Cyber Decision LedgerSeverity

Critical severity

17 public Decision Records in the whole ledger are currently rated critical. Back to the full Ledger →

Decision Records

Immediate defense of water-facility controllersCRT-2026-02452026.08.18Morning roundtable3 references

Harden internet-exposed water-facility controllers

Remove programmable controllers from direct internet exposure, restrict operational-technology ports, rotate credentials, require multifactor authentication, preserve evidence, verify configurations and water quality, rehearse manual operation, and notify relevant authorities.

Water facilities should remove programmable controllers from direct internet exposure, restrict operational-technology ports, rotate credentials, require multifactor authentication, preserve evidence, verify controller configurations and water quality, rehearse manual operation, and notify relevant authorities. This precautionary action does not assert a specific incident count or actor attribution.

ActiveLast revised 2026-08-18
AreaBreachVulnerability
SeverityCritical
ConfidenceHigh confidence · 1/8 backed · 2 gaps
Coldcard weak-seed remediationCRT-2026-02412026.08.17Afternoon roundtable4 references

Replace weak Coldcard wallet seeds after firmware remediation

A firmware update alone does not remediate seeds generated with weak entropy. Update affected devices, create entirely new seeds on fixed firmware, independently verify receiving addresses, replace affected signing descriptors, and migrate funds from old addresses.

Organizations with potentially affected Coldcard-generated seeds should update the device using authoritative vendor guidance, generate entirely new seeds, verify receiving addresses independently, replace affected signing descriptors, and migrate funds from old addresses. Avoid publishing exact affected version ranges until primary vendor evidence is recorded.

ActiveLast revised 2026-08-17
AreaVulnerability
SeverityCritical
ConfidenceHigh confidence · 0/8 backed · 2 gaps
VMware vCenter exploitation responseCRT-2026-02402026.08.17Afternoon roundtable4 references

Contain reported VMware vCenter exploitation

Remove vCenter management access from the internet, isolate systems showing compromise indicators, preserve evidence, apply vendor-supported fixes, rotate administrative credentials that may have been reachable, and hunt across managed ESXi hosts and datastores.

Organizations responding to reported vCenter exploitation should remove management interfaces from internet exposure, isolate systems with compromise indicators, preserve evidence, apply authoritative vendor fixes, rotate potentially reachable administrative credentials, and hunt across managed hosts and datastores. Verify local compromise rather than assuming every system was affected.

ActiveLast revised 2026-08-17
TechVirtualizationAreaBreachPatch prioritization
SeverityCritical
ConfidenceHigh confidence · 0/8 backed · 2 gaps
Exposed OT remote access continuityCRT-2026-02172026.08.08Afternoon roundtable6 references

Physical-process validation for exposed OT access

Treat exposed control-system and unsafe remote-access activity at water utilities and similar OT environments as an operational continuity incident. Remove direct internet exposure, require logged VPN and multifactor authentication where remote access remains necessary, preserve controller and access evidence, reset credentials carefully, and validate manual operations against physical instrumentation before trusting SCADA alone.

Water utilities and operators of exposed OT should remove direct controller exposure, route necessary remote access through logged VPN and multifactor authentication, preserve controller and access evidence, and validate physical process state with field instrumentation before relying on SCADA readings. Broader sector claims should be added only with sector-specific evidence.

ActiveLast revised 2026-08-08
TechICS / OTAreaRisk acceptanceSOC escalation
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps
CI/CD release integrity and dependency controlCRT-2026-02162026.08.08Afternoon roundtable8 references

CI/CD release freeze for exposed TeamCity and risky npm changes

Pause release builds triggered by exposed or suspect TeamCity infrastructure and apply risk-based holds on high-risk npm dependency changes until the build path is investigated, dependencies are pinned, and build-job credentials are rotated.

Engineering teams with exposed or suspect TeamCity infrastructure should pause affected release builds, preserve and investigate CI evidence, pin high-risk dependencies, and rotate credentials available to build jobs. npm dependency holds should remain risk-based unless package-specific evidence is added.

ActiveLast revised 2026-08-08
TechDevOps supply chainAreaPatch prioritizationSOC escalation
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps
N-central post-exploitation responseCRT-2026-02102026.08.08Morning roundtable6 references

N-able N-central compromise handling

Treat exposed or MSP-connected N-able N-central environments as a compromise investigation, not a patch-only task. Isolate affected systems from direct internet and customer reach, apply the current vendor-fixed release, rotate administrative and remote-control credentials, and hunt downstream for unauthorized access and possible persistence.

Organizations with exposed or MSP-connected N-able N-central should combine current vendor remediation with isolation, credential rotation, and compromise assessment. Customer-side review should include unauthorized remote access and, where evidence supports it, tunnel-like persistence hunting.

