Cyber Decision LedgerSeverity
Critical severity
17 public Decision Records in the whole ledger are currently rated critical. Back to the full Ledger →
Decision Records
Harden internet-exposed water-facility controllers
Remove programmable controllers from direct internet exposure, restrict operational-technology ports, rotate credentials, require multifactor authentication, preserve evidence, verify configurations and water quality, rehearse manual operation, and notify relevant authorities.
Water facilities should remove programmable controllers from direct internet exposure, restrict operational-technology ports, rotate credentials, require multifactor authentication, preserve evidence, verify controller configurations and water quality, rehearse manual operation, and notify relevant authorities. This precautionary action does not assert a specific incident count or actor attribution.
Replace weak Coldcard wallet seeds after firmware remediation
A firmware update alone does not remediate seeds generated with weak entropy. Update affected devices, create entirely new seeds on fixed firmware, independently verify receiving addresses, replace affected signing descriptors, and migrate funds from old addresses.
Organizations with potentially affected Coldcard-generated seeds should update the device using authoritative vendor guidance, generate entirely new seeds, verify receiving addresses independently, replace affected signing descriptors, and migrate funds from old addresses. Avoid publishing exact affected version ranges until primary vendor evidence is recorded.
Contain reported VMware vCenter exploitation
Remove vCenter management access from the internet, isolate systems showing compromise indicators, preserve evidence, apply vendor-supported fixes, rotate administrative credentials that may have been reachable, and hunt across managed ESXi hosts and datastores.
Organizations responding to reported vCenter exploitation should remove management interfaces from internet exposure, isolate systems with compromise indicators, preserve evidence, apply authoritative vendor fixes, rotate potentially reachable administrative credentials, and hunt across managed hosts and datastores. Verify local compromise rather than assuming every system was affected.
Physical-process validation for exposed OT access
Treat exposed control-system and unsafe remote-access activity at water utilities and similar OT environments as an operational continuity incident. Remove direct internet exposure, require logged VPN and multifactor authentication where remote access remains necessary, preserve controller and access evidence, reset credentials carefully, and validate manual operations against physical instrumentation before trusting SCADA alone.
Water utilities and operators of exposed OT should remove direct controller exposure, route necessary remote access through logged VPN and multifactor authentication, preserve controller and access evidence, and validate physical process state with field instrumentation before relying on SCADA readings. Broader sector claims should be added only with sector-specific evidence.
CI/CD release freeze for exposed TeamCity and risky npm changes
Pause release builds triggered by exposed or suspect TeamCity infrastructure and apply risk-based holds on high-risk npm dependency changes until the build path is investigated, dependencies are pinned, and build-job credentials are rotated.
Engineering teams with exposed or suspect TeamCity infrastructure should pause affected release builds, preserve and investigate CI evidence, pin high-risk dependencies, and rotate credentials available to build jobs. npm dependency holds should remain risk-based unless package-specific evidence is added.
N-able N-central compromise handling
Treat exposed or MSP-connected N-able N-central environments as a compromise investigation, not a patch-only task. Isolate affected systems from direct internet and customer reach, apply the current vendor-fixed release, rotate administrative and remote-control credentials, and hunt downstream for unauthorized access and possible persistence.
Organizations with exposed or MSP-connected N-able N-central should combine current vendor remediation with isolation, credential rotation, and compromise assessment. Customer-side review should include unauthorized remote access and, where evidence supports it, tunnel-like persistence hunting.
N-able N-central containment for exposed management environments
Treat exposed N-able N-central and Take Control environments as a critical containment event, not as patch-only remediation. Restrict management access, patch to validated fixed releases, revoke active admin sessions and credentials, and hunt for unauthorized remote-control activity and tunnel persistence before closure.
For exposed N-able management environments discussed in the briefing, treat remediation as containment-first. Restrict management access, patch to validated fixed releases, revoke sessions and credentials, and look for unauthorized remote-control activity or tunnel-style persistence before declaring recovery complete.
Safe-continuity response for exposed water-sector control paths
For internet-connected PLC, HMI, SCADA, or vendor remote-access paths in water or similar critical-infrastructure environments, treat exposure or suspected intrusion as a safety and continuity incident. Verify process state locally, shift to controlled local or manual operation when needed, isolate external command paths without breaking plant visibility, freeze engineering changes, preserve project files, and rotate engineering and vendor credentials from clean systems.
Water and critical-infrastructure operators should treat exposed or suspected-compromised control paths as urgent safety and continuity events. Confirm plant state locally, preserve evidence, use controlled local or manual operation where needed, isolate risky remote command paths carefully, and rotate engineering or vendor credentials from clean systems.
Handle Bluekit-style Microsoft AiTM phishing as session and token compromise
IAM and SOC teams should treat Bluekit-style Microsoft AiTM phishing as session/token compromise rather than password reset alone: revoke risky Microsoft sessions, invalidate refresh tokens, remove suspicious MFA methods and OAuth grants, enforce conditional access, force reauthentication, and move privileged or high-risk users to phishing-resistant authentication.
For Bluekit-style Microsoft AiTM phishing, response should focus on session and token containment rather than password reset alone: revoke risky sessions, invalidate refresh tokens, review MFA methods and OAuth grants, tighten conditional access, force reauthentication, and prioritize phishing-resistant authentication for privileged or high-risk users. Avoid claims about Bluekit scale or attribution unless independently sourced.
