Finding the network devices nobody owns means reconciling two lists that disagree
St. Lucie County found 3 unowned cameras from its permit file and 14 once it added a second list. The gap is the method.
Read →Notes on recent breaches and vulnerabilities — the specific practice that would have changed the outcome.
St. Lucie County found 3 unowned cameras from its permit file and 14 once it added a second list. The gap is the method.
Read →Fort Pierce police say an officer ran one plate 382 times and picked a reason each time. Nobody read the reasons for nine months.
Read →CISA gave three days to remediate two Linux kernel CVEs that name no product version. The fixed version is in your distro tracker, not the NVD range.
Read →Conductor 3.30.2 shipped June 3 and narrowed the GraalVM sandbox. It did not close the workflow API that evaluates expressions before login.
Read →Cisco named September 16 on September 9. The exploited ISE bug landed with a three-day KEV deadline, and the week before was the only slack.
Read →CVE-2026-85706 let an unauthenticated read of the GitLab secrets file, which holds the key that decrypts every CI/CD variable
Read →NCUA gives a credit union 72 hours from the moment it reasonably believes it had a reportable cyber incident, not from the moment it can prove one.
Read →Greenberg Traurig filed a consumer breach notice on September 9. It starts no clock for the client organizations whose documents were in the set.
Read →Cisco says upgrade only where exploitation of CVE-2026-76461 is not suspected. For a suspected virtual gateway it says new VM, rebuilt config, new credentials.
Read →For vCenter 7.0 the fix for CVE-2026-59310 is an extended support contract, and a tracker that reads patch available files it as done.
Read →FLHSMV could not wipe the personal phone a Plant City officer kept its login on. The controls it did hold were account scope and query volume.
Read →Three JFrog Artifactory advisories in 32 days: the 7.133 fix named in July is listed as affected in August, and all three CVEs are now in KEV.
Read →MikroTik shipped the compromise check inside the RouterOS patch. An un-flagged device has not been cleared, only checked against known signs.
Read →ConnectWise fixed CVE-2026-84869 in the ScreenConnect client, not the server. A patched server with stale agents is still the vulnerable build.
Read →Whether SAML gates CVE-2026-19490 depends on the NetScaler build. The June fixes sit in the gated range and 13.1 FIPS has no gate at all.
Read →A Sarasota vendor took 155 days to notify a breach against a 45-day Vermont deadline, because discovery was never defined in advance.
Read →CISA listed the Starlette and Kestra bugs by impact, not defect. Both are authorization bypasses, and your own middleware decides if yours is reachable.
Read →Two NetScaler CVEs shipped in one Citrix advisory. The precondition clause, not the severity score, decided which one could touch you.
Read →SonicWall shipped 12.4.3-03453 as the July fix for SMA1000. The September advisory lists that same build as affected, 49 days later.
Read →Craneware disclosed a breach to the London Stock Exchange. Your vendor disclosure venue is not the same thing as your notification clock.
Read →An Orlando practice was breached on legacy systems three months into an acquisition. The migration window is the gap nobody owns.
Read →A Miami Beach hospital settled a Florida wiretap claim over tracking scripts on its patient portal. The control that catches it is CSP report-only.
Read →Lennar detected a breach on March 30. A second intrusion began 57 days later, while the first investigation was still open.
Read →A NetScaler overread was exploited within a day of its patch and is still absent from KEV 45 days later. Your own config is the better trigger.
Read →A Kissimmee provider was named on a leak site 14 days after the estimated intrusion and had said nothing 8 days later. Both facts are normal.
Read →CISA replaced CVSS-scored patch deadlines with four variables in June. The KEV median deadline fell from 21 days to 3.
Read →Kovack Financial took 322 days to determine whose data was in the files. Regulation S-P now allows 30, and the default list is everyone.
Read →An Ocala IT provider and ten organizations hit a leak site in 26 hours. The RMM console is the admin account nobody audits.
Read →The FBI water-sector alert names no CVE. Initial access was the vendor programming software talking to an exposed PLC on a cellular modem.
Read →N-central 2026.2 fixed a critical auth bypass in April and named no CVE. The CVE arrived 95 days later, after the incomplete fix was exploited.
Read →CareCloud reported an eight-hour outage to the SEC. Its breach notice, four months later, described six days of database access nobody saw.
Read →Operation PAR detected the intrusion in four days and took 380 more to notify 145,714 people. The gap is a data inventory problem, not a legal one.
Read →Operation PAR detected the intrusion on day one and needed 365 more days to determine PHI was involved. The 60-day clock only starts at determination.
Read →