Executive summary
What changed, in a page you can forward
The month compressed to the few developments that actually move your risk, written so it survives being sent to leadership unedited.
DPRK tradecraft escalated sharply, and three supply chain attacks landed in one month: Trivy, Resolv, and Axios. Here is what each one changes for you.
Priority threat themes
Each incident traced to your architecture
Not a recap of what happened to somebody else. Every theme names the route into your systems, and which assumption you already made no longer holds.
The Drift compromise materially expands the threat model: an operator in constant contact with node operators, DeFi teams, and vendors must now treat all relationships as intrusion paths to privileged staff.
Action items
Work you can assign this week
Grouped by owner: threat hunting, personnel, policy, security controls, supply chain, monitoring. Specific enough to drop straight into a sprint.
Identify every contract compiled with Solidity 0.8.28–0.8.33 under --via-ir. Sweep the endpoint fleet for a Contagious Interview RAT payload hash.
Watchlist
What is not urgent yet
Developments tracked before they become action items, so the month they start to matter is not the month you first hear about them.
Quantum risk timelines pulled forward to 2029. Chain-killer bugs still surfacing, including arbitrary struct hijacking in the Aptos Move VM.