Cyber Decision LedgerPublic reviewed decisions

The decisions, on the record.

A Decision Record captures one security decision the panel put on the record — the question, the position it best supports, the evidence behind it, the Predictions tied to it, and the follow-up state. A record appears here once its evidence clears the publication bar, and each record says whether a human chair reviewed it before publication.

Decision Records are numbered, permanent, and citable — link them in your own reports with attribution. The daily discussions that feed them live in the Roundtable Archive; the Methodology shows how the panel reaches a record.

Latest decision2026.08.18
CriticalHigh confidenceImmediate defense of water-facility controllers
Harden internet-exposed water-facility controllers

Remove programmable controllers from direct internet exposure, restrict operational-technology ports, rotate credentials, require multifactor authentication, preserve evidence, verify configurations and water quality, rehearse manual operation, and notify relevant authorities.

From the Morning roundtable

Ledger at a glance

244
Public Decision Records
2
Prediction resolutions recorded
Calibration deep-dive
17
Critical severity
All critical records
9
Records with an open Prediction
1362
Evidence references
How the panel reaches a Public Decision Record

Every figure above covers the whole public ledger · as of

Filter this page · applies instantlyNo filters active · showing all records30 shown
Sort

Decision Records

18 AUGUST 20263 records
RecordCRT-2026-02452026.08.18Morning roundtable
Immediate defense of water-facility controllers

Harden internet-exposed water-facility controllers

Remove programmable controllers from direct internet exposure, restrict operational-technology ports, rotate credentials, require multifactor authentication, preserve evidence, verify configurations and water quality, rehearse manual operation, and notify relevant authorities.

AreaBreachVulnerability
SeverityCritical
Evidence and confidenceHigh confidence · 1/8 backed · 2 gaps3 references
StateActiveRev 2026-08-18
RecordCRT-2026-02442026.08.18Morning roundtable
LiteLLM supply-chain compromise response

Contain reported backdoored LiteLLM releases

Quarantine LiteLLM versions 1.82.7 and 1.82.8, preserve build and runtime evidence, rebuild from verified trusted artifacts, and rotate or revoke reachable credentials from a clean system.

AreaSupply chain
SeverityHigh
Evidence and confidenceHigh confidence · 1/8 backed · 2 gaps4 references
StateActiveRev 2026-08-18
RecordCRT-2026-02432026.08.18Morning roundtable
Coldcard seed replacement after weak entropy

Replace Coldcard seeds generated with weak entropy

Treat potentially affected seeds as a high-severity exposure. Generate replacement seeds on corrected or otherwise trusted hardware, verify recovery offline, and migrate funds promptly rather than relying on a firmware update alone.

AreaPatch prioritizationVulnerability
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps4 references
StateActiveRev 2026-08-18
17 AUGUST 20263 records
RecordCRT-2026-02422026.08.17Afternoon roundtable
Controlled validation of unauthorized Copilot actions

Validate Copilot boundary-crossing claims with an isolated canary

Run one isolated end-to-end canary test using synthetic identities, data, tokens, a harmless connector, a sandbox-only nonce, and tightly controlled egress. Contain immediately if an unauthorized action or boundary crossing occurs.

AreaVendor claim
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps4 references
StateActiveRev 2026-08-17
RecordCRT-2026-02412026.08.17Afternoon roundtable
Coldcard weak-seed remediation

Replace weak Coldcard wallet seeds after firmware remediation

A firmware update alone does not remediate seeds generated with weak entropy. Update affected devices, create entirely new seeds on fixed firmware, independently verify receiving addresses, replace affected signing descriptors, and migrate funds from old addresses.

AreaVulnerability
SeverityCritical
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps4 references
StateActiveRev 2026-08-17
RecordCRT-2026-02402026.08.17Afternoon roundtable
VMware vCenter exploitation response

Contain reported VMware vCenter exploitation

Remove vCenter management access from the internet, isolate systems showing compromise indicators, preserve evidence, apply vendor-supported fixes, rotate administrative credentials that may have been reachable, and hunt across managed ESXi hosts and datastores.

AreaBreachPatch prioritizationTechVirtualization
SeverityCritical
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps4 references
StateActiveRev 2026-08-17
16 AUGUST 20261 record
RecordCRT-2026-02392026.08.16Afternoon roundtable
SAP Commerce Cloud vulnerability response

Immediate exposure reduction for affected SAP Commerce Cloud systems

Identify potentially affected internet-facing Data Hub Adapter deployments, apply the applicable vendor-confirmed remediation or restrict the vulnerable endpoint until remediation is complete, preserve telemetry, and escalate to incident response only when exploit traffic is followed by consequential system behavior.

