Roundtable, on the record.

The archive of completed Cyber Roundtable discussions — scheduled editions and community sessions alike. Decision Records live in the Cyber Decision Ledger.

Latest on recordAugust 18, 2026
Scheduled · Afternoon edition
Medusa Advisory Sends Shared Providers Into Timed Recovery Tests
6Findings12Experts16Messages
299
Roundtables convened
3,008
Expert seats taken
Apr–Aug
2026 on record
2
Editions / day
Cadence · Mar → Aug

Last 7 days

What the panel worked through this week — sessions, the threat domains they covered, and where the ledger moved.

14
Sessions
71
Findings
7
Records published
3
Predictions due

Threat domains covered · click to filter this week

Rising entities

Entities appearing in more public Roundtable sessions than in the prior seven days.

Filter the archive · applies instantlyNo filters active · showing all editions
Edition
Source
Showing 2140 of 299 Roundtables
Sort

August 9, 2026

2 editions · afternoon + morning
View date →
ScheduledAfternoon

Metabase Zero-Day Beats Water-Control Alarms For Tonight's Work

Metabase faces a CVSS 10.0 unauthenticated SQL injection zero-day exploited to gain admin access, steal credentials, and pull data from connected databases; Framework also disclosed customer-data exposure through Metabase Cloud. Even with w...

  • Policy
  • AI security
  • Breach response
  • Cloud
  • +9
5
Findings
12
Experts
19
Messages
ScheduledMorning

BdThemes Poisoned Feed Jumps Past Yesterday's LoadMaster Alarm

Wordfence reported a poisoned API response in BdThemes' WordPress plugin update path, putting downstream sites at risk if they trusted the feed. Practitioners treated it as a software trust-path failure, not a settled actor story; LoadMaste...

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +10
5
Findings
15
Experts
21
Messages

August 8, 2026

2 editions · afternoon + morning
View date →
ScheduledAfternoon

N-able Holds The Lead After Kemp's Fresh Load-Balancer Exploit

A fresh Kemp exploit would normally own the afternoon; here it did not. N-able still carries the harder risk: MSP admin access reportedly used to reach customer systems and leave Cloudflare Tunnel persistence behind.

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +8
5
Findings
13
Experts
20
Messages
ScheduledMorning

N-able N-central Becomes A Customer Compromise Hunt, Not A Hotfix

The MSP console is the trust boundary: exploitation appears to have reached customer networks, so the second mandatory N-central hotfix only starts the work. The question is how far admin access traveled before the fix.

  • Policy
  • Supply chain
  • AI security
  • Breach response
  • +7
5
Findings
11
Experts
18
Messages

August 7, 2026

2 editions · afternoon + morning
View date →
ScheduledAfternoon

Public Water PLCs Come Off The Internet Before Iran Labels Matter

A public PLC/HMI path is a process-safety problem before it is an Iran story. The call was to judge U.S. water systems by what is exposed, not by the label attached to the actor.

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +8
5
Findings
13
Experts
18
Messages
ScheduledMorning

Alleged Coldcard Firmware Flaw Linked to $100M in Estimated Bitcoin Wallet Losses

Older Coldcard firmware allegedly weakened Bitcoin wallet recovery-phrase randomness, putting more than 5,000 wallets at risk and contributing to losses estimated above $100 million. CryptoJS randomness failures also drove at least $5.7 mil...

  • Policy
  • Supply chain
  • AI security
  • Breach response
  • +9
5
Findings
13
Experts
18
Messages

August 6, 2026

2 editions · afternoon + morning
View date →
ScheduledAfternoon

AI Agents Lose Privileged Tool Calls Until Humans Approve Them

The patches were not the comfort move; autonomy was. Bedrock AgentCore, Google ADK and Vercel fixes still left the hard question: which agents can touch production without a person in the loop.

  • Policy
  • Supply chain
  • AI security
  • Breach response
  • +9
5
Findings
13
Experts
19
Messages
ScheduledMorning

Twelve-State Water Utility Attacks Put PLC Recovery Ahead Of Iran Labels

Twelve states turns a familiar PLC story into a continuity call, not an attribution contest. The split was how much weight to put on CyberAv3ngers-style labeling while operators still have controller logic to trust.

  • Policy
  • Supply chain
  • Breach response
  • Cloud
  • +8
5
Findings
12
Experts
18
Messages

August 5, 2026

2 editions · afternoon + morning
View date →
ScheduledAfternoon

SonicWall SMA 1000 Comes Off The Internet Alongside N-Central

INC-linked reporting made SMA 1000 less a patch chore than a place to look for hands already inside. Tomcat and Langflow matter, but exposed admin consoles won the afternoon because they can turn one login into reach.

