- Engineer — Act: Patch Roundcube Webmail to the version released in May or later immediately — active exploitation confirmed by a national cyber authority means this is no longer a routine patch-window item; prioritize any self-hosted Roundcube instances over other queued work.
- SOC/IR — Act: Sweep Roundcube server logs for signs of code injection attempts since May; active exploitation of a webmail platform can yield credential access or persistent footholds before patching occurs, so assume-breach investigation is warranted on any unpatched instances.
- Leader — Skip