Beat
Commentary
Critique and analysis of vendor patterns, framework guides, and the gap between security writing and operations.
Written by Colten Anderson.
Lead story
Analysis · Jul 8, 2026 · Colten Anderson
Your incident runbook is stored inside the system that just went down
Wikis, IR plans, and recovery steps usually live on the same infrastructure, identity provider, and cloud region that go dark during an incident.
More from this beat
-
Analysis · Jul 7, 2026 · Colten Anderson
Your backup server is joined to the domain it exists to recover
Joining your backup server to the production Active Directory domain puts your last line of recovery inside the same trust boundary as the systems it protects, so one Domain Admin compromise reaches the backups too.
-
Analysis · Jul 7, 2026 · Colten Anderson
One in ten AD accounts is dormant. Here is the blast radius.
More than one in ten Active Directory user accounts is dormant, per Microsoft.
-
Analysis · Jul 6, 2026 · Colten Anderson
Edge devices need a tighter patch SLA than your servers
Vulnerability exploitation is now the top way attackers get in, and the edge is where it starts.
-
Analysis · Jun 30, 2026 · Colten Anderson
The AI under your SOC just became a supply-chain dependency
In three weeks of June 2026, the US government delayed, gated, or killed three frontier models on capability grounds.
-
Analysis · Jun 22, 2026 · Colten Anderson
CVE-2026-45657: 'Exploitation Less Likely' Is Not a Patch Window
Microsoft's June kernel use-after-free is wormable, CVSS 9.
-
Analysis · Jun 20, 2026 · Colten Anderson
GeoServer CVE-2024-36401: The Map Nobody Owned
A CVSS 9.
-
Analysis · Jun 19, 2026 · Colten Anderson
Your vuln scanner is looking for OpenSSH. The exploited bug is in Erlang.
CVE-2025-32433 is a CVSS 10.
-
Analysis · Jun 18, 2026 · Colten Anderson
Two Struts CVEs, one incomplete fix, and the enterprise Java visibility problem
CVE-2023-50164 and CVE-2024-53677 hit the same file upload component in Apache Struts, a year apart.
-
Analysis · Jun 18, 2026 · Colten Anderson
Patching Ivanti Sentry Closes the Door. It Doesn't Evict the Guest.
Shadowserver found backdoored Ivanti Sentry instances within 48 hours of the PoC and said the rest are most likely compromised.
-
Analysis · Jun 17, 2026 · Colten Anderson
regreSSHion proved 'hard to exploit' is not a patch window
CVE-2024-6387 got filed under 'low priority' because it's slow on 64-bit.
-
Analysis · Jun 16, 2026 · Colten Anderson
Juniper Junos OS has six KEV entries and two separate attack surfaces
Five CVSS 5.
-
Analysis · Jun 16, 2026 · Colten Anderson
A model was pulled for being too good at finding bugs
Anthropic shipped Claude Fable 5 and Mythos 5, then a federal directive killed both four days later.
-
Analysis · Jun 5, 2026 · Colten Anderson
Two AWS bugs you'd never have heard about, and the fix was yours
AWS disclosed two SageMaker SDK flaws on its own bulletins page.
-
Analysis · Jun 5, 2026 · Colten Anderson
Your Azure CLI session has an MFA exemption you never asked for
Two Entra Conditional Access changes land in the same fortnight, and they're the lead evidence in a longer story: Microsoft is closing the identity opt-outs orgs have leaned on for years.
-
Analysis · Jun 3, 2026 · Colten Anderson
Three CVEs keep getting called the Nx attack, and only one of them is this one
An 18-minute window on the VS Code marketplace ended with 3,800 of GitHub's own repositories copied.
-
Analysis · May 29, 2026 · Colten Anderson
Gogs has a critical RCE and no one is coming to fix it
Rapid7 found a push-button remote code execution flaw in Gogs, shipped a Metasploit module with it, and ran 72 days from report to publication with no patch and two months of maintainer silence.
-
Analysis · May 29, 2026 · Colten Anderson
Palo Alto's third edge zero-day in two years rhymes with the first two
CISA's federal deadline for CVE-2026-0300 landed four days before a patch existed.
-
Analysis · May 28, 2026 · Colten Anderson
GlassWorm's botnet is down, but the technique it proved still works
CrowdStrike, Google, and Shadowserver knocked out all four C2 channels at once.
-
Analysis · May 28, 2026 · Colten Anderson
Ingress-nginx got archived in March. The first critical CVE arrived in May.
The Kubernetes community archived ingress-nginx seven weeks before an 18-year-old heap overflow dropped in the NGINX core it ships.
-
Analysis · May 28, 2026 · Colten Anderson
The print stack regresses on schedule
KB5087424 broke 32-bit printing on Windows Server 2022 hotpatch fleets.
-
Analysis · May 27, 2026 · Colten Anderson
Hotpatch was supposed to be the smoother path
KB5087424 broke 32-bit printing on Windows Server 2022, and the no-reboot delivery model that was supposed to reduce friction has no fix path that doesn't surrender the security content.