ActiveLast revised 2026-08-08
TechEndpoint securityAreaSOC escalationVulnerability
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps
N-able N-central containmentCRT-2026-01872026.08.05Morning roundtable5 references

N-able N-central containment for exposed management environments

Treat exposed N-able N-central and Take Control environments as a critical containment event, not as patch-only remediation. Restrict management access, patch to validated fixed releases, revoke active admin sessions and credentials, and hunt for unauthorized remote-control activity and tunnel persistence before closure.

For exposed N-able management environments discussed in the briefing, treat remediation as containment-first. Restrict management access, patch to validated fixed releases, revoke sessions and credentials, and look for unauthorized remote-control activity or tunnel-style persistence before declaring recovery complete.

ActiveLast revised 2026-08-05
AreaPatch prioritizationSOC escalationVulnerability
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Water-sector OT exposure responseCRT-2026-01422026.07.30Morning roundtable6 references

Safe-continuity response for exposed water-sector control paths

For internet-connected PLC, HMI, SCADA, or vendor remote-access paths in water or similar critical-infrastructure environments, treat exposure or suspected intrusion as a safety and continuity incident. Verify process state locally, shift to controlled local or manual operation when needed, isolate external command paths without breaking plant visibility, freeze engineering changes, preserve project files, and rotate engineering and vendor credentials from clean systems.

Water and critical-infrastructure operators should treat exposed or suspected-compromised control paths as urgent safety and continuity events. Confirm plant state locally, preserve evidence, use controlled local or manual operation where needed, isolate risky remote command paths carefully, and rotate engineering or vendor credentials from clean systems.

ActiveLast revised 2026-07-30
TechICS / OTAreaRisk acceptanceSOC escalation
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Bluekit-style Microsoft AiTM session-token responseCRT-2026-00182026.06.28Afternoon roundtable7 references

Handle Bluekit-style Microsoft AiTM phishing as session and token compromise

IAM and SOC teams should treat Bluekit-style Microsoft AiTM phishing as session/token compromise rather than password reset alone: revoke risky Microsoft sessions, invalidate refresh tokens, remove suspicious MFA methods and OAuth grants, enforce conditional access, force reauthentication, and move privileged or high-risk users to phishing-resistant authentication.

For Bluekit-style Microsoft AiTM phishing, response should focus on session and token containment rather than password reset alone: revoke risky sessions, invalidate refresh tokens, review MFA methods and OAuth grants, tighten conditional access, force reauthentication, and prioritize phishing-resistant authentication for privileged or high-risk users. Avoid claims about Bluekit scale or attribution unless independently sourced.

ActiveLast revised 2026-06-28
TechIdentity & accessAreaSOC escalationVulnerability
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Amazon Q/AWS developer tooling malicious-repository exposureCRT-2026-00172026.06.28Afternoon roundtable6 references

Treat Amazon Q/AWS developer-tool malicious-repository exposure as a same-day affected-fleet action

For affected developer fleets, inventory Amazon Q Developer and AWS Language Server usage, apply available updates or disable affected tooling, review untrusted repositories for reported `.amazonq/mcp.json` or unexpected MCP/tool execution, check for exposed cloud or SSH credentials, and restrict AI coding agents from auto-loading untrusted workspace tool configuration.

Organizations using Amazon Q Developer or AWS Language Servers should treat reported malicious-repository/tool-configuration exposure as a same-day developer-fleet check: inventory the tooling, apply available updates or temporarily disable affected integrations, review untrusted repositories for `.amazonq/mcp.json` or unexpected MCP/tool execution, check for exposed developer cloud or SSH credentials, and prevent AI coding agents from auto-loading untrusted workspace tool configuration.

ActiveLast revised 2026-06-28
TechCloud platformAreaPatch prioritizationVulnerability
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Software supply-chain CI/CD containmentCRT-2026-00152026.06.28Morning roundtable8 references

Package Compromise Should Trigger CI/CD Secret Rotation and Build Containment

For suspected Miasma/Shai Hulud-style package compromise, freeze suspicious dependency changes, block affected package execution paths, audit npm/PyPI/Go lockfiles and GitHub Actions, rotate CI/CD, GitHub, package-manager, AWS and Redshift secrets, and inspect developer machines and runners for secret theft.

When package compromise is suspected in npm, PyPI, Go or CI/CD paths, freeze suspicious dependency changes, contain affected build paths, rotate workflow, package-manager and cloud secrets, and inspect runners and developer endpoints. Use known or suspected indicators pending local validation; do not imply this packet contains a complete IOC list.

ActiveLast revised 2026-06-28
TechCloud platformDevOps supply chainAreaSupply chainVulnerability
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Cisco Catalyst SD-WAN Manager incident responseCRT-2026-00142026.06.28Morning roundtable7 references

Cisco Catalyst SD-WAN Manager Exploitation Requires Control-Plane IR

Patch and investigate Cisco Catalyst SD-WAN Manager CVE-2026-20245 urgently; isolate and inspect the manager, hunt unauthorized admin or root sessions, configuration pushes, rogue users or API tokens, audit/log tampering and template changes, and treat reported indicators as incident response.

