The lead this morning is North Korean state hackers running a Windows zero-day against US defense contractors long enough that CISA had to order every federal agency to patch on an emergency clock, not a routine one. Exploitation preceded the fix rather than following it: Microsoft's own advisory confirms active use before disclosure. Pyongyang's operators are running a patched-late campaign against the exact contractor base that feeds Indo-Pacific weapons programs, which is why this sits above the Nvidia depreciation story on Wall Street's ledger despite the bigger headline number there. On the physical security side, the Air Force One decoy detail from Trump's NATO trip, flown empty as a diversion after Iran had reportedly mapped his stay down to a shoulder-fired missile threat, follows the same logic in a different domain: the defense moved before the disclosure, not after. Inflation cooling to 3.4% and the Lakers' record $12.5 billion sale are noise against that pattern. A Hong Kong-based CISO reading this before the open has one job today: confirm patch status against the specific CVE, not the vendor's general advisory language. What to watch: whether CISA's directive names a hard compliance deadline by end of day. An open-ended order means agencies self-police the exposure.