-
Analysis · May 25, 2026 · Colten Anderson
Microsoft patched a SYSTEM bug in 2020. It still works in 2026.
A pseudonymous researcher published MiniPlasma, a working PoC for CVE-2020-17103, and the only thing standing between you and a SYSTEM shell is a driver you cannot turn off.
-
Analysis · May 25, 2026 · Colten Anderson
SonicWall patched CVE-2024-12802 and left the bug in place on Gen6
The firmware update closes the code path but does not rewrite the LDAP config the exploit actually uses.
-
Analysis · May 24, 2026 · Colten Anderson
The patch window went negative. Now what?
Mandiant's mean time-to-exploit is negative seven days.
-
Analysis · May 22, 2026 · Colten Anderson
Your antivirus runs as SYSTEM, and that's the whole story
Two actively-exploited Defender zero-days look like 'the AV is broken.
-
Analysis · May 20, 2026 · Colten Anderson
CISA just gave the Conficker bug a 2026 deadline
Five of the seven CVEs CISA added on May 20 are 2008โ2010 fossils, including MS08-067 and Operation Aurora.
-
Analysis · May 20, 2026 · Colten Anderson
The Linux firewall bug your users can reach because you gave them a private root
CVE-2024-1086 is an nf_tables use-after-free that hands a local user root.
-
Analysis · May 20, 2026 · Colten Anderson
The most dangerous server in the hospital is the one nobody can name
Mirth Connect moves patient records between systems and runs with high privileges, and a lot of installs sit on the open internet.
-
Analysis · May 20, 2026 · Colten Anderson
The other half of the ScreenConnect chain just got a 2026 deadline
CVE-2024-1709 got the CVSS 10 and the headlines in February 2024.
-
Analysis · May 20, 2026 · Colten Anderson
The user opened a JPG they could see in the archive. A RAT installed behind it.
CVE-2023-38831 weaponizes the one thing you tell users is safe: opening a file they can see.
-
Analysis · May 18, 2026 · Colten Anderson
5 Ways GitHub Spent April Lighting Itself On Fire
GitHub logged ten separate outages in one month, including one fixed by turning DNS off and on again.
-
Analysis · May 18, 2026 · Colten Anderson
A valid signature is not a vouch
For 27 days the official DAEMON Tools installer carried a clean Disc Soft signature and a backdoor.
-
Analysis · May 18, 2026 · Colten Anderson
Microsoft titled it Spoofing. It's session hijacking.
CVE-2026-42897 is the first real test of Exchange Server Subscription Edition's new servicing model.
-
Analysis · May 17, 2026 · Colten Anderson
Three CitrixBleeds in 30 months is not a streak, it is a code surface
CVE-2026-3055 is the third pre-auth memory disclosure in NetScaler's authentication stack in 30 months.
-
Analysis · May 17, 2026 · Colten Anderson
The malware was signed. The signature was real. The package was poison.
TanStack's npm release pipeline published 84 malicious package versions with valid SLSA provenance.
-
Analysis · May 15, 2026 · Colten Anderson
The patch ring math stops working at fifty endpoints
Enterprise ring guidance assumes a fleet big enough that 5% is a meaningful sample.
-
Analysis · May 14, 2026 · Colten Anderson
Rapid7 found a second CVSS 10 in Cisco SD-WAN while researching the first
Two unauthenticated auth bypasses in the same Cisco vdaemon in under three months, both being exploited by the same actor that has been sitting in critical-infrastructure fabrics since 2023.
-
Analysis · May 14, 2026 · Colten Anderson
Vercel shipped the framework. You're shipping the patch
CVE-2026-44578 is a CVSS 8.
-
Analysis · May 14, 2026 · Colten Anderson
Does this CVE actually apply to you? Three filters before you patch
Single-score triage fails in both directions: 10.
-
Analysis · May 13, 2026 · Colten Anderson
Daybreak shipped without a single number of its own
OpenAI announced an end-to-end vulnerability detection and patching platform on May 12, then borrowed every performance figure from its predecessors.
-
Analysis · May 12, 2026 · Colten Anderson
What 14 days of TeamPCP told us about registry defense in 2026
Five compromises across two ecosystems in six weeks, then a 169-package npm wave on May 11.
-
Analysis · May 11, 2026 · Colten Anderson
Cisco is now telling you the patch doesn't clean the box
Cisco's April 23 PSIRT advisory says the ArcaneDoor implant survives upgrading to the September 2025 fixes for CVE-2025-20333 and CVE-2025-20362.
-
Analysis · May 11, 2026 · Colten Anderson
The CVSS 4.3 that APT28 was already using
Microsoft shipped the fix for CVE-2026-32202 without an exploitation flag while Russian state actors had a five-month head start.
-
Analysis · May 10, 2026 · Colten Anderson
Array Networks patched in a week and forgot to build a security program
CVE-2023-28461 is a CVSS 9.