For Cisco Catalyst SD-WAN Manager CVE-2026-20245, treat reported exploitation as a control-plane incident: patch urgently, inspect the manager, and hunt for unauthorized admin activity, configuration or API-token changes, and possible log or template tampering. Do not bundle separate PeopleSoft exploitation claims without primary support.

ActiveLast revised 2026-06-28
TechNetwork infrastructureAreaPatch prioritizationSOC escalation
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps
AWS AiTM IAM containmentCRT-2026-00132026.06.28Morning roundtable6 references

Suspected AWS AiTM Exposure Requires Same-Day IAM Containment

Treat suspected AWS AiTM credential/MFA capture as potential active session or token exposure: revoke sessions, invalidate tokens, rotate access keys and console credentials, inspect IAM persistence and console/API activity, and harden conditional-access and break-glass controls.

When AWS AiTM credential or MFA exposure is suspected, contain as if active sessions or tokens may be exposed: revoke sessions, rotate credentials and keys, inspect IAM changes and console/API activity, then harden access controls.

ActiveLast revised 2026-06-28
TechCloud platformAreaSOC escalationThreat actor
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Dify CVE-2026-41948 compensating controlsCRT-2026-00092026.06.25Afternoon roundtable6 references

Dify remediation should retain controls until CVE-2026-41948 closure is verified

Treat the packet's Dify 1.14.2 guidance as necessary but not complete remediation until public vendor release or advisory evidence confirms CVE-2026-41948 closure; retain WAF/ACL restrictions and tenant-crossing access hunting in the meantime.

Dify operators should apply available updates while retaining compensating controls on trace/config and plugin-daemon paths until public vendor evidence confirms CVE-2026-41948 is closed. Review tenant-crossing access patterns during that period.

ActiveLast revised 2026-06-25
AreaPatch prioritizationVendor claim
SeverityCritical
ConfidenceModerate confidence · 0/9 backed · 2 gaps
SonicWall SSLVPN exposure remediationCRT-2026-00052026.06.25Afternoon roundtable3 references

Prioritize exposed SonicWall SSLVPN remediation

Patch or isolate SonicWall SSLVPN exposure associated in the packet with CVE-2024-40766 today; rotate relevant local/VPN credentials, revoke active sessions, enforce MFA, and verify required post-patch configuration steps.

Organizations operating exposed SonicWall SSLVPN should treat remediation as urgent: patch or isolate affected exposure where applicable, rotate relevant VPN/local credentials, revoke active sessions, enforce MFA, and verify vendor-required post-patch configuration. Confirm exact affected scope and configuration details against authoritative SonicWall guidance.

ActiveLast revised 2026-06-25
TechIdentity & accessNetwork securityAreaPatch prioritization
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Salesloft Drift/Salesforce OAuth token containmentCRT-2026-00032026.06.25Afternoon roundtable3 references

Contain Salesloft Drift/Salesforce OAuth token abuse

For organizations using the affected Salesloft Drift/Salesforce integration, treat potential OAuth-token abuse as urgent containment: revoke Salesloft Drift OAuth access and refresh tokens, disconnect or reauthorize the Salesforce integration until assessed, and review Salesforce API/Event Monitoring logs, SOQL/query activity, exports, and CRM/support records for exposed secrets.

Organizations that use the affected Salesloft Drift/Salesforce integration should urgently revoke or rotate Drift OAuth access and refresh tokens, disconnect or reauthorize the Salesforce integration while assessing exposure, and review Salesforce API/Event Monitoring, SOQL/query and export activity, and CRM/support records for exposed secrets. Scope impact claims to tenant evidence and integration presence.

ActiveLast revised 2026-06-25
TechIdentity & accessSaaS collaborationAreaPatch prioritizationVulnerability
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Mastra npm supply-chain containmentCRT-2026-00022026.06.25Morning roundtable3 references

Contain Mastra/easy-day-js npm compromise exposure

Treat reported Mastra/easy-day-js npm exposure as requiring immediate precautionary CI and developer-environment containment: audit dependency use, check lockfiles and build logs for easy-day-js and suspect @mastra indicators, rebuild suspect CI runners, and rotate potentially exposed npm tokens and secrets.

Teams with Mastra/npm exposure should take precautionary containment steps for developer and CI environments, including dependency and lockfile review, CI runner rebuild where suspect, and token or secret rotation. Treat exact affected package scope and attribution as still caveated in this packet.

ActiveLast revised 2026-06-25
TechDevOps supply chainAreaRisk acceptanceSupply chain
SeverityCritical
ConfidenceHigh confidence · 0/9 backed · 2 gaps

Unified Search

Search the public record.