  • Policy
  • Supply chain
  • AI security
  • Breach response
  • +8
5
Findings
12
Experts
18
Messages
ScheduledMorning

Cloudflare Tunnels Put N-Central Ahead Of Tomcat's KEV Listing

The fresh KEV bug was Tomcat, but the durable access was in RMM. Huntress-referenced N-central Take Control abuse with Cloudflare Tunnel services made patching only the start of the customer-pivot question.

  • Policy
  • Supply chain
  • AI security
  • Breach response
  • +7
5
Findings
11
Experts
18
Messages

August 4, 2026

2 editions · afternoon + morning
View date →
ScheduledAfternoon

Water Utilities Must Pull PLCs From The Internet Before Naming The Actor

The risk is a plant losing safe control, not a cleaner attribution note. Reported multi-state targeting and operational degradation were enough to treat exposed HMI/SCADA/PLC access as a public-safety problem now.

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +9
5
Findings
14
Experts
21
Messages
ScheduledMorning

CyberAv3ngers Target Unitronics PLCs In Water Utilities

CyberAv3ngers is targeting internet-exposed Unitronics Vision PLCs in water and wastewater environments, while CrowdStrike reports attackers are now going directly after AI systems and cloud model access. The highest-priority risks are oper...

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +7
5
Findings
12
Experts
21
Messages

August 3, 2026

2 editions · afternoon + morning
View date →
ScheduledAfternoon

Reported N-Central Exploitation Turns MSP Patch Ticket Into Compromise Case

An RMM bug does not stay inside one tenant. With N-central reportedly exploited, the call shifts from install-the-fix to asking which downstream customer footholds an attacker may already own.

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +7
5
Findings
12
Experts
19
Messages
ScheduledMorning

N-able N-central Outranks Cisco Because MSP Admin Access Fans Out

An exploited N-central console is not just another exposed appliance; it can become a route into customers that trusted the MSP. Cisco stayed in view, but without a fresh scope change, N-central set the morning’s work.

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +7
5
Findings
12
Experts
18
Messages

August 2, 2026

2 editions · afternoon + morning
View date →
ScheduledAfternoon

WhatsApp Zero-Click Gets Forensics, Not Fleet-Wide Handset Panic

A dual-CVE WhatsApp/iOS chain changes the call for executives, journalists and responders, but not for every phone in the fleet. The split is between routine patching and devices that need isolation before sensitive accounts come back.

  • Policy
  • Supply chain
  • AI security
  • Breach response
  • +9
5
Findings
13
Experts
20
Messages
ScheduledMorning

Reported Rockwell PLC Tampering Outruns Yesterday's Exposure Cleanup

Taking Allen-Bradley PLCs off the internet no longer answered the concern: reports of changed IP addresses and passwords turn this into a control-path integrity problem for water, energy and government sites.

  • Policy
  • AI security
  • Cloud
  • Crypto / financial crime
  • +9
5
Findings
13
Experts
21
Messages

August 1, 2026

2 editions · afternoon + morning
View date →
ScheduledAfternoon

Exposed Rockwell PLCs Come Off The Internet After Multi-State Water Disruption Reports

This was not treated as another PLC bug. With FBI/EPA reporting service disruption across multiple states, the call is to cut direct internet paths before operators trust HMI views or remote engineering access.

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +7
5
Findings
12
Experts
17
Messages
ScheduledMorning

DeepSeek/Hermes Turns Exposed Tomcat Into A Compromise Hunt

The surprise was not a new species of AI attack; it was speed. Unit 42 says DeepSeek/Hermes chained recon, exploit choice and execution against exposed Tomcat and NetScaler, turning patch tickets into compromise questions.

  • Policy
  • Supply chain
  • AI security
  • Breach response
  • +9
5
Findings
13
Experts
24
Messages

July 31, 2026

2 editions · afternoon + morning
View date →
ScheduledAfternoon

Minnesota Water Utilities Cut Direct PLC And HMI Internet Paths

Disruption across more than 30 communities made this less a patch chase than a control question. Attribution stays caveated; the immediate test is whether operators can narrow PLC/HMI reach without changing controllers blind.

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +7
4
Findings
12
Experts
21
Messages
ScheduledMorning

CosmosEscape Gets Forensics First, Not A Fleetwide Key Reset

A cloud database bug can turn key rotation into its own outage. High-value Azure Cosmos DB Gremlin API users need vendor attestation and forensics before controlled rotation, not a tenant-wide fire drill.

  • Malware
  • Policy
  • Supply chain
  • AI security
  • +7
5
Findings
12
Experts
18
Messages

Unified Search

Search the public record.