Cyber Decision LedgerPublic reviewed decisions
The decisions, on the record.
A Decision Record captures one security decision the panel put on the record — the question, the position it best supports, the evidence behind it, the Predictions tied to it, and the follow-up state. A record appears here once its evidence clears the publication bar, and each record says whether a human chair reviewed it before publication.
Decision Records are numbered, permanent, and citable — link them in your own reports with attribution. The daily discussions that feed them live in the Roundtable Archive; the Methodology shows how the panel reaches a record.
Decision Records
Restrict exposed Linux ksmbd SMB services for CVE-2026-52911
Treat exposed TCP/445 ksmbd services as a high-priority exposure-management item: inventory Linux hosts running ksmbd, disable ksmbd where unnecessary, restrict TCP/445 to trusted subnets, segment SMB hosts, monitor unusual SMB churn or crashes, and track kernel or vendor fixes.
Contain Salesloft Drift/Salesforce OAuth token abuse
For organizations using the affected Salesloft Drift/Salesforce integration, treat potential OAuth-token abuse as urgent containment: revoke Salesloft Drift OAuth access and refresh tokens, disconnect or reauthorize the Salesforce integration until assessed, and review Salesforce API/Event Monitoring logs, SOQL/query activity, exports, and CRM/support records for exposed secrets.
Contain Mastra/easy-day-js npm compromise exposure
Treat reported Mastra/easy-day-js npm exposure as requiring immediate precautionary CI and developer-environment containment: audit dependency use, check lockfiles and build logs for easy-day-js and suspect @mastra indicators, rebuild suspect CI runners, and rotate potentially exposed npm tokens and secrets.
Treat FortiBleed/FortiGate exposure as credential-containment
Revoke active admin, VPN, and cloud sessions before treating password rotation as sufficient; rotate admin, local, VPN, and exposed secrets; restrict login and management surfaces; force re-authentication; replace SMS MFA with stronger MFA; rebuild or factory-reset only where persistence or tampering is suspected.
Showing 4 records · page 9 of 9
These controls filter only the 4 records on this page. Search the full Ledger →