AreaPatch prioritizationSOC escalationVulnerability
SeverityHigh
Evidence and confidenceHigh confidence · 0/9 backed · 2 gaps4 references
StateActiveRev 2026-08-16
11 AUGUST 202610 records
RecordCRT-2026-02382026.08.11Afternoon roundtable
Identity recovery, session reuse, and payment-change controls

Immediate hardening of identity recovery and payment-change workflows

Identity recovery, payroll, finance, manager, and privileged-user workflows should ban voice-only recovery, require verified approvals and pre-registered callbacks, move high-risk users toward phishing-resistant authentication, revoke sessions after suspected compromise, audit mailbox rules and delegates, and require out-of-band approval for payroll-bank changes.

AreaPatch prioritizationRisk acceptance
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps6 references
StateActiveRev 2026-08-11
RecordCRT-2026-02372026.08.11Afternoon roundtable
Roundcube emergency patching and post-patch hunting

Emergency patching for exposed self-hosted Roundcube

Exposed self-hosted Roundcube installations should preserve relevant logs first, then urgently upgrade according to vendor-fixed branches, restrict risky plugins or administrative access as needed, and hunt for abnormal mailbox, IMAP, callback, PHP execution, and session activity.

AreaPatch prioritizationVulnerability
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps5 references
StateActiveRev 2026-08-11
RecordCRT-2026-02362026.08.11Afternoon roundtable
OT remote-access compromise incident handling

Safety-first response to OT remote-access compromise

OT operators should treat remote-access compromise patterns as safety incidents, pairing incident leadership with operations, independently verifying physical conditions, freezing PLC and HMI changes, preserving remote-access logs, revoking sessions, restricting vendor access, and avoiding unsafe recovery steps.

AreaBreachRisk acceptanceTechICS / OT
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps6 references
StateActiveRev 2026-08-11
RecordCRT-2026-02352026.08.11Afternoon roundtable
Malicious package and AI skill supply-chain response

Clean rebuild after suspicious package or AI skill execution

Environments that installed suspicious packages or cloned AI skills should freeze questionable sources, identify internal installs from build records and caches, rotate secrets exposed to those runtimes, and rebuild runners and workspaces from clean pinned versions.

AreaRisk acceptanceSupply chain
SeverityHigh
Evidence and confidenceHigh confidence · 1/8 backed · 2 gaps7 references
StateActiveRev 2026-08-11
RecordCRT-2026-02342026.08.11Afternoon roundtable
SonicWall SMA1000 emergency containment and patching

Containment-first patching for exposed SonicWall SMA1000 appliances

Exposed SonicWall SMA1000 appliances should be isolated or tightly access-restricted before and during emergency patching, with logs preserved, active sessions revoked, and investigation for compromise that may have occurred before patching.

AreaPatch prioritizationTechNetwork security
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps7 references
StateActiveRev 2026-08-11
RecordCRT-2026-02332026.08.11Morning roundtable
Same-day Android checks for finance workflows

Finance-sensitive Android loader checks

Keep Anatsa-style Android loader activity below the edge and MSP emergency priority, but run same-day MDM and app inventory for finance-sensitive Android devices, require Play Protect or mobile threat scans, remove suspicious reader or utility apps, check Accessibility and SMS permissions, and increase banking, payroll, expense-card, and crypto transaction monitoring.

AreaPatch prioritizationTechMobile platform
SeverityMedium
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps6 references
StateActiveRev 2026-08-11
RecordCRT-2026-02322026.08.11Morning roundtable
Same-day OT remote-access safety review

OT remote-access safety sweep for small utilities

Small water, wastewater, and energy operators should perform a controlled OT safety sweep: verify physical process state locally, remove public PLC and HMI exposure, restrict vendor VPNs, cellular routers, private APN paths, and edge management access, rotate default credentials with OT staff present, preserve logs, and test manual fallback procedures before disruptive segmentation changes.

AreaPatch prioritizationTechICS / OT
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps8 references
StateActiveRev 2026-08-11
RecordCRT-2026-02312026.08.11Morning roundtable
Enterprise AI assistant and agent restrictions

Privileged AI assistant scope controls

Reduce AI assistant and agent scopes, block untrusted document ingestion into privileged workflows, isolate execution environments, remove ambient credentials, log prompts and tool calls, and require human approval for external writes, credential use, code execution, and data export.

AreaRisk acceptance
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps8 references
StateActiveRev 2026-08-11
RecordCRT-2026-02302026.08.11Morning roundtable
Dependency-confusion response for private namespaces

Private package namespace dependency-resolution freeze

For builds exposed to a reported private namespace dependency-confusion pattern, freeze dependency resolution, pin package managers to intended private registries, audit CI logs for unexpected public package fetches, compare lockfiles against approved internal names, and rotate CI/CD secrets exposed during suspicious builds.