-
Analysis · May 10, 2026 · Colten Anderson
The seven-year gap is the story, not the CVE
Microsoft patched CVE-2018-8639 in December 2018.
-
Analysis · May 10, 2026 · Colten Anderson
The second bug is the easy one now
Two unrelated actors weaponized the same Task Scheduler zero-day at the same time.
-
Analysis · May 10, 2026 · Colten Anderson
Zyxel patched CVE-2024-11667 in September. They named it in November
The fix shipped on September 3, 2024.
-
Analysis · May 10, 2026 · Colten Anderson
SimpleHelp CVE-2024-57727: a seven-day patch and a sixteen-month leak
SimpleHelp shipped a fix in seven days from full disclosure.
-
Analysis · May 8, 2026 · Colten Anderson
Five critical Fortinet CVEs in 28 months is not a streak of bad luck
Three heap overflows, two auth bypasses, all pre-auth, all ransomware-linked.
-
Analysis · May 8, 2026 · Colten Anderson
Three root shells in seven months. All from the same firewall.
CVE-2024-3400, CVE-2024-0012, and CVE-2024-9474 gave attackers unauthenticated root on Palo Alto firewalls twice in 2024.
-
Analysis · May 8, 2026 · Colten Anderson
Ivanti Connect Secure: the perimeter that keeps breaking
Five KEV-listed Ivanti Connect Secure bugs in fifteen months, all ransomware-tagged, all on the unauthenticated path.
-
Analysis · May 4, 2026 · Colten Anderson
Three hours was the good outcome: npm's trust model and the Axios compromise
A DPRK threat actor backdoored two Axios versions on npm.
-
Analysis · May 3, 2026 · Colten Anderson
50 CVEs in 18 months is not a growing pain. It's a design choice the industry keeps making.
MCP went from unknown to default AI integration in under two years.
-
Analysis · May 3, 2026 · Colten Anderson
Spirit Airlines is dead. Its attack surface isn't.
The security story isn't that an airline went bankrupt.
-
Analysis · May 1, 2026 · Colten Anderson
The security work that landed on ops
Cloud shared responsibility, compliance mandates, and insecure defaults have quietly moved security execution onto ops teams that were never staffed for it.
-
Analysis · May 1, 2026 · Colten Anderson
People problems wearing a server badge
The sysadmin job was sold as infrastructure.
-
Analysis · May 1, 2026 · Colten Anderson
Microsoft: the Patch Day cinematic universe
Licensing, patches, email blocking, Copilot, Recall, Windows replacement.
-
Analysis · May 1, 2026 · Colten Anderson
The feedback loop is broken
Executives keep making the same categories of bad IT decisions because the consequences land on operators, not decision-makers.
-
Analysis · May 1, 2026 · Colten Anderson
Your security vendor's AI isn't making you safer. It's making you tired.
76% of cybersecurity professionals say the AI landscape is overwhelmed by overpromotion.
-
Analysis · May 1, 2026 · Colten Anderson
The most dangerous sentence in a code comment is 'this should never happen'
From Therac-25 to CrowdStrike, the same pattern keeps producing catastrophic failures: an engineer reasons that a condition is impossible, skips the guard, and the system outgrows the assumption.
-
Analysis · May 1, 2026 · Colten Anderson
The same LDAP injection, in two firewalls, in the same month
OPNsense shipped a textbook LDAP filter injection that hid for eleven years.
-
Analysis · May 1, 2026 · Colten Anderson
The Vercel breach is the Heroku/Travis CI playbook, rerun through an AI tool
A compromised OAuth token at a small AI productivity company gave attackers a path into Vercel's internal systems.
-
Analysis · May 1, 2026 · Colten Anderson
Anthropic's MCP gives every downstream app unauthenticated RCE, and they called it expected behavior
The Model Context Protocol's STDIO transport passes user input directly into subprocess execution with no sanitization.
-
Analysis · May 1, 2026 · Colten Anderson
Windows Defender is the attack surface now, and two of the three exploits don't have patches
Three tools dropped in April turn Defender's own privileged operations into privilege escalation and detection evasion.
-
Field Note · Apr 29, 2026 · Colten Anderson
Best practices for patch prioritization in a hybrid environment: start with business impact
Severity scores tell you which CVE is nastiest.
-
Analysis · Apr 28, 2026 · Colten Anderson
What patching looks like when you support the whole mess: endpoints, M365, identity, browsers, VPN, and line-of-business tools
Patching isn't Windows Updates anymore.
-
Field Note · Apr 28, 2026 · Colten Anderson
Patch now, patch later, ignore for now: the triage model real IT teams actually need
A three-bucket triage model for sysadmins who don't own a vulnerability scanner and aren't going to buy one.
-
Analysis · Apr 28, 2026 · Colten Anderson
Why most patch summaries fail the people who actually have to do the work
Vendor advisories are written for completeness.