Treat Amazon Q/AWS developer-tool malicious-repository exposure as a same-day affected-fleet action
For affected developer fleets, inventory Amazon Q Developer and AWS Language Server usage, apply available updates or disable affected tooling, review untrusted repositories for reported `.amazonq/mcp.json` or unexpected MCP/tool execution, check for exposed cloud or SSH credentials, and restrict AI coding agents from auto-loading untrusted workspace tool configuration.
Organizations using Amazon Q Developer or AWS Language Servers should treat reported malicious-repository/tool-configuration exposure as a same-day developer-fleet check: inventory the tooling, apply available updates or temporarily disable affected integrations, review untrusted repositories for `.amazonq/mcp.json` or unexpected MCP/tool execution, check for exposed developer cloud or SSH credentials, and prevent AI coding agents from auto-loading untrusted workspace tool configuration.
Package Compromise Should Trigger CI/CD Secret Rotation and Build Containment
For suspected Miasma/Shai Hulud-style package compromise, freeze suspicious dependency changes, block affected package execution paths, audit npm/PyPI/Go lockfiles and GitHub Actions, rotate CI/CD, GitHub, package-manager, AWS and Redshift secrets, and inspect developer machines and runners for secret theft.
When package compromise is suspected in npm, PyPI, Go or CI/CD paths, freeze suspicious dependency changes, contain affected build paths, rotate workflow, package-manager and cloud secrets, and inspect runners and developer endpoints. Use known or suspected indicators pending local validation; do not imply this packet contains a complete IOC list.
Cisco Catalyst SD-WAN Manager Exploitation Requires Control-Plane IR
Patch and investigate Cisco Catalyst SD-WAN Manager CVE-2026-20245 urgently; isolate and inspect the manager, hunt unauthorized admin or root sessions, configuration pushes, rogue users or API tokens, audit/log tampering and template changes, and treat reported indicators as incident response.
For Cisco Catalyst SD-WAN Manager CVE-2026-20245, treat reported exploitation as a control-plane incident: patch urgently, inspect the manager, and hunt for unauthorized admin activity, configuration or API-token changes, and possible log or template tampering. Do not bundle separate PeopleSoft exploitation claims without primary support.
Suspected AWS AiTM Exposure Requires Same-Day IAM Containment
Treat suspected AWS AiTM credential/MFA capture as potential active session or token exposure: revoke sessions, invalidate tokens, rotate access keys and console credentials, inspect IAM persistence and console/API activity, and harden conditional-access and break-glass controls.
When AWS AiTM credential or MFA exposure is suspected, contain as if active sessions or tokens may be exposed: revoke sessions, rotate credentials and keys, inspect IAM changes and console/API activity, then harden access controls.
Dify remediation should retain controls until CVE-2026-41948 closure is verified
Treat the packet's Dify 1.14.2 guidance as necessary but not complete remediation until public vendor release or advisory evidence confirms CVE-2026-41948 closure; retain WAF/ACL restrictions and tenant-crossing access hunting in the meantime.
Dify operators should apply available updates while retaining compensating controls on trace/config and plugin-daemon paths until public vendor evidence confirms CVE-2026-41948 is closed. Review tenant-crossing access patterns during that period.
Prioritize exposed SonicWall SSLVPN remediation
Patch or isolate SonicWall SSLVPN exposure associated in the packet with CVE-2024-40766 today; rotate relevant local/VPN credentials, revoke active sessions, enforce MFA, and verify required post-patch configuration steps.
Organizations operating exposed SonicWall SSLVPN should treat remediation as urgent: patch or isolate affected exposure where applicable, rotate relevant VPN/local credentials, revoke active sessions, enforce MFA, and verify vendor-required post-patch configuration. Confirm exact affected scope and configuration details against authoritative SonicWall guidance.
Contain Salesloft Drift/Salesforce OAuth token abuse
For organizations using the affected Salesloft Drift/Salesforce integration, treat potential OAuth-token abuse as urgent containment: revoke Salesloft Drift OAuth access and refresh tokens, disconnect or reauthorize the Salesforce integration until assessed, and review Salesforce API/Event Monitoring logs, SOQL/query activity, exports, and CRM/support records for exposed secrets.
Organizations that use the affected Salesloft Drift/Salesforce integration should urgently revoke or rotate Drift OAuth access and refresh tokens, disconnect or reauthorize the Salesforce integration while assessing exposure, and review Salesforce API/Event Monitoring, SOQL/query and export activity, and CRM/support records for exposed secrets. Scope impact claims to tenant evidence and integration presence.
Contain Mastra/easy-day-js npm compromise exposure
Treat reported Mastra/easy-day-js npm exposure as requiring immediate precautionary CI and developer-environment containment: audit dependency use, check lockfiles and build logs for easy-day-js and suspect @mastra indicators, rebuild suspect CI runners, and rotate potentially exposed npm tokens and secrets.
Teams with Mastra/npm exposure should take precautionary containment steps for developer and CI environments, including dependency and lockfile review, CI runner rebuild where suspect, and token or secret rotation. Treat exact affected package scope and attribution as still caveated in this packet.