AreaVulnerabilityTechDevOps supply chain
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps5 references
StateActiveRev 2026-08-11
RecordCRT-2026-02292026.08.11Morning roundtable
WordPress supply-chain containment

BdThemes WordPress plugin containment

For affected or potentially affected BdThemes WordPress products, disable the components until administrators can verify a clean source, snapshot sites, inspect administrator accounts, plugin installs, web roots, scheduled tasks, MU-plugins, and outbound connections, and rotate credentials where untrusted code may have run.

AreaSupply chainTechWeb application
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps6 references
StateActiveRev 2026-08-11
10 AUGUST 202611 records
RecordCRT-2026-02282026.08.10Morning roundtable
AI agent access and action governance

Privileged automation governance for externally acting AI agents

AI agents that can read sensitive business content and act externally should be governed like privileged automation: use task-scoped identities, default-deny outbound paths, require human approval for external sends, bulk export, credential use, code execution, and irreversible actions, isolate tool use from production secrets, and log content retrieval, tool calls, destinations, and data volume.

AreaRisk acceptanceTechAI / ML systems
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps5 references
StateActiveRev 2026-08-10
RecordCRT-2026-02272026.08.10Morning roundtable
Mailbox and payment-fraud control response

Mailbox compromise response beyond password resets

Organizations should treat phished mailbox access as stolen session material, not just a password problem: revoke sessions, refresh tokens, app grants, and device trust; audit mailbox persistence and forwarding; disable external forwarding by default; use phishing-resistant authentication; and require out-of-band verification for payment or bank changes.

AreaRisk acceptanceVulnerabilityTechIdentity & access
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps7 references
StateActiveRev 2026-08-10
RecordCRT-2026-02262026.08.10Morning roundtable
Crypto payment infrastructure containment

Funds-control containment for exposed BTCPay and Lightning nodes

Crypto operators with exposed BTCPay Server or Lightning node administration surfaces should verify their deployment and vendor guidance, remove public admin and API exposure, pause automated payments, preserve wallet and channel state, revoke sessions and tokens, rotate node access material, and move funds from exposed hot environments into a clean environment.

AreaVulnerability
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps6 references
StateActiveRev 2026-08-10
RecordCRT-2026-02252026.08.10Morning roundtable
Exposed analytics and workflow systems

Assume-compromise handling for exposed Metabase and Langflow

Exposed Metabase and IBM Langflow instances should still be handled as possible compromise: remove internet exposure, upgrade or patch when applicable, revoke sessions, rotate connected credentials, and review logs for admin, export, secret-access, code-execution, and lateral-movement activity.

AreaPatch prioritizationSOC escalationVulnerability
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps8 references
StateActiveRev 2026-08-10
RecordCRT-2026-02242026.08.10Afternoon roundtable
Belgian eID signing workflow patching and signature reliance

Review reliance on Connective Belgian eID signatures

Do not assume blanket invalidity or continued reliance for signatures from the vulnerable window. Patch and version-verify managed endpoints, risk-tier or temporarily suspend high-value remote signing until verified, preserve signing logs and transaction metadata, and run a case-specific signature-reliance review before deciding whether affected transactions must be challenged, re-executed, caveated, or reported.

AreaPatch prioritizationRegulatoryRisk acceptance
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps5 references
StateActiveRev 2026-08-10
RecordCRT-2026-02232026.08.10Afternoon roundtable
Developer supply-chain containment and rebuild decisions

Freeze executed developer-trust paths after malicious packages or extensions

Freeze and quarantine CI jobs, build runners, publish workflows, and developer workstations where suspect npm packages, WEL1DROPPER or Sliver activity, malicious VS Code extensions, or AI-tool impersonators were installed or executed. Preserve artifacts first, rotate repository, cloud, package, and wallet credentials, and rebuild from clean images when payload execution, persistence, Sliver, or secret exposure is plausible.

AreaPatch prioritizationTechDevOps supply chain
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps7 references
StateActiveRev 2026-08-10
RecordCRT-2026-02222026.08.10Afternoon roundtable
AI agent delegated authority and connector controls

Govern AI agents as privileged connector infrastructure

Enterprise AI agents and assistants should be governed as privileged OAuth clients and connector brokers. Disable unused or overbroad connectors, limit write, administrator, export, and payment actions, require server-side object authorization and admin approval for high-risk grants, rotate or re-consent tokens where warranted, and log user-to-agent-to-tool actions alongside SaaS audit trails.

AreaBoard riskRisk acceptanceTechAI / ML systems
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps7 references
StateActiveRev 2026-08-10
RecordCRT-2026-02212026.08.10Afternoon roundtable
Identity and payment approval controls

Identity session and approval workflow hardening

Treat phishing-kit takedown as disruption, not remediation: revoke risky Microsoft 365 and Entra sessions and refresh tokens, inspect OAuth grants, require phishing-resistant MFA for high-risk roles, shorten session persistence, and move payment, payroll, vendor-bank, HR, and help-desk approvals to out-of-band dual control rather than relying on voice, video, email, or chat alone.

AreaPatch prioritizationRisk acceptanceTechIdentity & accessSaaS collaboration
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps5 references
StateActiveRev 2026-08-10
RecordCRT-2026-02202026.08.10Afternoon roundtable
WordPress core patch prioritization

WordPress emergency patching without mass RCE framing

Emergency-patch externally exposed and administrator-heavy WordPress sites, restrict login and admin paths to VPN or known IPs where patching is delayed, and reserve full containment for sites with post-exploitation indicators. Do not label the issue as mass unauthenticated remote code execution based on the reviewed evidence.

AreaPatch prioritizationTechWeb application
SeverityHigh
Evidence and confidenceHigh confidence · 0/9 backed · 2 gaps5 references
StateActiveRev 2026-08-10
RecordCRT-2026-02192026.08.10Afternoon roundtable
BTCPay Server LND credential safety

BTCPay Server LND release-status verification

Do not treat a reported release number as automatically safe. Treat BTCPay Server deployments with LND integration as exposed until the current project-fixed build is confirmed, public access is restricted, LND macaroons and related credential material are rotated or revoked, logs are reviewed, and funds are moved only after fresh credential authority is established.

AreaPatch prioritizationVulnerability
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps6 references
StateActiveRev 2026-08-10
RecordCRT-2026-02182026.08.10Afternoon roundtable
Metabase exposure response

Metabase exposure assume-compromise response

Treat affected or unverified exposed Metabase deployments and known Metabase Cloud exposure as possible compromise until the environment is verified: isolate admin paths, confirm the vendor fix or block the attack path, revoke stored database credentials and connector tokens, review sessions and admin changes, and assess connected datasets for possible exfiltration.

AreaRisk acceptanceVulnerability
SeverityHigh
Evidence and confidenceHigh confidence · 0/8 backed · 2 gaps6 references
StateActiveRev 2026-08-10
08 AUGUST 20262 records
RecordCRT-2026-02172026.08.08Afternoon roundtable
Exposed OT remote access continuity

Physical-process validation for exposed OT access

Treat exposed control-system and unsafe remote-access activity at water utilities and similar OT environments as an operational continuity incident. Remove direct internet exposure, require logged VPN and multifactor authentication where remote access remains necessary, preserve controller and access evidence, reset credentials carefully, and validate manual operations against physical instrumentation before trusting SCADA alone.

AreaRisk acceptanceSOC escalationTechICS / OT
SeverityCritical
Evidence and confidenceHigh confidence · 0/9 backed · 2 gaps6 references
StateActiveRev 2026-08-08
RecordCRT-2026-02162026.08.08Afternoon roundtable
CI/CD release integrity and dependency control

CI/CD release freeze for exposed TeamCity and risky npm changes

Pause release builds triggered by exposed or suspect TeamCity infrastructure and apply risk-based holds on high-risk npm dependency changes until the build path is investigated, dependencies are pinned, and build-job credentials are rotated.

AreaPatch prioritizationSOC escalationTechDevOps supply chain
SeverityCritical
Evidence and confidenceHigh confidence · 0/9 backed · 2 gaps8 references
StateActiveRev 2026-08-08

Showing 30 records of 244 public records · page 1 of 9

These controls filter only the 30 records on this page. Search the full Ledger

Prediction scoreboard

Calls on the record

Calibration deep-dive

Whole public corpus · 11 Calls made · 1 Calls graded right-or-wrong

Accuracy record

Graded right-or-wrong. Counts, never scores.

0Hit
1Miss
0Partial

Lifecycle exits

Closed without a grade — superseded by events or abandoned. Never counted with the accuracy record.

0Superseded
1Abandoned

Open calls

Still standing. Due language splits past from future.

9Still open
0Due ahead
9Overdue

Derived breakdowns (confidence × outcome, signal families) live in the calibration deep-dive; a derived cell under the minimum group size reads “Held” there.

Early-record retro pass pending — aggregate assessment will publish here; no per-record retro verdicts.

Unified Search

Search the public record.